wstg-athn-07 - Testing for Weak Password Policy
Tests password creation and change policies for length, complexity, common passwords, personal information, reuse, and maximum length weaknesses.
Tags
Updated: 2026-10-05Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Test minimum length
- Test maximum length
- Test complexity rules
- Test common password blocking
- Test personal information restrictions
- Test password history
- Test registration policies
Inputs
- Target application URL
- Password change endpoint
- Registration endpoint
- Authorization token
- Current password
- Username and email
- Password test values
- Common password wordlist
Outputs
- Password acceptance responses
- Minimum length result
- Complexity test results
- Common password findings
- Personal information findings
- Password reuse result
- Maximum length status
- Registration policy results
- Changed password state
Requirements
- Authorized test account
- Network access to target
- Shell environment
- curl command
- Python requests library
