本文提供的破解軟體僅供軟體試用,請於24小時內刪除。
眾所周知,Burp Suite是響噹噹的web應用程式滲透測試集成平臺。從應用程式攻擊表面的最初映射和分析,到尋找和利用安全漏洞等過程,所有工具為支持整體測試程序而無縫地在一起工作。
平臺中所有工具共享同一robust框架,以便統一處理HTTP請求、持久性、認證、上遊代理、日誌記錄、報警和可擴展性。Burp Suite允許攻擊者結合手工和自動技術去枚舉、分析、攻擊Web應用程式。
1.6.24
This release adds a new Scanner check for server-side template injection.
Template engines are widely used by web applications to present dynamic data via web pages and emails. Unsafely embedding user input in templates leads to a vulnerability that is:
frequently critical, allowing full arbitrary code execution on the server; and
easily mistaken for cross-site scripting, which is usually a much less serious issue.
pass:freebuf.com
下載請點擊閱讀原文。
*作者:legendsec,轉載須註明來自FreeBuf黑客與極客(FreeBuf.COM)