当前位置:网站首页>Burpsuite爆破之token值替换
Burpsuite爆破之token值替换
2022-07-25 04:17:00 【平凡的学者】
准备工作
首先需要搭建一个实验环境,这个实验环境我们选用的是DVWA。相信很多小伙伴在渗透测试的时候都会遇到token值不同的情况,那么我们需要做的是使用burpsuite工具自动获取网站生成的token值并进行爆破
复现过程
首先我们先访问DVWA网站,查看源代码发现,只要每刷新一次页面,token的值都会改变

当我们尝试使用burpsuite直接抓包爆破后,发现全是302重定向,明显这是行不通的
那么我们需要在Project Option的Session上添加自动捕捉token的选项
运行一个宏
这里我们选择刚开始GET请求获取到的网页

然后编辑这个选项,添加自动获取那个值选项


这里选择要更新的字段
然后进入Scope选项,添加URL地址

然后回到暴力破解模块,设置变量值和加载字典,并选择总是follow redirection选项

可以看到密码为password,账号为admin的响应包长度明显不同的
查看响应包内容发现爆破成功
边栏推荐
- GBase 8a 关于No Suitable Driver 问题
- @Summary of ResponseBody annotation
- Open source summer interview | "after 00" PMC member Bai Zeping
- Debezium series: when there are a large number of DML operations in the record source database, the debezium consumption data time lags behind the data generation time by several hours
- Math. Random, switch selection structure
- RGB and SATA function switching module based on Quanzhi rk3568j
- @ResponseBody注解的总结
- Sony announced the closure of Beijing mobile phone factory! The production line will be moved to Thailand, and the cost can be reduced by half!
- Optimize bubble sorting
- Creativity: presentation of AI oil paintings with high imitation mineral pigments
猜你喜欢

Jenkins continues to integrate entry to mastery

MongoDB的安全认证详解

Unity3d learning note 9 - loading textures

Introduction to computing system hardware (common servers)

Has baozi ever played in the multi merchant system?

The application could not be installed: INSTALL_ FAILED_ USER_ RESTRICTED

暗黑王者|ZEGO 低照度图像增强技术解析

Grafana visual configuration diagram histogram

数据链路层协议 ——— 以太网协议

Simple understanding of RPC
随机推荐
看问题的角度
[cloud picture theory] 247 first introduction to Huawei cloud analysis service
Network engineering case: integrated network design of CII company
PCBA scheme design -- Bluetooth intelligent nutrition scale scheme
运筹学基础【一】 之 导论
Custom dialog (including header and footer)
The interviewer asked MySQL transactions, locks and mvcc at one go. I
Libenent and libev
Definition and basic terms of tree
JS absolute minimum value of the sum of Huawei od two numbers
Has baozi ever played in the multi merchant system?
Huawei | mlgoperf: ML boot inline for optimizing performance
Dig deep into data dividends, Intel and industry accelerate the implementation of digital economy
盐粒和冰粒分不清
2019 telecast retest test questions
Bubble mart's market value evaporated by HK $21billion in seven days, which can't be sold in China, and its future at sea is uncertain
To clarify the tax arrears: there is no tax arrears, and will continue to operate in compliance, rooted in China
Introduction to computing system hardware (common servers)
MySQL 中RDS 链接数突然上涨怎么查?
LVGL 8.2 Slider