Web Form Password Brute Force with FireForce

I spent many hours today playing around with DVWA – (Damn Vulnerable Web App), from Randomstorm, brushing up on my web app pentesting skills, to be honest its been a long time and I really need to get back on top of this.

Anyways, after going through all the usual SQL injection, XSS stuff I thought I’d have a go at the brute forcing part of the app.

Well after what seemed like days I gave up, with little or no success – I’d tried the usual suspect for ‘bruting’ the password – Hydra.

Until I Googled around and found a Firefox addon called ‘Fireforce’ the article that I found is here Dark Reading

The website for the tool is here SCRT ,there is a manual in english too. Continue reading

RSMangler – Free Tool from RandomStorm

In my previous post I mentioned a company called RandomStorm and some of the products they have, well one of those products is free and its called RSMangler, basically is word-list generator with a few extras, that can be used with tools like John The Ripper.

 

Its incredibly easy to use and creates really excellent word-lists in no time all.

Continue reading