当前位置:网站首页>Vulnerability discovery - App application vulnerability probe type utilization and repair
Vulnerability discovery - App application vulnerability probe type utilization and repair
2022-07-01 00:19:00 【Dark white earphone】

Train of thought :
Decompile extract URL Or packet capture URL, Conduct WEB Application testing , If there is no agreement or other agreement , Net required
The network interface captures packets for data acquisition , Go to other protocol security tests !
APP->WEB APP-> other APP-> reverse
WEB Grab the bag , Other protocol capture demonstration and description
There is no packet capture at the reverse level to distinguish the testing of each protocol
Reverse layer extraction APK Code level data
https://www.cnblogs.com/L0ading/p/12388928.html
Case presentation :
Caught tools WEB Instructions for the use of the protocol surface
Packet capture tool non WEB Instructions for the use of the protocol surface
Android reverse convenience APK One click extraction URL demonstration
utilize Burp Screening and linkage function to play Military Boxing
Simulator four illegal cases APP Safety analysis and testing
Caught tools WEB Instructions for the use of the protocol surface ( demonstration )

burp Agent fills in this machine ip, Port and port ip Corresponding to the mobile phone simulator
burp advantage : On the simulator app The packets of all operations will be sent to HTTPhistory in , And you can filter and search packets by keywords
Open... In the simulator app, A blind meal , The packets are all recorded HTTPhistory in 
Teacup Charles Caught tools ( demonstration )
Modify and set the proxy port 
Check windows agent
Open... In the simulator after setting app,Charles The data package url Capture records 
Bag grabbing spirit


Wireshark Grab the bag
Other packet capturing software may only catch HTTP agreement , It can be used Wireshark Capture network interface . There are various agreements .
Android reverse convenience APK One click extraction URL
Leak a big hole 
utilize Burp Screening and linkage function to play Military Boxing
linkage Xray or awvs
xray Turn on port monitoring , monitor 127.0.0.1:6666 The data on the
Turn on burp agent ( Which packet to grab )
Will all pass burp All data is forwarded to 127.0.0.1:6666 On
Set up a proxy for the simulator , Let its data go through burp transmitted .( Here the agent address and burp The same as )
Yes app To operate , The corresponding packets will be forwarded to in real time xray On
technological process :
Simulator setup and burp The same agent , Access through the simulator app when , The accessed packets will pass through burp.burp Forward the data packet to the corresponding port through data forwarding , And then through xary Listen to this port . The packet will be in xary Real time display .
边栏推荐
- How do it outsourcing resident personnel position their pain points?
- Error when starting PHP: [pool www] cannot get uid for user '@php_ fpm_ [email protected]’
- [untitled]
- The girlfriend said: if you want to understand the three MySQL logs, I will let you heiheihei!
- MaxPool2d详解--在数组和图像中的应用
- 2022-2028 global public address fire alarm system industry research and trend analysis report
- Solutions to errors in installing OpenSSL for CentOS 6.3 x64 PHP 5.2.6 extensions
- PS2 handle-1 "recommended collection"
- The difference between union and union all in MySQL
- How does the VR cloud exhibition hall bring vitality to offline entities? What are the functions?
猜你喜欢

2022-2028 global weight loss ginger tea industry research and trend analysis report

Manage edge browser settings (ie mode, homepage binding, etc.) through group policy in the enterprise

20220215 CTF misc buuctf the world in the mirror the use of stegsolve tool data extract

Ditto set global paste only text shortcuts

5G智慧建筑解决方案2021

2022-2028 global ICT test probe industry research and trend analysis report

Shell multitasking to download video at the same time

2022-2028 global electric yacht industry research and trend analysis report

Analysis of 8253a register

Random ball size, random motion collision
随机推荐
Basic knowledge of Embedded Network - introduction of mqtt
CentOS installation starts redis
Manage edge browser settings (ie mode, homepage binding, etc.) through group policy in the enterprise
leetcode 474. Ones and Zeroes 一和零(中等)
Solutions to errors in installing OpenSSL for CentOS 6.3 x64 PHP 5.2.6 extensions
Repetition is the mother of skill
Dell r720 server installation network card Broadcom 5720 driver
2022-2028 global elevator emergency communication system industry research and trend analysis report
[PHP] self developed framework qphp, used by qphp framework
The programmer's girlfriend gave me a fatigue driving test
2022-2028 global rampant travel industry research and trend analysis report
Simple application example of rhai script engine
Combining online and offline, VR panorama is a good way to transform furniture online!
2022-2028 global mobile scanning radiology room industry survey and trend analysis report
Excuse me, does Flink support synchronizing data to sqlserver
How to close an open DNS resolver
女朋友说:你要搞懂了MySQL三大日志,我就让你嘿嘿嘿!
需求评审,测试人员应该发挥怎样的价值?两分钟让你不再懵逼
Warmup preheating learning rate "suggestions collection"
Red hat will apply container load server on project atomic