当前位置:网站首页>"WEB Security Penetration Testing" (28) Burp Collaborator-dnslog out-band technology
"WEB Security Penetration Testing" (28) Burp Collaborator-dnslog out-band technology
2022-08-05 00:20:00 【Stargazing at midnight】
1.What is Burp Collaborator
What is Burp Collaborator?It is a module that is carried by default in the new version of the penetration testing tool BurpSuite. It is a client. We can use BurpSuite to configure the outboard server for us. We can use the default carried by BurpSuite, or we can use our own private cloud server.
Having said so much, you may not understand what it is?
In fact, it is a DNSlog take-out tool. As long as you are doing network security, you should know http://dnslog.cn/ and http://www.ceye.io/ these two platforms, they are free DNSlog platforms, we can use them to monitor DNS resolution records and HTTP access records, which is very helpful for us to verify some vulnerabilities.
2.Burp Collaborator use
(1) Open BurpSuite, select "Project options" in the first step, "Misc" in the second step, and "Use the default Collaborator server" in the third step (use the default configured take-out server, if you want to use your ownThe server can be freely configured below), the fourth step is to click "Run health check.." to test whether the take-out server can work normally.

(2) Now go to start the client and select "Burp" under "Burp"
边栏推荐
- 软件测试面试题:手工测试与自动测试有哪些区别?
- 怎样进行在不改变主线程执行的时候,进行日志的记录
- After another 3 days, I have sorted out 90 NumPy examples, and I can't help but bookmark it!
- Flask框架 根据源码分析可扩展点
- 2022牛客多校训练第二场 J题 Link with Arithmetic Progression
- 10 个关于 Promise 和 setTimeout 知识的面试题,通过图解一次说透彻
- oracle创建用户以后的权限问题
- D - I Hate Non-integer Number (选数的计数dp
- LeetCode Hot 100
- 2022杭电多校第一场 1004 Ball
猜你喜欢

2022 Niu Ke Summer Multi-School Training Camp 5 (BCDFGHK)

oracle创建用户以后的权限问题

标识符、关键字、常量 和变量(C语言)

The master teaches you the 3D real-time character production process, the game modeling process sharing

2022杭电多校第三场 K题 Taxi

Cloud native - Kubernetes 】 【 scheduling constraints

【LeetCode】矩阵模拟相关题目汇总

jenkins send mail system configuration

First, the basic concept of reptiles

【Valentine's Day special effects】--Canvas realizes full screen love
随机推荐
.net (C#) get year month day between two dates
【idea】idea配置sql格式化
Huggingface入门篇 II (QA)
what?测试/开发程序员要被淘汰了?年龄40被砍到了32?一瞬间,有点缓不过神来......
could not build server_names_hash, you should increase server_names_hash_bucket_size: 32
图解 Canvas 入门
Mysql_13 事务
MAUI Blazor 权限经验分享 (定位,使用相机)
oracle创建用户
The applicable scenarios and common product types of the KT148A electronic voice chip ic solution
The master teaches you the 3D real-time character production process, the game modeling process sharing
2022杭电多校训练第三场 1009 Package Delivery
【LeetCode】图解 904. 水果成篮
Will domestic websites use Hong Kong servers be blocked?
ansible学习笔记分享-含剧本示例
2 用D435i运行VINS-fusion
[CVA Valuation Training Camp] Financial Modeling Guide - Lecture 1
MAUI Blazor 权限经验分享 (定位,使用相机)
QSunSync 七牛云文件同步工具,批量上传
软件测试面试题:您如何看待软件过程改进?在您曾经工作过的企业中,是否有一些需要改进的东西呢?您期望的理想的测试人员的工作环境是怎样的?