Penetration Testing mailing list archives

Re: looking for a webapp bruteforce video for non-techies


From: pand0ra <pand0ra.usa () gmail com>
Date: Tue, 3 Jun 2008 10:26:40 -0600

Irongeek.com

http://www.irongeek.com/i.php?page=security/hackingillustrated

On Tue, Jun 3, 2008 at 7:42 AM, Robin Wood <dninja () gmail com> wrote:
Hi
Can anyone recommend a video showing how easy it can be to brute force
a web application that I can show to non-technical people. I want
something quick and polite - preferably no leet speak banners or that
type of thing - that I can show to both board level people and just
generally to friends and family who chose bad passwords for web
applications.

I've just been with a client who, after being told a dictionary word
was bad, just put a 3 in instead of an e and thought she was
completely secure. It didn't help that the password was only 5
characters!

Thanks

Robin

-------------------------------------------------------------------------
Sponsored by: Watchfire
Methodologies & Tools for Web Application Security Assessment
With the rapid rise in the number and types of security threats, web application security assessments should be 
considered a crucial phase in the development of any web application. What methodology should be followed? What tools 
can accelerate the assessment process? Download this Whitepaper today!

https://www.watchfire.com/securearea/whitepapers.aspx?id=70170000000940F
-------------------------------------------------------------------------



------------------------------------------------------------------------
This list is sponsored by: Cenzic

Top 5 Common Mistakes 
in Securing Web Applications  
Find out now! Get Webinar Recording and PPT Slides

www.cenzic.com/landing/securityfocus/hackinar
------------------------------------------------------------------------


Current thread: