Bypassing authentication
There are various bypassing authentication methods such as capturing tokens and replaying them, client-side piggybacking, and cross-site request forgery. Some common tools include the Burp Suite and THC-Hydra for brute forcing attacks for password cracking that we'll briefly consider. THC-Hydra is an effectively fast, free, and legal login cracker developed for cyber security researchers and professionals to show how easy and vulnerable it is bypass certain authentication. It does require for certain parameters to be met such as the address IP, URL, form type, a username field, a password field, and failure response. We'll also be using the Burp Suite as a proxy, for example, but you can use any. You can launch it ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access