当前位置:网站首页>(7) Web security | penetration testing | how does network security determine whether CND exists, and how to bypass CND to find the real IP
(7) Web security | penetration testing | how does network security determine whether CND exists, and how to bypass CND to find the real IP
2022-07-02 13:04:00 【Black zone (rise)】
CDN The full name is Content Delivery Network, The content distribution network .CDN It is an intelligent virtual network based on the existing network , Rely on edge servers deployed everywhere , Load balancing through the central platform 、 content distribution 、 Scheduling and other functional modules , Let users get the content they need nearby , Reduce network congestion , Improve user access response speed and hit rate .
The above comes from :CDN_ Baidu Encyclopedia (baidu.com)
Personally feel cdn In short : Through the nearby temporary storage of information CDN Node sends information to users
cdn Will hide the server's real ip Address , Unable to penetrate the operating system of the target website ,cdn The site is virtual , Have the same website architecture , And cdn The server can interact with the site server , therefore sql The mining of injection and other vulnerabilities is not greatly affected .
Through the tool ping, Look at the display ip Is the address unique , If it's not the only one , Then these ip The address is CDN The address of
Using tools :
IP/IPv6 Inquire about , Server address query - Webmaster Tools (chinaz.com)
( Take Baidu for example )
You can see it in many places ip Address , It can be determined that this is its CDN node
There is also a tool to check authenticity ip:
But you can't determine this with tools ip Is it true
If you are not at ease, you can also use manual search , Combined with practice , Analyze the location of the company and ip Continue to analyze the location
When some websites register , Will pass email authentication , Or send an email message , At this time, analyze the... In the email data ip Address , The first ip It was sent by Tencent as a transit
Subdomain query :
Because some main stations do CDN Service and the sub station didn't do CDN service
Subdomain excavator :
link :https://pan.baidu.com/s/1otbSIrRVIYotbB3VVeCSlw
Extraction code :hj12
Mail service query :
Most mailboxes are accessed by insiders , And the number of visits is generally not very large , So I don't usually do CDN.
Foreign address request :
CDN Generally, it is arranged nearby according to the user group
example : The users of a website are all in China , For economic reasons , Then the website administrator will not be deployed abroad CDN node , Visiting abroad may directly access the truth IP. Choose more unpopular countries to visit , If IP All the same , It's probably true ip.
( This will use related tools )
Legacy documents :
example :php Of phpinfo.php, You may see the truth IP
Scan the whole network :
May get all IP, And then analyze it
Dark engine search : May get google Specific search for
fofa、shodan、 To listen attentively 、zoomeye、censys
( We should conduct an artificial analysis by ourselves )
Specific documents dns Historical record :
The website may not have CDN, So through the search of the new website CDN Historical record , You may find what was resolved at that time IP, This IP It may be the reality of the current website IP.
Look at :
One CDN Node traffic, such as 1G, So many people visit , Run out of wandering , After that, it may be true IP 了 .( Also known as traffic exhaustion attack ).
real IP After obtaining the address, the binding points to the address change local HOSTS Parse point to file
边栏推荐
- Do you know all the interface test interview questions?
- JS iterator generator asynchronous code processing promise+ generator - > await/async
- How to get the operating system running PHP- How to get the OS on which PHP is running?
- 哈希表 AcWing 841. 字符串哈希
- 应用LNK306GN-TL 转换器、非隔离电源
- 通过反射执行任意类的任意方法
- 架构师必须了解的 5 种最佳软件架构模式
- Interview questions for software testing - a collection of interview questions for large factories in 2022
- spfa AcWing 852. SPFA judgement negative ring
- spfa AcWing 851. SPFA finding the shortest path
猜你喜欢
[200 opencv routines] 100 Adaptive local noise reduction filter
Modular commonjs es module
Ali on three sides, it's really difficult to successfully get the offer rated P7
Heap acwing 839 Simulated reactor
腾讯三面:进程写文件过程中,进程崩溃了,文件数据会丢吗?
Js8day (rolling event (scroll family), offset family, client family, carousel map case (to be done))
Js7day (event object, event flow, event capture and bubble, prevent event flow, event delegation, student information table cases)
[opencv learning] [moving object detection]
Rust search server, rust quick service finding tutorial
Does C language srand need to reseed? Should srand be placed in the loop? Pseudo random function Rand
随机推荐
Apply lnk306gn-tl converter, non isolated power supply
C#修饰符
Js8day (rolling event (scroll family), offset family, client family, carousel map case (to be done))
线性DP AcWing 898. 数字三角形
Counter attack of flour dregs: MySQL 66 questions, 20000 words + 50 pictures in detail! A little six
LTC3307AHV 符合EMI标准,降压转换器 QCA7005-AL33 PHY
模数转换器(ADC) ADE7913ARIZ 专为三相电能计量应用而设计
NTMFS4C05NT1G N-CH 30V 11.9A MOS管,PDF
Execute any method of any class through reflection
C modifier
Dijkstra AcWing 850. Dijkstra finding the shortest circuit II
Jerry's watch modifies the alarm clock [chapter]
基于STM32的OLED 屏幕驱动
The redis development document released by Alibaba covers all redis operations
Domestic free data warehouse ETL dispatching automation operation and maintenance expert taskctl
bellman-ford AcWing 853. 有边数限制的最短路
Interval DP acwing 282 Stone merging
国内首款、完全自主、基于云架构的三维CAD平台——CrownCAD(皇冠CAD)
Analog to digital converter (ADC) ade7913ariz is specially designed for three-phase energy metering applications
传感器 ADXL335BCPZ-RL7 3轴 加速度计 符合 RoHS/WEEE