๐Ÿ” Info Lab โ€“ Logic Flaw in Password Brute-force Protection

This lab is vulnerable due to a logic flaw in its password brute-force protection mechanism.


๐ŸŽฏ Goal

To solve the lab:

  1. Brute-force the victim's password
  2. Log in as the victim
  3. Access their account page

๐Ÿงพ Credentials


๐Ÿง  Lab Concept

This lab is easy once you understand the main idea:

  1. ๐Ÿ”“ First, log in with your own credentials:
  2. ๐ŸŽฏ The goal is to log in as carlos, but we don't have his password.
  3. ๐Ÿ˜ต If we brute-force directly, we'll get rate limited / blocked.