In this Stream Recording of Late Hacking Night Day 03 (Sinhala), we explore Authentication Vulnerabilities Part I with practical labs from PortSwigger.
Topics Covered:
Introduction to Web Security
WAF (Web Application Firewalls) & DMZ
Common Web Technologies & Bug Bounty Hunting
Authentication vs Authorization
Using Burp Suite (Proxy, Repeater, Intruder)
Password-based vulnerabilities: Brute-force, Username Enumeration, Broken protections
Writing Python scripts for enumeration & exploitation
Labs Demonstrated:
Username enumeration via obvious and subtle response differences
Broken brute-force protection & IP block scenarios
Response timing–based enumeration
Account lock–based enumeration
💬 Join Heshan Streams WhatsApp Channel for live notifications and events :
https://bit.ly/heshanpererawhatsapp
🌍 Websites :
Main : https://destinyoo.com
Blog : https://blog.destinyoo.com
Portfolio : https://about.destinyoo.com
🎙️ Daily Streams and Content :
/ @heshankperera
‼️ Disclaimer: This content is for educational purposes only. I do not take responsibility for misuse. All material is freely available for those who love cybersecurity, use responsibly and ethically.
#cybersecurity #webhacking #CTF #portswiggerlabs #sinhala