The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Web Security Academy - Password brute-force via password change

Alpgiray | Last updated: Aug 17, 2022 03:30PM UTC

The provided solution doesn't probably work in any case for me. I checked it after solving the lab get inside maybe another approach is possible but that's not possible. The reason i'm telling this is that within the solution it states that we get a 'Current password is incorrect' error message when the password is not correct for the current user. However, in my case the website redirects me to the login page when it's wrong (which is probably a better solution). Therefore, i used a macro in order to login every time as wiener and then brute-force the password of carlos. Am i missing or doing something wrong or is the solution really out-dated. Thank you already for your reply.

Michelle, PortSwigger Agent | Last updated: Aug 18, 2022 10:58AM UTC