data:image/s3,"s3://crabby-images/d4248/d424833a2218c21e0e2176923ba0aeb172a5a9e3" alt="Kali Linux:An Ethical Hacker's Cookbook(Second Edition)"
上QQ阅读APP看书,第一时间看更新
How to do it...
Let's perform the following steps:
- Run the following command to install brutespray on Kali:
apt install brutespray
The following screenshot shows the output of the preceding command:
data:image/s3,"s3://crabby-images/4ba40/4ba40495b430cf42d4d1934105e2a92403685208" alt=""
- Once it is installed, we can run the tool with the -h flag to view the list of all features.
- To run a default brute force on all of the services that were discovered by a previously run Nmap scan, we can use the following command:
brutespray --file scan.xml --threads 5
The following screenshot shows the output of the preceding command:
data:image/s3,"s3://crabby-images/6dc5a/6dc5a18f0ea9d93c134cbf64c5cdbdb9c6a12f83" alt=""
- To run the tool on one particular service, we can use the -s flag and define the service we want to perform a brute force attack on. In the following example, we will use the Nmap scan that was done on a host and only check the default credentials on the FTP service:
brutespray -file scan.xml -t 5 -s ftp
The following screenshot shows the output of the preceding command:
data:image/s3,"s3://crabby-images/a6186/a61866441a2339d89e518e641e0848ebc76b8fef" alt=""
In the preceding screenshot, we can see that the FTP allows anonymous login, which is why the tool gave a success output for the credentials that were shown.