声明!
学习视频来自B站up主 泷羽sec 有兴趣的师傅可以关注一下,如涉及侵权马上删除文章,笔记只是方便各位师傅的学习和探讨,文章所提到的网站以及内容,只做学习交流,其他均与本人以及泷羽sec团队无关,切勿触碰法律底线,否则后果自负!!!!
工具:
通过网盘分享的文件:Burpsuite
链接: https://pan.baidu.com/s/1YWTg0WTl7G-2MQNMuSCuhw 提取码: jay1
准备
1. burpsuite安装captcha
打开软件,打开扩展,然后点击add(添加)
data:image/s3,"s3://crabby-images/57f10/57f101ee25a202c7ed52503716e28bab0117bc25" alt=""
将下载的文件导入进去
data:image/s3,"s3://crabby-images/78f29/78f29948f1ba4c7e60fa6d6e7c6a37f0352eec7c" alt=""
成功导入
2. 安装python必备模块
执行下面两个命令
pip install ddddocr
pip install aiohttp
具体操作
1. 包设置
以pikachu平台为例
data:image/s3,"s3://crabby-images/f4b3b/f4b3bf7ee879f3c4474fba4038f32075352d49e1" alt=""
打开代理,在验证码上右键打开新标签页并抓包
data:image/s3,"s3://crabby-images/10dd6/10dd6bd538e403a7555b76212dde1dd42ef32bc7" alt=""
鼠标右键
data:image/s3,"s3://crabby-images/66468/664682e1bf9da07c2ab18eee12956d7a09a5a377" alt=""
点击获取按钮
data:image/s3,"s3://crabby-images/c1dc2/c1dc2b6759ea81bd07ff5664da3025da46524d2b" alt=""
2. bp设置
打开命令面板,进入放插件的文件夹,输入
python codereg.py
开启监听
data:image/s3,"s3://crabby-images/75930/75930517f692be230c08f164bee3428d6a36d06f" alt=""
输入接口url
data:image/s3,"s3://crabby-images/8eea3/8eea36c40779ff98caf592f97c24a5b14f6e9a19" alt=""
然后右键选择ddddocr
data:image/s3,"s3://crabby-images/24377/2437704a4230d974dbc5d0336fb852ba618afc69" alt=""
再次点击识别即可,效果如下
data:image/s3,"s3://crabby-images/30d22/30d2287c416f8883026f009ccd8fa7c343386e0e" alt=""
3. 爆破
登录面板输入并抓包
data:image/s3,"s3://crabby-images/a2b5a/a2b5abb7e199e53986b8a5e20d7ccd67f00d539d" alt=""
发送到爆破模块,添加变量
data:image/s3,"s3://crabby-images/bb545/bb5459889c15b7f48b5c682f9c69e33988b4341a" alt=""
选择交叉模式
data:image/s3,"s3://crabby-images/32833/32833c9f92d383026b059701c249fb3833ad5d9d" alt=""
验证码变量选择这个类型
data:image/s3,"s3://crabby-images/75811/7581123cf7db7ace03a79647c5546bf4a3cf6ed8" alt=""
选择生成器
data:image/s3,"s3://crabby-images/55fb6/55fb699ee0b3a63f5d89b926db123b5751dbb18d" alt=""
启用插件
data:image/s3,"s3://crabby-images/03727/03727eb51e73a9ee8576892ddab0b84df8409e17" alt=""
资源池设置,如下设置
data:image/s3,"s3://crabby-images/eaf22/eaf220f0e35150bb47a2de3ef7082a45c81d9ecb" alt=""
然后开始攻击查看响应包即可