Case Study - Credential & Identity Testing (Identity Is the Perimeter)
One leaked GitHub token = SSO admin. Password never needed.
Auth
MFA, OTP, lockout
Session
Fixation, hijack
Exposed creds
Git, APK, JS
Priv-esc
Role → admin
Client Context
State-owned enterprise — SSO (SAML/OIDC) across 60 apps, HRIS + e-procurement + vendor portal. 18k users. Prior credential-stuffing wave.
Challenge
Test authentication, authorization, session management, exposed credentials, and identity weaknesses end-to-end — including human factors (password reuse, token leak) — before UU PDP audit.
Scope - Snipeyes Credential & Identity Testing
- Auth flows: password policy, lockout, MFA bypass, OTP brute-force/ replay, magic-link, OAuth consent abuse
- Session: fixation, timeout, concurrent, token storage (localStorage vs httpOnly), logout completeness
- Exposed credential sweep: Git history, mobile APK, JS bundles, Postman collections, S3, Jira tickets
- Authorization matrix: role × object × action (horizontal + vertical)
Key Findings (redacted)
- CRITICAL: Long-lived GitHub PAT in public fork
.env.example→ CI could assume SSO admin role (no scope restriction) - HIGH: OTP
123456retry unlimited (no rate-limit) → 6-digit takeover in ~4h window proven in staging - HIGH:
role=user→role=adminvia unsigned JWT claim swap on legacy procurement API - 1,100+ employee creds in breach corpora with SSO password reuse (forced reset scoped)
Outcome
- Token revoked + CI scoped to least-privilege, OTP throttled + 5-min expiry, JWT allow-list — retest takeover fully blocked
- Secrets scanning in pre-commit + quarterly exposed-cred sweep adopted
- UU PDP + ISO 27001 A.5.17 evidence delivered, auditor accepted
Relevance for you: If SSO is your perimeter — test the tokens, sessions, and leaks, not just the login box.