Tuesday, 17 January 2017

CTF2 Exercise 12 - Brute force admin

How to Brute force the admin panel!

Tools Required: Burp suite (https://portswigger.net/burp/freedownload)

Setup firefox to use burp

https://support.portswigger.net/customer/portal/articles/1783066-configuring-firefox-to-work-with-burp






1) See the hint on the page at the bottom.





2) Google filetype:lst password



postimage download the aircrack-ng password file



3) In burp find your post request

postimage



4) Right click and send to intruder and choose battering ram and hightlight the test password you used.



postimage



5) load the password file you downloaded earlier

postimage





6) start the attack until you see a change of the length of the response.

postimage

7) Check the response and you should be all good

postimage

















No comments:

Post a Comment