This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Testing for authentication
From OWASP
[Up]
OWASP Testing Guide v2 Table of Contents
Authentication Testing
...Intro here....
4.4.1 Default or guessable (dictionary) user account
4.4.2 Brute Force
4.4.3 Bypassing authentication schema
Directory traversal/file include
4.4.4 Vulnerable remember password and pwd reset
4.4.5 Logout and account expiry