Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


Tutorial Brute Forcing Login Page using Burp Suite filter_list
Author
Message
RE: Brute Forcing Login Page using Burp Suite #11
(10-04-2016, 01:33 PM)Bish0pQ Wrote: Do you have to manually check every response for the "index.php"? I mean, its not a problem when you run a wordlist of about a 100, but if you want to unleash 20 k passwords on the target, do you have to go through all 20k of those responses?

I'm not after authentication via the password Itself, so bruteforcing/dictionary attack Is Irrelevant to me.

I assess and test for vulnerabilities (namely SQLi), and the failed attacks when manipulating the SQL statement (via numerous SQLi commands) Is what's of concern. Every, and I mean every website that I've compromised did not have a single username or password. I've saved everything by taking screenshots- URLs unedited, Back-End access, database dumps etc, are all Inclusive. All up, I think there's close to 700 websites which my Intention Is to share the lot with selected members, yourself of course Included.
[Image: AD83g1A.png]

Reply

RE: Brute Forcing Login Page using Burp Suite #12
(10-04-2016, 01:33 PM)Bish0pQ Wrote: Do you have to manually check every response for the "index.php"? I mean, its not a problem when you run a wordlist of about a 100, but if you want to unleash 20 k passwords on the target, do you have to go through all 20k of those responses?

piggybacking this question? anybody have an answer?
[Image: giphy.gif]



Reply

RE: Brute Forcing Login Page using Burp Suite #13
(06-05-2017, 05:25 AM)Bonaparte Wrote: nice thanks for the share

As a friendly reminder, If you've replied to a thread where the last post Is more than 3 months old, that's considered grave digging and Is against forum rules.

You can read more about It here: https://sinister.ly/Thread-Post-Etiquett...%2Bdigging
[Image: AD83g1A.png]

Reply