<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://www.justus.pw/mediawiki/index.php?action=history&amp;feed=atom&amp;title=HtbTricks%2FHTTP</id>
	<title>HtbTricks/HTTP - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://www.justus.pw/mediawiki/index.php?action=history&amp;feed=atom&amp;title=HtbTricks%2FHTTP"/>
	<link rel="alternate" type="text/html" href="https://www.justus.pw/mediawiki/index.php?title=HtbTricks/HTTP&amp;action=history"/>
	<updated>2026-05-25T02:22:43Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.44.3</generator>
	<entry>
		<id>https://www.justus.pw/mediawiki/index.php?title=HtbTricks/HTTP&amp;diff=77&amp;oldid=prev</id>
		<title>Justus: Add page</title>
		<link rel="alternate" type="text/html" href="https://www.justus.pw/mediawiki/index.php?title=HtbTricks/HTTP&amp;diff=77&amp;oldid=prev"/>
		<updated>2026-01-05T07:56:35Z</updated>

		<summary type="html">&lt;p&gt;Add page&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;= Fingerprint =&lt;br /&gt;
&lt;br /&gt;
Given &amp;lt;code&amp;gt;$HOST&amp;lt;/code&amp;gt; and $PORT:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;curl -i http://$HOST:$PORT&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&amp;lt;span id=&amp;quot;feroxbuster&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
= Feroxbuster =&lt;br /&gt;
&lt;br /&gt;
Given &amp;lt;code&amp;gt;$HOST&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;$PORT&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;$MACHINE&amp;lt;/code&amp;gt;, and &amp;lt;code&amp;gt;$WORDLISTS&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Wordlists to try out:&lt;br /&gt;
&lt;br /&gt;
# &amp;lt;code&amp;gt;SecLists/Discovery/Web-Content/dsstorewordlist.txt&amp;lt;/code&amp;gt;&lt;br /&gt;
# &amp;lt;code&amp;gt;SecLists/Discovery/Web-Content/big.txt&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;fish&amp;quot;&amp;gt;feroxbuster --url http://$HOST:$PORT \&lt;br /&gt;
  --wordlist=(cat $WORDLISTS | sort -u | psub) \&lt;br /&gt;
  -o machines/$MACHINE/feroxbuster.log -C 404&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&amp;lt;span id=&amp;quot;cracking&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
= Cracking =&lt;br /&gt;
&lt;br /&gt;
Use patator for complex pw cracking, esp. with csrf tokens:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;fish&amp;quot;&amp;gt;patator.py \&lt;br /&gt;
    http_fuzz \&lt;br /&gt;
    url=http://$HOST:$PORT/$PATH \&lt;br /&gt;
    method=POST \&lt;br /&gt;
    accept_cookie=1 \&lt;br /&gt;
    before_urls=http://$HOST:$PORT/$BEFORE_PATH \&lt;br /&gt;
    # Example&lt;br /&gt;
    before_egrep=&amp;#039;_N1_:&amp;lt;input name=&amp;quot;__RequestVerificationToken&amp;quot; type=&amp;quot;hidden&amp;quot; value=&amp;quot;(\S+)&amp;quot; \/&amp;gt;&amp;#039; \&lt;br /&gt;
    body=&amp;#039;userNameOrEmail=FILE0&amp;amp;password=FILE1&amp;amp;rememberMe=false&amp;amp;__RequestVerificationToken=_N1_&amp;#039; \&lt;br /&gt;
    # Concat several files&lt;br /&gt;
    0=(echo &amp;#039;administrator&lt;br /&gt;
james&amp;#039; | psub) \&lt;br /&gt;
    1=SecLists/Passwords/probable-v2-top1575.txt \&lt;br /&gt;
    # Ignore if these results come up&lt;br /&gt;
    -x ignore:fgrep=&amp;#039;The username or e-mail or password provided is incorrect&amp;#039; -l log&lt;br /&gt;
    -x ignore:fgrep=&amp;#039;Internal Server Error&amp;#039; -l log&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;/div&gt;</summary>
		<author><name>Justus</name></author>
	</entry>
</feed>