Authentication Methods and Their Attacks.
Various authentication methods, the attacks that work against each one, and the mitigations that hold. Written for the moment you have to pick a method and then defend it.
Web App
Web App Security
Pages:
50
Format:
PDF
Level:
Intermediate
Updated:
Oct 2026

Key Takeaways
- Each method explained by how it actually works first: basic and form-based, multi-factor, token-based, OAuth, single sign-on with SAML, NTLM and LDAP.
- The attacks per method rather than a generic list: brute force, MFA bypass techniques, token theft, OAuth abuse, SAML and XML injection, NTLM attacks and LDAP injection.
- Mitigation points after every section, written for developers to implement rather than for auditors to tick.
- Where each method belongs, so the choice gets made on attack surface rather than on familiarity.
What's inside
Most authentication failures are not cryptographic. They are a token that never expires, a redirect URI that was never validated, a SAML assertion parsed before it was verified. Which attack applies depends entirely on which method you picked.
This ebook takes the methods one at a time. Each gets its working mechanism, the attacks that apply specifically to it, and the mitigation points that close them. It is written for developers, security professionals and the teams who have to make the choice and then live with it.
What the 50 pages cover
01
Introduction and what authentication has to do
p. 4
The scope of the ebook and how each method is assessed.
02
Basic and form-based authentication
p. 6
How each works, the attacks against them, and the mitigation points.
03
Multi-factor authentication and bypass techniques
p. 13
How MFA works, and the bypasses that keep succeeding against it.
04
Token-based authentication, OAuth and single sign-on
p.23
Token handling, the OAuth flow, SSO, and SAML assertion handling.
05
NTLM
p. 31
How it works, how it is attacked, and what to do where it cannot be removed.
06
Lightweight Directory Access Protocol
p. 38
How LDAP works, LDAP injection, and the mitigation points.
Look inside
A sample spread — the level of detail in every chapter.

Written by Payatu's application security team

Keep the mitigation points next to the code
The full 50-page PDF, with every method, its attacks and its mitigations laid out so a developer can act on the section that applies.











