struggling with Brute force sorry!

5 views
Skip to first unread message

Gary Stephens

unread,
Mar 9, 2026, 2:19:51 PM (yesterday) Mar 9
to ZAP User Group
So as the title says. 
I tried authenticating a known user and Pw to test my setup, I then setup a test for an unknown BF attack. 
What I am seeing is when I proxy the traffic on my Mac, running chrome, the username is in clear text but the pw is encrypted. as in 

<SessionLogin><userName>bob</userName><password>f682091852f6aad44f2d624256543e20ca1d7ae1f4fa40698b7cdd1b954aa8df</password><sessionID>114944cacb1d5e9a3c11</sessionID></SessionLogin>=sanitizedtoken0&


So if I setup a Fuzz, it fails unless I use the hashed value of the pw as above. Clearly this is not going to work so question, how do I get the Fuzzer to send the PW from the file where it's in plain text.

apologies for being a numpty but I can't find the answer anywhere.....

Reply all
Reply to author
Forward
0 new messages