The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Broken Business Logic leading into restrictions bypass and Alternative Solution found for PortSwigger Academy Lab: Username enumeration via account lock

Pedro | Last updated: Jan 11, 2022 02:54PM UTC

Hello! Found an alternative solution on the lab based on a bypass which I think would be awesome to present to the community. The bypass relays on switching the order of the HTTP POST parameters, which turns out to completely circumvent the account locking mechanism, enabling an attacker to test an unlimited set of passwords for whatever user he might want, skipping the enumeration phase and jumping directly into the correct combination of user:password, since we can differ by size and response contents those which aren't the correct combination and the exact correct one. PoC: https://www.youtube.com/watch?v=6ioVur1WrFQ ( account found at 5:30 )

Michelle, PortSwigger Agent | Last updated: Jan 12, 2022 05:15PM UTC

Thanks for getting in touch, we'll have a look through it and get back to you soon.

Michelle, PortSwigger Agent | Last updated: Jan 13, 2022 09:53AM UTC