Guida al Broken Authentication OWASP A07: username enumeration, brute force, bypass 2FA, session fixation, password reset e credential stuffing per pentest.