当前位置:网站首页>Use csrftester to automatically detect CSRF vulnerabilities
Use csrftester to automatically detect CSRF vulnerabilities
2022-07-27 00:45:00 【Cwillchris】
CSRFTester Download address : link : https://pan.baidu.com/s/1YEFVmIeyR_kzV23kYIihzg Extraction code : bgq2
1、 The purpose of detection
The purpose of detection is : Probe web Whether the application has prevention CSRF The measures of . If Web Application's HTTP There is no corresponding precaution in the request , Then it is certain to exist to a large extent CSRF Loophole
2、 Introduction to automatic detection tools
Experimental environment :win7 In the virtual machine
Steps are as follows
- Set up browser proxy :127.0.0.1:8008
- Sign in Web Applications , Submit Form , stay CSRF Modify the form content in the tool , See if you want to change , If the change form exists CSRF Loophole .
- production POC Code .
(1) start-up CSRFTester
Need to install JDK8, This JDK8 Install on the front burpsuite Already installed . There's no need to install it here .

(2) Firefox browser settings proxy
边栏推荐
- 10个Web API
- 细说 call、apply 以及 bind 的区别和用法 20211031
- 【4.4 快速幂详解及快速幂求逆元】
- 程序员必做50题
- 并行MPI程序传递发送消息
- 【AtCoder Beginner Contest 261 (A·B·C·D)】
- The use of C language static can flexibly change the life cycle and make you write code like a duck to water
- Drawing warehouse-2 (function image)
- Web middleware log analysis script 1.0 (shell script)
- Viterbi Viterbi decoding bit error rate simulation, modulation is QPSK, channel is Gaussian white noise
猜你喜欢

Reduced dimension mean dot product matrix multiplicative norm probability normal distribution square loss
![[4.10 detailed explanation of game theory]](/img/df/690f9fb3adcb00317eb3438a76baaa.png)
[4.10 detailed explanation of game theory]

DOM day_03(7.11) 事件冒泡机制、事件委托、待办事项、阻止默认事件、鼠标坐标、页面滚动事件、创建DOM元素、DOM封装操作

5_线性回归(Linear Regression)

JSCORE day_01(6.30) RegExp 、 Function

10_ Evaluate classification

DOM day_01(7.7) dom的介绍和核心操作

The use of C language static can flexibly change the life cycle and make you write code like a duck to water

Drawing warehouse-2 (function image)

DOM day_ 03 (7.11) event bubbling mechanism, event delegation, to-do items, block default events, mouse coordinates, page scrolling events, create DOM elements, DOM encapsulation operations
随机推荐
裁剪tif影像
Search engine realizes keyword highlighting
【4.2 约数】
[qt] container class, iterator, foreach keyword
7_主成分分析法(Principal Component Analysis)
【AcWing第61场周赛】
我的第一篇博客-迷茫的大三人
[acwing game 61]
【3. Vim 操作】
Reduced dimension mean dot product matrix multiplicative norm probability normal distribution square loss
Vector size performance problems
Shufflenet series (2): explanation of shufflenet V2 theory
【AtCoder Beginner Contest 261 (A·B·C·D)】
关于Redis问题的二三事
Visual studio C cs0006 C failed to find metadata file
Lt9611ux Mipi to HDMI 2.0 dual port with audio
[PCB open source sharing] stc8a8k64d4 development board
Ubantu installing Oracle JDK
JSCORE day_02(7.1)
[qt] solve the problem of Chinese garbled code