๐ง Info
This lab is vulnerable due to a logic flaw in its brute-force protection mechanism.
๐ฏ Goal
Brute-force Carlos's password and access his account page.
- ๐ค Victim's Username:
carlos
- ๐ Candidate Passwords: (Assumed to be provided separately or from a wordlist)
๐งฉ Lab Strategy (Step-by-Step)
โ
We already know the username โ carlos
๐ฏ Our goal is to discover the correct password
๐งช Step-by-Step Walkthrough:
๐ถ Step 1: Initial Testing
- Open the lab
- Try logging in with fake credentials:
- Username โ
carlos
- Password โ
12345
- ๐ค Send the request to Repeater
- ๐ Try multiple login attempts with different passwords
โ After 3 Attempts: