Brute forcing login pages using Burp Intruder

Let us not waste time and quickly head on to a few of the applications to see how we can use Burp to brute force credentials on authentication pages. The first application we will brute force is OrangeHRM in the OWASP BWA list. 

Once you open the app, you will be shown a login page; there is no option to register this application. So we have two options, either test for SQL injection or brute-force dictionary-based passwords with the hope that one of the username and password combinations hit valid. The following screenshot shows the homepage:

The default credentials of this application is admin ...

Get Hands-On Application Penetration Testing with Burp Suite now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.