ÔÚÐÅÏ¢±¬Õ¨µÄÊý×ÖʱÆÚ£¬ÎÒÃÇÿÌì¶¼ÔÚÓ뺣Á¿µÄÊý¾ÝºÍÐÅÏ¢´óË®¸ñ¶·¡£ÓÐʱ£¬ÎÒÃÇ·¢ÏÖ×Ô¼ºÖÃÉíÓÚÒ»¸ö¾Þ´óµÄÊý×ÖÃÔ¹¬£¬Ñ°ÕÒÌØ¶¨ÐÅÏ¢»ò½Ó¼ûij¸öÊÜÏÞÇøÓòÈçͬº£µ×ÀÌÕë¡£Õâʱ³½£¬¡°°µ²ØÈë¿Ú¡±µÄ¸ÅÏëÓ¦Ô˶øÉú£¬ËüÃÇÈçͬÊý×ÖÊÀ½çÖеÄÒþÃØÍ¨Â·£¬¿ÉÄÜÔ®ÊÖÎÒÃÇÈÆ¹ýͨÀýõè¾¶£¬Ö±´ïÖ¸±ê¡£
¶ø¡°17c¡±×÷ΪÆäÖÐÒ»¸ö±¸ÊܹØ×¢µÄ´úºÅ£¬Æä°µ²ØÈë¿ÚÌø×ª²½ÖèµÄË÷Ç󣬸üÊÇÒý·¢ÁËÎÞÊý¼¼Êõ°®ºÃÕߺÍÐÅÏ¢ËÑË÷ÕßµÄºÃÆæÐÄ¡£
ÎÒÃDZØÒªÀí½â¡°17c¡±¿ÉÄÜ´ú±íµÄÔ¢Òâ¡£Ëü¿ÉÄÜÊÇÒ»¸öÌØ¶¨µÄ?ƽ̨¡¢Ò»ÖÖ¼¼ÊõºÍ̸£¬»òÕßÊÇÒ»¸ö°µ²ØÔÚij¸öϵͳÖеÄÌØ¶¨±êʶ·û¡£¶ø¡°°µ²ØÈë¿Ú¡±£¬¹ËÃû˼Ò壬ÊÇÖ¸ÄÇЩ²»Ö±½Ó¶³öÔÚÓû§½çÃæ£¬µ«È´ÕæÊµ´æÔڵĽӼûõè¾¶»òÊý¾Ý½Ó¿Ú¡£ÕâЩÈë¿Ú¿ÉÄܱ»Éè¼ÆÓÃÓÚÏµÍ³ÊØ»¤¡¢Êý¾Ýµ÷ÊÔ£¬»òÕßÊÇΪÁËʵÏÖÄ³Ð©ÌØ¶¨µÄÖ°Äܶø´æÔÚ¡£
°ÑÎÕÁ˽ӼûÕâЩ°µ²ØÈë¿ÚµÄ²½Ö裬¾ÍÈçͬռÓÐÁËÒ»°Ñ½âËø¸üÉî²ãÊý×ÖÊÀ½çµÄÔ¿³×¡£
17c°µ²ØÈë¿ÚµÄÌø×ª²½Ö裬ͨ³£?Éæ¼°µ½¶ÔÍøÂçºÍ̸¡¢Êý¾Ý°ü½á¹¹¡¢»òÕßÌØ¶¨ÀûÓ÷¨Ê½Âß¼µÄÉî¿ÌÀí½â¡£Õâ¿ÉÄÜÔ̺¬µ«²»ÏÞÓÚ£º
HTTP/HTTPSÒªÇóµÄ¶¨Ô죺ͨ¹ýÅú¸ÄHTTP/HTTPSÒªÇóÍ·ÖеÄÌØ¶¨×ֶΣ¬ÀýÈçUser-Agent¡¢Referer£¬»òÕßÔÚURLÖÐÔö³¤°µ²Ø²ÎÊý£¬À´ºýŪ·þÎñÆ÷£¬Ê¹ÆäÒÔΪ½Ó¼ûÕßÕ¼ÓÐÌØ¶¨µÄȨÏÞ»òÕßÀ´×Ô¿ÉÐŵįðÔ´£¬´Ó¶øÔÊÐí½Ó¼û±¾²»Ê¢¿ªµÄÄÚÈÝ¡£
CookieºÍSessionÖÎÀí£ºÀûÓÃä¯ÀÀÆ÷´æ´¢µÄCookie»ò·þÎñÆ÷¶ËµÄSessionÐÅÏ¢£¬ÈƹýµÇ¼ÑéÖ¤»òÕßÖ±½Ó½Ó¼û±ØÒªÌض¨»á»°ÄÜÁ¦½øÈëµÄ?Ò³Ãæ¡£ÓÐʱ£¬Ìض¨µÄCookieÖµ»òSessionID×ÔÉí¾Í¿ÉÄܳÉΪ½øÈë°µ²ØÈë¿ÚµÄ¡°¼ÇºÅ¡±¡£JavaScriptºÍ¿Í»§¶Ë¾ç±¾£ºÄ³Ð©°µ²Ø?Èë¿Ú¿ÉÄܱØÒªÍ¨¹ýÖ´ÐÐÌØ¶¨µÄJavaScript´úÂëÀ´¼¤»î¡£
ÕâЩ¾ç±¾¿ÉÄÜÕÆ¹Ü»ú¹ØÌØÊâµÄÒªÇ󣬻òÕßÔÚ¿Í»§¶Ë´¦ÖüÓÃÜ/½âÃܹý³Ì£¬×îÖÕʵÏÖÌø×ª¡£API½Ó¿ÚµÄÖ±½ÓŲÓ㺺ܶàÏÖ´úÀûÓö¼ÒÀÀµÓÚAPI£¨ÀûÓ÷¨Ê½½Ó¿Ú£©½øÐÐÊý¾Ý½»»¥¡£ÈôÊÇ¿ÉÄÜ·¢ÏÖ²¢Ö±½ÓŲÓÃÕâЩAPI½Ó¿Ú£¬²¢°´?ÕÕÆäÔ¤ÆÚµÄÌåʽ·¢ËÍÒªÇ󣬾ÍÓпÉÄÜÈÆ¹ýǰ¶ËµÄUIÏÞ¶È£¬Ö±½Ó»ñÈ¡Êý¾Ý»òÖ´ÐвÙ×÷¡£
URL³ÁдºÍ·Óɹ涨µÄÀûÓãºWeb·þÎñÆ÷ͨ³£Ê¹ÓÃURL³Áд¹æ¶¨À´ÓÅ»¯URL½á¹¹»òʵÏÖ¸ºÔØÆ½ºâ¡£¶ÔÕâЩ¹æ¶¨µÄÀí½â£¬ÓÐʱ¿ÉÄÜÔ®ÊÖÎÒÃÇÕÒµ½±»°µ²ØÆðÀ´µÄÕæÊµ½Ó¼ûõè¾¶¡£ºÍ̸²ã?ÃæµÄ?Ë÷Ç󣺶ÔÓÚһЩ·ÇHTTP/HTTPSºÍ̸£¬ÈçFTP¡¢Telnet£¬»òÕ߸üµ×²ãµÄÍøÂçºÍ̸£¬°µ²ØÈë¿ÚµÄÌø×ª¿ÉÄÜÉæ¼°¶ÔÕâЩºÍ̸¸öÐÔµÄÉî¿ÌÍÚ¾òºÍÀûÓá£
¹ÌÈ»¡°17c°µ²ØÈë¿Ú¡±ÌýÆðÀ´ÓÐЩÉñÃØ£¬µ«Æä±³ºóµÄ¼¼ÊõµÀÀíÔںöೡ¾°Ï¶¼ÓÐÏÖʵµÄÀûÓüÛÖµ£º
¸ßЧµÄÐÅÏ¢¼ìË÷£º¶ÔÓÚ×êÑÐÈËÔ±¡¢¿ª·¢Õß»òÊý¾Ý·ÖÎöʦ¶øÑÔ£¬ÓÐʱ¹Ù·½ÌṩµÄ?ËÑË÷ºÍ½Ó¼û½Ó¿Ú¿ÉÄÜÎÞ·¨Âú×ãÆäÉî¶ÈÐèÒª¡£Í¨¹ýË÷Çó°µ²ØÈë¿Ú£¬Äܹ»¸ü¼±¾ç¡¢¸ü¾«×¼µØ»ñÈ¡ËùÐèÊý¾Ý¡£ÏµÍ³»úÄܲâÊÔÓëÓÅ»¯£º¿ª·¢ÕßÔÚ½øÐÐϵͳѹÁ¦²âÊÔ¡¢»úÄÜÆÀ¹Àʱ£¬ÍùÍù±ØÒªÖ±½Ó½Ó¼ûϵͳµÄÖ÷Ìâ×é¼þ»òµ×²ãÊý¾Ý£¬°µ²ØÈë¿Ú±ãÌṩÁËÕâÑùµÄ·½±ã¡£
°²È«·ì϶µÄÍÚ¾òÓ뽨¸´£¨°×ñÊӽǣ©£º¶ÔÓÚ°²È«×êÑÐÈËÔ±À´Ëµ£¬·¢ÏÖºÍÀí½â°µ²ØÈë¿ÚÊÇÆÀ¹Àϵͳ°²È«ÐԵijÁÒªÒ»»·¡£Í¨¹ý·ÂÕÕ¹¥»÷Õß¿ÉÄÜÀûÓõݵ²ØÈë¿Ú£¬Äܹ»Ô®ÊÔìóÒµÌáǰ·¢ÏÖ²¢½¨¸´Ç±Ôڵݲ?È«Òþ»¼¡£Ìض¨Ö°ÄܵÄʵÏÖ£ºÓÐЩ¸´ÔÓµÄÖ°ÄÜ¿ÉÄܲ»ÊÇͨ¹ý³ß¶ÈµÄUIÁ÷³ÌÀ´Â¶³ö£¬¶øÊǰµ²ØÔÚÄ³Ð©ÌØ¶¨µÄÈë¿ÚÖ®ºó£¬ÆÚ´ýÓµÓÐÌØ¶¨ÖªÊ¶µÄÓû§È¥·¢Ïֺͼ¤»î¡£
ÖµµÃÇ¿µ÷µÄÊÇ£¬Ë÷ÇóºÍÀûÓðµ²ØÈë¿ÚµÄÐÐΪ£¬±ØÐë³ÉÁ¢ÔںϷ¨ºÏ¹æ¡¢Â·µÂÕÆ¹ÜµÄ»ù´¡ÉÏ¡£Î´¾ÊÚȨµÄ½Ó¼ûºÍÀÄÓ㬲»½ö¿ÉÄÜ´¥·¸Ë¾·¨£¬¸ü¿ÉÄܶÔϵͳ°²È«ºÍÊý¾ÝÒþÖÔÔì³ÉÑϳÁÇÖº¦¡£Òò¶ø£¬ÎÒÃÇÔÚÏíÊܼ¼Êõ´øÀ´µÄ·½±ãʱ£¬¸üӦʱ¿Ì·þâß¡°ÒÔÉÆÎª±¾¡±µÄ×¼Ôò¡£
ÔÚÏàʶÁË17c°µ²ØÈë¿ÚµÄ¸ù»ù¸ÅÏëºÍ¼¼ÊõµÀÀíÖ®ºó£¬ÈôºÎÓÐЧµØ?È¥Ë÷ÇóºÍÀûÓÃËüÃÇ£¬³ÉΪÁËÎÒÃÇÏÂÒ»²½¹Ø×¢µÄ³Áµã¡£Õâ²¢·ÇÒ»¸öµ¥Ò»µÄ¹ý³Ì£¬Ëü±ØÒª½áºÏÕ½Êõ¡¢ÏàÒ˵Ť¾ß£¬ÒÔ¼°¶ÔDZÔÚ·çÏÕµÄÇ峺Òâʶ¡£
¹«¿ªÐÅÏ¢ÍÚ¾ò£º×Ðϸ×êÑÐÓë¡°17c¡±ÓйصĹٷ½Îĵµ?¡¢ÂÛ̳»áÉÌ¡¢¼¼Êõ²©¿Í¡¢ÉõÖÁÊÇÔ´´úÂ루ÈôÊÇ¿ªÔ´£©¡£Ñ°ÕÒ¹ØÓÚÆä¼Ü¹¹¡¢APIÉè¼Æ¡¢ÒÔ¼°ÌØÊâÖ°ÄܵãµÄÖëË¿Âí¼£¡£ÐÐΪ·ÖÎö£º¹Û²ì¡°17c¡±ÔÚÕý³£Ê¹Óùý³ÌÖУ¬Æäǰ¶ËÒ³ÃæÓëºó¶Ë·þÎñÆ÷Ö®¼äÊÇÈôºÎ½øÐÐͨѶµÄ¡£
ÀûÓÃä¯ÀÀÆ÷µÄ¿ª·¢Õß¹¤¾ß£¨ÈçChromeDevTools£©Äܹ»À¹½ØºÍ·ÖÎöHTTP/HTTPSÒªÇóºÍÏìÓ¦£¬´Ó¶ø·¢ÏÖ°µ²ØµÄAPIŲÓûò²ÎÊý¡£ÈÕÖ¾·ÖÎö£¨ÈôÊǿɵã©£ºÈôÊÇ¿ÉÄÜ»ñµÃ·þÎñÆ÷¶ËµÄÈÕÖ¾Îļþ£¬ÄÇôÆäÖмͼµÄ½Ó¼ûõè¾¶¡¢ÒªÇóÏêÇé¡¢ÒÔ¼°ÃýÎóÐÅÏ¢£¬½«ÊǽÒʾ°µ²ØÈë¿ÚµÄ¹óÖØÏßË÷¡£
Ŀ¼±¬?ÆÆ£ºÊ¹ÓÃרÃŵŤ¾ß£¬³¢ÊÔ½Ó¼û·þÎñÆ÷ÉÏ¿ÉÄÜ´æ?Ôڵġ¢µ«Î´±»Á´½Óµ½µÄĿ¼ºÍÎļþ¡£ÀýÈ磬³¢ÊÔ½Ó¼û/admin/,/debug/,/api/,/internal/µÈ³£¼ûõè¾¶£¬½áºÏ¡°17c¡±µÄÌØ¶¨±êʶ·û½øÐÐ×éºÏ¡£URL²ÎÊý²Â²â£º¶ÔÒÑÖªµÄ?URL½øÐвÎÊýµÄ±äÒìºÍ²Â²â£¬³¢ÊÔÔö³¤³£¼ûµÄÖÎÀí²ÎÊý£¨Èç?debug=true,?id=test,?admin=1£©»òÕßÌØ¶¨ÓÚ¡°17c¡±µÄ²ÎÊý¡£
¶Ë¿ÚɨÃ裺ɨÃèÖ¸±ê·þÎñÆ÷ÉÏ¿ÉÄÜÊ¢¿ªµÄ¡¢¼«¶È?¹æµÄ?·þÎñ¶Ë¿Ú£¬ÕâЩ¶Ë¿Ú¿ÉÄܳÐÔØ×ÅÒ»Ð©ÌØÊâµÄÖÎÀí½Ó¿Ú»òÊý¾Ýͨ·¡£
Àí½âÊý¾ÝÌåʽ£º¡°17c¡±µÄÊý¾Ý´«Êä¿ÉÄÜѡȡJSON,XML,ProtobufµÈ·ÖÆçÌåʽ¡£Àí½âÆäÊý¾Ý½á¹¹£¬ÓÐÖúÓÚ»ú¹ØÕýÈ·µÄ?ÒªÇóÌå¡£¼ÓÃÜÓë±àÂ룺ÈôÊÇ·¢ÏÖÊý¾Ý¾¹ý¼ÓÃÜ»ò±àÂë´¦Ö㬱ØÒª³¢ÊÔ¼ø±ðËùʹÓõÄËã·¨£¨ÈçBase64,AES,RSAµÈ£©£¬²¢Ñ°ÕÒ½âÃÜ»ò½âÂëµÄ²½Öè¡£
ä¯ÀÀÆ÷¿ª·¢Õß¹¤¾ß£¨ChromeDevTools,FirefoxDeveloperEdition£©£º±Ø±¸¹¤¾ß£¬ÓÃÓÚ¼à¿ØÍøÂçÒªÇ󡢲鿴Cookie¡¢·ÖÎöJavaScript¡¢µ÷ÊÔDOM¡£´úÀí¹¤¾ß£¨BurpSuite,OWASPZAP£©£ºÖ°ÄÜ׳´óµÄWebÀûÓð²È«²âÊÔ´úÀí£¬Äܹ»À¹½Ø¡¢Åú¸Ä¡¢³Á·ÅHTTP/HTTPSÒªÇ󣬽øÐоßÌåµÄÍøÂçÁ÷Á¿·ÖÎö¡£
HTTP¿Í»§¶Ë£¨Postman,Insomnia£©£ºÓÃÓÚ»ú¹ØºÍ·¢ËÍ×Ô½ç˵µÄHTTPÒªÇ󣬲âÊÔAPI½Ó¿Ú¡£Ä¿Â¼/Îļþ±¬ÆÆ¹¤¾ß£¨Dirb,Gobuster,Ffuf£©£º×Ô¶¯»¯É¨ÃèWeb·þÎñÆ÷Éϰµ²ØµÄĿ¼ºÍÎļþ¡£URLɨÃèÓë̽²â¹¤¾ß£¨Nmap,Masscan£©£ºÓÃÓÚ¶Ë¿ÚɨÃ裬·¢ÏÖ¿ÉÄÜÊ¢¿ªµÄ¼«¶È¹æ¶Ë¿Ú¡£
¾ç±¾Ëµ»°£¨Python,JavaScript£©£ºÓÃÓÚ±àд×Ô½ç˵¾ç±¾£¬×Ô¶¯»¯¸´ÔÓµÄ̽²â¡¢½âÎöºÍ¼ÓÃܽâÃܹý³Ì¡£
Ã÷È·ÊÚȨÁìÓò£ºÈκζ԰µ²ØÈë¿ÚµÄË÷Ç󣬶¼±ØÐëÔÚÃ÷È·»ñµÃÊÚȨµÄÁìÓòÄÚ½øÐС£Î´¾ÊÚȨµÄ½Ó¼û£¬ÎÞÂÛÖ÷ÕÅÊÇ·ñ¡°ÉÆÒ⡱£¬¶¼¿ÉÄÜ´¥·¸Ë¾·¨¡£±£?»¤×ÔÉí°²È«£ºÔÚ½øÐÐÈκδó¾ÖµÄ̽²âʱ£¬Îñ±Ø°ÑÎÈ×ÔÉíIPµØÖ·µÄ°µ²ØºÍÄäÃûÐÔ¡£Ê¹ÓÃVPN¡¢TorÍøÂ磬»òÕßÔÚÊܿصIJâÊÔ»·¾³ÖнøÐвÙ×÷£¬ÒÔÔ¤·À²»ÓÃÒªµÄ·çÏÕ¡£
×ð³ÁÒþÖÔÓëÊý¾Ý°²?È«£º°µ²ØÈë¿ÚÍùÍùÖ¸ÏòÃô¸ÐÊý¾Ý»òϵͳÖ÷Ìâ¡£ÔÚ½Ó¼û¹ý³ÌÖУ¬Ñϸñ×ñÊØÊý¾Ý±£ÃÜ×¼Ôò£¬²»Ð¹Â¶¡¢²»?ÀÄÓÃÈκλñÈ¡µ½µÄÐÅÏ¢¡£Ô¤·ÀÔì³Éϵͳ·ÛË飺ÃýÎóµÄÒªÇó»ò²»µ±µÄ²Ù×÷£¬¿ÉÄܵ¼ÖÂÖ¸±êϵͳ³öÏÖ¹ÊÕÏ¡¢Êý¾ÝÃÔʧÉõÖÁ±ÀÀ£¡£ÔÚ½øÐÐÈκοÉÄÜÓ°ÏìϵͳÔËÐеIJâ?ÊÔǰ£¬Îñ±ØÈý˼£¬²¢×öºÃÊý¾Ý±¸·ÝºÍ¸´ÔÔ¤°¸¡£
½ø½¨Óë³É³¤£¬¶ø·Ç¶ñÒâÀûÓãºË÷Çó°µ²ØÈë¿ÚµÄÖÕ×ÝÖ÷ÕÅ£¬¸Ãµ±ÊÇΪÁ˽ø½¨¼¼Êõ¡¢Àí½âϵͳÔË×÷µÀÀí¡¢ÌáÉý°²È«Òâʶ¡£½«ÕâЩ֪ʶÓÃÓÚÕý¹æ£¬Èç²Î¼ÓBugBountyÏîÄ¿¡¢ÐÖúÆóÒµÌáÉý°²È«ÐÔ£¬²½áÇ×î¾ß¼ÛÖµµÄÌåÏÖ¡£
¡°17c°µ²ØÈë¿ÚÌø×ª²½Ö衱µÄË÷Ç󣬾ÍÏñÊÇÔÚÊý×ÖÊÀ½çµÄµØÍ¼ÉÏѰÕÒδ±»ÏóÕ÷µÄ°ÂÃØº½Â·¡£Ëü¼ÈÊǶԼ¼ÊõÉî¶ÈÀí½âµÄÌôÕ½£¬Ò²ÊǶÔË÷ÇóÕßÖǻۺÍÔðÈθеĿ¼Ñ顣ͨ¹ýϵͳÐÔµÄÕ½Êõ¡¢ÏàÒ˵Ť¾ß£¬ÒÔ¼°×î³ÁÒªµÄ¡ª¡ªÒ»·ÝÑϽ÷ÕÆ¹ÜµÄ̬¶È£¬ÎÒÃÇÄÜÁ¦ÔÚ±£Õϰ²È«ÓëºÏ¹æµÄǰÌáÏ£¬ÕæÕý½âËøÊý×ÖÊÀ½çµÄ¸ü¶à¿ÉÄÜÐÔ£¬Èü¼ÊõµÄÁ¦Á¿·þÎñÓÚ¸ü¿í·ºµÄÀûÓúͷ¢Õ¹¡£