Ten Years of Service
Posts: 4,466
Threads: 227
RE: Brute Forcing Login Page using Burp Suite 09-05-2016, 09:16 PM
#2
Mr. Joshi, you weren't joshing about in this video.
•
Fourteen Years of Service
Posts: 74,287
Threads: 317
RE: Brute Forcing Login Page using Burp Suite 09-07-2016, 05:10 AM
#4
Provided there's no account lockout policy In place, whereby after x-amount of Invalid login attempts the account Is locked for a certain duration, and there Isn't a password complexity requirement Implemented (hence easy to guess/brutforce algorithms) this'll work well.
Appreciate the contribution, thanks.
•
Ten Years of Service
Posts: 3,024
Threads: 155
RE: Brute Forcing Login Page using Burp Suite 10-04-2016, 01:33 PM
#10
Do you have to manually check every response for the "index.php"? I mean, its not a problem when you run a wordlist of about a 100, but if you want to unleash 20 k passwords on the target, do you have to go through all 20k of those responses?
~~ Might be back? ~~
•