Re: hydra and HTTP NTLM

Security Auditor <[email protected]>
Newsgroups gmane.comp.security.web-applications
Message-ID <CAHj2+fz4PD=8kY0_=hAzNZrs_r+4d0_k5Lo5WP2OwwG76Op4Jw@mail.gmail.com>
Hi,
I would say use an interceptor proxy which can handle this stuff
easily. For example burp, ZAP or others.

I played with hydra on DVWA app and could not succeed at bruting.....

hope this helps

cheers

Audi

On Wed, May 23, 2012 at 2:14 PM, Robin Wood <[email protected]> wrote:
> Anyone know how to use the new HTTP NTLM feature in Hydra? I'm trying
> to brute force a MS Front Page login which only asks for
> authentication when the OPTIONS method is used as far as I can tell.
>
> Robin
>
>
>
> This list is sponsored by Cenzic
> --------------------------------------
> Let Us Hack You. Before Hackers Do!
> It's Finally Here - The Cenzic Website HealthCheck. FREE.
> Request Yours Now!
> http://www.cenzic.com/2009HClaunch_Securityfocus
> --------------------------------------
>



This list is sponsored by Cenzic
--------------------------------------
Let Us Hack You. Before Hackers Do!
It's Finally Here - The Cenzic Website HealthCheck. FREE.
Request Yours Now! 
http://www.cenzic.com/2009HClaunch_Securityfocus
--------------------------------------
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.