4 ms·
This is a fun read for novices who are interested in infosec stuff. <rant> I wish infosec tutorials/articles pushed writing custom tools. I've always considere
by nubb 8y ago
This is a fun read for novices who are interested in infosec stuff.
<rant> I wish infosec tutorials/articles pushed writing custom tools. I've always considered password spraying to really be just taking super common passwords and flipping them around a bit. <season><year><special char> or <month><year><special char>. Instead of pushing some existing tools, I wish this article encouraged writing custom wordlist generators using common knowledge/sense. </rant>
- EnFinlay 8y agoOn one hand I agree with you, on the other hand I don't think the space is short on people writing their own tools. The number of DNS enumerators I've seen shared over the past month alone speaks to this.
- nubb 8y agoI cant disagree with you there :)
- bashwizard 7y agoWhile custom tools are nice and all I don't really see the point of reinventing the wheel all the time. If there is a tool/script/exploit/etc out there doing most of what I want, you can be sure that I'm going to use it and modify it to my needs instead of writing my own. I'd say that's usually the case in 80% of the cases when doing pentests. Besides, time is money.
- svantana 7y agoThat sounds like guesswork, don't we already know which passwords are in common use from the various large-scale breaches? You could even use that data to train a character sequence model (e.g RNN), but really just randomly selecting from the 1000 most common passwords should be superior?
- Fnoord 7y agoWhat you say is the article lacks depth of what you find important. You could easily make such with a few UNIX tools such as date and seq plus a few variables in your favorite language. So that is covered in Linux, Bash, and Python courses. Burp also has support to prepend or append characters. They could've covered that as it is rather powerful. They could've also covered grabbing pastes from dark web to use as input.