Authentication & Identity¶
Authentication answers "who are you?" Identity protocols answer "how do I prove it to a third party?" The attacks in this section exploit weaknesses in how that proof is established, transmitted, stored, or verified.
Topics in this section¶
| Doc | Focus |
|---|---|
| Authentication & Session | Credential stuffing, spraying, MFA bypass, reset poisoning, fixation |
| JWT Token Security | Algorithm confusion (RS256→HS256), none alg, key confusion |
| OAuth 2.0 & OIDC | State parameter CSRF, redirect_uri abuse, implicit flow leakage |
| OIDC Deep Dive | ID token validation, nonce binding, hybrid flow |
| SAML | XML signature wrapping, XXE via assertion, replay |
| SSO | Cross-domain trust abuse, federation misconfig |
| WebAuthn & Passkeys | Ceremony flow, origin binding, attestation |
| MFA & Step-Up Auth | OTP bypass, SIM swap, push fatigue |
| Password Authentication | KDF selection, timing attacks, reset flows |
| Session Management | Fixation, hijacking, cookie attributes |
| Token Exchange | RFC 8693, scope reduction, impersonation |
| mTLS | Certificate binding, header spoofing in proxied flows |
| SPIFFE & SPIRE | Workload identity, SVID issuance, attestation |
| OpenID Federation | Trust chain, metadata endpoints, key rollover |
The core invariant¶
Proof of identity must be bound to a specific session, audience, and time window. Any token or credential that travels without audience binding, expiry, or channel binding can be replayed by a different principal against a different resource.