Password Spraying
Using Username/Password Lists
You can use multiple usernames or passwords by seperating the names/passwords with a space.
CME accepts txt files of usernames and passwords. One user/password per line. Watch out for account lockout!
By default CME will exit after a successful login is found. Using the --continue-on-success flag will continue spraying even after a valid password is found. Usefull for spraying a single password against a large user list Usage example:
Checking login == password using wordlist
Checking multiple usernames/passwords using worlist
The result will be:
user1 => password1
user1 => password2
user2 => password1
user2 => password2
Be careful to not lock accounts using this technique
Checking one login equal one password using wordlist
No bruteforce possible with this one as 1 user = 1 password
The result will be:
user1 => password1
user2 => password2
Avoid range or a list of IP when using option --no-bruteforce
Last updated