{"id":8,"date":"2023-10-15T12:50:25","date_gmt":"2023-10-15T04:50:25","guid":{"rendered":"http:\/\/54.254.190.68\/note\/archives\/8"},"modified":"2025-07-27T18:23:44","modified_gmt":"2025-07-27T10:23:44","slug":"burpsuite-app","status":"publish","type":"post","link":"https:\/\/systw.net\/note\/archives\/8","title":{"rendered":"burpsuite app"},"content":{"rendered":"\n<p>burpsuite\u7684app\u4e5f\u7c21\u7a31bapp\uff0c\u53ef\u64f4\u5c55\u8a31\u591a\u66f4\u9032\u968e\u7684\u529f\u80fd\uff0c\u5728bapp store\u4e0a\u53ef\u4ee5\u9078\u64c7\u591a\u500bbapp\u4e26\u4e0b\u8f09\uff0c\u5e7e\u500b\u5e38\u898b\u7684bapp\u4ecb\u7d39\u5982\u4e0b<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Collaborator Everywhere<\/h2>\n\n\n\n<p>\u529f\u80fd: \u80fd\u5920\u81ea\u52d5\u5c0b\u627eHTTP\u6a19\u982d\u4e2d\u7684SSRF\uff0c\u8a72\u529f\u80fd\u5c07\u5c0d\u6bcf\u500b\u8acb\u6c42\u653e\u5165\u5e38\u898b\u7684header\u505a\u6e2c\u8a66\u4e26\u9032\u884c\u91cd\u9001  <\/p>\n\n\n\n<p>\u4f7f\u7528\u65b9\u6cd5:<\/p>\n\n\n\n<p>\u53ef\u4ee5\u628a\u8981\u5206\u6790\u7684\u76ee\u6a19\u7db2\u7ad9\u6307\u5b9a\u5728&nbsp;<code>target scope<\/code>\u4e26\u700f\u89bd\uff0c\u6b64\u529f\u80fd\u5c31\u6703\u9032\u884c\u5206\u6790\u3002\u5982\u679c\u6709\u767c\u73fe\u4efb\u4f55\u7570\u5e38\u5c07\u986f\u793a\u5728<code>Issue<\/code>\u4e2d \u3002<\/p>\n\n\n\n<p>refer<br><a rev=\"en_rl_none\" href=\"http:\/\/blog.portswigger.net\/2017\/07\/cracking-lens-targeting-https-hidden.html\" rel=\"nofollow noopener\" target=\"_blank\">http:\/\/blog.portswigger.net\/2017\/07\/cracking-lens-targeting-https-hidden.html<\/a>&nbsp;<\/p>\n\n\n\n<p>\u529f\u80fd\u6e2c\u8a66\u53ef\u53c3\u8003:<br>Lab: Blind SSRF with Shellshock exploitation<\/p>\n\n\n\n<p><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">param miner<\/h2>\n\n\n\n<p>\u529f\u80fd:\u53ef\u767c\u73fe\u6f5b\u5728\u7684\u96b1\u85cf\u53c3\u6578\u3002\u5c0d\u65bc\u67e5\u627eweb cache poision\u5f88\u6709\u5e6b\u52a9<\/p>\n\n\n\n<p>\u4f7f\u7528\u65b9\u6cd5:<\/p>\n\n\n\n<p>\u5728<code>Target<\/code><span style=\"font-size: revert;\"><code>&gt;<\/code><\/span><code>Site map<\/code> \u6307\u5b9a\u5176\u4e2d\u4e00\u500b\u8acb\u6c42\u6309\u53f3\u9375\u9078<code>Extensions<span style=\"font-size: revert;\"> &gt; <\/span>Param Miner<span style=\"font-size: revert;\"> &gt; <\/span>Guess params<\/code><\/p>\n\n\n\n<p> \u6709\u56db\u500b\u9078\u9805\u53ef\u4ee5\u7528<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li> Guess GET parameters <\/li>\n\n\n\n<li> Guess cookie parameters <\/li>\n\n\n\n<li> Guess headers <\/li>\n\n\n\n<li> Guess everything! <\/li>\n<\/ul>\n\n\n\n<p>\u9078\u64c7\u5f8c\u6703\u5c0d\u8acb\u6c42\u50b3\u9001\u6e2c\u8a66\u8acb\u6c42\u5230\u76ee\u6a19,\u6e2c\u8a66\u5b8c\u53ef\u4ee5<code>Extensions<span style=\"font-size: revert;\"> &gt; <\/span>Installed<span style=\"font-size: revert;\"> &gt; <\/span>Param Miner<span style=\"font-size: revert;\"> &gt; <\/span>Output <\/code>\u770b\u7d50\u679c<\/p>\n\n\n\n<p>\u8209\u4f8b\u4f86\u8aaa\uff0c\u5982\u679c\u767c\u73fex-forwarded-host\u548cx-original-url\u6709\u554f\u984c\u6703\u986f\u793a\u5982\u4e0b\u4fe1\u606f<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Queued 1 attacks\nInitiating header bruteforce on 0af00023034b2a7380814e2c00a5009e.web-security-academy.net\nIdentified parameter on 0af00023034b2a7380814e2c00a5009e.web-security-academy.net: x-forwarded-host~%s.%h\nIdentified parameter on 0af00023034b2a7380814e2c00a5009e.web-security-academy.net: x-original-url~\/%s\n<\/code><\/pre>\n\n\n\n<p>refer<br>https:\/\/cn-sec.com\/archives\/2316992.html<br>https:\/\/www.wangan.com\/p\/7fygfgb3a9adb6b1<\/p>\n\n\n\n<p>\u529f\u80fd\u6e2c\u8a66\u53ef\u53c3\u8003:<br>Lab: Web cache poisoning to exploit a DOM vulnerability via a cache with strict cacheability criteria<br>Lab: Combining web cache poisoning vulnerabilities<\/p>\n\n\n\n<p><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Turbo Intruder<\/h2>\n\n\n\n<p>\u529f\u80fd:\u53ef\u4ee5\u4f7f\u7528\u6975\u4f4e\u7684\u8cc7\u6e90\u975e\u5e38\u5feb\u901f\u7684\u767c\u9001\u8acb\u6c42<\/p>\n\n\n\n<p>\u4f7f\u7528\u65b9\u6cd5:<\/p>\n\n\n\n<p>\u4ee5\u55ae\u500b\u8acb\u6c42\u653b\u64ca\u65b9\u6cd5\u70ba\u4f8b, \u5148\u9078\u64c7\u4e00\u500b\u8acb\u6c42\u6309\u53f3\u9375\u9078<code>Extensions &gt; Tubo Intruder &gt; Send to Turbo Intruder<\/code>,\u628a\u539f\u672c\u8acb\u6c42\u6b04\u4f4d\u4e2d\u9700\u8981\u66f4\u63db\u7684\u503c\u66ff\u63db\u6210<code>%s<\/code><\/p>\n\n\n\n<p>\u7136\u5f8c\u5728\u4e0b\u62c9\u9078\u55ae\u4e2d\u9078\u64c7<code>examples\/race-single-packer-attack.py<\/code>,\u4e26\u4f7f\u7528<code>passwords = wordlists.clipboard<\/code>\u529f\u80fd,\u9019\u6703\u8981\u6c42\u6b64\u5de5\u5177\u4f7f\u7528\u526a\u8cbc\u7c3f\u7684\u5217\u8868<\/p>\n\n\n\n<p>\u5b8c\u6574\u4ee3\u78bc\u5982\u4e0b(\u4ee5\u4e0b\u662f\u4f7f\u7528http2\u5354\u5b9a\u7684\u5beb\u6cd5)<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>def queueRequests(target, wordlists):\n    # as the target supports HTTP\/2, use engine=Engine.BURP2 and concurrentConnections=1 for a single-packet attack\n    engine = RequestEngine(endpoint=target.endpoint,\n                           concurrentConnections=1,\n                           engine=Engine.BURP2\n                           )\n    \n    # assign the list of candidate passwords from your clipboard\n    passwords = wordlists.clipboard\n    \n    # queue a login request using each password from the wordlist\n    # the 'gate' argument withholds the final part of each request until engine.openGate() is invoked\n    for password in passwords:\n        engine.queue(target.req, password, gate='1')\n    \n    # once every request has been queued\n    # invoke engine.openGate() to send all requests in the given gate simultaneously\n    engine.openGate('1')\n\ndef handleResponse(req, interesting):\n    table.add(req)<\/code><\/pre>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u52a0\u901f\u7b56\u7565<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">1.\u6e1b\u5c11\u8acb\u6c42\u982d\u5927\u5c0f<\/h4>\n\n\n\n<p>\u900f\u904e\u5f9e\u8acb\u6c42\u4e2d\u522a\u9664\u4e0d\u5fc5\u8981\u7684\u6a19\u982d\u548c cookie \u4f86\u6e1b\u5c11\u6bcf\u500b\u8acb\u6c42\u7684\u51fa\u7ad9\u6d41\u91cf\u8981\u6c42\uff0c\u4f7f\u5176\u76e1\u53ef\u80fd\u5c0f<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">2.\u9078\u64c7\u6700\u5feb\u7684\u5f15\u64ca<\/h4>\n\n\n\n<p>\u901f\u5ea6\u6392\u540d\u4f9d\u5e8f\u662fEngine.HTTP2\uff0cEngine.THREADED\uff0cEngine.BURP2\uff0cEngine.BURP<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">3.\u8abf\u6574\u5f15\u64ce\u8a2d\u5b9a<\/h4>\n\n\n\n<p>\u76ee\u6a19\u662f\u627e\u5230\u4f7fRPS\uff08\u6bcf\u79d2\u8acb\u6c42\u6578\uff09\u503c\u6700\u5927\u5316\u7684\u503c\uff0c\u540c\u6642\u4f7f\u91cd\u8a66\u8a08\u6578\u5668\u4fdd\u6301\u63a5\u8fd10<\/p>\n\n\n\n<p>\u4f7f\u7528Engine.BURP2\u6216Engine.BURP\u5f15\u64ce\uff0c\u53ea\u8981\u8abf\u6574concurrentConnections<\/p>\n\n\n\n<p>\u4f7f\u7528Engine.HTTP2\u6216Engine.THREADED\uff0c\u53ef\u8abf\u6574\u7ba1\u9053\u3001requestsPerConnection\u548c\u4e26\u767c\u9023\u63a5\u53c3\u6578<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">4.\u512a\u5316\u56de\u547c\u7a0b\u5f0f\u78bc<\/h4>\n\n\n\n<p>\u4f8b\u5982table.add() \u6703\u70ba Swing \u57f7\u884c\u7dd2\u5e36\u4f86\u6c89\u91cd\u7684\u8ca0\u8f09\uff0c\u56e0\u6b64\u53ef\u4ee5\u900f\u904e\u5206\u6790\u6bcf\u500b\u56de\u61c9\u4f86\u6c7a\u5b9a\u662f\u5426\u5c07\u5176\u653e\u5165\u7d50\u679c\u8868\u4e2d\uff0c\u5f9e\u800c\u6e1b\u8f15\u7cfb\u7d71\u7684 CPU \u8ca0\u64d4\u3002\u53e6\u5916\uff0c\u907f\u514d\u4f7f\u7528\u6b63\u898f\u8868\u793a\u5f0f\u548c\u5faa\u74b0\u5b57\u4e32\u9023\u63a5\u3002<\/p>\n\n\n\n<p>refer<br><a href=\"https:\/\/mp.weixin.qq.com\/s?__biz=MzAxNDM3NTM0NQ==&amp;mid=2657035813&amp;idx=3&amp;sn=367a002882fbcf76bef85f1424067513&amp;chksm=803fc6fbb7484fed3c007fb39044611b5736bf7429033b393333f7ca118961f2e3b89834b397&amp;scene=0&amp;xtrack=1\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/mp.weixin.qq.com\/s?__biz=MzAxNDM3NTM0NQ==&amp;mid=2657035813&amp;idx=3&amp;sn=367a002882fbcf76bef85f1424067513&amp;chksm=803fc6fbb7484fed3c007fb39044611b5736bf7429033b393333f7ca118961f2e3b89834b397&amp;scene=0&amp;xtrack=1<\/a><br><a href=\"https:\/\/portswigger.net\/research\/turbo-intruder-embracing-the-billion-request-attack\" target=\"_blank\" rel=\"noopener\">https:\/\/portswigger.net\/research\/turbo-intruder-embracing-the-billion-request-attack<\/a><\/p>\n\n\n\n<p>\u529f\u80fd\u6e2c\u8a66\u53ef\u53c3\u8003:<br>Lab: Web shell upload via race condition<br>Lab: Server-side pause-based request smuggling<br>Lab: Bypassing rate limits via race conditions<\/p>\n\n\n\n<p><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Hackvertor<\/h2>\n\n\n\n<p>\u529f\u80fd:\u652f\u6301\u5404\u7a2ehash\u8f49\u7fa9\u548c\u7de8\u78bc,\u4f8b\u5982unicode,16\u9032\u5236,8\u9032\u5236,html\u5be6\u9ad4\u7b49\u7de8\u78bc, \u4e26\u5177\u6709\u81ea\u52d5\u89e3\u78bc\u529f\u80fd,\u53ef\u4ee5\u731c\u6e2c\u6240\u9700\u8981\u8f49\u63db\u7684\u985e\u578b\u4e26\u81ea\u52d5\u89e3\u78bc\u591a\u5c11<\/p>\n\n\n\n<p>\u4f7f\u7528\u65b9\u6cd5<\/p>\n\n\n\n<p>\u5728\u8acb\u6c42\u4e2d\u9078\u64c7\u60f3\u5206\u6790\u7684\u5167\u5bb9\u6309\u53f3\u9375\u9078<code>Extensions &gt; Hackvertor &gt; Encode &gt; dec_entities\/hex_entities <\/code><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p>refer<br><a href=\"https:\/\/portswigger.net\/bappstore\/65033cbd2c344fbabe57ac060b5dd100\" target=\"_blank\" rel=\"noopener\">https:\/\/portswigger.net\/bappstore\/65033cbd2c344fbabe57ac060b5dd100<\/a><br><a href=\"https:\/\/portswigger.net\/web-security\/sql-injection\/lab-sql-injection-with-filter-bypass-via-xml-encoding\" target=\"_blank\" rel=\"noopener\">https:\/\/portswigger.net\/web-security\/sql-injection\/lab-sql-injection-with-filter-bypass-via-xml-encoding<\/a><\/p>\n\n\n\n<p><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Python Scripter<\/h2>\n\n\n\n<p>\u529f\u80fd:\u53ef\u5728\u9001\u51fa\u8acb\u6c42\u6642\u81ea\u52d5\u6839\u64dapython\u4ee3\u78bc\u505a\u4fee\u6539<\/p>\n\n\n\n<p>\u4f7f\u7528\u65b9\u6cd5:&nbsp;<\/p>\n\n\n\n<p>\u4f7f\u7528\u8a72\u529f\u80fd\u524d\u9700\u8981\u5148\u8b93burpsuite\u5b89\u88ddpython standalone\u7368\u7acbjar\u5305, \u53ef\u5728http:\/\/www.jython.org\u4e0b\u8f092.7.0\u7248\u672c.\u7136\u5f8c\u5230burpsuite\u7684<code>extender \/ option \/ python environment<\/code> \u6307\u5b9a\u8a72jar\u5305<\/p>\n\n\n\n<p>\u63a5\u8457\u5c31\u53ef\u4ee5\u5230<code>python scripter<\/code>\u64b0\u5bebpython\u4ee3\u78bc\u81ea\u52d5\u4fee\u6539\u8acb\u6c42<\/p>\n\n\n\n<p><\/p>\n\n\n\n<p>refer<br><a href=\"https:\/\/www.freebuf.com\/news\/193657.html\" target=\"_blank\" rel=\"noopener\">https:\/\/www.freebuf.com\/news\/193657.html<\/a><\/p>\n\n\n\n<p><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">CPH<\/h2>\n\n\n\n<p>\u529f\u80fd:\u63d0\u4f9bburpsuite Marcos\u66f4\u591a\u529f\u80fd, \u4f8b\u5982\u80fd\u984d\u5916\u652f\u63f4json\u683c\u5f0f(\u5167\u5efa\u529f\u80fd\u4e0d\u652f\u63f4) .<\/p>\n\n\n\n<p>\u4f7f\u7528\u65b9\u6cd5<\/p>\n\n\n\n<p>\u5728cph option \u8a2d\u5b9ascope:&nbsp;&nbsp; intruder, repeater<\/p>\n\n\n\n<p>\u5728cph tab\u8a2d\u5b9a\u5982\u4e0b<\/p>\n\n\n\n<p>1 find matches to this expression<br>ex:<br><code>(messageId\\\"\\:\\\")(.{32,32})<\/code><\/p>\n\n\n\n<p>2 target&nbsp; <code>the first<\/code> of the matches<\/p>\n\n\n\n<p>3 replace each target with this expression<br>ex:<br><code>\\g&lt;1&gt;\\g&lt;mid&gt;<\/code><\/p>\n\n\n\n<p>4 choose the value i need is dynamic<br>\u7136\u5f8c\u9078\u64c7<code>value returned by issuing a sequence of requests<\/code>\u7136\u5f8c\u5728\u4e0b\u65b9\u586b\u65b9expression<br>ex:<br><code>messageId\\\"\\:\\\"(?P&lt;mid&gt;.*?)\"\\,\\\"expire<\/code><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p>refer<br><a href=\"https:\/\/www.anquanke.com\/post\/id\/231145\" target=\"_blank\" rel=\"noopener\">https:\/\/www.anquanke.com\/post\/id\/231145<\/a><\/p>\n\n\n\n<p><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">SQLiPy<\/h2>\n\n\n\n<p>\u529f\u80fd:\u53ef\u81ea\u52d5\u8abf\u7528sqlmap\u5c0d\u8acb\u6c42\u505a\u6e2c\u8a66<\/p>\n\n\n\n<p>\u4f7f\u7528\u65b9\u6cd5:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>\u9700\u8981\u5148\u555f\u7528sqlmap,\u4e26\u6307\u5b9aburpsuite\u7684IP\u548cport  <code>python <a rev=\"en_rl_none\" href=\"http:\/\/sqlmapapi.py\" target=\"_blank\" rel=\"noopener\">sqlmapapi.py<\/a> -s -H &lt;IP&gt; -p &lt;Port&gt;<\/code><\/li>\n\n\n\n<li>\u5230burpsutie\u7684<code>sqlmap api<\/code>\u5340\u57df\u6307\u5b9aIP\u548cport\u5f8c\u9ede\u64castart api<\/li>\n<\/ol>\n\n\n\n<p>\u6ce8\u610f\u4e8b\u9805: \u8a72\u5de5\u5177\u4e0d\u6703\u628a\u6240\u6709header\u90fd\u9001\u51fa\u53bb,\u8981\u81ea\u5df1\u5230<code>CUSTOMER HEADER<\/code>\u589e\u52a0\u539f\u8acb\u6c42\u7684header<\/p>\n\n\n\n<p>\u4f8b\u5982:<br>\u5728headers\u6b04\u4f4d\u589e\u52a0<code>Content-Type: application\/json\\nAccept-Language: en-US<\/code>,\u5982\u56f0\u8981\u589e\u52a0\u591a\u500bheader\u90a3\u8981\u7528<code>\\n<\/code>\u505a\u5206\u9694<\/p>\n\n\n\n<p><\/p>\n\n\n\n<p>refer<br><a href=\"https:\/\/portswigger.net\/support\/using-burp-with-sqlmap\" target=\"_blank\" rel=\"noopener\">https:\/\/portswigger.net\/support\/using-burp-with-sqlmap<\/a><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p>\u5176\u4ed6\u53ef\u7528\u505asqlmap\u81ea\u52d5\u6e2c\u8a66\u7684app\u9084\u6709<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>gason\u63d2\u4ef6<\/li>\n\n\n\n<li>sqlmap4burp<b>\u63d2\u4ef6<\/b><\/li>\n<\/ul>\n\n\n\n<p>refer<\/p>\n\n\n\n<p><a href=\"https:\/\/t0data.gitbooks.io\/burpsuite\/content\/chapter18.html\" target=\"_blank\" rel=\"noopener\">https:\/\/t0data.gitbooks.io\/burpsuite\/content\/chapter18.html<\/a><\/p>\n\n\n\n<p><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">JWT Editor <\/h2>\n\n\n\n<p>\u529f\u80fd:\u53ef\u5206\u6790jwt token\u4e26\u4fee\u6539token\u5167\u5bb9<\/p>\n\n\n\n<p>refer<br><a href=\"https:\/\/portswigger.net\/web-security\/jwt\/working-with-jwts-in-burp-suite#editing-the-contents-of-jwts\" target=\"_blank\" rel=\"noopener\">https:\/\/portswigger.net\/web-security\/jwt\/working-with-jwts-in-burp-suite#editing-the-contents-of-jwts<\/a><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">RouteVulScan <\/h2>\n\n\n\n<p>\u529f\u80fd:\u4e00\u500b\u4f7f\u7528Java\u958b\u767c\u7684burp\u63d2\u4ef6\uff0c\u53ef\u4ee5\u905e\u6b78\u5730\u5075\u6e2c\u5b58\u5728\u6f0f\u6d1e\u7684\u8def\u5f91\u3002\u6b64\u63d2\u4ef6\u53ef\u4ee5\u900f\u904e\u88ab\u52d5\u6383\u63cf\u905e\u6b78\u5730\u5075\u6e2c\u6bcf\u4e00\u5c64\u7684\u8def\u5f91\uff0c\u4e26\u900f\u904e\u8a2d\u5b9a\u7684\u6b63\u898f\u8868\u793a\u5f0f\u4f86\u5339\u914d\u5c0d\u61c9\u5957\u4ef6\u7684\u95dc\u9375\u5b57\uff0c\u4e26\u986f\u793a\u5728VulDisplay\u4ecb\u9762\u4e0a\u3002\u60a8\u53ef\u4ee5\u81ea\u8a02\u76f8\u95dc\u8def\u5f91\u3001\u6bd4\u5c0d\u8cc7\u8a0a\u548c\u6f0f\u6d1e\u540d\u7a31\u3002\u5075\u6e2c\u5230\u7684url\u5c07\u5217\u5370\u5728Output\u4e2d\uff0c\u5982\u679c\u662f\u91cd\u8907\u7684url\uff0c\u5247\u4e0d\u6703\u8981\u6c42\u4e26\u5217\u5370\u5728Errors\u4e2d\u3002\u5982\u679c\u5b58\u53d6\u7684url\u7b26\u5408Config\u7684\u898f\u5247\uff0c\u5c31\u6703\u5132\u5b58\u5728VulDisplay\u9762\u677f\u4e2d\u9032\u884c\u986f\u793a\u3002<\/p>\n\n\n\n<p>\u8a72\u529f\u80fd\u50c5\u80fd\u642d\u914d\u5c08\u696d\u7248<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">JS Link Finder <\/h2>\n\n\n\n<p>\u529f\u80fd:\u7528\u65bc\u88ab\u52d5\u6383\u63cf JavaScript \u6a94\u6848\u4e2d\u7684\u7aef\u9ede\u9023\u7d50\u3002\u5c07\u7d50\u679c\u532f\u51fa\u5230\u6587\u5b57\u6a94\u6848 &#8211; \u6392\u9664\u7279\u5b9a\u7684js\u6587\u4ef6\uff0c\u4f8b\u5982 jquery\u3001google-analytics\u3002\u53ef\u80fd\u6703\u6709\u4e9bAPI\u4ecb\u9762\u6703\u88ab\u96b1\u85cf\u5728JS\u4e2d\u6c92\u6709\u88ab\u555f\u52d5\u3002\u9019\u6642\u5019\u53ef\u4ee5\u4f7f\u7528<code>JS Link Finder<\/code>\u63d2\u4ef6\u8f14\u52a9\u5206\u6790Javascript\u6a94\u6848\u4e2d\u7684\u63a5\u53e3<\/p>\n\n\n\n<p>\u8a72\u529f\u80fd\u50c5\u80fd\u642d\u914d\u5c08\u696d\u7248<\/p>\n\n\n\n<p><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u5176\u4ed6burpsuite\u5e38\u7528\u63d2\u4ef6\u4ecb\u7d39<\/h3>\n\n\n\n<p><a href=\"https:\/\/www.mad-coding.cn\/2019\/10\/04\/burpsuite\u5e38\u7528\u63d2\u4ef6\u63a8\u8350\u4e0e\u4f7f\u7528\/#0x00-\u524d\u8a00\" target=\"_blank\" rel=\"noopener\">https:\/\/www.mad-coding.cn\/2019\/10\/04\/burpsuite\u5e38\u7528\u63d2\u4ef6\u63a8\u8350\u4e0e\u4f7f\u7528\/#0x00-\u524d\u8a00<\/a><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>burpsuite\u7684app\u4e5f\u7c21\u7a31bapp\uff0c\u53ef\u64f4\u5c55\u8a31\u591a\u66f4\u9032\u968e\u7684 &#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"","fifu_image_alt":"","_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[369],"tags":[3],"class_list":["post-8","post","type-post","status-publish","format-standard","hentry","category-red-team","tag-tool"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/posts\/8","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/comments?post=8"}],"version-history":[{"count":1,"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/posts\/8\/revisions"}],"predecessor-version":[{"id":2406,"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/posts\/8\/revisions\/2406"}],"wp:attachment":[{"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/media?parent=8"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/categories?post=8"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/tags?post=8"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}