Where to start
Ordered by actual difficulty. At the same level: isolated lab first, then the guided room, and the full machine last.- PortSwigger β 2FA bypass using a brute-force attack (Apprentice) Β· π¬π§
- PortSwigger β 2FA simple bypass (Apprentice) Β· π¬π§
- PortSwigger β Authentication bypass via information disclosure (Apprentice) Β· π¬π§
- PortSwigger β Authentication bypass via OAuth implicit flow (Apprentice) Β· π¬π§
- PortSwigger β Broken brute-force protection, multiple credentials per request (Apprentice) Β· π¬π§
- PortSwigger β Host header authentication bypass (Apprentice) Β· π¬π§
Curated resources
HTB machines practicing Authentication Vulnerabilities (4)
PortSwigger labs practicing Authentication Vulnerabilities (27)
TryHackMe rooms practicing Authentication Vulnerabilities (2)
β Back to the full glossary Last updated: 2026-08-17