Comprehensive Authentication Guide π Updated September 12, 2026 β added the NetScaler SAML canonicalization overflow (CVE-2026-8452) and why pre-signature-verification parsing is every SAML SPβs unauthenticated attack surface.
A practitionerβs reference for authentication security β protocols, mechanisms, vulnerabilities, exploitation techniques, and defense strategies. Covers traditional and modern authentication methods from enterprise to web applications.
Table of Contents Fundamentals Password-Based Authentication Multi-Factor Authentication (MFA) OAuth 2.0 & OpenID Connect SAML & Enterprise SSO Modern Authentication (FIDO, WebAuthn, Passkeys) JWT Security Session Management Authentication Bypasses & Attacks Implementation Security Testing & Verification 1. Fundamentals Core Concepts Term Definition Security Impact Authentication (AuthN) Process of verifying identity claims Foundation of access control Digital Identity Unique representation in online context Basis for authorization decisions Identity Proofing Binding digital identity to real person KYC/compliance requirement Session Management Maintaining state across requests Critical for web application security Non-Human Identity (NHI) API keys, OAuth tokens, service accounts Path of least resistance for attackers β not bound by MFA or IP restrictions Authentication Factors Factor Type Examples Vulnerability Classes Something You Know Passwords, PINs, security questions Brute force, credential stuffing, social engineering Something You Have Hardware tokens, mobile apps, SMS SIM swapping, device theft, malware Something You Are Biometrics (fingerprint, face, voice) Spoofing, template theft, privacy concerns 2. Password-Based Authentication Password Strength Requirements Requirement NIST SP800-63B Standard Security Rationale Minimum Length 8 chars (with MFA), 14+ (without MFA) Increases brute force difficulty Maximum Length At least 64 characters Prevents artificial length limits Character Composition No mandatory complexity rules Avoid predictable patterns Dictionary Checking Block common passwords Prevent credential stuffing Common Password Vulnerabilities ATTACK VECTORS: βββ Credential Stuffing β βββ Breach databases (HaveIBeenPwned) β βββ Password reuse across sites β βββ Automated login attempts βββ Brute Force Attacks β βββ Dictionary attacks β βββ Rule-based mutations β βββ Hybrid attacks βββ Password Reset Flows βββ Weak reset tokens βββ Token reuse vulnerabilities βββ Account enumeration βββ Email interception for ATO (Post SMTP CVE-2025-24000 β Subscriber+ reads reset emails via broken REST API permissions) Secure Implementation Patterns Security Control Implementation Bypass Techniques Rate Limiting Progressive delays, account lockouts IP rotation, distributed attacks CAPTCHA Human verification challenges OCR bypass, solving services Password Hashing bcrypt, scrypt, Argon2 Rainbow tables (if salts weak) Breach Detection Monitor for credential exposure Private/corporate breaches REST API Auth Role-based permission callbacks (not just is_user_logged_in()) Subscriber-level access to admin endpoints 3. Multi-Factor Authentication (MFA) MFA Implementation Types Method Security Level User Experience Attack Vectors SMS OTP Low High friction SIM swapping, SS7 attacks TOTP Apps Medium Medium friction Device compromise, social engineering Push Notifications Medium-High Low friction MFA fatigue, device takeover Hardware Tokens High Medium friction Physical theft, supply chain Biometrics High Low friction Spoofing, template extraction Passwordless (FastPass/FIDO2) Very High Low friction Device compromise (Okta Terrify), endpoint proxy MFA Bypass Techniques BYPASS METHODS: βββ Social Engineering β βββ MFA fatigue (push spam) β βββ Vishing (voice phishing) β βββ SIM swapping βββ Technical Bypasses β βββ Session fixation β βββ MFA enrollment abuse β βββ Backup code exploitation β βββ Race conditions βββ Adversary-in-the-Middle (AiTM) β βββ Real-time phishing (Evilginx, Tycoon 2FA, Evilproxy, Mamba 2FA) β βββ Session cookie interception and replay β βββ Token replay β βββ Cloudflare Workers as transparent proxy (IOActive research) βββ Authentication Downgrade Attacks β βββ JSON config manipulation β flip FIDO2 isDefault:false, push isDefault:true β βββ CSS injection to hide passkey/FIDO2 UI options β βββ Browser User-Agent spoofing (e.g., Safari on Windows) to trigger Entra ID fallback β βββ WebAuthn immediate mediation abuse for non-WebAuthn fallback steering βββ Conditional Access Policy (CAP) Bypasses β βββ IP whitelisting bypass (VPN, Zscaler pivoting) β βββ Geo-whitelisting bypass (VPN/location spoofing) β βββ User-agent whitelisting bypass (custom UA strings) β βββ Cloud tooling bypasses (ROADtools, BloodHound, AADInternals) β βββ Non-MFA hosts (legacy protocols, password reset portals) βββ Machine-Based Attacks βββ Session token theft from memory (Cobalt Strike BOFs) βββ OTP keylogging / seed QR code theft βββ Okta Terrify β extract passwordless keys from compromised endpoint βββ Stolen/unlocked devices Phishing-as-a-Service (PhaaS) Kits Kit Technique Detection Evasion Evilginx Open-source reverse proxy AiTM Default LetsEncrypt certs, 8-char URL paths, TLS fingerprint differs from target Tycoon 2FA PhaaS MFA bypass Dynamically obfuscated JS, phishing URL gating, IP/UA filtering Evilproxy PhaaS MFA bypass Templates for popular targets, bot detection Mamba 2FA PhaaS MFA bypass Anti-crawler delays, redirect to benign pages Cloudflare Workers Serverless transparent proxy (IOActive PoC) Zero forensic footprint, trusted CDN IPs, ephemeral execution Implementation Security Checklist Control Verification Common Mistakes Enrollment Security Verify primary auth before MFA setup Allow MFA changes without re-auth Backup Mechanisms Secure recovery codes Weak backup code generation Device Trust Risk-based authentication Unlimited device trust Rate Limiting Throttle MFA attempts No limits on failed attempts Eliminate Fallbacks No SMS/TOTP/push if FIDO2 deployed Mixed-mode policies allow downgrade Audit MFA Logs Detect new MFA device registration post-compromise Missing persistence detection 4. OAuth 2.0 & OpenID Connect OAuth 2.0 Flow Types Grant Type Use Case Security Considerations Authorization Code Server-side web apps Most secure, requires PKCE for SPAs Authorization Code + PKCE Public clients, SPAs Prevents authorization code injection Implicit Legacy SPAs Deprecated, token in URL fragment Client Credentials Service-to-service No user context, secure storage critical Device Code IoT/limited input devices Phishing risk during user approval Common OAuth Vulnerabilities Vulnerability Attack Vector Mitigation Authorization Code Interception Redirect URI manipulation Strict redirect validation State Parameter Missing CSRF attacks Cryptographically strong state Scope Escalation Privilege elevation Minimal scope principle Client Impersonation Stolen client credentials Client authentication OAuth Parameter Injection Inject arbitrary params (redirect_uri, scope) into auth flow Input sanitization (Okta auth0/nextjs-auth0 vuln) Implicit Flow Token Theft Access token in URL fragment, referer leakage Migrate to Authorization Code + PKCE CSRF via Missing State Attacker injects own authorization code into victim session State parameter enforcement Redirect URI Bypass Pattern-matching bypass (%2f%2f, %5c%5c, %3F, %23, port injection) Exact string match, no wildcards Credential Leakage via Referer Authorization code or token in Referer header to third-party content No third-party resources on callback pages Non-Human Identity Abuse Compromised OAuth tokens with overly broad scopes, null expiry refresh tokens Scope minimization, token rotation, vendor vetting Dynamic Client Registration SSRF (PortSwigger Research) SSRF ATTACK SURFACE VIA DYNAMIC REGISTRATION: βββ logo_uri β Server fetches logo image β SSRF on /authorize βββ jwks_uri β Server fetches JWK set for client_assertion validation β Blind SSRF βββ sector_identifier_uri β Server fetches redirect_uri list β SSRF on registration or authorization βββ request_uris β Whitelisted request_uri values β SSRF on /authorize via request_uri param β (Even without dynamic registration, test request_uri on /authorize directly) βββ Discovery: GET /.well-known/openid-configuration βββ registration_endpoint βββ request_uri_parameter_supported βββ require_request_uri_registration CVE-2021-26715: SSRF via logo_uri in MITREid Connect ForgeRock OpenAM: SSRF via request_uri + redirect_uri Session Poisoning OAuth Security Implementation SECURITY CONTROLS: βββ Authorization Server β βββ Strict redirect URI validation (exact match, no wildcards) β βββ State parameter enforcement β βββ PKCE for public clients β βββ Short-lived authorization codes (single use) β βββ Disable Dynamic Client Registration if not needed βββ Resource Server β βββ Token introspection β βββ Scope validation β βββ Audience verification β βββ Rate limiting βββ Client Application β βββ Secure token storage (never in browser history/URL) β βββ Token refresh handling with expiry β βββ CSRF protection via state parameter β βββ PKCE code_verifier/code_challenge β βββ TLS everywhere βββ Non-Human Identity Governance βββ Monitor OAuth app registrations and consent grants βββ Audit token scopes vs actual usage βββ Enforce refresh token expiry (no null expiry) βββ Vendor breach monitoring for third-party OAuth apps OAuth Pentesting Checklist (Authorization Code Grant) Test Case What to Check Impact Redirect URI Validation Change redirect_uri to attacker domain, test pattern bypasses Token/code theft State Parameter Remove or reuse state, test CSRF Account hijacking Code Reuse Replay authorization code Session hijacking Client Secret Exposure Check JS source, mobile app binaries Full OAuth flow compromise Scope Manipulation Request elevated scopes Privilege escalation Token in URL/History Check if access_token appears in URL fragment or browser history Token theft Referer Leakage Check callback pages for third-party resource loads Code/token leakage request_uri SSRF Supply attacker URL in request_uri param on /authorize Server-side request forgery 5. SAML & Enterprise SSO SAML Attack Surface Component Attack Vectors Security Controls Identity Provider (IdP) XML signature bypass, SAML injection Strong XML validation, signature verification Service Provider (SP) Assertion replay, audience restriction bypass, parser differential exploitation Strict temporal/audience checks, single XML parser SAML Assertions XXE, signature wrapping (XSW), attribute pollution Secure XML parsing, validation Metadata Metadata spoofing, certificate substitution Out-of-band verification FortiCloud SSO Crafted SAMLResponse to /remote/saml/login (CVE-2025-59718) Disable FortiCloud SSO until patched Citrix NetScaler SAML canonicalization overflow (CVE-2026-8452) Citrix published CTX696604 on 30 June 2026. CVSS 8.8, unauthenticated, and it belongs in a SAML guide rather than a memory-safety one because of where in the SAML flow it sits.
...