<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: How to brute force http forms in windows</title>
	<atom:link href="http://www.sillychicken.co.nz/2011/05/how-to-brute-force-http-forms-in-windows/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.sillychicken.co.nz/2011/05/how-to-brute-force-http-forms-in-windows/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=how-to-brute-force-http-forms-in-windows</link>
	<description>The boat engine makes noise.....</description>
	<lastBuildDate>Tue, 21 Feb 2012 20:13:54 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Sillychicken</title>
		<link>http://www.sillychicken.co.nz/2011/05/how-to-brute-force-http-forms-in-windows/#comment-272</link>
		<dc:creator>Sillychicken</dc:creator>
		<pubDate>Sun, 15 Jan 2012 06:29:40 +0000</pubDate>
		<guid isPermaLink="false">http://wordpress.sillychicken.co.nz/?p=35#comment-272</guid>
		<description>Link removed, yes it should be renamed I will do an update to make the title reflect the attack.</description>
		<content:encoded><![CDATA[<p>Link removed, yes it should be renamed I will do an update to make the title reflect the attack.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dave</title>
		<link>http://www.sillychicken.co.nz/2011/05/how-to-brute-force-http-forms-in-windows/#comment-271</link>
		<dc:creator>Dave</dc:creator>
		<pubDate>Sun, 15 Jan 2012 05:37:43 +0000</pubDate>
		<guid isPermaLink="false">http://wordpress.sillychicken.co.nz/?p=35#comment-271</guid>
		<description>Why is this listed as a &quot;brute force&quot; attack if you need a dictionary file?

Also, &quot;max25&quot; above, you neglect to mention that the &quot;uniqpass&quot; password file mentioned on that site is not FREE!  That scam site (which is getting plugged in the comments of every single hydra post) is asking for $4 to get a copy of that file.  Fuck them.</description>
		<content:encoded><![CDATA[<p>Why is this listed as a &#8220;brute force&#8221; attack if you need a dictionary file?</p>
<p>Also, &#8220;max25&#8243; above, you neglect to mention that the &#8220;uniqpass&#8221; password file mentioned on that site is not FREE!  That scam site (which is getting plugged in the comments of every single hydra post) is asking for $4 to get a copy of that file.  Fuck them.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rogan</title>
		<link>http://www.sillychicken.co.nz/2011/05/how-to-brute-force-http-forms-in-windows/#comment-237</link>
		<dc:creator>Rogan</dc:creator>
		<pubDate>Tue, 06 Dec 2011 12:47:45 +0000</pubDate>
		<guid isPermaLink="false">http://wordpress.sillychicken.co.nz/?p=35#comment-237</guid>
		<description>Unfortunately, this does not work on all versions of Joomla, because the Admin logon page includes a random token that gets updated with every request, and there is no mechanism to specify this in Hydra.

i.e. 

&quot;/administrator/index.php:username=^USER^&amp;passwd=^PASS^&amp;lang=&amp;option=com_login&amp;task=login&amp;cec21c04bff97e66ecc0068f5cb4507d=1:do not match&quot;

The token &quot;cec21c04bff97e66ecc0068f5cb4507d&quot; needs to change with every request. While hydra can get a new cookie if required, there is no mechanism to tell it to get new form values/parameters on each submission.

Pity.</description>
		<content:encoded><![CDATA[<p>Unfortunately, this does not work on all versions of Joomla, because the Admin logon page includes a random token that gets updated with every request, and there is no mechanism to specify this in Hydra.</p>
<p>i.e. </p>
<p>&#8220;/administrator/index.php:username=^USER^&amp;passwd=^PASS^&amp;lang=&amp;option=com_login&amp;task=login&amp;cec21c04bff97e66ecc0068f5cb4507d=1:do not match&#8221;</p>
<p>The token &#8220;cec21c04bff97e66ecc0068f5cb4507d&#8221; needs to change with every request. While hydra can get a new cookie if required, there is no mechanism to tell it to get new form values/parameters on each submission.</p>
<p>Pity.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sillychicken</title>
		<link>http://www.sillychicken.co.nz/2011/05/how-to-brute-force-http-forms-in-windows/#comment-165</link>
		<dc:creator>Sillychicken</dc:creator>
		<pubDate>Mon, 28 Nov 2011 09:22:25 +0000</pubDate>
		<guid isPermaLink="false">http://wordpress.sillychicken.co.nz/?p=35#comment-165</guid>
		<description>Valid point :-o</description>
		<content:encoded><![CDATA[<p>Valid point <img src='http://www.sillychicken.co.nz/wp-includes/images/smilies/icon_surprised.gif' alt=':-o' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: iDOn</title>
		<link>http://www.sillychicken.co.nz/2011/05/how-to-brute-force-http-forms-in-windows/#comment-159</link>
		<dc:creator>iDOn</dc:creator>
		<pubDate>Sun, 27 Nov 2011 19:48:51 +0000</pubDate>
		<guid isPermaLink="false">http://wordpress.sillychicken.co.nz/?p=35#comment-159</guid>
		<description>this is not a brute force mode because you are using a list of passwords, it&#039;s called dictionary attack</description>
		<content:encoded><![CDATA[<p>this is not a brute force mode because you are using a list of passwords, it&#8217;s called dictionary attack</p>
]]></content:encoded>
	</item>
</channel>
</rss>

