Examples of applications burp suite

1. bugku Question 8 - You have to stop it

Here Insert Picture Description
Title in constantly refreshed interface, with burp interception page
Here Insert Picture Description
intercepted packages are not the same as found, continue to click go up
Here Insert Picture Description

2. bugku question 12 - First Class

Here Insert Picture Description
Point into a look, had nothing
Here Insert Picture Description
to use burp suite Ethereal
Here Insert Picture Description
Here Insert Picture Description

3. bugku 13 questions - website was hacked

What can not enter the operating interface
Here Insert Picture Description
using the Sword scan to see if there is no php
Here Insert Picture Description
Here Insert Picture Description
enter a password needed something
Here Insert Picture Description
opens burp blasting password, just lose a password, its capture
Here Insert Picture Description
selected password dictionary, and click start attack

in this case the dictionary contents started blasting password, and returns the length found when other inconsistencies password which
Here Insert Picture Description
the password flag to give
Here Insert Picture Description

4. bugku Question 14 - System Administrator

Casually enter a username and password prompts to disable ip
Here Insert Picture Description
finally found a base64 encoded in the source code, the decoding of test123, to give the password
Here Insert Picture Description
to enter a user name and password test123 admin, open blasting burp, and forged ----- local ip X-Forwarded- -For: 127.0.0.1
Here Insert Picture Description
Here Insert Picture Description

5. bugku 17th title - Enter the password to view flag

Here Insert Picture Description
Here Insert Picture Description
Decisive burp brute force
Here Insert Picture Description
because the number of 5-digit numeric password, type the election Numbers, tested from 10000-99999 ...
Here Insert Picture Description
experienced a 1.8 billion times the test is completed, a long time, found inconsistent returns the length of the password number is
Here Insert Picture Description
Here Insert Picture Description

Released nine original articles · won praise 0 · Views 120

Guess you like

Origin blog.csdn.net/weixin_46176911/article/details/104118635