Info 📜:

This lab's password change functionality makes it vulnerable to brute-force attacks.

Goal 🎯:

To solve the lab, use the list of candidate passwords to brute-force Carlos's account and access his "My Account" page.


How to Solve the Lab 🛠️

  1. Open the application and log in with your credentials 🔑:
  2. Change the password 🔄:
  3. Observe the request and response 🧐:
  4. Try different password combinations:
  5. Intercept the request using Burp Suite:
  6. Configure Burp Intruder 🖥️:
  7. Go to Settings ⚙️:
New passwords do not match
  1. Start the attack 🚀

Screenshot 2025-06-29 035828.png

  1. Once the attack finishes, you should see a response containing the "New passwords do not match" message. This indicates you have found the correct password.