当前位置:网站首页>Vulnerability discovery - App application vulnerability probe type utilization and repair
Vulnerability discovery - App application vulnerability probe type utilization and repair
2022-07-01 00:19:00 【Dark white earphone】

Train of thought :
Decompile extract URL Or packet capture URL, Conduct WEB Application testing , If there is no agreement or other agreement , Net required
The network interface captures packets for data acquisition , Go to other protocol security tests !
APP->WEB APP-> other APP-> reverse
WEB Grab the bag , Other protocol capture demonstration and description
There is no packet capture at the reverse level to distinguish the testing of each protocol
Reverse layer extraction APK Code level data
https://www.cnblogs.com/L0ading/p/12388928.html
Case presentation :
Caught tools WEB Instructions for the use of the protocol surface
Packet capture tool non WEB Instructions for the use of the protocol surface
Android reverse convenience APK One click extraction URL demonstration
utilize Burp Screening and linkage function to play Military Boxing
Simulator four illegal cases APP Safety analysis and testing
Caught tools WEB Instructions for the use of the protocol surface ( demonstration )

burp Agent fills in this machine ip, Port and port ip Corresponding to the mobile phone simulator
burp advantage : On the simulator app The packets of all operations will be sent to HTTPhistory in , And you can filter and search packets by keywords
Open... In the simulator app, A blind meal , The packets are all recorded HTTPhistory in 
Teacup Charles Caught tools ( demonstration )
Modify and set the proxy port 
Check windows agent
Open... In the simulator after setting app,Charles The data package url Capture records 
Bag grabbing spirit


Wireshark Grab the bag
Other packet capturing software may only catch HTTP agreement , It can be used Wireshark Capture network interface . There are various agreements .
Android reverse convenience APK One click extraction URL
Leak a big hole 
utilize Burp Screening and linkage function to play Military Boxing
linkage Xray or awvs
xray Turn on port monitoring , monitor 127.0.0.1:6666 The data on the
Turn on burp agent ( Which packet to grab )
Will all pass burp All data is forwarded to 127.0.0.1:6666 On
Set up a proxy for the simulator , Let its data go through burp transmitted .( Here the agent address and burp The same as )
Yes app To operate , The corresponding packets will be forwarded to in real time xray On
technological process :
Simulator setup and burp The same agent , Access through the simulator app when , The accessed packets will pass through burp.burp Forward the data packet to the corresponding port through data forwarding , And then through xary Listen to this port . The packet will be in xary Real time display .
边栏推荐
- To tell you the truth, ThreadLocal is really not an advanced thing
- Is it safe to choose mobile phone for stock trading account opening in Guangzhou?
- Examples of topological sequences
- 2022-2028 global electric yacht industry research and trend analysis report
- Fh6908a negative pole turn off synchronous rectification analog low voltage drop diode control IC chip tsot23-6 ultra low power rectifier 1W power consumption < 100ua static replacement mp6908
- Analysis of 8253a register
- 5g smart building solution 2021
- ABAQUS 2022 software installation package and installation tutorial
- Red Hat将在Project Atomic上运用容器负载服务器
- 女朋友说:你要搞懂了MySQL三大日志,我就让你嘿嘿嘿!
猜你喜欢

20220215 CTF misc buuctf the world in the mirror the use of stegsolve tool data extract

HP notebook disable touchpad after mouse is inserted

2022-2028 global PTFE lined valve industry research and trend analysis report

In depth understanding of jetpack compose kernel: slottable system

2022-2028 global capsule shell industry research and trend analysis report

Software engineering best practices - project requirements analysis

How does the VR cloud exhibition hall bring vitality to offline entities? What are the functions?

2022-2028 global rotary transmission system industry research and trend analysis report

5g smart building solution 2021

Detailed explanation of conv2d -- use in arrays and images
随机推荐
Introduction to ES6 promise, new features of ES7 and es8 async and await
Redis - sentinel mode
MySQL index test
1175. 質數排列 / 劍指 Offer II 104. 排列的數目
[NLP] [textcnn] text classification
leetcode 474. Ones and Zeroes 一和零(中等)
The programmer's girlfriend gave me a fatigue driving test
Maxpool2d explanation -- Application in arrays and images
Shell multitasking to download video at the same time
Summer Challenge [FFH] harmonyos mobile phone remote control Dayu development board camera
How to edit special effects in VR panorama? How to display detailed functions?
C# /platform:anycpu32bitpreferred 只能与 /t:exe、/t:winexe 和 /t:appcontainerexe 一起使用
2022-2028 global plant peptone industry research and trend analysis report
PS2 handle-1 "recommended collection"
Is it safe to choose mobile phone for stock trading account opening in Hangzhou?
2022-2028 global single travel industry research and trend analysis report
2022-2028 global herbal diet tea industry research and trend analysis report
76 page comprehensive solution 2022 for smart Logistics Park (download attached)
lvm-snapshot:基于LVM快照的备份
"Experience" my understanding of user growth "new users"