daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

index.md (6252B)


      1 ---
      2 title: "Brute Force & Rate Limit"
      3 topic: "Brute Force Rate Limit"
      4 topicSlug: "brute-force-rate-limit"
      5 sourcePath: "Brute Force Rate Limit/README.md"
      6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/Brute%20Force%20Rate%20Limit/README.md"
      7 sha: "3ac27901c711"
      8 isReadme: true
      9 ---
     10 
     11 # Brute Force & Rate Limit
     12 
     13 ## Summary
     14 
     15 * [Tools](#tools)
     16 * [Bruteforce](#bruteforce)
     17     * [Burp Suite Intruder](#burp-suite-intruder)
     18     * [FFUF](#ffuf)
     19 * [Rate Limit](#rate-limit)
     20     * [TLS Stack - JA3](#tls-stack---ja3)
     21     * [Network IPv4](#network-ipv4)
     22     * [Network IPv6](#network-ipv6)
     23 * [References](#references)
     24 
     25 ## Tools
     26 
     27 * [ZephrFish/OmniProx](https://github.com/ZephrFish/OmniProx) - IP Rotation from different providers - Like FireProx but for GCP, Azure, Alibaba and CloudFlare.
     28 * [ddd/gpb](https://github.com/ddd/gpb) - Bruteforcing the phone number of any Google user while rotating IPv6 addresses.
     29 * [ffuf/ffuf](https://github.com/ffuf/ffuf) - Fast web fuzzer written in Go.
     30 * [PortSwigger/Burp Suite](https://portswigger.net/burp) - The class-leading vulnerability scanning, penetration testing, and web app security platform.
     31 * [lwthiker/curl-impersonate](https://github.com/lwthiker/curl-impersonate) - A special build of curl that can impersonate Chrome & Firefox.
     32 
     33 ## Bruteforce
     34 
     35 In a web context, brute-forcing refers to the method of attempting to gain unauthorized access to web applications, particularly through login forms or other user input fields. Attackers systematically input numerous combinations of credentials or other values (e.g., iterating through numeric ranges) to exploit weak passwords or inadequate security measures.
     36 
     37 For instance, they might submit thousands of username and password combinations or guess security tokens by iterating through a range, such as 0 to 10,000. This method can lead to unauthorized access and data breaches if not mitigated effectively.
     38 
     39 Countermeasures like rate limiting, account lockout policies, CAPTCHA, and strong password requirements are essential to protect web applications from such brute-force attacks.
     40 
     41 ### Burp Suite Intruder
     42 
     43 * **Sniper attack**: target a single position (one variable) while cycling through one payload set.
     44 
     45     ```ps1
     46 
     47     Username: password
     48     Username1:Password1
     49     Username1:Password2
     50     Username1:Password3
     51     Username1:Password4
     52     ```
     53 
     54 * **Battering ram attack**: send the same payload to all marked positions at once by using a single payload set.
     55 
     56     ```ps1
     57     Username1:Username1
     58     Username2:Username2
     59     Username3:Username3
     60     Username4:Username4
     61     ```
     62 
     63 * **Pitchfork attack**: use different payload lists in parallel, combining the nth entry from each list into one request.
     64 
     65     ```ps1
     66     Username1:Password1
     67     Username2:Password2
     68     Username3:Password3
     69     Username4:Password4
     70     ```
     71 
     72 * **Cluster bomb attack**: iterate through all combinations of multiple payload sets.
     73 
     74     ```ps1
     75     Username1:Password1
     76     Username1:Password2
     77     Username1:Password3
     78     Username1::Password4
     79 
     80     Username2:Password1
     81     Username2:Password2
     82     Username2:Password3
     83     Username2:Password4
     84     ```
     85 
     86 ### FFUF
     87 
     88 ```bash
     89 ffuf -w usernames.txt:USER -w passwords.txt:PASS \
     90      -u https://target.tld/login \
     91      -X POST -d "username=USER&password=PASS" \
     92      -H "Content-Type: application/x-www-form-urlencoded" \
     93      -H "X-Forwarded-For: FUZZ" -w ipv4-list.txt:FUZZ \
     94      -mc all
     95 ```
     96 
     97 ## Rate Limit
     98 
     99 ### HTTP Pipelining
    100 
    101 HTTP pipelining is a feature of HTTP/1.1 that lets a client send multiple HTTP requests on a single persistent TCP connection without waiting for the corresponding responses first. The client "pipes" requests one after another over the same connection.
    102 
    103 ### TLS Stack - JA3
    104 
    105 JA3 is a method for fingerprinting TLS clients (and JA3S for TLS servers) by hashing the contents of the TLS "hello" messages. It gives a compact identifier you can use to detect, classify, and track clients on the network even when higher-level protocol fields (like HTTP user-agent) are hidden or faked.
    106 
    107 > JA3 gathers the decimal values of the bytes for the following fields in the Client Hello packet; SSL Version, Accepted Ciphers, List of Extensions, Elliptic Curves, and Elliptic Curve Formats. It then concatenates those values together in order, using a "," to delimit each field and a "-" to delimit each value in each field.
    108 
    109 * Burp Suite JA3: `53d67b2a806147a7d1d5df74b54dd049`, `62f6a6727fda5a1104d5b147cd82e520`
    110 * Tor Client JA3: `e7d705a3286e19ea42f587b344ee6865`
    111 
    112 **Countermeasures:**
    113 
    114 * Use browser-driven automation (Puppeteer / Playwright)
    115 * Spoof TLS handshakes with [lwthiker/curl-impersonate](https://github.com/lwthiker/curl-impersonate)
    116 * JA3 randomization plugins for browsers/libraries
    117 
    118 ### Network IPv4
    119 
    120 Use multiple proxies to simulate multiple clients.
    121 
    122 ```bash
    123 proxychains ffuf -w wordlist.txt -u https://target.tld/FUZZ
    124 ```
    125 
    126 * Use `random_chain` to rotate each request
    127 
    128     ```ps1
    129     random_chain
    130     ```
    131 
    132 * Set the number of proxies to chain per connection to 1.
    133 
    134     ```ps1
    135     chain_len = 1
    136     ```
    137 
    138 * Finally, specify the proxies in a configuration file:
    139 
    140     ```ps1
    141     # type  host      port
    142     socks5  127.0.0.1 1080
    143     socks5  192.168.1.50 1080
    144     http    proxy1.example.com 8080
    145     http    proxy2.example.com 8080
    146     ```
    147 
    148 ### Network IPv6
    149 
    150 Many cloud providers, such as Vultr, offer /64 IPv6 ranges, which provide a vast number of addresses (18 446 744 073 709 551 616). This allows for extensive IP rotation during brute-force attacks.
    151 
    152 ## References
    153 
    154 * [Bruteforcing the phone number of any Google user - brutecat - June 9, 2025](https://web.archive.org/web/20250609141236/https://brutecat.com/articles/leaking-google-phones)
    155 * [Burp Intruder attack types - PortSwigger - August 19, 2025](https://web.archive.org/web/20260124024947/https://portswigger.net/burp/documentation/desktop/tools/intruder/configure-attack/attack-types)
    156 * [Detecting and annoying Burp users - Julien Voisin -  May 3, 2021](https://web.archive.org/web/20260102160139/https://dustri.org/b/detecting-and-annoying-burp-users.html)
    157 * [OmniProx: Multi-Cloud IP Rotation Made Simple - Andy Gill - September 28, 2025](https://web.archive.org/web/20260215082718/https://blog.zsec.uk/omniprox/)