Tuesday, June 4, 2024

Is there a way to bypass web app client side hashing?


I am learning how to use Evilginx and the website I am testing on hashes the login forms password with a salt from the client side when I try to intercept the login page HTTP request via burpsuite. I know that this is probably done by some javascript function, but I can't seem to find it. Perhaps I am wrong and it's impossible, but I'm not sure. During the intercept I can see the hashed password, the salt and the token. by HowToHack on Reddit.com Is there a way to bypass web app client side hashing? - I am learning how to use Evilginx and the website I am testing on hashes the login forms password with a salt from the client side when I try to intercept the login page HTTP request via burpsuite. I know that this is probably done by some javascript function, but I can't seem to find it. Perhaps I am wrong and it's impossible, but I'm not sure. During the intercept I can see the hashed password, the salt and the token.
buy funny gadgets: https://ebay.us/5MCoAl title=

Comments System

Disqus Shortname

Disqus Shortname

designcart
Powered by Blogger.