This lab is vulnerable to username enumeration because the response from the server is slightly different when a valid username is provided.
We make use of burps Grep - Extract feature to analyse the server response contained within defined boundaries. This allows us to easily see which response from the server is different.
When enumerating the password, we make use of the http status code to determine a successful login. In previous authentication labs we were able to sort by the response length to make differentiations, but the response length is now randomised making this impossible.
Support This Channel
======================
Please like and subscribe, it means a lot!
Please buy me a coffee so I can continue to make content.
https://buymeacoffee.com/zenshell
My cybersec and webdev training site
https://www.zenshell.ninja
Join our Discord
/ discord