Burp Suite and Hydra vs DVWA

Поделиться
HTML-код
  • Опубликовано: 21 ноя 2024

Комментарии • 63

  • @tylercoan
    @tylercoan Год назад +11

    I swear RUclips algorithms are spying on me. Your video is timely. Just went over this topic in TCM's class.

    • @theGaryRuddell
      @theGaryRuddell  Год назад +1

      Oh the algorithm is DEFINITELY working the magic!

  • @teachmecyber
    @teachmecyber Год назад +1

    BurpSutie is a great tool to know. You can do so much with it.

    • @theGaryRuddell
      @theGaryRuddell  Год назад

      Yeah it’s incredible. There’s really not a competitor I know of??

  • @joshuakhan3409
    @joshuakhan3409 28 дней назад

    Explained burp better then when I tried to do it for a class 😅

  • @MHamidAshraf
    @MHamidAshraf 8 месяцев назад +2

    simple and quick.. thanks a lot

  • @pbrown22
    @pbrown22 Год назад +3

    Another Great video Gary

  • @nullowl1305
    @nullowl1305 Год назад +2

    Great to see you starting off this year with amazing content Gary !
    What's your take on different tools for Bruteforcing,lets say we have hydra,John the ripper and hashcat,how do you ideally choose between them I'm kinda confused sometimes,does it depends upon what exactly we looking for ?

    • @theGaryRuddell
      @theGaryRuddell  Год назад

      Yeah I’m recording a Hashcat video very soon. Hashcat is mainly used if you get hashes from say /etc/passwd or anywhere else for that matter, and you want to crack them. You can do it really cheap in the cloud these days. Hydra is great for CTFs and things like that, but you can’t really have much success on enterprise systems because of MFA and Fail2Ban etc. John the Ripper is similar to Hashcat in many ways at a basic level.

    • @nullowl1305
      @nullowl1305 Год назад

      @@theGaryRuddellOkay got it thanks 👍🏻

  • @petregmd
    @petregmd Год назад +2

    Nice video, Gary! Do you mind if I write a short blog post based on this video? I will mention the source. 🙂

    • @theGaryRuddell
      @theGaryRuddell  Год назад +1

      Yeah sure! I’d love to see where you share it in the end. I’m on LinkedIn too if it’s easier to talk there 😊

    • @petregmd
      @petregmd Год назад

      @@theGaryRuddell Thank you, Gary. I will share it on LinkedIn. 🙂

  • @Liam-d8v
    @Liam-d8v Год назад +1

    KEEP UP THE GOOD WORK

  • @diogorech
    @diogorech Год назад

    Thank you for sharing your knowledge! I followed the steps of the video and always get 16 valid passwords, none of which were actually the correct one. Where should I start to solve this problem ?

    • @theGaryRuddell
      @theGaryRuddell  Год назад

      Hey it’s hard to say from here! But I’d recommend watching other tutorials to see if something clicks!

  • @jejakperetas
    @jejakperetas Год назад +1

    🙂 thank you

  • @noureldinehab2686
    @noureldinehab2686 Год назад +2

    💙

  • @Stuff-morestuff
    @Stuff-morestuff 8 месяцев назад

    whatever I do I can't get username=test&password=test&login=login to show up

  • @gerdmuller8258
    @gerdmuller8258 9 месяцев назад +1

    ciao, io sono stato hackerato su outlook. Ho seguito il tuo video che si può fare su outlook?

    • @theGaryRuddell
      @theGaryRuddell  9 месяцев назад

      Grazie per la visione, se vieni violato su Outlook, dovrai parlare con il supporto Microsoft.

    • @gerdmuller8258
      @gerdmuller8258 9 месяцев назад

      @@theGaryRuddell ho provato contattare con il supporto su Xbox Microsoft. Hanno detto che non si può recuperare account. Quindi il tuo video si può recuperare l'account Outlook?

    • @theGaryRuddell
      @theGaryRuddell  9 месяцев назад

      @@gerdmuller8258 Se Microsoft non riesce a recuperare un account compromesso, nessun altro può farlo. Scusa amico!

  • @MehmoodKing-j2y
    @MehmoodKing-j2y 10 месяцев назад

    What is the format if website start from https mean secure

    • @theGaryRuddell
      @theGaryRuddell  10 месяцев назад

      Sorry I don’t understand the question

  • @ReligionAndMaterialismDebunked
    @ReligionAndMaterialismDebunked Год назад +1

    Early :3

  • @eTqXfc6ODY7g8bDV
    @eTqXfc6ODY7g8bDV Год назад +1

    Hello I have two problems. I look for my password but I don't need to have a login. I only need a password to log in. So how I do to make an attack without the flag -l or -L. Morover my request body for the http-post-form is "username=admin&password=c9bcacd403244145cea61db556e9efd0" and hydra say that "the variables argument needs at least the strings ^USER^, ^PASS^, ^USER64^ or ^PASS64^. I don't kwon how to do. Can you help me ?

    • @theGaryRuddell
      @theGaryRuddell  Год назад +1

      Try using another tool like Brutus or Burp Suite. I’m not sure on this one!

    • @eTqXfc6ODY7g8bDV
      @eTqXfc6ODY7g8bDV Год назад +1

      @@theGaryRuddell Ok but do you know how I can do if I only need a password to log in and not a login ? How can I process ?

    • @theGaryRuddell
      @theGaryRuddell  Год назад

      Brutus and Burp have that functionality!

    • @eTqXfc6ODY7g8bDV
      @eTqXfc6ODY7g8bDV Год назад

      @@theGaryRuddell ok thank you. I will test them later.

    • @Bailey-k2j
      @Bailey-k2j 10 дней назад +1

      c9bcacd403244145cea61db556e9efd0 cracked: fzfzfz 😁

  • @U-shapeMgall
    @U-shapeMgall 6 месяцев назад

    What about the app that I download how to find the name and password

  • @BaconGod078
    @BaconGod078 2 месяца назад

    Out of curiosity, if you tried to hack Google or Facebook or any other majorly reputable company that'd get you jailed for years, would you get caught if you're running the brute force program for a login page through kali linux in a virtual machine?

    • @theGaryRuddell
      @theGaryRuddell  2 месяца назад

      Yes. You certainly would if you pushed hard enough.

    • @BaconGod078
      @BaconGod078 2 месяца назад

      @theGaryRuddell what if the request is run through a vpn and/or tor browser while inside the VM?

    • @theGaryRuddell
      @theGaryRuddell  2 месяца назад

      Try it and find out? 😝 brute forcing is dumb

  • @SnappyTTV
    @SnappyTTV Месяц назад

    I’m so confused, lol. Can I like email you with questions?

    • @theGaryRuddell
      @theGaryRuddell  Месяц назад +1

      They’ll be too hard to answer. Best option is chatGPT and you can feed it any error messages

  • @joebol2036
    @joebol2036 7 месяцев назад

    you did not cover the other important aspect re users and passwords files. Where/how did you get them?

    • @theGaryRuddell
      @theGaryRuddell  7 месяцев назад

      Correct. I did not. Have you Googled “where can I find username and password combinations”?

  • @Drluxurious
    @Drluxurious 7 месяцев назад

    will this work to hack an old Gmail account? if yes how? forgot the password to my old Gmail account.

    • @theGaryRuddell
      @theGaryRuddell  7 месяцев назад +1

      Whether it’s an old account or not, you’re hacking Google. That’s stupid. Just email customer support and prove it’s your old account.

  • @Bailey-k2j
    @Bailey-k2j 10 дней назад

    UGH!!!!!!! I keep getting MITM detected.

  • @MdTanzidAhmed-y1g
    @MdTanzidAhmed-y1g 8 месяцев назад

    Kali Linux,Can I hack Facebook account suing this

  • @PCs454
    @PCs454 8 месяцев назад

    why is the audio so quiet even at 100% volume ;//////

    • @theGaryRuddell
      @theGaryRuddell  8 месяцев назад

      It isn’t for me. Make sure your RUclips volume AND your computer volume are right?

    • @PCs454
      @PCs454 8 месяцев назад

      @@theGaryRuddell both are on 100% and i got a notification and it scared me as it was so loud,
      its just youtube is acting weird. and it affect other videos too..

    • @theGaryRuddell
      @theGaryRuddell  8 месяцев назад

      @PCs454 😂
      Yeah it works fine for all of my devices.

  • @harijs6263
    @harijs6263 Год назад +1

    Hi, i sent you an email, if you are able to reply, it would be great!