> For the complete documentation index, see [llms.txt](https://appsecexplained.gitbook.io/appsecexplained/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://appsecexplained.gitbook.io/appsecexplained/common-vulns/authentication.md).

# Authentication

## What is it?

Authentication is the process by which a system confirms the identity of a user or application. It's essentially all about **who you are**.&#x20;

Targeting authentication mechanisms allow us to to impersonate users, admins, or systems and gain unauthorized access. Often, we look to attack logic issues and lack of brute-force protection.&#x20;

Common targets in authentication attacks include:

* Passwords or passphrases
* Multi-Factor Authentication (MFA)
* Session tokens
* Cookies
* Recovery questions and answers

For more details on specific authentication attack techniques, see the relevant child pages.
