Lab: Broken brute-force protection, multiple credentials per request
This lab is vulnerable due to a logic flaw in its brute-force protection. To solve the lab, brute-force Carlos's password, then access his "My account" page.
- Candidate passwords
With Burp running, investigate the login page. Notice that the
POST /loginrequest submits the login credentials in
JSONformat. Send this request to Burp Repeater.
In Burp Repeater, replace the single string value of the password with an array of strings containing all of the candidate passwords. For example:
"username" : "carlos",
"password" : [
- Send the request. This will return a 302 response.
Right-click on this request and select "Show response in browser". Copy the URL and load it in your browser. The page loads and you are logged in as
- Click "My account" to solve the lab.