๐Ÿงช Info Lab โ€“ Username Enumeration & Password Brute-force

This lab is vulnerable to username enumeration and password brute-force attacks. It contains an account with a predictable username and password that can be found in the wordlists below:

๐Ÿ”— Useful Wordlists:


๐ŸŽฏ Goal

To solve the lab:

  1. Enumerate a valid username.
  2. Brute-force the user's password.
  3. Access the account page.

๐Ÿ’ก Idea

We need to perform a brute-force attack on both the username and password.

There are two main ways to do this:


๐Ÿ” Step-by-Step โ€“ Using Burp Suite Intruder

  1. ๐Ÿงญ Open the lab