🧠 Info

This lab’s two-factor authentication (2FA) is vulnerable due to a logic flaw in how it handles verification.


🎯 Goal

Access Carlos's account page to solve the lab.

πŸ’‘ Hint: Carlos will not attempt to log in himself.


πŸ§ͺ Step-by-Step Walkthrough

πŸ”§ Part 1 – Normal Login (Baseline)

  1. πŸ” Open FoxyProxy
  2. πŸ” Login with:wiener : peter
  3. πŸ“© Go to the Email Client and retrieve your 2FA code
  4. βœ… Paste the code and log in successfully
  5. Open Burp Suite β†’ Proxy > HTTP History
  6. πŸ“₯ Find the GET /login2 request
  7. πŸ“€ Send it to Repeater
  8. ✏️ Change the parameter:username=wiener β†’ username=carlos