โ† Back to Dashboard
๐Ÿ“Š Login Attempts: 0 (No limit!) ๐Ÿ”„ Reset Counter

Login Form

๐Ÿ”“ Security Weaknesses:

  • โŒ No rate limiting
  • โŒ No account lockout
  • โŒ No CAPTCHA
  • โŒ No delay between attempts
  • โŒ Username enumeration possible
  • โŒ No 2FA

Common Passwords to Try:

admin password 123456 password123 admin123 letmein qwerty welcome 12345678

๐ŸŽฏ Vulnerability Info

Type: Brute Force / No Rate Limiting

Severity: Medium

๐Ÿ’ก How to Exploit

  • No protection against multiple login attempts
  • Use automated tools to try many passwords
  • Username enumeration reveals valid users

๐Ÿ”ง Burp Suite Intruder

  1. Capture login POST request
  2. Send to Intruder (Ctrl+I)
  3. Clear all positions, select password value
  4. Load password wordlist in Payloads
  5. Start Attack
  6. Look for different response length/status

๐Ÿงช Hydra Command

hydra -l admin -P /path/to/wordlist.txt \ localhost http-post-form \ "/vulnlab/vulnerabilities/brute-force/:username=^USER^&password=^PASS^:Invalid"

๐Ÿ“ Sample Wordlist

# Top passwords to try: admin123 password 123456 password123 letmein admin user123 guest qwerty123 welcome1

๐Ÿ“š Valid Users

  • admin
  • user
  • john
  • jane
  • guest