The purpose of this demo is to show how a BIG-IP Advanced WAF security policy can protect a web application against brute force attacks that target a single username using a CAPTCHA challenge. In this demo we will:
1. Show a brute force attack against a vulnerable web application.
2. Configure and test a login page element in an existing BIG-IP Advanced WAF security policy.
3. Configure brute force protection for usernames using a CAPTCHA challenge.
4. Attempt the brute force attack again and show the results.