The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Lab: Broken brute-force protection, multiple credentials per request - Solved in a different way

Rubén | Last updated: Oct 09, 2023 07:25PM UTC

Hello everyone, I would like to contact with someone in staff since I think I have found a different way to solve the Lab mentioned in the subject. It does not imply the json format; as a matter of fact imagine my face while seeing the suggested solution. Haha. I was like... So the json format was relevant? Well, I guess now I know two ways of solving it. My solution was focused only in the auth page since the lab's descriptions says there is a brute force vulnerability in the brute force protection due a to a flaw in its logic. So, should I report my solution here? Is it irrelevant? Should I post this somewhere else? Thank you! :)

Ben, PortSwigger Agent | Last updated: Oct 10, 2023 12:38PM UTC

Hi, Are you able to send us an email at support@portswigger.net and include details of the steps that you are taking so that we can take a look at this? It is worth noting that there might be more than one way to solve a particular lab. We do not use attack signatures to verify solutions - we simply look for the attack effect so if the objective is to delete the carlos user then we simply check whether the user has been deleted rather than checking that the steps you used to get to that point match our written solution. Having said the above, we obviously want to prevent situations whereby there are 'easier' solutions or solutions that circumvent the learning objective so it would be useful to know the exact steps that you have used in this scenario.

Rubén | Last updated: Oct 10, 2023 01:03PM UTC

Thanks for your answer. I will do it asap. :)

Ben, PortSwigger Agent | Last updated: Oct 11, 2023 06:36AM UTC

Thank you Rubén, we have received your email so will respond to that in due course.

Rubén | Last updated: Oct 11, 2023 09:29AM UTC