Пропускане към основното съдържание

OWASP-AGI Automation for Gathering Information-Kali Linux 2020.2

+ custom report...
NOTE: The reported files are stored into your /home/zapcontainer directory
they are two if you decide to export .HTML report(.html and zap.xml).
WARNING: You should save these files somewhere else!
After the program has finished his work!


Popular Posts

DVWA - Brute Force (High Level) - Anti-CSRF Tokens

This is the final "how to" guide which brute focuses Damn Vulnerable Web Application (DVWA), this time on the high security level. It is an expansion from the "low" level (which is a straightforward HTTP GET form attack). The main login screen shares similar issues (brute force-able and with anti-CSRF tokens). The only other posting is the "medium" security level post (which deals with timing issues). For the final time, let's pretend we do not know any credentials for DVWA.... Let's play dumb and brute force DVWA... once and for all! TL;DR: Quick copy/paste 1: CSRF=$(curl -s -c dvwa.cookie "" | awk -F 'value=' '/user_token/ {print $2}' | cut -d "'" -f2) 2: SESSIONID=$(grep PHPSESSID dvwa.cookie | cut -d $'\t' -f7) 3: curl -s -b dvwa.cookie -d "username=admin&password=password&user_token=${CSRF}&Login=Login" "192.168.1


Exploiting after error checking. NOTE: Especially for the curious people!

insmod_block module by nu11secur1ty * Beta