This lab's two-factor authentication is vulnerable to brute-forcing.
You already have valid credentials, but not the 2FA verification code.
Brute-force the 2FA code and access Carlos's account page.
carlos:montoyaWhen logging in with Carlos’s credentials:
➡️ So we need to brute-force the 2FA code efficiently while keeping the session active
✅ That’s where Burp Suite Macros come in!