Predict, test, and explain. Everything here runs in this browser file with made-up data. No account or internet connection is needed.
The browser starts blank. Choose a protocol to load the pretend website. The login details and network trace are invented.
Predict: What will a hallway observer see when this site sends a login over HTTP? What changes with HTTPS?
Sign in with the pretend details below.
Choose HTTP or HTTPS. Then send the pretend login.
This trace shows the idea. Real packets contain more fields.
HTTPS encrypts the request and verifies the destination. A network observer can often infer the destination, but cannot read the encrypted form fields. An encrypted connection does not fix bugs inside a site.
The browser requested clubhouse.example, but the certificate names games.example. Compare the address bar and the warning. What should you do?
The certificate is for games.example, but the address bar says clubhouse.example. The browser cannot verify this site's identity.
NET::ERR_CERT_COMMON_NAME_INVALID
The https:// text alone does not prove that you reached the intended site. The browser warning says it cannot verify this site's identity.
Predict: How many possible codes have three digits? What if we add one more digit?
10 × 10 × 10, including 000.
Ten times as many possibilities.
26 × 26 × 26 × 26 possibilities.
The command line below uses short, Hydra-inspired classroom commands for preset fake secrets. Choose an example, then press Run. These shortcuts are not complete Hydra commands.
Simulation ready. Type hydra -h and press Enter, or choose an example above.
The word search uses a short sample list. “Dragon” is a playable Scrabble word. This is not the complete dictionary. The simulated results do not measure real guessing speed. Real sites can enforce rate limits and other defenses.
You are signed in as Alice Hart. Alice owns account number 103. This pretend bank has accounts 1 through 109.
Predict what happens when you change the account ID to 2, 50, or 109.
All 109 accounts contain invented data. First open another ID with the ownership check off. Turn the check on and try again. The server must check ownership on every request.