Falhas de identificação e autenticação de software - Aula 12
What happens in your program when identification fails? (Lesson 12/15) 🔐🚪 Identifying a user, authenticating them, and managing their session seems simple, but it's where devastating attacks like Brute Force and Credential Stuffing (using leaked password lists from other websites) reside. In this lesson, "Uncle Pessoni" explains why session management cannot be done in the URL and why your system's error messages should never serve as an "oracle" for the attacker. We'll discuss why MFA (Multi-Factor Authentication) has gone from a luxury to a mandatory feature and how timeouts protect users on public computers. A warning to QAs: stop trying to automate Captchas and understand that certain protections exist precisely to stop bots! 🎓 What we'll learn today: Automated Attacks: How hackers use leaked email lists to break into accounts through trial and error. Weak Passwords: The danger of allowing admin123 or password1 and the importance of validating against common password lists. MFA (Multi-Factor Authentication): Why the second authentication factor (SMS, Email, Token) is the strongest defense today. Session Management: The risk of exposing the session ID in the URL and the importance of secure cookies. Oracle Attack: Why messages like "User not found" help the hacker map your database. Timeouts and Logouts: Ensuring that a forgotten session on a public computer doesn't become an open door. 📂 CONTINUE THE COURSE: This is Lesson 12 of 15. We're reaching the final episodes of the OWASP Top 10! If you missed the lesson on Vulnerable Components, check it out now. 👉 • Segurança de software - Curso gratis intro... 📑 Lesson Chapters: 00:00 - Introduction: What are Identification and Authentication Flaws? 01:45 - Brute Force Attacks and Credential Stuffing 03:30 - Default and Weak Passwords: How to Prohibit the Obvious 05:00 - The End of "Secret Questions": Why They Are Insecure 07:15 - The Importance of MFA (Multi-Factor Authentication) 09:30 - Session in URL vs. Secure Cookies: The Danger of an Exposed Session ID 12:00 - Why you should NOT automate CAPTCHAs in testing 🚀 Materials and Links: OWASP A07 Documentation: https://owasp.org/Top10/A07_2021-Iden... DISCORD: / discord TELEGRAM: https://t.me/pessonizando #automatedtesting #informationsecurity #softwaretesting

Software and data integrity failures - Lesson 13

How to Design APIs Like a Senior Engineer (REST, GraphQL, Auth, Security)

Outdated and vulnerable software components - Lesson 11

Neuroscientist reveals: you DON'T START because you skip this step

AI as a Tester: How to Use It Without Becoming Dependent on the Tool

OWASP's Top 10 Ways to Attack LLMs: AI Vulnerabilities Exposed

AI and the Battle for the Soul with Iain McGilchrist - Lecture 1: Information is Not Understanding

Android 17 sucks. So I put Linux on a phone.

Algorithms 1 - What comes before programming?

Aula 12 - Igreja

The Invisible Phone: Ditch PSTN Forever – No IMEI, No IMSI, No KYC, Total Stealth Calling

System Design Explained: APIs, Databases, Caching, CDNs, Load Balancing & Production Infra

Keynote: Benchmarking - It's About Time - Matt Godbolt - C++Now 2026

Algoritmos 2 - Fundamentos da programação

The Most Important Conversation in AI Right Now

Turing Award Winner: Disagreeing with Google, Postgres, Future Problems | Mike Stonebraker

What is software security - Lesson 1

Why Siemens is changing forever right now…

AJ Styles On Retirement, Gunther, Hall Of Fame, John Cena, One More Match?

