Wstg: ATHN-02 Testing for Default Credentials

Created on 12 Sep 2020  路  7Comments  路  Source: OWASP/wstg

What's the issue?
Overwritten test scenario, can be summarized and link to payload lists from other repos

How do we solve it?
Chop down the content to the required and needed information, link to payload lists instead of enumerating all possible usernames and passwords, provide further guidance on how to test.

If no one is up to handle it, I can take care of it

good first issue help wanted revise

All 7 comments

I will take a pass at revising the writing for brevity and clarity.

Lovely! Thanks for taking this on!

Following on #650 's discussion, and after reviewing the IDNT and ATHN scenarios, this should be merged into ATHN-04.
It can be a section in enumerating users or credentials, tackling default accounts that were not removed.

Does this feel doable @efx ?

@ThunderSon 馃憢 would this be taking the content of ATHN-02 as of (bd0106c5fca40f0d32cc7c7430e22a65006a1af2) and adding it to the appropriate part of ATHN-04?

Feel free to change the content however you see fit to be part of that scenario.

@ThunderSon thanks for the update. Due to other commitments and my lack of understanding I will not be finishing this. Can you remove me from being the assignee when you are free? Many thanks!

No problem, thanks for your help.

Was this page helpful?
0 / 5 - 0 ratings

Related issues

kingthorin picture kingthorin  路  4Comments

Abhi-M picture Abhi-M  路  8Comments

ThunderSon picture ThunderSon  路  5Comments

Hsiang-Chih picture Hsiang-Chih  路  8Comments

victoriadrake picture victoriadrake  路  7Comments