Burp Suite

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ

Basic Payloads

  • ๊ฐ„๋‹จํ•œ ๋ชฉ๋ก: ๊ฐ ์ค„์— ํ•ญ๋ชฉ์ด ํฌํ•จ๋œ ๋ชฉ๋ก
  • ๋Ÿฐํƒ€์ž„ ํŒŒ์ผ: ๋Ÿฐํƒ€์ž„์— ์ฝ๋Š” ๋ชฉ๋ก(๋ฉ”๋ชจ๋ฆฌ์— ๋กœ๋“œ๋˜์ง€ ์•Š์Œ). ํฐ ๋ชฉ๋ก์„ ์ง€์›ํ•˜๊ธฐ ์œ„ํ•ด.
  • ๋Œ€์†Œ๋ฌธ์ž ์ˆ˜์ •: ๋ฌธ์ž์—ด ๋ชฉ๋ก์— ์ผ๋ถ€ ๋ณ€๊ฒฝ ์‚ฌํ•ญ ์ ์šฉ(๋ณ€๊ฒฝ ์—†์Œ, ์†Œ๋ฌธ์ž, ๋Œ€๋ฌธ์ž, ๊ณ ์œ ๋ช…์‚ฌ - ์ฒซ ๊ธ€์ž๋งŒ ๋Œ€๋ฌธ์ž, ๋‚˜๋จธ์ง€๋Š” ์†Œ๋ฌธ์ž-, ๊ณ ์œ ๋ช…์‚ฌ - ์ฒซ ๊ธ€์ž๋งŒ ๋Œ€๋ฌธ์ž, ๋‚˜๋จธ์ง€๋Š” ๊ทธ๋Œ€๋กœ-).
  • ์ˆซ์ž: Z ๋‹จ๊ณ„ ๋˜๋Š” ๋ฌด์ž‘์œ„๋กœ X์—์„œ Y๊นŒ์ง€ ์ˆซ์ž ์ƒ์„ฑ.
  • ๋ธŒ๋ฃจํŠธ ํฌ์„œ: ๋ฌธ์ž ์ง‘ํ•ฉ, ์ตœ์†Œ ๋ฐ ์ตœ๋Œ€ ๊ธธ์ด.

https://github.com/0xC01DF00D/Collabfiltrator : ๋ช…๋ น์„ ์‹คํ–‰ํ•˜๊ณ  burpcollab์— ๋Œ€ํ•œ DNS ์š”์ฒญ์„ ํ†ตํ•ด ์ถœ๋ ฅ์„ ๊ฐ€์ ธ์˜ค๋Š” ํŽ˜์ด๋กœ๋“œ.

https://medium.com/@ArtsSEC/burp-suite-exporter-462531be24e

https://github.com/h3xstream/http-script-generator

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ