﻿{"id":496,"date":"2020-08-12T04:40:45","date_gmt":"2020-08-11T20:40:45","guid":{"rendered":"https:\/\/byy3.com\/?p=496"},"modified":"2020-08-12T04:40:45","modified_gmt":"2020-08-11T20:40:45","slug":"tryhackme-rp%ef%bc%9aburp-suite","status":"publish","type":"post","link":"https:\/\/byy3.com\/?p=496","title":{"rendered":"tryhackme&#8211;RP\uff1aBurp Suite"},"content":{"rendered":"<section class=\"ft fu fv fw fx\">\n<div class=\"n p\">\n<div class=\"z ab ac ae af fy ah ai\">\n<div>\n<h1 id=\"2c6f\" class=\"fz ga bi gb b gc gd ge gf gg gh gi gj gk gl gm gn go gp gq gr cs\"><span>tryhackme\uff0cRP\uff1aBurp Suite<\/span><\/h1>\n<div class=\"gs\">\n<div class=\"n es gt gu gv\">\n<div class=\"o n\">\n<div><a href=\"https:\/\/byy3.com\/go\/?url=https:\/\/medium.com\/@rowls.cyber?source=post_page-----4b68de1c69e5----------------------\" rel=\"noopener\" rel=\"nofollow\" ><img loading=\"lazy\" decoding=\"async\" class=\"r dl gw gx\" data-original=\"https:\/\/miro.medium.com\/fit\/c\/96\/96\/1*RnE_FLi27bpe5RBohhM9oQ.jpeg\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" width=\"48\" height=\"48\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe\" \/><\/a><\/div>\n<div class=\"gy ai r\">\n<div class=\"n\">\n<div><\/div>\n<\/div>\n<div><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<figure class=\"ig ih ii ij ik il fn fo paragraph-image\">\n<div class=\"im in cc io ai\">\n<div class=\"fn fo if\">\n<div class=\"is r cc fb\">\n<div class=\"it iu r\">\n<div class=\"cb ip s t u ds ai bu iq ir\"><img loading=\"lazy\" decoding=\"async\" class=\"s t u ds ai iv iw ap uu\" data-original=\"https:\/\/miro.medium.com\/max\/60\/0*6CIpzVFqciXtu66J.png?q=20\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" width=\"800\" height=\"180\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe1\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe1\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"eg ul s t u ds ai c\" data-original=\"https:\/\/miro.medium.com\/max\/1000\/0*6CIpzVFqciXtu66J.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" sizes=\"auto, 700px\" srcset=\"https:\/\/miro.medium.com\/max\/345\/0*6CIpzVFqciXtu66J.png 276w, https:\/\/miro.medium.com\/max\/690\/0*6CIpzVFqciXtu66J.png 552w, https:\/\/miro.medium.com\/max\/800\/0*6CIpzVFqciXtu66J.png 640w, https:\/\/miro.medium.com\/max\/875\/0*6CIpzVFqciXtu66J.png 700w\" width=\"800\" height=\"180\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe2\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe2\" \/><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/figure>\n<\/div>\n<\/div>\n<\/section>\n<hr class=\"iy hb iz ja bx jb jc jd je jf jg jh\" \/>\n<section class=\"ft fu fv fw fx\">\n<div class=\"n p\">\n<div class=\"z ab ac ae af fy ah ai\">\n<h1 id=\"fef4\" class=\"ji jj bi bh et jk jl jm jn jo jp jq jr js jt ju jv jw jx jy jz cs\" data-selectable-paragraph=\"\"><span>\u76ee\u5f55<\/span><\/h1>\n<ol class=\"\">\n<li id=\"4a84\" class=\"ka kb bi kc b kd ke kf kg kh ki kj kk kl km kn ko kp kq kr ks kt ku kv kw kx ky kz la cs\" data-selectable-paragraph=\"\"><span>\u5148\u51b3\u6761\u4ef6<\/span><\/li>\n<li id=\"0262\" class=\"ka kb bi kc b kd lf kf kg kh lg kj kk kl lh kn ko kp li kr ks kt lj kv kw kx ky kz la cs\" data-selectable-paragraph=\"\"><span>\u4ecb\u7ecd<\/span><\/li>\n<li id=\"10d5\" class=\"ka kb bi kc b kd lf kf kg kh lg kj kk kl lh kn ko kp li kr ks kt lj kv kw kx ky kz la cs\" data-selectable-paragraph=\"\"><span>\u5b89\u88c5<\/span><\/li>\n<li id=\"5343\" class=\"ka kb bi kc b kd lf kf kg kh lg kj kk kl lh kn ko kp li kr ks kt lj kv kw kx ky kz la cs\" data-selectable-paragraph=\"\"><span>Gettin'[CA]\u8ba4\u8bc1<\/span><\/li>\n<li id=\"38ff\" class=\"ka kb bi kc b kd lf kf kg kh lg kj kk kl lh kn ko kp li kr ks kt lj kv kw kx ky kz la cs\" data-selectable-paragraph=\"\"><span>\u529f\u80fd\u6982\u8ff0<\/span><\/li>\n<li id=\"e900\" class=\"ka kb bi kc b kd lf kf kg kh lg kj kk kl lh kn ko kp li kr ks kt lj kv kw kx ky kz la cs\" data-selectable-paragraph=\"\"><span>\u53c2\u4e0e\u9ed1\u6697\u6a21\u5f0f<\/span><\/li>\n<li id=\"8f7b\" class=\"ka kb bi kc b kd lf kf kg kh lg kj kk kl lh kn ko kp li kr ks kt lj kv kw kx ky kz la cs\" data-selectable-paragraph=\"\"><span>\u4ee3\u7406<\/span><\/li>\n<li id=\"14ec\" class=\"ka kb bi kc b kd lf kf kg kh lg kj kk kl lh kn ko kp li kr ks kt lj kv kw kx ky kz la cs\" data-selectable-paragraph=\"\"><span>\u76ee\u6807\u5b9a\u4e49<\/span><\/li>\n<li id=\"6d3f\" class=\"ka kb bi kc b kd lf kf kg kh lg kj kk kl lh kn ko kp li kr ks kt lj kv kw kx ky kz la cs\" data-selectable-paragraph=\"\"><span>\u5c06\u6240\u6709\u5185\u5bb9\u91cd\u590d\u653e\u7f6e[er]<\/span><\/li>\n<li id=\"db40\" class=\"ka kb bi kc b kd lf kf kg kh lg kj kk kl lh kn ko kp li kr ks kt lj kv kw kx ky kz la cs\" data-selectable-paragraph=\"\"><span>\u6551\u547d\uff01\u6709\u4e00\u4e2a\u5165\u4fb5\u8005\uff01<\/span><\/li>\n<li id=\"e657\" class=\"ka kb bi kc b kd lf kf kg kh lg kj kk kl lh kn ko kp li kr ks kt lj kv kw kx ky kz la cs\" data-selectable-paragraph=\"\"><span>\u4e8b\u5b9e\u8bc1\u660e\uff0c\u8fd9\u4e9b\u673a\u5668\u6bd4\u6211\u4eec\u7684\u6570\u5b66\u80fd\u529b\u66f4\u597d\u3002<\/span><\/li>\n<li id=\"7b75\" class=\"ka kb bi kc b kd lf kf kg kh lg kj kk kl lh kn ko kp li kr ks kt lj kv kw kx ky kz la cs\" data-selectable-paragraph=\"\"><span>\u89e3\u7801\u5668\u548c\u6bd4\u8f83\u5668<\/span><\/li>\n<li id=\"df9e\" class=\"ka kb bi kc b kd lf kf kg kh lg kj kk kl lh kn ko kp li kr ks kt lj kv kw kx ky kz la cs\" data-selectable-paragraph=\"\"><span>\u5b89\u88c5\u4e00\u4e9bMod [Extender]<\/span><\/li>\n<li id=\"ce4d\" class=\"ka kb bi kc b kd lf kf kg kh lg kj kk kl lh kn ko kp li kr ks kt lj kv kw kx ky kz la cs\" data-selectable-paragraph=\"\"><span>\u4f46\u662f\uff0c\u7b49\u7b49\uff0c\u8fd8\u6709\u66f4\u591a\uff01<\/span><\/li>\n<li id=\"3131\" class=\"ka kb bi kc b kd lf kf kg kh lg kj kk kl lh kn ko kp li kr ks kt lj kv kw kx ky kz la cs\" data-selectable-paragraph=\"\"><span>\u989d\u5916\u4fe1\u7528<\/span><\/li>\n<li id=\"3e46\" class=\"ka kb bi kc b kd lf kf kg kh lg kj kk kl lh kn ko kp li kr ks kt lj kv kw kx ky kz la cs\" data-selectable-paragraph=\"\"><span>\u7ed3\u8bba<\/span><\/li>\n<\/ol>\n<\/div>\n<\/div>\n<\/section>\n<hr class=\"iy hb iz ja bx jb jc jd je jf jg jh\" \/>\n<section class=\"ft fu fv fw fx\">\n<div class=\"n p\">\n<div class=\"z ab ac ae af fy ah ai\">\n<h1 id=\"a9bf\" class=\"ji jj bi bh et jk jl jm jn jo jp jq jr js jt ju jv jw jx jy jz cs\" data-selectable-paragraph=\"\"><span>\u5148\u51b3\u6761\u4ef6<\/span><\/h1>\n<p id=\"e05f\" class=\"ka kb bi kc b kd ke kf kg kh ki kj kk kl km kn ko kp kq kr ks kt ku kv kw kx ft cs\" data-selectable-paragraph=\"\"><em class=\"lk\"><span>\u5728\u5c1d\u8bd5\u8be5\u4f1a\u8bae\u5ba4\u4e4b\u524d\uff0c\u6211\u5f3a\u70c8\u5efa\u8bae\u60a8\u67e5\u770b<\/span><\/em><span><em class=\"lk\">NinjaJc01<\/em><em class=\"lk\">\u7684\u201c\u00a0<\/em><\/span><em class=\"lk\"><span>Web\u57fa\u7840\u77e5\u8bc6<\/span><\/em><em class=\"lk\"><span>\u00a0\u201d\u4f1a\u8bae\u5ba4<\/span><\/em><span><em class=\"lk\">\u3002<\/em><em class=\"lk\">\u5982\u679c\u60a8\u719f\u6089\u57fa\u672c\u7684Web\u8bf7\u6c42\u7ed3\u6784\u548cSQL\u6ce8\u5165\uff0c\u90a3\u4e48\u60a8\u5df2\u7ecf\u8bbe\u7f6e\u597d\u4e86\uff01<\/em><\/span><\/p>\n<\/div>\n<\/div>\n<\/section>\n<hr class=\"iy hb iz ja bx jb jc jd je jf jg jh\" \/>\n<section class=\"ft fu fv fw fx\">\n<div class=\"n p\">\n<div class=\"z ab ac ae af fy ah ai\">\n<h1 id=\"70ef\" class=\"ji jj bi bh et jk jl jm jn jo jp jq jr js jt ju jv jw jx jy jz cs\" data-selectable-paragraph=\"\"><span>\u4ecb\u7ecd<\/span><\/h1>\n<p id=\"8863\" class=\"ka kb bi kc b kd ke kf kg kh ki kj kk kl km kn ko kp kq kr ks kt ku kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u4eca\u5929\u6211\u4eec\u5c06\u8981\u5c1d\u8bd5\u5b8c\u6210\u5728\u7ea2\u5e95\u6f06\u6253\u55dd\u5957\u623f<\/span><span>\u00a0-\u5982\u679c\u4f60\u60f3\u5c1d\u8bd5\u7684\u94fe\u63a5\u53ef\u4ee5\u5728\u8fd9\u91cc\u627e\u5230\uff1a<\/span><a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/tryhackme.com\/room\/rpburpsuite\" target=\"_blank\" rel=\"noopener nofollow noreferrer\" rel=\"nofollow\" ><span>https:\/\/tryhackme.com\/room\/rpburpsuite<\/span><\/a><\/p>\n<p id=\"e57a\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>Burp Suite\u662fWeb\u5e94\u7528\u7a0b\u5e8f\u6e17\u900f\u6d4b\u8bd5\u5de5\u5177\u7684\u6846\u67b6\uff0c\u88ab\u5e7f\u6cdb\u8ba4\u4e3a\u662f\u6267\u884cWeb\u5e94\u7528\u7a0b\u5e8f\u6d4b\u8bd5\u65f6\u4f7f\u7528\u7684\u4e8b\u5b9e\u4e0a\u7684\u5de5\u5177\u3002\u5728\u6574\u4e2a\u4f1a\u8bae\u5ba4\u4e2d\uff0c\u6211\u4eec\u5c06\u4ecb\u7ecd\u5b89\u88c5\u548c\u4f7f\u7528\u6b64\u5de5\u5177\u7684\u57fa\u7840\u77e5\u8bc6\u4ee5\u53ca\u5b83\u7684\u5404\u4e2a\u4e3b\u8981\u7ec4\u4ef6\u3002\u5728\u6574\u4e2a\u4f1a\u8bae\u5ba4\u4e2d\uff0c\u5927\u591a\u6570\u4efb\u52a1\u7684\u5e95\u90e8\u90fd\u63d0\u4f9b\u4e86\u6bcf\u8282\u76f8\u5173\u6587\u6863\u7684\u53c2\u8003\u94fe\u63a5\u3002<\/span><\/p>\n<figure class=\"ig ih ii ij ik il fn fo paragraph-image\">\n<div class=\"im in cc io ai\">\n<div class=\"fn fo if\">\n<div class=\"is r cc fb\">\n<div class=\"it iu r\">\n<div class=\"cb ip s t u ds ai bu iq ir\"><img loading=\"lazy\" decoding=\"async\" class=\"s t u ds ai iv iw ap uu\" data-original=\"https:\/\/miro.medium.com\/max\/60\/0*GmHZqmJC5MGBQtzV.png?q=20\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" width=\"800\" height=\"180\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe3\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe3\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"eg ul s t u ds ai c\" data-original=\"https:\/\/miro.medium.com\/max\/1000\/0*GmHZqmJC5MGBQtzV.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" sizes=\"auto, 700px\" srcset=\"https:\/\/miro.medium.com\/max\/345\/0*GmHZqmJC5MGBQtzV.png 276w, https:\/\/miro.medium.com\/max\/690\/0*GmHZqmJC5MGBQtzV.png 552w, https:\/\/miro.medium.com\/max\/800\/0*GmHZqmJC5MGBQtzV.png 640w, https:\/\/miro.medium.com\/max\/875\/0*GmHZqmJC5MGBQtzV.png 700w\" width=\"800\" height=\"180\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe4\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe4\" \/><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/figure>\n<\/div>\n<\/div>\n<\/section>\n<hr class=\"iy hb iz ja bx jb jc jd je jf jg jh\" \/>\n<section class=\"ft fu fv fw fx\">\n<div class=\"n p\">\n<div class=\"z ab ac ae af fy ah ai\">\n<h1 id=\"e8f8\" class=\"ji jj bi bh et jk jl jm jn jo jp jq jr js jt ju jv jw jx jy jz cs\" data-selectable-paragraph=\"\"><span>\u5b89\u88c5<\/span><\/h1>\n<p id=\"7325\" class=\"ka kb bi kc b kd ke kf kg kh ki kj kk kl km kn ko kp kq kr ks kt ku kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u5728\u6211\u4eec\u6df1\u5165\u7814\u7a76Burp Suite\u8fd9\u4e2a\u4ee4\u4eba\u60ca\u53f9\u7684\u5de5\u5177\u4e4b\u524d\uff0c\u6211\u4eec\u9996\u5148\u5fc5\u987b\u5b89\u88c5\u5b83\u3002\u5bf9\u6211\u4eec\u6765\u8bf4\u5e78\u8fd0\u7684\u662f\uff0c\u5982\u679c\u60a8\u5728Kali Linux\u4e0a\u5b89\u88c5\u6b64\u673a\u623f\uff0c\u5219\u5df2\u7ecf\u5b89\u88c5\u4e86Burp Suite\u3002\u7531\u4e8e\u8be5\u4f1a\u8bae\u5ba4\u4e5f\u5b8c\u5168\u53ef\u4ee5\u5728Windows\u4e0a\u8fd0\u884c\uff0c\u56e0\u6b64\u6211\u4eec\u5c06\u7b80\u8981\u4ecb\u7ecd\u5982\u4f55\u4e3a\u4efb\u4f55\u7cfb\u7edf\u83b7\u53d6Burp Suite\uff08\u793e\u533a\u7248\uff09\uff0c\u56e0\u4e3a\u5b83\u76f8\u5f53\u8f7b\u677e\u3002<\/span><strong class=\"kc lq\"><span>\u60a8\u8fd8\u53ef\u4ee5<\/span><\/strong><a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/tryhackme.com\/my-machine\" target=\"_blank\" rel=\"noopener nofollow noreferrer\" rel=\"nofollow\" ><strong class=\"kc lq\"><span>\u5728<\/span><\/strong><\/a><span><strong class=\"kc lq\">\u5df2\u5b89\u88c5BurpSuite\u7684\u60c5\u51b5\u4e0b<\/strong><strong class=\"kc lq\">\u4f7f\u7528\u90e8\u7f72\u81ea\u5df1<\/strong><a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/tryhackme.com\/my-machine\" target=\"_blank\" rel=\"noopener nofollow noreferrer\" rel=\"nofollow\" ><strong class=\"kc lq\">\u7684\u6d4f\u89c8\u5668<\/strong><\/a><\/span><strong class=\"kc lq\"><span>\u5185\u7f6e\u8ba1\u7b97\u673a\uff01<\/span><\/strong><\/p>\n<p id=\"cffc\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u5982\u679c\u8981\u4ece\u5934\u5f00\u59cb\u5b89\u88c5Burp\uff08\u901a\u5e38\u79f0\u4e3aBurp\uff09\uff0c\u5219\u9700\u8981\u5148\u8bbf\u95ee\u6b64\u94fe\u63a5\uff1a<a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/portswigger.net\/burp\/communitydownload\" target=\"_blank\" rel=\"noopener nofollow noreferrer\" rel=\"nofollow\" >https<\/a>\u00a0:\u00a0<\/span><a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/portswigger.net\/burp\/communitydownload\" target=\"_blank\" rel=\"noopener nofollow noreferrer\" rel=\"nofollow\" ><span>\/\/portswigger.net\/burp\/communitydownload<\/span><\/a><\/p>\n<p id=\"2e0c\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\uff031<\/span><\/p>\n<p id=\"f5ee\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u5982\u679c\u8981\u4ece\u5934\u5f00\u59cb\u5b89\u88c5Burp\uff08\u901a\u5e38\u79f0\u4e3aBurp\uff09\uff0c\u5219\u9700\u8981\u5148\u8bbf\u95ee\u6b64\u94fe\u63a5\uff1a<a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/portswigger.net\/burp\/communitydownload\" target=\"_blank\" rel=\"noopener nofollow noreferrer\" rel=\"nofollow\" >https<\/a>\u00a0:\u00a0<\/span><a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/portswigger.net\/burp\/communitydownload\" target=\"_blank\" rel=\"noopener nofollow noreferrer\" rel=\"nofollow\" ><span>\/\/portswigger.net\/burp\/communitydownload<\/span><\/a><\/p>\n<p id=\"f58b\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>2\u53f7<\/span><\/p>\n<p id=\"7f2c\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u8fdb\u5165Port Swigger\u4e0b\u8f7d\u9875\u9762\u540e\uff0c\u7ee7\u7eed\u4e0b\u8f7d\u9002\u7528\u4e8e\u60a8\u7684\u64cd\u4f5c\u7cfb\u7edf\u7684\u7248\u672c<\/span><\/p>\n<p id=\"4ddb\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\uff033<\/span><\/p>\n<p id=\"dc6f\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>Burp Suite\u9700\u8981Java JRE\u624d\u80fd\u8fd0\u884c\u3002\u5728\u6b64\u5904\u4e0b\u8f7d\u5e76\u5b89\u88c5Java\uff1a<a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/www.java.com\/en\/download\/\" target=\"_blank\" rel=\"noopener nofollow noreferrer\" rel=\"nofollow\" >https<\/a>\uff1a<\/span><a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/www.java.com\/en\/download\/\" target=\"_blank\" rel=\"noopener nofollow noreferrer\" rel=\"nofollow\" ><span>\/\/www.java.com\/en\/download\/<\/span><\/a><\/p>\n<p id=\"09ae\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u5b8c\u6210\u6240\u6709\u8bbe\u7f6e\u540e\uff0c\u79fb\u4ea4\u7ed9\u6211\u4eec\u7684\u4e0b\u4e00\u9879\u4efb\u52a1\uff0c\u5373\u83b7\u5f97Gettin'[CA]\u8ba4\u8bc1\uff01<\/span><\/p>\n<\/div>\n<\/div>\n<\/section>\n<hr class=\"iy hb iz ja bx jb jc jd je jf jg jh\" \/>\n<section class=\"ft fu fv fw fx\">\n<div class=\"n p\">\n<div class=\"z ab ac ae af fy ah ai\">\n<h1 id=\"4834\" class=\"ji jj bi bh et jk jl jm jn jo jp jq jr js jt ju jv jw jx jy jz cs\" data-selectable-paragraph=\"\"><span>Gettin'[CA]\u8ba4\u8bc1<\/span><\/h1>\n<p id=\"56ae\" class=\"ka kb bi kc b kd ke kf kg kh ki kj kk kl km kn ko kp kq kr ks kt ku kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u5728\u5f00\u59cb\u4f7f\u7528\u65b0\u5b89\u88c5\u7684\uff08\u6216\u9884\u5b89\u88c5\u7684\uff09Burp Suite\u4e4b\u524d\uff0c\u6211\u4eec\u5fc5\u987b\u4fee\u590d\u8bc1\u4e66\u8b66\u544a\u3002\u6211\u4eec\u9700\u8981\u5b89\u88c5CA\u8bc1\u4e66\uff0c\u56e0\u4e3aBurpSuite\u5145\u5f53\u60a8\u7684\u6d4f\u89c8\u5668\u4e4b\u95f4\u7684\u4ee3\u7406\uff0c\u5e76\u901a\u8fc7Internet\u53d1\u9001\u5b83\u2014\u5b83\u4f7fBurpSuite\u5e94\u7528\u7a0b\u5e8f\u53ef\u4ee5\u8bfb\u53d6\u548c\u53d1\u9001HTTPS\u6570\u636e\u3002<\/span><\/p>\n<figure class=\"ig ih ii ij ik il fn fo paragraph-image\">\n<div class=\"im in cc io ai\">\n<div class=\"fn fo lr\">\n<div class=\"is r cc fb\">\n<div class=\"ls iu r\">\n<div class=\"cb ip s t u ds ai bu iq ir\"><img loading=\"lazy\" decoding=\"async\" class=\"s t u ds ai iv iw ap uu\" data-original=\"https:\/\/miro.medium.com\/max\/60\/0*R8yaU-Ul94rf6DWc.png?q=20\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" width=\"876\" height=\"324\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe5\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe5\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"eg ul s t u ds ai c\" data-original=\"https:\/\/miro.medium.com\/max\/1095\/0*R8yaU-Ul94rf6DWc.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" sizes=\"auto, 700px\" srcset=\"https:\/\/miro.medium.com\/max\/345\/0*R8yaU-Ul94rf6DWc.png 276w, https:\/\/miro.medium.com\/max\/690\/0*R8yaU-Ul94rf6DWc.png 552w, https:\/\/miro.medium.com\/max\/800\/0*R8yaU-Ul94rf6DWc.png 640w, https:\/\/miro.medium.com\/max\/875\/0*R8yaU-Ul94rf6DWc.png 700w\" width=\"876\" height=\"324\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe6\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe6\" \/><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/figure>\n<p id=\"f4db\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><em class=\"lk\"><span>\u9664\u975e\u6211\u4eec\u5b89\u88c5Burp\u7684CA\u8bc1\u4e66\uff0c\u5426\u5219\u5c06\u51fa\u73b0\u8bc1\u4e66\u8b66\u544a\u3002<\/span><\/em><\/p>\n<p id=\"7f1e\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\"><span>\u5feb\u901f\u8bf4\u660e\u4e00\u4e0b\uff0c\u5728\u672c\u5b9e\u9a8c\u4e2d\uff0c\u6211\u5c06\u4f7f\u7528Firefox\u548cFoxy Proxy<\/span><\/strong><span>\uff08\u53ef\u5728<\/span><a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/addons.mozilla.org\/en-US\/firefox\/addon\/foxyproxy-standard\/\" target=\"_blank\" rel=\"noopener nofollow noreferrer\" rel=\"nofollow\" ><span>\u6b64\u5904<\/span><\/a><span>\u627e\u5230\uff09\u3002\u6211\u5728\u8fd9\u79cd\u60c5\u51b5\u4e0b\u4f7f\u7528Firefox\uff0c\u56e0\u4e3a\u4f7f\u7528Burp Suite\u65f6\u5b83\u4f7f\u7528\u8d77\u6765\u66f4\u5bb9\u6613\u4e00\u4e9b\u3002<\/span><\/p>\n<p id=\"8f1c\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\"><span>\uff031<\/span><\/strong><\/p>\n<p id=\"6e39\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u9996\u5148\uff0c\u8ba9\u6211\u4eec\u7ee7\u7eed\u524d\u8fdb\uff0c\u542f\u52a8Burp\u3002\u6211\u4eec\u53ef\u4ee5\u901a\u8fc7\u5de6\u4fa7\u7684\u56fe\u6807\u5728Kali\u4e0a\u6267\u884c\u6b64\u64cd\u4f5c\u3002\u5728\u4e0b\u9762\u7684\u56fe\u50cf\u4e2d\uff0c\u5b83\u662f\u5de6\u4fa7\u9876\u90e8\u7b2c7\u4e2a\u56fe\u6807\u3002<\/span><strong class=\"kc lq\"><span>\u5982\u679c\u60a8\u7684Kali\u684c\u9762\u770b\u8d77\u6765\u4e0d\u50cf\u4e0b\u9762\u7684\u5c4f\u5e55\u622a\u56fe\uff0c\u8bf7\u5355\u51fb\u201c\u5e94\u7528\u7a0b\u5e8f\u201d\u5e76\u952e\u5165Burp Suite\u3002\u5355\u51fb\u51fa\u73b0\u7684Burp Suite\u56fe\u6807\u3002<\/span><\/strong><\/p>\n<figure class=\"ig ih ii ij ik il fn fo paragraph-image\">\n<div class=\"im in cc io ai\">\n<div class=\"fn fo lt\">\n<div class=\"is r cc fb\">\n<div class=\"lu iu r\">\n<div class=\"cb ip s t u ds ai bu iq ir\"><img loading=\"lazy\" decoding=\"async\" class=\"s t u ds ai iv iw ap uu\" data-original=\"https:\/\/miro.medium.com\/max\/60\/0*xAyT2rpkHiNUYO7c.png?q=20\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" width=\"1366\" height=\"768\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe7\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe7\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"eg ul s t u ds ai c\" data-original=\"https:\/\/miro.medium.com\/max\/1708\/0*xAyT2rpkHiNUYO7c.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" sizes=\"auto, 700px\" srcset=\"https:\/\/miro.medium.com\/max\/345\/0*xAyT2rpkHiNUYO7c.png 276w, https:\/\/miro.medium.com\/max\/690\/0*xAyT2rpkHiNUYO7c.png 552w, https:\/\/miro.medium.com\/max\/800\/0*xAyT2rpkHiNUYO7c.png 640w, https:\/\/miro.medium.com\/max\/875\/0*xAyT2rpkHiNUYO7c.png 700w\" width=\"1366\" height=\"768\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe8\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe8\" \/><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/figure>\n<p id=\"00d2\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u542f\u52a8\u6253p\uff01<\/span><\/p>\n<p id=\"75cb\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\"><span>\uff032<\/span><\/strong><\/p>\n<p id=\"d342\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u542f\u52a8Burp\u540e\uff0c\u5c06\u51fa\u73b0\u4ee5\u4e0b\u5c4f\u5e55\uff1a<\/span><\/p>\n<figure class=\"ig ih ii ij ik il fn fo paragraph-image\">\n<div class=\"im in cc io ai\">\n<div class=\"fn fo lv\">\n<div class=\"is r cc fb\">\n<div class=\"lw iu r\">\n<div class=\"cb ip s t u ds ai bu iq ir\"><img loading=\"lazy\" decoding=\"async\" class=\"s t u ds ai iv iw ap uu\" data-original=\"https:\/\/miro.medium.com\/max\/60\/0*rGbLCxExRzc0Oucw.png?q=20\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" width=\"962\" height=\"619\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe9\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe9\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"eg ul s t u ds ai c\" data-original=\"https:\/\/miro.medium.com\/max\/1203\/0*rGbLCxExRzc0Oucw.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" sizes=\"auto, 700px\" srcset=\"https:\/\/miro.medium.com\/max\/345\/0*rGbLCxExRzc0Oucw.png 276w, https:\/\/miro.medium.com\/max\/690\/0*rGbLCxExRzc0Oucw.png 552w, https:\/\/miro.medium.com\/max\/800\/0*rGbLCxExRzc0Oucw.png 640w, https:\/\/miro.medium.com\/max\/875\/0*rGbLCxExRzc0Oucw.png 700w\" width=\"962\" height=\"619\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe10\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe10\" \/><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/figure>\n<p id=\"7aa4\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u5f39\u51fa\u540e\uff0c\u5355\u51fb\u201c\u4e34\u65f6\u9879\u76ee\u201d\uff0c\u7136\u540e\u5355\u51fb\u201c\u4e0b\u4e00\u6b65\u201d\u3002<\/span><\/p>\n<p id=\"4b2f\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><em class=\"lk\"><span>*\u73b0\u5728\uff0c\u60a8\u53ef\u80fd\u5df2\u7ecf\u6ce8\u610f\u5230\u201c\u78c1\u76d8\u4e0a\u7684\u65b0\u9879\u76ee\u201d\u548c\u201c\u6253\u5f00\u73b0\u6709\u9879\u76ee\u201d\u90fd\u663e\u793a\u4e3a\u7070\u8272\u3002\u5982\u8be5\u7a97\u53e3\u9876\u90e8\u6240\u793a\uff0c\u4fdd\u5b58\u9879\u76ee\u662f\u4e0eBurp Suite Professional\u76f8\u5173\u7684\u529f\u80fd\uff0c\u56e0\u4e3a\u4fdd\u5b58\u5e76\u8fd4\u56de\u591a\u5929Web\u5e94\u7528\u7a0b\u5e8f\u6d4b\u8bd5\u662f\u5f88\u5e38\u89c1\u7684\u3002<\/span><\/em><\/p>\n<p id=\"6d91\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\"><span>\uff033<\/span><\/strong><\/p>\n<p id=\"52d8\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u63a5\u4e0b\u6765\uff0c\u5c06\u63d0\u793a\u6211\u4eec\u8be2\u95ee\u6211\u4eec\u8981\u4f7f\u7528\u54ea\u79cd\u914d\u7f6e\u3002\u73b0\u5728\uff0c\u9009\u62e9\u201c\u4f7f\u7528\u6253Bur\u9ed8\u8ba4\u8bbe\u7f6e\u201d\u3002<\/span><\/p>\n<figure class=\"ig ih ii ij ik il fn fo paragraph-image\">\n<div class=\"im in cc io ai\">\n<div class=\"fn fo lx\">\n<div class=\"is r cc fb\">\n<div class=\"ly iu r\">\n<div class=\"cb ip s t u ds ai bu iq ir\"><img loading=\"lazy\" decoding=\"async\" class=\"s t u ds ai iv iw ap uu\" data-original=\"https:\/\/miro.medium.com\/max\/60\/0*N6qURdOFbO7n83fw.png?q=20\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" width=\"948\" height=\"604\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe11\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe11\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"eg ul s t u ds ai c\" data-original=\"https:\/\/miro.medium.com\/max\/1185\/0*N6qURdOFbO7n83fw.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" sizes=\"auto, 700px\" srcset=\"https:\/\/miro.medium.com\/max\/345\/0*N6qURdOFbO7n83fw.png 276w, https:\/\/miro.medium.com\/max\/690\/0*N6qURdOFbO7n83fw.png 552w, https:\/\/miro.medium.com\/max\/800\/0*N6qURdOFbO7n83fw.png 640w, https:\/\/miro.medium.com\/max\/875\/0*N6qURdOFbO7n83fw.png 700w\" width=\"948\" height=\"604\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe12\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe12\" \/><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/figure>\n<p id=\"4fc1\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><em class=\"lk\"><span>\u5305\u542b\u6b64\u9009\u9879\u662f\u56e0\u4e3a\u5b83\u5bf9\u4e8e\u4e3a\u4ee3\u7406\u6216\u5176\u4ed6\u8bbe\u7f6e\u521b\u5efa\u81ea\u5b9a\u4e49\u914d\u7f6e\u6587\u4ef6\u975e\u5e38\u6709\u7528\uff0c\u5c24\u5176\u662f\u53d6\u51b3\u4e8e\u60a8\u7684\u7f51\u7edc\u914d\u7f6e\u65b9\u5f0f\u548c\/\u6216\u662f\u5426\u901a\u8fc7\u8bf8\u5982<\/span><\/em><a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/www.youtube.com\/watch?v=auePeI8vZA8\" target=\"_blank\" rel=\"noopener nofollow noreferrer\" rel=\"nofollow\" ><em class=\"lk\"><span>x11\u8f6c\u53d1<\/span><\/em><\/a><span><em class=\"lk\">\u8fdc\u7a0b\u542f\u52a8Burp Suite\u65f6<\/em><\/span><em class=\"lk\"><span>\u3002<\/span><\/em><\/p>\n<p id=\"961c\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\"><span>\uff034<\/span><\/strong><\/p>\n<p id=\"1df8\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u6700\u540e\uff0c\u8ba9\u6211\u4eec\u5f00\u59cbBurp\uff01\u7acb\u5373\u70b9\u51fb\u201c\u5f00\u59cb\u6253p\u201d\uff01<\/span><\/p>\n<p id=\"c652\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\"><span>\uff035<\/span><\/strong><\/p>\n<p id=\"60ec\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u73b0\u5728\uff0c\u60a8\u5c06\u770b\u5230\u4e00\u4e2a\u7c7b\u4f3c\u4e8e\u4ee5\u4e0b\u5185\u5bb9\u7684\u5c4f\u5e55\uff1a<\/span><\/p>\n<figure class=\"ig ih ii ij ik il fn fo paragraph-image\">\n<div class=\"im in cc io ai\">\n<div class=\"fn fo lz\">\n<div class=\"is r cc fb\">\n<div class=\"ma iu r\">\n<div class=\"cb ip s t u ds ai bu iq ir\"><img loading=\"lazy\" decoding=\"async\" class=\"s t u ds ai iv iw ap uu\" data-original=\"https:\/\/miro.medium.com\/max\/60\/0*E_eAwMoUz6VYZWeV.png?q=20\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" width=\"1447\" height=\"718\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe13\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe13\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"eg ul s t u ds ai c\" data-original=\"https:\/\/miro.medium.com\/max\/1809\/0*E_eAwMoUz6VYZWeV.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" sizes=\"auto, 700px\" srcset=\"https:\/\/miro.medium.com\/max\/345\/0*E_eAwMoUz6VYZWeV.png 276w, https:\/\/miro.medium.com\/max\/690\/0*E_eAwMoUz6VYZWeV.png 552w, https:\/\/miro.medium.com\/max\/800\/0*E_eAwMoUz6VYZWeV.png 640w, https:\/\/miro.medium.com\/max\/875\/0*E_eAwMoUz6VYZWeV.png 700w\" width=\"1447\" height=\"718\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe14\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe14\" \/><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/figure>\n<p id=\"b798\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u7531\u4e8e\u6211\u4eec\u73b0\u5728\u6b63\u5728\u8fd0\u884cBurp Suite\uff0c\u56e0\u6b64\u9ed8\u8ba4\u60c5\u51b5\u4e0b\u5c06\u4f7f\u7528\u5b83\u542f\u52a8\u4ee3\u7406\u670d\u52a1\u3002\u4e3a\u4e86\u5145\u5206\u5229\u7528\u6b64\u4ee3\u7406\uff0c\u6211\u4eec\u5fc5\u987b\u5b89\u88c5Burp Suite\u968f\u9644\u7684CA\u8bc1\u4e66\uff08\u5426\u5219\u6211\u4eec\u5c06\u65e0\u6cd5\u4f7f\u7528SSL\u52a0\u8f7d\u4efb\u4f55\u5185\u5bb9\uff09\u3002\u4e3a\u6b64\uff0c\u8bf7\u7acb\u5373\u542f\u52a8Firefox\uff01<\/span><\/p>\n<ul class=\"\">\n<li id=\"8028\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx mb kz la cs\" data-selectable-paragraph=\"\"><em class=\"lk\">You can do this part with your browser of choice, however, I\u2019ll be using Firefox for this room. Burp suite latest update also comes with an inbuilt browser to skip installing the CA certificate.<\/em><\/li>\n<\/ul>\n<p id=\"79ca\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">#6<\/strong><\/p>\n<p id=\"2f3b\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">Now that we\u2019ve started Burp, let\u2019s add an extension to our web browser to allow up to easily route or traffic through it! For this room, we\u2019ll be using \u2018FoxyProxy Standard\u2019 on Firefox.<\/p>\n<figure class=\"ig ih ii ij ik il fn fo paragraph-image\">\n<div class=\"im in cc io ai\">\n<div class=\"fn fo mc\">\n<div class=\"is r cc fb\">\n<div class=\"md iu r\">\n<div class=\"cb ip s t u ds ai bu iq ir\"><img loading=\"lazy\" decoding=\"async\" class=\"s t u ds ai iv iw ap uu\" data-original=\"https:\/\/miro.medium.com\/max\/60\/0*7gekt3UCs3xXvCjn.png?q=20\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" width=\"796\" height=\"374\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe15\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe15\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"eg ul s t u ds ai c\" data-original=\"https:\/\/miro.medium.com\/max\/995\/0*7gekt3UCs3xXvCjn.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" sizes=\"auto, 700px\" srcset=\"https:\/\/miro.medium.com\/max\/345\/0*7gekt3UCs3xXvCjn.png 276w, https:\/\/miro.medium.com\/max\/690\/0*7gekt3UCs3xXvCjn.png 552w, https:\/\/miro.medium.com\/max\/800\/0*7gekt3UCs3xXvCjn.png 640w, https:\/\/miro.medium.com\/max\/875\/0*7gekt3UCs3xXvCjn.png 700w\" width=\"796\" height=\"374\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe16\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe16\" \/><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/figure>\n<p id=\"606a\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">Navigate to the following link to install FoxyProxy Standard:\u00a0<a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/addons.mozilla.org\/en-US\/firefox\/addon\/foxyproxy-standard\/\" target=\"_blank\" rel=\"noopener nofollow noreferrer\" rel=\"nofollow\" >Link<\/a><\/p>\n<p id=\"b8c5\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">Go ahead and install this now!<\/p>\n<p id=\"d421\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">#7<\/strong><\/p>\n<p id=\"3fc0\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">Next, click on FoxyProxy among your extensions.<\/p>\n<figure class=\"ig ih ii ij ik il fn fo paragraph-image\">\n<div class=\"fn fo me\">\n<div class=\"is r cc fb\">\n<div class=\"mf iu r\">\n<div class=\"cb ip s t u ds ai bu iq ir\"><img loading=\"lazy\" decoding=\"async\" class=\"s t u ds ai iv iw ap uu\" data-original=\"https:\/\/miro.medium.com\/max\/60\/0*6g1vwuAJcxM0Atj6.png?q=20\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" width=\"216\" height=\"39\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe17\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe17\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"eg ul s t u ds ai c\" data-original=\"https:\/\/miro.medium.com\/max\/270\/0*6g1vwuAJcxM0Atj6.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" sizes=\"auto, 216px\" srcset=\"\" width=\"216\" height=\"39\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe18\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe18\" \/><\/div>\n<\/div>\n<\/div>\n<\/figure>\n<p id=\"3832\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">After that, click on \u2018Options\u2019.<\/p>\n<figure class=\"ig ih ii ij ik il fn fo paragraph-image\">\n<div class=\"fn fo mg\">\n<div class=\"is r cc fb\">\n<div class=\"mh iu r\">\n<div class=\"cb ip s t u ds ai bu iq ir\"><img loading=\"lazy\" decoding=\"async\" class=\"s t u ds ai iv iw ap uu\" data-original=\"https:\/\/miro.medium.com\/max\/60\/0*tCPD6nBeZNpSNny1.png?q=20\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" width=\"368\" height=\"200\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe19\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe19\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"eg ul s t u ds ai c\" data-original=\"https:\/\/miro.medium.com\/max\/460\/0*tCPD6nBeZNpSNny1.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" sizes=\"auto, 368px\" srcset=\"https:\/\/miro.medium.com\/max\/345\/0*tCPD6nBeZNpSNny1.png 276w, https:\/\/miro.medium.com\/max\/460\/0*tCPD6nBeZNpSNny1.png 368w\" width=\"368\" height=\"200\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe20\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe20\" \/><\/div>\n<\/div>\n<\/div>\n<\/figure>\n<p id=\"93fc\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">After that, click \u2018Add\u2019 in the top left.<\/p>\n<figure class=\"ig ih ii ij ik il fn fo paragraph-image\">\n<div class=\"fn fo mi\">\n<div class=\"is r cc fb\">\n<div class=\"mj iu r\">\n<div class=\"cb ip s t u ds ai bu iq ir\"><img loading=\"lazy\" decoding=\"async\" class=\"s t u ds ai iv iw ap uu\" data-original=\"https:\/\/miro.medium.com\/max\/60\/0*1108od4tpb749n0e.png?q=20\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" width=\"108\" height=\"45\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe21\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe21\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"eg ul s t u ds ai c\" data-original=\"https:\/\/miro.medium.com\/max\/135\/0*1108od4tpb749n0e.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" sizes=\"auto, 108px\" srcset=\"\" width=\"108\" height=\"45\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe22\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe22\" \/><\/div>\n<\/div>\n<\/div>\n<\/figure>\n<p id=\"2084\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">Enter in the following settings and then click \u2018Save\u2019<\/p>\n<figure class=\"ig ih ii ij ik il fn fo paragraph-image\">\n<div class=\"im in cc io ai\">\n<div class=\"fn fo mk\">\n<div class=\"is r cc fb\">\n<div class=\"ml iu r\">\n<div class=\"cb ip s t u ds ai bu iq ir\"><img loading=\"lazy\" decoding=\"async\" class=\"s t u ds ai iv iw ap uu\" data-original=\"https:\/\/miro.medium.com\/max\/60\/0*9tyng6xVcvr8utJx.png?q=20\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" width=\"1254\" height=\"559\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe23\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe23\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"eg ul s t u ds ai c\" data-original=\"https:\/\/miro.medium.com\/max\/1568\/0*9tyng6xVcvr8utJx.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" sizes=\"auto, 700px\" srcset=\"https:\/\/miro.medium.com\/max\/345\/0*9tyng6xVcvr8utJx.png 276w, https:\/\/miro.medium.com\/max\/690\/0*9tyng6xVcvr8utJx.png 552w, https:\/\/miro.medium.com\/max\/800\/0*9tyng6xVcvr8utJx.png 640w, https:\/\/miro.medium.com\/max\/875\/0*9tyng6xVcvr8utJx.png 700w\" width=\"1254\" height=\"559\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe24\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe24\" \/><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/figure>\n<p id=\"fd09\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">Finally, click on the FoxyProxy extension icon again and select \u2018Burp\u2019.<\/p>\n<figure class=\"ig ih ii ij ik il fn fo paragraph-image\">\n<div class=\"fn fo mg\">\n<div class=\"is r cc fb\">\n<div class=\"mh iu r\">\n<div class=\"cb ip s t u ds ai bu iq ir\"><img loading=\"lazy\" decoding=\"async\" class=\"s t u ds ai iv iw ap uu\" data-original=\"https:\/\/miro.medium.com\/max\/60\/0*h-IbMcV9ain3kxV6.png?q=20\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" width=\"368\" height=\"200\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe25\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe25\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"eg ul s t u ds ai c\" data-original=\"https:\/\/miro.medium.com\/max\/460\/0*h-IbMcV9ain3kxV6.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" sizes=\"auto, 368px\" srcset=\"https:\/\/miro.medium.com\/max\/345\/0*h-IbMcV9ain3kxV6.png 276w, https:\/\/miro.medium.com\/max\/460\/0*h-IbMcV9ain3kxV6.png 368w\" width=\"368\" height=\"200\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe26\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe26\" \/><\/div>\n<\/div>\n<\/div>\n<\/figure>\n<p id=\"ce5d\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><em class=\"lk\">In the image above Burp isn\u2019t selected. Make sure it is in yours!<\/em><\/p>\n<p id=\"2bb7\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u63a5\u4e0b\u6765\uff0c\u6211\u4eec\u5c06\u7ee7\u7eed\u6dfb\u52a0Burp\u7684\u8bc1\u4e66\uff01<\/span><\/p>\n<p id=\"d53c\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\"><span>\uff038<\/span><\/strong><\/p>\n<p id=\"03f0\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u4f7f\u7528Firefox\uff0c\u5bfc\u822a\u5230\u4ee5\u4e0b\u5730\u5740\uff1a<\/span><a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=http:\/\/localhost:8080\/\" target=\"_blank\" rel=\"noopener nofollow noreferrer\" rel=\"nofollow\" ><span>http\uff1a\/\/ localhost\uff1a8080<\/span><\/a><\/p>\n<p id=\"a02e\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\"><span>\uff039<\/span><\/strong><\/p>\n<p id=\"c2b7\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u60a8\u5c06\u4f1a\u770b\u5230\u4ee5\u4e0b\u7f51\u7ad9\uff1a<\/span><\/p>\n<figure class=\"ig ih ii ij ik il fn fo paragraph-image\">\n<div class=\"im in cc io ai\">\n<div class=\"fn fo mm\">\n<div class=\"is r cc fb\">\n<div class=\"mn iu r\">\n<div class=\"cb ip s t u ds ai bu iq ir\"><img loading=\"lazy\" decoding=\"async\" class=\"s t u ds ai iv iw ap uu\" data-original=\"https:\/\/miro.medium.com\/max\/60\/0*gDU0vL0RixLLDVHt.png?q=20\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" width=\"1904\" height=\"438\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe27\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe27\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"eg ul s t u ds ai c\" data-original=\"https:\/\/miro.medium.com\/max\/2380\/0*gDU0vL0RixLLDVHt.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" sizes=\"auto, 700px\" srcset=\"https:\/\/miro.medium.com\/max\/345\/0*gDU0vL0RixLLDVHt.png 276w, https:\/\/miro.medium.com\/max\/690\/0*gDU0vL0RixLLDVHt.png 552w, https:\/\/miro.medium.com\/max\/800\/0*gDU0vL0RixLLDVHt.png 640w, https:\/\/miro.medium.com\/max\/875\/0*gDU0vL0RixLLDVHt.png 700w\" width=\"1904\" height=\"438\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe28\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe28\" \/><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/figure>\n<p id=\"3a1e\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u5355\u51fb\u53f3\u4e0a\u89d2\u7684\u201c CA\u8bc1\u4e66\u201d\u4ee5\u4e0b\u8f7d\u5e76\u4fdd\u5b58CA\u8bc1\u4e66\u3002<\/span><\/p>\n<p id=\"78cb\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\"><span>\uff0310<\/span><\/strong><\/p>\n<p id=\"3ff5\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u65e2\u7136\u6211\u4eec\u5df2\u7ecf\u4e0b\u8f7d\u4e86CA\u8bc1\u4e66\uff0c\u8bf7\u79fb\u81f3Firefox\u4e2d\u7684\u8bbe\u7f6e\u83dc\u5355\u3002\u5728\u641c\u7d22\u680f\u4e2d\u641c\u7d22\u201c\u8bc1\u4e66\u201d\u3002<\/span><\/p>\n<figure class=\"ig ih ii ij ik il fn fo paragraph-image\">\n<div class=\"im in cc io ai\">\n<div class=\"fn fo mo\">\n<div class=\"is r cc fb\">\n<div class=\"mp iu r\">\n<div class=\"cb ip s t u ds ai bu iq ir\"><img loading=\"lazy\" decoding=\"async\" class=\"s t u ds ai iv iw ap uu\" data-original=\"https:\/\/miro.medium.com\/max\/60\/0*axLkEF6s_6dVG5hj.png?q=20\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" width=\"929\" height=\"331\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe29\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe29\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"eg ul s t u ds ai c\" data-original=\"https:\/\/miro.medium.com\/max\/1161\/0*axLkEF6s_6dVG5hj.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" sizes=\"auto, 700px\" srcset=\"https:\/\/miro.medium.com\/max\/345\/0*axLkEF6s_6dVG5hj.png 276w, https:\/\/miro.medium.com\/max\/690\/0*axLkEF6s_6dVG5hj.png 552w, https:\/\/miro.medium.com\/max\/800\/0*axLkEF6s_6dVG5hj.png 640w, https:\/\/miro.medium.com\/max\/875\/0*axLkEF6s_6dVG5hj.png 700w\" width=\"929\" height=\"331\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe30\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe30\" \/><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/figure>\n<p id=\"55be\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u70b9\u51fb\u201c\u67e5\u770b\u8bc1\u4e66\u201d<\/span><\/p>\n<p id=\"3e23\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\"><span>\uff0311<\/span><\/strong><\/p>\n<p id=\"f55c\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u63a5\u4e0b\u6765\uff0c\u5728\u201c\u6743\u9650\u201d\u6807\u7b7e\u4e2d\uff0c\u70b9\u51fb\u201c\u5bfc\u5165\u201d<\/span><\/p>\n<p id=\"59cd\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\"><span>\uff0312<\/span><\/strong><\/p>\n<p id=\"728d\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u5bfc\u822a\u5230\u60a8\u4fdd\u5b58\u6211\u4eec\u5148\u524d\u4e0b\u8f7d\u7684CA\u8bc1\u4e66\u7684\u4f4d\u7f6e\u3002\u9009\u62e9\u6b64\u8bc1\u4e66\u540e\uff0c\u5355\u51fb\u201c\u786e\u5b9a\u201d\u3002<\/span><\/p>\n<p id=\"2c7b\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\"><span>\uff0313<\/span><\/strong><\/p>\n<p id=\"6995\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u6700\u540e\uff0c\u9009\u62e9\u6b64\u7167\u7247\u4e2d\u663e\u793a\u7684\u4ee5\u4e0b\u4e24\u4e2a\u9009\u9879\uff1a<\/span><\/p>\n<figure class=\"ig ih ii ij ik il fn fo paragraph-image\">\n<div class=\"im in cc io ai\">\n<div class=\"fn fo mq\">\n<div class=\"is r cc fb\">\n<div class=\"mr iu r\">\n<div class=\"cb ip s t u ds ai bu iq ir\"><img loading=\"lazy\" decoding=\"async\" class=\"s t u ds ai iv iw ap uu\" data-original=\"https:\/\/miro.medium.com\/max\/60\/0*hx9ZAXF6u3IE13-z.png?q=20\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" width=\"864\" height=\"458\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe31\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe31\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"eg ul s t u ds ai c\" data-original=\"https:\/\/miro.medium.com\/max\/1080\/0*hx9ZAXF6u3IE13-z.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" sizes=\"auto, 700px\" srcset=\"https:\/\/miro.medium.com\/max\/345\/0*hx9ZAXF6u3IE13-z.png 276w, https:\/\/miro.medium.com\/max\/690\/0*hx9ZAXF6u3IE13-z.png 552w, https:\/\/miro.medium.com\/max\/800\/0*hx9ZAXF6u3IE13-z.png 640w, https:\/\/miro.medium.com\/max\/875\/0*hx9ZAXF6u3IE13-z.png 700w\" width=\"864\" height=\"458\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe32\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe32\" \/><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/figure>\n<p id=\"dc63\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u5b8c\u6210\u6b64\u64cd\u4f5c\u540e\uff0c\u9009\u62e9\u201c\u786e\u5b9a\u201d\u3002\u606d\u559c\uff0c\u6211\u4eec\u73b0\u5728\u5df2\u7ecf\u5b89\u88c5\u4e86Burp Suite CA\u8bc1\u4e66\uff01<\/span><\/p>\n<\/div>\n<\/div>\n<\/section>\n<hr class=\"iy hb iz ja bx jb jc jd je jf jg jh\" \/>\n<section class=\"ft fu fv fw fx\">\n<div class=\"n p\">\n<div class=\"z ab ac ae af fy ah ai\">\n<h1 id=\"111f\" class=\"ji jj bi bh et jk jl jm jn jo jp jq jr js jt ju jv jw jx jy jz cs\" data-selectable-paragraph=\"\"><span>\u529f\u80fd\u6982\u8ff0<\/span><\/h1>\n<p id=\"1dec\" class=\"ka kb bi kc b kd ke kf kg kh ki kj kk kl km kn ko kp kq kr ks kt ku kv kw kx ft cs\" data-selectable-paragraph=\"\">Now that we\u2019ve set up Burp, let\u2019s take a look at everything it has to offer. Web application pentesting can be a messy affair but Burp has something for every step of the way.<\/p>\n<figure class=\"ig ih ii ij ik il fn fo paragraph-image\">\n<div class=\"im in cc io ai\">\n<div class=\"fn fo if\">\n<div class=\"is r cc fb\">\n<div class=\"ms iu r\">\n<div class=\"cb ip s t u ds ai bu iq ir\"><img loading=\"lazy\" decoding=\"async\" class=\"s t u ds ai iv iw ap uu\" data-original=\"https:\/\/miro.medium.com\/max\/60\/0*kBMpSrL9w_WBDXB4.jpg?q=20\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" width=\"800\" height=\"600\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe33\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe33\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"eg ul s t u ds ai c\" data-original=\"https:\/\/miro.medium.com\/max\/1000\/0*kBMpSrL9w_WBDXB4.jpg\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" sizes=\"auto, 700px\" srcset=\"https:\/\/miro.medium.com\/max\/345\/0*kBMpSrL9w_WBDXB4.jpg 276w, https:\/\/miro.medium.com\/max\/690\/0*kBMpSrL9w_WBDXB4.jpg 552w, https:\/\/miro.medium.com\/max\/800\/0*kBMpSrL9w_WBDXB4.jpg 640w, https:\/\/miro.medium.com\/max\/875\/0*kBMpSrL9w_WBDXB4.jpg 700w\" width=\"800\" height=\"600\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe34\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe34\" \/><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/figure>\n<p id=\"0e16\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/dribbble.com\/shots\/4887261-Tools\" target=\"_blank\" rel=\"noopener nofollow noreferrer\" rel=\"nofollow\" ><em class=\"lk\">Tools by Ana Miminoshvili on Dribbble<\/em><\/a><\/p>\n<p id=\"d5a2\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">Throughout this room, we\u2019ll be taking a look at these components of Burp Suite. Here\u2019s a quick overview of each section covered:<\/p>\n<ul class=\"\">\n<li id=\"2129\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx mb kz la cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">Proxy<\/strong>\u00a0\u2014 What allows us to funnel traffic through Burp Suite for further analysis<\/li>\n<li id=\"0c35\" class=\"ka kb bi kc b kd lf kf kg kh lg kj kk kl lh kn ko kp li kr ks kt lj kv kw kx mb kz la cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">Target<\/strong>\u00a0\u2014 How we set the scope of our project. We can also use this to effectively create a site map of the application we are testing.<\/li>\n<li id=\"091d\" class=\"ka kb bi kc b kd lf kf kg kh lg kj kk kl lh kn ko kp li kr ks kt lj kv kw kx mb kz la cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">Intruder<\/strong>\u00a0\u2014 Incredibly powerful tool for everything from field fuzzing to credential stuffing and more<\/li>\n<li id=\"8226\" class=\"ka kb bi kc b kd lf kf kg kh lg kj kk kl lh kn ko kp li kr ks kt lj kv kw kx mb kz la cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">Repeater<\/strong>\u00a0\u2014 Allows us to \u2018repeat\u2019 requests that have previously been made with or without modification. Often used in a precursor step to fuzzing with the aforementioned Intruder<\/li>\n<li id=\"214e\" class=\"ka kb bi kc b kd lf kf kg kh lg kj kk kl lh kn ko kp li kr ks kt lj kv kw kx mb kz la cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">Sequencer<\/strong>\u00a0\u2014 Analyzes the \u2018randomness\u2019 present in parts of the web app which are intended to be unpredictable. This is commonly used for testing session cookies<\/li>\n<li id=\"819d\" class=\"ka kb bi kc b kd lf kf kg kh lg kj kk kl lh kn ko kp li kr ks kt lj kv kw kx mb kz la cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">Decoder<\/strong>\u00a0\u2014 As the name suggests, Decoder is a tool that allows us to perform various transforms on pieces of data. These transforms vary from decoding\/encoding to various bases or URL encoding.<\/li>\n<li id=\"e46a\" class=\"ka kb bi kc b kd lf kf kg kh lg kj kk kl lh kn ko kp li kr ks kt lj kv kw kx mb kz la cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">Comparer<\/strong>\u00a0\u2014 Comparer as you might have guessed is a tool we can use to compare different responses or other pieces of data such as site maps or proxy histories (awesome for access control issue testing). This is very similar to the Linux tool diff.<\/li>\n<li id=\"3017\" class=\"ka kb bi kc b kd lf kf kg kh lg kj kk kl lh kn ko kp li kr ks kt lj kv kw kx mb kz la cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">Extender<\/strong>\u00a0\u2014 Similar to adding mods to a game like Minecraft, Extender allows us to add components such as tool integrations, additional scan definitions, and more!<\/li>\n<li id=\"5a3d\" class=\"ka kb bi kc b kd lf kf kg kh lg kj kk kl lh kn ko kp li kr ks kt lj kv kw kx mb kz la cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">Scanner<\/strong>\u00a0\u2014 Automated web vulnerability scanner that can highlight areas of the application for further manual investigation or possible exploitation with another section of Burp. This feature, while not in the community edition of Burp Suite, is still a key facet of performing a web application test.<\/li>\n<\/ul>\n<p id=\"ab91\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">#1<\/strong><\/p>\n<p id=\"2646\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">Which tool in Burp Suite can we use to perform a \u2018diff\u2019 on responses and other pieces of data?<\/p>\n<pre class=\"ig ih ii ij ik mt mu mv\"><span id=\"86bf\" class=\"cs mw jj bi mx b ca my mz r na\" data-selectable-paragraph=\"\">comparer<\/span><\/pre>\n<p id=\"7d17\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">#2<\/strong><\/p>\n<p id=\"1e00\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">What tool could we use to analyze randomness in different pieces of data such as password reset tokens?<\/p>\n<pre class=\"ig ih ii ij ik mt mu mv\"><span id=\"4564\" class=\"cs mw jj bi mx b ca my mz r na\" data-selectable-paragraph=\"\">sequencer<\/span><\/pre>\n<p id=\"82c4\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">#3<\/strong><\/p>\n<p id=\"0da6\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">Which tool can we use to set the scope of our project?<\/p>\n<pre class=\"ig ih ii ij ik mt mu mv\"><span id=\"2a39\" class=\"cs mw jj bi mx b ca my mz r na\" data-selectable-paragraph=\"\">target<\/span><\/pre>\n<p id=\"1361\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">#4<\/strong><\/p>\n<p id=\"7a6b\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">While only available in the premium versions of Burp Suite, which tool can we use to automatically identify different vulnerabilities in the application we are examining?<\/p>\n<pre class=\"ig ih ii ij ik mt mu mv\"><span id=\"2df3\" class=\"cs mw jj bi mx b ca my mz r na\" data-selectable-paragraph=\"\">scanner<\/span><\/pre>\n<p id=\"05e7\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">#5<\/strong><\/p>\n<p id=\"9b94\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">Encoding or decoding data can be particularly useful when examining URL parameters or protections on a form, which tool allows us to do just that?<\/p>\n<pre class=\"ig ih ii ij ik mt mu mv\"><span id=\"b208\" class=\"cs mw jj bi mx b ca my mz r na\" data-selectable-paragraph=\"\">decoder<\/span><\/pre>\n<p id=\"f8ea\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">#6<\/strong><\/p>\n<p id=\"ce52\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">Which tool allows us to redirect our web traffic into Burp for further examination?<\/p>\n<pre class=\"ig ih ii ij ik mt mu mv\"><span id=\"3ee1\" class=\"cs mw jj bi mx b ca my mz r na\" data-selectable-paragraph=\"\">proxy<\/span><\/pre>\n<p id=\"92b4\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">#7<\/strong><\/p>\n<p id=\"8ad8\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">Simple in concept but powerful in execution, which tool allows us to reissue requests?<\/p>\n<pre class=\"ig ih ii ij ik mt mu mv\"><span id=\"8a09\" class=\"cs mw jj bi mx b ca my mz r na\" data-selectable-paragraph=\"\">repeater<\/span><\/pre>\n<p id=\"2bab\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">#8<\/strong><\/p>\n<p id=\"8bd2\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u901a\u8fc7\u56db\u79cd\u6a21\u5f0f\uff0c\u6211\u4eec\u53ef\u4ee5\u5728Burp\u4e2d\u4f7f\u7528\u54ea\u79cd\u5de5\u5177\u6765\u5b9e\u73b0\u591a\u79cd\u76ee\u7684\uff0c\u4f8b\u5982\u73b0\u573a\u6a21\u7cca\u6d4b\u8bd5\uff1f<\/span><\/p>\n<pre class=\"ig ih ii ij ik mt mu mv\"><span id=\"5fc1\" class=\"cs mw jj bi mx b ca my mz r na\" data-selectable-paragraph=\"\"><span>\u5165\u4fb5\u8005<\/span><\/span><\/pre>\n<p id=\"e5ca\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\"><span>\uff039<\/span><\/strong><\/p>\n<p id=\"2c0b\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u6700\u540e\u4f46\u5e76\u975e\u6700\u4e0d\u91cd\u8981\u7684\u4e00\u70b9\u662f\uff0c\u54ea\u4e2a\u5de5\u5177\u5141\u8bb8\u6211\u4eec\u901a\u8fc7\u6dfb\u52a0\u6269\u5c55\u6765\u4fee\u6539Burp Suite\uff1f<\/span><\/p>\n<pre class=\"ig ih ii ij ik mt mu mv\"><span id=\"d2ee\" class=\"cs mw jj bi mx b ca my mz r na\" data-selectable-paragraph=\"\"><span>\u8865\u5145\u5242<\/span><\/span><\/pre>\n<\/div>\n<\/div>\n<\/section>\n<hr class=\"iy hb iz ja bx jb jc jd je jf jg jh\" \/>\n<section class=\"ft fu fv fw fx\">\n<div class=\"n p\">\n<div class=\"z ab ac ae af fy ah ai\">\n<h1 id=\"3a50\" class=\"ji jj bi bh et jk jl jm jn jo jp jq jr js jt ju jv jw jx jy jz cs\" data-selectable-paragraph=\"\"><span>\u53c2\u4e0e\u9ed1\u6697\u6a21\u5f0f<\/span><\/h1>\n<p id=\"95fe\" class=\"ka kb bi kc b kd ke kf kg kh ki kj kk kl km kn ko kp kq kr ks kt ku kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u5728\u6df1\u591c\u8fdb\u884c\u9879\u76ee\uff1f\u522b\u518d\u5bb3\u6015\u4e86\uff01\u5728\u6b64\u4efb\u52a1\u4e2d\uff0c\u6211\u4eec\u5c06\u4ecb\u7ecd\u5982\u4f55\u5728Burp Suite\u4e2d\u542f\u7528\u6697\u6a21\u5f0f\uff01<\/span><\/p>\n<figure class=\"ig ih ii ij ik il fn fo paragraph-image\">\n<div class=\"im in cc io ai\">\n<div class=\"fn fo nb\">\n<div class=\"is r cc fb\">\n<div class=\"ms iu r\">\n<div class=\"cb ip s t u ds ai bu iq ir\"><img loading=\"lazy\" decoding=\"async\" class=\"s t u ds ai iv iw ap uu\" data-original=\"https:\/\/miro.medium.com\/max\/60\/0*SuzL2dtGYaB27Lkz.jpg?q=20\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" width=\"1600\" height=\"1200\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe35\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe35\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"eg ul s t u ds ai c\" data-original=\"https:\/\/miro.medium.com\/max\/2000\/0*SuzL2dtGYaB27Lkz.jpg\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" sizes=\"auto, 700px\" srcset=\"https:\/\/miro.medium.com\/max\/345\/0*SuzL2dtGYaB27Lkz.jpg 276w, https:\/\/miro.medium.com\/max\/690\/0*SuzL2dtGYaB27Lkz.jpg 552w, https:\/\/miro.medium.com\/max\/800\/0*SuzL2dtGYaB27Lkz.jpg 640w, https:\/\/miro.medium.com\/max\/875\/0*SuzL2dtGYaB27Lkz.jpg 700w\" width=\"1600\" height=\"1200\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe36\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe36\" \/><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/figure>\n<p id=\"b82e\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/dribbble.com\/shots\/10374655-Work-Hard\" target=\"_blank\" rel=\"noopener nofollow noreferrer\" rel=\"nofollow\" ><em class=\"lk\"><span>\u4e4c\u5170\uff08Uran\uff09\u5728Dribbble\u4e0a\u52aa\u529b\u5de5\u4f5c<\/span><\/em><\/a><\/p>\n<p id=\"1d68\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\"><em class=\"lk\"><span>\u6b64\u4efb\u52a1\u662f\u53ef\u9009\u7684\uff01\u5982\u679c\u60a8\u60f3\u8df3\u8fc7\u6240\u6709\u95ee\u9898\uff0c\u53ea\u9700\u5355\u51fb\u201c\u5b8c\u6210\u201d\u3002\u672c\u90e8\u5206\u7eaf\u7cb9\u662f\u4e3a\u4e86\u5728\u6574\u4e2a\u4f1a\u8bae\u5ba4\u4e2d\u4f7f\u7528Burp Suite\u65f6\u6539\u5584\u201c\u751f\u6d3b\u8d28\u91cf\u201d\u3002\u60a8\u53ef\u4ee5\u5728\u4efb\u52a1\u516b\u7684\u95ee\u9898\u4e09\u4e2d\u770b\u5230\u6697\u6a21\u5f0f\u3002<\/span><\/em><\/strong><\/p>\n<p id=\"8fa6\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\"><span>\uff031<\/span><\/strong><\/p>\n<p id=\"0e33\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u542f\u52a8Burp Suite\u540e\uff0c\u8ba9\u6211\u4eec\u9996\u5148\u5bfc\u822a\u5230\u201c\u7528\u6237\u9009\u9879\u201d\u6807\u7b7e\u3002<\/span><\/p>\n<figure class=\"ig ih ii ij ik il fn fo paragraph-image\">\n<div class=\"fn fo nc\">\n<div class=\"is r cc fb\">\n<div class=\"nd iu r\">\n<div class=\"cb ip s t u ds ai bu iq ir\"><img loading=\"lazy\" decoding=\"async\" class=\"s t u ds ai iv iw ap uu\" data-original=\"https:\/\/miro.medium.com\/max\/60\/0*plFYzKiDawFHHv7V.png?q=20\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" width=\"227\" height=\"91\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe37\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe37\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"eg ul s t u ds ai c\" data-original=\"https:\/\/miro.medium.com\/max\/284\/0*plFYzKiDawFHHv7V.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" sizes=\"auto, 227px\" srcset=\"\" width=\"227\" height=\"91\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe38\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe38\" \/><\/div>\n<\/div>\n<\/div>\n<\/figure>\n<p id=\"f21b\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\"><span>\uff032<\/span><\/strong><\/p>\n<p id=\"f2fd\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u63a5\u4e0b\u6765\uff0c\u70b9\u51fb\u201c\u663e\u793a\u201d\u5b50\u6807\u7b7e\u3002<\/span><\/p>\n<figure class=\"ig ih ii ij ik il fn fo paragraph-image\">\n<div class=\"fn fo ne\">\n<div class=\"is r cc fb\">\n<div class=\"nf iu r\">\n<div class=\"cb ip s t u ds ai bu iq ir\"><img loading=\"lazy\" decoding=\"async\" class=\"s t u ds ai iv iw ap uu\" data-original=\"https:\/\/miro.medium.com\/max\/60\/0*aE1BsxfL0Pm9K0EB.png?q=20\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" width=\"255\" height=\"85\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe39\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe39\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"eg ul s t u ds ai c\" data-original=\"https:\/\/miro.medium.com\/max\/319\/0*aE1BsxfL0Pm9K0EB.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" sizes=\"auto, 255px\" srcset=\"\" width=\"255\" height=\"85\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe40\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe40\" \/><\/div>\n<\/div>\n<\/div>\n<\/figure>\n<p id=\"19db\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\"><span>\uff033<\/span><\/strong><\/p>\n<p id=\"f097\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u73b0\u5728\uff0c\u5355\u51fb\u201c\u5916\u89c2\u201d\u4e0b\u62c9\u83dc\u5355\u3002\u9009\u62e9\u201c Darcula\u201d\u3002<\/span><\/p>\n<figure class=\"ig ih ii ij ik il fn fo paragraph-image\">\n<div class=\"fn fo ng\">\n<div class=\"is r cc fb\">\n<div class=\"nh iu r\">\n<div class=\"cb ip s t u ds ai bu iq ir\"><img loading=\"lazy\" decoding=\"async\" class=\"s t u ds ai iv iw ap uu\" data-original=\"https:\/\/miro.medium.com\/max\/60\/0*pJV69FHRAj7l4bwn.png?q=20\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" width=\"412\" height=\"364\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe41\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe41\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"eg ul s t u ds ai c\" data-original=\"https:\/\/miro.medium.com\/max\/515\/0*pJV69FHRAj7l4bwn.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" sizes=\"auto, 412px\" srcset=\"https:\/\/miro.medium.com\/max\/345\/0*pJV69FHRAj7l4bwn.png 276w, https:\/\/miro.medium.com\/max\/515\/0*pJV69FHRAj7l4bwn.png 412w\" width=\"412\" height=\"364\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe42\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe42\" \/><\/div>\n<\/div>\n<\/div>\n<\/figure>\n<p id=\"9669\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\"><span>\uff034<\/span><\/strong><\/p>\n<p id=\"f109\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u6700\u540e\uff0c\u5173\u95ed\u5e76\u91cd\u65b0\u542f\u52a8Burp Suite\uff0c\u4ee5\u4f7f\u6df1\u8272\u4e3b\u9898\uff08\u6216\u60a8\u9009\u62e9\u7684\u4efb\u4f55\u4e3b\u9898\uff09\u751f\u6548\u3002<\/span><\/p>\n<\/div>\n<\/div>\n<\/section>\n<hr class=\"iy hb iz ja bx jb jc jd je jf jg jh\" \/>\n<section class=\"ft fu fv fw fx\">\n<div class=\"n p\">\n<div class=\"z ab ac ae af fy ah ai\">\n<h1 id=\"3a01\" class=\"ji jj bi bh et jk jl jm jn jo jp jq jr js jt ju jv jw jx jy jz cs\" data-selectable-paragraph=\"\"><span>\u4ee3\u7406<\/span><\/h1>\n<p id=\"6d3a\" class=\"ka kb bi kc b kd ke kf kg kh ki kj kk kl km kn ko kp kq kr ks kt ku kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u4e00\u822c\u800c\u8a00\uff0c\u6839\u636e\u5b9a\u4e49\uff0c\u4ee3\u7406\u670d\u52a1\u5668\u4f7f\u6211\u4eec\u80fd\u591f\u901a\u8fc7\u66ff\u4ee3\u8def\u7531\u5c06\u6d41\u91cf\u4e2d\u7ee7\u5230Internet\u3002\u8fd9\u6837\u505a\u7684\u539f\u56e0\u6709\u5f88\u591a\uff0c\u4ece\u6559\u80b2\u8fc7\u6ee4\uff08\u5728\u5b66\u6821\u4e2d\u901a\u5e38\u5fc5\u987b\u963b\u6b62\u53d7\u9650\u5236\u7684\u5185\u5bb9\u7684\u60c5\u51b5\u4e0b\u8fdb\u884c\u8fc7\u6ee4\uff09\u5230\u8bbf\u95ee\u7531\u4e8e\u533a\u57df\u9501\u5b9a\u6216\u7981\u4ee4\u800c\u65e0\u6cd5\u83b7\u5f97\u7684\u5185\u5bb9\u3002\u4f46\u662f\uff0c\u901a\u8fc7\u4f7f\u7528\u4ee3\u7406\u8fdb\u884cWeb\u5e94\u7528\u7a0b\u5e8f\u6d4b\u8bd5\uff0c\u6211\u4eec\u53ef\u4ee5\u7ec6\u7c92\u5ea6\u67e5\u770b\u548c\u4fee\u6539\u5185\u8054\u6d41\u91cf\u3002\u5728\u6574\u4e2a\u4efb\u52a1\u4e2d\uff0c\u6211\u4eec\u5c06\u63a2\u7d22Burp\u4ee3\u7406\u7684\u4e3b\u8981\u7ec4\u6210\u90e8\u5206\uff0c\u5305\u62ec\u62e6\u622a\uff0c\u8bf7\u6c42\u5386\u53f2\u8bb0\u5f55\u4ee5\u53ca\u6211\u4eec\u53ef\u4ee5\u8bbf\u95ee\u7684\u5404\u79cd\u914d\u7f6e\u9009\u9879\u3002<\/span><\/p>\n<figure class=\"ig ih ii ij ik il fn fo paragraph-image\">\n<div class=\"im in cc io ai\">\n<div class=\"fn fo ni\">\n<div class=\"is r cc fb\">\n<div class=\"nj iu r\">\n<div class=\"cb ip s t u ds ai bu iq ir\"><img loading=\"lazy\" decoding=\"async\" class=\"s t u ds ai iv iw ap uu\" data-original=\"https:\/\/miro.medium.com\/max\/60\/0*yNW1Mowj7jYQrQnB.png?q=20\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" width=\"1280\" height=\"480\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe43\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe43\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"eg ul s t u ds ai c\" data-original=\"https:\/\/miro.medium.com\/max\/1600\/0*yNW1Mowj7jYQrQnB.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" sizes=\"auto, 700px\" srcset=\"https:\/\/miro.medium.com\/max\/345\/0*yNW1Mowj7jYQrQnB.png 276w, https:\/\/miro.medium.com\/max\/690\/0*yNW1Mowj7jYQrQnB.png 552w, https:\/\/miro.medium.com\/max\/800\/0*yNW1Mowj7jYQrQnB.png 640w, https:\/\/miro.medium.com\/max\/875\/0*yNW1Mowj7jYQrQnB.png 700w\" width=\"1280\" height=\"480\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe44\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe44\" \/><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/figure>\n<p id=\"2d37\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><em class=\"lk\"><span>\u901a\u8fc7\u4ee3\u7406\u4e2d\u7ee7\u901a\u4fe1\u7684\u57fa\u672c\u793a\u610f\u56fe\u2014\u00a0<\/span><\/em><a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/en.wikipedia.org\/wiki\/Proxy_server\" target=\"_blank\" rel=\"noopener nofollow noreferrer\" rel=\"nofollow\" ><em class=\"lk\"><span>\u7ef4\u57fa\u767e\u79d1\u2014\u4ee3\u7406\u670d\u52a1\u5668<\/span><\/em><\/a><\/p>\n<p id=\"a122\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u5728\u83b7\u5f97Gettin's [CA]\u8ba4\u8bc1\u7684\u4efb\u52a1\u4e09\u4e2d\uff0c\u6211\u4eec\u5c06\u7f51\u7edc\u6d41\u91cf\u914d\u7f6e\u4e3a\u901a\u8fc7Burp Suite\u5b9e\u4f8b\u8fdb\u884c\u8def\u7531\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u201c\u6253p\u201d\u5c06\u8bbe\u7f6e\u4e3a\u201c\u62e6\u622a\u201d\u6211\u4eec\u7684\u6d41\u91cf\u3002\u8fd9\u610f\u5473\u7740\u51e0\u4ef6\u4e8b\uff1a<\/span><\/p>\n<p id=\"7719\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>1.\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u8bf7\u6c42\u5c06\u9700\u8981\u6211\u4eec\u7684\u6388\u6743\u3002<\/span><\/p>\n<p id=\"e6fe\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>2.\u6211\u4eec\u53ef\u4ee5\u50cf\u5728\u4e2d\u95f4\u4eba\u653b\u51fb\u4e2d\u770b\u5230\u7684\u90a3\u6837\uff0c\u5728\u7ebf\u4fee\u6539\u6211\u4eec\u7684\u8bf7\u6c42\uff0c\u7136\u540e\u5c06\u5176\u53d1\u9001\u3002<\/span><\/p>\n<p id=\"7aff\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>3.\u6211\u4eec\u8fd8\u53ef\u4ee5\u5220\u9664\u6211\u4eec\u4e0d\u60f3\u53d1\u9001\u7684\u8bf7\u6c42\u3002\u8fd9\u5bf9\u4e8e\u5728\u5355\u51fb\u6309\u94ae\u6216\u5728\u7f51\u7ad9\u4e0a\u6267\u884c\u5176\u4ed6\u64cd\u4f5c\u540e\u67e5\u770b\u8bf7\u6c42\u5c1d\u8bd5\u5f88\u6709\u7528\u3002<\/span><\/p>\n<p id=\"f57c\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>4.\u6700\u540e\u4f46\u5e76\u975e\u6700\u4e0d\u91cd\u8981\u7684\u4e00\u70b9\u662f\uff0c\u6211\u4eec\u53ef\u4ee5\u5c06\u8fd9\u4e9b\u8bf7\u6c42\u53d1\u9001\u5230\u5176\u4ed6\u5de5\u5177\uff0c\u4f8b\u5982Repeater\u548cIntruder\uff0c\u4ee5\u8fdb\u884c\u4fee\u6539\u548c\u64cd\u4f5c\u4ee5\u8bf1\u53d1\u6f0f\u6d1e\u3002<\/span><\/p>\n<p id=\"3181\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><em class=\"lk\"><span>\u4ee3\u7406\u7684Burp Suite\u53c2\u8003\u6587\u6863\uff1a<\/span><\/em><a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/portswigger.net\/burp\/documentation\/desktop\/tools\/proxy\" target=\"_blank\" rel=\"noopener nofollow noreferrer\" rel=\"nofollow\" ><em class=\"lk\"><span>\u94fe\u63a5<\/span><\/em><\/a><\/p>\n<p id=\"a051\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\uff031<\/span><\/p>\n<p id=\"ca98\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u90e8\u7f72\u6b64\u4efb\u52a1\u9644\u5e26\u7684VM\uff01<\/span><\/p>\n<p id=\"70bc\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u8981\u5b8c\u6210\u6b64\u4efb\u52a1\uff0c\u60a8\u9700\u8981\u901a\u8fc7<\/span><a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/tryhackme.com\/connect\" target=\"_blank\" rel=\"noopener nofollow noreferrer\" rel=\"nofollow\" ><span>OpenVPN<\/span><\/a><span>\u8fde\u63a5\u5230TryHackMe\u7f51\u7edc\u3002\u5982\u679c\u60a8\u4f7f\u7528\u7684<\/span><a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/tryhackme.com\/my-machine\" target=\"_blank\" rel=\"noopener nofollow noreferrer\" rel=\"nofollow\" ><span>\u662f\u6d4f\u89c8\u5668\u5185<\/span><\/a><span>\u8ba1\u7b97\u673a\uff0c\u5219\u4e0d\u9700\u8981\u8fd9\u6837\u505a\uff08\u4f46\u8bf7\u786e\u4fdd\u60a8\u6b63\u5728\u8bbf\u95ee\u8be5\u8ba1\u7b97\u673a\u5e76\u5728\u6d4f\u89c8\u5668\u5185\u8ba1\u7b97\u673a\u5185\u90e8\u4f7f\u7528Burp\uff09\u3002<\/span><\/p>\n<p id=\"5db3\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\"><span>\uff032<\/span><\/strong><\/p>\n<p id=\"3fc8\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0cBurp Suite\u4ee3\u7406\u4ec5\u5728\u4e00\u4e2a\u63a5\u53e3\u4e0a\u4fa6\u542c\u3002\u5b83\u662f\u4ec0\u4e48\uff1f<\/span><em class=\"lk\"><span>\u4f7f\u7528IP\uff1aPORT\u7684\u683c\u5f0f<\/span><\/em><\/p>\n<pre class=\"ig ih ii ij ik mt mu mv\"><span id=\"3154\" class=\"cs mw jj bi mx b ca my mz r na\" data-selectable-paragraph=\"\"><span>127.0.0.1:8080<\/span><\/span><\/pre>\n<p id=\"9d60\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\"><span>\uff033<\/span><\/strong><\/p>\n<p id=\"b6dd\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u5728Burp Suite\u4e2d\uff0c\u5bfc\u822a\u5230\u201c\u4ee3\u7406\u201d\u90e8\u5206\u7684\u201c\u62e6\u622a\u201d\u5b50\u9009\u9879\u5361\u3002\u542f\u7528\u62e6\u622a<\/span><\/p>\n<p id=\"5445\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\"><span>\uff034<\/span><\/strong><\/p>\n<p id=\"97c2\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">Return to your web browser and navigate to the web application hosted on the VM we deployed just a bit ago. Note that the page appears to be continuously loading. Change back to Burp Suite, we now have a request that\u2019s waiting in our intercept tab. Take a look at the actions, which\u00a0<strong class=\"kc lq\">shortcut<\/strong>\u00a0allows us to forward the request to Repeater?<\/p>\n<pre class=\"ig ih ii ij ik mt mu mv\"><span id=\"3735\" class=\"cs mw jj bi mx b ca my mz r na\" data-selectable-paragraph=\"\">ctrl-R<\/span><\/pre>\n<p id=\"37b6\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">#5<\/strong><\/p>\n<p id=\"6363\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">How about if we wanted to forward our request to Intruder?<\/p>\n<pre class=\"ig ih ii ij ik mt mu mv\"><span id=\"db42\" class=\"cs mw jj bi mx b ca my mz r na\" data-selectable-paragraph=\"\">ctrl-i<\/span><\/pre>\n<p id=\"c07b\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">#6<\/strong><\/p>\n<p id=\"4aab\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">Burp Suite saves the history of requests sent through the proxy along with their varying details. This can be especially useful when we need to have proof of our actions throughout a penetration test or we want to modify and resend a request we sent a while back. What is the name of the first section wherein general web requests (GET\/POST) are saved?<\/p>\n<pre class=\"ig ih ii ij ik mt mu mv\"><span id=\"a771\" class=\"cs mw jj bi mx b ca my mz r na\" data-selectable-paragraph=\"\">http history<\/span><\/pre>\n<p id=\"e914\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">#7<\/strong><\/p>\n<p id=\"f30b\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">Defined in RFC 6455 as a low-latency communication protocol that doesn\u2019t require HTTP encapsulation, what is the name of the second section of our saved history in Burp Suite? These are commonly used in collaborate application which require real-time updates (Google Docs is an excellent example here).<\/p>\n<pre class=\"ig ih ii ij ik mt mu mv\"><span id=\"1b60\" class=\"cs mw jj bi mx b ca my mz r na\" data-selectable-paragraph=\"\">websocket history<\/span><\/pre>\n<p id=\"bf00\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">#8<\/strong><\/p>\n<p id=\"7779\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">Before we move onto exploring our target definition, let\u2019s take a look at some of the advanced customization we can utilize in the Burp proxy. Move over to the Options section of the Proxy tab and scroll down to Intercept Client Requests. Here we can apply further fine-grained rules to define which requests we would like to intercept. Perhaps the most useful out of the default rules is our only AND rule. What is it\u2019s match type?<\/p>\n<pre class=\"ig ih ii ij ik mt mu mv\"><span id=\"3cdc\" class=\"cs mw jj bi mx b ca my mz r na\" data-selectable-paragraph=\"\">URL<\/span><\/pre>\n<p id=\"ecfb\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">#9<\/strong><\/p>\n<p id=\"bdad\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">How about it\u2019s \u2018Relationship\u2019?\u00a0<em class=\"lk\">In this situation, enabling this match rule can be incredibly useful following target definition as we can effectively leave intercept on permanently (unless we need to navigate without intercept) as it won\u2019t disturb sites which are outside of our scope \u2014 something which is particularly nice if we need to Google something in the same browser.<\/em><\/p>\n<pre class=\"ig ih ii ij ik mt mu mv\"><span id=\"f9ec\" class=\"cs mw jj bi mx b ca my mz r na\" data-selectable-paragraph=\"\">is in target scope<\/span><\/pre>\n<\/div>\n<\/div>\n<\/section>\n<hr class=\"iy hb iz ja bx jb jc jd je jf jg jh\" \/>\n<section class=\"ft fu fv fw fx\">\n<div class=\"n p\">\n<div class=\"z ab ac ae af fy ah ai\">\n<h1 id=\"f4b8\" class=\"ji jj bi bh et jk jl jm jn jo jp jq jr js jt ju jv jw jx jy jz cs\" data-selectable-paragraph=\"\">Target Definition<\/h1>\n<p id=\"1077\" class=\"ka kb bi kc b kd ke kf kg kh ki kj kk kl km kn ko kp kq kr ks kt ku kv kw kx ft cs\" data-selectable-paragraph=\"\">Perhaps the most important feature in Burp Suite, we\u2019ll now be turning our focus to the Target tab!<\/p>\n<figure class=\"ig ih ii ij ik il fn fo paragraph-image\">\n<div class=\"im in cc io ai\">\n<div class=\"fn fo if\">\n<div class=\"is r cc fb\">\n<div class=\"ms iu r\">\n<div class=\"cb ip s t u ds ai bu iq ir\"><img loading=\"lazy\" decoding=\"async\" class=\"s t u ds ai iv iw ap uu\" data-original=\"https:\/\/miro.medium.com\/max\/60\/0*-bnAltONYnMnAUmc.jpg?q=20\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" width=\"800\" height=\"600\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe45\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe45\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"eg ul s t u ds ai c\" data-original=\"https:\/\/miro.medium.com\/max\/1000\/0*-bnAltONYnMnAUmc.jpg\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" sizes=\"auto, 700px\" srcset=\"https:\/\/miro.medium.com\/max\/345\/0*-bnAltONYnMnAUmc.jpg 276w, https:\/\/miro.medium.com\/max\/690\/0*-bnAltONYnMnAUmc.jpg 552w, https:\/\/miro.medium.com\/max\/800\/0*-bnAltONYnMnAUmc.jpg 640w, https:\/\/miro.medium.com\/max\/875\/0*-bnAltONYnMnAUmc.jpg 700w\" width=\"800\" height=\"600\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe46\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe46\" \/><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/figure>\n<p id=\"9c77\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/dribbble.com\/shots\/2363233-Lock-On-Target\" target=\"_blank\" rel=\"noopener nofollow noreferrer\" rel=\"nofollow\" ><em class=\"lk\">Lock on Target by Alexei Vella on Dribbble<\/em><\/a><\/p>\n<p id=\"e33c\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">The Target tab in Burp allows us to perform arguably some of the most important parts of a web application penetration test: defining our scope, viewing a site map, and specifying our issue definitions (although this is more useful within report generation and scanning).<\/p>\n<p id=\"724f\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">When starting a web application test you\u2019ll very likely be provided a few things:<\/p>\n<p id=\"8d83\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">- The application URL (hopefully for dev\/test and not prod)<br \/>\n- A list of the different user roles within the application<br \/>\n- Various test accounts and associated credentials for those accounts<br \/>\n- A list of pieces\/forms in the application which are out-of-scope for testing and should be avoided<\/p>\n<p id=\"a3c9\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">From this information, we can now start to build our scope within Burp, something which is incredibly important in the case we are planning on performing any automated testing. Typically this is done in a tiered approach wherein we work our way up from the lowest privileged account (this includes unauthenticated access), browsing the site as a normal user would. Browsing like this to discover the full extent of the site is commonly referenced as the \u2018happy path\u2019. Following the creation of a site map via browsing the happy path, we can go through and start removing various items from the scope. These items typically fit one of these criteria:<\/p>\n<p id=\"5688\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">- The item (page, form, etc) has been designated as out of scope in the provided documentation from the client<br \/>\n- Automated exploitation of the item (especially in a credentialed manner) would cause a huge mess (like sending hundreds of password reset emails \u2014 If you\u2019ve done a web app professionally you\u2019ve probably done this at one point)<br \/>\n- Automated exploitation of the item (especially in a credentialed manner) would lead to damaging and potentially crashing the web app<\/p>\n<p id=\"5093\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">Once we\u2019ve removed any restricted or otherwise potentially dangerous items from our scope, we can move onto other areas of testing with the various tools within Burp Suite.<\/p>\n<p id=\"683d\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><em class=\"lk\">Burp Suite reference documentation for Target:\u00a0<\/em><a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/portswigger.net\/burp\/documentation\/desktop\/tools\/target\" target=\"_blank\" rel=\"noopener nofollow noreferrer\" rel=\"nofollow\" ><em class=\"lk\">Link<\/em><\/a><\/p>\n<\/div>\n<\/div>\n<\/section>\n<hr class=\"iy hb iz ja bx jb jc jd je jf jg jh\" \/>\n<section class=\"ft fu fv fw fx\">\n<div class=\"n p\">\n<div class=\"z ab ac ae af fy ah ai\">\n<p id=\"a853\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">#1<\/strong><\/p>\n<p id=\"c858\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">Before leaving the Proxy tab, switch Intercept to disabled. We\u2019ll still see the pages we navigate to in our history and the target tab, just having Intercept constantly stopping our requests for this next bit will get old fast.<\/p>\n<p id=\"8071\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">#2<\/strong><\/p>\n<p id=\"aa1d\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">Navigate to the Target tab in Burp. In our last task, Proxy, we browsed to the website on our target machine (in this case OWASP Juice Shop). Find our target site in this list and right-click on it. Select \u2018Add to scope\u2019.<\/p>\n<p id=\"72f7\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">#3<\/strong><\/p>\n<p id=\"e9d7\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">Clicking \u2018Add to scope\u2019 will trigger a pop-up. This will stop Burp from sending out-of-scope items to our site map.<\/p>\n<p id=\"988e\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">#4<\/strong><\/p>\n<p id=\"1a9f\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">Select \u2018Yes\u2019 to close the popup.<\/p>\n<p id=\"1582\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">#5<\/strong><\/p>\n<p id=\"24fe\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u6d4f\u89c8\u5e94\u7528\u7a0b\u5e8f\u7684\u5176\u4f59\u90e8\u5206\uff0c\u4ee5\u5728\u76ee\u6807\u9009\u9879\u5361\u4e2d\u6784\u5efa\u6211\u4eec\u7684\u9875\u9762\u7ed3\u6784\u3002\u8bbf\u95ee\u5b8c\u7f51\u7ad9\u7684\u5927\u90e8\u5206\u9875\u9762\u540e\uff0c\u8bf7\u8fd4\u56deBurp Suite\u5e76\u5c55\u5f00\u5e94\u7528\u7a0b\u5e8f\u76ee\u5f55\u7684\u5404\u4e2a\u7ea7\u522b\u3002\u6211\u4eec\u5982\u4f55\u79f0\u547c\u8fd9\u79cd\u96c6\u5408Web\u5e94\u7528\u7a0b\u5e8f\u7684\u8868\u793a\uff1f<\/span><\/p>\n<pre class=\"ig ih ii ij ik mt mu mv\"><span id=\"405f\" class=\"cs mw jj bi mx b ca my mz r na\" data-selectable-paragraph=\"\"><span>\u7f51\u7ad9\u5730\u56fe<\/span><\/span><\/pre>\n<p id=\"92cb\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\"><span>\uff036<\/span><\/strong><\/p>\n<p id=\"6a95\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u5728\u8fdb\u4e00\u6b65\u68c0\u67e5\u4e4b\u524d\uff0c\u4ee5\u666e\u901a\u7528\u6237\u8eab\u4efd\u6d4f\u89c8\u5e94\u7528\u7a0b\u5e8f\u7684\u672f\u8bed\u662f\u4ec0\u4e48\uff1f<\/span><\/p>\n<pre class=\"ig ih ii ij ik mt mu mv\"><span id=\"d9e3\" class=\"cs mw jj bi mx b ca my mz r na\" data-selectable-paragraph=\"\"><span>\u5e78\u798f\u7684\u9053\u8def<\/span><\/span><\/pre>\n<p id=\"9b2e\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\"><span>\uff037<\/span><\/strong><\/p>\n<p id=\"336e\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u5728\u7ee7\u7eed\u4e4b\u524d\u7684\u6700\u540e\u4e00\u4ef6\u4e8b\u3002\u5728\u76ee\u6807\u9009\u9879\u5361\u4e2d\uff0c\u60a8\u53ef\u80fd\u5df2\u7ecf\u6ce8\u610f\u5230\u95ee\u9898\u5b9a\u4e49\u7684\u5b50\u9009\u9879\u5361\u3002\u73b0\u5728\u70b9\u51fb\u8fdb\u5165\u3002<\/span><\/p>\n<p id=\"ff30\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\"><span>\uff038<\/span><\/strong><\/p>\n<p id=\"451c\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u6b64\u5904\u627e\u5230\u7684\u95ee\u9898\u5b9a\u4e49\u662fBurp Suite\u5982\u4f55\u5b9a\u4e49\u62a5\u544a\u4e2d\u7684\u95ee\u9898\u3002\u5728\u5f00\u59cb\u65f6\uff0c\u8fd9\u4e9b\u95ee\u9898\u5b9a\u4e49\u5bf9\u4e8e\u7406\u89e3\u548c\u5206\u7c7b\u6211\u4eec\u53ef\u80fd\u62e5\u6709\u7684\u5404\u79cd\u53d1\u73b0\u7279\u522b\u6709\u7528\u3002\u5f53\u9ad8\u901f\u7f13\u5b58\u8fdb\u7a0b\u80cc\u540e\u7684\u5e94\u7528\u7a0b\u5e8f\u8f93\u5165\u672a\u5305\u542b\u5728\u9ad8\u901f\u7f13\u5b58\u5bc6\u94a5\u4e2d\u65f6\uff0c\u4f1a\u51fa\u73b0\u54ea\u4e2a\u4e2d\u6bd2\u95ee\u9898\uff1f<\/span><\/p>\n<pre class=\"ig ih ii ij ik mt mu mv\"><span id=\"f39b\" class=\"cs mw jj bi mx b ca my mz r na\" data-selectable-paragraph=\"\"><span>Web\u7f13\u5b58\u4e2d\u6bd2<\/span><\/span><\/pre>\n<\/div>\n<\/div>\n<\/section>\n<hr class=\"iy hb iz ja bx jb jc jd je jf jg jh\" \/>\n<section class=\"ft fu fv fw fx\">\n<div class=\"n p\">\n<div class=\"z ab ac ae af fy ah ai\">\n<h1 id=\"17bf\" class=\"ji jj bi bh et jk jl jm jn jo jp jq jr js jt ju jv jw jx jy jz cs\" data-selectable-paragraph=\"\"><span>\u5c06\u6240\u6709\u5185\u5bb9\u91cd\u590d\u653e\u7f6e[er]<\/span><\/h1>\n<p id=\"16e8\" class=\"ka kb bi kc b kd ke kf kg kh ki kj kk kl km kn ko kp kq kr ks kt ku kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u987e\u540d\u601d\u4e49\uff0cRepeater\u5141\u8bb8\u6211\u4eec\u91cd\u590d\u5df2\u7ecf\u53d1\u51fa\u7684\u8bf7\u6c42\u3002\u8fd9\u4e9b\u8bf7\u6c42\u53ef\u4ee5\u6309\u539f\u6837\u91cd\u65b0\u53d1\u5e03\uff0c\u4e5f\u53ef\u4ee5\u8fdb\u884c\u4fee\u6539\u3002\u4e0e\u5165\u4fb5\u8005\u76f8\u6bd4\uff0c\u4e2d\u7ee7\u5668\u901a\u5e38\u7528\u4e8e\u5b9e\u9a8c\u6216\u66f4\u7cbe\u7ec6\u7684\u5f00\u53d1\u76ee\u7684\uff0c\u5176\u4e2d\u53ef\u80fd\u4e0d\u9700\u8981\u81ea\u52a8\u5316\u3002\u6211\u4eec\u5c06\u68c0\u67e5Repeater\u7684\u76ee\u7684\u662f\u627e\u5230\u4e00\u4e2a\u6982\u5ff5\u8bc1\u660e\uff0c\u8bc1\u660eJuice Shop\u5bb9\u6613\u53d7\u5230SQL\u6ce8\u5165\u7684\u653b\u51fb\u3002<\/span><\/p>\n<figure class=\"ig ih ii ij ik il fn fo paragraph-image\">\n<div class=\"im in cc io ai\">\n<div class=\"fn fo nb\">\n<div class=\"is r cc fb\">\n<div class=\"ms iu r\">\n<div class=\"cb ip s t u ds ai bu iq ir\"><img loading=\"lazy\" decoding=\"async\" class=\"s t u ds ai iv iw ap uu\" data-original=\"https:\/\/miro.medium.com\/max\/60\/0*Gpfzh42QvbPr_3QC.png?q=20\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" width=\"1600\" height=\"1200\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe47\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe47\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"eg ul s t u ds ai c\" data-original=\"https:\/\/miro.medium.com\/max\/2000\/0*Gpfzh42QvbPr_3QC.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" sizes=\"auto, 700px\" srcset=\"https:\/\/miro.medium.com\/max\/345\/0*Gpfzh42QvbPr_3QC.png 276w, https:\/\/miro.medium.com\/max\/690\/0*Gpfzh42QvbPr_3QC.png 552w, https:\/\/miro.medium.com\/max\/800\/0*Gpfzh42QvbPr_3QC.png 640w, https:\/\/miro.medium.com\/max\/875\/0*Gpfzh42QvbPr_3QC.png 700w\" width=\"1600\" height=\"1200\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe48\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe48\" \/><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/figure>\n<p id=\"012a\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/dribbble.com\/shots\/10090741-Record-Player\" target=\"_blank\" rel=\"noopener nofollow noreferrer\" rel=\"nofollow\" ><em class=\"lk\"><span>Briton Baker\u5728Dribbble\u4e0a\u7684\u7535\u5531\u673a<\/span><\/em><\/a><\/p>\n<p id=\"0460\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><em class=\"lk\"><span>Burp Suite\u4e2d\u7ee7\u5668\u53c2\u8003\u6587\u6863\uff1a<\/span><\/em><a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/portswigger.net\/burp\/documentation\/desktop\/tools\/repeater\" target=\"_blank\" rel=\"noopener nofollow noreferrer\" rel=\"nofollow\" ><em class=\"lk\"><span>\u94fe\u63a5<\/span><\/em><\/a><\/p>\n<\/div>\n<\/div>\n<\/section>\n<hr class=\"iy hb iz ja bx jb jc jd je jf jg jh\" \/>\n<section class=\"ft fu fv fw fx\">\n<div class=\"n p\">\n<div class=\"z ab ac ae af fy ah ai\">\n<p id=\"ae90\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\"><span>\uff031<\/span><\/strong><\/p>\n<p id=\"1964\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u9996\u5148\uff0c\u5355\u51fbJuice Shop\u53f3\u4e0a\u89d2\u7684\u201c\u5e10\u6237\u201d\uff08\u53d6\u51b3\u4e8eJuice Shop\u7684\u7248\u672c\uff0c\u53ef\u80fd\u662f\u201c\u767b\u5f55\u201d\uff09\u4ee5\u5bfc\u822a\u5230\u767b\u5f55\u9875\u9762\u3002<\/span><\/p>\n<figure class=\"ig ih ii ij ik il fn fo paragraph-image\">\n<div class=\"fn fo nk\">\n<div class=\"is r cc fb\">\n<div class=\"nl iu r\">\n<div class=\"cb ip s t u ds ai bu iq ir\"><img loading=\"lazy\" decoding=\"async\" class=\"s t u ds ai iv iw ap uu\" data-original=\"https:\/\/miro.medium.com\/max\/60\/0*7Ffys1BbIaaOzlEs.png?q=20\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" width=\"132\" height=\"50\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe49\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe49\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"eg ul s t u ds ai c\" data-original=\"https:\/\/miro.medium.com\/max\/165\/0*7Ffys1BbIaaOzlEs.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" sizes=\"auto, 132px\" srcset=\"\" width=\"132\" height=\"50\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe50\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe50\" \/><\/div>\n<\/div>\n<\/div>\n<\/figure>\n<p id=\"86ee\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\"><span>\uff032<\/span><\/strong><\/p>\n<p id=\"a9b5\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u5c1d\u8bd5\u4f7f\u7528\u65e0\u6548\u7684\u51ed\u636e\u767b\u5f55\u3002\u767b\u5f55\u5931\u8d25\u4f1a\u4ea7\u751f\u4ec0\u4e48\u9519\u8bef\uff1f<\/span><\/p>\n<figure class=\"ig ih ii ij ik il fn fo paragraph-image\">\n<div class=\"fn fo nm\">\n<div class=\"is r cc fb\">\n<div class=\"nn iu r\">\n<div class=\"cb ip s t u ds ai bu iq ir\"><img loading=\"lazy\" decoding=\"async\" class=\"s t u ds ai iv iw ap uu\" data-original=\"https:\/\/miro.medium.com\/max\/60\/0*7pM1OgaEk61CwDiJ.png?q=20\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" width=\"678\" height=\"626\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe51\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe51\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"eg ul s t u ds ai c\" data-original=\"https:\/\/miro.medium.com\/max\/848\/0*7pM1OgaEk61CwDiJ.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" sizes=\"auto, 678px\" srcset=\"https:\/\/miro.medium.com\/max\/345\/0*7pM1OgaEk61CwDiJ.png 276w, https:\/\/miro.medium.com\/max\/690\/0*7pM1OgaEk61CwDiJ.png 552w, https:\/\/miro.medium.com\/max\/800\/0*7pM1OgaEk61CwDiJ.png 640w, https:\/\/miro.medium.com\/max\/848\/0*7pM1OgaEk61CwDiJ.png 678w\" width=\"678\" height=\"626\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe52\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe52\" \/><\/div>\n<\/div>\n<\/div>\n<\/figure>\n<pre class=\"ig ih ii ij ik mt mu mv\"><span id=\"4425\" class=\"cs mw jj bi mx b ca my mz r na\" data-selectable-paragraph=\"\"><span>\u65e0\u6548\u7684\u7535\u5b50\u90ae\u4ef6\u6216\u5bc6\u7801<\/span><\/span><\/pre>\n<p id=\"1f1f\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\"><span>\uff033<\/span><\/strong><\/p>\n<p id=\"1db7\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u4f46\u662f\uff0c\u7b49\u7b49\uff0c\u6211\u4eec\u662f\u5426\u4e0d\u60f3\u5c06\u8be5\u8bf7\u6c42\u53d1\u9001\u7ed9Repeater\uff1f\u5373\u4f7f\u6211\u4eec\u6700\u521d\u6ca1\u6709\u901a\u8fc7\u62e6\u622a\u5c06\u5176\u53d1\u9001\u7ed9Repeater\uff0c\u6211\u4eec\u4ecd\u7136\u53ef\u4ee5\u5728\u5386\u53f2\u8bb0\u5f55\u4e2d\u627e\u5230\u8be5\u8bf7\u6c42\u3002\u5207\u6362\u5230\u201c\u4ee3\u7406\u201d\u7684\u201c HTTP\u201d\u5b50\u9009\u9879\u5361\u3002\u6d4f\u89c8\u8fd9\u4e9b\u8bf7\u6c42\uff0c\u76f4\u5230\u627e\u5230\u6211\u4eec\u5931\u8d25\u7684\u767b\u5f55\u5c1d\u8bd5\u3002<\/span><strong class=\"kc lq\"><span>\u53f3\u952e\u5355\u51fb\u6b64\u8bf7\u6c42\uff0c\u7136\u540e\u5c06\u5176\u53d1\u9001\u5230Repeater\uff0c\u7136\u540e\u518d\u5c06\u5176\u53d1\u9001\u5230Intruder\uff01<\/span><\/strong><\/p>\n<figure class=\"ig ih ii ij ik il fn fo paragraph-image\">\n<div class=\"im in cc io ai\">\n<div class=\"fn fo no\">\n<div class=\"is r cc fb\">\n<div class=\"np iu r\">\n<div class=\"cb ip s t u ds ai bu iq ir\"><img loading=\"lazy\" decoding=\"async\" class=\"s t u ds ai iv iw ap uu\" data-original=\"https:\/\/miro.medium.com\/max\/60\/0*Ny_kf7g75ZPs3P9c.png?q=20\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" width=\"968\" height=\"272\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe53\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe53\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"eg ul s t u ds ai c\" data-original=\"https:\/\/miro.medium.com\/max\/1210\/0*Ny_kf7g75ZPs3P9c.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" sizes=\"auto, 700px\" srcset=\"https:\/\/miro.medium.com\/max\/345\/0*Ny_kf7g75ZPs3P9c.png 276w, https:\/\/miro.medium.com\/max\/690\/0*Ny_kf7g75ZPs3P9c.png 552w, https:\/\/miro.medium.com\/max\/800\/0*Ny_kf7g75ZPs3P9c.png 640w, https:\/\/miro.medium.com\/max\/875\/0*Ny_kf7g75ZPs3P9c.png 700w\" width=\"968\" height=\"272\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe54\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe54\" \/><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/figure>\n<p id=\"0c7c\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\"><span>\uff034<\/span><\/strong><\/p>\n<p id=\"880d\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u73b0\u5728\uff0c\u6211\u4eec\u5df2\u5c06\u8bf7\u6c42\u53d1\u9001\u5230Repeater\uff0c\u8ba9\u6211\u4eec\u5c1d\u8bd5\u8c03\u6574\u8bf7\u6c42\uff0c\u4ee5\u4fbf\u6211\u4eec\u5c06\u5355\u5f15\u53f7\uff08'\uff09\u4f5c\u4e3a\u7535\u5b50\u90ae\u4ef6\u548c\u5bc6\u7801\u53d1\u9001\u3002\u6b64\u8bf7\u6c42\u4ea7\u751f\u4ec0\u4e48\u9519\u8bef\uff1f<\/span><\/p>\n<figure class=\"ig ih ii ij ik il fn fo paragraph-image\">\n<div class=\"fn fo nq\">\n<div class=\"is r cc fb\">\n<div class=\"nr iu r\">\n<div class=\"cb ip s t u ds ai bu iq ir\"><img loading=\"lazy\" decoding=\"async\" class=\"s t u ds ai iv iw ap uu\" data-original=\"https:\/\/miro.medium.com\/max\/60\/0*gOUbILhW2Tg8iY6E.png?q=20\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" width=\"698\" height=\"460\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe55\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe55\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"eg ul s t u ds ai c\" data-original=\"https:\/\/miro.medium.com\/max\/873\/0*gOUbILhW2Tg8iY6E.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" sizes=\"auto, 698px\" srcset=\"https:\/\/miro.medium.com\/max\/345\/0*gOUbILhW2Tg8iY6E.png 276w, https:\/\/miro.medium.com\/max\/690\/0*gOUbILhW2Tg8iY6E.png 552w, https:\/\/miro.medium.com\/max\/800\/0*gOUbILhW2Tg8iY6E.png 640w, https:\/\/miro.medium.com\/max\/873\/0*gOUbILhW2Tg8iY6E.png 698w\" width=\"698\" height=\"460\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe56\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe56\" \/><\/div>\n<\/div>\n<\/div>\n<\/figure>\n<pre class=\"ig ih ii ij ik mt mu mv\"><span id=\"ac1b\" class=\"cs mw jj bi mx b ca my mz r na\" data-selectable-paragraph=\"\"><span>SQLITE_ERROR<\/span><\/span><\/pre>\n<p id=\"f28d\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\"><span>\uff035<\/span><\/strong><\/p>\n<p id=\"b57c\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">Now that we\u2019ve leveraged Repeater to gain proof of concept that Juice Shop\u2019s login is vulnerable to SQLi, let\u2019s try something a little more mischievous and attempt to leave a devastating zero-star review. First, click on the drawer button in the top-left of the application.\u00a0<strong class=\"kc lq\">If this isn\u2019t present for you, just skip to the next question.<\/strong><\/p>\n<figure class=\"ig ih ii ij ik il fn fo paragraph-image\">\n<div class=\"fn fo ns\">\n<div class=\"is r cc fb\">\n<div class=\"nt iu r\">\n<div class=\"cb ip s t u ds ai bu iq ir\"><img loading=\"lazy\" decoding=\"async\" class=\"s t u ds ai iv iw ap uu\" data-original=\"https:\/\/miro.medium.com\/max\/60\/0*7ucZatMbTgvkWnkQ.png?q=20\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" width=\"78\" height=\"66\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe57\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe57\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"eg ul s t u ds ai c\" data-original=\"https:\/\/miro.medium.com\/max\/98\/0*7ucZatMbTgvkWnkQ.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" sizes=\"auto, 78px\" srcset=\"\" width=\"78\" height=\"66\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe58\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe58\" \/><\/div>\n<\/div>\n<\/div>\n<\/figure>\n<p id=\"334d\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">#6<\/strong><\/p>\n<p id=\"1147\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">Next, click on \u2018Customer Feedback\u2019 (depending on the version of Juice Shop this also might be along the top of the page next to \u2018Login\u2019 under \u2018Contact Us\u2019)<\/p>\n<figure class=\"ig ih ii ij ik il fn fo paragraph-image\">\n<div class=\"fn fo nu\">\n<div class=\"is r cc fb\">\n<div class=\"nv iu r\">\n<div class=\"cb ip s t u ds ai bu iq ir\"><img loading=\"lazy\" decoding=\"async\" class=\"s t u ds ai iv iw ap uu\" data-original=\"https:\/\/miro.medium.com\/max\/60\/0*z1Q9qk4lZKxzbT93.png?q=20\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" width=\"285\" height=\"66\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe59\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe59\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"eg ul s t u ds ai c\" data-original=\"https:\/\/miro.medium.com\/max\/356\/0*z1Q9qk4lZKxzbT93.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" sizes=\"auto, 285px\" srcset=\"https:\/\/miro.medium.com\/max\/345\/0*z1Q9qk4lZKxzbT93.png 276w, https:\/\/miro.medium.com\/max\/356\/0*z1Q9qk4lZKxzbT93.png 285w\" width=\"285\" height=\"66\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe60\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe60\" \/><\/div>\n<\/div>\n<\/div>\n<\/figure>\n<p id=\"5e05\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">#7<\/strong><\/p>\n<p id=\"6f96\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">With the Burp proxy on submit feedback. Once this is done, find the POST request in your HTTP History in Burp and send it to Repeater.<\/p>\n<p id=\"0563\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">#8<\/strong><\/p>\n<p id=\"c60b\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">What field do we have to modify in order to submit a zero-star review?<\/p>\n<pre class=\"ig ih ii ij ik mt mu mv\"><span id=\"bb80\" class=\"cs mw jj bi mx b ca my mz r na\" data-selectable-paragraph=\"\">rating<\/span><\/pre>\n<p id=\"c757\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">#9<\/strong><\/p>\n<p id=\"a8f2\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">Submit a zero-star review and complete this challenge in Juice Shop!<\/p>\n<\/div>\n<\/div>\n<\/section>\n<hr class=\"iy hb iz ja bx jb jc jd je jf jg jh\" \/>\n<section class=\"ft fu fv fw fx\">\n<div class=\"n p\">\n<div class=\"z ab ac ae af fy ah ai\">\n<h1 id=\"9679\" class=\"ji jj bi bh et jk jl jm jn jo jp jq jr js jt ju jv jw jx jy jz cs\" data-selectable-paragraph=\"\">Help! There\u2019s an Intruder!<\/h1>\n<p id=\"14fe\" class=\"ka kb bi kc b kd ke kf kg kh ki kj kk kl km kn ko kp kq kr ks kt ku kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>Intruder\u53ef\u4ee5\u8bf4\u662fBurp Suite\u4e2d\u529f\u80fd\u6700\u5f3a\u5927\u7684\u5de5\u5177\uff0c\u5b83\u53ef\u4ee5\u7528\u4e8e\u4ece\u6a21\u7cca\u6d4b\u8bd5\u5230\u66b4\u529b\u7834\u89e3\u7684\u8bb8\u591a\u4e8b\u60c5\u3002Intruder\u7684\u6838\u5fc3\u76ee\u7684\u4e4b\u4e00\u662f\uff1a\u81ea\u52a8\u5316\u3002<\/span><\/p>\n<p id=\"c032\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u5c3d\u7ba1Repeater\u53ef\u4ee5\u6700\u597d\u5730\u8fdb\u884c\u5b9e\u9a8c\u6216\u4e00\u6b21\u6027\u6d4b\u8bd5\uff0c\u4f46\u4e00\u65e6\u6982\u5ff5\u8bc1\u660e\u5df2\u7ecf\u5efa\u7acb\uff0cIntruder\u4fbf\u53ef\u4ee5\u8fdb\u884c\u91cd\u590d\u6d4b\u8bd5\u3002\u6839\u636e<\/span><a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/portswigger.net\/burp\/documentation\/desktop\/tools\/intruder\/using\" target=\"_blank\" rel=\"noopener nofollow noreferrer\" rel=\"nofollow\" ><span>Burp Suite\u6587\u6863<\/span><\/a><span>\uff0c\u4e00\u4e9b\u5e38\u89c1\u7528\u6cd5\u5982\u4e0b\uff1a<\/span><\/p>\n<p id=\"069b\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>-\u679a\u4e3e\u6807\u8bc6\u7b26\uff0c\u4f8b\u5982\u7528\u6237\u540d\uff0c\u5728\u53ef\u9884\u6d4b\u7684\u4f1a\u8bdd\/\u5bc6\u7801\u6062\u590d\u4ee4\u724c\u4e2d\u5faa\u73af\u4ee5\u53ca\u5c1d\u8bd5\u7b80\u5355\u7684\u5bc6\u7801\u731c\u6d4b<\/span><br \/>\n<span>-\u901a\u8fc7\u91cd\u590d\u6211\u4eec\u7684\u54cd\u5e94\u4ece\u7528\u6237\u4e2a\u4eba\u8d44\u6599\u6216\u5176\u4ed6\u611f\u5174\u8da3\u7684\u9875\u9762\u4e2d\u6536\u96c6\u6709\u7528\u7684\u6570\u636e<\/span><br \/>\n<span>-\u6a21\u7cca\u68c0\u6d4b\u6f0f\u6d1e\uff0c\u4f8b\u5982SQL\u6ce8\u5165\uff0c\u8de8\u7ad9\u70b9\u811a\u672c\uff08XSS\uff09\u548c\u6587\u4ef6\u8def\u5f84\u904d\u5386<\/span><\/p>\n<figure class=\"ig ih ii ij ik il fn fo paragraph-image\">\n<div class=\"im in cc io ai\">\n<div class=\"fn fo if\">\n<div class=\"is r cc fb\">\n<div class=\"ms iu r\">\n<div class=\"cb ip s t u ds ai bu iq ir\"><img loading=\"lazy\" decoding=\"async\" class=\"s t u ds ai iv iw ap uu\" data-original=\"https:\/\/miro.medium.com\/max\/60\/0*x5_u7y44OBug233J.jpg?q=20\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" width=\"800\" height=\"600\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe61\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe61\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"eg ul s t u ds ai c\" data-original=\"https:\/\/miro.medium.com\/max\/1000\/0*x5_u7y44OBug233J.jpg\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" sizes=\"auto, 700px\" srcset=\"https:\/\/miro.medium.com\/max\/345\/0*x5_u7y44OBug233J.jpg 276w, https:\/\/miro.medium.com\/max\/690\/0*x5_u7y44OBug233J.jpg 552w, https:\/\/miro.medium.com\/max\/800\/0*x5_u7y44OBug233J.jpg 640w, https:\/\/miro.medium.com\/max\/875\/0*x5_u7y44OBug233J.jpg 700w\" width=\"800\" height=\"600\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe62\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe62\" \/><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/figure>\n<p id=\"8fab\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/dribbble.com\/shots\/2384392-The-Overcoat-Nikolai-Gogol-Illustration\" target=\"_blank\" rel=\"noopener nofollow noreferrer\" rel=\"nofollow\" ><em class=\"lk\"><span>Chill Desk\u5728Dribbble\u4e0a\u7684\u5927\u8863<\/span><\/em><\/a><\/p>\n<p id=\"6f68\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u4e3a\u4e86\u5b8c\u6210\u8fd9\u4e9b\u5404\u79cd\u7528\u4f8b\uff0c\u5165\u4fb5\u8005\u5177\u6709<\/span><a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/portswigger.net\/burp\/documentation\/desktop\/tools\/intruder\/positions\" target=\"_blank\" rel=\"noopener nofollow noreferrer\" rel=\"nofollow\" ><span>\u56db\u79cd<\/span><\/a><span>\u4e0d\u540c\u7684\u653b\u51fb\u7c7b\u578b\uff1a<\/span><\/p>\n<p id=\"4f33\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>1.\u00a0<\/span><em class=\"lk\"><span>\u72d9\u51fb\u624b<\/span><\/em><span>\u00a0-\u6700\u53d7\u6b22\u8fce\u7684\u653b\u51fb\u7c7b\u578b\uff0c\u5b83\u5728\u6211\u4eec\u9009\u62e9\u7684\u4f4d\u7f6e\u4e4b\u95f4\u5faa\u73af\uff0c\u5c06\u4e0b\u4e00\u4e2a\u53ef\u7528\u7684\u6709\u6548\u8d1f\u8f7d\uff08\u6765\u81ea\u5355\u8bcd\u5217\u8868\u7684\u9879\u76ee\uff09\u4f9d\u6b21\u653e\u5728\u6bcf\u4e2a\u4f4d\u7f6e\u3002\u8fd9\u4ec5\u4f7f\u7528\u4e00\u7ec4\u6709\u6548\u8d1f\u8f7d\uff08\u4e00\u4e2a\u5355\u8bcd\u5217\u8868\uff09\u3002<\/span><\/p>\n<p id=\"4e80\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>2.\u00a0<\/span><em class=\"lk\"><span>Battering Ram<\/span><\/em><span>\u00a0\u2014\u4e0eSniper\u7c7b\u4f3c\uff0cBattering Ram\u4ec5\u4f7f\u7528\u4e00\u7ec4\u6709\u6548\u8f7d\u8377\u3002\u4e0eSniper\u4e0d\u540c\uff0cBattering Ram\u5c06\u6bcf\u4e2a\u6709\u6548\u8f7d\u8377\u653e\u7f6e\u5230\u6bcf\u4e2a\u9009\u5b9a\u7684\u4f4d\u7f6e\u3002\u8003\u8651\u4e00\u4e0b\u649e\u9524\u5982\u4f55\u4f7f\u5927\u8868\u9762\u4e0e\u5355\u4e2a\u8868\u9762\u63a5\u89e6\uff0c\u56e0\u6b64\uff0c\u8be5\u653b\u51fb\u7c7b\u578b\u7684\u540d\u79f0\u4e3a\u649e\u9524\u3002<\/span><\/p>\n<p id=\"3fa0\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>3.\u00a0<\/span><em class=\"lk\"><span>\u5e72\u8349\u53c9<\/span><\/em><span>\u00a0\u2014\u5e72\u8349\u53c9\u653b\u51fb\u7c7b\u578b\u4f7f\u6211\u4eec\u53ef\u4ee5\u4f7f\u7528\u591a\u4e2a\u6709\u6548\u8f7d\u8377\u96c6\uff08\u6bcf\u4e2a\u4f4d\u7f6e\u9009\u62e9\u4e00\u4e2a\uff09\u5e76<\/span><em class=\"lk\"><span>\u540c\u65f6<\/span><\/em><span>\u8fed\u4ee3\u4e24\u4e2a\u6709\u6548\u8f7d\u8377\u96c6\u3002\u4f8b\u5982\uff0c\u5982\u679c\u6211\u4eec\u9009\u62e9\u4e24\u4e2a\u4f4d\u7f6e\uff08\u4f8b\u5982\uff0c\u7528\u6237\u540d\u5b57\u6bb5\u548c\u5bc6\u7801\u5b57\u6bb5\uff09\uff0c\u5219\u53ef\u4ee5\u63d0\u4f9b\u7528\u6237\u540d\u548c\u5bc6\u7801\u6709\u6548\u8d1f\u8f7d\u5217\u8868\u3002\u7136\u540e\uff0c\u5165\u4fb5\u8005\u5c06\u5faa\u73af\u6d4f\u89c8\u7528\u6237\u540d\u548c\u5bc6\u7801\u7684\u7ec4\u5408\uff0c\u4ece\u800c\u5bfc\u81f4\u7ec4\u5408\u7684\u603b\u6570\u7b49\u4e8e\u6240\u63d0\u4f9b\u7684\u6700\u5c0f\u6709\u6548\u8f7d\u8377\u96c6\u3002<\/span><\/p>\n<p id=\"02cf\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>4.\u00a0<\/span><em class=\"lk\"><span>\u7fa4\u96c6\u70b8\u5f39<\/span><\/em><span>\u00a0\u2014\u7fa4\u96c6\u70b8\u5f39\u653b\u51fb\u7c7b\u578b\u4f7f\u6211\u4eec\u53ef\u4ee5\u4f7f\u7528\u591a\u4e2a\u6709\u6548\u8f7d\u8377\u96c6\uff08\u6bcf\u4e2a\u4f4d\u7f6e\u4e00\u4e2a\uff09\uff0c\u5e76\u904d\u5386\u6211\u4eec\u63d0\u4f9b\u7684\u6709\u6548\u8f7d\u8377\u5217\u8868\u7684\u6240\u6709\u7ec4\u5408\u3002\u4f8b\u5982\uff0c\u5982\u679c\u6211\u4eec\u9009\u62e9\u4e24\u4e2a\u4f4d\u7f6e\uff08\u4f8b\u5982\uff0c\u7528\u6237\u540d\u5b57\u6bb5\u548c\u5bc6\u7801\u5b57\u6bb5\uff09\uff0c\u5219\u53ef\u4ee5\u63d0\u4f9b\u7528\u6237\u540d\u548c\u5bc6\u7801\u6709\u6548\u8d1f\u8f7d\u5217\u8868\u3002\u7136\u540e\uff0c\u5165\u4fb5\u8005\u5c06\u5faa\u73af\u6d4f\u89c8\u7528\u6237\u540d\u548c\u5bc6\u7801\u7684\u7ec4\u5408\uff0c\u4ece\u800c\u5f97\u51fa\u7b49\u4e8e\u7528\u6237\u540dx\u5bc6\u7801\u7684\u7ec4\u5408\u603b\u6570\u3002<\/span><em class=\"lk\"><span>\u8bf7\u6ce8\u610f\uff0c\u5982\u679c\u60a8\u4f7f\u7528\u7684\u662fBurp\u793e\u533a\u7248\uff0c\u8fd9\u53ef\u80fd\u4f1a\u5f88\u957f\u3002<\/span><\/em><\/p>\n<figure class=\"ig ih ii ij ik il fn fo paragraph-image\">\n<div class=\"fn fo nw\">\n<div class=\"is r cc fb\">\n<div class=\"nx iu r\">\n<div class=\"cb ip s t u ds ai bu iq ir\"><img loading=\"lazy\" decoding=\"async\" class=\"s t u ds ai iv iw ap uu\" data-original=\"https:\/\/miro.medium.com\/max\/60\/0*O-DqaytDS468ZwqM.png?q=20\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" width=\"238\" height=\"117\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe63\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe63\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"eg ul s t u ds ai c\" data-original=\"https:\/\/miro.medium.com\/max\/298\/0*O-DqaytDS468ZwqM.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" sizes=\"auto, 238px\" srcset=\"\" width=\"238\" height=\"117\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe64\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe64\" \/><\/div>\n<\/div>\n<\/div>\n<\/figure>\n<p id=\"7690\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><em class=\"lk\"><span>\u5165\u4fb5\u8005\u653b\u51fb\u7c7b\u578b\u9009\u62e9<\/span><\/em><\/p>\n<p id=\"bbba\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u4e3a\u4e86\u6211\u4eec\u7684\u76ee\u7684\uff0c\u6211\u4eec\u5c06\u8fd4\u56de\u5230\u4ee5\u524d\u901a\u8fc7\u4f7f\u7528Repeater\u53d1\u73b0\u7684SQL\u6ce8\u5165\u6f0f\u6d1e\u3002<\/span><\/p>\n<p id=\"8123\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><em class=\"lk\">For some additional practice on using Intruder, check out the older\u00a0<\/em><a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/tryhackme.com\/room\/learnburp\" target=\"_blank\" rel=\"noopener nofollow noreferrer\" rel=\"nofollow\" ><em class=\"lk\">Learn Burp Suite room<\/em><\/a><em class=\"lk\">\u00a0here on TryHackMe<\/em><\/p>\n<p id=\"588f\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><em class=\"lk\">Burp Suite reference documentation for Intruder:\u00a0<\/em><a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/portswigger.net\/burp\/documentation\/desktop\/tools\/intruder\" target=\"_blank\" rel=\"noopener nofollow noreferrer\" rel=\"nofollow\" ><em class=\"lk\">Link<\/em><\/a><\/p>\n<\/div>\n<\/div>\n<\/section>\n<hr class=\"iy hb iz ja bx jb jc jd je jf jg jh\" \/>\n<section class=\"ft fu fv fw fx\">\n<div class=\"n p\">\n<div class=\"z ab ac ae af fy ah ai\">\n<p id=\"8802\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">#1<\/strong><\/p>\n<p id=\"9089\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">Which attack type allows us to select multiple payload sets (one per position) and iterate through them simultaneously?<\/p>\n<pre class=\"ig ih ii ij ik mt mu mv\"><span id=\"651a\" class=\"cs mw jj bi mx b ca my mz r na\" data-selectable-paragraph=\"\">sniper<\/span><\/pre>\n<p id=\"4d8a\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">#2<\/strong><\/p>\n<p id=\"6f9a\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">How about the attack type which allows us to use one payload set in every single position we\u2019ve selected simultaneously?<\/p>\n<pre class=\"ig ih ii ij ik mt mu mv\"><span id=\"2ff8\" class=\"cs mw jj bi mx b ca my mz r na\" data-selectable-paragraph=\"\">battering ram<\/span><\/pre>\n<p id=\"b579\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">#3<\/strong><\/p>\n<p id=\"2dd7\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">Which attack type allows us to select multiple payload sets (one per position) and iterate through all possible combinations?<\/p>\n<pre class=\"ig ih ii ij ik mt mu mv\"><span id=\"003a\" class=\"cs mw jj bi mx b ca my mz r na\" data-selectable-paragraph=\"\">cluster bomb<\/span><\/pre>\n<p id=\"3401\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">#4<\/strong><\/p>\n<p id=\"cea4\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">Perhaps the most commonly used, which attack type allows us to cycle through our payload set, putting the next available payload in each position in turn?<\/p>\n<pre class=\"ig ih ii ij ik mt mu mv\"><span id=\"5699\" class=\"cs mw jj bi mx b ca my mz r na\" data-selectable-paragraph=\"\">sniper<\/span><\/pre>\n<p id=\"43d4\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">#5<\/strong><\/p>\n<p id=\"c341\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">Download the wordlist attached to this room, this is a shortened version of the\u00a0<a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/github.com\/fuzzdb-project\/fuzzdb\/blob\/master\/attack\/sql-injection\/detect\/xplatform.txt\" target=\"_blank\" rel=\"noopener nofollow noreferrer\" rel=\"nofollow\" >fuzzdb SQLi platform detection list<\/a>.<\/p>\n<p id=\"e164\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">#6<\/strong><\/p>\n<p id=\"d40d\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">Return to the Intruder in Burp. In our previous task, we passed our failed login attempt to both Repeater and Intruder for further examination. Open up the Positions sub-tab in the Intruder tab with this request now and verify that \u2018Sniper\u2019 is selected as our attack type.<\/p>\n<figure class=\"ig ih ii ij ik il fn fo paragraph-image\">\n<div class=\"fn fo ny\">\n<div class=\"is r cc fb\">\n<div class=\"nz iu r\">\n<div class=\"cb ip s t u ds ai bu iq ir\"><img loading=\"lazy\" decoding=\"async\" class=\"s t u ds ai iv iw ap uu\" data-original=\"https:\/\/miro.medium.com\/max\/60\/0*nLcibI0RLPxksU29.png?q=20\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" width=\"180\" height=\"47\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe65\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe65\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"eg ul s t u ds ai c\" data-original=\"https:\/\/miro.medium.com\/max\/225\/0*nLcibI0RLPxksU29.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" sizes=\"auto, 180px\" srcset=\"\" width=\"180\" height=\"47\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe66\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe66\" \/><\/div>\n<\/div>\n<\/div>\n<\/figure>\n<p id=\"ff19\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">#7<\/strong><\/p>\n<p id=\"b535\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">Burp attempts to automatically highlight possible fields of interest for Intruder, however, it doesn\u2019t have it quite right for what we\u2019ll be looking at in this instance. Hit \u2018Clear\u2019 on the right-hand side to clear all selected fields.<\/p>\n<figure class=\"ig ih ii ij ik il fn fo paragraph-image\">\n<div class=\"fn fo oa\">\n<div class=\"is r cc fb\">\n<div class=\"ob iu r\">\n<div class=\"cb ip s t u ds ai bu iq ir\"><img loading=\"lazy\" decoding=\"async\" class=\"s t u ds ai iv iw ap uu\" data-original=\"https:\/\/miro.medium.com\/max\/60\/0*eWrMiQLB-y4La-qR.png?q=20\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" width=\"131\" height=\"43\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe67\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe67\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"eg ul s t u ds ai c\" data-original=\"https:\/\/miro.medium.com\/max\/164\/0*eWrMiQLB-y4La-qR.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" sizes=\"auto, 131px\" srcset=\"\" width=\"131\" height=\"43\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe68\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe68\" \/><\/div>\n<\/div>\n<\/div>\n<\/figure>\n<p id=\"e6f9\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">#8<\/strong><\/p>\n<p id=\"1803\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">Next, let\u2019s highlight the email field between the double quotes (\u201c).\u00a0<em class=\"lk\">This will be whatever you entered in the email field for our previous failed login attempt.<\/em><\/p>\n<figure class=\"ig ih ii ij ik il fn fo paragraph-image\">\n<div class=\"im in cc io ai\">\n<div class=\"fn fo oc\">\n<div class=\"is r cc fb\">\n<div class=\"od iu r\">\n<div class=\"cb ip s t u ds ai bu iq ir\"><img loading=\"lazy\" decoding=\"async\" class=\"s t u ds ai iv iw ap uu\" data-original=\"https:\/\/miro.medium.com\/max\/60\/0*IANial5QPObziNqF.png?q=20\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" width=\"1528\" height=\"314\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe69\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe69\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"eg ul s t u ds ai c\" data-original=\"https:\/\/miro.medium.com\/max\/1910\/0*IANial5QPObziNqF.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" sizes=\"auto, 700px\" srcset=\"https:\/\/miro.medium.com\/max\/345\/0*IANial5QPObziNqF.png 276w, https:\/\/miro.medium.com\/max\/690\/0*IANial5QPObziNqF.png 552w, https:\/\/miro.medium.com\/max\/800\/0*IANial5QPObziNqF.png 640w, https:\/\/miro.medium.com\/max\/875\/0*IANial5QPObziNqF.png 700w\" width=\"1528\" height=\"314\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe70\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe70\" \/><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/figure>\n<p id=\"3717\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">#9<\/strong><\/p>\n<p id=\"9fce\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u73b0\u5728\uff0c\u5355\u51fb\u201c\u6dfb\u52a0\u201d\u4ee5\u9009\u62e9\u6211\u4eec\u7684\u7535\u5b50\u90ae\u4ef6\u5b57\u6bb5\u4f5c\u4e3a\u6709\u6548\u8d1f\u8f7d\u7684\u4f4d\u7f6e\u3002<\/span><\/p>\n<figure class=\"ig ih ii ij ik il fn fo paragraph-image\">\n<div class=\"fn fo oe\">\n<div class=\"is r cc fb\">\n<div class=\"of iu r\">\n<div class=\"cb ip s t u ds ai bu iq ir\"><img loading=\"lazy\" decoding=\"async\" class=\"s t u ds ai iv iw ap uu\" data-original=\"https:\/\/miro.medium.com\/max\/60\/0*db-JwzURr2m4HYlg.png?q=20\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" width=\"130\" height=\"42\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe71\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe71\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"eg ul s t u ds ai c\" data-original=\"https:\/\/miro.medium.com\/max\/163\/0*db-JwzURr2m4HYlg.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" sizes=\"auto, 130px\" srcset=\"\" width=\"130\" height=\"42\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe72\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe72\" \/><\/div>\n<\/div>\n<\/div>\n<\/figure>\n<p id=\"567d\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\"><span>\uff0310<\/span><\/strong><\/p>\n<p id=\"a1ac\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u63a5\u4e0b\u6765\uff0c\u8ba9\u6211\u4eec\u5207\u6362\u5230Intruder\u7684\u6709\u6548\u8d1f\u8f7d\u5b50\u9009\u9879\u5361\u3002\u5230\u8fbe\u90a3\u91cc\u540e\uff0c\u70b9\u51fb\u201c\u52a0\u8f7d\u201d\uff0c\u7136\u540e\u9009\u62e9\u60a8\u5148\u524d\u5728\u95ee\u98985\u4e2d\u4e0b\u8f7d\u7684\u5355\u8bcd\u5217\u8868\uff0c\u8be5\u5355\u8bcd\u5217\u8868\u5df2\u9644\u52a0\u5230\u6b64\u4efb\u52a1\u3002<\/span><\/p>\n<figure class=\"ig ih ii ij ik il fn fo paragraph-image\">\n<div class=\"fn fo og\">\n<div class=\"is r cc fb\">\n<div class=\"oh iu r\">\n<div class=\"cb ip s t u ds ai bu iq ir\"><img loading=\"lazy\" decoding=\"async\" class=\"s t u ds ai iv iw ap uu\" data-original=\"https:\/\/miro.medium.com\/max\/60\/0*X66CNDUsPemrBxMa.png?q=20\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" width=\"570\" height=\"374\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe73\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe73\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"eg ul s t u ds ai c\" data-original=\"https:\/\/miro.medium.com\/max\/713\/0*X66CNDUsPemrBxMa.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" sizes=\"auto, 570px\" srcset=\"https:\/\/miro.medium.com\/max\/345\/0*X66CNDUsPemrBxMa.png 276w, https:\/\/miro.medium.com\/max\/690\/0*X66CNDUsPemrBxMa.png 552w, https:\/\/miro.medium.com\/max\/713\/0*X66CNDUsPemrBxMa.png 570w\" width=\"570\" height=\"374\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe74\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe74\" \/><\/div>\n<\/div>\n<\/div>\n<\/figure>\n<p id=\"50bd\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\"><span>\uff0311<\/span><\/strong><\/p>\n<p id=\"a49b\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u5dee\u4e0d\u591a\u4e86\uff01\u5411\u4e0b\u6eda\u52a8\u5e76\u53d6\u6d88\u9009\u4e2d\u201c\u5bf9\u8fd9\u4e9b\u5b57\u7b26\u8fdb\u884cURL\u7f16\u7801\u201d\u3002\u6211\u4eec\u4e0d\u60f3\u8ba9\u6709\u6548\u8f7d\u8377\u4e2d\u53d1\u9001\u7684\u5b57\u7b26\u8fdb\u884c\u7f16\u7801\uff0c\u56e0\u4e3a\u5426\u5219\u5b83\u4eec\u5c06\u4e0d\u4f1a\u88abSQL\u8bc6\u522b\u3002<\/span><\/p>\n<figure class=\"ig ih ii ij ik il fn fo paragraph-image\">\n<div class=\"im in cc io ai\">\n<div class=\"fn fo oi\">\n<div class=\"is r cc fb\">\n<div class=\"oj iu r\">\n<div class=\"cb ip s t u ds ai bu iq ir\"><img loading=\"lazy\" decoding=\"async\" class=\"s t u ds ai iv iw ap uu\" data-original=\"https:\/\/miro.medium.com\/max\/60\/0*w4KslXs4NwumFkBY.png?q=20\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" width=\"840\" height=\"135\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe75\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe75\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"eg ul s t u ds ai c\" data-original=\"https:\/\/miro.medium.com\/max\/1050\/0*w4KslXs4NwumFkBY.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" sizes=\"auto, 700px\" srcset=\"https:\/\/miro.medium.com\/max\/345\/0*w4KslXs4NwumFkBY.png 276w, https:\/\/miro.medium.com\/max\/690\/0*w4KslXs4NwumFkBY.png 552w, https:\/\/miro.medium.com\/max\/800\/0*w4KslXs4NwumFkBY.png 640w, https:\/\/miro.medium.com\/max\/875\/0*w4KslXs4NwumFkBY.png 700w\" width=\"840\" height=\"135\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe76\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe76\" \/><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/figure>\n<p id=\"c97e\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\"><span>\uff0312<\/span><\/strong><\/p>\n<p id=\"e1cb\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u6700\u540e\uff0c\u70b9\u51fb\u201c\u5f00\u59cb\u653b\u51fb\u201d\u3002\u8fd4\u56de200\u72b6\u6001\u4ee3\u7801\uff08\u8868\u660e\u6211\u4eec\u5df2\u6210\u529f\u7ed5\u8fc7\u8eab\u4efd\u9a8c\u8bc1\uff09\u7684\u7b2c\u4e00\u4e2a\u6709\u6548\u8f7d\u8377\u662f\u4ec0\u4e48\uff1f<\/span><\/p>\n<pre class=\"ig ih ii ij ik mt mu mv\"><span id=\"92f2\" class=\"cs mw jj bi mx b ca my mz r na\" data-selectable-paragraph=\"\"><span>a'\u62161 = 1--<\/span><\/span><\/pre>\n<\/div>\n<\/div>\n<\/section>\n<hr class=\"iy hb iz ja bx jb jc jd je jf jg jh\" \/>\n<section class=\"ft fu fv fw fx\">\n<div class=\"n p\">\n<div class=\"z ab ac ae af fy ah ai\">\n<h1 id=\"d1d0\" class=\"ji jj bi bh et jk jl jm jn jo jp jq jr js jt ju jv jw jx jy jz cs\" data-selectable-paragraph=\"\"><span>\u4e8b\u5b9e\u8bc1\u660e\uff0c\u5728\u6570\u5b66\u65b9\u9762\uff0c\u673a\u5668\u6bd4\u6211\u4eec\u66f4\u597d\u3002<\/span><\/h1>\n<p id=\"fa75\" class=\"ka kb bi kc b kd ke kf kg kh ki kj kk kl km kn ko kp kq kr ks kt ku kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u867d\u7136\u5728\u5b9e\u8df5\u73af\u5883\u4e2d\u4e0d\u90a3\u4e48\u5e38\u7528\uff0c\u4f46Sequencer\u4ee3\u8868\u4e86\u9002\u5f53\u7684Web\u5e94\u7528\u7a0b\u5e8f\u6e17\u900f\u6d4b\u8bd5\u4e2d\u7684\u6838\u5fc3\u5de5\u5177\u3002<\/span><a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/portswigger.net\/burp\/documentation\/desktop\/tools\/sequencer\/getting-started\" target=\"_blank\" rel=\"noopener nofollow noreferrer\" rel=\"nofollow\" ><span>\u6839\u636eBurp\u6587\u6863<\/span><\/a><span>\uff0cBurp\u7684Sequencer\u00a0\u662f\u4e00\u79cd\u5de5\u5177\uff0c\u7528\u4e8e\u5206\u6790\u5e94\u7528\u7a0b\u5e8f\u7684\u4f1a\u8bdd\u4ee4\u724c\u548c\u5176\u4ed6\u91cd\u8981\u6570\u636e\u9879\u4e2d\u7684\u968f\u673a\u6027\uff0c\u800c\u8fd9\u4e9b\u8d28\u91cf\u672c\u6765\u662f\u65e0\u6cd5\u9884\u6d4b\u7684\u3002\u4e00\u4e9b\u7ecf\u5e38\u5206\u6790\u7684\u9879\u76ee\u5305\u62ec\uff1a<\/span><\/p>\n<p id=\"5e65\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>-\u4f1a\u8bdd\u4ee4\u724c<\/span><br \/>\n<span>-\u53cdCSRF\uff08\u8de8\u7ad9\u70b9\u8bf7\u6c42\u4f2a\u9020\uff09\u4ee4\u724c<\/span><br \/>\n<span>-\u5bc6\u7801\u91cd\u7f6e\u4ee4\u724c\uff08\u4e0e\u5bc6\u7801\u91cd\u7f6e\u4e00\u8d77\u53d1\u9001\uff0c\u7406\u8bba\u4e0a\uff0c\u5bc6\u7801\u91cd\u7f6e\u5c06\u7528\u6237\u4e0e\u4ed6\u4eec\u7684\u5bc6\u7801\u91cd\u7f6e\u8bf7\u6c42\u552f\u4e00\u5730\u7ed1\u5b9a\u5728\u4e00\u8d77\uff09<\/span><\/p>\n<p id=\"7674\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u6211\u4eec\u5c06\u5feb\u901f\u6d4f\u89c8\u4e00\u4e0b\u5982\u4f55\u4f7f\u7528Sequencer\u6765\u68c0\u67e5Juice Shop\u53d1\u51fa\u7684\u4f1a\u8bddcookie\u3002<\/span><\/p>\n<figure class=\"ig ih ii ij ik il fn fo paragraph-image\">\n<div class=\"im in cc io ai\">\n<div class=\"fn fo if\">\n<div class=\"is r cc fb\">\n<div class=\"ms iu r\">\n<div class=\"cb ip s t u ds ai bu iq ir\"><img loading=\"lazy\" decoding=\"async\" class=\"s t u ds ai iv iw ap uu\" data-original=\"https:\/\/miro.medium.com\/max\/60\/0*XJhMoVZtJg1NHYKj.png?q=20\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" width=\"800\" height=\"600\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe77\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe77\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"eg ul s t u ds ai c\" data-original=\"https:\/\/miro.medium.com\/max\/1000\/0*XJhMoVZtJg1NHYKj.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" sizes=\"auto, 700px\" srcset=\"https:\/\/miro.medium.com\/max\/345\/0*XJhMoVZtJg1NHYKj.png 276w, https:\/\/miro.medium.com\/max\/690\/0*XJhMoVZtJg1NHYKj.png 552w, https:\/\/miro.medium.com\/max\/800\/0*XJhMoVZtJg1NHYKj.png 640w, https:\/\/miro.medium.com\/max\/875\/0*XJhMoVZtJg1NHYKj.png 700w\" width=\"800\" height=\"600\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe78\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe78\" \/><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/figure>\n<p id=\"c454\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/dribbble.com\/shots\/4033707-SEO-Friendly-Progressive-Web-Applications-with-Angular-Universal\" target=\"_blank\" rel=\"noopener nofollow noreferrer\" rel=\"nofollow\" ><em class=\"lk\"><span>Maxime Bourgeois\u5728Dribbble\u4e0a\u4f7f\u7528Angular Universal\u8fdb\u884cSEO\u53cb\u597d\u7684\u6e10\u8fdb\u5f0fWeb\u5e94\u7528\u7a0b\u5e8f<\/span><\/em><\/a><\/p>\n<p id=\"ce71\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><em class=\"lk\">Burp Suite reference documentation for Sequencer:\u00a0<\/em><a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/portswigger.net\/burp\/documentation\/desktop\/tools\/sequencer\" target=\"_blank\" rel=\"noopener nofollow noreferrer\" rel=\"nofollow\" ><em class=\"lk\">Link<\/em><\/a><\/p>\n<\/div>\n<\/div>\n<\/section>\n<hr class=\"iy hb iz ja bx jb jc jd je jf jg jh\" \/>\n<section class=\"ft fu fv fw fx\">\n<div class=\"n p\">\n<div class=\"z ab ac ae af fy ah ai\">\n<p id=\"1509\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">#1<\/strong><\/p>\n<p id=\"4f00\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">Switch over to the HTTP history sub-tab of Proxy.<\/p>\n<p id=\"1f48\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">#2<\/strong><\/p>\n<p id=\"8025\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">We\u2019re going to dig for a\u00a0<strong class=\"kc lq\">response<\/strong>\u00a0which issues a cookie. Parse through the various responses we\u2019ve received from Juice Shop until you find one that includes a \u2018Set-Cookie\u2019 header.<\/p>\n<p id=\"ea4e\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">#3<\/strong><\/p>\n<p id=\"8765\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">Once you\u2019ve found a request response that issues a cookie, right-click on the request and select \u2018Send to Sequencer\u2019.<\/p>\n<p id=\"2c61\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">#4<\/strong><\/p>\n<p id=\"869b\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">Change over Sequencer and select \u2018Start live capture\u2019<\/p>\n<p id=\"4d7e\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">#5<\/strong><\/p>\n<p id=\"4c0e\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">Let Sequencer run and collect ~10,000 requests. Once it hits roughly that amount hit \u2018Pause\u2019 and then \u2018Analyze now\u2019<\/p>\n<p id=\"be94\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">#6<\/strong><\/p>\n<p id=\"1160\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">Parse through the results. What is the effective estimated entropy measured in?<\/p>\n<pre class=\"ig ih ii ij ik mt mu mv\"><span id=\"dcbc\" class=\"cs mw jj bi mx b ca my mz r na\" data-selectable-paragraph=\"\">bits<\/span><\/pre>\n<p id=\"6742\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">#7<\/strong><\/p>\n<p id=\"db4a\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u4e3a\u4e86\u627e\u5230\u71b5\u7684\u53ef\u7528\u4f4d\uff0c\u6211\u4eec\u7ecf\u5e38\u5fc5\u987b\u8fdb\u884c\u4e00\u4e9b\u8c03\u6574\u4ee5\u5177\u6709\u6807\u51c6\u5316\u7684\u6570\u636e\u96c6\u3002\u5728\u6b64\u8fc7\u7a0b\u4e2d\u8f6c\u6362\u4e86\u4ec0\u4e48\u9879\u76ee\uff1f<\/span><\/p>\n<pre class=\"ig ih ii ij ik mt mu mv\"><span id=\"bdea\" class=\"cs mw jj bi mx b ca my mz r na\" data-selectable-paragraph=\"\"><span>\u4ee3\u5e01<\/span><\/span><\/pre>\n<p id=\"273a\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\"><span>\uff038<\/span><\/strong><\/p>\n<p id=\"9940\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u901a\u8bfb\u4ee4\u724c\u5206\u6790\u7684\u5176\u4f59\u7ed3\u679c<\/span><\/p>\n<\/div>\n<\/div>\n<\/section>\n<hr class=\"iy hb iz ja bx jb jc jd je jf jg jh\" \/>\n<section class=\"ft fu fv fw fx\">\n<div class=\"n p\">\n<div class=\"z ab ac ae af fy ah ai\">\n<h1 id=\"799b\" class=\"ji jj bi bh et jk jl jm jn jo jp jq jr js jt ju jv jw jx jy jz cs\" data-selectable-paragraph=\"\"><span>\u89e3\u7801\u5668\u548c\u6bd4\u8f83\u5668<\/span><\/h1>\n<p id=\"cb5a\" class=\"ka kb bi kc b kd ke kf kg kh ki kj kk kl km kn ko kp kq kr ks kt ku kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u89e3\u7801\u5668\u548c\u6bd4\u8f83\u5668\u867d\u7136\u662fBurp Suite\u4e2d\u7684\u6b21\u8981\u5de5\u5177\uff0c\u4f46\u5bf9\u4e8e\u6210\u4e3a\u719f\u7ec3\u7684Web\u5e94\u7528\u7a0b\u5e8f\u6d4b\u8bd5\u4eba\u5458\u6765\u8bf4\uff0c\u7406\u89e3\u548c\u5229\u7528\u5b83\u4eec\u4ecd\u7136\u662f\u5fc5\u4e0d\u53ef\u5c11\u7684\u3002<\/span><\/p>\n<p id=\"9aee\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u987e\u540d\u601d\u4e49\uff0c\u89e3\u7801\u5668\u662f\u4e00\u79cd\u5de5\u5177\uff0c\u53ef\u8ba9\u6211\u4eec\u5bf9\u6570\u636e\u8fdb\u884c\u5404\u79cd\u8f6c\u6362\u3002\u8fd9\u4e9b\u8f6c\u6362\u4ece\u89e3\u7801\/\u7f16\u7801\u5230\u5404\u79cd\u57fa\u7840\u6216URL\u7f16\u7801\u4e0d\u7b49\u3002\u6211\u4eec\u5c06\u8fd9\u4e9b\u8f6c\u6362\u94fe\u63a5\u5728\u4e00\u8d77\uff0c\u5e76\u4e14\u6bcf\u5f53\u6211\u4eec\u9009\u62e9\u89e3\u7801\u5668\uff0c\u7f16\u7801\u5668\u6216\u54c8\u5e0c\u65f6\uff0cDecoder\u5c06\u81ea\u52a8\u4ea7\u751f\u4e00\u4e2a\u9644\u52a0\u5c42\u3002<\/span><em class=\"lk\"><span>\u6700\u7ec8\uff0c\u8be5\u5de5\u5177\u7684\u529f\u80fd\u4e0e<\/span><\/em><a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/gchq.github.io\/CyberChef\/\" target=\"_blank\" rel=\"noopener nofollow noreferrer\" rel=\"nofollow\" ><em class=\"lk\"><span>Cyber\u200b\u200bChef<\/span><\/em><\/a><span><em class=\"lk\">\u975e\u5e38\u76f8\u4f3c<\/em><\/span><em class=\"lk\"><span>\uff0c\u5c3d\u7ba1\u529f\u80fd\u7a0d\u5dee\u4e00\u4e9b\u3002<\/span><\/em><\/p>\n<figure class=\"ig ih ii ij ik il fn fo paragraph-image\">\n<div class=\"im in cc io ai\">\n<div class=\"fn fo if\">\n<div class=\"is r cc fb\">\n<div class=\"ms iu r\">\n<div class=\"cb ip s t u ds ai bu iq ir\"><img loading=\"lazy\" decoding=\"async\" class=\"s t u ds ai iv iw ap uu\" data-original=\"https:\/\/miro.medium.com\/max\/60\/0*dS4BQ9R2EkMhgbYh.png?q=20\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" width=\"800\" height=\"600\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe79\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe79\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"eg ul s t u ds ai c\" data-original=\"https:\/\/miro.medium.com\/max\/1000\/0*dS4BQ9R2EkMhgbYh.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" sizes=\"auto, 700px\" srcset=\"https:\/\/miro.medium.com\/max\/345\/0*dS4BQ9R2EkMhgbYh.png 276w, https:\/\/miro.medium.com\/max\/690\/0*dS4BQ9R2EkMhgbYh.png 552w, https:\/\/miro.medium.com\/max\/800\/0*dS4BQ9R2EkMhgbYh.png 640w, https:\/\/miro.medium.com\/max\/875\/0*dS4BQ9R2EkMhgbYh.png 700w\" width=\"800\" height=\"600\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe80\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe80\" \/><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/figure>\n<p id=\"d92d\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/dribbble.com\/shots\/6549514-Encryption\" target=\"_blank\" rel=\"noopener nofollow noreferrer\" rel=\"nofollow\" ><em class=\"lk\"><span>Muriel\u5728Dribbble\u4e0a\u7684\u52a0\u5bc6<\/span><\/em><\/a><\/p>\n<p id=\"ffe3\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">Similarly, Comparer, as you might have guessed is a tool we can use to compare different responses or other pieces of data such as site maps or proxy histories (awesome for access control issue testing). This is very similar to the Linux tool diff.<\/p>\n<p id=\"de4f\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">Per the Burp\u00a0<a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/portswigger.net\/burp\/documentation\/desktop\/tools\/comparer\" target=\"_blank\" rel=\"noopener nofollow noreferrer\" rel=\"nofollow\" >documentation<\/a>, some common uses for Comparer are as follows:<\/p>\n<p id=\"395d\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">- When looking for username enumeration conditions, you can compare responses to failed logins using valid and invalid usernames, looking for subtle differences in responses.\u00a0<em class=\"lk\">This is also sometimes useful for when enumerating password recovery forms or another similar recovery\/account access mechanism.<\/em><\/p>\n<p id=\"fec6\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">- When an Intruder attack has resulted in some very large responses with different lengths than the base response, you can compare these to quickly see where the differences lie.<\/p>\n<p id=\"f397\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">- When comparing the site maps or Proxy history entries generated by different types of users, you can compare pairs of similar requests to see where the differences lie that give rise to different application behaviour. This may reveal possible access control issues in the application wherein lower privileged users can access pages they really shouldn\u2019t be able to.<\/p>\n<p id=\"e691\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">- When testing for blind SQL injection bugs using Boolean condition injection and other similar tests, you can compare two responses to see whether injecting different conditions has resulted in a relevant difference in responses.<\/p>\n<p id=\"7180\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><em class=\"lk\">*These examples are taken nearly in their entirety from the Burp docs simply to provide a broader set of examples to consider when using Comparer.<\/em><\/p>\n<figure class=\"ig ih ii ij ik il fn fo paragraph-image\">\n<div class=\"im in cc io ai\">\n<div class=\"fn fo if\">\n<div class=\"is r cc fb\">\n<div class=\"ms iu r\">\n<div class=\"cb ip s t u ds ai bu iq ir\"><img loading=\"lazy\" decoding=\"async\" class=\"s t u ds ai iv iw ap uu\" data-original=\"https:\/\/miro.medium.com\/max\/60\/0*dJV8ZHtm9Yl_x5V4.png?q=20\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" width=\"800\" height=\"600\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe81\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe81\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"eg ul s t u ds ai c\" data-original=\"https:\/\/miro.medium.com\/max\/1000\/0*dJV8ZHtm9Yl_x5V4.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" sizes=\"auto, 700px\" srcset=\"https:\/\/miro.medium.com\/max\/345\/0*dJV8ZHtm9Yl_x5V4.png 276w, https:\/\/miro.medium.com\/max\/690\/0*dJV8ZHtm9Yl_x5V4.png 552w, https:\/\/miro.medium.com\/max\/800\/0*dJV8ZHtm9Yl_x5V4.png 640w, https:\/\/miro.medium.com\/max\/875\/0*dJV8ZHtm9Yl_x5V4.png 700w\" width=\"800\" height=\"600\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe82\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe82\" \/><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/figure>\n<p id=\"a518\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/dribbble.com\/shots\/3551926-JavaScript-Arrays-in-Depth\" target=\"_blank\" rel=\"noopener nofollow noreferrer\" rel=\"nofollow\" ><em class=\"lk\">JavaScript Arrays in Depth by Maxime Bourgeois on Dribbble<\/em><\/a><\/p>\n<p id=\"011b\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><em class=\"lk\">Burp Suite reference documentation for\u00a0<\/em><a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/portswigger.net\/burp\/documentation\/desktop\/tools\/decoder\" target=\"_blank\" rel=\"noopener nofollow noreferrer\" rel=\"nofollow\" ><em class=\"lk\">Decoder<\/em><\/a><em class=\"lk\">\u00a0and\u00a0<\/em><a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/portswigger.net\/burp\/documentation\/desktop\/tools\/comparer\" target=\"_blank\" rel=\"noopener nofollow noreferrer\" rel=\"nofollow\" ><em class=\"lk\">Comparer<\/em><\/a><\/p>\n<\/div>\n<\/div>\n<\/section>\n<hr class=\"iy hb iz ja bx jb jc jd je jf jg jh\" \/>\n<section class=\"ft fu fv fw fx\">\n<div class=\"n p\">\n<div class=\"z ab ac ae af fy ah ai\">\n<p id=\"be84\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">#1<\/strong><\/p>\n<p id=\"31fc\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">Let\u2019s first take a look at decoder by revisiting an old friend. Previously we discovered the scoreboard within the site JavaScript. Return to our target tab and find the API endpoint highlighted in the following request:<\/p>\n<figure class=\"ig ih ii ij ik il fn fo paragraph-image\">\n<div class=\"fn fo nc\">\n<div class=\"is r cc fb\">\n<div class=\"ok iu r\">\n<div class=\"cb ip s t u ds ai bu iq ir\"><img loading=\"lazy\" decoding=\"async\" class=\"s t u ds ai iv iw ap uu\" data-original=\"https:\/\/miro.medium.com\/max\/60\/0*bYY77nrZt7Ww5Z21.png?q=20\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" width=\"227\" height=\"104\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe83\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe83\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"eg ul s t u ds ai c\" data-original=\"https:\/\/miro.medium.com\/max\/284\/0*bYY77nrZt7Ww5Z21.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" sizes=\"auto, 227px\" srcset=\"\" width=\"227\" height=\"104\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe84\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe84\" \/><\/div>\n<\/div>\n<\/div>\n<\/figure>\n<p id=\"9db2\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">#2<\/strong><\/p>\n<p id=\"e3ec\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">Copy the first line of that request and paste it into Decoder. Next, select \u2018Decode as \u2026\u2019 URL<\/p>\n<p id=\"e542\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">#3<\/strong><\/p>\n<p id=\"f33f\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">What character does the %20 in the request we copied into Decoder decode as?<\/p>\n<pre class=\"ig ih ii ij ik mt mu mv\"><span id=\"fb58\" class=\"cs mw jj bi mx b ca my mz r na\" data-selectable-paragraph=\"\">space<\/span><\/pre>\n<p id=\"5dd3\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">#4<\/strong><\/p>\n<p id=\"e36e\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">Similar to CyberChef, Decoder also has a \u2018Magic\u2019 mode where it will automatically attempt to decode the input it is provided. What is this mode called?<\/p>\n<pre class=\"ig ih ii ij ik mt mu mv\"><span id=\"1e7a\" class=\"cs mw jj bi mx b ca my mz r na\" data-selectable-paragraph=\"\">smart decode<\/span><\/pre>\n<p id=\"f7a0\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">#5<\/strong><\/p>\n<p id=\"c064\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">What can we load into Comparer to see differences in what various user roles can access?\u00a0<em class=\"lk\">This is very useful to check for access control issues.<\/em><\/p>\n<pre class=\"ig ih ii ij ik mt mu mv\"><span id=\"4314\" class=\"cs mw jj bi mx b ca my mz r na\" data-selectable-paragraph=\"\">site maps<\/span><\/pre>\n<p id=\"9e09\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">#6<\/strong><\/p>\n<p id=\"7cfb\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">Comparer can perform a diff against two different metrics, which one allows us to examine the data loaded in as-is rather than breaking it down into bytes?<\/p>\n<pre class=\"ig ih ii ij ik mt mu mv\"><span id=\"3cb5\" class=\"cs mw jj bi mx b ca my mz r na\" data-selectable-paragraph=\"\">words<\/span><\/pre>\n<\/div>\n<\/div>\n<\/section>\n<hr class=\"iy hb iz ja bx jb jc jd je jf jg jh\" \/>\n<section class=\"ft fu fv fw fx\">\n<div class=\"n p\">\n<div class=\"z ab ac ae af fy ah ai\">\n<h1 id=\"9c41\" class=\"ji jj bi bh et jk jl jm jn jo jp jq jr js jt ju jv jw jx jy jz cs\" data-selectable-paragraph=\"\">Installing some Mods [Extender]<\/h1>\n<p id=\"98ae\" class=\"ka kb bi kc b kd ke kf kg kh ki kj kk kl km kn ko kp kq kr ks kt ku kv kw kx ft cs\" data-selectable-paragraph=\"\">Similar to adding mods to a game like Minecraft, Extender allows us to add components such as tool integrations, additional scan definitions, and more! Here are some of the most popular extensions I suggest checking out (not all of these are free but I suggest looking into them all the same):<\/p>\n<ul class=\"\">\n<li id=\"109c\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx mb kz la cs\" data-selectable-paragraph=\"\"><a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/portswigger.net\/bappstore\/470b7057b86f41c396a97903377f3d81\" target=\"_blank\" rel=\"noopener nofollow noreferrer\" rel=\"nofollow\" >Logger++<\/a>\u00a0\u2014 Adds enhanced logging to all requests and responses from all Burp Suite tools, enable this one before you need it \ud83d\ude09<\/li>\n<li id=\"3f66\" class=\"ka kb bi kc b kd lf kf kg kh lg kj kk kl lh kn ko kp li kr ks kt lj kv kw kx mb kz la cs\" data-selectable-paragraph=\"\"><a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/portswigger.net\/bappstore\/aaaa60ef945341e8a450217a54a11646\" target=\"_blank\" rel=\"noopener nofollow noreferrer\" rel=\"nofollow\" >Request Smuggler<\/a>\u00a0\u2014 A relatively new extension, this allows you to attempt to smuggle requests to backend servers. See this talk by James Kettle for more details:\u00a0<a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/www.youtube.com\/watch?v=_A04msdplXs\" target=\"_blank\" rel=\"noopener nofollow noreferrer\" rel=\"nofollow\" >Link<\/a><\/li>\n<li id=\"cef1\" class=\"ka kb bi kc b kd lf kf kg kh lg kj kk kl lh kn ko kp li kr ks kt lj kv kw kx mb kz la cs\" data-selectable-paragraph=\"\"><a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/portswigger.net\/bappstore\/f9bbac8c4acf4aefa4d7dc92a991af2f\" target=\"_blank\" rel=\"noopener nofollow noreferrer\" rel=\"nofollow\" >Autorize<\/a>\u00a0\u2014 Useful for authentication testing in web app tests. These tests typically revolve around navigating to restricted pages or issuing restricted GET requests with the session cookies of low-privileged users<\/li>\n<li id=\"83af\" class=\"ka kb bi kc b kd lf kf kg kh lg kj kk kl lh kn ko kp li kr ks kt lj kv kw kx mb kz la cs\" data-selectable-paragraph=\"\"><a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/github.com\/Static-Flow\/BurpSuite-Team-Extension\" target=\"_blank\" rel=\"noopener nofollow noreferrer\" rel=\"nofollow\" >Burp Teams Server<\/a>\u00a0\u2014 Allows for collaboration on a Burp project amongst team members. Project details are shared in a chatroom-like format<\/li>\n<li id=\"b5bd\" class=\"ka kb bi kc b kd lf kf kg kh lg kj kk kl lh kn ko kp li kr ks kt lj kv kw kx mb kz la cs\" data-selectable-paragraph=\"\"><a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/portswigger.net\/bappstore\/36238b534a78494db9bf2d03f112265c\" target=\"_blank\" rel=\"noopener nofollow noreferrer\" rel=\"nofollow\" >Retire.js<\/a>\u00a0\u2014 Adds scanner checks for outdated JavaScript libraries that contain vulnerabilities, this is a premium extension<\/li>\n<li id=\"e647\" class=\"ka kb bi kc b kd lf kf kg kh lg kj kk kl lh kn ko kp li kr ks kt lj kv kw kx mb kz la cs\" data-selectable-paragraph=\"\"><a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/portswigger.net\/bappstore\/7ec6d429fed04cdcb6243d8ba7358880\" target=\"_blank\" rel=\"noopener nofollow noreferrer\" rel=\"nofollow\" >J2EEScan<\/a>\u00a0\u2014 Adds scanner test coverage for J2EE (java platform for web development) applications, this is a premium extension<\/li>\n<li id=\"7119\" class=\"ka kb bi kc b kd lf kf kg kh lg kj kk kl lh kn ko kp li kr ks kt lj kv kw kx mb kz la cs\" data-selectable-paragraph=\"\"><a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/portswigger.net\/bappstore\/56675bcf2a804d3096465b2868ec1d65\" target=\"_blank\" rel=\"noopener nofollow noreferrer\" rel=\"nofollow\" >Request Timer<\/a>\u00a0\u2014 Captures response times for requests made by all Burp tools, useful for discovering timing attack vectors<\/li>\n<\/ul>\n<figure class=\"ig ih ii ij ik il fn fo paragraph-image\">\n<div class=\"im in cc io ai\">\n<div class=\"fn fo if\">\n<div class=\"is r cc fb\">\n<div class=\"ms iu r\">\n<div class=\"cb ip s t u ds ai bu iq ir\"><img loading=\"lazy\" decoding=\"async\" class=\"s t u ds ai iv iw ap uu\" data-original=\"https:\/\/miro.medium.com\/max\/60\/0*O4apHwClodfi4SuZ.png?q=20\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" width=\"800\" height=\"600\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe85\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe85\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"eg ul s t u ds ai c\" data-original=\"https:\/\/miro.medium.com\/max\/1000\/0*O4apHwClodfi4SuZ.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" sizes=\"auto, 700px\" srcset=\"https:\/\/miro.medium.com\/max\/345\/0*O4apHwClodfi4SuZ.png 276w, https:\/\/miro.medium.com\/max\/690\/0*O4apHwClodfi4SuZ.png 552w, https:\/\/miro.medium.com\/max\/800\/0*O4apHwClodfi4SuZ.png 640w, https:\/\/miro.medium.com\/max\/875\/0*O4apHwClodfi4SuZ.png 700w\" width=\"800\" height=\"600\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe86\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe86\" \/><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/figure>\n<p id=\"fb40\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/dribbble.com\/shots\/3870703-Contributing\" target=\"_blank\" rel=\"noopener nofollow noreferrer\" rel=\"nofollow\" ><em class=\"lk\">Contributing by Matt Scribner on Dribbble<\/em><\/a><\/p>\n<p id=\"9583\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">A prerequisite for many of the extensions offered for Burp, we\u2019ll walk through the installation of Jython, the Java implementation of Python.<\/p>\n<figure class=\"ig ih ii ij ik il fn fo paragraph-image\">\n<div class=\"fn fo ol\">\n<div class=\"is r cc fb\">\n<div class=\"om iu r\">\n<div class=\"cb ip s t u ds ai bu iq ir\"><img loading=\"lazy\" decoding=\"async\" class=\"s t u ds ai iv iw ap uu\" data-original=\"https:\/\/miro.medium.com\/max\/60\/0*2szsoDZEzamgG2SY.png?q=20\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" width=\"367\" height=\"224\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe87\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe87\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"eg ul s t u ds ai c\" data-original=\"https:\/\/miro.medium.com\/max\/459\/0*2szsoDZEzamgG2SY.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" sizes=\"auto, 367px\" srcset=\"https:\/\/miro.medium.com\/max\/345\/0*2szsoDZEzamgG2SY.png 276w, https:\/\/miro.medium.com\/max\/459\/0*2szsoDZEzamgG2SY.png 367w\" width=\"367\" height=\"224\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe88\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe88\" \/><\/div>\n<\/div>\n<\/div>\n<\/figure>\n<p id=\"281f\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><em class=\"lk\">Burp Suite reference documentation for Extender:\u00a0<\/em><a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/portswigger.net\/burp\/documentation\/desktop\/tools\/extender\" target=\"_blank\" rel=\"noopener nofollow noreferrer\" rel=\"nofollow\" ><em class=\"lk\">Link<\/em><\/a><\/p>\n<p id=\"c0ce\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><em class=\"lk\">Article on some of the top extensions for Burp Suite:\u00a0<\/em><a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/portswigger.net\/testers\/penetration-testing-tools\" target=\"_blank\" rel=\"noopener nofollow noreferrer\" rel=\"nofollow\" ><em class=\"lk\">Link<\/em><\/a><\/p>\n<\/div>\n<\/div>\n<\/section>\n<hr class=\"iy hb iz ja bx jb jc jd je jf jg jh\" \/>\n<section class=\"ft fu fv fw fx\">\n<div class=\"n p\">\n<div class=\"z ab ac ae af fy ah ai\">\n<p id=\"0c52\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">#1<\/strong><\/p>\n<p id=\"364b\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">To start, let\u2019s go ahead and switch over to the Options sub-tab of the Extender tab.<\/p>\n<p id=\"cc87\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">#2<\/strong><\/p>\n<p id=\"449d\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">Scroll down until you reach the \u2018Python Environment\u2019 section. Note, Burp requires the standalone edition of Jython.<\/p>\n<p id=\"f6c8\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">#3<\/strong><\/p>\n<p id=\"0351\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\">Download the standalone version of Jython from here:\u00a0<a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/www.jython.org\/download.html\" target=\"_blank\" rel=\"noopener nofollow noreferrer\" rel=\"nofollow\" >Link<\/a>\u00a0\u2014\u00a0<em class=\"lk\">I suggest saving this or moving it to your Documents folder<\/em><\/p>\n<p id=\"0ab7\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\">#4<\/strong><\/p>\n<p id=\"da39\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u8fd4\u56deBurp\u5e76\u5728Jython Standalone\u7684Python Environment\u5b50\u90e8\u5206\u4e0b\u5355\u51fb\u201c\u9009\u62e9\u6587\u4ef6\u201d\u3002\u5bfc\u822a\u5230\u60a8\u521a\u521a\u4e0b\u8f7d\u6b64\u6587\u4ef6\u7684\u4f4d\u7f6e\u5e76\u9009\u62e9\u5b83\u3002<\/span><\/p>\n<p id=\"93ef\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\"><span>\uff035<\/span><\/strong><\/p>\n<p id=\"4469\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>Burp\u73b0\u5728\u53ef\u4ee5\u7528\u4e8e\u5b89\u88c5\u6269\u5c55\u7a0b\u5e8f\u4e86\u3002\u5207\u6362\u5230Extender\u7684BApp Store\u5b50\u9009\u9879\u5361\uff0c\u5e76\u6d4f\u89c8\u63d0\u4f9b\u7684\u5404\u79cd\u6269\u5c55\u3002<\/span><\/p>\n<p id=\"d764\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\"><span>\uff036<\/span><\/strong><\/p>\n<p id=\"b349\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u54ea\u4e2a\u6269\u5c55\u5141\u8bb8\u6211\u4eec\u4e5f\u4e3a\u5404\u79cd\u8bf7\u6c42\u6dfb\u52a0\u4e66\u7b7e\uff1f<\/span><\/p>\n<pre class=\"ig ih ii ij ik mt mu mv\"><span id=\"6f6a\" class=\"cs mw jj bi mx b ca my mz r na\" data-selectable-paragraph=\"\"><span>\u4e66\u7b7e<\/span><\/span><\/pre>\n<\/div>\n<\/div>\n<\/section>\n<hr class=\"iy hb iz ja bx jb jc jd je jf jg jh\" \/>\n<section class=\"ft fu fv fw fx\">\n<div class=\"n p\">\n<div class=\"z ab ac ae af fy ah ai\">\n<h1 id=\"5523\" class=\"ji jj bi bh et jk jl jm jn jo jp jq jr js jt ju jv jw jx jy jz cs\" data-selectable-paragraph=\"\"><span>\u4f46\u662f\uff0c\u7b49\u7b49\uff0c\u8fd8\u6709\u66f4\u591a\uff01<\/span><\/h1>\n<p id=\"509e\" class=\"ka kb bi kc b kd ke kf kg kh ki kj kk kl km kn ko kp kq kr ks kt ku kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u5728\u603b\u7ed3\u4e4b\u524d\uff0c\u8ba9\u6211\u4eec\u5feb\u901f\u4e86\u89e3Burp Suite Professional\u63d0\u4f9b\u7684\u529f\u80fd\uff1aBurp Suite\u626b\u63cf\u4eea\u548c\u534f\u4f5c\u8005\u5ba2\u6237\u7aef\uff01<\/span><\/p>\n<figure class=\"ig ih ii ij ik il fn fo paragraph-image\">\n<div class=\"im in cc io ai\">\n<div class=\"fn fo if\">\n<div class=\"is r cc fb\">\n<div class=\"ms iu r\">\n<div class=\"cb ip s t u ds ai bu iq ir\"><img loading=\"lazy\" decoding=\"async\" class=\"s t u ds ai iv iw ap uu\" data-original=\"https:\/\/miro.medium.com\/max\/60\/0*TkBsvG7E3lEbLHVI.jpg?q=20\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" width=\"800\" height=\"600\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe89\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe89\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"eg ul s t u ds ai c\" data-original=\"https:\/\/miro.medium.com\/max\/1000\/0*TkBsvG7E3lEbLHVI.jpg\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" sizes=\"auto, 700px\" srcset=\"https:\/\/miro.medium.com\/max\/345\/0*TkBsvG7E3lEbLHVI.jpg 276w, https:\/\/miro.medium.com\/max\/690\/0*TkBsvG7E3lEbLHVI.jpg 552w, https:\/\/miro.medium.com\/max\/800\/0*TkBsvG7E3lEbLHVI.jpg 640w, https:\/\/miro.medium.com\/max\/875\/0*TkBsvG7E3lEbLHVI.jpg 700w\" width=\"800\" height=\"600\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe90\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe90\" \/><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/figure>\n<p id=\"8bf2\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/dribbble.com\/shots\/3988968-Engage\" target=\"_blank\" rel=\"noopener nofollow noreferrer\" rel=\"nofollow\" ><em class=\"lk\"><span>Todd Zlab\u5728Dribbble\u4e0a\u7684\u8ba2\u5a5a<\/span><\/em><\/a><\/p>\n<p id=\"402f\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>Burp Suite\u626b\u63cf\u7a0b\u5e8f\u53ef\u4ee5\u8bf4\u662fBurp Suite\u4e2d\u6700\u5f3a\u5927\u7684\u529f\u80fd\uff0c\u5b83\u4f7f\u6211\u4eec\u80fd\u591f\u88ab\u52a8\u548c\u4e3b\u52a8\u5730\u626b\u63cf\u548c\u722c\u7f51\u6211\u4eec\u6b63\u5728\u6d4b\u8bd5\u7684\u7f51\u7ad9\u662f\u5426\u5b58\u5728\u6f0f\u6d1e\u3002\u5728Burp 2.0\u7684\u57fa\u4e8e\u4efb\u52a1\u7684\u6a21\u578b\u4e2d\uff0c\u6211\u4eec\u53ef\u4ee5\u4ece\u4eea\u8868\u677f\u4e0a\u542f\u52a8\u8fd9\u4e9b\u626b\u63cf\uff08\u626b\u63cf\u4eea\u548c\u8718\u86db\uff09\uff0c\u5e76\u8ba9\u5b83\u4eec\u5728\u540e\u53f0\u8fd0\u884c\uff0c\u540c\u65f6\u7ee7\u7eed\u68c0\u67e5Web\u5e94\u7528\u7a0b\u5e8f\u3002\u5728\u8fd9\u79cd\u60c5\u51b5\u4e0b\uff0c\u6211\u5bf9Juice Shop\u8fd0\u884c\u4e86\u672a\u7ecf\u8eab\u4efd\u9a8c\u8bc1\u7684\u626b\u63cf\uff0c\u5e76\u5c06\u5176\u9644\u52a0\u5230\u6b64\u4efb\u52a1\u4e2d\u3002\u8fd9\u4e9b\u62a5\u544a\u53ef\u4ee5\u4e3a\u901a\u8fc7Burp Suite\u4e2d\u7684\u5176\u4ed6\u5de5\u5177\u8fdb\u884c\u8fdb\u4e00\u6b65\u679a\u4e3e\u548c\u5229\u7528\u63d0\u4f9b\u8d77\u70b9\u3002<\/span><\/p>\n<figure class=\"ig ih ii ij ik il fn fo paragraph-image\">\n<div class=\"im in cc io ai\">\n<div class=\"fn fo on\">\n<div class=\"is r cc fb\">\n<div class=\"oo iu r\">\n<div class=\"cb ip s t u ds ai bu iq ir\"><img loading=\"lazy\" decoding=\"async\" class=\"s t u ds ai iv iw ap uu\" data-original=\"https:\/\/miro.medium.com\/max\/60\/0*78okwDS-G70HD2D1.png?q=20\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" width=\"1220\" height=\"580\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe91\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe91\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"eg ul s t u ds ai c\" data-original=\"https:\/\/miro.medium.com\/max\/1525\/0*78okwDS-G70HD2D1.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" sizes=\"auto, 700px\" srcset=\"https:\/\/miro.medium.com\/max\/345\/0*78okwDS-G70HD2D1.png 276w, https:\/\/miro.medium.com\/max\/690\/0*78okwDS-G70HD2D1.png 552w, https:\/\/miro.medium.com\/max\/800\/0*78okwDS-G70HD2D1.png 640w, https:\/\/miro.medium.com\/max\/875\/0*78okwDS-G70HD2D1.png 700w\" width=\"1220\" height=\"580\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe92\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe92\" \/><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/figure>\n<p id=\"ab20\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><em class=\"lk\"><span>Burp Professional\u521b\u5efa\u7684\u6b64\u4efb\u52a1\u6240\u9644\u62a5\u544a\u7684\u9884\u89c8<\/span><\/em><\/p>\n<p id=\"60f5\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>Burp Collaborator Client\u901a\u5e38\u7528\u4e8e\u624b\u52a8\u6d4b\u8bd5\u4e2d\uff0c\u4f7f\u6211\u4eec\u80fd\u591f\u6df1\u5165\u4e86\u89e3\u53ef\u80fd\u65e0\u6cd5\u4ea7\u751f\u4efb\u4f55\u7ed3\u679c\u7684\u95ee\u9898\u3002\u901a\u5e38\uff0c\u5728\u6d4b\u8bd5\u8fc7\u7a0b\u4e2d\uff0c\u6211\u4eec\u53ef\u80fd\u4f1a\u9047\u5230\u4e00\u4e9b\u9879\u76ee\uff0c\u8fd9\u4e9b\u9879\u76ee\u53ef\u80fd\u7531\u4e8eWeb\u5e94\u7528\u7a0b\u5e8f\u7684\u65f6\u95f4\/\u901f\u5ea6\u6162\u6216\u7f3a\u4e4f\u4efb\u4f55\u53cd\u5e94\u800c\u5f88\u5bb9\u6613\u53d7\u5230\u653b\u51fb\uff0c\u4f46\u4e0d\u4f1a\u4ea7\u751f\u4efb\u4f55\u53ef\u80af\u5b9a\u7684\u6307\u6807\u3002\u4f46\u662f\uff0c\u501f\u52a9Burp Collaborator\uff0c\u6211\u4eec\u53ef\u4ee5\u901a\u8fc7\u751f\u6210\u6709\u6548\u8f7d\u8377\u6765\u4ea7\u751f\u5e26\u5916\u8b66\u62a5\uff0c\u8fd9\u4e9b\u6709\u6548\u8f7d\u8377\u53ef\u4ee5\u4e3a\u6211\u4eec\u8fd4\u56deBurp Suite\u7684\u670d\u52a1\u5668\u3002<\/span><\/p>\n<figure class=\"ig ih ii ij ik il fn fo paragraph-image\">\n<div class=\"im in cc io ai\">\n<div class=\"fn fo op\">\n<div class=\"is r cc fb\">\n<div class=\"oq iu r\">\n<div class=\"cb ip s t u ds ai bu iq ir\"><img loading=\"lazy\" decoding=\"async\" class=\"s t u ds ai iv iw ap uu\" data-original=\"https:\/\/miro.medium.com\/max\/60\/0*Ykr_VCa7JRrIDE84.png?q=20\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" width=\"1121\" height=\"923\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe93\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe93\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"eg ul s t u ds ai c\" data-original=\"https:\/\/miro.medium.com\/max\/1401\/0*Ykr_VCa7JRrIDE84.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" sizes=\"auto, 700px\" srcset=\"https:\/\/miro.medium.com\/max\/345\/0*Ykr_VCa7JRrIDE84.png 276w, https:\/\/miro.medium.com\/max\/690\/0*Ykr_VCa7JRrIDE84.png 552w, https:\/\/miro.medium.com\/max\/800\/0*Ykr_VCa7JRrIDE84.png 640w, https:\/\/miro.medium.com\/max\/875\/0*Ykr_VCa7JRrIDE84.png 700w\" width=\"1121\" height=\"923\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe94\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe94\" \/><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/figure>\n<p id=\"47ab\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><em class=\"lk\"><span>\u9002\u7528\u4e8e<\/span><\/em><a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/portswigger.net\/burp\/documentation\/scanner\" target=\"_blank\" rel=\"noopener nofollow noreferrer\" rel=\"nofollow\" ><em class=\"lk\"><span>Scanner<\/span><\/em><\/a><em class=\"lk\"><span>\u548c<\/span><\/em><span><a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/portswigger.net\/burp\/documentation\/desktop\/tools\/collaborator-client\" target=\"_blank\" rel=\"noopener nofollow noreferrer\" rel=\"nofollow\" ><em class=\"lk\">Collaborator\u5ba2\u6237\u7aef\u7684<\/em><\/a><em class=\"lk\">\u00a0Burp Suite\u53c2\u8003\u6587\u6863<\/em><\/span><\/p>\n<\/div>\n<\/div>\n<\/section>\n<hr class=\"iy hb iz ja bx jb jc jd je jf jg jh\" \/>\n<section class=\"ft fu fv fw fx\">\n<div class=\"n p\">\n<div class=\"z ab ac ae af fy ah ai\">\n<p id=\"5182\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\"><span>\uff031<\/span><\/strong><\/p>\n<p id=\"90dc\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u4e0b\u8f7d\u6b64\u4efb\u52a1\u6240\u9644\u7684\u62a5\u544a\u3002\u552f\u4e00\u7684\u5173\u952e\u95ee\u9898\u662f\u4ec0\u4e48\uff1f<\/span><\/p>\n<pre class=\"ig ih ii ij ik mt mu mv\"><span id=\"8ff9\" class=\"cs mw jj bi mx b ca my mz r na\" data-selectable-paragraph=\"\"><a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/medium.com\/@rowls.cyber\/try-hack-me-rp-burp-suite-4b68de1c69e5#1\" rel=\"noopener\" rel=\"nofollow\" ><strong class=\"mx lq\"><span>\u8de8\u57df\u8d44\u6e90\u5171\u4eab\uff1a\u53ef\u4fe1\u4efb\u4efb\u610f\u6e90<\/span><\/strong><\/a><\/span><\/pre>\n<p id=\"87fa\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\"><span>\uff032<\/span><\/strong><\/p>\n<p id=\"aecd\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>Burp\u627e\u5230\u4e86\u591a\u5c11\u201c\u67d0\u4e9b\u201d\u4f4e\u7ea7\u95ee\u9898\uff1f<\/span><\/p>\n<pre class=\"ig ih ii ij ik mt mu mv\"><span id=\"2b7c\" class=\"cs mw jj bi mx b ca my mz r na\" data-selectable-paragraph=\"\"><span>12<\/span><\/span><\/pre>\n<\/div>\n<\/div>\n<\/section>\n<hr class=\"iy hb iz ja bx jb jc jd je jf jg jh\" \/>\n<section class=\"ft fu fv fw fx\">\n<div class=\"n p\">\n<div class=\"z ab ac ae af fy ah ai\">\n<h1 id=\"f30e\" class=\"ji jj bi bh et jk jl jm jn jo jp jq jr js jt ju jv jw jx jy jz cs\" data-selectable-paragraph=\"\"><span>\u989d\u5916\u4fe1\u7528<\/span><\/h1>\n<p id=\"9b20\" class=\"ka kb bi kc b kd ke kf kg kh ki kj kk kl km kn ko kp kq kr ks kt ku kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u60f3\u4e86\u89e3\u66f4\u591a\uff1f\u4f60\u771f\u5e78\u8fd0\uff01Burp Suite\u7684\u5236\u9020\u5546Port Swigger\u62e5\u6709\uff08\u5927\u90e8\u5206\uff09\u514d\u8d39\u7684\u5728\u7ebfWeb\u5b89\u5168\u5b66\u9662\uff01\u8fd9\u9879\u5728\u7ebf\u57f9\u8bad\u975e\u5e38\u9002\u5408\u4e8e\u5b66\u4e60\u66f4\u591a\u6709\u5173Web\u5f00\u53d1\u6280\u672f\u7684\u77e5\u8bc6\uff0c\u5e76\u5c06\u60a8\u65b0\u9020\u7684Burp\u6280\u80fd\u7528\u4e8e\u6d4b\u8bd5\uff01\u51e0\u4e4e\u6240\u6709\u8fd9\u4e9b\u57f9\u8bad\u90fd\u662f<\/span><strong class=\"kc lq\"><span>\u514d\u8d39\u7684<\/span><\/strong><span>\uff0c\u552f\u4e00\u7684\u4f8b\u5916\u662f\u4e00\u4e9b\u5b9e\u9a8c\u5ba4\u9700\u8981Burp Suite\u4e13\u4e1a\u7248\u3002<\/span><\/p>\n<p id=\"e0a5\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u60a8\u53ef\u4ee5\u5728\u8fd9\u91cc\u627e\u5230Port Swigger Web Security Academy\u57f9\u8bad\uff1a<a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/portswigger.net\/web-security\" target=\"_blank\" rel=\"noopener nofollow noreferrer\" rel=\"nofollow\" >https<\/a>\u00a0:\/\/portswigger.net\/web-security<\/span><\/p>\n<figure class=\"ig ih ii ij ik il fn fo paragraph-image\">\n<div class=\"im in cc io ai\">\n<div class=\"fn fo or\">\n<div class=\"is r cc fb\">\n<div class=\"os iu r\">\n<div class=\"cb ip s t u ds ai bu iq ir\"><img loading=\"lazy\" decoding=\"async\" class=\"s t u ds ai iv iw ap uu\" data-original=\"https:\/\/miro.medium.com\/max\/60\/0*6Ool8_wTjDmqkbto.png?q=20\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" width=\"1514\" height=\"409\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe95\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe95\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"eg ul s t u ds ai c\" data-original=\"https:\/\/miro.medium.com\/max\/1893\/0*6Ool8_wTjDmqkbto.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" sizes=\"auto, 700px\" srcset=\"https:\/\/miro.medium.com\/max\/345\/0*6Ool8_wTjDmqkbto.png 276w, https:\/\/miro.medium.com\/max\/690\/0*6Ool8_wTjDmqkbto.png 552w, https:\/\/miro.medium.com\/max\/800\/0*6Ool8_wTjDmqkbto.png 640w, https:\/\/miro.medium.com\/max\/875\/0*6Ool8_wTjDmqkbto.png 700w\" width=\"1514\" height=\"409\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe96\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe96\" \/><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/figure>\n<p id=\"ae11\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u9664\u4e86Port Swigger\u7684\u57f9\u8bad\u4e4b\u5916\uff0cSANS\u8fd8\u63d0\u4f9b\u51fa\u8272\u7684Web\u5e94\u7528\u7a0b\u5e8f\u6e17\u900f\u6d4b\u8bd5\u8bfe\u7a0b\u3002\u5176\u4e2d\u4e00\u4e9b\u5305\u62ecSANS\u00a0<\/span><a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/www.sans.org\/course\/web-app-penetration-testing-ethical-hacking\" target=\"_blank\" rel=\"noopener nofollow noreferrer\" rel=\"nofollow\" ><span>SEC 542<\/span><\/a><span>\u548c<\/span><a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/www.sans.org\/course\/advanced-web-app-penetration-testing-ethical-hacking\" target=\"_blank\" rel=\"noopener nofollow noreferrer\" rel=\"nofollow\" ><span>SEC 642<\/span><\/a><span>\u3002\u8bf7\u6ce8\u610f\uff0c\u8fd9\u4e9b\u57f9\u8bad\u8bfe\u7a0b\u662f\u6709\u507f\u7684\uff0c\u53ef\u80fd\u76f8\u5f53\u6602\u8d35\u3002\u8bdd\u867d\u5982\u6b64\uff0c\u5b83\u4eec\u7684\u8d28\u91cf\u4ee4\u4eba\u96be\u4ee5\u7f6e\u4fe1\uff0c\u503c\u5f97\u4e00\u8bd5\u3002<\/span><\/p>\n<figure class=\"ig ih ii ij ik il fn fo paragraph-image\">\n<div class=\"fn fo ot\">\n<div class=\"is r cc fb\">\n<div class=\"ou iu r\">\n<div class=\"cb ip s t u ds ai bu iq ir\"><img loading=\"lazy\" decoding=\"async\" class=\"s t u ds ai iv iw ap uu\" data-original=\"https:\/\/miro.medium.com\/max\/60\/0*lB5tPXWUfRGgRnpZ.png?q=20\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" width=\"600\" height=\"600\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe97\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe97\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"eg ul s t u ds ai c\" data-original=\"https:\/\/miro.medium.com\/max\/750\/0*lB5tPXWUfRGgRnpZ.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" sizes=\"auto, 600px\" srcset=\"https:\/\/miro.medium.com\/max\/345\/0*lB5tPXWUfRGgRnpZ.png 276w, https:\/\/miro.medium.com\/max\/690\/0*lB5tPXWUfRGgRnpZ.png 552w, https:\/\/miro.medium.com\/max\/750\/0*lB5tPXWUfRGgRnpZ.png 600w\" width=\"600\" height=\"600\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe98\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe98\" \/><\/div>\n<\/div>\n<\/div>\n<\/figure>\n<p id=\"17c1\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u6700\u540e\u4f46\u5e76\u975e\u6700\u4e0d\u91cd\u8981\u7684\u662f\uff0c\u60a8\u53ef\u4ee5\u5728TryHackMe\u7684\u623f\u95f4\u4e2d\u7ee7\u7eed\u4f7f\u7528OWASP Juice Shop\u5b66\u4e60\uff01<\/span><a class=\"cf di lb lc ld le\" href=\"https:\/\/byy3.com\/go\/?url=https:\/\/tryhackme.com\/room\/juiceshop\" target=\"_blank\" rel=\"noopener nofollow noreferrer\" rel=\"nofollow\" ><span>\u94fe\u63a5<\/span><\/a><\/p>\n<figure class=\"ig ih ii ij ik il fn fo paragraph-image\">\n<div class=\"im in cc io ai\">\n<div class=\"fn fo ov\">\n<div class=\"is r cc fb\">\n<div class=\"ow iu r\">\n<div class=\"cb ip s t u ds ai bu iq ir\"><img loading=\"lazy\" decoding=\"async\" class=\"s t u ds ai iv iw ap uu\" data-original=\"https:\/\/miro.medium.com\/max\/50\/0*G5An9vyahPb2imji.png?q=20\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" width=\"2000\" height=\"2400\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe99\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe99\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"eg ul s t u ds ai c\" data-original=\"https:\/\/miro.medium.com\/max\/2500\/0*G5An9vyahPb2imji.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" sizes=\"auto, 700px\" srcset=\"https:\/\/miro.medium.com\/max\/345\/0*G5An9vyahPb2imji.png 276w, https:\/\/miro.medium.com\/max\/690\/0*G5An9vyahPb2imji.png 552w, https:\/\/miro.medium.com\/max\/800\/0*G5An9vyahPb2imji.png 640w, https:\/\/miro.medium.com\/max\/875\/0*G5An9vyahPb2imji.png 700w\" width=\"2000\" height=\"2400\" title=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe100\" alt=\"tryhackme&#8211;RP\uff1aBurp Suite\u63d2\u56fe100\" \/><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/figure>\n<\/div>\n<\/div>\n<\/section>\n<hr class=\"iy hb iz ja bx jb jc jd je jf jg jh\" \/>\n<section class=\"ft fu fv fw fx\">\n<div class=\"n p\">\n<div class=\"z ab ac ae af fy ah ai\">\n<p id=\"f032\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><strong class=\"kc lq\"><span>\uff031<\/span><\/strong><\/p>\n<p id=\"b637\" class=\"ka kb bi kc b kd ll kf kg kh lm kj kk kl ln kn ko kp lo kr ks kt lp kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u67e5\u770b\u63d0\u4f9b\u7684\u94fe\u63a5\u5e76\u7ee7\u7eed\u5b66\u4e60\uff01<\/span><\/p>\n<\/div>\n<\/div>\n<\/section>\n<hr class=\"iy hb iz ja bx jb jc jd je jf jg jh\" \/>\n<section class=\"ft fu fv fw fx\">\n<div class=\"n p\">\n<div class=\"z ab ac ae af fy ah ai\">\n<h1 id=\"84ae\" class=\"ji jj bi bh et jk jl jm jn jo jp jq jr js jt ju jv jw jx jy jz cs\" data-selectable-paragraph=\"\"><span>\u7ed3\u8bba<\/span><\/h1>\n<p id=\"e398\" class=\"ka kb bi kc b kd ke kf kg kh ki kj kk kl km kn ko kp kq kr ks kt ku kv kw kx ft cs\" data-selectable-paragraph=\"\"><span>\u6df1\u5165\u4e86\u89e3\u5982\u4f55\u622a\u53d6\u548c\u4fee\u6539\u53d1\u9001\u5230\u5916\u90e8\u7ad9\u70b9\u7684\u6570\u636e\u3002\u6211\u4eec\u5df2\u7ecf\u5b66\u4e60\u4e86\u5982\u4f55\u901a\u8fc7\u8f93\u5165\u4fee\u6539\u6765\u68c0\u67e5\u67d0\u4e9b\u6f0f\u6d1e\uff0c\u4ee5\u53ca\u5982\u4f55\u5411\u7f51\u7ad9\u63d0\u4ea4\u5404\u79cd\u6709\u6548\u8f7d\u8377\u3002<\/span><\/p>\n<\/div>\n<\/div>\n<\/section>\n","protected":false},"excerpt":{"rendered":"<p>tryhackme\uff0cRP\uff1aBurp Suite \u76ee\u5f55 \u5148\u51b3\u6761\u4ef6 \u4ecb\u7ecd \u5b89\u88c5 Gettin'[CA]\u8ba4\u8bc1 \u529f\u80fd\u6982 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-496","post","type-post","status-publish","format-standard","hentry","category-net-security"],"_links":{"self":[{"href":"https:\/\/byy3.com\/index.php?rest_route=\/wp\/v2\/posts\/496","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/byy3.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/byy3.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/byy3.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/byy3.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=496"}],"version-history":[{"count":0,"href":"https:\/\/byy3.com\/index.php?rest_route=\/wp\/v2\/posts\/496\/revisions"}],"wp:attachment":[{"href":"https:\/\/byy3.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=496"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/byy3.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=496"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/byy3.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=496"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}