当前位置:网站首页>CTFHub-Web-密码口令-弱口令
CTFHub-Web-密码口令-弱口令
2022-06-29 02:12:00 【长街395】
打开题目是个登录网页:

我们默认他的用户名是admin
我们需要爆破的是他的密码,又题目中提出是弱口令,我们就可以抓包然后利用一些弱口令字典进行爆破。
1.抓包拦截:

2.右键单击,选择send intruder:
进入到intruder之后,先点击clear,然后选中我们刚才填写的password字段值,点击add。这样,就确定了爆破点是password是位置。
然后将你在网上下载的字典导入到Simple list里 ,最后点击Strat attack


之后看Length的变化:

右键单击,send reputer 查看响应:

就可以找到flag了。
参考文章:
1.弱口令--CtfHub学习之旅-web前置技能-密码口令:弱口令--CtfHub学习之旅-web前置技能-密码口令 - 哔哩哔哩
2.使用burp进行暴力破解:https://blog.csdn.net/ChuMeng1999/article/details/122555284
边栏推荐
- 东方财富股票开户是会有什么风险吗?东方财富开户安全吗
- [redis] hash type
- SystemVerilog-结构体(一)
- 如何成为一名高级数字 IC 设计工程师(6-5)数字 IC 验证篇:覆盖率收集
- Is the ETF fund reliable and safe
- Kubernetes: container resource requirements and constraints (constraints)
- 数字 IC 设计、FPGA 设计秋招笔试题目、答案、解析(2)2021 华为海思(上)
- Koa 快速入门
- Is it safe to contact the account manager online to open an account for stock speculation?
- 【Redis】SortedSet类型
猜你喜欢

【Redis】初识 Redis

Exclusive analysis | real situation of software test about resume and interview

项目研发,有哪些好用的免费脑图工具软件

C language course design - food warehouse management system

【Redis】Set类型
![[redis] get to know redis for the first time](/img/02/3c6a7f6ea8c563386a4cd458024728.png)
[redis] get to know redis for the first time

Introduction to super dongle scheme

How to become a senior digital IC Design Engineer (4-3)

Live broadcast preview | can SQL also play industrial machine learning? Mlops meetup V3 takes you to the bottom!

Boost the digital economy and face the future office | the launch of the new version of spreadjsv15.0 is about to begin
随机推荐
[learn FPGA programming from scratch -49]: Vision - how is the chip designed?
Uniapp notes
Oculusrifts and unity UI interaction (1) - Overview
[MySQL practice of high concurrency, high performance and high availability of massive data -9] - transaction concurrency control solutions lbcc and mvcc
Digital IC design, FPGA design written examination questions, answers and analysis of autumn move (1) 2022 Ziguang zhanrui (Part 1)
我把整个研发中台拆分过程的一些心得总结
Which is the best billing method for okcc call center
如何成为一名高级数字 IC 设计工程师(6-5)数字 IC 验证篇:覆盖率收集
[redis] hash type
基于 FPGA 的 RISC CPU 设计(4)关于项目的 36 个问题及其答案
跨境资讯站
SQL splits strings into tables
e. Difference between target and e.currenttarget
RISC CPU design based on FPGA (4) 36 questions about the project and their answers
Callback function of unity after importing resources
How to become a senior digital IC Design Engineer (6-5) digital IC Verification: coverage collection
Examen final de troisième année
【Redis】List类型
[从零开始学习FPGA编程-49]:视野篇 - 芯片是如何被设计出来的?
Pyinstaller打包pikepdf失败的问题排查