Review
- 2020/03/31
- 2023/08/05
- 2024/03/01
- 2024-09-29 06:45
[!Summary]
一、Introduction #
目标功能:
- 智能扫描器(自动生成XSS攻击载荷漏洞检测)
- 浏览器兼容测试
- 代码库漏洞检测
- 照片、文件检测
- 敏感词检测
漏洞简介:
- XSS漏洞(Cross site scripting)()
- SQL注入(SQL Injection)
- WebShell攻击
- 内网渗透
反射型XSS定义是:如果URL地址当中的恶意参数会直接被输出到页面中,导致攻击代码被触发,便称之为反射型XSS
存储型XSS,顾名思义便是恶意参数被存储起来了
漏洞扫描检测工具 #
- Retire.js 基于规则进行代码审计,故要经常根据最新漏洞来更新规则。
- burp https://portswigger.net/burp 付费
- OWASP_ZED https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project [FREE]
- https://github.com/zaproxy/zaproxy
- tensorflow.js toxicity model 检测暴力词汇(模型存储于Google,怎样能下载下来?)
- Burp/AWVS/Appscan
- SQLmap
- 后台扫描器(havij、御剑、burp)进行探测
- Arachni(Web Application Security Scanner Framework) https://github.com/Arachni/arachni
- Tsunami is a general purpose network security scanner with an extensible plugin system for detecting high severity vulnerabilities with high confidence. https://github.com/google/tsunami-security-scanner
- Scanners-Box(A powerful and open-source toolkit for hackers and security automation) https://github.com/We5ter/Scanners-Box
- dirsearch(Web path scanner) https://github.com/maurosoria/dirsearch