Lab: Username enumeration via subtly different responses
PreviousLab: Username enumeration via different responsesNextLab: Username enumeration via response timing
Last updated
Last updated
it returns error for both incorrect username and password
It just returns the username al
so i just used it for the username
since it returns different from the rest
Here i used the username al
with the password wordlist
and we got a redirect
solve it using burp
user al doesnt have 1
now just brute force for password and you will see a different status code