当前位置:网站首页>Infiltration learning diary day19
Infiltration learning diary day19
2022-07-04 01:10:00 【XiXioo1】
Here I added waf Knowledge
Combined with the safety dog learned before , I've seen a lot of simulated interview answers
1. Inline comments The first kind /*! The second kind /*! Add numbers , If it is greater than ( Still less than )mysql Version number of , The annotated statements here can also be used
2. Run keyword dictionary , Then run keyword combinations
3. Parameter pollution , False comment
Upload files :
1. The front-end verification can be passed directly burp Repackage , First upload his limited format , Then change the package to the suffix we want to write
2.content-type, through burp Repackage ,content-type This is based on the different content we upload type The type will change , But it can also be in burp Modify it into the format specified in
Blacklist detection : Write the suffix that is not allowed to upload in the array to match
Bypass :
upload-labs Methods that appear in
Add . .( Dot space dot )
Double write after the suffix ::$DATA
.htaceess File attack
.htaccess Two conditions for the successful operation of files as local variables
1.Allow Override All
2.LoadMoudule rewrite_module modules/mod_rewrite.so#rewrite The module is on
If you don't know which configuration file the above module is in , It can be used phpstorm open phpstudy File global search (ctrl+shift+F)
Implementation method
Create a new one .htaccess Name the file , Then add
<FilesMatch " A name ">
SetHandler application/x-httpd-php
</FilesMatch>
Then create a new one named above under this path .txt Text , Join in php The code can be parsed successfully
Add a link :
.htaccess Detailed explanation of file parsing vulnerability
边栏推荐
- 中电资讯-信贷业务数字化转型如何从星空到指尖?
- [common error] UART cannot receive data error
- Function: store the strings entered in the main function in reverse order. For example, if you input the string "ABCDEFG", you should output "gfedcba".
- 【.NET+MQTT】.NET6 环境下实现MQTT通信,以及服务端、客户端的双边消息订阅与发布的代码演示
- The FISCO bcos console calls the contract and reports an error does not exist
- Functions and arrays of shell scripts
- Long article review: entropy, free energy, symmetry and dynamics in the brain
- 功能:求5行5列矩阵的主、副对角线上元素之和。注意, 两条对角线相交的元素只加一次。例如:主函数中给出的矩阵的两条对角线的和为45。
- 不得不会的Oracle数据库知识点(一)
- Design of database table foreign key
猜你喜欢
It's OK to have hands-on 8 - project construction details 3-jenkins' parametric construction
Pytest unit test framework: simple and easy to use parameterization and multiple operation modes
Long article review: entropy, free energy, symmetry and dynamics in the brain
中电资讯-信贷业务数字化转型如何从星空到指尖?
Sequence list and linked list
Data mining vs Machine Learning: what is the difference between them? Which is more suitable for you to learn
Eight year test old bird, some suggestions for 1-3 year programmers
GUI application: socket network chat room
技術實踐|線上故障分析及解决方法(上)
2-Redis架构设计到使用场景-四种部署运行模式(下)
随机推荐
Who moved my code!
CesiumJS 2022^ 源码解读[8] - 资源封装与多线程
我管你什么okr还是kpi,PPT轻松交给你
A malware detection method for checking PLC system using satisfiability modulus theoretical model
Huawei BFD and NQA
Function: find the approximate value of the limit of the ratio of the former term to the latter term of Fibonacci sequence. For example, when the error is 0.0001, the function value is 0.618056.
Cesiumjs 2022^ source code interpretation [8] - resource encapsulation and multithreading
The force deduction method summarizes the single elements in the 540 ordered array
How to set the response description information when the response parameter in swagger is Boolean or integer
Gee: create a new feature and set corresponding attributes
CLP information - how does the digital transformation of credit business change from star to finger?
功能:求5行5列矩阵的主、副对角线上元素之和。注意, 两条对角线相交的元素只加一次。例如:主函数中给出的矩阵的两条对角线的和为45。
Design of database table foreign key
Fundamentals of machine learning: feature selection with lasso
2-Redis架构设计到使用场景-四种部署运行模式(下)
机器学习基础:用 Lasso 做特征选择
Force deduction solution summary 1189- maximum number of "balloons"
Alibaba test engineer with an annual salary of 500000 shares notes: a complete set of written tests of software testing
技術實踐|線上故障分析及解决方法(上)
Beijing invites reporters and media