May 2017
Intermediate to advanced
416 pages
21h 33m
English
Use the following Nmap command to perform brute force password auditing against a resource protected by HTTP's basic authentication:
$ nmap -p80 --script http-brute <target>
The results will return all the valid accounts that were found (if any):
PORT STATE SERVICE REASON 80/tcp open http syn-ack | http-brute: | Accounts | admin:secret => Valid credentials | Statistics |_ Perfomed 603 guesses in 7 seconds, average tps: 86
Read now
Unlock full access