当前位置:网站首页>Token value replacement of burpsuite blasting
Token value replacement of burpsuite blasting
2022-07-25 04:36:00 【An ordinary scholar】
preparation
First of all, we need to build an experimental environment , The experimental environment we choose is DVWA. I believe many partners will encounter in penetration testing token Value different situations , So what we need to do is to use burpsuite The tool automatically gets the website generated token Value and blast
The recurrence process
First, let's visit DVWA Website , Check source code discovery , Just refresh the page every time ,token The value of will change 

When we try to use burpsuite After direct bag grabbing blasting , Find all 302 Redirect , Obviously this will not work 
So we need to Project Option Of Session Add autosnap on token The option to 
Run a macro 
Here we choose the beginning GET Requested page 

Then edit this option , Add the option to automatically get that value 


Here, select the field to update 
Then enter Scope Options , add to URL Address 

Then return to the brute force cracking module , Set variable values and load dictionaries , And choose always follow redirection Options 

You can see that the password is password, Account No admin The response packet length of is obviously different 
Check the contents of the response package and find that the explosion is successful 
边栏推荐
- Preparation for Android development in big companies
- [golang from introduction to practice] stone scissors paper game
- GBase JDBC 连接数据库异常
- Custom dialog (including header and footer)
- The United States has launched 337 investigations on a number of Chinese companies: Bubugao is full of lying guns!
- Infinite connection · infinite collaboration | the first global enterprise communication cloud conference WECC is coming
- Function and technical principle of data desensitization [detailed explanation]
- The LAF protocol elephant of defi 2.0 may be one of the few profit-making means in your bear market
- How many rows does PostgreSQL need to partition for each table?
- 数据链路层协议 ——— 以太网协议
猜你喜欢

Docker install MySQL 5.7

5年经验的大厂测试/开发程序员,怎样突破技术瓶颈?大厂通病......

RGB and SATA function switching module based on Quanzhi rk3568j

2019 telecast retest test questions

GDT,LDT,GDTR,LDTR

Kubesphere 3.3.0 offline installation tutorial

Huawei cloud from entry to actual combat | cloud rapid site establishment service and enterprise host security service

GDT,LDT,GDTR,LDTR

盐粒和冰粒分不清

Bubble mart's market value evaporated by HK $21billion in seven days, which can't be sold in China, and its future at sea is uncertain
随机推荐
[golang from introduction to practice] stone scissors paper game
Docker install MySQL 5.7
ESWC 2018 | R-GCN:基于图卷积网络的关系数据建模
Beijing University of Posts and telecommunications | RIS assisted in-house multi robot communication system joint deep reinforcement learning
The United States has launched 337 investigations on a number of Chinese companies: Bubugao is full of lying guns!
LVGL 8.2 Textarea
Actual combat | record an attack and defense drill management
Large screen visual adaptation file
[ CTF 学习 ] CTF 中的隐写集合 —— 图片隐写术
LVGL 8.2 Tabview
etcd学习
自然的状态最好
Do you really understand images? (machine vision)
深入掌握Service
C# 之 FileStream类介绍
Analyze the exploration in high-quality steam Education
How to transfer NFT metadata from IPFs to smart contracts
LVGL 8.2 Span
Kubesphere 3.3.0 offline installation tutorial
TS learning (VII): interface and type compatibility of TS