Skip to main content

Test common authentication attacks

Distinguish and test guessing, stuffing, spraying, phishing, MFA fatigue, recovery abuse, and session theft.

Learning outcomes

  • Distinguish attacks on secrets, ceremonies, recovery, sessions, and identity operations.
  • Select prevention and detection controls for each attack path.
  • Test containment from source event to last accepted action.
  • Avoid treating MFA as protection from every credential or session attack.

Assets and security objectives

Protect authenticators, verifier data, recovery, sessions, tokens, identity administration, and the actions available after sign-in. Prevent unauthorized authentication and limit use after compromise.

Actors and components

Actors include remote attackers with breach corpora, phishers, malicious insiders, malware, and compromised support staff. Components include identity provider, verifier, authenticator, browser, device, recovery, Pomerium session, protected application, telemetry, and containment controls.

Trust boundaries

Boundaries include user to browser, browser to issuer, authenticator to client, issuer to Pomerium, session to request, gateway to application, and support to recovery. Distinguish primary authentication from later session use.

Normal request path

A user reaches the intended issuer, completes the required authenticator ceremony, receives a bounded session, and sends a protected request. Policy authorizes the named resource and action. Evidence ties authentication, session, decision, and application result.

Failure path: credential attacks

Credential stuffing replays breached pairs. Spraying uses a few likely passwords across many accounts. Online guessing targets one account. Offline cracking attacks stolen verifier data. Controls include compromised-value checks, strong verifier storage, rate and abuse controls, phishing-resistant authentication, and detection across accounts and sources.

Failure path: ceremony and session attacks

Phishing sends the user to a false verifier. MFA fatigue induces approval. Recovery social engineering replaces a strong authenticator. Session theft reuses authority after authentication. Controls differ: origin-bound authenticators, clear transaction context, narrow recovery, device and session protection, reauthentication for high-impact actions, and fast revocation.

Design tradeoffs and residual risk

Aggressive lockouts stop guessing and enable denial of service. More prompts can train blind approval. Device binding limits replay and complicates recovery. Rich detection adds privacy and false positives.

Residual risk includes a compromised device using a valid session, malicious recovery staff, attacker-in-the-browser, and accepted application actions before containment.

Pomerium boundary

Pomerium relies on the configured identity provider for the authentication ceremony and can apply policy to the resulting session on covered routes. Operators own provider controls, session protection, recovery, detection, application actions, and direct paths. MFA at the issuer does not protect a stolen active session by itself.

Exercise

In a test tenant, simulate one low-rate spray, one known breached password, one false-origin sign-in, repeated push prompts, recovery of a protected account, and replay of a copied session. Verify each produces a distinct signal and containment path.

Evaluation checklist

  • Does each attack target a password, ceremony, recovery path, session, or identity operation?
  • Are rate controls evaluated across accounts and sources without unsafe lockout?
  • Do phishing-resistant methods verify the intended origin?
  • Can recovery and support not bypass the required assurance silently?
  • Is last accepted access measured after session and identity containment?

Next learning unit

Authentication

Verify that a claimant controls one or more authenticators bound to an account without confusing that result with authorization.

Sources and further reading

Keep learning

Identity and AuthenticationSecurity Operations and Risk

Revocation Latency

Measure how long a disabled identity, authenticator, session, claim, or permission can continue to authorize action.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo