In this lesson, participants receive a demonstration of a username enumeration via web service. Using mutillidea, participants learn about a username enumeration using a Burp extender in the Burp Suite. Participants learn step by step instructions in obtaining all valid usernames and getting user responses to see which accounts exist and which do not.

