Sry for long posting but this is holiday in france
I have decide to show you how I bruteforce in windows for all people same me who hate linux, you lose time to run linux in VM with hydra
This method is called FUZZER, bruteforce form login is useless because very low and sometimes
protected by captcha...
|
form login |
.
Fuzzer method is bruteforce the request you send to the server with the username and password
|
live http header (firefox plugin), you can se the request
|
I teach you 2 method with different software one with webslayer and one with acunetix/burp suite
You need to download dictionnary for password
I used only admin for username
For password, I used this .
txt
For find admin panel, I simply used havij (panel finder) or google seach
#1 Webslayer method
you need to download :
webslayer and
live http header (firefox plugin) don't exist for chrome
Webslayer is the fuzzer, he don't sniff the http headers, you need to used for that live http headers.
First find a form login (botnet, exploit pack, istealer login planel ... or website too).
Send the link in firefox and open live http header and write
123456 or what you want in login and password, and copy this request :
|
Exemple of a request |
After you past the link in Webslayer and modify the
123456 in admin (for login) and FUZZ (for password)
FUZZ is the text file with login or password you have choose
you can used FUZ2Z if you want used 2 dictionnary
|
Webslayer ready to start ! |
You have just to press start attack
If all is green, this mean fuzzer work, for find the good login and pass if location change or chars/code change ...
Just wait one night with and a day of work with a good dictionnary and you can find what you want :)
You can execute an unlimited number of webslayer :)
#2 acunetix/burp suite method
In this exemple I will show you only acunetix method because more popular than burp suite, but this is the same method for 99%
first buy acunetix with for 2000$, no this is a joke used a hacked credit card or used this cracked version 8 (last version)
At First got to this link and download acunetix scanner
http://www.acunetix.com/download/fullver8
ID: acunetixwvsfullv8
Password: nFu834!29bg_S2q
Then install it do not open it
If opened Closed it
Open patch and click on patch
Now open Acunetix you will be asked for some details
Enter below details
License Key: 2e3b81463d2s56ae60dwe77fd54f7d60
Name: Hmily/[LCG]
ComPany: Www.52PoJie.Cn
Email: Hmily@Acunetix.com
Telephone: 110
Patch Download Link:here
You need to download too another firefox plugin (yes if you prefer chrome this is not exsit)
Download
foxyproxy
We used only the fuzzer of acunetix, don't used authentification tester this is not work with cracked version
Foxyproxy can send request to acunetix to the httpsniffer because if you dont used foxyproxy, acunetix cant sniff http for firefox
First find a url with form login, open foxyproxy and add localhost and 8080 same in this picture
|
foxyproxy option |
After click on
used the proxy localhost:8080 for all url
open acunetix and click on start for http sniffer
connect to your form login with
123456 for user and password
In the http sniffer find the request and right click send to http fuzzer
|
Http sniffer |
Now we start fuzzing, add click on add generator and add
file generator with 2 files one with login.txt and one other with password.txt (select filetype
Text)
click on
insert into request in you 123456 for login and pass and click on start
|
Http fuzzer setting |
After you have just to wait same Webslayer
|
Http fuzzer in action |
dont forget to stop http proxy sniffer and foxyproxy
Conclusion
For me acunetix is most fast than webslayer (for not a lot)
You can open only 2 acunetix in same time and a number of unlimited of webslayer
All night and for each day of work I used 2 acunetix and 5 Webslayer in same time
I try to access to botnet, exploit pack ... not only webshop too (but I dont do any ilegal activity)
One day with this method I found login and pass of a shop with lot of credit card in clear (not crypted)
|
Hacked cvv2 |
I dont resell them in shop or other (Im 100% White hat)
You can be surprised with fuzzing method, you can access to big website with a big dictionnary
(I would like show admin for big website I have but this is too many ilegal)
Personnaly I never access to a botnet or exploit pack now :( (just an istealer and a webshell)
Maybe
xylito is better than me.
Dont do that for hacked website
If you have any question I am here
I used a lot acunetix not only for fuzzing, but scanning and other, I can rep to your ask with this penetration soft