Jump to content

C-Force 1.01b


Black pearl

Recommended Posts

  • Replies 93
  • Created
  • Last Reply

Top Posters In This Topic

This is the hidden content, please

This is the hidden content, please

 

C-Force is a bruteforcer in the purest meaning of the word. It has been designed to test a list of username and password combinations against the login of a site. It allows a webmaster to test the security of his site against bruteforce attacks. C-Force is build so that it detects the type of protection and it will perform a bruteforce test according to its analyse, at the moment C-Force recognises basic authorization and form logins (without verification code) for http sites. C-Force works with full proxy support or with direct connect, it also has a link-checker for fast checking of a list of logins.

 

Notes that you need to read:

1. C-Force is as good as your wordlist, this means if your wordlist is outdated and has no working combo in it, then you can't get a hit with C-Force...

2. C-Force needs proxies... and anonimous ones... and as many as possible if you want toperform an anonimous test.

 

How To use C-Force

 

C-Force fresh started

 

1. Go to AUTO , load proxie list, load combo list, put member URL in

2. Hit START

 

New wordlist - same site as previous session

 

1. Load new wordlist

2. Hit start

 

New site - same wordlist

 

1. Enter member-url in auto-tab

2. Load wordlist again

3. Press Start

 

Same site - same wordlist after abort

 

1. Press Resume

 

Basic return codes

 

ALL memberpages are 200 ok and that is the only thing we're looking for. For pop-up logins: basically you can state that you have 401 for a bad combo (the C-Force engine handles all of them the way they should be handled)and 200 for a working combo. For Form-logins: Only 200 ok is good. By the way... all fakes have a 200 ok code as well. Some 200 ok however are also caused by bad proxies but these are detected by c-force in most of the cases. Some 200 ok are bad combo's cause the server sends you a different error page... C-Force can not detect it by itself but you can adjust it's accuracy during the bruteforce process.

All the other replies are caused by proxy problems, connection problems or server related problems. The better your proxies, the more decent messages you will have.

"bad server reply"

 

"Bad server reply" is used when you receive no header from the server.

Most of the time it's caused by bad proxies or sometimes when a server is overloaded or even your own system is overloaded (too much traffic on your connection)

But you can always enable debugmode... C-Force then saves all actions (sended headers + received headers and content) in files per bot.

 

*** hidden content ***

 

This is the hidden content, please

 

This is the hidden content, please

thanks dude

Link to comment
Share on other sites

  • 2 weeks later...
  • 3 weeks later...
  • 2 months later...
  • 2 weeks later...
  • 3 months later...
  • 1 month later...
  • 1 month later...

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.


×
×
  • Create New...