Using Burp to Hack Cookies and Manipulate Sessions


Access the lab

Using Burp to Brute Force a Login Page :

  1. Set Up Burp Suite
  1. Capture the Login Request
  1. Send Request to Intruder
  1. Configure Payloads
  1. Analyze Results
  1. Verify Success

Additional Considerations :


Steps :

  1. First open this page , after doing the intercept off then login by giving username: user : password : user.
    attachments/Pasted image 20250314110202.png

  2. intercept on → refresh the page → then send to repeater

  3. send this to repeater
    attachments/Pasted image 20250314110227.png

  4. click on SEND
    attachments/Pasted image 20250314110245.png

  5. edit the uid form 23 to 1
    attachments/Pasted image 20250314110304.png

  6. show response in browser
    attachments/Pasted image 20250314110322.png

  7. copy the link and open in the browser
    attachments/Pasted image 20250314110338.png

  1. now you logged in through user but you got acces to admin account through this process,
    attachments/Pasted image 20250314110400.png