WBCE/WBCE_CMS

Bypass account protection

Closed this issue · 1 comments

Hi team,

I found a way to bypass account protection (not blocked when brute-force account).

Step: *this is demo some cases

  1. If I log in wrongly too many times, it will be locked
    image

  2. But i can pass it by insert X-Forwarded-For header, then brute-force without being locked (use intruder plugin of burp suite)
    image

  3. set payload to brute-force and start attack
    image
    image

  4. Result find user (bypass account protection without blocked)
    image