Authentication Vulnerabilities - Lab #6 Broken brute-force protection, IP block | Long Version

Опубликовано: 30 Сентябрь 2024
на канале: Rana Khalil
3,697
103

In this video, we cover Lab #6 in the Authentication module of the Web Security Academy. This lab is vulnerable due to a logic flaw in its password brute-force protection. To solve the lab, we brute-force the victim's password, then log in and access their account page.

Your credentials: wiener:peter
Victim's username: carlos
Candidate passwords: https://portswigger.net/web-security/...

▬ ✨ Support Me ✨ ▬▬▬▬▬▬▬▬▬▬
Buy my course: https://academy.ranakhalil.com/p/web-...

▬ 📚 Contents of this video 📚 ▬▬▬▬▬▬▬▬▬▬
00:00​​​ - Introduction
00:11 - Web Security Academy Course (https://bit.ly/30LWAtE)
01:22 - Navigation to the exercise
01:50 - Understand the exercise and make notes about what is required to solve it
02:22 - Exploit the lab
15:18 - Summary
15:30 - Thank You

▬ 🔗 Links 🔗 ▬▬▬▬▬▬▬▬▬▬
Python script: https://github.com/rkhal101/Web-Secur...
Notes.txt document: https://github.com/rkhal101/Web-Secur...
Web Security Academy Lab Exercise: https://portswigger.net/web-security/...
Rana's Twitter account:   / rana__khalil