Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


401 Authorization question filter_list
Author
Message
401 Authorization question #1
So I was browsing neopets.com (don't judge, I've made $1000's on there) earlier today and noticed that whenever I go to a certain page, it asks for a username and password regardless if I'm logged into an account already. If I enter a random un and pw, it brings me to a 401 authorization required page (I'll include a couple screenshots). I tried to do a little research online, but I wasn't able to conclude anything pertinent to my situation.

My question, would it be possible to gain access to an admin's account via this page? Or possibly input random usernames and bruteforce passwords? I've never been much of a hacker so I'm just wanting to know if it's possible to exploit anything useful, or if I'm just wasting my time. Any help would be greatly appreciated.


https://imgur.com/a/X1jfu
https://imgur.com/a/BC2PZ

Reply

RE: 401 Authorization question #2
Chances are rather small. Definitely because it seems you only get access to an image server. It might be possible to bruteforce it through BurpSuite or other tools.
~~ Might be back? ~~

Reply

RE: 401 Authorization question #3
(08-30-2017, 10:32 AM)Bish0pQ Wrote: Chances are rather small. Definitely because it seems you only get access to an image server.  It might be possible to bruteforce it through BurpSuite or other tools.

Hmm I'll look into that. I noticed that it was just the image server, but with human thinking, if someone has access to multiple areas they likely use the same login information to do so.

Reply

RE: 401 Authorization question #4
(08-30-2017, 11:28 PM)FreightTrain Wrote:
(08-30-2017, 10:32 AM)Bish0pQ Wrote: Chances are rather small. Definitely because it seems you only get access to an image server.  It might be possible to bruteforce it through BurpSuite or other tools.

Hmm I'll look into that. I noticed that it was just the image server, but with human thinking, if someone has access to multiple areas they likely use the same login information to do so.
Lol I use all the same usernames (besides on accounts). But dB password is one thing. Account password is one thing. Etc. It's good practice not to use the same pass.

Reply

RE: 401 Authorization question #5
(08-29-2017, 06:33 PM)FreightTrain Wrote: My question, would it be possible to gain access to an admin's account via this page? Or possibly input random usernames and bruteforce passwords?

Anything Is possible If vulnerability(s) exist.

There may also be other gateways to gain access. Check/scan and Identify all known vulnerabilities and work from there. In terms of brute forcing, depending on the complexity of the password and given such an attack enumerates every possible combination/algorithm as per the character range set, you may be sitting by your PC for years (so to speak)- even with a powerful GPU analyzing It's mathematical operations at a very quick rate.
[Image: AD83g1A.png]

Reply