Hack the website password with Burpsuite

Source: Internet
Author: User

    • Burpsuite Professional Edition

    • A website

Method/Step
  1. 1

    Switch to the option option on the Proxy tab, set the proxy address and port: 127.0.0.1:8080.

  2. 2

    Start the agent you just set up

  3. 3

    Open Internet Properties, select: Connections->lan Settings->proxy Server. Enter 127.0.0.1 and 8080 respectively.

  4. 4

    Find a destination URL for

  5. 5

    Click "Login" when a pop-up window appears, in order to find a real login URL, we click "Free Registration".

  6. 6

    Click "Login" next to enter an account, enter the password "123456". (Do not click the login button first)

  7. 7

    Select the "Intercept" option under the Proxy tab, click on the "Intercept is off" button and the button will change to "Intercept is on"

  8. 8

    Open the previous landing page and click on the "Login" button.

  9. 9

    At this point we will see the packets just intercepted under the burpsuite. You can see the username and keywords we just entered.

  10. 10

    Right-click within the text area and select Send to Intrder

  11. 11

    Switch to the Intruder tab, select "Target", set the host address and port number, the port number by default is 80, if the website is using the HTTPS protocol, tick "use HTTPS" to switch to 443 port (SSL)

  12. 12

    To switch to the positions option, click the "Clear $" button on the right to clear all default parameters.

  13. 13

    The mouse selects the text behind username (the user name we entered) and clicks the "Add $" button.

  14. 14

    To switch to the "payloads" option, select the "Payload type" to use, here we select "Simple List".

  15. Select a password in the "Add from List" below, where we select "8 Letter Words".

  16. Switch to the Options tab, set the number of threads and other parameters, as shown in.

  17. Click "Intruder" on the menu bar and select "Start attack"

  18. When we scan to the same time, we sort by length size. This is where we will see several different packets, many of which are the same, and there are a few packets that are quite basic enough to be correct.

  19. Select one of the smaller packets, click "Response" below, and you will see a prompt "username or password is wrong"

  20. Similarly, we then select a larger packet, which is, we will see below without prompting "username or password error",

  21. When I reopen the login page, I find I can't get in.

  22. The initial guess is that the IP is blocked by the site, so we have to change an IP login to try. I use the mobile phone to open the Hotspot link computer, then go to open the Web page is displayed.

  23. Enter the username that we just got (take merchant for example) and password 123456. Then click Sign In.

  24. Successful Login

Hack the website password with Burpsuite

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.