Falhas de identificação e autenticação de software - Aula 12

What happens in your program when identification fails? (Lesson 12/15) 🔐🚪 Identifying a user, authenticating them, and managing their session seems simple, but it's where devastating attacks like Brute Force and Credential Stuffing (using leaked password lists from other websites) reside. In this lesson, "Uncle Pessoni" explains why session management cannot be done in the URL and why your system's error messages should never serve as an "oracle" for the attacker. We'll discuss why MFA (Multi-Factor Authentication) has gone from a luxury to a mandatory feature and how timeouts protect users on public computers. A warning to QAs: stop trying to automate Captchas and understand that certain protections exist precisely to stop bots! 🎓 What we'll learn today: Automated Attacks: How hackers use leaked email lists to break into accounts through trial and error. Weak Passwords: The danger of allowing admin123 or password1 and the importance of validating against common password lists. MFA (Multi-Factor Authentication): Why the second authentication factor (SMS, Email, Token) is the strongest defense today. Session Management: The risk of exposing the session ID in the URL and the importance of secure cookies. Oracle Attack: Why messages like "User not found" help the hacker map your database. Timeouts and Logouts: Ensuring that a forgotten session on a public computer doesn't become an open door. 📂 CONTINUE THE COURSE: This is Lesson 12 of 15. We're reaching the final episodes of the OWASP Top 10! If you missed the lesson on Vulnerable Components, check it out now. 👉    • Segurança de software - Curso gratis intro...   📑 Lesson Chapters: 00:00 - Introduction: What are Identification and Authentication Flaws? 01:45 - Brute Force Attacks and Credential Stuffing 03:30 - Default and Weak Passwords: How to Prohibit the Obvious 05:00 - The End of "Secret Questions": Why They Are Insecure 07:15 - The Importance of MFA (Multi-Factor Authentication) 09:30 - Session in URL vs. Secure Cookies: The Danger of an Exposed Session ID 12:00 - Why you should NOT automate CAPTCHAs in testing 🚀 Materials and Links: OWASP A07 Documentation: https://owasp.org/Top10/A07_2021-Iden... DISCORD:   / discord   TELEGRAM: https://t.me/pessonizando #automatedtesting #informationsecurity #softwaretesting