π§ Info
This labβs two-factor authentication (2FA) is vulnerable due to a logic flaw in how it handles verification.
π― Goal
Access Carlos's account page to solve the lab.
- π€ Your Credentials:
wiener:peter
- π― Victimβs Username:
carlos
- π§ You also have access to the email server to receive your own 2FA codes
π‘ Hint: Carlos will not attempt to log in himself.
π§ͺ Step-by-Step Walkthrough
π§ Part 1 β Normal Login (Baseline)
- π Open FoxyProxy
- π Login with:
wiener : peter
- π© Go to the Email Client and retrieve your 2FA code
- β
Paste the code and log in successfully
- Open Burp Suite β
Proxy > HTTP History
- π₯ Find the
GET /login2 request
- π€ Send it to Repeater
- βοΈ Change the parameter:
username=wiener β username=carlos