当前位置:网站首页>captcha-killer验证码识别插件
captcha-killer验证码识别插件
2022-07-06 09:23:00 【又懒有菜】
目录
环境的配置
插件下载地址GitHub - broken5/captcha-killer-java8
https://github.com/broken5/captcha-killer-java8
0x01 作用
在目前实战挖掘src或者渗透测试中 大部分验证码是不可以啊绕过的 。想要通过爆破来进入后台页面 。 repeat模块测试后,验证码不可绕过,用captcha-killer能够识别验证码。 之后再进行弱口令爆破。
0x02 安装插件
jar的安装跳过了 安装成功效果如下


实战第一步 抓包方式
0x01 截取验证码包
这里截取之后不会再porxy中显示 但是history可以查看数据包

0x02 发送包
将验证码包发送到captcha-killer 如上图右键没有扩展插件
先将包发送到repeat中 再在repeat发送到capcha-killer模块

发送成功点击获取

实战第二步 接口配置
0x01 接口的配置
这里接口选用云打码平台(错误率大概5%):
图片识别-打码平台-打码网站-识别验证码-图鉴网络科技有限公司
http://www.ttshitu.com/
POST /predict HTTP/1.1
Host: api.ttshitu.com
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36
Accept: application/json;
Accept-Encoding: gzip, deflate
Accept-Language: zh-CN,zh;q=0.9
Cookie: Hm_lvt_d92eb5418ecf5150abbfe0e505020254=1585994993,1586144399; SESSION=5ebf9c31-a424-44f8-8188-62ca56de7bdf; Hm_lpvt_d92eb5418ecf5150abbfe0e505020254=1586144399
Connection: close
Content-Type: application/json;charset=UTF-8
Content-Length: 109
{"username":"账号","password":"密码","typeid":"3","image":"<@BASE64><@IMG_RAW></@IMG_RAW></@BASE64>"}
识别率如上图
实战第三步 爆破模块的设置
0x01 为验证码设置变量

边栏推荐
- Xray and burp linkage mining
- 实验六 继承和多态
- 7-1 输出2到n之间的全部素数(PTA程序设计)
- 1. Preliminary exercises of C language (1)
- Ucos-iii learning records (11) - task management
- 扑克牌游戏程序——人机对抗
- The United States has repeatedly revealed that the yield of interest rate hiked treasury bonds continued to rise
- Relationship between hashcode() and equals()
- Get started with typescript
- Brief introduction to XHR - basic use of XHR
猜你喜欢
随机推荐
7-4 散列表查找(PTA程序设计)
Safe driving skills on ice and snow roads
1. Preliminary exercises of C language (1)
[MySQL database learning]
7-5 staircase upgrade (PTA program design)
攻防世界MISC练习区(gif 掀桌子 ext3 )
7-11 机工士姆斯塔迪奥(PTA程序设计)
HackMyvm靶机系列(3)-visions
1143_ SiCp learning notes_ Tree recursion
Intensive literature reading series (I): Courier routing and assignment for food delivery service using reinforcement learning
UGUI—Text
3. Input and output functions (printf, scanf, getchar and putchar)
7-1 输出2到n之间的全部素数(PTA程序设计)
Principles, advantages and disadvantages of two persistence mechanisms RDB and AOF of redis
sqqyw(淡然点图标系统)漏洞复现和74cms漏洞复现
Build domain environment (win)
Low income from doing we media? 90% of people make mistakes in these three points
Implementation of count (*) in MySQL
Renforcer les dossiers de base de l'apprentissage
Meituan dynamic thread pool practice ideas, open source








