当前位置:网站首页>Goby+AWVS 实现攻击面检测
Goby+AWVS 实现攻击面检测
2022-06-24 15:46:00 【Bypass】
针对不断扩大的攻击面,需要企业从攻击者的视角出发,从外部探测企业的网络资产,并对Web 站点进行深入扫描,及时发现并处理高危风险,进而能够有效收敛攻击面。
通过一些工具自动化检测攻击面,在一定程度上可以提升安全人员的工作效率,本文分享的是Goby+AWVS 实现攻击面检测,下面一起来学习一下吧。
使用场景:企业资产探测、web漏洞扫描、团队协作等。
01、Goby服务器部署
将Goby部署到服务器运行,就可以实现无限扫描,任何成员只需要接入服务器就可以共享资产,有利于团队协助。
(1)下载Goby,解压缩
wget https://gobies.org/goby-linux-x64-1.9.325.zip
unzip goby-linux-x64-1.9.325.zip(2)后台运行,输出到指定日志文件
#创建.sh并写入命令
/home/admin/goby-linux/golib/goby-cmd-linux -apiauth user:pass -mode api -bind 0.0.0.0:8361
#实现屏幕输出记录到日志文件
nohup sh goby.sh > info.log &(3)本地Goby客户端,服务器管理→增加,填写远端服务器信息。
02、联动AWVS漏洞扫描
(1)Goby扩展程序,下载AWVS插件。
(2)在Goby,设置→扩展设置,填写AWVS的API Key及地址。
AWVS的API Key获取位置如下:
(3)在Goby的Web检测里,看到扫描出来的资产,可以直接点击AWVS的按钮,就可以开启扫描任务。
(4)在AWVS控制台,可以看到Goby下发的扫描任务,并且已完成扫描任务。
(5)回到Goby客户端,可以看到漏洞扫描结果,可导出漏洞报告。
边栏推荐
- A new weapon to break the memory wall has become a "hot search" in the industry! Persistent memory enables workers to play with massive data + high-dimensional models
- Rush for IPO, Hello, I'm in a hurry
- Flink kubernetes application deployment
- "Industry foresight" future development trend of intelligent security monitoring industry
- 如何在Thymeleaf3标签中使用嵌套标签
- Why is it easy for enterprises to fail in implementing WMS warehouse management system
- 60 divine vs Code plug-ins!!
- 【Prometheus】5. Alertmanager alarm (incomplete)
- leetcode 139. Word Break 單詞拆分(中等)
- [interview high frequency questions] sequential DP questions with difficulty of 3/5 and direct construction
猜你喜欢

How to expand disk space on AWS host

国产芯片的赶超,让美国手机芯片龙头高通害怕了,出招应对竞争

Most common usage of vim editor
![clang: warning: argument unused during compilation: ‘-no-pie‘ [-Wunused-command-line-argument]](/img/f0/42f394dbc989d381387c7b953d2a39.jpg)
clang: warning: argument unused during compilation: ‘-no-pie‘ [-Wunused-command-line-argument]

存在安全隐患 路虎召回部分混动揽运

微信公众号调试与Natapp环境搭建

How to easily realize online karaoke room and sing "mountain sea" with Wang Xinling

Wechat official account debugging and natapp environment building

如何扩展aws主机上的磁盘空间
![[cloud native | kubernetes chapter] Introduction to kubernetes Foundation (III)](/img/21/503ed54a2fa14fbfd67f75a55ec286.png)
[cloud native | kubernetes chapter] Introduction to kubernetes Foundation (III)
随机推荐
Some experiences of K project: global template highlights
Cap: multiple attention mechanism, interesting fine-grained classification scheme | AAAI 2021
Siggraph 2022 | truly restore the hand muscles. This time, the digital human hands have bones, muscles and skin
一文详解JackSon配置信息
New de debugging
Linux record -4.22 MySQL 5.37 installation (supplementary)
60 divine vs Code plug-ins!!
One article explains Jackson configuration information in detail
One article explains Jackson configuration information in detail
Istio practical tips: Customize Max_ body_ size
个人常用的高效工具
April 26, 2021: the length of the integer array arr is n (3 < = n < = 10^4), and each number is
Using alicloud RDS for SQL Server Performance insight to optimize database load - first understanding of performance insight
[C language questions -- leetcode 12 questions] take you off and fly into the garbage
Three solutions for Jenkins image failing to update plug-in Center
Jenkins 镜像无法更新插件中心的3种解决方法
Logging is not as simple as you think
Remain true to our original aspiration
Wi-Fi 7 来啦,它到底有多强?
我与“Apifox”的网络情缘