当前位置:网站首页>Penetration test - get the system fofa keyword to brush the hole
Penetration test - get the system fofa keyword to brush the hole
2022-04-21 08:50:00 【amingMM】
How to get FOFA Syntax keywords
Sometimes a new loophole , Want to take poc To brush a wave , But I don't know how to use fofa Search for
H3C For example

The vulnerable page is like this , We found that we can't right-click to view the source code ( It's fine too F12),
So at this time, we can find keywords according to the characteristics existing on some pages .
according to url Search for keywords in :
For example, the picture above url in /imc/login.jsf,
This path may be the path unique to this product ,
We can directly copy and paste the path in fofa Mid search ( Not particularly accurate ):

Search according to website keywords :
fofa It is a website that supports search body Of , This shows that we can search according to some specific keywords on the website ,
For example, in the picture above iMC Guests access the self-service management system and product registration ,
These two keywords may be h3c Unique keywords , And the keyword is in html Of body label :

According to the relevant background or logo Search for :
Generally, such a system , some logo The files are stored in a specific path ,
We can find the path of this picture , Then search according to the specific image path :
Found that these two things are logo, and logo In general, the path of a specific system will not change ,
We can copy this path to fofa To search



Of course , There are many other ways to get some specific information about a system FOFA grammar .
For example, using ico hash etc.
版权声明
本文为[amingMM]所创,转载请带上原文链接,感谢
https://yzsam.com/2022/04/202204210831568848.html
边栏推荐
- Selection of WiFi module for data transmission through industrial control serial port of intelligent gateway of Internet of things
- PageRank-案例-机场
- LDO系列--PSRR
- L2-026 小字辈 (25 分)
- JS prototype and prototype chain
- 内网渗透-代理穿透-提权-注入-msf-中间件-域渗透-日志清除-学习资源
- Actual combat analysis of PC wechat robot personal number interface API wechat agrees with friend call
- 基于Ansible实现Apache Doris快速部署运维指南
- Simulated 100 questions and simulated examination of Shanghai safety officer C certificate examination in 2022
- 电网企标B接口接入记录(二):资源上报
猜你喜欢

2022年山东省安全员C证考试题及模拟考试

C language counting and sorting

Eight sorts (Part 1)

Alibaba Wen Shao came out again to reconstruct fastjson and launch fastjson 2

ZABBIX 5.4 server installation

2022年流动式起重机司机考试练习题模拟考试平台操作
![BUUCTF[HCTF 2018]WarmUp](/img/89/5d7d147dfb8e2bc10a2ff0bb68debe.png)
BUUCTF[HCTF 2018]WarmUp
![[GYCTF2020]Blacklist](/img/23/14236d426700925f2da86119b2e4f7.png)
[GYCTF2020]Blacklist

物联网智能网关工控串口数据透传WiFi模块的选型

【(强推)李宏毅2021/2022春机器学习课程】Unsupervised Learning - Linear Methods
随机推荐
Ten classic problems and solutions in SIP voice environment
苹果计划将儿童信息通信安全功能扩展到英国和加拿大
Flink's API introduction case
idea连接SqlServer报错
【Appium】使用模拟器实现有道云App的业务功能-新增、搜索、修改、删除
ue5 小知识点 动画蓝图接口 不能在editor中复制新的
Workerman给Timer定时器里的方法传参数
MySQL error of Navicat connection under Linux access denied for user 'root' @ 'xxx XXX. XXX. XXX‘ (USING PASSWORD: YES
互动多媒体应用所表现的特点
Common file types and content type of Apache Tika
LDO series -- PSRR
51 single chip microcomputer learning_ 1.1 turn on an LED
物联网智能网关工控串口数据透传WiFi模块的选型
Map Object WeakMap
卷积运算与互相关运算
C 100 points secret script sduwh
Kotlin's extended function knowledge points
初识UI自动化(inspect.exe + uiautomation)
7.4 并行卷积神经网络 GoogleNet
Latest system vulnerability -- omero Web cross site scripting vulnerability