Insecure authentication method - Basic
Description
The server uses Basic authentication over an insecure channel.
Impact
Gather base 64 coded credentials.
Recommendation
Use stronger authentication mechanisms like Bearer and OAuth.
Threat
Unauthorized attacker from adjacent network performing a Sniffing attack.
Expected Remediation Time
⏱️ 120 minutes.
Requirements
030 - Avoid object reutilization228 - Authenticate using standard protocols319 - Make authentication options equally secureRules
Http Basic Auth Over HttpC Sharp Basic Auth Header Hardcoded CredentialsXml Basic Auth Method UsedXml Authorization Header With Basic TokenTerraform Password Authentication EnabledTerraform Missing Admin Auth MethodPython Basic Auth Header UsedPhp Basic Auth Header Hardcoded CredentialsJava Basic Auth Header Untrusted Input