Print this document
High Quality
Open the downloaded document, and select print from the file menu (PDF reader required).
Browser Printing
Coming soon!
User registration offered on insecure HTTP connection
User enumeration through verbose error messages
Application accepting weak passwords during registration
User enumeration through verbose error messages
Default and brute forcible passwords
Credential transport over insecure HTTP connection
User credentials passed within HTTP GET request
Fail open authentication
“Remember me” option offered on login page
Password cached within web browser
Authentication bypass
Account lockout policies
Weak CAPTCHA implementation
Issues concerning multi-factor authentication
Logout function does not exist
Logout does not invalidate session tokens on server
Idle timeout set for too long
Idle timeout does not invalidate session tokens on server
Password change mechanism not implemented
Password aging not implemented for critical applications
Current password not required for password change
Weak passwords accepted during password change
User enumeration through verbose error messages
User verification vulnerable to brute force
Weak password delivery mechanism
Weak passwords allowed during password reset
Password change not enforced after default password