๐Ÿงช Info Lab โ€“ Subtle Username Enumeration & Brute-force

This lab is subtly vulnerable to username enumeration and password brute-force attacks. It contains an account with a predictable username and password, both found in the wordlists below:

๐Ÿ”— Useful Wordlists:


๐ŸŽฏ Goal

To solve the lab:

  1. Enumerate a valid username.
  2. Brute-force the user's password.
  3. Access the account page.

๐Ÿง  Approach

This lab is similar to the previous one, but the response differences are more subtle โ€” requiring careful observation of status codes and response bodies.


๐Ÿ› ๏ธ Steps

  1. ๐Ÿ“ Fill the login form with any random username and password
  2. ๐Ÿงฒ Intercept the request using Burp Suite
  3. ๐Ÿ” Send the request to Repeater and observe the response
  4. ๐ŸŽฏ Send the request to Intruder