Broken Authentication

Broken authentication refers to any application flaw that allows unintended access to the application. Examples include default and weak passwords that are easy to guess or could be victims of automated or manual brute-force and dictionary attacks. Session attacks, such as session hijacking are also included because a successful attack provides a hacker with access to the application as the owner of the stolen session.

