
• Gotta work for it…
• Brute Force RDS Access (If Enabled)
– Check if RDS is enabled
– Brute force RDS
• Brute Force Admin Interfaces
– Main login page uses a salt that changes every 60 sec
– Use another login page also accepts admin password
• Set’s cookie when you guess the right password
• No account lockouts
• Depending on version no username required
• No password complexity requirements
• No real logging (web server logging)
Attacking ColdFusion
Comentarios a estos manuales