A2:2017-Broken Authentication

Login enumeration

→ Invalid email ≠ invalid password (define if email exist or not)

→ look at forgot password

<aside> 📗 Look for session fixation and test token reuse etc

</aside>

Definition