Discovering authentication weaknesses

After services, ports, and technology detection, the next step is to navigate and understand the application's flow. Here, we will focus on the authentication section.

  1. So, open Burp Suite, and after configuring the web browser, go to https://www.mercadolibre.com.mx/.
  2. As we mentioned before, Mercado Libre is a big online retailer, which is an intermediate party between sellers and buyers offering package services and financial services.
  3. Enter valid credentials in the login section in order to understand how works.
  4. A resume about the authentication flow is given here:
    • The user enters an email address or username and a password
    • The user is logged in
    • If the user closes the session, the next time they enter ...

Get Hands-On Application Penetration Testing with Burp Suite now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.