Burpsuite crack username and password

Build environment:

        Target website: http://43.138.211.45:82

        Burpsuite tools and a set of codebooks

1. Open the login background of Burpsuite and http://43.138.211.45:82

 2. Turn on Burpsuite interception

Proxy-intercept is on。

 3. Burpsuite Capture Packet

Enter the user name and password, and you can see the captured data under Proxy.

 4. Send the truncated request to Burpsuite Intruder

Right click - Send to intruder.

 5.Cluster bomb blasting

1) Clear the variable $ automatically highlighted by the cookie, click the bomb bombing (cluster bomb) blasting, and add the variable $ under username and password.

2) Click on payload (payload), add the prepared codebook to variable 1 and variable 2 respectively, and click start attract to attack.

 3) Get the real username and password according to the difference in response and length.

 

Guess you like

Origin blog.csdn.net/m0_73792568/article/details/128874570