๐ Info Lab โ Logic Flaw in Password Brute-force Protection
This lab is vulnerable due to a logic flaw in its password brute-force protection mechanism.
๐ฏ Goal
To solve the lab:
- Brute-force the victim's password
- Log in as the victim
- Access their account page
๐งพ Credentials
๐ง Lab Concept
This lab is easy once you understand the main idea:
- ๐ First, log in with your own credentials:
- username: wiener
- password: peter
- ๐ฏ The goal is to log in as carlos, but we don't have his password.
- ๐ต If we brute-force directly, we'll get rate limited / blocked.