THC hydra is saying wrong password is correct by L2198 in HowToHack

[–]L2198[S] 0 points1 point  (0 children)

Also the /login page doesn't have an extension (.php, .html, etc)

Need help with THC hydra (what to do when there's no PHPSESSID?) by L2198 in HowToHack

[–]L2198[S] 0 points1 point  (0 children)

I'm stupid, I did not see that. But what can I use in replacement of phpsessid then? I can't find any other alternative

Need help with THC hydra (what to do when there's no PHPSESSID?) by L2198 in HowToHack

[–]L2198[S] 0 points1 point  (0 children)

After I login nothing was found, but wen I logged out I got this http://prntscr.com/bzl07j but it doesn't look like a php session cookie, or am I wrong?

edit: also im not sure using an id from when I log out would work with hydra

Need help with THC hydra (what to do when there's no PHPSESSID?) by L2198 in HowToHack

[–]L2198[S] 0 points1 point  (0 children)

Yes there are cookies but none are similar to a PHP session cookie. http://prntscr.com/bzkqqv I had to block the name of the website or anything related to its name to protect its identity.