当前位置:网站首页>Penetration test information collection - site architecture and construction
Penetration test information collection - site architecture and construction
2022-07-06 18:35:00 【Aspirin. two thousand and two】
List of articles
information gathering — framework 、 Construction, etc
1、 Site construction analysis
1.1、 Directory site
xxx.com
and xxx.com/bbs
There are two different pages , It can be regarded as two sets of procedures , But the vulnerability of any page has an impact on the website
The home page may be in D Under the plate www In the directory root Catalog ,bbs The page is on root in bbs Catalog
1.2、 Port class site
xxx.com:8080
The default home page is 80 port , however 8080 Port vulnerabilities will also affect 80 port , Both are on the same server
Port settings , Different ports correspond to different applications . such as ssh The default port is 22
1.3、 Subdomain site
goodlift-www.bbs
master station :www.goodlift.net
substation :bbs.goodlift.net
bbs.goodlift.net Yes, it is Discuz Built , and www.goodlift.net Yes, it is destoon b2b Built . Two websites are not necessarily on the same server
1.4、 Similar domain name sites
It must be on the same server
1.4、 Similar domain name sites
Different domain name , Same website
边栏推荐
- Self supervised heterogeneous graph neural network with CO comparative learning
- Compilation Principle -- C language implementation of prediction table
- DOM Brief
- Jdbc driver, c3p0, druid and jdbctemplate dependent jar packages
- POJ 2208 six lengths of tetrahedron are known, and the volume is calculated
- 【中山大学】考研初试复试资料分享
- 30 分钟看懂 PCA 主成分分析
- Transport layer congestion control - slow start and congestion avoidance, fast retransmission, fast recovery
- 爬虫玩得好,牢饭吃到饱?这3条底线千万不能碰!
- 测试1234
猜你喜欢
TOP命令详解
Distiller les connaissances du modèle interactif! L'Université de technologie de Chine & meituan propose Virt, qui a à la fois l'efficacité du modèle à deux tours et la performance du modèle interacti
Splay
Rb157-asemi rectifier bridge RB157
30 分钟看懂 PCA 主成分分析
十、进程管理
287. Find duplicates
递归的方式
Use cpolar to build a business website (1)
CSRF漏洞分析
随机推荐
Shangsilicon Valley JUC high concurrency programming learning notes (3) multi thread lock
CSRF漏洞分析
2022暑期项目实训(二)
This article discusses the memory layout of objects in the JVM, as well as the principle and application of memory alignment and compression pointer
30 minutes to understand PCA principal component analysis
DOM简要
Numerical analysis: least squares and ridge regression (pytoch Implementation)
2022暑期项目实训(三)
文档编辑之markdown语法(typora)
[Matlab] Simulink 同一模块的输入输出的变量不能同名
Test 1234
Using block to realize the traditional values between two pages
CRMEB 商城系统如何助力营销?
图之广度优先遍历
从交互模型中蒸馏知识!中科大&美团提出VIRT,兼具双塔模型的效率和交互模型的性能,在文本匹配上实现性能和效率的平衡!...
D binding function
阿里云国际版ECS云服务器无法登录宝塔面板控制台
监控界的最强王者,没有之一!
2022 Summer Project Training (I)
爬虫玩得好,牢饭吃到饱?这3条底线千万不能碰!