Author Topic: WAF bypass help  (Read 2099 times)

0 Members and 1 Guest are viewing this topic.

Offline yhi

  • Serf
  • *
  • Posts: 42
  • Cookies: -70
    • View Profile
WAF bypass help
« on: May 19, 2015, 12:06:01 pm »
i was trying to bruteforce a wordpress website with wpscan
& i got this error

[!] The plugin limit-login-attempts has been detected. It might record the IP and timestamp of every failed login and/or prevent brute forcing altogether. Not a good idea for brute forcing!
[?] Do you want to start the brute force anyway ? [Y]es [N]o, default: [N]
y
  • Starting the password brute forcer

  Brute Forcing '7m1z1g' Time: 00:00:00 <===                                                                                  > (1 / 21)  4.76%  ETA: 00:00:17
  ERROR: No response from remote server. WAF/IPS?

  ERROR: No response from remote server. WAF/IPS?



anyway to bypass it ?

Offline P!X3LTR0N

  • Peasant
  • *
  • Posts: 97
  • Cookies: 16
  • Security for some is a matter of perspective
    • View Profile
Re: WAF bypass help
« Reply #1 on: May 19, 2015, 12:12:24 pm »
I have had this issue before with hydra, have you tried reducing the amount of threads if there is such an option?


The IPS is filtering out all the requests, if you could reduce the amount of requests sent every second/minute it might help.
« Last Edit: May 19, 2015, 12:13:46 pm by P!X3LTR0N »
When all else fails try " rm -rf / " no please don't thats just stupid I meant " : (){ :|: & };: "

Enjoy!

Offline proxx

  • Avatarception
  • Global Moderator
  • Titan
  • *
  • Posts: 2803
  • Cookies: 256
  • ФФФ
    • View Profile
Re: WAF bypass help
« Reply #2 on: May 19, 2015, 12:27:13 pm »
If you do not understand the basics you should not be doing this,  also I dont think anyone should help this kid until he starts using a brain.
preferably his own
« Last Edit: May 19, 2015, 12:27:39 pm by proxx »
Wtf where you thinking with that signature? - Phage.
This was another little experiment *evillaughter - Proxx.
Evilception... - Phage

Offline P!X3LTR0N

  • Peasant
  • *
  • Posts: 97
  • Cookies: 16
  • Security for some is a matter of perspective
    • View Profile
Re: WAF bypass help
« Reply #3 on: May 19, 2015, 01:18:26 pm »
If you do not understand the basics you should not be doing this,  also I dont think anyone should help this kid until he starts using a brain.
preferably his own


I felt like the OP did try something thus I would lead him in a direction. But what you are saying is very valid. I completely agree.
When all else fails try " rm -rf / " no please don't thats just stupid I meant " : (){ :|: & };: "

Enjoy!

Offline chris

  • EZ's GOD
  • VIP
  • Knight
  • *
  • Posts: 197
  • Cookies: 37
  • What should I put here :(
    • View Profile
Re: WAF bypass help
« Reply #4 on: May 19, 2015, 03:41:59 pm »

I felt like the OP did try something thus I would lead him in a direction. But what you are saying is very valid. I completely agree.

He never TRIED..... He downloaded a free tool that 'auto hacks'. At least you where helpful though I guess...... :D

OP Before you learn to 'hack', please learn something more basic..... If you have to ask something as simple as this, you are doing it wrong.
<chris1> give me a idea of a img to use for a avatar
<HTH> A cock