BETA Shoulder jest w wersji beta — Wyniki mogą czasami być błędne. Twoja opinia kształtuje to, co naprawimy w następnej kolejności. Podziel się opinią
#7 A07:2021

Identification and Authentication Failures

Confirmation of the user's identity, authentication, and session management is critical to protect against authentication-related attacks.

Przeglad

Previously known as Broken Authentication. Slid down from #2, now includes CWEs more related to identification failures. This category is still an integral part of the Top 10.

Jak Atakujacy To Wykorzystuja

Zrozumienie wzorcow atakow pomaga budowac lepsze zabezpieczenia. To sa techniki, ktore zespoly bezpieczenstwa monitoruja.

Credential stuffing

Attackers use lists of stolen credentials from other breaches to attempt login across many sites.

Sygnal wykrywania: High volume of failed logins across multiple accounts from distributed sources

Session hijacking

Session tokens are captured or predicted, allowing attackers to impersonate authenticated users.

Sygnal wykrywania: Session tokens appearing in URLs, sessions used from unexpected locations

Brute force attacks

Automated attempts to guess passwords through systematic trial of many possibilities.

Sygnal wykrywania: High volume of failed login attempts against single or multiple accounts

Jak Zapobiegac

  • Implement multi-factor authentication where possible
  • Do not ship or deploy with default credentials
  • Implement weak password checks against common passwords
  • Align password policies with modern guidelines
  • Harden registration and credential recovery against enumeration
  • Limit or delay failed login attempts with proper logging
  • Use secure session management with high-entropy session IDs

CWE z Wykrywaniem Shoulder (9)

Te CWE maja reguly wykrywania Shoulder. Kliknij, aby zobaczyc konkretne podatnosci i poprawki.

Inne Zmapowane CWE (13)

Te CWE sa zmapowane do tej kategorii, ale nie maja jeszcze regul Shoulder.