当前位置:网站首页>(4) Web security | penetration testing | network security web site source code and related analysis
(4) Web security | penetration testing | network security web site source code and related analysis
2022-07-06 07:07:00 【Black zone (rise)】
as everyone knows :
web Source code is a very important source of information in security testing , It can be used for code audit vulnerabilities and information breakthrough , among WEB There are many technologies in the source code that need concise analysis .
eg: obtain ASP The source code can be downloaded from the default database , To obtain the source code vulnerability of some other script, you can conduct code audit, mine or analyze its business logic, etc , Therefore, the acquisition of source code will provide more ideas for later security testing
Web Source directory structure
Database configuration file , Background Directory , The template directory , Database directory, etc
admin---------------------------------- Website background Directory
data------------------------------------ Database related directories
install---------------------------------- The installation directory
member------------------------------- Membership directory
template------------------------------ The template directory ( Build an overall architecture related to the website )
data(confing.php)-------------- Database configuration file , Communication information of website and database , Connection account password , You can connect to each other's database , From the database to get the source code of this website, which involves the administrator's account and password .
You can see how to open a source code of Baidu online , Some small ones may only have some directories
Web Source script type
ASP,PHP,ASPX,JSP,JAVAWEB And other script type source code security issues
Check the type of website through the file directory
About Web Source application classification
Portal site --------------------------- comprehensive
Online retailers --------------------------------- Business logic
Forum ---------------------------------XSS
Blog --------------------------------- Less
The third party ------------------------------ Look at its function
Access to source code : Search for , Free fish Taobao , Third party source station , Corresponding to various industries .
Open source : You can search the vulnerability related articles on the Internet .
Inside : Routine penetration tests , Use scanning tools to judge .
If you can't get the source code, you can find the same type of source code analysis
Identify the cms, Here's a asp Script written website
The bottom display technical support is GOOMAY company-developed ,
Then I want to find out if he is using cms Developed , Developed by ourselves
Add /robots.txt See if you can see
The result is the login page
Now I'm going to try this one that provides technical support , It is developed by ourselves , still cms Developed
① If we analyze the used cms edition , You can find the vulnerability of the corresponding version of Baidu online
② If the website has been patched , Then consider scanning tools and related source code for analysis
③ If they developed it bit by bit , No source code , It's time to scan bit by bit
边栏推荐
猜你喜欢
18.多级页表与快表
首发织梦百度推送插件全自动收录优化seo收录模块
医疗软件检测机构怎么找,一航软件测评是专家
NFT on fingertips | evaluate ambire on G2, and have the opportunity to obtain limited edition collections
LeetCode 78:子集
leetcode35. 搜索插入位置(简单,找插入位置,不同写法)
Do you really know the use of idea?
开源的网易云音乐API项目都是怎么实现的?
Visitor tweets about how you can layout the metauniverse
leetcode704. 二分查找(查找某个元素,简单,不同写法)
随机推荐
GET 和 POST 请求类型的区别
微信公众号无限回调授权系统源码 全网首发
Windows Server 2016 standard installing Oracle
首发织梦百度推送插件全自动收录优化seo收录模块
LeetCode Algorithm 2181. 合并零之间的节点
Due to high network costs, arbitrum Odyssey activities are suspended, and nitro release is imminent
The first Baidu push plug-in of dream weaving fully automatic collection Optimization SEO collection module
【Hot100】739. Daily temperature
Fast target recognition based on pytorch and fast RCNN
Pymongo gets a list of data
Zhongqing reading news
《从0到1:CTFer成长之路》书籍配套题目(周更)
kubernetes集群搭建Zabbix监控平台
攻防世界 MISC中reverseMe简述
Three methods of adding color to latex text
leetcode59. 螺旋矩阵 II(中等)
编译,连接 -- 笔记 -2
Raspberry pie 3B update VIM
The author is dead? AI is conquering mankind with art
Setting and using richview trvstyle template style