AUTHENTICATION (AT5)

Javier can use default, test or easily guessable credentials to authenticate, or can use an old account or an account not necessary for the application

AUTHENTICATION
5

Javier can use default, test or easily guessable credentials to authenticate, or can use an old account or an account not necessary for the application

OWASP SCP

54,175,178

OWASP ASVS

4.1.5

OWASP AppSensor

AE12,HT3

CAPEC

-

SAFECODE

28

How to play?

No default (e.g. vendor), old, or test accounts should exist. Each user should have their own individual account, and accounts should only be issued and active for those people/systems that have been permitted access for the required need of their job/role. Put automatic time limits on temporary accounts. Review accounts periodically to check whether any need to be de-activated or deleted. Utilize strong passwords/phrases and/or implement multi-factor authentication, especially for accounts with more privileged access.

Mappings

OWASP ASVS (4.0): 4.1.5

Capec: 70

OWASP SCP: 54,175,178

OWASP Appsensor: AE12,HT3

Safecode: 28

ASVS (4.0) Cheatsheetseries Index

ASVS V4.1 - General Access Control Design

No suitable mappings were found.

Attacks

Password Guessing/Brute Force Attacks

Credential Stuffing

Social engineering attack

OWASP Cornucopia

  • OWASP Cornucopia is a mechanism in the form of a card game to assist software development teams identify security requirements in Agile, conventional and formal development processes. It is language, platform and technology-agnostic, and is free to use.
  • OWASP Cornucopia is licensed under the Creative Commons Attribution-ShareAlike 3.0 license, so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar licence to this one.
  • © 2012-2025 OWASP Foundation. The Open Worldwide Application Security Project (OWASP) is a nonprofit foundation that works to improve the security of software.