Scanning for weak/default passwords in web servers

Tess Sluijter

Well-known member
Apr 1, 2020
333
1
479
the Netherlands
www.kilala.nl
Define "in web servers".

If you mean web applications, or HTML forms, or HTTP basic auth, then yes absolutely. Something like Hydra has existed for years. Configure the authentication, feed it a wordlist and let it rip. And it'll even work for different protocols.
 

Innocent V. Mulula

Well-known member
Nov 10, 2021
24
43
Define "in web servers".

If you mean web applications, or HTML forms, or HTTP basic auth, then yes absolutely. Something like Hydra has existed for years. Configure the authentication, feed it a wordlist and let it rip. And it'll even work for different protocols.
Thanks @Tess Sluijter
 

Brian Ford

Well-known member
  • Jul 15, 2021
    63
    110
    Flagler Beach, FL
    ccie2106.net
    Define "in web servers".

    If you mean web applications, or HTML forms, or HTTP basic auth, then yes absolutely. Something like Hydra has existed for years. Configure the authentication, feed it a wordlist and let it rip. And it'll even work for different protocols.
    Great suggestion Tess! There are also a couple of different implementations of Hydra using Docker. That would be a great way to demo the use of containers.

    https://hub.docker.com/r/linuxserver/hydra

    and