当前位置:网站首页>"WEB Security Penetration Testing" (28) Burp Collaborator-dnslog out-band technology
"WEB Security Penetration Testing" (28) Burp Collaborator-dnslog out-band technology
2022-08-05 00:20:00 【Stargazing at midnight】
1.What is Burp Collaborator
What is Burp Collaborator?It is a module that is carried by default in the new version of the penetration testing tool BurpSuite. It is a client. We can use BurpSuite to configure the outboard server for us. We can use the default carried by BurpSuite, or we can use our own private cloud server.
Having said so much, you may not understand what it is?
In fact, it is a DNSlog take-out tool. As long as you are doing network security, you should know http://dnslog.cn/ and http://www.ceye.io/ these two platforms, they are free DNSlog platforms, we can use them to monitor DNS resolution records and HTTP access records, which is very helpful for us to verify some vulnerabilities.
2.Burp Collaborator use
(1) Open BurpSuite, select "Project options" in the first step, "Misc" in the second step, and "Use the default Collaborator server" in the third step (use the default configured take-out server, if you want to use your ownThe server can be freely configured below), the fourth step is to click "Run health check.." to test whether the take-out server can work normally.

(2) Now go to start the client and select "Burp" under "Burp"
边栏推荐
猜你喜欢
随机推荐
克服项目管理中恐惧心理
Getting started with 3D modeling for games, what modeling software can I choose?
leetcode:267. 回文排列 II
软件测试面试题:手工测试与自动测试有哪些区别?
导入JankStats检测卡帧库遇到问题记录
How to automatically push my new articles to my fans (very simple, can't learn to hit me)
Flask框架 根据源码分析可扩展点
IDEA file encoding modification
What is next-generation modeling (with learning materials)
KT148A voice chip ic working principle and internal architecture description of the chip
Brainstorm: Complete Backpack
uinty lua 关于异步函数的终极思想
NMS原理及其代码实现
Some thoughts on writing
The master teaches you the 3D real-time character production process, the game modeling process sharing
【论文笔记】—低照度图像增强—Unsupervised—EnlightenGAN—2019-TIP
工业物联网 —— 新型数据库的召唤
About I double-checked and reviewed the About staff page, returning an industry question
E - Many Operations (按位考虑 + dp思想记录操作后的结果
软件测试面试题:软件测试类型都有哪些?




![[Cloud Native--Kubernetes] Pod Controller](/img/e1/1a8cc82223f9a9be79ebbf1211e9a4.png)




![情侣牵手[贪心 & 抽象]](/img/7d/1cafc000dc58f1c5e2e92150be7953.png)