Testing the possibility of circumvention of the authenticity mechanism

Attempts to bypass the authenticity mechanism are intended to verify that it is possible to access resources not intended for the user in an unauthorized manner. You can use Burp Suite to test these types of errors,and the tests themselves should include checking the following: attempt to bypass the authentication… Continue reading

Test for authentication data compatibility with popular dictionaries

Most web application users do not follow the recommendations for using difficult, non-dictionary access data. They often base their passwords on words and phrases they easily won't forget. These words are children's names, street addresses, favorite football team, place of birth, etc.User accounts – Especially administrative accounts should be protected… Continue reading