Testing default web credentials
- pma bf
- top 300 passwd
- "rd" option
- News default usernames, passwords, inputs endpoints
- fix any bugs
- Fixed cross-module
NameErrors (globals that were never shared between modules) - Fixed argument-order bugs in the
bf_top_password()calls (bruteforce now receives the right params) - Fixed malformed ANSI escape codes in the live status lines
- Fixed
-U:-uis now correctly treated as a URLs file, and a hit on one URL no longer aborts the whole batch - Fixed
time.sleep()on rate-limit (was passing a string),KeyErrors on unknown templates, and the broken input-detection parser - Fixed the bruteforce progress counter (it now resets per username and shows
user (i/N) | pass i/N) - Python 3.12 compatible;
requirements.txtnow listsmmh3(needed by the favicon fingerprint) - Content/header/cookie fingerprint in addition to the favicon hash (Django, Grafana, Jenkins, GitLab, WordPress, Joomla, phpMyAdmin, Tomcat)
- Form-aware login submission: the tool now parses the real login form, carries over its hidden fields (CSRF tokens, framework markers like Django's
this_is_the_login_form) and persists cookies (sessionid,csrftoken) through a session, and setsReferer— so CSRF-protected apps (Django & co.) can actually be tested --rbraw request replay: feed a raw HTTP request copied from Burp/ZAP and bruteforce it directly (auto-detects the username/password fields, replays cookies + hidden fields + headers verbatim)-T/--technoforce the technology: skip fingerprinting and go straight to a known techno's default creds + form template (--list-technoprints the supported names)- Expanded default-credentials DB to 90 technologies / 200+ credentials (Django, Grafana, Jenkins, GitLab, Nexus, JBoss, WebLogic, Zabbix, Nagios, Proxmox, iDRAC, iLO, Cisco, Fortinet, Citrix, Confluence, Jira, RabbitMQ, MinIO, Hikvision, and many more), with content/header/cookie fingerprints for each
git clone https://github.com/c0dejump/CredzCheckr.git
cd CredzCheckr
pip3 install -r requirements.txt
usage: credzcheckr.py [-h] [-u URL] [-U] [-w] [-b] [-i INPUTS] [-k [KEY_WORDS ...]] [-d DOMAIN]
[-X POST_REQUEST] [-uap] [-T TECHNO] [--list-techno] [--user USER_KNOWN] [--cookie COOKIE_] [--onlypass]
[--rf REQ_FILE] [--rd REQ_DATA] [--rb REQ_BURP] [--nomessage NOMESSAGE]
optional arguments:
-h, --help show this help message and exit
-u URL URL login to test [required]
-U, --urls_file Treat -u as a file containing one URL per line.
-w list of your passwords to test Default:
credz/wordlists/top_300_default_passwd.txt
-b, --bruteforce Bruteforce username/password
-i INPUTS, --inputs INPUTS
if that not found inputs during the scan, this option add auto in inputs.txt
file. Ex: -i "user:passwd"
-k [KEY_WORDS ...], --key_words [KEY_WORDS ...]
if you want add personal password in list
-d DOMAIN, --domain DOMAIN
Add domain to test all combinaison like domain@2019, domain2021...
-X POST_REQUEST POST requests URL Ex: credzcheckr -u toto.com/login -X
toto.com/login_check
-uap, --user-as-pass test user-as-pass
-T TECHNO, --techno TECHNO
Force the technology instead of fingerprinting it (e.g. -T django)
--list-techno List the supported technologies and exit
--user USER_KNOWN If you want test just a known username
--cookie COOKIE_ To add cookie
--onlypass If there is just only password to test
--rf REQ_FILE Json file containing the indications to carry out for a request
--rd REQ_DATA TXT file containing the data of the requests with 'BFU' for username & 'BFP' for password params (exemple in config/request_data.txt)
--rb REQ_BURP TXT file containing a raw HTTP request (Burp/ZAP). Creds auto-detected or marked with BFU/BFP
--nomessage NOMESSAGE
if the value of this option is not found in the source code of the page it
will be considered as potentially found
//Basic
python3 credzcheckr.py -u URL/login.php
// With particular inputs
python3 credzcheckr.py -u URL/login.php -i "user_input:password_input"
// With a domain name
python3 credzcheckr.py -u facebook.com/login.php -d facebook
// BF default username/password
python3 credzcheckr.py -u URL/login.php -b
// Force the technology (skip fingerprinting)
python3 credzcheckr.py -u URL/admin/ -T django -b
python3 credzcheckr.py --list-techno
// With specific format requests file
python3 credzcheckr.py --rf config/request_json.json
// Replay a raw Burp/ZAP request and bruteforce it (creds auto-detected)
python3 credzcheckr.py --rb request.txt -b
// -> paste the raw request into request.txt; mark the fields with BFU/BFP
// if auto-detection misses them, e.g. username=BFU&password=BFP
// With nomessage option
python3 credzcheckr.py -u URL/login.php -b --nomessage "incorrect"
// With POST redirect URL
python3 credzcheckr.py -u URL/login.php -X URL/login_check.php
- [IP] Different credentials forms
- Get (nmap) file to scan
- Captcha bypass
- Selenium when javascript do enable
- Bruteforce with user@domain.(fr/en...)
- MF'er BF (bf as a dirty all possible combinations (have a good cpu) )
- ztgrace for "changeme" tool https://github.com/ztgrace/changeme
- For other default password wordlist:
- pma bf based on https://github.com/pendoubleg/phpmyadmin-authentication-bruteforce

