Authentication & Authorization (AAJ)

Authentication & Authorization
J

Prasad can bypass the centralized authentication and authorization controls since they are not being used comprehensively on all interactions

How to play?

Scenario: Prasad can bypass the centralized authentication and authorization controls because they are not applied comprehensively to all interactions

Example

Prasad visits a charity book sale at his favorite local bookshop. For this, the shop uses an app where the tablet asks the cashier for a PIN at login but asks nothing of the visiting customer, then leaves the button for the cashier's sales dashboard exposed on every later screen. He taps through the catalog, finds and opens the cashier's sales dashboard, and discovers that the “honor system” comes with a surprisingly generous refund menu, thereby making the charity book sale more charitable than intended.

Threat Modeling

STRIDE

This scenario is primarily Elevation of Privilege in STRIDE because Prasad can bypass the centralized authentication and authorization controls because they are not applied comprehensively to all interactions. He is not entering the cashier's PIN (Spoofing); he is granting himself unauthorized access (Elevation of Privilege).

What can go wrong?

Authentication and authorization controls may be centralized in appearance but missing from individual interactions. An app in which these controls are missing from individual interactions may let a caller reach protected operations after passing a superficial check. If Prasad can bypass the centralized authentication and authorization controls because they are not being used comprehensively on all interactions, the app could let an attacker bypass the authentication and authorization boundaries and reach data or capabilities that this flow should protect. Attack vectors include:

  • Debugging the app at runtime.
  • Using dynamic instrumentation.
  • Misusing logical flaws.

What are we going to do about it?

Enforce authentication and authorization at every entry point, not just the main screen: test the release build while debugging and instrumenting it, protect IPC with narrow permissions, and have the server re-check the identity and each sensitive action.

See the mapped MASTG tests for how to verify that the app is safe. Follow the mapped MASTG best practices during coding, and prepare yourself by reading through the mapped MASTG knowledge.

Mappings

STRIDE: Elevation of Privilege

MASTG: 0266,0267,0268,0269,0270,0271,0327,0330,0364,0365,0366

MASTG Best: 0036,0052

MASTG Know: 0056,0057,0001,0043,0047,0012,0132,0017,0020,0133,0134

MASWE: 0020,0021,0022,0018

CAPEC™: 36,121

SAFECode™: 8,10,11

MASVS: MASVS-AUTH-2,MASVS-CRYPTO-2,MASVS-AUTH-1,MASVS-PLATFORM-1,MASVS-STORAGE-2

No attacks registered!

OWASP Cornucopia

OWASP Cornucopia is a mechanism in the form of a card game to assist software development teams identify security requirements in Agile, conventional and formal development processes. It is language, platform and technology-agnostic, and is free to use. OWASP Cornucopia is licensed under the Creative Commons Attribution-ShareAlike 4.0 license, so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar licence to this one.

© 2012-2025 OWASP Foundation. The Open Worldwide Application Security Project (OWASP) is a nonprofit foundation that works to improve the security of software.