The Wayback Machine - https://web.archive.org/web/20201125191525/https://github.com/topics/password-cracking
Skip to content
#

password-cracking

Here are 62 public repositories matching this topic...

jhertz
jhertz commented Apr 17, 2020

Hi All,

So I'm trying to use hydra to bruteforce a login on a system that uses custom http headers to receive the username and password. Hydra does not seem to be doing substitution of ^USER^ and ^PASS^ when used as HTTP headers. If I issue issuing a call to hydra like this:

hydra "http-post://0.0.0.0:8000/:H=username\:^USER^:H=password\:^PASS^" -l admin -p admin

I see the following r

Kaonashi
Sc00bz
Sc00bz commented May 6, 2019

You should order masks by efficiency (occurrences/key_space) because this will lead to the less guesses to crack passwords.

Looking at the top 5:
https://github.com/kaonashi-passwords/Kaonashi/blob/5239bd333ed34993b43126a4499606ba70086034/masks/kaonashi_masks_numbered.txt#L1-L5

And ordering just the 1000 in kaonashi_masks_numbered.txt by efficiency the top 5 are now:

673407:?u?u?u?u

Improve this page

Add a description, image, and links to the password-cracking topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the password-cracking topic, visit your repo's landing page and select "manage topics."

Learn more

You can’t perform that action at this time.