How Easy Is It For Hackers To Brute Force Login Pages?!

Поделиться
HTML-код
  • Опубликовано: 7 фев 2025
  • // Membership //
    Want to learn all about cyber-security and become an ethical hacker? Join this channel now to gain access into exclusive ethical hacking videos by clicking this link: / @loiliangyang
    // Courses //
    Full Ethical Hacking Course: www.udemy.com/...
    Full Web Ethical Hacking Course: www.udemy.com/...
    Full Mobile Hacking Course: www.udemy.com/...
    // Books //
    Kali Linux Hacking: amzn.to/3IUXaJv
    Linux Basics for Hackers: amzn.to/3EzRPV6
    The Ultimate Kali Linux Book: amzn.to/3m7cutD
    // Social Links //
    Website: www.loiliangya...
    Facebook: / loiliangyang
    Instagram: / loiliangyang
    LinkedIn: / loiliangyang
    // Disclaimer //
    Hacking without permission is illegal. This channel is strictly educational for learning about cyber-security in the areas of ethical hacking and penetration testing so that we can protect ourselves against the real hackers.

Комментарии • 607

  • @LoiLiangYang
    @LoiLiangYang  3 года назад +285

    You have the same password as hacker loi?

    • @shubhamkumar-wn2gj
      @shubhamkumar-wn2gj 3 года назад +5

      yes 😂 but of my mobile hotspot

    • @likitadevi
      @likitadevi 3 года назад +9

      @@shubhamkumar-wn2gj Wait you shouldn't have answered that.

    • @TrixieTheGreat
      @TrixieTheGreat 3 года назад +7

      I usually have a password of 3 words in different languages divided by special symbols and the words themselves have "tactical" typos in them.

    • @ismail.dalhatu
      @ismail.dalhatu 3 года назад +3

      My Password: 123LoiLiangYangHack456ICanHackNow 😂😂😂😂😂😂

    • @videocorner2498
      @videocorner2498 3 года назад +3

      Make video on
      How hacker hack firebase data

  • @elder2623
    @elder2623 3 года назад +340

    Ive learned more about burpsuite in this video than I would ever learn in a 20 min tutorial. Keep it up!

    • @zboy.05
      @zboy.05 3 года назад +4

      Fr i just learned more than most videos ive watched on hacking

    • @mouadabid1272
      @mouadabid1272 3 года назад

      dude RTFM

    • @creativegamershopnil1879
      @creativegamershopnil1879 3 года назад +1

      Burp suite and 20 minutes good student

    • @VladmirPutin232
      @VladmirPutin232 3 года назад

      @@creativegamershopnil1879 😂😂😂🤣

    • @ethanbousfield76
      @ethanbousfield76 Год назад +1

      did 5 weeks of labs on burp suite as part of my degree but the lecturer massively over complicated everything, I've learned more from this guy and HTB than I have at uni

  • @algertislamaj5925
    @algertislamaj5925 Год назад +26

    Finally someone who gets straight at the point u deserve a subscriber

  • @mohammedissam3651
    @mohammedissam3651 3 года назад +9

    I don’t learn form you to hack users rather I learn from you to be a great cyber security and dive into hackers mind. Thank you , god bless you.

  • @edmonddantes218
    @edmonddantes218 3 года назад +24

    you are the best teacher loi , really so easy so simple and charismatic i see people look at your videos as movies . keep it up i went to school 10 yrs and never learned as much as 40 minutes watching you !

  • @warrenmiranda4943
    @warrenmiranda4943 3 года назад +11

    Setting your password to 1234 is like training self defence for so many years and end up dying because of car accident.

  • @likitadevi
    @likitadevi 3 года назад +77

    Imagine being caught by a cyber police who saw that intro.

  • @portia-assamensis
    @portia-assamensis 2 года назад +4

    You are the GOAT. The amount of useful knowledge you just crammed into a 5 minute video is beautiful

  • @MrMiRou
    @MrMiRou 3 года назад +4

    dude why are you the best ?!!
    the lessons become easyyyyy if you explain it !!!
    I really enjoyed these 4:29mins and I learned something from you thnx man

  • @BarelyGoodTV
    @BarelyGoodTV 3 года назад +63

    I've been thinking lately that one could possibly train an AI to learn password patterns to make brute force attempts viable which is a scary thought

    • @keepyoursins
      @keepyoursins 3 года назад +14

      Yeah, if you setup a profile from a person with stuff like family members, pets and so on, the AI can then use all of those points in passwords attempts if that makes sense

    • @BarelyGoodTV
      @BarelyGoodTV 3 года назад +3

      @@keepyoursins yea training it for a specific target would be especially deadly

    • @keepyoursins
      @keepyoursins 3 года назад +6

      @@BarelyGoodTV wanna team up? 👀 Jk

    • @BarelyGoodTV
      @BarelyGoodTV 3 года назад +1

      @@keepyoursins lmao

    • @Ranburu
      @Ranburu 3 года назад +1

      @@martiict350 Nah, he talking about automatic way to do this

  • @Gupatik
    @Gupatik 3 года назад +3

    now I get names and stuffs thank you, I'm literally starting my career here with you.
    Thank you.

  • @sleekbr7666
    @sleekbr7666 3 года назад +2

    This is a basic eye opener. For advanced attacks you have to rotate proxies, have a huge password list, get a good GPU, make api configs to bypass ssl pinning etc. Good though

  • @captainforyoubruh
    @captainforyoubruh 10 месяцев назад +2

    Bro love your vibes and enthusiasm.
    Just subscribed for sure💯

  • @rubix187
    @rubix187 3 года назад +48

    Coders, programmers and hackers will inherit the earth

    • @whoisPremier
      @whoisPremier 3 года назад +2

      literally.

    • @ggLP42
      @ggLP42 3 года назад +1

      @@whoisPremier and gamers

    • @ggLP42
      @ggLP42 3 года назад +1

      @@whoisPremier and gamers

    • @ggLP42
      @ggLP42 3 года назад +1

      @@whoisPremier and gamers

    • @curtisdesler2100
      @curtisdesler2100 3 года назад +1

      Very funny dude

  • @anupriyadayaratne
    @anupriyadayaratne 3 года назад +21

    Clean and Clear tutorials I ever seen . Thanks lot ..!!!

    • @rcgnetworks
      @rcgnetworks 3 года назад +2

      හැක් කරන්නතෙ හදන්නේ.යසයි බේසික පුටෝ යසයි 🙂👻

  • @kabandajamir9844
    @kabandajamir9844 3 года назад +1

    The world's best teacher may God reward you great

  • @m.r.d4550
    @m.r.d4550 3 года назад +3

    Would be nice if you made a tutorial literally starting from 0. How to install burpsuite, setup, can it be used on windows etc.

  • @dimerdim8403
    @dimerdim8403 3 года назад +4

    Awesome video man! Love how you been improving your videos format to a funnier way. keep it up..

  • @takingpictures4536
    @takingpictures4536 3 года назад +54

    thanks for the tut :) But instead of brute force, you actually used a dictionary attack ;)

    • @-AnyWho
      @-AnyWho 3 года назад +5

      brute force would have taken longer than video ...

    • @mihaisolomon2893
      @mihaisolomon2893 3 года назад +2

      a dictionary attack is still brute force

    • @takingpictures4536
      @takingpictures4536 3 года назад +6

      @@mihaisolomon2893 I do not consider dictionary attacks to be brute force attacks. In order to create a dictionary you purposfully craft strings which are likely to be used by humans. The same logic does not apply to brute force, which is the 'dumbest' form of attacking logins.

    • @daleryanaldover6545
      @daleryanaldover6545 3 года назад +4

      True, a dictionary would prove to be useless for unaccounted passwords. It would only work if say make a dictionary from pawned passwords and hope the user haven't change their password.
      Brute force is different, it will also take longer time since it will account for all possible combinations available for the password.
      So the step should be > go try register and account and purposely fail password validation in order to get an insight of possible password combinations, like how long is the min max strings, are special characters required, numbers? > then formulate the actual password generator pattern.
      Also most web apps now have request limiting that further slows down how much request you can send at a particular moment. Definitely will eat days or weeks, you might wanna go to vacation and still find the brute force command not finished by the time you get back.

  • @newbe379
    @newbe379 2 года назад +4

    i used this program and was hack the bank of america and take 1 trillion of dollars in my account simple like only use this software
    thanks for share

  • @Jupiterxice
    @Jupiterxice 3 года назад +1

    You simplified this tutorial with burpsuite i never could get to. Thank you for add tool

  • @janekmachnicki2593
    @janekmachnicki2593 2 года назад +1

    I brought your Udemy cours .So profesional so cool so stealthy lol.Thanks

  • @mahdiabedian6382
    @mahdiabedian6382 2 года назад +1

    the best person for hacking

  • @Drusher10
    @Drusher10 3 года назад +4

    his videos are always on point and always w8ing like a crazy for the next one!! keep going man1!

  • @Heavenig
    @Heavenig 3 года назад +3

    He's videos are sweet. I need student like me to compete with

  • @zgredfryd
    @zgredfryd 3 года назад +1

    I like Your videos a lot man! Funny beginning :D Straight to the point as always!

  • @imyoubutbetter9951
    @imyoubutbetter9951 3 года назад +4

    how do you set the foxy proxy to do that coz when i added it to chrome i only see log in my ip address and options

  • @evd8175
    @evd8175 16 дней назад +1

    how do you get that payload file of the most common passwords?

  • @EC4U2C_Studioz
    @EC4U2C_Studioz 5 месяцев назад

    I think it's about time to switch from passwords with or without MFA to passwordless passkeys, using instead the biometric method to get into phones, tablets, and computers in the first place to access the accounts in question. While using password managers that include MFA on the password manager itself can help, a passkey is preferred as they are the hardest for hackers to hack. It may be to the point that even a password at least 30 characters might no longer be secure enough.

  • @loginet1
    @loginet1 2 года назад +3

    How realistic is this? To find a username for a website and then use common simple passwords to hack the session? And if it is how can you defend against brute force? Logging IPs and blocking the attack if tried more than 3 times (get the error message) or blocking the whole range of IPS, allowing only some IPs. It will be good enough?

  • @VENOMOUS57
    @VENOMOUS57 2 года назад

    love the way you start your video don't say you know hacker Loi 😁

  • @pkpointurdu3793
    @pkpointurdu3793 3 года назад

    You have given very good information in terms of security. Thank u

  • @Sanjay_Venkatesan
    @Sanjay_Venkatesan 3 года назад +2

    Thanks a lot for your tutorial but most of real world web application has the Rate limit in there login .

  • @akhalaqmonis5178
    @akhalaqmonis5178 3 года назад

    This channel is really very informative and underrated.
    hope to see million subscribers soon.

  • @d3cryptor745
    @d3cryptor745 3 года назад +22

    You Are My Inspiration, Thanks For All The Things Hacker Loi ❤️
    The Way You Are Talking Is Just Love

    • @justmohamed7929
      @justmohamed7929 3 года назад

      name of books neer him pls

    • @johnmalugu487
      @johnmalugu487 3 года назад

      Hi, i wanna chart with you about cyber security can i get your contact or email?

  • @IsaPotaxii
    @IsaPotaxii Год назад +2

    What happened if there is a 2-step verification?

  • @darkcheq
    @darkcheq 3 года назад +4

    But this is not a real world hacking. I mean most of real sites have failed login attemps protection. How do you bypass that ?

    • @365hype
      @365hype 3 года назад +1

      Exactly. This guys full of shit. None of his videos are real world hacking examples. Nothing on RUclips is a real world hacking example. Xss, sql vuln, nmap etc.. all browsers protect against this type of stuff. The only real world hacking today is social engineering like phishing. Everything else is just for show.

    • @RelatableTom2
      @RelatableTom2 3 года назад

      @@365hype Do you assume that shit like that would be allowed on RUclips

  • @peeptube0
    @peeptube0 6 месяцев назад +1

    dear fbi: Idk who this man is i use his videos as asmr to fall asleep

  • @zugzwang2161
    @zugzwang2161 3 года назад +2

    I can’t use any of these tools on my own network to practice or test it. Except wireshark so far. I’ll just stick to learning python 3 for now.

    • @seanfaherty
      @seanfaherty 3 года назад

      If you run windows you can try using virtual machines.
      A virtual machine for Kali or parrot and a virtual machine to attack.
      I was able to find metaspoitable3 in a VM compatible file… it was a bit easier
      Once you pick VMware or Vbox it will just be a matter of googleing every question and error code you’ll get.
      Good luck

  • @vivekmishra5692
    @vivekmishra5692 3 года назад

    I am from Nepal I love your teaching sir I also want to be like you and contribute for my country because of you I got a chance to learn many many important things you are awesome sirrrr lots of love and support from Nepal

  • @osadchuks
    @osadchuks 6 месяцев назад

    How do you handle cases with Burp Suite when there is a login attempt limit?

  • @user-wm8yz
    @user-wm8yz 2 года назад

    you're a great men ... thank u

  • @avijeetupadhyaya3885
    @avijeetupadhyaya3885 3 года назад +2

    if we use in real website login page
    withiut owner knowing
    what is the result ?are we ethical hacker or not

  • @camelotenglishtuition6394
    @camelotenglishtuition6394 2 года назад +1

    All well and good but most sites implement brute force protection, so this just doesn't work. An alternative would be to just change the response using burp to 302, and direct it to the location you want /admin etc by looking at the source code.

    • @jahnyewalker75
      @jahnyewalker75 Год назад

      Can you elaborate?

    • @camelotenglishtuition6394
      @camelotenglishtuition6394 Год назад +1

      @@jahnyewalker75 to be honest brute force isn't viable these days. This is especially true of ssh logins. Learning these techniques is antiquated and nonsensical tbh. If you want to bypass logins there are plenty of other ways. Studying the source is going to get you far further in accessing data. Plus if you just want to see user A's data, it's much easier to sign up, authenticate as a user and then try a bola attack to see user A's data. Password spraying can also help in getting access so you don't need to sign up. You can also try token forgery ( if you're messing with an api), cookie injection, malicious links.. I mean the list is endless but this video is far from a realistic real world example.

  • @RandomScientist
    @RandomScientist Год назад

    Can't believe a person can teach burp suite in 5 mts MashaAllah.

  • @zakof10
    @zakof10 3 года назад +1

    hi mr loi can you pls show us how to use brute force with hydra ?
    like any wepsite .

  • @SteveSultanian
    @SteveSultanian 2 года назад

    Loi, I'm new to this but am determined to learn as much as I can from your tutorials.. I have an issue where someone has hijacked a facebook account and is causing all kinds of problems.. I know youve shared how to go after passwords, just not for FB accounts. Can you please assist me on this with either a response or tutorial specifically for this situation.. It's getting bad, as this person is requesting money from my friends and family, playing as if its me doing this.. Thank you in advance..

  • @ghtrends3606
    @ghtrends3606 3 года назад

    And please what kind of browser do you use

  • @filmies7021
    @filmies7021 3 года назад +2

    Sir , show us Admin panel bypass .

  • @ManishKumar-ue5il
    @ManishKumar-ue5il 3 года назад +1

    Everything is okay but what tools you are using... Please make a video on it🙏🙏

  • @Sami-xh1zc
    @Sami-xh1zc 2 года назад

    Man you are awesome ! Thank you

  • @JUSHI1221
    @JUSHI1221 Год назад

    i don't get the part of the terminal. what terminal did he lunched it?

  • @elxyser
    @elxyser 3 года назад

    can u help me pls? wich abilities do i've to learn for basic CTFs? i need you advice

  • @aditibhatiya2204
    @aditibhatiya2204 6 месяцев назад

    My question is that if id password not in common password list so what can i do ?

  • @MALAYAPH24
    @MALAYAPH24 3 года назад

    Thanks a lot for your wonderful tutorials

  • @kundan.rajput
    @kundan.rajput 3 года назад

    sir which will be the best book to learn hacking

  • @deathstar3006
    @deathstar3006 2 года назад +18

    What if their password isn't in the list of common passwords

    • @hansjurgens2263
      @hansjurgens2263 Год назад +8

      The title of the video literally sais "Bruteforce"... do you know what bruteforcing is?

    • @Hackazillarex
      @Hackazillarex Месяц назад +2

      If the password isnt on the list, he cant get in.

    • @Squeeze827
      @Squeeze827 Месяц назад +2

      Use your brain

    • @scooperlosses4634
      @scooperlosses4634 Месяц назад +1

      the only way is to generate every single password. this gonna take a while

  • @SadhanandhaReddyEedara
    @SadhanandhaReddyEedara 6 месяцев назад

    bro! i getting one problem in this video. the problem is when im start attack it is executing a payloads after that it will be showing all payloads are valid. there is no invalid payloads. can you please explain how can i solve it. im waiting for your reply bro.

  • @marksGSJnr
    @marksGSJnr 3 года назад

    Burp suite.. is your site running on a local sever..?

  • @mariamakter8109
    @mariamakter8109 3 года назад

    Do i need deep knowledge about vlan for hacking ?

  • @dineshtechtuts9676
    @dineshtechtuts9676 3 года назад

    whats is the extension used and name to add in firefox ???

  • @m_u_s_i_c.f_a_n
    @m_u_s_i_c.f_a_n Год назад

    Pleaseee what do you use for that ??

  • @mlcdpriest5061
    @mlcdpriest5061 3 года назад

    Please which browser are you Using

  • @memorysmelody4589
    @memorysmelody4589 Год назад

    I have added the extension of foxyproxy but the burpsuite option isn't showing. Any solution !!??

  • @kaneki_ken_07
    @kaneki_ken_07 3 года назад

    With burpsuit we get foxyproxy or we have to download it differently, I am really confused in that part, rest is as clear as glass

  • @captainforyoubruh
    @captainforyoubruh 10 месяцев назад

    It is only recommend on linux to carry out burpsuite??

  • @T__12
    @T__12 7 месяцев назад

    If I switch on burpsuite or foxy proxy the other website im testing goes offline and doesnt respond, any solutions?

  • @shibbyshaggy
    @shibbyshaggy 3 года назад

    How to do that on a webpage that locks you out after 4 failed attempts? Also how didi it brute force and where was setup for that?

  • @harshitpal4996
    @harshitpal4996 3 года назад

    Do this work for social media platforms too..

  • @arknan9624
    @arknan9624 3 года назад +1

    Bien tes vidéos mais ce genre de hack ne peut être fais que si tu as accès au pc distant puisqu'il faut utiliser burpsuit.. Donc ça ne sert pas à grand chose

  • @darkclown2267
    @darkclown2267 2 года назад

    Sir can we do this in any site or just in bwapp

  • @lucasez4782
    @lucasez4782 3 года назад

    Hacker loi do u need a terminal to get burpsuite or can u get it on windows 10:)

  • @Stadiyana18
    @Stadiyana18 2 года назад

    in going to use this for "educational purposes" only ;)

  • @strongman7940
    @strongman7940 Год назад

    what if i use login attempt on a lockout address this my help me right ?

  • @prodbyd1972
    @prodbyd1972 Год назад

    Does it work the same if the site says enter username or email ?

  • @sogodtambay_3350
    @sogodtambay_3350 2 года назад

    I need to know all the tool using .. imma download them

  • @ajayparkarexhibitsolutions
    @ajayparkarexhibitsolutions Год назад

    Dude he is really awesome😭😎😎✌

  • @saeidmansorinia845
    @saeidmansorinia845 3 года назад

    your best of the best man

  • @typicalneko3348
    @typicalneko3348 15 дней назад

    HOLY SHIT THANK YOU! I CAN FINALLY REPORT SOMETHING GOOD TO MY SUPERVISOR

  • @fate5624
    @fate5624 2 года назад

    you didnt explain why foxy proxy is needed or even if

  • @ElementalEu
    @ElementalEu 2 года назад +1

    is it possable to get into my gmail saccount using this?

  • @QadriHarris
    @QadriHarris 3 года назад

    Very clear understanding tutorial

  • @michealphiri9383
    @michealphiri9383 2 года назад

    Is it possible to do this without kali linux?

  • @wowanimalspro3066
    @wowanimalspro3066 Год назад

    Awesome bro ❤❤❤

  • @Richi.Espinaca
    @Richi.Espinaca 3 года назад

    How can I have the foxyproxy? Any video?

  • @xxploit7382
    @xxploit7382 3 года назад

    you should have 1 million subs

  • @yogitaraut4107
    @yogitaraut4107 3 года назад +1

    Hey man you should do a coplab with Networkchuck!!!

  • @jorgefigueroa3536
    @jorgefigueroa3536 3 года назад

    Loi Liang Yang man, have a question hope an answer :)
    This way works even if the application has a max login attempts ? cause i think no, but maybe i am wrong.
    Not thinking to do it obviously ;) hahaha.
    thanks for teaching us, u rock.
    Regards.

  • @nicolasciani1933
    @nicolasciani1933 3 года назад

    i have a problem with burp suite, and its that it cant load a big dicctionary.... (im triyng with juice shop)

  • @lkjhgfd1504
    @lkjhgfd1504 2 года назад

    Is that any way to know the current admin password windows 7 without change it or log in without know the password
    every time i need to install a software or program i need admin permission is very annoying
    please

  • @ougksout5446
    @ougksout5446 2 года назад

    Can be used to router page also;

  • @drakegad7147
    @drakegad7147 3 года назад

    can u make a video about the stereotypes received as a cyber-security professional

  • @davidmartinez6347
    @davidmartinez6347 3 месяца назад +1

    Have to be on same network for it to work. Don’t waste your time

  • @venaculaporter9825
    @venaculaporter9825 2 года назад

    What terminal do you use

  • @Zeix02
    @Zeix02 3 года назад

    What is with ip blocking? This attack work when the developer records the false login counts from the same ip address?

  • @sirgesound
    @sirgesound 3 года назад

    As you requested, my password is "12345678½"...👀🙄🤨🤔😅🙃
    Great segment...as always. 👍🏽

  • @watchwatc
    @watchwatc Год назад

    take those skill to bypass captcha its very hard to do that it requires trained ai to solve those easy captchas

  • @xrop116
    @xrop116 3 месяца назад

    I am facing an error when I open the brusuite internal browser and I turn intercept mode on and try to open my router web page takes forever and still not load when I turn the mode off it worked then after loading the login page I turn the mode on again and put wrong user and password I just won't try to login like the page is stuck but when I turn intercept mode off I work completely fine. Can any one have the same issue please help me

  • @motivationalai1420
    @motivationalai1420 3 года назад

    Thank my teacher 👨‍🏫

  • @chrismutuma2858
    @chrismutuma2858 Месяц назад

    Hey loi,,,please explain how hybrid attacks works...with experiment ofc as always 💯