Lab: 2FA broken logic | Portswigger
This lab’s two-factor authentication is vulnerable due to its flawed logic. To solve the lab, access Carlos’s account page.
Lab: 2FA broken logic | Portswigger
This lab’s two-factor authentication is vulnerable due to its flawed logic. To solve the lab, access Carlos’s account page.
- Your credentials:
wiener:peter - Victim’s username:
carlos
You also have access to the email server to receive your 2FA verification code.
- With Burp running, log in to your own account and investigate the 2FA verification process. Notice that in the
POST /login2request, theverifyparameter is used to determine which user's account is being accessed. - Log out of your account.
- Send the
GET /login2request to Burp Repeater. Change the value of theverifyparameter tocarlosand send the request. This ensures that a temporary 2FA code is generated for Carlos. - Go to the login page and enter your username and password. Then, submit an invalid 2FA code.
- Send the
POST /login2request to Burp Intruder. - In Burp Intruder, set the
verifyparameter tocarlosand add a payload position to themfa-codeparameter. Brute-force the verification code. - Load the 302 response in the browser.
- Click My account to solve the lab.



Please comment on which part you like most. If you need any further assistance, please feel free to let me know!
“SECURING- DIGITAL ASSEST OF LIFE”
For more details, Ping a message on LinkedIn:
메타데이터
- post_id
- 0b7a113bd6cc
- slug
- lab-2fa-broken-logic-portswigger-0b7a113bd6cc
- url
- https://osintteam.blog/lab-2fa-broken-logic-portswigger-0b7a113bd6cc
- canonical_url
- https://osintteam.blog/lab-2fa-broken-logic-portswigger-0b7a113bd6cc
- author_url
- https://medium.com/@lavanya.agre.cyb
- status
- ok
- fetched_at
- 2026-06-09 18:04:40