Web server digest authentication.
#2
Just an update, I was able to disable hex in the potfile by using the switch --outfile-autohex-disable

The password was then written to the log, from there I switched out the hash for my unknown one, edited the mask file to brute force the last 3 characters of what I thought the password might have been, 7 seconds later I got lucky and was able to retrieve the password. Hope this helps someone in the future.


Messages In This Thread
Web server digest authentication. - by Zzzz - 07-31-2017, 12:51 PM
RE: Web server digest authentication. - by Zzzz - 07-31-2017, 02:43 PM