差别
这里会显示出您选择的修订版和当前版本之间的差别。
| 后一修订版 | 前一修订版 | ||
| burp [2026/03/09 12:06] – 创建 张叶安 | burp [2026/03/09 13:57] (当前版本) – 张叶安 | ||
|---|---|---|---|
| 行 11: | 行 11: | ||
| {{pasted: | {{pasted: | ||
| + | 下载后备用 | ||
| jython运行环境https:// | jython运行环境https:// | ||
| 行 16: | 行 17: | ||
| {{pasted: | {{pasted: | ||
| - | + | 下载后备用 | |
| - | 下载三者后,安装Burp,安装jython并记住路径 | + | |
| 点击设置\插件\Python环境,设置jython安装路径 | 点击设置\插件\Python环境,设置jython安装路径 | ||
| + | |||
| + | {{pasted: | ||
| + | |||
| + | {{pasted: | ||
| 点击设置\插件\增加 ,安装python插件 | 点击设置\插件\增加 ,安装python插件 | ||
| + | |||
| + | {{pasted: | ||
| + | |||
| + | 谷歌浏览器安装 FoxyProxy 扩展 | ||
| + | |||
| + | {{pasted: | ||
| + | |||
| + | 点击 FoxyProxy 图标 → Options → Add | ||
| + | |||
| + | {{pasted: | ||
| + | |||
| + | - Title: Burp | ||
| + | - Type: HTTP | ||
| + | - Hostname: 127.0.0.1 | ||
| + | - Port: 8080 | ||
| + | |||
| + | {{pasted: | ||
| + | |||
| + | 保存后点击图标选择 " | ||
| + | |||
| + | {{pasted: | ||
| + | |||
| + | 安装 CA 证书(HTTPS 抓包必需) | ||
| + | |||
| + | 浏览器访问: | ||
| + | |||
| + | 点击 "CA Certificate" | ||
| + | |||
| + | {{pasted: | ||
| + | |||
| + | 浏览器导入证书: | ||
| + | |||
| + | Chrome: 设置 → 隐私和安全 → 安全 → 管理设备证书 → 导入 → 受信任的根证书颁发机构 | ||
| + | |||
| + | {{pasted: | ||
| + | |||
| + | {{pasted: | ||
| + | |||
| + | {{pasted: | ||
| + | |||
| + | {{pasted: | ||
| + | |||
| + | {{pasted: | ||
| + | |||
| + | 点击Dashboard\New live task,新建task | ||
| + | |||
| + | {{pasted: | ||
| + | |||
| + | 点击Target\Site map \open browser | ||
| + | |||
| + | {{pasted: | ||
| + | |||
| + | 打开测试网址 | ||
| + | |||
| + | {{pasted: | ||
| + | |||
| + | 打开view/ | ||
| + | |||
| + | {{pasted: | ||
| + | |||
| + | 打开intercept off | ||
| + | |||
| + | {{pasted: | ||
| + | |||
| + | 打开浏览器 输入网址 | ||
| + | |||
| + | {{pasted: | ||
| + | |||
| + | {{pasted: | ||
| + | |||
| + | 点击Forward控制浏览步骤前进 | ||
| + | |||
| + | {{pasted: | ||
| + | |||
| + | 操纵网页,一直点前进 | ||
| + | |||
| + | 点击http history | ||
| + | |||
| + | 可以看见浏览过程中的api调用情况 | ||
| + | |||
| + | 如目前这个网站的一些json配置是暴露在访问者权限上面的, | ||
| + | |||
| + | {{pasted: | ||
| + | |||
| + | |||
| + | 更多学习资料 | ||
| + | |||
| + | https:// | ||
| + | |||
| + | {{pasted: | ||
| + | |||
| + | |||
| + | https:// | ||
| + | |||
| + | https:// | ||
| + | |||
| + | https:// | ||
| + | |||