Sinisterly
Medusa: configure web form properly - Printable Version

+- Sinisterly (https://sinister.ly)
+-- Forum: Hacking (https://sinister.ly/Forum-Hacking)
+--- Forum: Hacking Tools (https://sinister.ly/Forum-Hacking-Tools)
+--- Thread: Medusa: configure web form properly (/Thread-Medusa-configure-web-form-properly)



Medusa: configure web form properly - gettingold - 10-21-2011

Hi,

I ve problems in configuring Medusa (and Hydra too) for bruteforcing web http post form.
I made already several attemps on sites on which I have a login and a password, but no way. I couldn't not find any tutorial that explains that really in details...

May someone explain in detail how to configure the web form option (everything to put inside, tu not put, syntax, name value login etc etc)? Is there an issue about cookie as well to configure it correctly?

Or do you know a very detailed tutorial about that?

I read about using http live headers for finding the good data, someoen figure out how to do it?

Thanks a lot for your help,
cheers



RE: Medusa: configure web form properly - TheShadow1 - 10-21-2011

http://www.aldeid.com/wiki/Medusa#form-web
This tutorial is for linux. But the same concept applies.


RE: Medusa: configure web form properly - gettingold - 10-21-2011

(10-21-2011, 12:53 PM)TheShadow1 Wrote: http://www.aldeid.com/wiki/Medusa#form-web
This tutorial is for linux. But the same concept applies.

Thanks a lot!

The tutorial is very good, but still I cannot succeed in it (tried with 3 different sites
in which have login-password). I am wondering if can be something related to cookies or something similar.
It is not able to find the good password-login pair, even if I try just giving the good pair.
I tried with hydra as well but either I get all the pairs positive, or all negative.

Do someone had the same problem and managed to solve it?

Or someone knows some sites for which this definitely work on which is possible to test it?

Cheers