OTP offline brute-force with burpsuite
一位用户尝试通过Kali和Burp Suite对Instagram iOS应用进行离线暴力破解OTP的挑战。由于仅限于自己的设备发起会话请求,用户计划模拟请求并拦截后尝试本地破解。用户询问这种方法是否可行或是否为死胡同,并提到Instagram的限流机制和之前token hijacking未被重视的情况。 2025-7-10 09:59:44 Author: www.reddit.com(查看原文) 阅读量:13 收藏

hi hi,

I have a challenge for myself: to get an OTP by offline brute-force with kali & burpsuite. The objective is the instagram iOS app but with a difficulty, only my device is the one that had the session initiated from the account, and therefore access to request the OTP.

Don’t wanna know how, only if the effort can be worthy or if is a dead end

The idea would be to simulate that the request is from my device, intercept the request to try local brute-force, and send only the real request. Do you think is doable or shouldn't I even try? Insta have a good rate limitting or can you have a chance somehow?

for the token hijacking someone did me, instagram didn't take it so seriously so I don't know how they work with this validations hahahahaha

viable? thanks! (script kiddie insults allowed)


文章来源: https://www.reddit.com/r/HowToHack/comments/1lw8th4/otp_offline_bruteforce_with_burpsuite/
如有侵权请联系:admin#unsafe.sh