← All concepts
Authentication bypass

Understanding Authentication bypass

What it is

Authentication proves who is making a request. A bypass is any path that reaches an authenticated state without presenting the secret that state is meant to require — a default credential, a flawed comparison, a token that is trusted when it should not be, a step in a flow that can be skipped.

How you approach it

  1. Look at exactly what the login flow checks, and in what order. Is there a state it can be nudged into that skips the check?
  2. Compare the requests for a failed login and a successful one. What single field decides which you get?
  3. The gate trusts a value it should have verified. Supply the value it wants, not the credential it asks for.

How it gets fixed

The server decided you were signed in from a value the client controlled rather than one only a real login could produce. Setting that value directly walked past the credential check entirely. The fix is to derive the authenticated state from a server-side session, never from a request the client can forge.

Practise it

Every lab in the Authentication bypass category drills exactly this. Start at Apprentice and work up.

Practise it

ApprenticeAuthentication bypass

The default credential nobody changed

Get past the login without the credential it is supposed to demand.

10 pts · 20 minStart →
ApprenticeAuthentication bypass

A login that leaks which half was wrong

Get past the login without the credential it is supposed to demand.

10 pts · 20 minStart →
PractitionerAuthentication bypass

Skipping the second step of a two-step login

Get past the login without the credential it is supposed to demand.

25 pts · 45 minStart →
PractitionerAuthentication bypass

The remember-me cookie that means too much

Get past the login without the credential it is supposed to demand.

25 pts · 45 minStart →
ExpertAuthentication bypass

An OAuth state parameter nobody validates

Get past the login without the credential it is supposed to demand.

50 pts · 90 minStart →
ExpertAuthentication bypass

A password reset that trusts the wrong field

Get past the login without the credential it is supposed to demand.

50 pts · 90 minStart →