NIbbles

Hey for those that have been struggling with the login credentials.

If you run the tool cewl to generate the password list from http:///nibbleblog/, then cleanup the data (remove things that are obviously not going to be the passwords). Take the remaining data and convert string to upper and lower case. You should be able to find the password. The login credentials can easily be found by enumerating sub directories using your favorite tools for finding content (burp spider worked for me) and searching the files for clues.

Note, it looks like people are changing the password periodically, so if the password doesn’t hit. Maybe a reset on the box is needed if you don’t find it during your first pass.

I hope this helps anyone that is still struggling with this box.

Regards,
DJ