RE: brute force http post session with cookies

From: Adi Sharabani (asharabani@watchfire.com)
Date: Wed Aug 15 2007 - 04:37:22 EDT


Hi Chris,

You can also use the Authentication Tester which has a simple but strong
GUI interface. It allows you to record a login request, and then gives
you different abilities to enumerate both username and password. For
example, you can configure it to enumerate all passwords that contains
two words (found in a dictionary) separated by a number.
The tool can be used for free and bundled with AppScan's Trail version:
        http://www.watchfire.com/products/appscan/powertools.aspx

Good luck,
/AdiSh

Christian Perst wrote:
> Hi,
>
> is there a tool like hydra, but which can be used for http post
> sessions? It should be a brute force tool, where cookie handling
> is implemented.
>
> Thanks for the hint,
> Chris
>
>

------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------



This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 10:58:02 EDT