๐Ÿง  Info

This lab is vulnerable due to a logic flaw in its brute-force protection mechanism.


๐ŸŽฏ Goal

Brute-force Carlos's password and access his account page.


๐Ÿงฉ Lab Strategy (Step-by-Step)

โœ… We already know the username โ†’ carlos

๐ŸŽฏ Our goal is to discover the correct password

๐Ÿงช Step-by-Step Walkthrough:


๐Ÿšถ Step 1: Initial Testing

  1. Open the lab
  2. Try logging in with fake credentials:
  3. ๐Ÿ“ค Send the request to Repeater
  4. ๐Ÿ” Try multiple login attempts with different passwords

โ›” After 3 Attempts: