In this module we look at some of the common authentication brute-force protection mechanisms used by modern web applications and how a penetration tester might bypass these controls.
We demonstrate some basic techniques attackers and penetration testers may use to get around mechanisms such as account lockout, IP address lockout and rate limiting using PortSwigger's labs and Burp Suite Professional Edition.
Website: http://predatech.co.uk
Facebook: / predatechsec
Twitter: / predatechsec
Linkedin: / predatech
PortSwigger Lab Links:
X-Forwarded-For: https://portswigger.net/web-security/...
Successful Login Counter Reset: https://portswigger.net/web-security/...
Forced Logout Bypass (With Macro): https://portswigger.net/web-security/...