Hunt Brute Force

"Hunt Missing/Weak Rate Limiting — login brute force, OTP/2FA brute force (10^6 keyspace), password-reset-token brute, credential stuffing, username/email enumeration via error-string / status-code / timing differences, weak password policy, missing CAPTCHA (CAPTCHA token replay / single-use / concurrency-window bypass specifics → hunt-captcha-bypass), IP-based rate-limit bypass via X-Forwarded-Fo

wufufu770 Updated

File contents

wufufu770/skills/tree/main/ext/2-web-vulns/031-hunt-brute-force commit ab9e52a6ed

Frequently asked questions

npx skillmds@latest add wufufu770/hunt-brute-force