b0ySie7e
search
⌘Ctrlk
b0ySie7e
  • Bienvenido
  • Write up
    • DockerLabs
    • Tryhackme
    • Hackthebox
    • PortSwigger
      • SQL Injection
      • Cross-site scripting
      • CSRF
      • Path Traversal
      • Autenthentication vulnerabilities
        • Username enumeration via different responses
        • Username enumeration via subtly different responses
        • Username enumeration via response timing
        • Broken brute-force protection, IP block
        • Username enumeration via account lock
        • 2FA simple bypass
        • 2FA broken logic
        • Brute-forcing a stay-logged-in cookie
        • Offline password cracking
        • Password reset broken logic
        • Password reset poisoning via middleware
        • Password brute-force via password change
      • SSRF
      • CORS
      • Clickjacking
  • Notas
    • Pentesting
    • Pentesting Web
    • Escalada de Privilegios
    • Red Team
  • Guias y Herramientas
    • MetaSploit
    • Nmap
    • Git
    • Fortinet
  • Articulos
    • Proyectos
    • Laboratorio
  • Vulnerabilidaes
    • Explotacion
gitbookPowered by GitBook
block-quoteOn this pagechevron-down
  1. Write upchevron-right
  2. PortSwigger

Autenthentication vulnerabilities

Username enumeration via different responseschevron-rightUsername enumeration via subtly different responseschevron-rightUsername enumeration via response timingchevron-rightBroken brute-force protection, IP blockchevron-rightUsername enumeration via account lockchevron-right2FA simple bypasschevron-right2FA broken logicchevron-rightBrute-forcing a stay-logged-in cookiechevron-rightOffline password crackingchevron-rightPassword reset broken logicchevron-rightPassword reset poisoning via middlewarechevron-rightPassword brute-force via password changechevron-right
PreviousFile path traversal, validation of file extension with null byte bypasschevron-leftNextUsername enumeration via different responseschevron-right

Last updated 6 months ago