RE: Brute Forcing Login Page using Burp Suite 09-07-2016, 12:48 PM
#5
(09-07-2016, 05:10 AM)mothered Wrote: Provided there's no account lockout policy In place, whereby after x-amount of Invalid login attempts the account Is locked for a certain duration, and there Isn't a password complexity requirement Implemented (hence easy to guess/brutforce algorithms) this'll work well.
Appreciate the contribution, thanks.
that is true....modern web apps have counter measures installed for stopping brute forcing....




![[+]](https://sinister.li/images/modern/collapse_collapsed.png)