Imagine we have this website.

image.png

now let’s try to login.

image.png

As shown we get banned if we made more than a login faliure

now let’s intercept the login request.

image.png

Now let’s get the passwords.

image.png

now let’s attack.

image.png

now let’s login.

image.png