当前位置:网站首页>"WEB Security Penetration Testing" (28) Burp Collaborator-dnslog out-band technology
"WEB Security Penetration Testing" (28) Burp Collaborator-dnslog out-band technology
2022-08-05 00:20:00 【Stargazing at midnight】
1.What is Burp Collaborator
What is Burp Collaborator?It is a module that is carried by default in the new version of the penetration testing tool BurpSuite. It is a client. We can use BurpSuite to configure the outboard server for us. We can use the default carried by BurpSuite, or we can use our own private cloud server.
Having said so much, you may not understand what it is?
In fact, it is a DNSlog take-out tool. As long as you are doing network security, you should know http://dnslog.cn/ and http://www.ceye.io/ these two platforms, they are free DNSlog platforms, we can use them to monitor DNS resolution records and HTTP access records, which is very helpful for us to verify some vulnerabilities.
2.Burp Collaborator use
(1) Open BurpSuite, select "Project options" in the first step, "Misc" in the second step, and "Use the default Collaborator server" in the third step (use the default configured take-out server, if you want to use your ownThe server can be freely configured below), the fourth step is to click "Run health check.." to test whether the take-out server can work normally.

(2) Now go to start the client and select "Burp" under "Burp"
边栏推荐
猜你喜欢
![[CVA Valuation Training Camp] Financial Modeling Guide - Lecture 1](/img/8b/360df9a9094037dc358cb21c60cdc8.png)
[CVA Valuation Training Camp] Financial Modeling Guide - Lecture 1

找不到DiscoveryClient类型的Bean

仿网易云音乐小程序-uniapp

SQL association table update
![[LeetCode] Summary of Matrix Simulation Related Topics](/img/80/bd71ca5211cce5805909015a642893.jpg)
[LeetCode] Summary of Matrix Simulation Related Topics

2 用D435i运行VINS-fusion

测试经理要不要做测试执行?

Implementation principle of golang coroutine

leetcode:266. 回文全排列

How to automatically push my new articles to my fans (very simple, can't learn to hit me)
随机推荐
After another 3 days, I have sorted out 90 NumPy examples, and I can't help but bookmark it!
Will domestic websites use Hong Kong servers be blocked?
【无标题】
MVCC是什么
2022杭电多校第三场 K题 Taxi
2022牛客多校第三场 A Ancestor
软件测试面试题:黑盒测试、白盒测试以及单元测试、集成测试、系统测试、验收测试的区别与联系?
2022牛客多校训练第二场 L题 Link with Level Editor I
IDEA 文件编码修改
2 用D435i运行VINS-fusion
what?测试/开发程序员要被淘汰了?年龄40被砍到了32?一瞬间,有点缓不过神来......
倒计时1天!8月2日—4日与你聊聊开源与就业那些事!
【云原生--Kubernetes】调度约束
【Unity编译器扩展之进度条】
What is next-generation modeling (with learning materials)
The master teaches you the 3D real-time character production process, the game modeling process sharing
动态上传jar包热部署
Raw and scan of gorm
KT6368A Bluetooth certification problem_FCC and BQB_CE_KC certification or other instructions
僵尸进程和孤儿进程