当前位置:网站首页>"WEB Security Penetration Testing" (28) Burp Collaborator-dnslog out-band technology
"WEB Security Penetration Testing" (28) Burp Collaborator-dnslog out-band technology
2022-08-05 00:20:00 【Stargazing at midnight】
1.What is Burp Collaborator
What is Burp Collaborator?It is a module that is carried by default in the new version of the penetration testing tool BurpSuite. It is a client. We can use BurpSuite to configure the outboard server for us. We can use the default carried by BurpSuite, or we can use our own private cloud server.
Having said so much, you may not understand what it is?
In fact, it is a DNSlog take-out tool. As long as you are doing network security, you should know http://dnslog.cn/ and http://www.ceye.io/ these two platforms, they are free DNSlog platforms, we can use them to monitor DNS resolution records and HTTP access records, which is very helpful for us to verify some vulnerabilities.
2.Burp Collaborator use
(1) Open BurpSuite, select "Project options" in the first step, "Misc" in the second step, and "Use the default Collaborator server" in the third step (use the default configured take-out server, if you want to use your ownThe server can be freely configured below), the fourth step is to click "Run health check.." to test whether the take-out server can work normally.
(2) Now go to start the client and select "Burp" under "Burp"
边栏推荐
- typeScript - Partially apply a function
- oracle创建用户以后的权限问题
- 软件测试面试题:LoadRunner 分为哪三个模块?
- 【数据挖掘概论】数据挖掘的简单描述
- Chinese and Japanese color style
- Getting started with 3D modeling for games, what modeling software can I choose?
- [LeetCode] Summary of Matrix Simulation Related Topics
- 00、数组及字符串常用的 API(详细剖析)
- Detailed explanation of common DNS resource record types
- 子连接中的参数传递
猜你喜欢
随机推荐
Brainstorm: Complete Backpack
2022杭电多校第三场 L题 Two Permutations
软件测试面试题:黑盒测试、白盒测试以及单元测试、集成测试、系统测试、验收测试的区别与联系?
标识符、关键字、常量 和变量(C语言)
gorm的Raw与scan
《MySQL入门很轻松》第2章:MySQL管理工具介绍
【LeetCode】图解 904. 水果成篮
oracle创建用户
IDEA file encoding modification
2022牛客多校训练第二场 L题 Link with Level Editor I
在线中文姓名生成工具推荐
机器学习(公式推导与代码实现)--sklearn机器学习库
仿网易云音乐小程序-uniapp
软件测试面试题:手工测试与自动测试有哪些区别?
E - Many Operations (按位考虑 + dp思想记录操作后的结果
First, the basic concept of reptiles
僵尸进程和孤儿进程
【LeetCode】滑动窗口题解汇总
软件测试面试题:系统测试的策略有?
Metasploit-域名上线隐藏IP