Making a post just to clarify an issue I experienced in the “Broken Authentication” Module. The Default Credentials page in the Login Bruteforcing segment of the module has a challenge that requires you to use default credentials to log in via a web form.
ya, do not use that list. Google it and found this one usefulhttps://www.192-168-1-1-ip.co/router/advantech/advantech-webaccess-browser-based-hmi-and-scada-software/11215/
Yes thanks. Some of the questions are quite frustrating where the lesson tells you to use certain things, but then the end question requires something completely different.
Thank you for sharing this valuable information and warning about the challenge in the “Broken Authentication” module. It’s essential for others to be aware that the file scada-pass.csv from the SecLists repository does not contain the necessary username for completing the challenge. Instead, the correct username can be found on the website SCADA Default Password List