The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Lab Username enumeration via account lock

Samuel | Last updated: Dec 19, 2022 03:57PM UTC

Hi all, I'm not able to solve lab "Username enumeration via account lock". Despite I'm trying to send Intruder requests in chunks of 20 usernames, I'm receiving 200 OK and lengths of 2976 bytes with no variations.

Samuel | Last updated: Dec 19, 2022 03:58PM UTC

x-special/nautilus-clipboard copy file:///tmp/VMwareDnD/GlK2Zi/burp_request.jpg

Michelle, PortSwigger Agent | Last updated: Dec 19, 2022 04:42PM UTC

Thanks for getting in touch. Are you using Burp Suite Community or Burp Suite Professional when you are working on this lab? Can you describe the steps you are taking to set up your attack?

Samuel | Last updated: Dec 19, 2022 04:48PM UTC

Hi Michelle, I'm using burp community. Steps are: - First, get POST request and send it to Burp - Set Attack Type: Cluster Bomb - Clear payloads - Set payloads username=$test$&password=test$$ - For payload 1, type 'Simple List' and load first chunks of 20 usernames - For payload 2, type 'Null payload' and set 5 payloads per username. I've also tried 3, 7 or 10 payloads and I'm getting same result - Start Attack. On this point, I only receive 200 OK with a value of 2976 bytes responses

Samuel | Last updated: Dec 19, 2022 04:49PM UTC

To clarify, for payload 1 I rotated my 5 lists of chunks of 20 with same result.

Michelle, PortSwigger Agent | Last updated: Dec 21, 2022 10:22AM UTC

Hi Your method looks good, I've just tried it here (using Community), and I was able to identify the username. I did use the sort the Length column in the Intruder results window to make it easier to spot which username triggered the different behavior.

Samuel | Last updated: Dec 28, 2022 02:51PM UTC

Sure I also try to filter responses sorting lenght column, without any variation.

xray | Last updated: Jan 01, 2023 05:34PM UTC

Hello, Same trouble for me, with Community. It seems there is no account lockout at all or variation ,neither by manual probing nor using Burp. Got code 200 with 2976 Bytes.

Ben, PortSwigger Agent | Last updated: Jan 02, 2023 10:48AM UTC