当前位置:网站首页>(7) Web security | penetration testing | how does network security determine whether CND exists, and how to bypass CND to find the real IP
(7) Web security | penetration testing | how does network security determine whether CND exists, and how to bypass CND to find the real IP
2022-07-02 13:04:00 【Black zone (rise)】
CDN The full name is Content Delivery Network, The content distribution network .CDN It is an intelligent virtual network based on the existing network , Rely on edge servers deployed everywhere , Load balancing through the central platform 、 content distribution 、 Scheduling and other functional modules , Let users get the content they need nearby , Reduce network congestion , Improve user access response speed and hit rate .
The above comes from :CDN_ Baidu Encyclopedia (baidu.com)
Personally feel cdn In short : Through the nearby temporary storage of information CDN Node sends information to users
cdn Will hide the server's real ip Address , Unable to penetrate the operating system of the target website ,cdn The site is virtual , Have the same website architecture , And cdn The server can interact with the site server , therefore sql The mining of injection and other vulnerabilities is not greatly affected .
Through the tool ping, Look at the display ip Is the address unique , If it's not the only one , Then these ip The address is CDN The address of
Using tools :
IP/IPv6 Inquire about , Server address query - Webmaster Tools (chinaz.com)
( Take Baidu for example )

You can see it in many places ip Address , It can be determined that this is its CDN node
There is also a tool to check authenticity ip:

But you can't determine this with tools ip Is it true
If you are not at ease, you can also use manual search , Combined with practice , Analyze the location of the company and ip Continue to analyze the location
When some websites register , Will pass email authentication , Or send an email message , At this time, analyze the... In the email data ip Address , The first ip It was sent by Tencent as a transit
Subdomain query :
Because some main stations do CDN Service and the sub station didn't do CDN service
Subdomain excavator :
link :https://pan.baidu.com/s/1otbSIrRVIYotbB3VVeCSlw
Extraction code :hj12
Mail service query :
Most mailboxes are accessed by insiders , And the number of visits is generally not very large , So I don't usually do CDN.
Foreign address request :
CDN Generally, it is arranged nearby according to the user group
example : The users of a website are all in China , For economic reasons , Then the website administrator will not be deployed abroad CDN node , Visiting abroad may directly access the truth IP. Choose more unpopular countries to visit , If IP All the same , It's probably true ip.
( This will use related tools )
Legacy documents :
example :php Of phpinfo.php, You may see the truth IP
Scan the whole network :
May get all IP, And then analyze it
Dark engine search : May get google Specific search for
fofa、shodan、 To listen attentively 、zoomeye、censys
( We should conduct an artificial analysis by ourselves )
Specific documents dns Historical record :
The website may not have CDN, So through the search of the new website CDN Historical record , You may find what was resolved at that time IP, This IP It may be the reality of the current website IP.
Look at :
One CDN Node traffic, such as 1G, So many people visit , Run out of wandering , After that, it may be true IP 了 .( Also known as traffic exhaustion attack ).
real IP After obtaining the address, the binding points to the address change local HOSTS Parse point to file
边栏推荐
- JSON serialization and parsing
- spfa AcWing 852. spfa判断负环
- JS10day(api 阶段性完结,正则表达式简介,自定义属性,过滤敏感词案例,注册模块验证案例)
- Heap acwing 839 Simulated reactor
- Domestic free data warehouse ETL dispatching automation operation and maintenance expert taskctl
- Floyd AcWing 854. Floyd求最短路
- Hundreds of web page special effects can be used. Don't you come and have a look?
- Do you know all the interface test interview questions?
- 通过反射执行任意类的任意方法
- 哈希表 AcWing 841. 字符串哈希
猜你喜欢

js5day(事件监听,函数赋值给变量,回调函数,环境对象this,全选反选案例,tab栏案例)

Analog to digital converter (ADC) ade7913ariz is specially designed for three-phase energy metering applications

Js4day (DOM start: get DOM element content, modify element style, modify form element attributes, setinterval timer, carousel Map Case)

Js6day (search, add and delete DOM nodes. Instantiation time, timestamp, timestamp cases, redrawing and reflow)

架构师必须了解的 5 种最佳软件架构模式

Linear DP acwing 897 Longest common subsequence

3 A VTT端接 稳压器 NCP51200MNTXG资料

自主可控三维云CAD:CrownCAD赋能企业创新设计
![[opencv learning] [image filtering]](/img/4c/fe22e9cdf531873a04a7c4e266228d.jpg)
[opencv learning] [image filtering]

C#运算符
随机推荐
js4day(DOM开始:获取DOM元素内容,修改元素样式,修改表单元素属性,setInterval定时器,轮播图案例)
How to get the operating system running PHP- How to get the OS on which PHP is running?
Hash table acwing 841 String hash
Linear DP acwing 899 Edit distance
The coloring method determines the bipartite graph acwing 860 Chromatic judgement bipartite graph
JS6day(DOM结点的查找、增加、删除。实例化时间,时间戳,时间戳的案例,重绘和回流)
Interview questions for software testing - a collection of interview questions for large factories in 2022
Obtain file copyright information
基于STM32的OLED 屏幕驱动
Linear DP acwing 897 Longest common subsequence
Jerry's weather direction coding table [chapter]
West digital decided to raise the price of flash memory products immediately after the factory was polluted by materials
Redis transaction mechanism implementation process and principle, and use transaction mechanism to prevent inventory oversold
The UVM Primer——Chapter2: A Conventional Testbench for the TinyALU
染色法判定二分图 AcWing 860. 染色法判定二分图
spfa AcWing 852. spfa判断负环
moon
Ali was killed by two programming problems at the beginning, pushed inward again, and finally landed (he has taken an electronic offer)
JS7day(事件对象,事件流,事件捕获和冒泡,阻止事件流动,事件委托,学生信息表案例)
上手报告|今天聊聊腾讯目前在用的微服务架构