gpt4 book ai didi

linux - Hydra http 连接失败

转载 作者:太空宇宙 更新时间:2023-11-04 11:10:26 24 4
gpt4 key购买 nike

我想检查我的页面只有一个ip没有主机名(http://ip.ip.ip.ip/dologin.htm)

现在我想检查它是否来自 hydra

我尝试的是:

hydra -l admin  -p admin ip.ip.ip.ip http-post-form "/dologin.htm:P2=^PASS^&Login=:1"

P2: 密码形式

LOGIN:用户名形式(这是空的 - 没有用户名)

:1:尝试输入错误密码(没有输入错误密码的消息)...

所以结果是:

当我在 hydra 中输入正确的密码时,它说你的密码是错误的......

我该怎么办?

谢谢

最佳答案

问题是您的失败条件 (:1)。

来自source我们可以看到option字段的格式如下:

The option field (following the service field) takes three ":" separated values and an optional fourth value, the first is the page on the server to GET or POST to, the second is the POST/GET variables (taken from either the browser, or a proxy such as PAROS) with the varying usernames and passwords in the "^USER^" and "^PASS^" placeholders, the third is the string that it checks for an invalid or valid login - any exception to this is counted as a success. So please: * invalid condition login should be preceded by "F=" * valid condition login should be preceded by "S=". By default, if no header is found the condition is assume to be a fail, so checking for invalid login. The fourth optional value, can be a 'C' to define a different page to GET initial cookies from.

所以你应该能够提供一个success条件而不是一个fail条件。

因此在成功登录后将页面中的 :1 更改为 :S=string

关于linux - Hydra http 连接失败,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/23455070/

24 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com