{"id":20445884,"url":"https://github.com/rapid7/mybff","last_synced_at":"2025-08-21T11:33:31.169Z","repository":{"id":66307140,"uuid":"53071356","full_name":"rapid7/myBFF","owner":"rapid7","description":"myBFF - a Brute Force Framework","archived":false,"fork":false,"pushed_at":"2023-12-20T14:47:54.000Z","size":112,"stargazers_count":138,"open_issues_count":1,"forks_count":31,"subscribers_count":28,"default_branch":"master","last_synced_at":"2024-12-18T06:23:44.330Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"","language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/rapid7.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE.txt","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2016-03-03T17:56:13.000Z","updated_at":"2024-11-14T22:38:58.000Z","dependencies_parsed_at":"2023-12-20T16:14:39.219Z","dependency_job_id":null,"html_url":"https://github.com/rapid7/myBFF","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/rapid7%2FmyBFF","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/rapid7%2FmyBFF/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/rapid7%2FmyBFF/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/rapid7%2FmyBFF/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/rapid7","download_url":"https://codeload.github.com/rapid7/myBFF/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":230511479,"owners_count":18237657,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-11-15T10:15:11.428Z","updated_at":"2024-12-19T23:14:07.247Z","avatar_url":"https://github.com/rapid7.png","language":"Python","funding_links":[],"categories":[],"sub_categories":[],"readme":"# myBFF - a Brute Force Framework\n```\n                         `.-:-.`           `.-::-.`\n                     `:oyhhyooooo+:`    -+osooooyhhs+.\n                   `/yhhs:`      `.-.`-/:.      `./syyo.\n                  `shyy:            `-.            .+yyy.\n    \\M:         `ohyy/             `               `/yys\n    :M:          .hyyy-                              .yyy.\n    :M:          -hyyy/                              .hhy`\n    :M:          `shyyy:                            `ohh+\n    :M:           .shyyy+.                         .shh+`\n    :M:            .+hhhyyo-`                    `/yho-\n    :M:             `-ohhhhhy+-`               .+yy+-\n    /M:              `./syhhhhs/.          -/os+-`\n                         `.-+syddho-     `:+/-`\n                             `.-+yddo.  `/.\n                                 `-ohh- ``\n                                   `-yh.\n                                     .yo\n                                      -s\n                                      ./\n                                      `\n                               -.`--:--:..`         -.//:.:-////://:.`/o/ `.-/:--::///:://-.`o+-\n                              .hNdNNdyhmNmds.       .sMMMmMmyhhosshdm+NMh `-dMMNNMdyhyosyhdyyMM/\n                               /MMNN:  .hMMMs        oMMMMMo       `:-NM-   dMMMMN-       `:oMd`\n                               .MMMN-   +MMm-        /MMMMd`         `hM`   yMMMMo          .Mh\n                               `MNNM+ .:mMs+`        -NMMMd       ``  sm`   sMMMMo       .   No\n                               `NMMNsymMMh--``       `yMMMd      .yo  :o    .NMMM+     `:d.  s-\n                               `dMMMMMMMMNMMddho:    -NMMMy    `sNM-  .:    oMMMM:    .dNh`  :.\n                               .NMMmMd++//omMMMMM-   `NMMMNo+-+hMMm         /MMMMd+/:omMMo\n                               `MMNmM:     -NMMMM/   /MMMMMNdmNNMMd         yMMMMMmdmNMMM+\n                               `mmNds       sMMMM.   -MMMMm.``.:sNm         sMMMMs``..:dMo\n                               `hNNm:       +MMMN`   `mMMMy`     -y`        :MMMM/     `+s\n                               -MNmM:       :MMMy    -NMMMh.       `        oMMMMo\n                               .NmMM+       yMMd`    `hMMMm`                -NMMMs\n  yms`.:+o` `-//`               hNMMs       hMN/     .mMMMd                 +MMMM+\n  sMNssoNMhyyodmh``dm/   -+yh`  oNMNd      .dM:      `hMMMm`                :NMMMs\n  /md`  +MMo  `:N: mN.    omo  `NMMMh    `sNms       :dMMMm                 oNMMMo\n   dd   `mM.   -N+ sd     oMo   hMMMN/-/yddo/        :MMMMm.                sMMMMh\n  .N+    /N:   sMs ym-``-oNMo  .mMMMNdmds.           /MMMMM+`               yMMMMm:\n  /ms:  `oh:   /hh-:ydyyo/+No ::/yhoso:`             ohdhydhs/             `hddyhdyo.\n                      `   :No                                `                     `\n                          `mo\n                          `mo\n                          `mo\n                 :-      `sN:\n                ++      -yNo\n               oy   `-+hh+.\n              -mdoooo+-`\n               ..`\n--- A Brute Force Framework by Kirk Hayes (l0gan)\n--- myBFF v1.5.1\n```\nmyBFF is a web application brute force framework (currently)\n\nPoint the framework at a file containing usernames, a host, and give it a password. The framework will determine what type of web application is in use, then attempt to brute force accounts. After brute forcing accounts, myBFF will then do a little more, like enumerating apps available, and reading in important data. Each module is different so try them out!\n\n## Current modules:\n\n- HP SiteScope (will attempt to give you a Meterpreter Shell!)\n- Citrix Gateway (also enumerates authorized applications)\n- Juniper Portal (Will look for 2FA bypass and list what is accessible)\n- MobileIron (Unknown. Have to find out what is accessible first!)\n- Outlook/Office365 (will parse email, contacts, and other data from email)\n- Wordpress (Will be adding \"SomethingCool\" soon)\n- CiscoVPN (Enumerate User accounts (May not work on all configurations))\n- Okta (Enumerate Applications and check if 2FA is setup for account)\n- Jenkins (Will be adding \"Something Cool\" soon)\n- SMB (Check if user is an administrator) (must use --domain with this module. for host, use smb://)\n- FTP (List root dir contents)\n\nNew modules will be added.\n\n## CONFIGURATION\nmyBFF requires lxml and pysmb. \n\nInstall using \n\n'sudo apt-get install python-lxml'\n\n'sudo pip install pysmb'\n\n## USE:\nhttps://github.com/MooseDojo/myBFF/wiki/Use\n```\npython myBFF.py --host https://example.com -U userfile.txt -p password123\n--host - Host including protocol. Protocols currently support http, https, and smb only.\n-u \u003cusername\u003e - test single username\n-U \u003cusernameFile\u003e - username file\n-p \u003cpassword\u003e - password\n-P \u003cpasswordFile\u003e - password file\n-d - dry run mode (skip somethingCool/password guessing only)\n--vhost \u003cvirtualDirectory\u003e (optional) - virtual hosting. This is for when you have a site where https://example.com goes to one page, but https://example.com/owa goes to another\n-o \u003coutputFile\u003e - output file\n--timeout \u003cvalue\u003e - timeout (Used to pause during password file attacks.)\n```\n\n## Planned Development:\n\nSee: https://github.com/MooseDojo/myBFF/wiki/Future-Plans\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Frapid7%2Fmybff","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Frapid7%2Fmybff","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Frapid7%2Fmybff/lists"}