15–25 min Updated

Password Mismanagement

By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security

Safe treatment of passwords is essential to a secure authentication system - yet many websites get this wrong.

Prevalence
Common
Exploitability
Moderate
Impact
Devastating

What is password mismanagement?

Password mismanagement is an authentication vulnerability in which an application stores or handles passwords insecurely, for example keeping them in plain text, hashing them with a fast or unsalted algorithm, or permitting weak passwords. If the database is stolen, attackers can recover the passwords and reuse them in credential stuffing attacks against other sites.

What you'll learn

  • When to hand authentication to a third party using OAuth or SAML
  • How hashing, salt and pepper protect stored passwords
  • How to design password rules, resets and lockouts
  • When to add multi-factor authentication

Where this lesson counts

OWASP Top 10

PCI DSS 4.0

  • Password Mismanagement lab

    Work through the decisions behind a login system: whether to hand authentication to a third party using OAuth or SAML, how strict to make password rules, how to run resets and lockouts, how to store passwords with hashing, salt and pepper, and when to add multi-factor authentication.

  • How to prevent Password Mismanagement

    The prevention guide covers eight approaches:

    • Use Third-Party Authentication if Possible
    • Ensure Password Complexity
    • Allow Password Resets via Email
    • Confirm Old Password On Reset
    • Prevent Brute-Forcing
    • Store Passwords With A Strong Hash, Salted
    • Timeout Sessions After Inactivity, and Provide a Logout Function
    • Use HTTPS for Secure Communication
  • Password Mismanagement quiz

    Three questions. Passing marks the lesson complete.

  • User Enumeration

    Leaking username information on your site makes things much easier for hackers.

  • Weak Session IDs

    Guessable session IDs make your website vulnerable to session hijacking.

  • Session Fixation

    Insecure treatment of session IDs can leave your users vulnerable to having their session hijacked.

  • Privilege Escalation

    Privilege escalation occurs when an attacker exploits a vulnerability to impersonate another user or gain extra permissions.