In this chapter, we will cover:
- Username enumeration
- Dictionary attack on login pages with Burp Suite
- Brute forcing basic authentication with Hydra
- Attacking Tomcat's passwords with Metasploit
- Manually identifying vulnerabilities in cookies
- Attacking a session fixation vulnerability
- Evaluating a session identifier's quality with Burp Sequencer
- Abusing insecure direct object references
- Performing a Cross-Site Request Forgery attack