Logout Functionality
Check List
Methodology
Black Box
Logout Bypass
Open the browser and go to the login page of the target
Enter a valid username/email and password
Submit the login form, Successfully access the authenticated dashboard
Click the Logout button
Confirm you are redirected to the login page or a "Logged out" message appears
Immediately after logout, press the Back button (or use keyboard shortcut Alt + ←)
Observe if the previous authenticated page reloads and you still have full access
Navigate freely inside the dashboard
Perform a privileged action (change settings, view private data) → If successful → Logout bypass confirmed
Failure to Invalidate Session on Logout
Login to the application using Chrome Browser and browse the application
Use “Edit this Cookie” plugin in Chrome and copy all the cookies present
Now Logout from the application and Clear the cookies from browser
Use “Edit this Cookie” plugin and paste all the cookies that copied earlier
Click on Okay and refresh the page , can see the application is getting logged in
White Box
Cheat Sheet
Last updated