Jump to content
Nytro

Complex Website Login Form Attacks Using Burp Suite

Recommended Posts

Complex Website Login Form Attacks Using Burp Suite

 

 

Dictionary attack complex web login forms with Burp Suite's Intruder. This is a follow up video to my Hydra web form login video.https://www.youtube.com/watch?v=ZVngj... You can learn more in this blog post http://se.azinstall.net/2016/03/using... 
This video shows you how to use Burp Suite to intercept login form posts, alter them in Burp Suite's Intruder and launch an automated attack that will work against most websites. In the video we attack a website that has an Antiforgery token that is hidden in the form. This, along with a tracking cookie that is submitted with the form prevents the server from even attempting to validate the login if these tokens don't match. This will prevent tools like Hydra from effectively hacking the login.

Follow me on Twitter, @gFogerlie (https://twitter.com/gfogerlie), Google+ https://plus.google.com/+GarrettFogerlie and Facebookhttps://www.facebook.com/garrett.foge...
 

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...