当前位置:网站首页>Vulnerability discovery - App application vulnerability probe type utilization and repair
Vulnerability discovery - App application vulnerability probe type utilization and repair
2022-07-01 00:19:00 【Dark white earphone】

Train of thought :
Decompile extract URL Or packet capture URL, Conduct WEB Application testing , If there is no agreement or other agreement , Net required
The network interface captures packets for data acquisition , Go to other protocol security tests !
APP->WEB APP-> other APP-> reverse
WEB Grab the bag , Other protocol capture demonstration and description
There is no packet capture at the reverse level to distinguish the testing of each protocol
Reverse layer extraction APK Code level data
https://www.cnblogs.com/L0ading/p/12388928.html
Case presentation :
Caught tools WEB Instructions for the use of the protocol surface
Packet capture tool non WEB Instructions for the use of the protocol surface
Android reverse convenience APK One click extraction URL demonstration
utilize Burp Screening and linkage function to play Military Boxing
Simulator four illegal cases APP Safety analysis and testing
Caught tools WEB Instructions for the use of the protocol surface ( demonstration )

burp Agent fills in this machine ip, Port and port ip Corresponding to the mobile phone simulator
burp advantage : On the simulator app The packets of all operations will be sent to HTTPhistory in , And you can filter and search packets by keywords
Open... In the simulator app, A blind meal , The packets are all recorded HTTPhistory in 
Teacup Charles Caught tools ( demonstration )
Modify and set the proxy port 
Check windows agent
Open... In the simulator after setting app,Charles The data package url Capture records 
Bag grabbing spirit


Wireshark Grab the bag
Other packet capturing software may only catch HTTP agreement , It can be used Wireshark Capture network interface . There are various agreements .
Android reverse convenience APK One click extraction URL
Leak a big hole 
utilize Burp Screening and linkage function to play Military Boxing
linkage Xray or awvs
xray Turn on port monitoring , monitor 127.0.0.1:6666 The data on the
Turn on burp agent ( Which packet to grab )
Will all pass burp All data is forwarded to 127.0.0.1:6666 On
Set up a proxy for the simulator , Let its data go through burp transmitted .( Here the agent address and burp The same as )
Yes app To operate , The corresponding packets will be forwarded to in real time xray On
technological process :
Simulator setup and burp The same agent , Access through the simulator app when , The accessed packets will pass through burp.burp Forward the data packet to the corresponding port through data forwarding , And then through xary Listen to this port . The packet will be in xary Real time display .
边栏推荐
- New trend of embedded software development: Devops
- 2022-2028 global ICT test probe industry research and trend analysis report
- Advanced mathematical modeling
- Warmup preheating learning rate "suggestions collection"
- [untitled]
- 2022-2028 global public address fire alarm system industry research and trend analysis report
- 2022-2028 global PTFE lined valve industry research and trend analysis report
- On the application of cluster analysis in work
- Is it safe to open a stock account of Huatai Securities online?
- 2022-2028 global mobile scanning radiology room industry survey and trend analysis report
猜你喜欢

Bridge emqx cloud data to AWS IOT through the public network

2022-2028 global mobile scanning radiology room industry survey and trend analysis report

IFLYTEK active competition summary! (12)

2022-2028 global elevator emergency communication system industry research and trend analysis report

Redis - how to understand publishing and subscribing

2022-2028 global ultra high purity electrolytic iron sheet industry research and trend analysis report

Vmware16 installing win11 virtual machine (the most complete step + stepping on the pit)

Fh6908a negative pole turn off synchronous rectification analog low voltage drop diode control IC chip tsot23-6 ultra low power rectifier 1W power consumption < 100ua static replacement mp6908

Which is better, server rental or hosting services in the United States?

Maxpool2d explanation -- Application in arrays and images
随机推荐
在指南针上买基金安全吗?
Software engineering best practices - project requirements analysis
深入理解 Jetpack Compose 内核:SlotTable 系统
Dell r720 server installation network card Broadcom 5720 driver
What SQL statements are supported for data filtering
LVM snapshot: preparation of backup based on LVM snapshot
Operation record of reinitialization instance of Dameng database
1175. Disposition des nombres premiers / échange de doigts II 104. Nombre de permutations
How does the VR cloud exhibition hall bring vitality to offline entities? What are the functions?
CesiumJS 2022^ 源码解读[6] - 三维模型(ModelExperimental)新架构
Redis - cache penetration, cache breakdown, cache avalanche
2022-2028 global carbon fiber room scraper system industry research and trend analysis report
Techo youth 2022 academic year college open class: behind the live broadcast of Lianmai, explore how to apply audio and video technology
What is the fastest way to import data from HDFS to Clickhouse? Spark is imported through JDBC or HDFS
2022-06-30: what does the following golang code output? A:0; B:2; C: Running error. package main import “fmt“ func main()
Wordpress blog uses volcano engine veimagex for static resource CDN acceleration (free)
2022-2028 global PTFE lined valve industry research and trend analysis report
A detailed explanation of the implementation principle of go Distributed Link Tracking
On the application of cluster analysis in work
When is it appropriate to replace a virtual machine with a virtual machine?