ObiWaN – Web Server Brute Forcing from Phenoelit

Find your website's Achilles' Heel


This Phenoelit tool called ObiWaN is written to carry out brute force security testing on Webservers.

The idea behind this is webservers with simple challenge-response authentication mechanism mostly have no switches to set up intruder lockout or delay timings for wrong passwords. In fact this is the point to start from. Every user with a HTTP connection to a host with basic authentication can try username-password combinations as long as he/she likes.

Like other programs for UNIX system passwords (crack) or NT passwords (l0phtcrack) ObiWaN uses wordlists and alternations of numeric or alpha-numeric characters as possible passwords. Since Webservers allow unlimited requests it is a question of time and bandwith to break in a server system.

The most interesting targets are web based administration frontends like Netscapes Server Administration. If you can break in, you are able to create accounts, stop the server and modify its content. Real fun.

You can read the full documentation here.

Various versions (including Windows, Linux and Solaris) of ObiWaN are available for download here:

ObiWan – Project 2068/11.1


Posted in: Hacking Tools, Password Cracking, Web Hacking

, , , , , , , , , ,

Recent in Hacking Tools:
- Unicorn – PowerShell Downgrade Attack
- Wfuzz – Web Application Brute Forcer
- wildpwn – UNIX Wildcard Attack Tool

Related Posts:

Most Read in Hacking Tools:
- Top 15 Security/Hacking Tools & Utilities - 1,978,150 views
- Brutus Password Cracker – Download brutus-aet2.zip AET2 - 1,420,437 views
- wwwhack 1.9 – Download wwwhack19.zip Web Hacking Tool - 678,978 views

Malwarebytes Anti-Exploit Premium | 1 Year 1 PC for $24.95


Trackbacks/Pingbacks

  1. Internet Security and Programming » Blog Archive » ObiWaN - Web Server Brute Forcing from Phenoelit - March 23, 2007

    […] category News. You can read any responses through the RSS 2.0 feed. You can give a response, or trackback from your site. « Microsoft: Kill screensavers, not the planet ‘Government forkids’ website launched » […]