SRC---一些好用的bp插件、bp小技巧

1.代理小技巧

在渗透测试的时候难免会搜索一些东西,然后这些搜索的网站会影响我们对渗透目标的判断

这里我们可以在代理的时候过滤掉这些网址

switchyOmega

2.sqlmap4burp++

下载地址:https://github.com/c0ny1/sqlmap4burp-plus-plus
这个插件时非常丝滑的联动sqlmap,测试效果也不错
3.Hack Bar
下载地址:https://github.com/d3vilbug/HackBar
4.SSRF-King
https://github.com/ethicalhackingplayground/ssrf-king
支持扫描和自动发现SSRF漏洞
5.burp-sensive-param-extrator
下载地址:https://github.com/theLSA/burp-sensitive-param-extractor
检测敏感参数
6.Burp-unauth-checker
下载地址:https://github.com/theLSA/burp-unauth-checker
检测未授权
7.FastjsonScan
下载地址:https://github.com/zilong3033/fastjsonScan
8.BurpShiroPassiveScan
下载地址:https://github.com/pmiaowu/BurpShiroPassiveScan
⾃动检测Shiro+发现密钥,不依赖dnslog来检查。
9.403Bypasser
下载地址:https://github.com/sting8k/BurpSuite_403Bypasser
⽤各种姿势来绕过403访问
10.Shelling
https://github.com/ewilded/shelling
11.Reflector
下载地址:https://github.com/elkokc/reflector
通过设置Content-Type, 我们可以快速找到请求中的参数哪个被返回到回显的Body
12.BurpJSLinkFinder
下载地址:https://github.com/InitRoot/BurpJSLinkFinder
13.Unexpected information
下载地址:https://github.com/ScriptKid-Beta/Unexpected_information
⽤于⾼亮特征和定位敏感信息
14.JSON decoder
商店有,美化json
评论
成就一亿技术人!
拼手气红包6.0元
还能输入1000个字符
 
 条评论被折叠 查看
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值