Where to start
Ordered by actual difficulty. At the same level: isolated lab first, then the guided room, and the full machine last.- PortSwigger — 2FA bypass using a brute-force attack (Apprentice) · 🇬🇧
- PortSwigger — 2FA simple bypass (Apprentice) · 🇬🇧
- PortSwigger — Authentication bypass via information disclosure (Apprentice) · 🇬🇧
- PortSwigger — Authentication bypass via OAuth implicit flow (Apprentice) · 🇬🇧
- PortSwigger — Broken brute-force protection, multiple credentials per request (Apprentice) · 🇬🇧
- PortSwigger — Host header authentication bypass (Apprentice) · 🇬🇧
Curated resources
HTB machines practicing Authentication Vulnerabilities (4)
PortSwigger labs practicing Authentication Vulnerabilities (27)
TryHackMe rooms practicing Authentication Vulnerabilities (2)
← Back to the full glossary Last updated: 2026-08-17