{"id":192651,"date":"2020-11-14T02:28:13","date_gmt":"2020-11-13T18:28:13","guid":{"rendered":"http:\/\/4563.org\/?p=192651"},"modified":"2020-11-14T02:28:13","modified_gmt":"2020-11-13T18:28:13","slug":"%e6%b8%97%e9%80%8f%e6%b5%8b%e8%af%95%e5%b7%a5%e7%a8%8b%e5%b8%88%e6%b1%82%e8%81%8c%ef%bc%8c%e4%b8%8d%e9%99%90%e5%9c%b0%e5%9f%9f","status":"publish","type":"post","link":"http:\/\/4563.org\/?p=192651","title":{"rendered":"\u6e17\u900f\u6d4b\u8bd5\u5de5\u7a0b\u5e08\u6c42\u804c\uff0c\u4e0d\u9650\u5730\u57df"},"content":{"rendered":"<div>\n<div>\n<div>\n<h1>                  \u6e17\u900f\u6d4b\u8bd5\u5de5\u7a0b\u5e08\u6c42\u804c\uff0c\u4e0d\u9650\u5730\u57df               <\/h1>\n<p> <\/p>\n<div>\n<div> <span>\u8cc7\u6df1\u5927\u4f6c : lllllllllllllllj <\/span>  <span><i><\/i> 2<\/span> <\/div>\n<div> <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div isfirst=\"1\"> <\/p>\n<p>\u8f9e\u804c\u57f9\u8bad\u4e86 3 \u4e2a\u6708 web \u5b89\u5168<\/p>\n<p>\u6709\u4e00\u70b9\u56f0\u60d1\u60f3\u8bf7\u6559\u5404\u4f4d\u524d\u8f88<\/p>\n<p>\u6211\u662f\u4ece\u521d\u4e2d\u5f00\u59cb\u5c31\u662f\u4e2a\u811a\u672c\u5c0f\u5b50\uff0c\u5e94\u8be5 15 \u5e74\u5de6\u53f3\u4e60\u79d1\u3001\u6cd5\u514b\u8fd9\u4e9b\u8bba\u575b\u90fd\u5173\u95ed\u4e86\uff0c\u540e\u7eed\u518d\u6ca1\u4e86\u89e3\u8fd9\u65b9\u9762\u3002<\/p>\n<p>\u5e74\u521d\u5f00\u59cb\u5173\u6ce8 web \u5b89\u5168\u57f9\u8bad\uff0c8 \u6708\u4efd\u5de6\u53f3\u4e0b\u5b9a\u51b3\u5fc3\u8f9e\u804c\u8fc7\u6765\uff0c\u8fc7\u6765\u540e\u624d\u77e5\u9053\u6c42\u804c\u9700\u8981\u7b80\u5386\u9020\u5047\u3002\uff08\u4e4b\u524d\u6ca1\u4e86\u89e3\u8fc7 IT \u57f9\u8bad\u73ed\uff09<\/p>\n<p>\u4f46\u6211\u4e0d\u592a\u60f3\u9020\u5047\uff0c\u4e5f\u4e0d\u60f3\u53bb\u5916\u5305\u516c\u53f8\uff0c\u4f46\u56e0\u4e3a\u4e4b\u524d\u5de5\u4f5c\u7ecf\u9a8c\u8ddf\u7f51\u7edc\u5b89\u5168\u5b8c\u5168\u6ca1\u6709\u5173\u8054\uff0c\u53bb\u542f\u660e\u661f\u8fb0\u3001\u5929\u878d\u4fe1\u8fd9\u4e9b\u5b89\u5168\u5382\u5546\u4e0d\u77e5\u9053\u7b80\u5386\u80fd\u4e0d\u80fd\u8fc7\u521d\u7b5b\u3002<\/p>\n<p>V2 \u5e94\u8be5\u4e5f\u6709\u57f9\u8bad\u51fa\u6765\u7684\u670b\u53cb\uff0c\u8bf7\u6559\u4e0b\u5404\u4f4d\u57f9\u8bad\u7ed3\u675f\u627e\u5de5\u4f5c\u65f6\u7b80\u5386\u662f\u5982\u5b9e\u5199\u7684\u5417\uff1f<\/p>\n<p>\u76ee\u524d\u638c\u63e1\u7684\u4e00\u4e9b\u4e1c\u897f\uff0c\u4e5f\u8bf7\u5927\u4f6c\u4eec\u5e2e\u5fd9\u770b\u4e00\u4e0b\uff1a<\/p>\n<ul>\n<li>\n<p>\u4e86\u89e3 OWASP TOP 10 \u6f0f\u6d1e\u4ea7\u751f\u539f\u56e0\u53ca\u5404\u7c7b\u6f0f\u6d1e\u5bb9\u6613\u4ea7\u751f\u7684\u4f4d\u7f6e\uff1b<\/p>\n<\/li>\n<li>\n<p>\u6e17\u900f\u6d4b\u8bd5\u6b65\u9aa4\u3001\u65b9\u6cd5\u3001\u6d41\u7a0b\uff0c\u6e17\u900f\u6d4b\u8bd5\u62a5\u544a\u7f16\u5199\uff1b<\/p>\n<\/li>\n<li>\n<p>\u719f\u7ec3\u4f7f\u7528 BurpSuite \u3001Sqlmap \u3001nmap \u3001AWVS \u7b49\u8fdb\u884c\u6d4b\u8bd5\uff1b<\/p>\n<\/li>\n<li>\n<p>\u53ef\u4f7f\u7528 IIS \u3001Apache \u3001Nginx \u7b49\u4e2d\u95f4\u4ef6\u90e8\u7f72\u73af\u5883\uff0c\u590d\u73b0\u6f0f\u6d1e\uff1b<\/p>\n<\/li>\n<li>\n<p>PHP \u4ee3\u7801\u5ba1\u8ba1\u53ea\u4f1a\u4f7f\u7528 Fortify \uff1b<\/p>\n<\/li>\n<li>\n<p>\u80fd\u591f\u4f7f\u7528 python \u7f16\u5199\u7b80\u5355\u811a\u672c\u3001tamper \uff1b\uff08\u521a\u770b\u5b8c ms08067 \u7684 python \u5b89\u5168\u653b\u9632\uff09\uff1b<\/p>\n<\/li>\n<li>\n<p>\u5728\u672c\u5730\u9776\u573a\u4f7f\u7528\u8fc7 MSF \u3001CS \uff1b<\/p>\n<\/li>\n<\/ul><\/div>\n<div> <b>\u5927\u4f6c\u6709\u8a71\u8aaa<\/b> (<span>7<\/span>)        <\/div>\n<div> <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<ul>\n<li data-pid=\"4162955\" data-uid=\"2\">\n<div>\n<div>\n<div> <span>\u8cc7\u6df1\u5927\u4f6c : onice <\/span>  <\/div>\n<div> <i title=\"\u5f15\u7528\"><\/i>  <span>          <\/span> <\/div>\n<\/p><\/div>\n<div>                                                             \u5bf9\u81ea\u5df1\u8fd9\u4e48\u6ca1\u81ea\u4fe1\u561b\uff0c\u8fd8\u8981\u9020\u5047\u3002\u6211\u4e5f\u662f\u57f9\u8bad\u51fa\u6765\u7684\uff0c\u5c31\u6ca1\u9020\u5047\uff0c\u57f9\u8bad\u7ecf\u5386\u5199\u660e\u4e86\u57f9\u8bad\u673a\u6784\u3002\u4e00\u6837\u627e\u5230\u4e86\u5de5\u4f5c\uff0c\u8fd8\u662f\u7532\u65b9\u3002<br \/>\u8bdd\u8bf4\uff0c\u4f60\u5e94\u8058\u6e17\u900f\uff0c\u91cd\u8981\u7684\u662f\u9879\u76ee\u7ecf\u5386\u3002\u4f60\u8fde\u6316\u6d1e\u7684\u7ecf\u5386\u90fd\u6ca1\u6709\u5417\uff1f\u6211\u5f53\u65f6\u7b80\u5386\u4e0a\u6709\u4e09\u4e2a\u9879\u76ee\uff0c\u4e00\u4e2a\u9879\u76ee\u662f src \u6316\u7684\u6d1e\uff0c\u4e8c\u4e2a\u662f HW \u7684\u84dd\u961f\u7ecf\u5386\uff0c\u4e09\u4e2a\u662f\u81ea\u5df1\u7528\u79c1\u6709\u4e91\u8bbe\u8ba1\u5e76\u642d\u5efa\u7684\u4f01\u4e1a\u7ea7\u7eb5\u6df1\u9632\u5fa1\u4f53\u7cfb\u3002<br \/>\u5efa\u8bae\u4f60\u5148\u6316\u6d1e\uff0c\u6bcf\u79cd\u6f0f\u6d1e\u7c7b\u578b\u81f3\u5c11\u6316\u4e00\u4e2a\uff0c\u4f5c\u4e3a\u9879\u76ee\u4e00\u3002\u7136\u540e\u6253\u9776\u573a\uff0c\u628a\u9776\u573a\u7684\u6e17\u900f\u8fc7\u7a0b\u5199\u6210\u9879\u76ee\u4e8c\uff0c\u6e17\u900f\u8fc7\u7a0b\u8981\u6d89\u53ca\u5230 web \u6e17\u900f\u548c\u5185\u7f51\u6e17\u900f\uff0c\u4ee5\u53ca\u81ea\u5df1\u7684\u601d\u8def\u3002\u6700\u540e\u81ea\u5df1\u7528 python \u5199\u4e2a\u5b89\u5168\u5de5\u5177\uff0c\u4f5c\u4e3a\u9879\u76ee\u4e09\u3002<br \/>\u4e0d\u77e5\u9053\u4f60\u662f\u54ea\u4e2a\u57f9\u8bad\u73ed\uff0c\u5c31\u4e1a\u90fd\u6ca1\u4eba\u6307\u5bfc\u561b\uff1f                                                            <\/div>\n<\/p><\/div>\n<\/li>\n<li data-pid=\"4162956\" data-uid=\"2\">\n<div>\n<div>\n<div> <span>\u8cc7\u6df1\u5927\u4f6c : hjw45611 <\/span>  <\/div>\n<div> <i title=\"\u5f15\u7528\"><\/i>  <span>          <\/span> <\/div>\n<\/p><\/div>\n<div>                                                             \u4e0d\u57f9\u8bad\u54ea\u6765\u7684\u8fd9\u4e48\u591a\u7684\u6e17\u900f\u6d4b\u8bd5\uff1f\u53c2\u4e0e\u4e00\u4e9b\u6709\u540d\u5b89\u5168\u7f51\u7ad9\u7684 CTF \u6bd4\u8d5b\u3001\u8865\u5929\u4e4b\u7c7b\u7684 src                                                            <\/div>\n<\/p><\/div>\n<\/li>\n<li data-pid=\"4162957\" data-uid=\"2\">\n<div>\n<div>\n<div> <span>\u8cc7\u6df1\u5927\u4f6c : neituineitui <\/span>  <\/div>\n<div> <i title=\"\u5f15\u7528\"><\/i>  <span>          <\/span> <\/div>\n<\/p><\/div>\n<div>                                                             \u5b57\u8282\u8df3\u52a8\u8003\u8651\u5417<\/p>\n<p>\u5185\u63a8\u94fe\u63a5\uff1ajob.toutiao.com\/s\/JuwuUf1<\/p>\n<p>\u4e5f\u53ef\u4ee5\u8054\u7cfb wechat\uff1as n k 1 1 4 4 7 7<\/p>\n<p>\u54a8\u8be2\u4fe1\u606f                                                            <\/p><\/div>\n<\/p><\/div>\n<\/li>\n<li data-pid=\"4162958\" data-uid=\"2\">\n<div>\n<div>\n<div> <span>\u8cc7\u6df1\u5927\u4f6c : neituineitui <\/span>  <\/div>\n<div> <i title=\"\u5f15\u7528\"><\/i>  <span>          <\/span> <\/div>\n<\/p><\/div>\n<div>                                                             \u8fd9\u4e2a\u94fe\u63a5\u53ef\u4ee5\u76f4\u63a5\u6295\u9012\u7b80\u5386<br \/>job.bytedance.com\/referral\/pc\/position?keywords=%E6%B8%97%E9%80%8F%E6%B5%8B%E8%AF%95%E5%B7%A5%E7%A8%8B%E5%B8%88&amp;category=&amp;location=&amp;project=&amp;type=&amp;job_hot_flag=&amp;current=1&amp;limit=10&amp;token=MzsxNjA1MDg2MDIyMjkwOzY4MDE4Nzg2NTY5NjE3MjU5NjA7MA                                                            <\/div>\n<\/p><\/div>\n<\/li>\n<li data-pid=\"4162959\" data-uid=\"2\">\n<div>\n<div>\n<div> <span>\u4e3b<\/span> <span>\u8cc7\u6df1\u5927\u4f6c : lllllllllllllllj <\/span>  <\/div>\n<div> <i title=\"\u5f15\u7528\"><\/i>  <span>          <\/span> <\/div>\n<\/p><\/div>\n<div>                                                             @onice \u8fd8\u6ca1\u6709\u5c31\u4e1a\u6307\u5bfc\uff0c\u4f30\u8ba1\u4e5f\u662f\u6309\u9020\u5047\u6765\u7684\u3002\u6559\u80b2\u7f51 src \u4e00\u76f4\u5728\u6316\uff0c\u535a\u5ba2\u4e5f\u5199\u8fc7\u51e0\u7bc7\u6253\u9776\u573a\u7684\u6587\uff0c\u8c22\u8c22\u8001\u54e5\u6307\u5bfc\uff0c\u9879\u76ee\u5c31\u6309\u7167\u8fd9\u4e2a\u601d\u8def\u5199\u4e86\u54c8\u54c8                                                            <\/div>\n<\/p><\/div>\n<\/li>\n<li data-pid=\"4162960\" data-uid=\"2\">\n<div>\n<div>\n<div> <span>\u4e3b<\/span> <span>\u8cc7\u6df1\u5927\u4f6c : lllllllllllllllj <\/span>  <\/div>\n<div> <i title=\"\u5f15\u7528\"><\/i>  <span>          <\/span> <\/div>\n<\/p><\/div>\n<div>                                                             @hjw45611 \u786e\u5b9e\uff0c\u5927\u90e8\u5206\u90fd\u662f\u5954\u7740\u597d\u5c31\u4e1a\u6765\u7684\uff08\u53bb\u5916\u5305\uff09                                                            <\/div>\n<\/p><\/div>\n<\/li>\n<li data-pid=\"4162961\" data-uid=\"2\">\n<div>\n<div>\n<div> <span>\u8cc7\u6df1\u5927\u4f6c : wangkai0351 <\/span>  <\/div>\n<div> <i title=\"\u5f15\u7528\"><\/i>  <span>          <\/span> <\/div>\n<\/p><\/div>\n<div>                                                             \u5982\u679c\u4f60\u6709\u4e00\u4e2a\u4e13\u6ce8\u7684\u65b9\u5411\u641e\u4e0b\u53bb\uff0c\u5237\u51e0\u4e2a CVE\uff0c\u66f4\u5bb9\u6613\u627e\u5b89\u5168\u670d\u52a1\u7c7b\u5c97\u4f4d\u3002\u6211\u60f3\uff0c\u811a\u672c\u5c0f\u5b50\u7684\u5de5\u8d44\u548c\u4f1a\u5199 helloworld \u7a0b\u5e8f\u5458\u7684\u5de5\u8d44\u63a5\u8fd1\u3002                                                            <\/div>\n<\/p><\/div>\n<\/li>\n<li>\n","protected":false},"excerpt":{"rendered":"<p>\u6e17\u900f\u6d4b\u8bd5\u5de5\u7a0b\u5e08\u6c42\u804c\uff0c\u4e0d\u9650\u5730\u57df \u8cc7\u6df1&hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[],"tags":[],"_links":{"self":[{"href":"http:\/\/4563.org\/index.php?rest_route=\/wp\/v2\/posts\/192651"}],"collection":[{"href":"http:\/\/4563.org\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/4563.org\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/4563.org\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/4563.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=192651"}],"version-history":[{"count":0,"href":"http:\/\/4563.org\/index.php?rest_route=\/wp\/v2\/posts\/192651\/revisions"}],"wp:attachment":[{"href":"http:\/\/4563.org\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=192651"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/4563.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=192651"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/4563.org\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=192651"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}