Burp插件
burp用过的插件
BurpShiroPassiveScan-1.7.7
https://github.com/pmiaowu/BurpShiroPassiveScan/releases/tag/BurpShiroPassiveScan-1.7.7
简单使用,起一个shiro服务
J2EEScan
https://github.com/ilmila/J2EEScan/archive/refs/tags/v2.0.0.zip
idea打开
cd spring/CVE-2018-1273 |
抓包
WooYun-Payload
https://github.com/boy-hack/wooyun-payload/releases
Struts2-RCE
https://github.com/prakharathreya/Struts2-RCE
cd vulhub-master/struts2/s2-001 |
Fastjson-Scanner
https://github.com/zilong3033/fastjsonScan
cd /vulhub-master/fastjson/1.2.24-rce |
Autorize
先登录低权限的
拿低权限的cookie
打开认证开关
登录admin,这期间低权限的不要退出
在admin全都点一遍
Turbo Intruder
Software Vulnerability Scanner
Logger++ —— 更强大的请求历史查看器
burp 日志Logger++插件从原理到实践_J0hnson666的博客-CSDN博客_logger++
Brida —— 连接 frida 与 burpsuite
没看懂
sqlmap4burp++ —— 连接 burpsuite 与 sqlmap
https://github.com/c0ny1/sqlmap4burp-plus-plus/releases/tag/0.2
Knife —— 工具箱、自定义 payload
https://github.com/bit4woo/knife/releases 一般
CSRF Token Tracker —— 绕过CSRF限制进行暴力破解
设置安全级别为高
第一次
第二次
可以看到怎么重放都是200了
HAE
domain hunter
https://github.com/bit4woo/domain_hunter_pro/releases/tag/v1.7
CaA
https://github.com/gh0stkey/CaA/releases
JWT4B
APIKit
https://github.com/API-Security/APIKit/releases/tag/release
.\xray.exe webscan --listen 127.0.0.1:7777 --html-output ./results/proxy.html |
Passive Scan Client
https://github.com/c0ny1/passive-scan-client/releases/tag/0.3.0
reflector
https://github.com/elkokc/reflector/releases/tag/2.1
https://zhuanlan.zhihu.com/p/384779063
https://www.secpulse.com/archives/124527.html
jsonp cors跨域
https://github.com/p1g3/JSONP-Hunter
https://github.com/p1g3/CORS-SCAN