Investigation of the Broken Authentication Vulnerability in Web Applications

Yuriy Lakh, Elena Nyemkova, Andrian Piskozub, Viktor Yanishevskyi · 2021 11th IEEE International Conference on Intelligent Data Acquisition and Advanced Computing Systems: Technology and Applications (IDAACS) · 2021

In this work the vulnerabilities, authentication problems, different typologies of authentication, working with input data / user details have been investigated. The server using digest and basic authentication has been configured. Authentication flaws as well as broken authentication problems have been investigated. In addition, brute force attacks have been modeled for a resource using HTTP Basic Authentication - which has been configured in the RESTful web server, along with digest authentication. Finally, vulnerabilities of authentication were searched for in public resources. As an example there has been selected the web service www.reddit.com with the ability to perform automated requests from legal users - “legal bots”, a potential door to brute-force attacks with advanced functionality. For implementation the Bot class has been written containing functionalities - intended for standard actions of clients consisting in use of a separate RESTful resource. In conclusion, the implementation of this functionality has been demonstrated.

Read the paper · More papers on PaperTik