Minichan

Topic: I want to be a script kiddie and run a dictionary attack on a twitter account

Anonymous A started this discussion 14 years ago #17,733

Can anybody point me in the right direction as to where I can get started?

Ks !KansasxqvM joined in and replied with this 14 years ago, 48 seconds later[^] [v] #297,927

brute force lol

Anonymous A (OP) replied with this 14 years ago, 29 seconds later, 1 minute after the original post[^] [v] #297,930

@previous (Ks !KansasxqvM)
I don't know any other way.

Ks !KansasxqvM replied with this 14 years ago, 2 minutes later, 3 minutes after the original post[^] [v] #297,933

@previous (A)
Social engineering or phishing is the way to go. Why do you want to do this?

Anonymous A (OP) replied with this 14 years ago, 1 minute later, 5 minutes after the original post[^] [v] #297,935

@previous (Ks !KansasxqvM)
There's this shitty, pathetic excuse for a news blog that's insulted my friends and the organization I work for one too many times.

Ks !KansasxqvM replied with this 14 years ago, 2 minutes later, 7 minutes after the original post[^] [v] #297,936

@previous (A)
I imagine Twitter has security in place to prevent brute force, it'd be just silly if they didn't. Unless you plan on hacking Twitter's database (lolno), it's time to get creative.

Anonymous A (OP) replied with this 14 years ago, 2 minutes later, 9 minutes after the original post[^] [v] #297,937

@previous (Ks !KansasxqvM)
The blog publisher is a massive potential lolcow and I often masturbate to thoughts of what I could do if I had an army of the size and determination that went after Kimmo.

Anonymous C joined in and replied with this 14 years ago, 3 hours later, 3 hours after the original post[^] [v] #297,975

you need pure will power

Anonymous D joined in and replied with this 14 years ago, 41 minutes later, 4 hours after the original post[^] [v] #297,991

@297,936 (Ks !KansasxqvM)
> I imagine Twitter has security in place to prevent brute force
Dictionary attacks worked well enough to crack some pretty high profile Twitter accounts (Britney Spears, Obama, FOX News, etc.) back in 2009. After that, Twitter started locking down accounts after too many failed attempts were made. There were some problems with just locking down accounts though: Not only could someone attempting to crack your password freeze you out of accessing your account, but people managed to lock themselves out of their accounts after changing and forgetting their passwords or when their apps tried to automatically log them in repeatedly with old passwords.

I would guess that they have something in place now that checks failed attempts per user (by browser session or IP address or something) and blocks repeated attempts per session or IP. Twitter has a metric fuckton of traffic though. I imagine you would have to do something spectacularly blatant to trigger anything more than a temporary IP ban or cool-down period.

@OP
Why not? Start compiling some dictionary files and tailoring them to your target. Write some scripts and play around. Find out how many attempts per hour are possible before Twitter shitlists your IP and what the cool-down period is once that happens. Report back to us with --incriminating evidence we can use against you-- exciting stories of --pending litigation against you-- your exploits. If that fails, maybe just get into their email and tell Twitter to reset their password via email.

adam jensen !AIy/L67q.s joined in and replied with this 14 years ago, 7 hours later, 11 hours after the original post[^] [v] #298,057

Doesn't it require e-mail confirmation after you enter the password wrong 3 times?

Anonymous F joined in and replied with this 14 years ago, 2 minutes later, 11 hours after the original post[^] [v] #298,058

@297,935 (A)
What reason would they have to do that?

protip !!pMmAiEwOm joined in and replied with this 14 years ago, 4 hours later, 16 hours after the original post[^] [v] #298,112

lolno
:

Please familiarise yourself with the rules and markup syntax before posting.