You're using the wrong tools for this job, you can't just point burp proxy at this with a list of passwords. The "password" never gets sent to the server, all encryption/decryption is done locally in the browser and your browser sends out signed transactions. There's no traditional login api on a central server for you to brute force. You could've just tried the list of passwords in the browser manually by now :P
You are viewing a single comment's thread from: