当前位置:网站首页>awd --waf deployment
awd --waf deployment
2022-07-30 06:38:00 【[email protected]】
Introduction: After completing the password change and downloading the source code, you can consider hanging your own waf, you can use the pass-through waf (please don't complain, the pass-through has been turned off, hahaha)
The role of waf:
1. The most important thing is to analyze the traffic. When others attack us, we can see how others attack.In this way, even if we can't find the attack point, when we are very distressed, we can analyze the traffic and use other people's attack methods.
2. It can be directly defended, similar to a firewall (general games are not allowed to use, after all, the game time is short, and it is impossible to bypass the waf at all, then the game is boring)
With waf link: https://github.com/leohearts/awd-watchbird
1. After packaging, upload it directly to the html directory
Go back to the terminal, in the uploaded waf directory, use the command
php watchbird.php --install /var/www/htmlIn this way, the php code of each page can be included under waf
2. After running waf, open our web page, enter ?watchbird=ui after any php page, you will enter to the waf configuration page and set the password (Note: You need to set a password when opening it for the first time)
3 Once configured, you can enter the internal web page
Here you can perform a series of operations!
版权声明
本文为[[email protected]]所创,转载请带上原文链接,感谢
https://yzsam.com/2022/211/202207300539173426.html
边栏推荐
猜你喜欢

【面经】米哈游数据开发面经
![[HCTF 2018]admin](/img/4e/58234ca163c22fc334334eb89a5b00.png)
[HCTF 2018]admin

【文献阅读】Age Progress/Regression by Conditional Adversarial Autoencoder 基于条件对抗自编码器(CAAE)的老化/去龄化方案

MongoDB快速入门与基本使用

DVWA installation tutorial (understand what you don't understand · in detail)
CTF之misc-文件隐写
![[PASECA2019]honey_shop](/img/8f/7161a63dab10dc02fef1fea075401a.png)
[PASECA2019]honey_shop
CTF之misc-内存分析(Volatility)
![[网鼎杯 2020 青龙组]AreUSerialz](/img/f2/9aef8b8317eff31af2979b3a45b54c.png)
[网鼎杯 2020 青龙组]AreUSerialz

jsonpath
随机推荐
【面经】米哈游数据开发面经
C#中对委托的理解和使用
【问题解决】在写CSDN博客时,如何对段落进行首行缩进?
复习 redux 总结
【数仓】数据质量
js 去除掉对象中的null,‘‘,[],{}
攻防世界easy_web
Detailed MySQL-Explain
连接云服务器Docker中的Mysql 详细图文操作(全)
Operators and Interaction Basics
SSTI range
C# WPF中监听窗口大小变化事件
uni-app:关于自定义组件、easycom规范、uni_modules等问题
使用PyQt5为YoloV5添加界面(一)
CTF之misc-文件隐写
js基础 判断数据类型
MongoDB快速入门与基本使用
phpok网站漏洞利用分析
node包的导入与导出
[Net Ding Cup 2020 Qinglong Group] AreUSerialz