Noteable Posts

Saturday, June 6, 2020

Brutality: A Fuzzer For Any GET Entries

Brutalitys' Features

  • Multi-threading on demand.
  • Fuzzing, bruteforcing GET params.
  • Find admin panels.
  • Colored output.
  • Hide results by return code, word numbers.
  • Proxy support.
  • Big wordlist.
Screenshots:

Brutality's Installtion

How to use Brutality?

Examples:
   Use default wordlist with 5 threads (-t 5) and hide 404 messages (–e 404) to fuzz the given URL (http://192.168.1.1/FUZZ):
python brutality.py -u 'http://192.168.1.1/FUZZ' -t 5 -e 404

   Use common_pass.txt wordlist (-f ./wordlist/common_pass.txt), remove response with 6969 length (-r 6969) and proxy at 127.0.0.1:8080 (-p http://127.0.0.1:8080) to fuzz the given URL (http://192.168.1.1/brute.php?username=admin&password=FUZZ&submit=submit#):
python brutality.py -u 'http://192.168.1.1/brute.php?username=admin&password=FUZZ&submit=submit#' -f ./wordlist/common_pass.txt -r 6969 -p http://127.0.0.1:8080

ToDo List:
  • Smooth output.
  • Export file report.
  • Modularization.

Related news

  1. Pentest Gear
  2. Hacking Apps
  3. Hacking Box
  4. Hacking With Raspberry Pi
  5. Hacker Prank
  6. Pentest App
  7. Hacking Device
  8. Hacker Computer
  9. Hacking Programs
  10. Pentest Kit
  11. Pentest Open Source
  12. Pentest Process
  13. Pentest Magazine
  14. Rapid7 Pentest
  15. Pentest Standard

No comments: