当前位置:网站首页>"WEB Security Penetration Testing" (28) Burp Collaborator-dnslog out-band technology
"WEB Security Penetration Testing" (28) Burp Collaborator-dnslog out-band technology
2022-08-05 00:20:00 【Stargazing at midnight】
1.What is Burp Collaborator
What is Burp Collaborator?It is a module that is carried by default in the new version of the penetration testing tool BurpSuite. It is a client. We can use BurpSuite to configure the outboard server for us. We can use the default carried by BurpSuite, or we can use our own private cloud server.
Having said so much, you may not understand what it is?
In fact, it is a DNSlog take-out tool. As long as you are doing network security, you should know http://dnslog.cn/ and http://www.ceye.io/ these two platforms, they are free DNSlog platforms, we can use them to monitor DNS resolution records and HTTP access records, which is very helpful for us to verify some vulnerabilities.
2.Burp Collaborator use
(1) Open BurpSuite, select "Project options" in the first step, "Misc" in the second step, and "Use the default Collaborator server" in the third step (use the default configured take-out server, if you want to use your ownThe server can be freely configured below), the fourth step is to click "Run health check.." to test whether the take-out server can work normally.
(2) Now go to start the client and select "Burp" under "Burp"
边栏推荐
- 元宇宙:未来我们的每一个日常行为是否都能成为赚钱工具?
- 2022牛客多校第三场 J题 Journey
- Detailed explanation of common DNS resource record types
- 【unity编译器扩展之模型动画拷贝】
- 软件测试面试题:黑盒测试、白盒测试以及单元测试、集成测试、系统测试、验收测试的区别与联系?
- SQL association table update
- E - Distance Sequence (前缀和优化dp
- 软件测试面试题:您以往所从事的软件测试工作中,是否使用了一些工具来进行软件缺陷(Bug)的管理?如果有,请结合该工具描述软件缺陷(Bug)跟踪管理的流程?
- ARC129E Yet Another Minimization 题解 【网络流笔记】
- 【论文笔记】—低照度图像增强—Unsupervised—EnlightenGAN—2019-TIP
猜你喜欢
【云原生--Kubernetes】调度约束
jenkins send mail system configuration
Implementation principle of golang coroutine
子连接中的参数传递
[230]连接Redis后执行命令错误 MISCONF Redis is configured to save RDB snapshots
[idea] idea configures sql formatting
国内网站用香港服务器会被封吗?
leetcode:266. 回文全排列
TinyMCE禁用转义
What is next-generation modeling (with learning materials)
随机推荐
【LeetCode】图解 904. 水果成篮
简单的顺序结构程序(C语言)
2022杭电多校第三场 L题 Two Permutations
情侣牵手[贪心 & 抽象]
2022多校第二场 K题 Link with Bracket Sequence I
could not build server_names_hash, you should increase server_names_hash_bucket_size: 32
LeetCode Hot 100
typeScript - Partially apply a function
《WEB安全渗透测试》(28)Burp Collaborator-dnslog外带技术
Couple Holding Hands [Greedy & Abstract]
看图识字,DELL SC4020 / SCv2000 控制器更换过程
canvas 高斯模糊效果
ARC129E Yet Another Minimization 题解 【网络流笔记】
软件测试面试题:BIOS, Fat, IDE, Sata, SCSI, Ntfs windows NT?
E - Distance Sequence (前缀和优化dp
Getting started with 3D modeling for games, what modeling software can I choose?
机器学习(公式推导与代码实现)--sklearn机器学习库
软件开发工具的技术要素
僵尸进程和孤儿进程
QSunSync 七牛云文件同步工具,批量上传