当前位置:网站首页>Penetration test information collection - site architecture and construction

Penetration test information collection - site architecture and construction

2022-07-06 18:35:00 Aspirin. two thousand and two

information gathering — framework 、 Construction, etc

1、 Site construction analysis

1.1、 Directory site

xxx.com and xxx.com/bbs There are two different pages , It can be regarded as two sets of procedures , But the vulnerability of any page has an impact on the website

The home page may be in D Under the plate www In the directory root Catalog ,bbs The page is on root in bbs Catalog

1.2、 Port class site

xxx.com:8080

The default home page is 80 port , however 8080 Port vulnerabilities will also affect 80 port , Both are on the same server

Port settings , Different ports correspond to different applications . such as ssh The default port is 22

1.3、 Subdomain site

goodlift-www.bbs

master station :www.goodlift.net

substation :bbs.goodlift.net

bbs.goodlift.net Yes, it is Discuz Built , and www.goodlift.net Yes, it is destoon b2b Built . Two websites are not necessarily on the same server

1.4、 Similar domain name sites

It must be on the same server

1.4、 Similar domain name sites

Different domain name , Same website

原网站

版权声明
本文为[Aspirin. two thousand and two]所创,转载请带上原文链接,感谢
https://yzsam.com/2022/02/202202131300352666.html