Access & Authentication badge

5 exercisesEarned by 0Certificate of completion

Who are you, and what are you allowed to do? Broken access control, password storage, sessions, CSRF and JSON Web Tokens — the whole identity story, attack and defence.

#ExerciseTypeAvg. timeDifficultyTier
1 Broken Access Control
The bug you find by changing a number in the URL. Learn IDOR, why it is the most common serious web flaw, and the server-side check that stops it.
Course 30 min Medium 🔒 Pro
2 How Passwords Are Stored and Cracked
Why sites store hashes not passwords, how attackers crack a leaked hash, and why a pinch of salt and a slow algorithm change everything.
Course 30 min Medium 🔒 Pro
3 Session Management
A login is only as strong as the session it creates. Learn how session cookies work, the three ways they go wrong, and the flags and habits that keep them safe.
Course 25 min Medium 🔒 Pro
4 Cross-Site Request Forgery (CSRF)
Your browser attaches your session cookie to every request to a site — even requests a different site told it to make. Learn how that is abused and the token that stops it.
Course 25 min Medium 🔒 Pro
5 JSON Web Tokens (JWT)
A JWT lets a server trust a token instead of looking up a session — but only if it verifies the signature properly. Learn the structure, the classic mistakes, and how to use them safely.
Course 30 min Hard 🔒 Pro