Hunt Brute Force

Hunt Missing/Weak Rate Limiting — login brute force, OTP/2FA brute force (10^6 keyspace), password-reset-token brute, credential stuffing, username/email enumeration via error-string / status-code / timing differences, weak password policy, missing CAPTCHA, IP-based rate-limit bypass via X-Forwarded-For and friends, ReDoS. Distinguishes hard lockout vs soft IP-throttle vs CAPTCHA-injection vs silent shadow-throttling (avoids false-negative 'no rate limit' conclusions). Medium to Critical depending on what the brute reaches (OTP→ATO = Critical).

uphiago 6a12816 19.6 KB Updated

File contents

uphiago/recon-skills/tree/main/redteam/hunt-brute-force commit 6a128167c5

Frequently asked questions

npx skillmds@latest add uphiago/hunt-brute-force