当前位置:网站首页>CTFHub-Web-密码口令-弱口令
CTFHub-Web-密码口令-弱口令
2022-06-29 02:12:00 【长街395】
打开题目是个登录网页:

我们默认他的用户名是admin
我们需要爆破的是他的密码,又题目中提出是弱口令,我们就可以抓包然后利用一些弱口令字典进行爆破。
1.抓包拦截:

2.右键单击,选择send intruder:
进入到intruder之后,先点击clear,然后选中我们刚才填写的password字段值,点击add。这样,就确定了爆破点是password是位置。
然后将你在网上下载的字典导入到Simple list里 ,最后点击Strat attack


之后看Length的变化:

右键单击,send reputer 查看响应:

就可以找到flag了。
参考文章:
1.弱口令--CtfHub学习之旅-web前置技能-密码口令:弱口令--CtfHub学习之旅-web前置技能-密码口令 - 哔哩哔哩
2.使用burp进行暴力破解:https://blog.csdn.net/ChuMeng1999/article/details/122555284
边栏推荐
- 大智慧手机股票开户哪个券商更安全更方便?
- The left toolbar of hbuilder is missing
- 如何成为一名高级数字 IC 设计工程师(6-6)数字 IC 验证篇:系统级仿真
- How to become a senior digital IC Design Engineer (6-5) digital IC Verification: coverage collection
- 数字 IC 设计、FPGA 设计秋招笔试题目、答案、解析(1)2022 紫光展锐(上)
- Blog publishing test 1
- Exclusive analysis | real situation of software test about resume and interview
- [redis] sortedset type
- Crawler exercise (IV) -- IP address problem
- 2022.02.15
猜你喜欢

【Redis】Key的层级结构

Project R & D, what are the free brain mapping tools that are easy to use

Redis data migration (III)

Interviewer: with the for loop, why do you need foreach??
Scala 基础 (三):运算符和流程控制

I have summarized some experiences from the whole process of R & D platform splitting

In simple terms, server intrusion prevention

Differences between web testing and app testing

Adding, deleting, checking and modifying stack - dynamic memory
![[redis] get to know redis for the first time](/img/02/3c6a7f6ea8c563386a4cd458024728.png)
[redis] get to know redis for the first time
随机推荐
Google Borg论文
在按钮禁用时消除hover效果
【Redis】数据介绍 & 通用命令 & String类型
In simple terms, server intrusion prevention
为什么建议大家尽可能选择自研公司
Which brokerage is safer and more convenient to open an account for compass mobile stock?
Callback function of unity after importing resources
[learn FPGA programming from scratch -50]: Vision - how are chips made? The thirteen steps of chip manufacturing.
[机缘参悟-33]:眼见不一定为实,大多数时候“眼见为虚”
Business system anti-virus
[learning notes] subsets and questions
110. 简易聊天室13:聊天室服务端
Finally got the byte offer. The 25-year-old inexperienced experience in software testing is written to you who are still confused
[C language] Fibonacci sequence and frog jumping steps (the most detailed elementary frog jumping steps)
瀑布型项目管理最常用的10个小工具,可以自由搭建使用
KOA Quick Start
Blog publishing test 3
e.target与e.currentTarget的区别
Eliminate the hover effect when the button is disabled
利用kubernetes资源锁完成自己的HA应用