EvilZone

Hacking and Security => Hacking and Security => Topic started by: FurqanHanif on May 03, 2015, 05:48:39 PM

Title: HTTP 1.1 / Basic Authentication Bypass?? Possible??
Post by: FurqanHanif on May 03, 2015, 05:48:39 PM
i Have A router , Model i Think 2009 or 10 , using micro_httpd  so  is  it's authentication can be bypass , is it possible to retrieve the password in hash and then crack it or simply bypass it's authentication ??? 
i Know About Xhydra and i also used it , so please don't tell me about using such kind of password cracking software...
Thanks in advance ...

this is the full detail of my Router..
(http://i.imgur.com/UMv6TeG.png)
Title: Re: HTTP 1.1 / Basic Authentication Bypass?? Possible??
Post by: iTpHo3NiX on May 03, 2015, 06:05:10 PM
Bruteforce
Title: Re: HTTP 1.1 / Basic Authentication Bypass?? Possible??
Post by: Cicada 3301 on May 03, 2015, 07:56:24 PM
Try attacking the 8-digit pin in the router. You can do this by using Reaver, it takes about ~ 4 - 10 hours.


This only works if WPS is not locked. You can see if it is open or not using wash (wash -i <monitor interface>)
Title: Re: HTTP 1.1 / Basic Authentication Bypass?? Possible??
Post by: FurqanHanif on May 03, 2015, 08:34:10 PM
Bruteforce
Bruteforce Not Gonna work if password is #kjkjhuijko88287098JbJh#$%%# and you Know it ..
So ......
Title: Re: HTTP 1.1 / Basic Authentication Bypass?? Possible??
Post by: FurqanHanif on May 03, 2015, 08:35:19 PM
Try attacking the 8-digit pin in the router. You can do this by using Reaver, it takes about ~ 4 - 10 hours.


This only works if WPS is not locked. You can see if it is open or not using wash (wash -i <monitor interface>)
I am Talking About Login , Not Wifi Hacking...  ???
Title: Re: HTTP 1.1 / Basic Authentication Bypass?? Possible??
Post by: Cicada 3301 on May 03, 2015, 08:36:30 PM
I am Talking About Login , Not Wifi Hacking...  ???


-.- You are trying to crack the password, then that would work.
Title: Re: HTTP 1.1 / Basic Authentication Bypass?? Possible??
Post by: TheWormKill on May 03, 2015, 08:37:21 PM
Bruteforce Not Gonna work if password is #kjkjhuijko88287098JbJh#$%%# and you Know it ..
So ......
Bruteforce always works. It's just not efficient and thus slow. And use the damn modify-button!
Title: Re: HTTP 1.1 / Basic Authentication Bypass?? Possible??
Post by: Cicada 3301 on May 03, 2015, 08:40:19 PM
Bruteforce always works. It's just not efficient and thus slow. And use the damn modify-button!


Some list of characters don't include what the password is. So brute force might not always work.


It all depends on the complexity.
Title: Re: HTTP 1.1 / Basic Authentication Bypass?? Possible??
Post by: iTpHo3NiX on May 03, 2015, 08:40:28 PM
Then reset the router to go back to admin:password defaults. Brute force/word list is the solution. A good one? No, the only one that will work? Yes.

Another solution is routerpwn. You either need to find an exploit or develop your own for that router and firmware. Its not going to be in the http author unless you can get the pwd file from the server, however that's easier said than done depending on the system.


Some list of characters don't include what the password is. So brute force might not always work.

It all depends on the complexity.

You need to shut your mouth when you don't know something. Brute force will ALWAYS work. If your skidshit tool don't have the characters, obviously you need to have them inputted. The only time brute force will fail is if there's antihammar, which doesn't mean brute force doesn't always work, it means the system blocks it because it knows it WILL WORK which is why all secure systems will lock you out after so many failed attempts.


-.- You are trying to crack the password, then that would work.
The wireless encryption password does not give you access to the router password. He's already on the network dumbfuck

Learn something before you open your mouth and spread your ignorance please.
Title: Re: HTTP 1.1 / Basic Authentication Bypass?? Possible??
Post by: HTTP on May 04, 2015, 02:21:22 AM
Fuck dude, your ignorant. First of all, I assume he misunderstood the question, dumbfuck. Why talk about the knowledge?Also, no shit you need them inputted, that's why brute force might not work if the characters arenot inputted, fucking tard.
Title: Re: HTTP 1.1 / Basic Authentication Bypass?? Possible??
Post by: HTTP on May 04, 2015, 09:09:03 PM
And who the hell would ever let reaver run its full course nowadays? Oh yeah, dumb fucks that don't have a clue what they are talking about.


Are you retarded? Is this comment for real? Oh yeah, I forgot, you work as a construction worker.
Title: Re: HTTP 1.1 / Basic Authentication Bypass?? Possible??
Post by: TheWormKill on May 04, 2015, 09:15:39 PM

Are you retarded? Is this comment for real? Oh yeah, I forgot, you work as a construction worker.
It's interesting how you accuse others of being dumb (without a proper argument, and no yours isn't valid, read what DeepCopy 0pt1mu5pr1m3 etc. wrote), yet fail to follow the simple "No double-posting, faggot"-rule.

Apart from that: why the fuck does every second thread I see develop into a flamewar of the lowest, though entertaining kind?
Title: Re: HTTP 1.1 / Basic Authentication Bypass?? Possible??
Post by: HTTP on May 04, 2015, 09:34:55 PM
Optimus's response made sense to you? I've had plenty success by attacking the routers 8 digit pin if WPS is open.


Oh, it's that because evilzone is not what it was before. And fuck EZ, it's turned to shit, and I'm not going to be serious on this shit forum anymore. I'm just going to use 4chan logic from now on.
Title: Re: HTTP 1.1 / Basic Authentication Bypass?? Possible??
Post by: 0E 800 on May 04, 2015, 09:36:22 PM
Optimus's response made sense to you? I've had plenty success by attacking the routers 8 digit pin if WPS is open.

(http://cdn.meme.am/instances/500x/60977146.jpg)
Title: Re: HTTP 1.1 / Basic Authentication Bypass?? Possible??
Post by: Axon on May 04, 2015, 09:50:33 PM
Calm down kids, discuss this issue as civilized individuals?
Title: Re: HTTP 1.1 / Basic Authentication Bypass?? Possible??
Post by: HTTP on May 04, 2015, 09:53:31 PM
What if I'm not civilized? I'm using 4chan logic, good luck having a civilized conversation with me, fag.
Title: Re: HTTP 1.1 / Basic Authentication Bypass?? Possible??
Post by: Axon on May 04, 2015, 09:56:46 PM
What if I'm not civilized? I'm using 4chan logic, good luck having a civilized conversation with me, fag.
I didn't insult you in the first place, I don't see why you are attacking me personally. If you have an anger management issue, seek assistance.
Title: Re: HTTP 1.1 / Basic Authentication Bypass?? Possible??
Post by: HTTP on May 04, 2015, 09:59:31 PM
Let me explain. EvilZone is ruined, I don't care for this forum anymore, it's gone into shit. Also, it's the internet, you shouldn't be offended if I say you are a fag, doesn't mean you are literally a fag, or if I call you stupid, doesn't mean you are literally stupid, it's the internet. I wasn't attacking you personally, I've just lost hope for this forum, so I don't give a shit what my reputation is or what people think of me.
Title: Re: HTTP 1.1 / Basic Authentication Bypass?? Possible??
Post by: Axon on May 04, 2015, 10:05:24 PM
Let me explain. EvilZone is ruined, I don't care for this forum anymore, it's gone into shit. Also, it's the internet, you shouldn't be offended if I say you are a fag, doesn't mean you are literally a fag, or if I call you stupid, doesn't mean you are literally stupid, it's the internet. I wasn't attacking you personally, I've just lost hope for this forum, so I don't give a shit what my reputation is or what people think of me.
If EZ is ruined,then why bother being here! I'm not offended personally, but I pity you. Anyway, it's likely that this thread will get closed.
Title: Re: HTTP 1.1 / Basic Authentication Bypass?? Possible??
Post by: HTTP on May 04, 2015, 10:06:45 PM
Go ahead, I'm here to piss people off, it's amusing. It's called trolling.
Title: Re: HTTP 1.1 / Basic Authentication Bypass?? Possible??
Post by: white-knight on May 04, 2015, 10:07:45 PM
Go ahead, I'm here to piss people off, it's amusing. It's called trolling.


I don't feel loved will you TROLL me some :)
Title: Re: HTTP 1.1 / Basic Authentication Bypass?? Possible??
Post by: Darkvision on May 05, 2015, 04:55:53 AM
Go ahead, I'm here to piss people off, it's amusing. It's called trolling.
Sup, I'm HTTP. Surprised no one has taken that name yet  :P


I do shit basically. That's all.
So you admit you do shit, you give shit advice, or talk about tools(never actual knowledge), yet want to consider yourself a hacker, and claim it is EZ that has fallen? after being here a month? I mean honestly i dont know how much more of a skidd you could be without being registered at hackforums. Or are you registered on that site and just got lost on the way because its hard to figure out how to work one of these newfangled web browsers? Anyway you really arnt any good at this whole "troll" thing, about as good at it as you are at hacking, which is to say not at all. The very fact that your idea of "trolling" is to copy some other "popular" place(4chan) really shows the level of intellect you have, or for that matter apply to anything, that is virtually none. We could replace you with a monkey mashing buttons and not tell the difference, and thats just sadlypathetic.
Title: Re: HTTP 1.1 / Basic Authentication Bypass?? Possible??
Post by: iTpHo3NiX on May 05, 2015, 06:15:39 AM
Still thinks wps pin/WiFi pass is the router login password lmfao

Quote from: HTTP
Optimus's response made sense to you? I've had plenty success by attacking the routers 8 digit pin if WPS is open.

Title: Re: HTTP 1.1 / Basic Authentication Bypass?? Possible??
Post by: marineboyz on May 05, 2015, 05:36:29 PM
Do you knw how to hack mmorpg games? If u knw please tell me
Title: Re: HTTP 1.1 / Basic Authentication Bypass?? Possible??
Post by: white-knight on May 05, 2015, 05:44:24 PM
Do you knw how to hack mmorpg games? If u knw please tell me


follow this it will hack them for you..
up up down down  left right left right a b a b
Title: Re: HTTP 1.1 / Basic Authentication Bypass?? Possible??
Post by: 0E 800 on May 05, 2015, 06:00:58 PM
There should be an option for members to vote to permanently erase a whole thread.

I vote to remove this, I find it to be offensive.
Title: Re: HTTP 1.1 / Basic Authentication Bypass?? Possible??
Post by: M1lak0 on May 07, 2015, 11:02:36 AM
Someone is still serious here. :P
Trying to make this thread a bit worth reading..!

Well I recently found a way to bypass.
Let me show you something:
It shows up the login.

(http://upload.evilzone.org?page=download&file=yOCEcOswtbuEGFYkQ3Od9J8vHIjA8yGKlhChG4WBNI2X6uLzCr)

I tried to access the index.php file but I failed:

(http://upload.evilzone.org?page=download&file=5Ns3yWfP4Qavulk7XjUN8ebF6lwlaCe73vn1jPUu3qYPyOCef4)

Sometimes the .htaccess rules goes wrong:

(http://upload.evilzone.org/index.php?page=img&img=EmB6xYb6QY6rZ7StMFykvloRhipwzWZGcAvtATiN5vTto4kHht)

As we can see it is limited to only GET Request so lets send a POST request like this:

(http://upload.evilzone.org/index.php?page=img&img=rNZ1JAmyDpdWgR00GUyXcZZmAnOMBue1JDoKMmRq8Fsy4KpVHV)

And here we are.. :D
I am really not sure that if it'll work for you because this depends on how the .htaccess file is configured.

Good luck for your try :) (Y)