In this chapter, we will cover the following recipes:
- Testing for account enumeration and guessable accounts
- Testing for weak lock-out mechanisms
- Testing for bypassing authentication schemes
- Testing for browser cache weaknesses
- Testing the account provisioning process via REST API