{"id":16,"date":"2023-10-15T12:50:29","date_gmt":"2023-10-15T04:50:29","guid":{"rendered":"http:\/\/54.254.190.68\/note\/archives\/16"},"modified":"2025-07-27T18:23:35","modified_gmt":"2025-07-27T10:23:35","slug":"burpsuite-introduce","status":"publish","type":"post","link":"https:\/\/systw.net\/note\/archives\/16","title":{"rendered":"burpsuite"},"content":{"rendered":"\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Burp Suite\u529f\u80fd\u6982\u8981\uff1a<\/h3>\n\n\n\n<p>\u57fa\u672c\u529f\u80fd<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Proxy\uff1a\u5c07Burp\u914d\u7f6e\u70baWeb\u4ee3\u7406\uff0c\u4f4d\u65bc\u700f\u89bd\u5668\u548c\u76ee\u6a19Web\u670d\u52d9\u5668\u4e4b\u9593\u3002\u9019\u4f7f\u5f97Burp\u80fd\u5920\u6514\u622a\u3001\u6aa2\u67e5\u548c\u4fee\u6539\u5728\u5169\u500b\u65b9\u5411\u4e0a\u901a\u904e\u7684HTTP\u5167\u5bb9\u3002<\/li>\n\n\n\n<li>target\uff1a\u53ef\u9650\u5236\u5206\u6790\u7bc4\u570d\uff0c\u4e26\u5efa\u7acb\u7ad9\u9ede\u5730\u5716<\/li>\n\n\n\n<li>Intruder\uff1a\u53ef\u5229\u7528Intruder\u9032\u884c\u66b4\u529b\u7834\u89e3\u653b\u64ca\uff0c\u4e5f\u53ef\u6aa2\u6e2cSQL\u6ce8\u5165\u3001XSS\u7b49\u6f0f\u6d1e\u3002<\/li>\n\n\n\n<li>Repeater\uff1a\u7528\u65bc\u624b\u52d5\u6e2c\u8a66HTTP Request\u7684\u7c21\u55ae\u529f\u80fd\uff0c\u53ef\u4ee5\u4fee\u6539\u8acb\u6c42\u7684\u5167\u5bb9\uff0c\u91cd\u65b0\u767c\u9001\u4e26\u89c0\u5bdf\u7d50\u679c\u3002<\/li>\n\n\n\n<li>Decoder\uff1a\u5c07\u5df2\u7de8\u78bc\u7684\u6578\u64da\u8f49\u63db\u70ba\u5176\u898f\u7bc4\u5f62\u5f0f\uff0c\u6216\u5c07\u539f\u59cb\u6578\u64da\u8f49\u63db\u70ba\u5404\u7a2e\u7de8\u78bc\u548c\u6563\u5217\u5f62\u5f0f\u7684\u5de5\u5177\u3002<\/li>\n\n\n\n<li>Comparer\uff1a\u5728\u4efb\u610f\u5169\u500b\u6578\u64da\u9805\u4e4b\u9593\u57f7\u884c\u6bd4\u8f03\uff08\u4e00\u500b\u53ef\u8996\u5316\u7684\u5dee\u7570\uff09\u7684\u5de5\u5177\u3002<\/li>\n\n\n\n<li>Extender\uff1a\u5141\u8a31\u52a0\u8f09\u5176\u4ed6Burpsuite app\uff0c\u4f7f\u7528\u5b89\u5168\u6e2c\u8a66\u4eba\u54e1\u81ea\u5df1\u7684\u6216\u7b2c\u4e09\u65b9\u4ee3\u78bc\u64f4\u5c55Burp\u7684\u529f\u80fd\u3002<\/li>\n\n\n\n<li>Sequencer\uff1a\u5206\u6790\u6578\u64da\u9805\u6a23\u672c\u96a8\u6a5f\u6027\u7684\u5de5\u5177\u3002\u5b83\u53ef\u7528\u65bc\u6e2c\u8a66\u61c9\u7528\u7a0b\u5f0f\u7684\u6703\u8a71\u4ee4\u724c\u6216\u5176\u4ed6\u91cd\u8981\u7684\u6578\u64da\u9805\uff0c\u5982\u53cdCSRF\u4ee4\u724c\u3001\u5bc6\u78bc\u91cd\u7f6e\u4ee4\u724c\u7b49\u3002<\/li>\n<\/ul>\n\n\n\n<p>\u5c08\u696d\u7248\u6709\u53e6\u5916\u63d0\u4f9b\u4ee5\u4e0b\u529f\u80fd<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Scanner\uff1a\u9019\u662fweb\u7db2\u9801\u5f31\u9ede\u6383\u63cf\u5de5\u5177\uff0c\u53ef\u505a\u81ea\u52d5\u7db2\u6383 <\/li>\n\n\n\n<li>Burp Collaborator\uff1a\u53ef\u7528\u4f86\u6e2c\u8a66\u662f\u5426\u53ef\u8a2a\u554f\u5916\u90e8\u670d\u52d9<\/li>\n<\/ul>\n\n\n\n<p><\/p>\n\n\n\n<p>refer<br><a rev=\"en_rl_none\" href=\"https:\/\/ithelp.ithome.com.tw\/articles\/10214839\" target=\"_blank\" rel=\"noopener\">https:\/\/ithelp.ithome.com.tw\/articles\/10214839<\/a><br><a rev=\"en_rl_none\" href=\"https:\/\/t0data.gitbooks.io\/burpsuite\/content\/chapter3.html\" target=\"_blank\" rel=\"noopener\">https:\/\/t0data.gitbooks.io\/burpsuite\/content\/chapter3.html<\/a><br><a rev=\"en_rl_none\" href=\"https:\/\/portswigger.net\/support\/how-to-use-burp-suite\" target=\"_blank\" rel=\"noopener\">https:\/\/portswigger.net\/support\/how-to-use-burp-suite<\/a><br><a href=\"https:\/\/portswigger.net\/support\/configuring-your-browser-to-work-with-burp\" target=\"_blank\" rel=\"noopener\">https:\/\/portswigger.net\/support\/configuring-your-browser-to-work-with-burp<\/a><\/p>\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\u9032\u968e\u4f7f\u7528\u65b9\u5f0f<\/h2>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u4f7f\u7528\u689d\u4ef6\u7af6\u901f\u540c\u6642\u767c\u9001\u8acb\u6c42<\/h3>\n\n\n\n<p>\u5c07\u8acb\u6c42\u50b3\u9001\u5230<code>repeater<\/code>\u529f\u80fd\uff0c\u7136\u5f8c\u5efa\u7acb\u7fa4\u7d44\uff0c\u628a\u591a\u500b\u8acb\u6c42\u79fb\u5230\u7fa4\u7d44\u4e2d<\/p>\n\n\n\n<p>\u5728\u91cd\u9001\u7fa4\u7d44\u4e2d\u6709\u4ee5\uff13\u7a2e\u767c\u9001\u65b9\u5f0f\uff0c\u9078\u64c7<code>parallel<\/code>\u5c31\u53ef\u4ee5\u5be6\u73fe\u689d\u4ef6\u7af6\u901f\u540c\u6642\u8acb\u6c42<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Send group in sequence (single connection)<\/li>\n\n\n\n<li>Send group in sequence (separate connections)<\/li>\n\n\n\n<li>Send group in parallel&nbsp;<\/li>\n<\/ul>\n\n\n\n<p><\/p>\n\n\n\n<p>refer<br><a href=\"https:\/\/portswigger.net\/burp\/documentation\/desktop\/tools\/repeater\/send-group\" target=\"_blank\" rel=\"noopener\">https:\/\/portswigger.net\/burp\/documentation\/desktop\/tools\/repeater\/send-group<\/a><\/p>\n\n\n\n<p>\u529f\u80fd\u6e2c\u8a66\u53ef\u53c3\u8003:<br>lab: limit overrun race conditions<\/p>\n\n\n\n<p><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u6307\u5b9a\u6514\u622a\u898f\u5247<\/h3>\n\n\n\n<p>\u5230<code>proxy<\/code>&gt; <code>proxy setting<\/code> &gt; <code>request interception rules<\/code>  ,\u9ede\u64ca<code>add<\/code>\u5f8c\u53ef\u589e\u52a0\u898f\u5247<\/p>\n\n\n\n<p>\u5047\u5982\u6211\u53ea\u60f3\u5728intercept\u529f\u80fd\u4e2d\u6514\u622awww.google.com\u7684\u8acb\u6c42,\u898f\u5247\u53ef\u4ee5\u9019\u6a23\u8a2d\u5b9a<br>boolean operator: And<br>match type: Domain name<br>match relationship: Matches<br>match condition: www.google.com<\/p>\n\n\n\n<p>refer<br><a href=\"https:\/\/www.cnblogs.com\/lsdb\/p\/9026109.html\" target=\"_blank\" rel=\"noopener\">https:\/\/www.cnblogs.com\/lsdb\/p\/9026109.html<\/a><\/p>\n\n\n\n<p><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u81ea\u52d5\u4fee\u6539\u6bcf\u6b21\u8acb\u6c42\u5167\u5bb9<\/h3>\n\n\n\n<p>\u5230<code>proxy<\/code>&gt; <code>proxy setting<\/code> &gt; <code>Match and Replace<\/code>  ,\u9ede\u64ca<code>add<\/code>\u5f8c\u53ef\u589e\u52a0\u898f\u5247\u8abf\u6574\u6bcf\u6b21\u8acb\u6c42\u5167\u5bb9<\/p>\n\n\n\n<p>\u4f8b\u5982,<br>\u6211\u60f3\u6bcf\u6b21\u7d93\u904eproxy\u5f8c\u8acb\u6c42\u90fd\u5e36<code>X-Custom-IP-Authorization: 127.0.0.1<\/code>,\u898f\u5247\u53ef\u8a2d\u5b9a\u5982\u4e0b<\/p>\n\n\n\n<p>type\u4fdd\u6301request header<br>match\u7dad\u6301\u7a7a\u767d<br>replace\u8f38\u5165X-Custom-IP-Authorization: 127.0.0.1<\/p>\n\n\n\n<p>\u529f\u80fd\u6e2c\u8a66\u53ef\u53c3\u8003:<br>Lab: Authentication bypass via information disclosure<\/p>\n\n\n\n<p><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u81ea\u52d5\u5316\u57f7\u884c\u591a\u500b\u8acb\u6c42<\/h3>\n\n\n\n<p>\u5230<code>proxy<\/code>&gt; <code>proxy setting<\/code> &gt;<code>Sessions<\/code>, <\/p>\n\n\n\n<p>\u5728<code>Session Handling Rules<\/code>\u5340\u57df\u9ede\u64ca<code>add<\/code>\u958b\u555f<code>Session handling rule editor<\/code><\/p>\n\n\n\n<p>\u5728\u5c0d\u8a71\u7a97\u4e2d\u9078\u64c7<code>scope <\/code>,\u4e26\u5728<code>url scope<\/code>\u5340\u57df\u9078\u64c7<code>Include all URLs<\/code><\/p>\n\n\n\n<p>\u5728\u5c0d\u8a71\u7a97\u4e2d\u9078\u64c7<code>detail<\/code>,\u4e26\u5728<code>rule actions<\/code>\u5340\u57df\u9ede\u64ca<code>add<\/code>\u9078<code>Run a macro<\/code><\/p>\n\n\n\n<p>\u5728<code>Select macro<\/code>\u5340\u57df\u4e2d\u9ede\u64ca<code>add<\/code>\u4ee5\u958b\u555f<code>Macro Recorder<\/code>,\u5728\u9019\u88e1\u53ef\u4ee5\u9078\u64c7\u4f60\u9700\u8981\u81ea\u52d5\u57f7\u884c\u7684\u5404\u7a2e\u8acb\u6c42,<\/p>\n\n\n\n<p>\u9078\u5b8c\u5f8c\u6309<code>ok<\/code>\u5c31\u6703\u9032\u5165<code>Macro Editor<\/code>,\u5728\u9019\u88e1\u53ef\u4ee5\u4f9d\u9700\u6c42\u5728<code>Configure item<\/code>\u589e\u52a0<code>custom parameter<\/code>\u4f86\u50b3\u905e\u4e0d\u540c\u8acb\u6c42\u4e4b\u9593\u7684\u503c<\/p>\n\n\n\n<p>\u7de8\u8f2f\u5b8c\u5f8c\u53ef\u4ee5\u9ede\u64ca<code>Test macro<\/code>\u89c0\u5bdf\u81ea\u52d5\u8acb\u6c42\u662f\u5426\u6b63\u5e38\u904b\u4f5c<\/p>\n\n\n\n<p><\/p>\n\n\n\n<p>\u61c9\u7528\u5834\u666f\u5305\u542b\u767b\u5165\u5f8c\u6383\u63cf,\u53ef\u53c3\u8003\u4ee5\u4e0b<br><a href=\"https:\/\/portswigger.net\/support\/configuring-burp-suites-session-handling-rules\" target=\"_blank\" rel=\"noopener\">https:\/\/portswigger.net\/support\/configuring-burp-suites-session-handling-rules<\/a><\/p>\n\n\n\n<p> <\/p>\n\n\n\n<p>refer<br><a href=\"http:\/\/hackdig.com\/09\/hack-141296.htm\" target=\"_blank\" rel=\"noopener\">http:\/\/hackdig.com\/09\/hack-141296.htm<\/a><br><a href=\"https:\/\/xz.aliyun.com\/t\/3751\" target=\"_blank\" rel=\"noopener\">https:\/\/xz.aliyun.com\/t\/3751<\/a><\/p>\n\n\n\n<p>\u529f\u80fd\u6e2c\u8a66\u53ef\u53c3\u8003:<br>Lab: 2FA bypass using a brute-force attack<br>Lab: Infinite money logic flaw<\/p>\n\n\n\n<p><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u7522\u751f\u65e5\u5fd7<\/h3>\n\n\n\n<p>\u5230<code>setting<\/code>&gt; <code>project<\/code> &gt;<code>logging<\/code>, <\/p>\n\n\n\n<p>\u5728logging\u5340\u57df\u4e2d\u53ef\u4ee5\u9078\u64c7\u54ea\u4e9b\u529f\u80fd\u8981\u7522\u751f\u65e5\u5fd7<\/p>\n\n\n\n<p>\u65e5\u5fd7\u5167\u5bb9\u5927\u81f4\u5982\u4e0b<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>======================================================\n17:24:48  http:\/\/systw.net:80  &#91;1.1.1.1]\n======================================================\nGET \/home HTTP\/1.1\nHost:systw.net\nCache-Control: max-age=0\nUpgrade-Insecure-Requests: 1\nUser-Agent: Mozilla\/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/94.0.4147.135 Safari\/537.36\nAccept: text\/html,application\/xhtml+xml,application\/xml;q=0.9,image\/webp,image\/apng,*\/*;q=0.8,application\/signed-exchange;v=b3;q=0.9\nAccept-Encoding: gzip, deflate\nAccept-Language: zh-CN,zh;q=0.9<\/code><\/pre>\n\n\n\n<p>ps: <br>\u9019\u4e9b\u65e5\u5fd7\u53ef\u9935\u7d66sqlmap,\u5c0d\u65e5\u5fd7\u5167\u7684\u76ee\u6a19\u505a\u6aa2\u6e2c,\u6307\u4ee4\u70ba <code>sqlmap -l burpsuitelog.txt<\/code><\/p>\n\n\n\n<p><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u7db2\u7ad9\u5167\u5bb9\u5c0b\u627e<\/h3>\n\n\n\n<p>\u5c08\u696d\u7248\u624d\u6709\u7684\u529f\u80fd<\/p>\n\n\n\n<p>\u5230<code>target &gt; site map<\/code> \u9078\u64c7\u6307\u5b9a\u7db2\u7ad9\u5f8c\u53f3\u9375\u9078 <code>Engagement tools<\/code>  &gt;  <code>Discover content<\/code> <\/p>\n\n\n\n<p>\u63a5\u8457\u5c31\u53ef\u4ee5\u5728\u6307\u5b9a\u7db2\u7ad9\u5167\u641c\u5c0b\u5404\u7a2e\u654f\u611f\u76ee\u9304\uff0c\u50cf\u662fbackup, admin\u76ee\u9304\u7b49<\/p>\n\n\n\n<p>\u529f\u80fd\u6e2c\u8a66\u53ef\u53c3\u8003:<br>Lab: Source code disclosure via backup files<br>Lab: Inconsistent handling of exceptional input<br>Lab: Inconsistent security controls<\/p>\n\n\n\n<p><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u8a3b\u89e3\u641c\u5c0b<\/h3>\n\n\n\n<p>\u5c08\u696d\u7248\u624d\u6709\u7684\u529f\u80fd<\/p>\n\n\n\n<p>\u5230<code>target &gt; site map<\/code> \u9078\u64c7\u6307\u5b9a\u7db2\u7ad9\u5f8c\u53f3\u9375\u9078 <code>Engagement tools<\/code>  &gt;  <code>Find comments<\/code> <\/p>\n\n\n\n<p>\u63a5\u8457\u5c31\u53ef\u4ee5\u5728\u6307\u5b9a\u7db2\u7ad9\u5167\u641c\u5c0b\u8a3b\u89e3\u5167\u7684\u5404\u7a2e\u654f\u611f\u4fe1\u606f<\/p>\n\n\n\n<p>\u529f\u80fd\u6e2c\u8a66\u53ef\u53c3\u8003:<br>Lab: Information disclosure on debug page<\/p>\n\n\n\n<p><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u81ea\u52d5\u7522\u751fCSRF HTML<\/h3>\n\n\n\n<p>\u5c08\u696d\u7248\u624d\u6709\u7684\u529f\u80fd<\/p>\n\n\n\n<p>\u5728\u4efb\u4f55\u8acb\u6c42\u4e2d\u6309\u53f3\u9375\u9078 <code>Engagement tools<\/code>  &gt;  <code>Generate CSRF PoC<\/code> \u5c31\u53ef\u4ee5\u7522\u751f\u4e00\u500bcsrf HTML,  <\/p>\n\n\n\n<p>\u5982\u679c\u60f3\u8981\u6709\u81ea\u52d5\u63d0\u4ea4\u529f\u80fd, \u53ef\u900f\u904e<code>option<\/code>\u5c07<code>auto-submit script<\/code>\u52a0\u5165,\u5728\u6309<code>Regenerate<\/code>\u5373\u53ef\u7522\u751f<\/p>\n\n\n\n<p>\u529f\u80fd\u6e2c\u8a66\u53ef\u53c3\u8003:<br>Lab: CSRF vulnerability with no defenses<\/p>\n\n\n\n<p><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Burp Collaborator \u6a21\u7d44<\/h3>\n\n\n\n<p>\u529f\u80fd \u63a2\u6e2c external service interaction\uff08\u5916\u90e8\u670d\u52d9\u4ea4\u4e92\u653b\u64ca\uff09<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Burp Collaborator \u4f3a\u670d\u5668\u901a\u5e38\u904b\u884c\u5728\u516c\u7db2\u4e0a\u3002<\/li>\n\n\n\n<li>\u5b83\u4f7f\u7528\u81ea\u5df1\u7684\u5c08\u7528\u57df\u540d\uff0c\u4e26\u4e14\u9019\u500b\u4f3a\u670d\u5668\u5df2\u8a3b\u518a\u70ba\u8a72\u57df\u540d\u7684\u6b0a\u5a01DNS\u4f3a\u670d\u5668\u3002<\/li>\n\n\n\n<li>\u5b83\u63d0\u4f9b\u4e00\u500bDNS\u670d\u52d9\uff0c\u53ef\u4ee5\u56de\u61c9\u4efb\u4f55\u5c0d\u5b83\u7684 DNS \u8acb\u6c42\u3002<\/li>\n\n\n\n<li>\u5b83\u63d0\u4f9b HTTP\/HTTPS \u670d\u52d9\uff0c\u4f7f\u7528\u4e00\u500b\u6709\u6548\u7684SSL\u6191\u8b49\u3002<\/li>\n\n\n\n<li>\u5c07\u4f86\u53ef\u4ee5\u6dfb\u52a0\u5176\u4ed6\u7684\u670d\u52d9\uff0c\u6bd4\u5982 SMTP \u548c FTP\u3002<\/li>\n<\/ul>\n\n\n\n<p><\/p>\n\n\n\n<p>\u529f\u80fd\u6e2c\u8a66\u53ef\u53c3\u8003:<br>Lab: Blind SQL injection with out-of-band data exfiltration<br>Lab: Blind OS command injection with out-of-band interaction<br>Lab: Blind OS command injection with out-of-band data exfiltration<\/p>\n\n\n\n<p><\/p>\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\u4f7f\u7528\u524d\u8a2d\u5b9a<\/h2>\n\n\n\n<p><\/p>\n\n\n\n<p>\u5728\u4ee3\u7406\u7684\u6a21\u5f0f\u4e0b\uff0c\u8a2d\u5b9a\u700f\u89bd\u5668\u53ef\u8a2a\u554fSSL<\/p>\n\n\n\n<p>1.\u8a2a\u554fhttp:\/\/burpsuite<\/p>\n\n\n\n<p>2.\u5728burpsuite\u8f38\u51faCA<br>burpsuite: proxy-&gt;option-&gt;proxy listeners, import\/export CA certificate&nbsp;<br>CA certificate: export, certificate in der format, next-&gt; choose export path<\/p>\n\n\n\n<p>3.\u5728chrome\u8a2d\u5b9a<br>chrome:\u8a2d\u7f6e\u9078\u9805-&gt;\u7ba1\u7406\u8b49\u66f8<br>\u8b49\u66f8:\u5728\u53d7\u4fe1\u4efb\u4e00\u6b04\u4f4d\u4e2d\u9078\u64c7\u5c0e\u5165,\u5c07\u525b\u624d\u4fdd\u5b58\u5728\u672c\u5730\u7684\u8b49\u66f8\u5c0e\u5165\u9032\u53bb\u5373\u53ef<\/p>\n\n\n\n<p><\/p>\n\n\n\n<p>refer<br><a href=\"https:\/\/blog.csdn.net\/sinat_25449961\/article\/details\/51585919\" target=\"_blank\" rel=\"noopener\">https:\/\/blog.csdn.net\/sinat_25449961\/article\/details\/51585919<\/a><br><a href=\"https:\/\/portswigger.net\/burp\/documentation\/desktop\/external-browser-config\/certificate\/ca-cert-chrome-windows\" target=\"_blank\" rel=\"noopener\">https:\/\/portswigger.net\/burp\/documentation\/desktop\/external-browser-config\/certificate\/ca-cert-chrome-windows<\/a><\/p>\n\n\n\n<p> <\/p>\n\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"> <\/h2>\n","protected":false},"excerpt":{"rendered":"<p>Burp Suite\u529f\u80fd\u6982\u8981\uff1a \u57fa\u672c\u529f\u80fd \u5c08\u696d\u7248\u6709\u53e6\u5916\u63d0\u4f9b\u4ee5 &#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"","fifu_image_alt":"","_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[369],"tags":[3],"class_list":["post-16","post","type-post","status-publish","format-standard","hentry","category-red-team","tag-tool"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/posts\/16","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/comments?post=16"}],"version-history":[{"count":1,"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/posts\/16\/revisions"}],"predecessor-version":[{"id":2405,"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/posts\/16\/revisions\/2405"}],"wp:attachment":[{"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/media?parent=16"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/categories?post=16"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/tags?post=16"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}