Terminology Index

Glossary

1801 terms

Open concept maps

Showing 129-160 of 1801 terms

A
32

Authentication Testing

Systematically evaluating an application's login and identity mechanisms during a security assessment to find weaknesses, such as weak session handling, missing MFA enforcement, or flaws in password and reset flows.

In an authorized assessment, a tester examines whether authentication can be bypassed, brute-forced, or weakened, checking session management, lockout, MFA, and credential handling against established guidance like the OWASP Testing Guide. The goal is to confirm the controls hold before an attacker tests them.

Introduced in: Web Application Penetration Testing

Examples

  • Verifying that sessions properly invalidate on logout.
  • Checking whether MFA is enforced consistently across entry points.
  • Confirming account lockout and reset flows resist abuse.

No related terms linked yet.