Burp Suite User Forum

Create new post

How do I bypass a certian amount of OTP attemtps?

Dylan | Last updated: May 16, 2021 01:41PM UTC

Im attemting an attack but after a few OTP tries, the target says I have tried too many times and that I should try again later. How can I go about this?

Hannah, PortSwigger Agent | Last updated: May 17, 2021 03:10PM UTC

Hi Dylan My colleague has responded to your other post with the following: You can find some ideas from the Academy labs: - https://portswigger.net/web-security/all-labs#authentication However, if there are restrictions set up on the server itself (e.g. an account lockout policy) then it will be difficult to bypass that. You can also try intercepting the request with the OTP and brute force using the Intruder as demonstrated in this lab: - https://portswigger.net/web-security/authentication/multi-factor/lab-2fa-bypass-using-a-brute-force-attack Please let us know if you need any further assistance.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.