Authorization refers to rules that determine who is allowed to do what. E.g. Adam may be authorized to create and delete databases, while Usama is only authorised to read.
Authentication is the process of ascertaining that somebody really is who he claims to be.- site minder tool used to test this
Check for cookies, browser session mgt. redirects, back and forwards, networks, browser, db, encryption, field lengths, 3 max attempts, url manipulation,