当前位置:网站首页>Learn to punch in Web
Learn to punch in Web
2022-07-06 20:11:00 【Five five six six_ Pendulum machine 0524】
Hetian network security laboratory
2022.7.5
Use burp Punch in with brute force
burpsuite
burp It is equivalent to adding a layer of proxy at the middle end of the browser sending requests to the server , The request sent will be intercepted
burpsuite Set listening port :
burp:Proxy-Options, Local 8080 The port is selected by default , You can add another Add
Local : Control panel - The Internet and Internet-Internet Options - Connect - LAN settings - proxy server
Proxy-Intercept-Intercept is on, Then start visiting the website , Click after interception forward, This package is sent from the proxy to the server , The results returned by the server will still be recorded , Click on drop This bag will be thrown away
compare The module compares the two packets
Right click on the packet send to comparer,Comparer-Words/Bytes
repeater Module replay analysis response
Right click on the packet send to repeater,Repeater-Go, The right side returns the server's response
intruder Module burst
Right click on the packet send to intruder,Target Set to explode host Address and port number ,positions Of Add$ Field blasting point ,Payloads Set the type of blasting fill ,Load Add Dictionary
CTFweb Subtotal two punch
see HTTP Original request package and response package
F12-network- Click on php
style=“display:none” Hidden elements
Used to hide an element ,none Change it to block You can unhide
●display:none --- Do not reserve physical space for hidden objects , That is, the object disappears completely on the page , Generally speaking, you can't see or touch .
●visible:hidden--- Make objects invisible on Web pages , However, the space occupied by the object on the web page has not changed , Generally speaking, you can't see but feel .
come from display:none_harry5508 The blog of -CSDN Blog _display:none
边栏推荐
- 01 基础入门-概念名词
- 案例 ①|主机安全建设:3个层级,11大能力的最佳实践
- Introduction to enterprise lean management system
- 【Yann LeCun点赞B站UP主使用Minecraft制作的红石神经网络】
- Crawler (14) - scrape redis distributed crawler (1) | detailed explanation
- New generation garbage collector ZGC
- AddressSanitizer 技术初体验
- 5. Wireless in vivo nano network: top ten "feasible?" problem
- HMS core machine learning service creates a new "sound" state of simultaneous interpreting translation, and AI makes international exchanges smoother
- 句号压缩过滤器
猜你喜欢
BUUCTF---Reverse---easyre
Tencent T3 Daniel will teach you hand-in-hand, the internal information of the factory
腾讯架构师首发,2022Android面试笔试总结
报错分析~csdn反弹shell报错
[calculating emotion and thought] floor sweeper, typist, information panic and Oppenheimer
New generation garbage collector ZGC
Tencent byte Alibaba Xiaomi jd.com offer got a soft hand, and the teacher said it was great
The "white paper on the panorama of the digital economy" has been released with great emphasis on the digitalization of insurance
案例 ①|主机安全建设:3个层级,11大能力的最佳实践
Oceanbase Community Edition OBD mode deployment mode stand-alone installation
随机推荐
使用ssh连接被拒
Special topic of rotor position estimation of permanent magnet synchronous motor -- Summary of position estimation of fundamental wave model
[cloud native and 5g] micro services support 5g core network
腾讯T3手把手教你,真的太香了
Tencent architects first, 2022 Android interview written examination summary
Crawler (14) - scrape redis distributed crawler (1) | detailed explanation
[cloud lesson] EI lesson 47 Mrs offline data analysis - processing OBS data through Flink
Standardized QCI characteristics
22-07-05 upload of qiniu cloud storage pictures and user avatars
Vscode debug run fluent message: there is no extension for debugging yaml. Should we find yaml extensions in the market?
Cesium Click to draw a circle (dynamically draw a circle)
腾讯字节阿里小米京东大厂Offer拿到手软,老师讲的真棒
Standardized QCI characteristics
深入浅出,面试突击版
JVM_常见【面试题】
颜色(color)转换为三刺激值(r/g/b)(干股)
Example of applying fonts to flutter
【计网】第三章 数据链路层(4)局域网、以太网、无线局域网、VLAN
5. Wireless in vivo nano network: top ten "feasible?" problem
1805. Number of different integers in the string