Add NTLM authentication to MSTG-CRYPTO-3 #2096
AndreMCCarvalho
started this conversation in
Ideas
Replies: 1 comment
-
Hi @AndreMCCarvalho, that could be a good fit for testing authentication. We could include tests for "Testing for insecure algorithms". But we really have to discuss this since testing authentication is more on the side of the OWASP ASVS. Thanks for the feedback, we'll consider it for the upcoming refactoring of the MASVS-AUTH category. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Hey guys,
I was reading your documentation and noticed that Microsoft NTLM authentication is not present in your MSTG-CRYPTO-3. NTLM is known to be an outdated authentication protocol that uses insecure encryption algorithms. I feel like it could belong into the MSTG-CRYPTO-3 category.
Best regards,
Andre
Beta Was this translation helpful? Give feedback.
All reactions