In this lab we see an example of broken force protection. Although there is brute force protection in the form of IP blacklisting, there is a flaw in the way that the brute forcer protection works.
The counter for invalid logins resets every time a valid login is made. Provided we intersperse invalid request with valid requests we can avoid triggering the IP blacklisting.
Since custom wordlists are required for this lab, we make use of node.js to create custom text files.
Support This Channel
======================
Please like and subscribe, it means a lot!
Please buy me a coffee so I can continue to make content.
https://buymeacoffee.com/zenshell
My cybersec and webdev training site
https://www.zenshell.ninja
Join our Discord
/ discord