Offensive and defensive world-weak_auth-weak password

Violent blasting of weak passwords

Insert picture description here

F12 found after entering the wrong password one time

Insert picture description here

Weak command dictionary blasting
agent opens burp

Insert picture description here

Insert picture description here
Find the different length,
check the response and
get the flag
Insert picture description here

Notes
1. Use dictionary blasting for weak passwords without verification.
2. There are important tips for html comments
3. Weak password dictionary
4. Blasting variables need to be added by themselves, you can just blast the password, click Add to add the $$ variable placeholder.

Guess you like

Origin blog.csdn.net/m0_51641607/article/details/113870213