Skip to content

Commit

Permalink
Update owasp-whhb.md
Browse files Browse the repository at this point in the history
  • Loading branch information
xapax authored Jan 17, 2019
1 parent 4def2f7 commit e0a921f
Showing 1 changed file with 4 additions and 0 deletions.
4 changes: 4 additions & 0 deletions owasp-whhb.md
Original file line number Diff line number Diff line change
Expand Up @@ -191,6 +191,9 @@ https://blog.netspi.com/attacking-sso-common-saml-vulnerabilities-ways-find/
* [ ] Test for Insecure Storage
* [ ] Testing for Weak security question/answer (OTG-AUTHN-008)

## Test two factor authentication (2fa)
* [ ] Check 2fa

## Password reset mechanism
* [ ] Testing for weak password change or reset functionalities (OTG-AUTHN-009)
* [ ] Check if password reset token can be used several times
Expand All @@ -200,6 +203,7 @@ https://blog.netspi.com/attacking-sso-common-saml-vulnerabilities-ways-find/
* [ ] Check that password reset token is of high entropy
* [ ] Check that password reset token is unique, random
* [ ] Check that lifespan of the password reset token (Max 24 hours)
* [ ] Check that there is not link to external page where token is sent in referer header

## Other Tests
* [ ] Test Any Remember Me/Password Function
Expand Down

0 comments on commit e0a921f

Please sign in to comment.