Remember a digging example

In a test of src,

 

A management system exists on other ports encountered by the master

 

 

 

 

 

Looking at the past, you can only try to log in.

 

 

 

 

 

In general, we can test for weak passwords, SQL injection, etc. But it doesn't exist here. After burp captures the packet, the response returns a 302 jump. Generally speaking, most people will not test it here.

 

But I always feel that there is a problem here, so I looked at the source code of the webpage.

 

 

Then this page goes directly to the background, tsk tsk

 

 

Guess you like

Origin http://43.154.161.224:23101/article/api/json?id=325461844&siteId=291194637