No Rate Limit on login Function (P4 - Low)
How To Test:
- Visit the login endpoint.
- Enter any username and password.
- Intercept the request and send it to the Intruder tab.
- Select null payload and choose 50.
- If there's no rate limiting, report it!
SQL Injection on login Function (P1 - Critical)
How To Test:
- Visit the login endpoint.
- Enter any username and password.
- Intercept the request and save it into the file req.txt.
- Use SQLMap with the following command:
sqlmap -r req.txt --random-agent --level 3 --risk 3 --batch --skip-waf --dbs
Weak login Function over HTTP (P4 - Low)
How To Test:
- Visit the login endpoint.
- Enter any username and password.
- Intercept the request and check the protocol.
- If the username and password are submitted over HTTP, report it.
Account Lockout on login (P3 - Medium or P2 - High)
How To Test:
- Visit the login endpoint.
- Enter a victim's email and any password.
- Intercept the request and send it to the Intruder tab.
- Select null payload and choose 100.
- Check if you receive a message that the victim's email has been locked for a specific duration. If so, report it.
Fuzzing on Login Page (High)
How To Test:
- Visit the login endpoint.
- For example, if you found this endpoint: https://target.com/login?error=403.
- Try to test XSS or SQL on this parameter and try fuzzing to discover more parameters using the following command:
ffuf -w params-names.txt -u https://target.com/login?FUZZ=test - Test again XSS, SQL, and Open Redirect on the discovered parameters.
Open Redirect on Login Page (P4 - Low)
How To Test:
- Visit the login endpoint.
- Look at the URL. For example, if you found this URL: https://target.com/login?next=/dashboard.
- Enter a valid username and password and send the request to Burp Intruder.
- Select $dashboard$ as payload and use open redirect payloads bypass from GitHub.
- Start the attack and look for status code 300. If you are redirected, confirm the bug and report it.
Session Not Validated After Logout (P4 - Low)
How To Test:
- Visit the login endpoint.
- Login using valid username and password.
- Logout and check if you are still logged in. If so, report it.
No Password Policy on Login Page (P4 - Low)
How To Test:
- First, try to create an account with a very weak password such as 12345678.
- If you are able to create the account with a very weak password, there's no password policy.
- Go to the login endpoint.
- Enter your username and your weak password, then report it.

No comments yet