130 Days Bug Hunting Learning Challenge | Week - 03
Authentication, Enumeration, Brute force Logic
DAY 011
Topic: Authentication Mechanisms & Username Enumeration
Welcome to Day 011 of the 130 Days Bug Hunting Learning Challenge.
This week, you’ll begin exploring how modern authentication systems work and how attackers identify common authentication weaknesses through observation and hands-on practice.
STUDY — 60 MINUTES
1. PortSwigger Web Security Academy – Authentication Vulnerabilities
Read the Authentication Mechanisms and Username Enumeration sections.
🔗 https://portswigger.net/web-security/authentication
🔗 https://portswigger.net/web-security/authentication/password-based
2. Pre-Lab Recall
Before starting the labs, identify the source/sink (input trust boundary) and decide which request you will modify in Burp.
PRACTICE — 90 MINUTES
Core — Complete Today
• Username Enumeration via Different Responses
• Username Enumeration via Subtly Different Responses
Solve Rule
25-minute self-attempt → Revisit theory → Use a hint → View the solution if necessary → Reset and solve again
NOTE + RESEARCH — 30 MINUTES
• Write 5 things you learned today
• Write 1 important mistake or problem you faced
• Note one HTTP Request/Response or an important concept
• Research which observable signals distinguish valid and invalid usernames, and how to avoid false positives
DAY COMPLETE WHEN
✅ Study Completed
✅ Core Practice Completed
✅ Progress Saved
✅ 30-Minute Notes Completed
DAY 012
Topic: Subtle Response Differences
Welcome to Day 012 of the 130 Days Bug Hunting Learning Challenge.
Today, you’ll learn how subtle response differences can reveal valid usernames and how to identify these behaviors during authentication testing.
STUDY — 60 MINUTES
1. PortSwigger Web Security Academy — Authentication Vulnerabilities
Read the Subtle Response Differences section and understand where the vulnerability occurs, detection signals, impact, and prevention.
🔗 https://portswigger.net/web-security/authentication#how-do-authentication-vulnerabilities-arise
🔗 https://portswigger.net/web-security/authentication/password-based
2. Pre-Lab Review
Identify the source/sink (input trust boundary) and decide which request you will modify in Burp before starting the labs.
PRACTICE — 90 MINUTES
Core — Complete Today
• Username Enumeration via Response Timing
• Broken Brute-Force Protection, IP Block
Solve Rule
25-minute self-attempt → Revisit theory → Use a hint → View the solution if necessary → Reset and solve again
NOTE + RESEARCH — 30 MINUTES
• Write 5 things you learned today
• Write 1 important mistake or problem you faced
• Note one HTTP Request/Response or an important concept
• Research how subtle response differences can distinguish valid and invalid usernames, how to avoid false positives, and what a secure design should look like.
DAY COMPLETE WHEN
✅ Study Completed
✅ Core Practice Completed
✅ Progress Saved
✅ 30-Minute Notes Completed
DAY 013
Topic: Timing & Account Lock Behavior
Welcome to Day 013 of the 130 Days Bug Hunting Learning Challenge.
Today, you’ll learn how timing differences and account lock behavior can reveal valid usernames and how to recognize these observable signals during authentication testing.
STUDY — 60 MINUTES
1. PortSwigger Web Security Academy — Authentication Vulnerabilities
Read the Timing & Account Lock Behavior section. Understand where the vulnerability occurs, detection signals, impact, and prevention.
🔗 https://portswigger.net/web-security/authentication/password-based
2. Pre-Lab Review
Identify the source/sink (input trust boundary) and decide which request you will modify in Burp before starting the lab.
PRACTICE — 90 MINUTES
Core — Complete Today
• Username Enumeration via Account Lock
Solve Rule
25-minute self-attempt → Revisit theory → Use a hint → View the solution if necessary → Reset and solve again
NOTE + RESEARCH — 30 MINUTES
• Write 5 things you learned today
• Write 1 important mistake or problem you faced
• Note one HTTP Request/Response or an important concept
• Research how timing and account lock behavior create observable signals that distinguish valid and invalid usernames, how to avoid false positives, and what a secure design should look like.
DAY COMPLETE WHEN
✅ Study Completed
✅ Core Practice Completed
✅ Progress Saved
✅ 30-Minute Notes Completed
DAY 014
Topic: Rate Limit & IP Block Weaknesses
Welcome to Day 014 of the 130 Days Bug Hunting Learning Challenge.
Today, you’ll learn how rate limiting and IP blocking work, understand their common weaknesses, and recognize observable signals during authentication testing.
STUDY — 60 MINUTES
1. PortSwigger Web Security Academy — Authentication Vulnerabilities
Read the Rate Limit & IP Block Weaknesses section. Understand where the vulnerability occurs, detection signals, impact, and prevention.
🔗 https://portswigger.net/web-security/authentication/password-based
2. Pre-Lab Review
Identify the source/sink (input trust boundary) and decide which request you will modify in Burp before starting the lab.
PRACTICE — 90 MINUTES
Core — Complete Today
• Broken Brute Force Protection, Multiple Credentials per Request
Solve Rule
25-minute self-attempt → Revisit theory → Use a hint → View the solution if necessary → Reset and solve again
NOTE + RESEARCH — 30 MINUTES
• Write 5 things you learned today
• Write 1 important mistake or problem you faced
• Note one HTTP Request/Response or an important concept
• Research how rate limits and IP blocking work, what weaknesses attackers may exploit, how to recognize observable signals, avoid false positives, and what a secure implementation should look like.
DAY COMPLETE WHEN
✅ Study Completed
✅ Core Practice Completed
✅ Progress Saved
✅ 30-Minute Notes Completed
DAY 015
Topic: Multi Credential Request Behavior
Welcome to Day 015 of the 130 Days Bug Hunting Learning Challenge.
Today, you’ll learn how multi-credential request behavior affects authentication security and understand how to identify weaknesses in multi-factor authentication implementations.
STUDY — 60 MINUTES
1. PortSwigger Web Security Academy — Authentication Vulnerabilities
Read the Multi Credential Request Behavior section. Understand where the vulnerability occurs, detection signals, impact, and prevention.
🔗 https://portswigger.net/web-security/authentication/multi-factor
2. Pre-Lab Review
Identify the source/sink (input trust boundary) and decide which request you will modify in Burp before starting the lab.
PRACTICE — 90 MINUTES
Core — Complete Today
• 2FA Simple Bypass
🔗 https://portswigger.net/web-security/authentication/multi-factor/lab-2fa-simple-bypass
Solve Rule
25-minute self-attempt → Revisit theory → Use a hint → View the solution if necessary → Reset and solve again
NOTE + RESEARCH — 30 MINUTES
• Write 5 things you learned today
• Write 1 important mistake or problem you faced
• Note one HTTP Request/Response or an important concept
• Research how Multi Credential Request Behavior distinguishes valid and invalid states, how to avoid false positives, and what a secure design should look like.
DAY COMPLETE WHEN
✅ Study Completed
✅ Core Practice Completed
✅ Progress Saved
✅ 30-Minute Notes Completed
Learn More About HAXSTIK : CLICK HERE




