Authentication Vulnerabilities - Lab #7 Username enumeration via account lock | Long Version

Опубликовано: 17 Март 2026
на канале: Rana Khalil
4,823
105

In this video, we cover Lab #7 in the Authentication module of the Web Security Academy. This lab is vulnerable to username enumeration. It uses account locking, but this contains a logic flaw. To solve the lab, we enumerate a valid username, brute-force this user's password, then access their account page.

Candidate usernames: https://portswigger.net/web-security/...
Candidate passwords: https://portswigger.net/web-security/...

▬ ✨ Support Me ✨ ▬▬▬▬▬▬▬▬▬▬
Buy my course: https://academy.ranakhalil.com/p/web-...

▬ 📚 Contents of this video 📚 ▬▬▬▬▬▬▬▬▬▬
00:00​​​ - Introduction
00:12 - Web Security Academy Course (https://bit.ly/30LWAtE)
01:23 - Navigation to the exercise
01:52 - Understand the exercise and make notes about what is required to solve it
02:24 - Exploit the lab
10:30 - Summary
10:52 - Thank You

▬ 🔗 Links 🔗 ▬▬▬▬▬▬▬▬▬▬
Notes.txt document: https://github.com/rkhal101/Web-Secur...
Web Security Academy Lab Exercise: https://portswigger.net/web-security/...
Rana's Twitter account:   / rana__khalil