logo

More Complex Intruder Attacks with Burp!

ID: 56e083a5-33ec-5344-b09e-e22be4c03d36

STIX ID: report--56e083a5-33ec-5344-b09e-e22be4c03d36

Feed Name: TrustedSec blog

Threat Score
45/100

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

This write-up details an external penetration test targeting a firewall's browser-based SSL VPN: the author reverse-engineers the login JavaScript (which builds a CHAP-style MD5 digest from form values and the password), extracts the logic locally, and integrates it into Burp Intruder via a custom external command to automate password-spray and brute-force attacks while describing operational trade-offs and session handling considerations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.