<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Multi-Factor Authentication on 보안 연구 노트</title><link>https://blog.mingon.dev/tags/multi-factor-authentication/</link><description>Recent content in Multi-Factor Authentication on 보안 연구 노트</description><generator>Hugo -- gohugo.io</generator><language>ko-KR</language><lastBuildDate>Sun, 12 Jul 2026 14:00:00 +0900</lastBuildDate><atom:link href="https://blog.mingon.dev/tags/multi-factor-authentication/index.xml" rel="self" type="application/rss+xml"/><item><title>[Note] PortSwigger - Authentication 토픽 정리 및 실습</title><link>https://blog.mingon.dev/note/note-portswigger---authentication-%ED%86%A0%ED%94%BD-%EC%A0%95%EB%A6%AC-%EB%B0%8F-%EC%8B%A4%EC%8A%B5/</link><pubDate>Sun, 12 Jul 2026 14:00:00 +0900</pubDate><guid>https://blog.mingon.dev/note/note-portswigger---authentication-%ED%86%A0%ED%94%BD-%EC%A0%95%EB%A6%AC-%EB%B0%8F-%EC%8B%A4%EC%8A%B5/</guid><description>인증의 세 가지 요소와 인증·인가의 구분, 취약점이 생기는 두 갈래(취약한 브루트포스 방어·구현 로직 결함), Username 열거·브루트포스·MFA·세션 유지·비밀번호 재설정 등 유형별 우회 경로, 그리고 진단 방법과 대응 방안을 정리한 자료</description></item><item><title>[Write-up] PortSwigger - 2FA bypass using a brute-force attack</title><link>https://blog.mingon.dev/write-up/portswigger/authentication/write-up-portswigger---2fa-bypass-using-a-brute-force-attack/</link><pubDate>Sat, 11 Jul 2026 12:00:00 +0900</pubDate><guid>https://blog.mingon.dev/write-up/portswigger/authentication/write-up-portswigger---2fa-bypass-using-a-brute-force-attack/</guid><description>매 시도마다 세션·CSRF·재로그인이 강제되는 2FA를 상태 머신 스크립트로 자동 연쇄해, 시도 제한이 없는 4자리 코드를 전수 대입으로 뚫는 EXPERT Authentication 풀이</description></item><item><title>[Write-up] PortSwigger - 2FA broken logic</title><link>https://blog.mingon.dev/write-up/portswigger/authentication/write-up-portswigger---2fa-broken-logic/</link><pubDate>Thu, 09 Jul 2026 18:00:00 +0900</pubDate><guid>https://blog.mingon.dev/write-up/portswigger/authentication/write-up-portswigger---2fa-broken-logic/</guid><description>2단계 코드가 세션이 아닌 verify 쿠키에 묶인 점을 이용해 대상 계정으로 코드를 발급시키고, 시도 제한 없는 4자리 코드를 브루트포스해 계정을 탈취하는 Authentication 풀이</description></item><item><title>[Write-up] PortSwigger - 2FA simple bypass</title><link>https://blog.mingon.dev/write-up/portswigger/authentication/write-up-portswigger---2fa-simple-bypass/</link><pubDate>Wed, 08 Jul 2026 12:00:00 +0900</pubDate><guid>https://blog.mingon.dev/write-up/portswigger/authentication/write-up-portswigger---2fa-simple-bypass/</guid><description>2단계 인증을 거치지 않고 인증 이후 페이지로 바로 접근해 2FA를 통째로 건너뛰는 기본 Authentication 풀이</description></item></channel></rss>