BRUTEFORCE (III): ATTACKING A WEB SERVER WITH HYDRA
- Layout for this exercise:
data:image/s3,"s3://crabby-images/4bc7e/4bc7e834b2decc588cc2c21b6c1d5caec3b935c1" alt=""
- Enumerating the victim, the attacker Kali checks that the port 80 is open at the victim machine:
data:image/s3,"s3://crabby-images/9e32b/9e32bd6281c267984d74cf7cad8780ff108e768e" alt=""
- Connecting to the DVWA Vulnerability: Brute Force page:
data:image/s3,"s3://crabby-images/9194d/9194d20ee80829f8c3e711a98a388835df9b378b" alt=""
- Configuring a proxy server at the attacker machine:
data:image/s3,"s3://crabby-images/b138e/b138eead9d156c12d968d9e2d74a6b16fd75a14b" alt=""
- Launching Burp:
data:image/s3,"s3://crabby-images/375fc/375fccb674234befa2b75bd3ea2fa180aaa69a05" alt=""
- Now, clicking Login at the DVWA web page, even not entering any username or password:
data:image/s3,"s3://crabby-images/9ae08/9ae0835bbdaaa37b3ab102315e0923c308055f93" alt=""
- Burp intercepts the connection trial:
data:image/s3,"s3://crabby-images/6c21e/6c21eaedba0323103e9161d743e5d4113d188668" alt=""
- There are two important pieces of information data:
i) method GET is used for the login script:
data:image/s3,"s3://crabby-images/0ff6a/0ff6ac806bc96fa6637de01869a7582f77ceb763" alt=""
ii) an ID session cookie is generated by the Web server:
data:image/s3,"s3://crabby-images/f2df1/f2df1e2d6f8bc311769bd1d9d7ab676dbdfba6d9" alt=""
- Now, launching an Hydra command (including the intercepted information by Burp) the result of the attack is successful:
data:image/s3,"s3://crabby-images/b8929/b89291a8f753db560a971f5369ca0cc9681d5b81" alt=""
- The wordlist used in the attack is provided by Kali, and it is composed of 182 lines, including the right password "password":
data:image/s3,"s3://crabby-images/d0025/d00255c759e095b79588e2475fd4d99ddb027d37" alt=""
data:image/s3,"s3://crabby-images/c0993/c09938ac75135c51da1cc560fafe5b8df2299e03" alt=""
data:image/s3,"s3://crabby-images/0197c/0197cbdfd9d2969828c2f7edecf016c7a787c50e" alt=""