当前位置:网站首页>菜刀,蚁剑,冰蝎,哥斯拉的流量特征
菜刀,蚁剑,冰蝎,哥斯拉的流量特征
2022-07-05 16:39:00 【qq_51550750】
蚁剑:
ini_set
ini_set_time
ini_set_limit
@ini_set(“display_errors”,“0”)
部分代码明文传输,较好辨认
菜刀:
老版本采用明文传输,非常好辨认
新版本采用base64加密,检测思路就是分析流量包,发现大量的base64加密密文就需要注意
冰蝎:
冰蝎1:冰蝎1有一个密钥协商过程,这个过程是明文传输,并且有两次流量,用来校验
冰蝎2:因为内置了很多的UA头,所以当某一个相同IP重复请求,但是UA头不一样的时候就需要注意了
冰蝎3:因为省去了协商过程,所以流量上可以绕过很多,但是其他特征依旧保留,比如ua头
冰蝎数据包总是伴随着大量的content-type:application什么什么,无论GET还是POST,请求的http中,content-type为application/octet-stream
还有他们的accept之类的长度总是等长,正常的根据应用场景和不同文件,长度是不同的
哥斯拉:
cookie这个值的地方有一个小纰漏,就是正常请求cookie最后结尾是没有分号的,可能后续作者会进行调整修改
还有响应,哥斯拉会响应三次,而且我认为还有一个地方需要注意的就是webshell连接,所以一般会设置长时间连接,所以connection这里会是keep-alive
边栏推荐
- The second day of learning C language for Asian people
- easyNmon使用汇总
- 【testlink】TestLink1.9.18常见问题解决方法
- Jarvis OJ 简单网管协议
- PHP talent recruitment system development source code recruitment website source code secondary development
- How can C TCP set heartbeat packets to be elegant?
- 阈值同态加密在隐私计算中的应用:解读
- Use byte stream to read Chinese from file to console display
- American chips are no longer proud, and Chinese chips have successfully won the first place in emerging fields
- Solution of vant tabbar blocking content
猜你喜欢
项目引入jar从私服Nexus 拉去遇到的一个问题
Embedded UC (UNIX System Advanced Programming) -2
The two ways of domestic chip industry chain go hand in hand. ASML really panicked and increased cooperation on a large scale
精准防疫有“利器”| 芯讯通助力数字哨兵护航复市
Android privacy sandbox developer preview 3: privacy, security and personalized experience
Jarvis OJ Webshell分析
7.Scala类
Machine learning compilation lesson 2: tensor program abstraction
激动人心!2022开放原子全球开源峰会报名火热开启!
干货!半监督预训练对话模型 SPACE
随机推荐
Embedded UC (UNIX System Advanced Programming) -1
张平安:加快云上数字创新,共建产业智慧生态
PHP strict mode
什么是ROM
Etcd 构建高可用Etcd集群
【剑指 Offer】66. 构建乘积数组
tf. sequence_ Mask function explanation case
Learnopongl notes (II) - Lighting
Use byte stream to read Chinese from file to console display
How does the outer disk futures platform distinguish formal security?
启牛商学院股票开户安全吗?靠谱吗?
C how TCP restricts the access traffic of a single client
Embedded-c language-6
Solve cmakelist find_ Package cannot find Qt5, ECM cannot be found
The first lesson of EasyX learning
【jmeter】jmeter脚本高级写法:接口自动化脚本内全部为变量,参数(参数可jenkins配置),函数等实现完整业务流测试
Get ready for the pre-season card game MotoGP ignition champions!
American chips are no longer proud, and Chinese chips have successfully won the first place in emerging fields
Jarvis OJ Webshell分析
If you can't afford a real cat, you can use code to suck cats -unity particles to draw cats