Authentication 12
- Password brute-force via password change
- Password reset poisoning via middleware
- Offline password cracking
- Brute-forcing a stay-logged-in cookie
- 2FA broken logic
- Username enumeration via account lock
- Broken brute-force protection, IP block
- Username enumeration via response timing
- Username enumeration via subtly different responses
- Password reset broken logic
- 2FA simple bypass
- Username enumeration via different responses