> For the complete documentation index, see [llms.txt](https://kunalwalavalkar.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://kunalwalavalkar.gitbook.io/write-ups/portswigger-labs/server-side-topics/authentication/username-enumeration-via-different-responses.md).

# Username enumeration via different responses

https\://portswigger.net/web-security/authentication/password-based/lab-username-enumeration-via-different-responses

<figure><img src="https://1586847736-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtSZ40gLWhBDTzPEgHsVB%2Fuploads%2Fzqa7DoeHIJPWoqHRMuxI%2F1.png?alt=media&amp;token=bbd41ebe-d67b-45b1-bb99-a42beb2ad13c" alt=""><figcaption></figcaption></figure>

We can click on `My Account` in order to login.

<figure><img src="https://1586847736-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtSZ40gLWhBDTzPEgHsVB%2Fuploads%2F84DYhyPXZwMjsSuolnET%2F2.png?alt=media&amp;token=39aa63b6-f7fd-4dd7-93f8-3f456048ae84" alt=""><figcaption></figcaption></figure>

We can view the `Proxy > HTTP History` in Burp Suite to view this request.

<figure><img src="https://1586847736-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtSZ40gLWhBDTzPEgHsVB%2Fuploads%2FXFBGT2JQEYQNgvTf5WFY%2F3.png?alt=media&amp;token=a9f353a5-e072-40a4-9f1b-7ed77b2c84f1" alt=""><figcaption></figcaption></figure>

Let's forward it to the `Intruder` and add a payload field to the `username` parameter.

<figure><img src="https://1586847736-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtSZ40gLWhBDTzPEgHsVB%2Fuploads%2FvUMngoZXRlWA0JWwsagv%2F4.png?alt=media&amp;token=72e2bf7e-3ccd-4129-868a-3a2080062f9c" alt=""><figcaption></figcaption></figure>

Next we can go to the `Payloads` tab and set the `Payload type` to `Simple list`. Once that is done, we can paste the usernames provided to us here in the `Payloads settings` section.

<figure><img src="https://1586847736-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtSZ40gLWhBDTzPEgHsVB%2Fuploads%2FlAFTT3XWCBymAFI2wJfT%2F5.png?alt=media&amp;token=5c5a39e5-462c-484e-9bbb-473db960611e" alt=""><figcaption></figcaption></figure>

Let's start the attack.

<figure><img src="https://1586847736-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtSZ40gLWhBDTzPEgHsVB%2Fuploads%2Fye5Jo0dPgxxjNDy6ONO7%2F6.png?alt=media&amp;token=b9f3b19d-1cc8-4e65-886b-5d98ec4e5734" alt=""><figcaption></figcaption></figure>

We can observe that the request with `username` set to `analyzer` returned a different response than the others. This is because this username was correct whereas the others weren't.

&#x20;Now we can craft another attack by setting the `username` parameter to `carlos` and adding a payload field to the `password` parameter.

<figure><img src="https://1586847736-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtSZ40gLWhBDTzPEgHsVB%2Fuploads%2FICAj3lxVL0LtA3mDvb6w%2F7.png?alt=media&amp;token=e634e784-e660-48b3-bf3e-69bf8567ab43" alt=""><figcaption></figcaption></figure>

In the `Payloads` tab we will again be using a `Simple list`. Let's paste the passwords provided to use here in the `Paeyloads section`.

<figure><img src="https://1586847736-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtSZ40gLWhBDTzPEgHsVB%2Fuploads%2F6hUtR1Cur2pBrehw8pW5%2F8.png?alt=media&amp;token=dba2289d-3a58-492e-9ca7-4a77474a10e9" alt=""><figcaption></figcaption></figure>

We are now set to start the attack.

<figure><img src="https://1586847736-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtSZ40gLWhBDTzPEgHsVB%2Fuploads%2FiFO3m206F03rBJclYTbG%2F9.png?alt=media&amp;token=3f5b3908-1929-4b22-88b1-9e6ac1c8e370" alt=""><figcaption></figcaption></figure>

As we can see, the request with the `password` set to `1234567890` gives a `302` response. Now that we know what the username and password are, let's login.

| Username | Password   |
| -------- | ---------- |
| analyzer | 1234567890 |

<figure><img src="https://1586847736-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtSZ40gLWhBDTzPEgHsVB%2Fuploads%2FWkUfyMSUroDp41nqwjY0%2F10.png?alt=media&amp;token=cc3118e3-27c9-4f9a-9190-1aaba136b46f" alt=""><figcaption></figcaption></figure>

We have solved the lab.

<figure><img src="https://1586847736-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtSZ40gLWhBDTzPEgHsVB%2Fuploads%2FLMYZdNJsmyhnEHdTRBEw%2F11.png?alt=media&amp;token=b9fcf546-c779-4ec1-8ba0-f146375d84cc" alt=""><figcaption></figcaption></figure>
