Burpsuite tutorials and tips for HTTP brute brute force hack

Source: Internet
Author: User

Regular payload test for USERNAME/PASSWPRD, I think we should have no problem, but for authorization:basic dxnlcm5hbwu6cgfzc3dvcmq= such a problem, a lot of friends puzzled.

Before, I remember I introduced Burpsuite's Intruder function (Burpsuite tutorials and techniques of SQL injection), presumably a lot of people have no impression, here, with the HTTP brute to revisit the intruder function.

Follow the examples below (for illustrative purposes only, whichever is your goal)

auth=dxnlcjpwyxnzd29yza==, which is our key position.

So how do you do it? The approximate operation process is as follows:

1. Decrypt the base64 string 2.  Generate Test Payload3.  testing with the payload        

1. Base64 String for decryption verification

The decrypted string is:

Auth=user:password   

The problem is, for User:password this form of string, how do we set payload?

It must have been a lot of people here. To solve this problem, let's look at the second part.

2. Generating payload for testing

For this format, it is not possible to use Burpsuite to complete the test successfully, that will need to enrich the corresponding payload.

My approach is to use Burpsuite to generate the payload text I want.

Auth=§user§§:§§password§    

Set 3 payloads,

1------§user§2------§:§3------§password§  

Then build payloads according to the intruder battering ram/pitchfork/cluster bomb (generated according to your own requirements)

Here I choose to take cluster bomb as an example, use intruder to generate the payloads you need, and then save it to a text file.

There's a detail when you save it. Delimiter Select customer

3. Test with payload

When testing, we choose Sniper, we only need a payload variable

If there are deficiencies, please correct me.

Burpsuite tutorials and tips for HTTP brute brute force hack

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.