BreakMesh – Vulnerability Simulator & Cyber Range

Scanner package

Auth & Session scanner

A focused review of everything around authentication and session handling — where account-takeover and access-control bugs usually live.

What it checks

Auth & Session reviews login surface controls, session cookie scope and flags, password reset flow behavior, account enumeration indicators, weak password policy signals, MFA configuration, and OAuth 2.0 / OIDC security checks.

With a disposable test account, it also runs an authenticated deep crawl, and — with a second disposable account — a two-account BOLA/IDOR and BFLA comparison that replays one account's resource URLs and API calls using the other to catch broken object- and function-level authorization.

Consent-gated, never on real accounts

Credentialed checks only run with explicit consent and disposable test accounts you provide — BreakMesh never touches real customer accounts or production credentials.

The password-spray indicator check is capped at 10 total login attempts against generic probe usernames (never real or customer-supplied ones), specifically to test lockout protection without risking account disruption.

All 16 checks in this package

Included from the Team plan and up.

  • Login Surface Controls
  • Session Cookie Scope
  • Login Rate-Limit Simulation
  • Password Reset Flow Checks
  • Account Enumeration Indicators
  • Credentialed Test-Account Checks
  • Weak Password Policy Review
  • MFA Configuration Indicators
  • Authenticated Deep Crawl
  • OAuth 2.0 / OIDC Security Checks
  • BOLA / IDOR Two-Account Comparison
  • BFLA Privilege Escalation Probe
  • CSRF Protection Enforcement
  • Session Fixation Check
  • Password Spray Indicator
  • Default Credentials Check