当前位置:网站首页>Penetration test information collection - site architecture and construction
Penetration test information collection - site architecture and construction
2022-07-06 18:35:00 【Aspirin. two thousand and two】
List of articles
information gathering — framework 、 Construction, etc
1、 Site construction analysis
1.1、 Directory site
xxx.com and xxx.com/bbs There are two different pages , It can be regarded as two sets of procedures , But the vulnerability of any page has an impact on the website
The home page may be in D Under the plate www In the directory root Catalog ,bbs The page is on root in bbs Catalog
1.2、 Port class site
xxx.com:8080
The default home page is 80 port , however 8080 Port vulnerabilities will also affect 80 port , Both are on the same server
Port settings , Different ports correspond to different applications . such as ssh The default port is 22
1.3、 Subdomain site
goodlift-www.bbs
master station :www.goodlift.net
substation :bbs.goodlift.net
bbs.goodlift.net Yes, it is Discuz Built , and www.goodlift.net Yes, it is destoon b2b Built . Two websites are not necessarily on the same server
1.4、 Similar domain name sites
It must be on the same server
1.4、 Similar domain name sites
Different domain name , Same website
边栏推荐
- MS-TCT:Inria&SBU提出用于动作检测的多尺度时间Transformer,效果SOTA!已开源!(CVPR2022)...
- Ms-tct: INRIA & SBU proposed a multi-scale time transformer for motion detection. The effect is SOTA! Open source! (CVPR2022)...
- Introduction and case analysis of Prophet model
- 解读云原生技术
- [.Net core] solution to error reporting due to too long request length
- UDP protocol: simple because of good nature, it is inevitable to encounter "city can play"
- 第三季百度网盘AI大赛盛夏来袭,寻找热爱AI的你!
- 2019 Alibaba cluster dataset Usage Summary
- 2022暑期项目实训(一)
- [sword finger offer] 60 Points of N dice
猜你喜欢

C language exchanges two numbers through pointers

44所高校入选!分布式智能计算项目名单公示

Windows connects redis installed on Linux

Penetration test information collection - CDN bypass

Xu Xiang's wife Ying Ying responded to the "stock review": she wrote it!

Maixll-Dock 摄像头使用

On time and parameter selection of asemi rectifier bridge db207

第三季百度网盘AI大赛盛夏来袭,寻找热爱AI的你!

当保存参数使用结构体时必备的开发技巧方式
![[Matlab] Simulink 同一模块的输入输出的变量不能同名](/img/99/adfe50075010916439cd053b8f04c7.png)
[Matlab] Simulink 同一模块的输入输出的变量不能同名
随机推荐
Top command details
F200 - UAV equipped with domestic open source flight control system based on Model Design
C language college laboratory reservation registration system
D binding function
首先看K一个难看的数字
徐翔妻子应莹回应“股评”:自己写的!
Use cpolar to build a business website (1)
287. 寻找重复数
【剑指 Offer】 60. n个骰子的点数
win10系统下插入U盘有声音提示却不显示盘符
Breadth first traversal of graph
44所高校入选!分布式智能计算项目名单公示
阿里云国际版ECS云服务器无法登录宝塔面板控制台
JDBC驱动器、C3P0、Druid和JDBCTemplate相关依赖jar包
C语言高校实验室预约登记系统
30 分钟看懂 PCA 主成分分析
Epoll () whether it involves wait queue analysis
Reprint: defect detection technology of industrial components based on deep learning
First, look at K, an ugly number
Jerry is the custom background specified by the currently used dial enable [chapter]