Skip to content

Commit 373ae60

Browse files
committed
docs: Add Attack Scenario #1
1 parent 0de89c7 commit 373ae60

File tree

1 file changed

+6
-0
lines changed

1 file changed

+6
-0
lines changed

2019/en/0xa2-broken-authentitcation.md

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -12,6 +12,12 @@ A2:2019 Broken Authentication
1212

1313
## Scenario #1
1414

15+
An attacker using brute-force to find hidden directories, finds a specific
16+
endpoint called `/backoffice` with hardcoded credentials. When accessing this
17+
specific endpoint it would automatically call the API admin which provides the
18+
attacker with all the endpoints, logged in user tokens, load balancer
19+
configurations and much more.
20+
1521
## Scenario #2
1622

1723
An attacker with access to a cloud-based team collaboration tool creates a

0 commit comments

Comments
 (0)