当前位置:网站首页>Goby+awvs realize attack surface detection
Goby+awvs realize attack surface detection
2022-06-24 16:07:00 【Bypass】
An expanding range of attacks against , Enterprises need to start from the perspective of attackers , Detect the enterprise's network assets from the outside , Also on Web In depth scanning of the site , Timely identify and deal with high-risk risks , Then it can effectively converge the attack surface .
Automatic detection of attack surface through some tools , To a certain extent, it can improve the work efficiency of safety personnel , This article shares Goby+AWVS Realize attack surface detection , Now let's learn .
Use scenarios : Enterprise asset detection 、web Vulnerability scanning 、 Teamwork, etc .
01、Goby Server deployment
take Goby Deploy to the server to run , You can achieve unlimited scanning , Any member can share assets only by accessing the server , Conducive to team assistance .
(1) download Goby, decompression
wget https://gobies.org/goby-linux-x64-1.9.325.zip
unzip goby-linux-x64-1.9.325.zip(2) Background operation , Output to the specified log file
# establish .sh And write the command
/home/admin/goby-linux/golib/goby-cmd-linux -apiauth user:pass -mode api -bind 0.0.0.0:8361
# Realize screen output recording to log file
nohup sh goby.sh > info.log &(3) Local Goby client , Server management → increase , Fill in the remote server information .
02、 linkage AWVS Vulnerability scanning
(1)Goby add-in , download AWVS plug-in unit .
(2) stay Goby, Set up → Extended settings , Fill in AWVS Of API Key And address .
AWVS Of API Key Get the location as follows :
(3) stay Goby Of Web Detection inside , See the scanned assets , You can click AWVS The button , You can start the scanning task .
(4) stay AWVS Console , You can see Goby Scanning tasks issued , And the scanning task has been completed .
(5) go back to Goby client , You can see the vulnerability scanning results , Exportable vulnerability report .
边栏推荐
- Logging is not as simple as you think
- Three solutions for Jenkins image failing to update plug-in Center
- How to implement SQLSERVER database migration in container
- MySQL日期时间戳转换
- Summer Challenge harmonyos - to do list with date effect
- April 23, 2021: there are n cities in the TSP problem, and there is a distance between any two cities
- 2021-05-02: given the path of a file directory, write a function
- 【面试高频题】难度 3/5,可直接构造的序列 DP 题
- B. Terry sequence (thinking + greed) codeforces round 665 (Div. 2)
- D. Solve The Maze(思维+bfs)Codeforces Round #648 (Div. 2)
猜你喜欢

The penetration of 5g users of operators is far slower than that of 4G. The popularity of 5g still depends on China Radio and television

Build go command line program tool chain

实现领域驱动设计 - 使用ABP框架 - 领域逻辑 & 应用逻辑

Mongodb Getting started Practical Tutoriel: Learning Summary Table des matières

Intelij 中的 Database Tools可以连接但是无法显示SCHEMA, TABLES

Linux record -4.22 MySQL 5.37 installation (supplementary)

Three solutions for Jenkins image failing to update plug-in Center

Here comes Wi Fi 7. How strong is it?

CAP:多重注意力机制,有趣的细粒度分类方案 | AAAI 2021

【应用推荐】最近大火的Apifox & Apipost 上手体验与选型建议
随机推荐
ZOJ——4104 Sequence in the Pocket(思维问题)
The catch-up of domestic chips has scared Qualcomm, the leader of mobile phone chips in the United States, and made moves to cope with the competition
D. Solve the maze (thinking +bfs) codeforces round 648 (Div. 2)
Software test [high frequency] interview questions sorted out by staying up late (latest in 2022)
几种常见的DoS攻击
Flink kubernetes application deployment
Reference to junit5 test framework in gradle
MongoDB入門實戰教程:學習總結目錄
Instruction document for online written examination assistance of smart side school recruitment
Fastjson 漏洞利用技巧
[my advanced OpenGL learning journey] learning notes of OpenGL coordinate system
转置卷积学习笔记
Easy installation of Jenkins
great! The novel website project is completely open source
D. Solve The Maze(思维+bfs)Codeforces Round #648 (Div. 2)
企业安全攻击面分析工具
Ascinema with asciicast2gif for efficient command line terminal recording
B. Terry sequence (thinking + greed) codeforces round 665 (Div. 2)
Some experiences of K project: global template highlights
One article explains Jackson configuration information in detail