Git Product home page Git Product logo

masonhackathon's Introduction

#MasonHackathon

This code is from the first-place prize in social engineering and brute force attacks.

Problem statement: George Mason University has a vulnerability in its username and password management for the redhat HTTP Server.

Background: Usernames are publicly available at (ssh:https://binf.gmu.edu/). Given the usernames, passwords are dictated by the username plus the last four digits of the student or faculty ID number.

Solution: Brute force password checks of username+4-digits provides access to the restricted folders.

Suggestions: Require users upon account creation to set a new unique password, or link to university password. Restrict access to the root folder containing usernames. This system should be designed to block or delay repeated access attempts to prevent this kind of attack.

Warning: This script is trying to brute force the SSH login of a server by guessing passwords. Accessing a computer system without authorization is a crime in many jurisdictions, including under the United States Computer Fraud and Abuse Act (CFAA), and typically against the terms of service of any legitimate service provider. The code provided was used on my own account under the supervision of MasonHacks a group dedicated to finding vulnerabilities in and ethical manner.

masonhackathon's People

Contributors

nminster avatar

Stargazers

 avatar

Watchers

 avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.