Skip to content
Contact
SYS_TIME [ 00 00 00 ]

Rendered from the original file. Use Open in New Tab for the download.

Prince Sultan University

College of Computer and Information Sciences

CYS401 – Fundamentals of Cybersecurity

Practical 4: Hacking Web Application - Perform a Brute-force Attack using Burp Suite in Kali Linux

Instructions:

  • The assignment must be done individually.
  • The assignment is of 10 marks. You’ll have to demonstrate the assignment on your PC OR submit a report. For each assignment, there will be an assessment.
  • The assignment should preferably be done on a laptop.
  • Required Tools: Kali- Linux, Burp Suite (available in kali Linux).

Requirements:

  • Select the user whose password you want to know, in order to get access to his/ her account.
  • It works only for less complex passwords (E.g., Combination of Alphanumeric, Alphabets with uppercase letters at start and end).
  • Download a word dictionary from internet or need to create your own word dictionary.

Burp Suite:

Burp Suite is an integrated platform for performing security testing of web applications. It has various tools that work together to support the entire testing process from the initial mapping and analysis of an application’s attack surface to finding and exploiting security vulnerabilities. Burp Suite contains key components such as an intercepting proxy, application-aware spider, advanced web application scanner, intruder tool, repeater tool, and sequencer tool.

Here, we will perform a brute-force attack on the target website using Burp Suite.

Tasks:

  • Download Burpsuite https://portswigger.net/burp/communitydownload. Also available in kali Linux.
  • First of all you need to create an account on any website which you want to attack. In this case we are using demo website. “demo.testfire.net” Below you can find the details below:
  • Create the fake website Portal.
  • In Kali Linux, go to applications, select social engineering.
  • Type password kali type 1 “Social Engineering Attack” Type 2 “Website Attack Vectors” Type 3 “Credential Harvester Attack Method” Type 2 “Site Cloner”.
  • It will ask for the IP Address (Copy the given IP somewhere for later use 192.168.42.129). This is the address of Kali Machine. Just Hit “ENTER”.
  • Go to the browser, open http://demo.testfire.net/login.jsp
  • Paste the copied URL in “enter the URL to clone” option in the kali terminal. And hit “ENTER”
  • Go to your web browser. In the search URL type the IP address of Kali Machine and hit “ENTER”.
  • You will see the fake portal has been generated successfully.
  • Now login with the “username” and “password” and click Sign in. Your credential will directly go to your Kali Machine IP address (which is acting as an attacker). (Note: Don’t close the browser window).
  • Go to your Kali Terminal and check, you will see the username and password there. Now you can use this username and password to access other accounts of this user.
  • It looks very simply but the issue is that user will not click on this URL directly.
  • Do not Close the Previous Terminal of Kali Linux.
  • Secondly, you need to setup your firefox proxy in order to allow it to work with burpsuite.

Firefox-> settings -> options -> Proxy -> set proxy -> 127.0.0.1 and port -> 8080

Check box -> Sock 5.

  • Open your burpsuite -> under proxy -> set the http connection to -> 127.0.0.1 and port 8080.
  • Whatever traffic you are sending on internet goes through burpsuite. It works as sniffing tool.
  • First open your website on which you created account and go to login page.
  • Open burpsuite -> go to proxy -> press intercept in off.
  • Once you press it, intercept gets on.
  • Now go back to your firefox, enter user name and Password of the user. But keep in mind the password should be incorrect. Assume you only know the user name and wants to find the password using dictionary attack.
  • Now go back to burpsuite, whatever user name and password you entered on web page, it is shown in burpsuite.
  • On Burpsuite perform the following actions:
  • Press action and select send to intruder
  • Go to Intruder tab.
  • Here you need to press $clear$
  • Then select only username and password and click $Add$ from right panel.
  • Select Cluster Bomb from drop down menu.
  • Choose payload tab -> select payload 1 and start entering the username/ names.
  • Select payload 2 and start creating your dictionary. (Note: you can also load dictionary that you have downloaded from internet, but it takes almost 10 hours to process that dictionary)
  • Click on Start Attack button

  • A new Pop-up window appears that start matching your user-name and with the dictionary of passwords that you created.
  • For correct password, It shows different length & size.

Bonus Marks:

Task:

Find your own vulnerable site that runs on “http”, create account on it and perform dictionary attack on it.

**************** Password Found Successfully ******************