当前位置:网站首页>Public testing, exclusive, penetration testing, picking up ragged tips
Public testing, exclusive, penetration testing, picking up ragged tips
2022-04-22 01:00:00 【Guapi Chen】
0x00 Preface
About public testing 、 How to pick up leaks in exclusive xss hole , hydrological , hydrological , hydrological !!!
0x01
Daily boring test site , When you're doing penetration testing , Found some html The tag calls the... Of the image in the server , And it's the kind to join the server ip Address of the , You can try to modify host Head fuzz once , Detect the presence of xss.


Seeing this situation, we can roughly guess , The latter part of the code may look like the following :
<img src="<?php echo "http://{$_SERVER['HTTP_HOST']}/"?>xxx/aaa.png" />
So it seems very simple , Modify the... In the request package host Can cause xss Slightly .

Successful pop-up


Pick up rags tips The end , Hydrology is good .
版权声明
本文为[Guapi Chen]所创,转载请带上原文链接,感谢
https://yzsam.com/2022/04/202204211645261612.html
边栏推荐
- hex,base64,urlencode编码方案对比
- 解决 idea web项目没有小蓝点的问题
- ApacheCon Asia 2022 演讲征集开始了!
- Build a personal blog (WordPress) on Alibaba cloud
- [langage C] opération de fichier d'analyse approfondie [niveau avancé examen spécial]
- redis持久化
- 24张图攻克border-image
- 序列化 及 transient关键字
- Redis has three modes - master-slave replication, sentinel mode and cluster
- MySQL进阶之表的增删改查
猜你喜欢
随机推荐
BI工具如何选型?这3个问题是关键!
Beauty salon management system based on SSM (with source code + project display)
Watch mechanism of redis
智能生活—给智能家居的设备定时有多方便?
From concept to realization, how does smart home come into our life step by step
Redis 的五种数据结构分析
Wu Jiesheng: today's application architecture is at an unpredictable stage
[pyGame game] the most classic alien game in history, which fully guarantees the courage to break through (Unsolved Mystery)
Material UI中JSS的写法(随手笔记)
Deep learning tips (1) -- why is residual connection of RESNET useful?
[opencv actual combat] beauty mode, open: is the beauty function so powerful? (demons dancing. JPG)
Cross chain bridge vulnerability summary
看看项目经理是如何把一个项目带崩的
MySQL进阶之常用函数
常用的注解
程序员怎么个人接单?
Introduction to microservices, euraka, ribbon, openfeign
MySQL基础合集
捷码有奖征文活动 | 低代码行业趣事等你分享
自动化测试框架有哪些优势?









