Password brute-force via password change

3 min read Easy PortSwigger
Authentication
Contents

On this page

The lab

here is how portswigger describes it

This lab's password change functionality makes it vulnerable to brute-force attacks. To solve the lab, use the list of candidate passwords to brute-force Carlos's account and access his "My account" page.

the reset poisoning lab abused the forgot password flow. this one abuses the opposite feature, changing your password while logged in, and turns its error messages into a way to brute force someone else's current password without ever tripping the account lock.

why the change password form leaks the answer#

the change password feature asks for your current password and a new one twice. that gives it three possible outcomes depending on what you submit, and the app word the responses differently for each. that difference is the whole vulnerability.

walk through the three cases. if the current password is wrong and the two new passwords match, the account gets locked, which is a dead end. if the current password is wrong and the two new passwords do not match, the message says the current password is incorrect. but if the current password is right and the two new passwords do not match, the message changes to new passwords do not match. that last case is the oracle. by always sending two different new passwords on purpose, we dodge the account lock entirely and force the app to tell us, through which error it returns, whether the current password we guessed was correct. the form was built to protect your own account, and the username being a hidden field we can edit lets us point it at carlos instead.

Step 1 - study the three responses#

we log in as wiener and play with the change password form while watching the requests. the first thing to spot is that the username travels as a hidden input in the POST /my-account/change-password request, which means we can swap it for another account.

then we try the combinations to confirm the behaviour. wrong current password with matching new passwords locks the account, so we avoid that. wrong current password with two different new passwords returns current password is incorrect. a correct current password with two different new passwords returns new passwords do not match. those two distinct messages, both reached with mismatched new passwords, are what we will tell apart.

Step 2 - aim the attack at carlos#

we take a request where we enter our own correct current password and two new passwords that differ, and send it to intruder.

now we rework it to target carlos. we change the username to carlos, put a payload position on the current-password parameter so the wordlist gets tried there, and keep the two new password fields set to different values so the account never locks during the run:

username=carlos&current-password=§incorrect-password§&new-password-1=123&new-password-2=abc

we load the candidate password list into that single position.

Step 3 - grep for the telltale message and solve#

we need to pick out the one guess that hit carlos's real password. since a correct current password is the only thing that produces new passwords do not match, that message is our success flag.

in the settings we add a grep match rule for the string New passwords do not match, then start the attack. almost every guess comes back with current password is incorrect, but the one request whose current password is actually carlos's gets flagged with the mismatch message instead.

that flagged row's payload is carlos's current password. we log in as carlos with it and reach his account page.

with this, the lab is solved!