Sentry Cracking 04-02-2014, 05:09 PM
#1
Hi!
As requested; I am now posting a tutorial on how to crack with Sentry MBA (thank you, @Aurora).
Having written this; it seems quite long; but it's mostly filler text, so don't worry about that
What you will need:
- Sentry MBA (DL link)
- A config for your desired site (I won't be using any example, PM me if you need one)
- A combo list (at least for this tutorial)
- A live proxy list (used for the cracking part)
- Some time for your computer to crack (like when you're at work/school or overnight)
The process
Sentry is a cracking program for any site that doesn't use any security (captchas and alike) for their logins.
What we'll do in this guide; is to use a multiple proxy servers and username/password combinations to eventually find a couple accounts that work.
Pros with cracking: The upside of cracking with MBA is that we don't need lots of knowledge about website structuring (unless we're writing our own configuration files).
Cons: The downside with this method is that, we don't have a huge successrate compared to DB exploits, where we can get a list of all users. A decent 10% successrate is what I usually hope for, but that's on the high-end of what you should be expecting.
Getting started
Okay, so when we open Sentry, we get a window looking like this:
![[Image: z1PrWL9.png?1]](http://i.imgur.com/z1PrWL9.png?1)
You may want to make sure all check boxes comply with mine, unless you know what you're doing
So, now we want to load a Config ("snapshot"). We do this by clicking this:
![[Image: blWsd0J.png?2]](http://i.imgur.com/blWsd0J.png?2)
Now select the config file for the site you're cracking.
The config file is basically a configuration which tells Sentry what and how to crack the website, since they don't all look the same.
Once we've opened that; we want to navigate to the "Lists" tab, and then click "Proxylist".
![[Image: WXZU0df.png?3]](http://i.imgur.com/WXZU0df.png?3)
Now open your proxy file (blue arrow).
What we need now, is the combo, which contains usernames and password for Sentry to try.
We get this by clicking the tab called "Wordlist", and click "open".
![[Image: Cc2AXHd.png?2]](http://i.imgur.com/Cc2AXHd.png?2)
Also, make sure you've selected "Combo list" in the drop-down list (blue arrow)
Great; now we've loaded everything we need to get crackin' ^^
Now we want to click the "Progression" tab, below "Lists".
![[Image: gglUIHt.png?2]](http://i.imgur.com/gglUIHt.png?2)
In the image above; note how the bots are set to 151. I usually go with ~100 bots, as that gives a good speed (slide it to change bot count).
When you've loaded that, just click the green refresh button to make sure everything's fine, and check the wordlist position at 1.
All checked and cross-checked; click the large yello lightning in the top left corner to start cracking, and then click "Start the Bruteforcer Engine!" to set it off.
The results
Now that we've been to work for a day, and get back to our finished machine, it's time to look at the different codes.
As you notice in the little windows down-right; we have loads of various info.
What we need for our results, though, is only the red section called "Results".
By "Hits", MBA refers to all accouts which worked, and you can log in with.
"Reds" has nothing to do with colour, but means any accounts after testing, the site redirects us to another page. This can in some cases mean success; so try one or two accounts is you get lots of reds.
The rest of these codes are not massively important, so I'll leave you with those.
The three digit codes on the left are simply what the website outputs after testing an account (in website code).
That's it
That's pretty much all there is to cracking website accounts with Sentry MBA, unless you go into writing configs or modifying beyond the basics.
Hope you get some account worth having (or selling), and please reply or PM me if there is something on which I wasn't clear.
As requested; I am now posting a tutorial on how to crack with Sentry MBA (thank you, @Aurora).
Having written this; it seems quite long; but it's mostly filler text, so don't worry about that

What you will need:
- Sentry MBA (DL link)
- A config for your desired site (I won't be using any example, PM me if you need one)
- A combo list (at least for this tutorial)
- A live proxy list (used for the cracking part)
- Some time for your computer to crack (like when you're at work/school or overnight)
The process
Sentry is a cracking program for any site that doesn't use any security (captchas and alike) for their logins.
What we'll do in this guide; is to use a multiple proxy servers and username/password combinations to eventually find a couple accounts that work.
Pros with cracking: The upside of cracking with MBA is that we don't need lots of knowledge about website structuring (unless we're writing our own configuration files).
Cons: The downside with this method is that, we don't have a huge successrate compared to DB exploits, where we can get a list of all users. A decent 10% successrate is what I usually hope for, but that's on the high-end of what you should be expecting.
Getting started
Okay, so when we open Sentry, we get a window looking like this:
Spoiler:
![[Image: z1PrWL9.png?1]](http://i.imgur.com/z1PrWL9.png?1)
You may want to make sure all check boxes comply with mine, unless you know what you're doing

So, now we want to load a Config ("snapshot"). We do this by clicking this:
Spoiler:
![[Image: blWsd0J.png?2]](http://i.imgur.com/blWsd0J.png?2)
Now select the config file for the site you're cracking.
The config file is basically a configuration which tells Sentry what and how to crack the website, since they don't all look the same.
Once we've opened that; we want to navigate to the "Lists" tab, and then click "Proxylist".
Spoiler:
![[Image: WXZU0df.png?3]](http://i.imgur.com/WXZU0df.png?3)
Now open your proxy file (blue arrow).
What we need now, is the combo, which contains usernames and password for Sentry to try.
We get this by clicking the tab called "Wordlist", and click "open".
Spoiler:
![[Image: Cc2AXHd.png?2]](http://i.imgur.com/Cc2AXHd.png?2)
Also, make sure you've selected "Combo list" in the drop-down list (blue arrow)
Great; now we've loaded everything we need to get crackin' ^^
Now we want to click the "Progression" tab, below "Lists".
Spoiler:
![[Image: gglUIHt.png?2]](http://i.imgur.com/gglUIHt.png?2)
In the image above; note how the bots are set to 151. I usually go with ~100 bots, as that gives a good speed (slide it to change bot count).
When you've loaded that, just click the green refresh button to make sure everything's fine, and check the wordlist position at 1.
All checked and cross-checked; click the large yello lightning in the top left corner to start cracking, and then click "Start the Bruteforcer Engine!" to set it off.
The results
Now that we've been to work for a day, and get back to our finished machine, it's time to look at the different codes.
As you notice in the little windows down-right; we have loads of various info.
What we need for our results, though, is only the red section called "Results".
By "Hits", MBA refers to all accouts which worked, and you can log in with.
"Reds" has nothing to do with colour, but means any accounts after testing, the site redirects us to another page. This can in some cases mean success; so try one or two accounts is you get lots of reds.
The rest of these codes are not massively important, so I'll leave you with those.
The three digit codes on the left are simply what the website outputs after testing an account (in website code).
That's it
That's pretty much all there is to cracking website accounts with Sentry MBA, unless you go into writing configs or modifying beyond the basics.
Hope you get some account worth having (or selling), and please reply or PM me if there is something on which I wasn't clear.
Thank you for reading, and Have A Nice Day!
![[Image: R5aCcWV.png]](http://i.imgur.com/R5aCcWV.png)




![[+]](https://sinister.ly/images/modern/collapse_collapsed.png)










![[Image: dHJ4Beo.gif]](http://i.imgur.com/dHJ4Beo.gif)








