Pikachu brute force - to bypass the authentication code (on server)

When the authentication code input errors, empty and enter the correct would be the following two cases:

 

 This section describes the platform is then used to build a package validation burpsuite task.

 

Sent to the repeater module, the page is refreshed to obtain a new code, the codes of the data parameters to the new contract verification code

 

And even if we repeatedly change your password, a verification code can be found not change.

Even changed using the original codes but also through.

So you can use the same code correctly direct blasting.

 

You can get the password 123456

 

Guess you like

Origin www.cnblogs.com/ApricityJ/p/12628819.html