Case Study - Credential & Identity Testing (Identity Is the Perimeter)

One leaked GitHub token = SSO admin. Password never needed.

ILLUSTRATION — IDENTITY LAYERS TESTED
🔑
Auth
MFA, OTP, lockout
🪪
Session
Fixation, hijack
🕵️
Exposed creds
Git, APK, JS
🏰
Priv-esc
Role → admin

Client Context

State-owned enterprise — SSO (SAML/OIDC) across 60 apps, HRIS + e-procurement + vendor portal. 18k users. Prior credential-stuffing wave.

Challenge

Test authentication, authorization, session management, exposed credentials, and identity weaknesses end-to-end — including human factors (password reuse, token leak) — before UU PDP audit.

Scope - Snipeyes Credential & Identity Testing

  • Auth flows: password policy, lockout, MFA bypass, OTP brute-force/ replay, magic-link, OAuth consent abuse
  • Session: fixation, timeout, concurrent, token storage (localStorage vs httpOnly), logout completeness
  • Exposed credential sweep: Git history, mobile APK, JS bundles, Postman collections, S3, Jira tickets
  • Authorization matrix: role × object × action (horizontal + vertical)

Key Findings (redacted)

  • CRITICAL: Long-lived GitHub PAT in public fork .env.example → CI could assume SSO admin role (no scope restriction)
  • HIGH: OTP 123456 retry unlimited (no rate-limit) → 6-digit takeover in ~4h window proven in staging
  • HIGH: role=user → role=admin via unsigned JWT claim swap on legacy procurement API
  • 1,100+ employee creds in breach corpora with SSO password reuse (forced reset scoped)

Outcome

  • Token revoked + CI scoped to least-privilege, OTP throttled + 5-min expiry, JWT allow-list — retest takeover fully blocked
  • Secrets scanning in pre-commit + quarterly exposed-cred sweep adopted
  • UU PDP + ISO 27001 A.5.17 evidence delivered, auditor accepted

Relevance for you: If SSO is your perimeter — test the tokens, sessions, and leaks, not just the login box.