当前位置:网站首页>Vulnerability discovery - App application vulnerability probe type utilization and repair
Vulnerability discovery - App application vulnerability probe type utilization and repair
2022-07-01 00:19:00 【Dark white earphone】

Train of thought :
Decompile extract URL Or packet capture URL, Conduct WEB Application testing , If there is no agreement or other agreement , Net required
The network interface captures packets for data acquisition , Go to other protocol security tests !
APP->WEB APP-> other APP-> reverse
WEB Grab the bag , Other protocol capture demonstration and description
There is no packet capture at the reverse level to distinguish the testing of each protocol
Reverse layer extraction APK Code level data
https://www.cnblogs.com/L0ading/p/12388928.html
Case presentation :
Caught tools WEB Instructions for the use of the protocol surface
Packet capture tool non WEB Instructions for the use of the protocol surface
Android reverse convenience APK One click extraction URL demonstration
utilize Burp Screening and linkage function to play Military Boxing
Simulator four illegal cases APP Safety analysis and testing
Caught tools WEB Instructions for the use of the protocol surface ( demonstration )

burp Agent fills in this machine ip, Port and port ip Corresponding to the mobile phone simulator
burp advantage : On the simulator app The packets of all operations will be sent to HTTPhistory in , And you can filter and search packets by keywords
Open... In the simulator app, A blind meal , The packets are all recorded HTTPhistory in 
Teacup Charles Caught tools ( demonstration )
Modify and set the proxy port 
Check windows agent
Open... In the simulator after setting app,Charles The data package url Capture records 
Bag grabbing spirit


Wireshark Grab the bag
Other packet capturing software may only catch HTTP agreement , It can be used Wireshark Capture network interface . There are various agreements .
Android reverse convenience APK One click extraction URL
Leak a big hole 
utilize Burp Screening and linkage function to play Military Boxing
linkage Xray or awvs
xray Turn on port monitoring , monitor 127.0.0.1:6666 The data on the
Turn on burp agent ( Which packet to grab )
Will all pass burp All data is forwarded to 127.0.0.1:6666 On
Set up a proxy for the simulator , Let its data go through burp transmitted .( Here the agent address and burp The same as )
Yes app To operate , The corresponding packets will be forwarded to in real time xray On
technological process :
Simulator setup and burp The same agent , Access through the simulator app when , The accessed packets will pass through burp.burp Forward the data packet to the corresponding port through data forwarding , And then through xary Listen to this port . The packet will be in xary Real time display .
边栏推荐
- 2022-06-30: what does the following golang code output? A:0; B:2; C: Running error. package main import “fmt“ func main()
- 深入理解 Jetpack Compose 内核:SlotTable 系统
- [leetcode] [SQL] notes
- 76 page comprehensive solution 2022 for smart Logistics Park (download attached)
- Dataloader source code_ DataLoader
- 2022-2028 global encrypted external hard disk industry research and trend analysis report
- 需求评审,测试人员应该发挥怎样的价值?两分钟让你不再懵逼
- 76页智慧物流园区综合解决方案2022(附下载)
- The full technology stack, full scene and full role cloud native series training was launched to help enterprises build a hard core cloud native technology team
- 高等数学建模
猜你喜欢

The programmer's girlfriend gave me a fatigue driving test

2022-2028 global rotary transmission system industry research and trend analysis report

ABAQUS 2022 latest edition - perfect realistic simulation solution

C WinForm program interface optimization example

2022-2028 global weight loss ginger tea industry research and trend analysis report

Introduction to ES6 promise, new features of ES7 and es8 async and await

ABAQUS 2022 software installation package and installation tutorial

2022-2028 global plant peptone industry research and trend analysis report
![[UML] UML class diagram](/img/6f/30bd15967103969e600d69e618d8bf.png)
[UML] UML class diagram

Netease cloud sign in lottery? That year I could sign in for 365 days. No? Look.
随机推荐
MaxPool2d详解--在数组和图像中的应用
How does the VR cloud exhibition hall bring vitality to offline entities? What are the functions?
When is it appropriate to replace a virtual machine with a virtual machine?
Analysis of 8253a register
网上开华泰证券的股票账户是否安全呢?
如何关闭一个开放的DNS解析器
Why did kubernetes win? The changes in the container circle!
Rust book materials - yazhijia Library
A detailed explanation of the implementation principle of go Distributed Link Tracking
Error 2059 when Navicat connects to MySQL
Redis - cache penetration, cache breakdown, cache avalanche
The college entrance examination in 2022 is over. Does anyone really think programmers don't need to study after work?
Solving the weird problem that the query conditions affect the value of query fields in MySQL query
The difference between union and union all in MySQL
NATs cluster deployment
2022-2028 global weight loss ginger tea industry research and trend analysis report
2022-2028 global public address fire alarm system industry research and trend analysis report
How to edit special effects in VR panorama? How to display detailed functions?
[designmode] factory pattern
Solutions to errors in installing OpenSSL for CentOS 6.3 x64 PHP 5.2.6 extensions