Web Hacker Basics 05 (Brute Forcing); featuring THC Hydra

preview_player
Показать описание
Ugh, I know, Brute Forcing. A little too basic, but I want to make sure we at least have this covered. Usually, we use brute forcing as a way to guess someone's login credentials. We try every possible password combination and hope we get one of them right. To put it more generally: "Try everything, and hope something sticks". It's not always effective, but when it is it gives us much more access than cleaver guessing alone. So let's take an in depth look at how brute forcing works.

Brute Force Overview:

Testing for Brute Force (OWASP):

Brute Force Tools:
Рекомендации по теме
Комментарии
Автор

This is useful. Not enough people make explanatory videos for these popular tools. Thank you.

FLUFFYCAT_PNW
Автор

Great tutorial! But no one mentions what to input if the request body looks like this: {user: "user", password: "password"}
What do I '\' out and what do I keep?

LINGLING-epev
Автор

OGG my job asked me to hack into a dummy account at work for a bonus and you almost helped me. username & password are not in the URL so I can't continue with hydra.

jessicaito
Автор

do you have a link for hydra thats working today for windows? i wasnt able to get any, on the oficial website it says "404 not found"

NatalieWasner
welcome to shbcf.ru