Welcome to my Github page! I am kN6jq!
- Java
- Golang
一款burp插件,请看简介
B站:视频教程呢?
public class DbUtils
中的写法,会判定.gather目录是不是判定。如果目录不存在,就会创造数据库失败。
要修改create()
请问下师傅 插件中的模块都是被动流量检测的嘛
sql模块发送普通的post数据包就会一个一个参数的去打payload,碰到json数据包,就直接所有参数都一次性打上去了。碰到某些参数又会跳过不测试例如 regiongrade ,mouduleTYpe
尝试使用了一下fastjson回显模块,只看到有spring的回显payload,辛苦大佬有空添加一下其他方式的回显
现有功能进过配置都能达到,但是最好预集成进初始配置中,增加开包即用,且个人配置不会随着未来版本迭代重新配置
(就是懒
用的release里的gatherBurp-gatherBurp-1.0.7-SNAPSHOT-jar-with-dependencies
Routescan初始配置只有xxl-job的poc。
【建议】
能带带嘛师傅,java不知道怎么学了
burpsuite 版本 2023.9.1
gatherBurp update 20230821
在 Proxy 选中请求右键选择 PermBypass Check ,然后切换到插件页面,看不到任何请求。
[SQLITE_ERROR] SQL error or missing database (no such table: route)
1、重复的url似乎会重复进行扫描
2、sql注入模块,如果出现报错的话,可以增加一个提示,就不用每个url都点进去看,像xia_sql那个插件那样
sql注入有时候注入点在URL中,如 /api/XXX(注入点)/XXX/?xxx=xxx,能否参考sqlmap的做法,让用户在疑似注入点的位置加个*号标记
A declarative, efficient, and flexible JavaScript library for building user interfaces.
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
An Open Source Machine Learning Framework for Everyone
The Web framework for perfectionists with deadlines.
A PHP framework for web artisans
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
Some thing interesting about web. New door for the world.
A server is a program made to process requests and deliver data to clients.
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
Some thing interesting about visualization, use data art
Some thing interesting about game, make everyone happy.
We are working to build community through open source technology. NB: members must have two-factor auth.
Open source projects and samples from Microsoft.
Google ❤️ Open Source for everyone.
Alibaba Open Source for everyone
Data-Driven Documents codes.
China tencent open source team.