当前位置:网站首页>CTFHub-Web-密码口令-弱口令
CTFHub-Web-密码口令-弱口令
2022-06-29 02:12:00 【长街395】
打开题目是个登录网页:

我们默认他的用户名是admin
我们需要爆破的是他的密码,又题目中提出是弱口令,我们就可以抓包然后利用一些弱口令字典进行爆破。
1.抓包拦截:

2.右键单击,选择send intruder:
进入到intruder之后,先点击clear,然后选中我们刚才填写的password字段值,点击add。这样,就确定了爆破点是password是位置。
然后将你在网上下载的字典导入到Simple list里 ,最后点击Strat attack


之后看Length的变化:

右键单击,send reputer 查看响应:

就可以找到flag了。
参考文章:
1.弱口令--CtfHub学习之旅-web前置技能-密码口令:弱口令--CtfHub学习之旅-web前置技能-密码口令 - 哔哩哔哩
2.使用burp进行暴力破解:https://blog.csdn.net/ChuMeng1999/article/details/122555284
边栏推荐
- 想请教一下,我在中山,到哪里开户比较好?在线开户是安全么?
- Is there any risk in opening an account for Dongfang fortune stock? Is it safe for Dongfang fortune to open an account
- How does flush open an account? Is it safe to open an account online?
- 直播预告|SQL也能玩转工业级机器学习?MLOps meetup V3带你一探究竟!
- 【Redis】List类型
- 11 go Foundation: Interface
- B1006 output integer in another format
- [learn FPGA programming from scratch -49]: Vision - how is the chip designed?
- Finally got the byte offer. The 25-year-old inexperienced experience in software testing is written to you who are still confused
- Secondary encapsulation of storage (sessionstorage/localstorage) using TS
猜你喜欢

Koa 快速入门
![[redis] data introduction & General Command & string type](/img/86/3abc5047f9c0a051f432e82ccc816c.png)
[redis] data introduction & General Command & string type

Project R & D, what are the free brain mapping tools that are easy to use

Live broadcast preview | can SQL also play industrial machine learning? Mlops meetup V3 takes you to the bottom!

Exclusive analysis | real situation of software test about resume and interview

In simple terms, server intrusion prevention
![[redis] hash type](/img/8b/2585908318f5fe88b455323d3f392e.png)
[redis] hash type

SystemVerilog-结构体(一)

Boost the digital economy and face the future office | the launch of the new version of spreadjsv15.0 is about to begin

Understand flex layout in an article
随机推荐
如何成为一名高级数字 IC 设计工程师(6-5)数字 IC 验证篇:覆盖率收集
How to become a senior digital IC Design Engineer (6-7) digital IC Verification: debug skills
When you complain about the roll, others have quietly begun to prepare for the golden three silver four
110. 简易聊天室13:聊天室服务端
Ambiguity between 0 and 1
[C language] Fibonacci sequence and frog jumping steps (the most detailed elementary frog jumping steps)
KOA Quick Start
【Redis】List类型
如何成为一名高级数字 IC 设计工程师(3-5)工具篇:SpyGlass 技术
Which is the best billing method for okcc call center
Use kubernetes resource lock to complete your own ha application
想请教股票开户要认识谁?现在网上开户安全么?
How to use project Gantt chart to make project report
【学习笔记】子集和问题
How to become a senior digital IC Design Engineer (4-3)
Scala 基礎 (三):運算符和流程控制
Server antivirus
C language course design - food warehouse management system
如何成为一名高级数字 IC 设计工程师(4-2)脚本篇:Verilog HDL 代码实现的文件读写操作
How to become a senior digital IC Design Engineer (1-1) Verilog coding Grammar: Introduction