身份认证绕过
bugcrowd.com | 漏洞 | #pentesting | #burp-suite | #authentication-bypass | #sql-injection | #web-security | #tutorial | #owasp
摘要
Pamela O'Shea 讲解渗透测试中身份认证绕过的四大检查点:强制浏览(Forced Browsing)、参数修改、会话标识预测与登录表单 SQL 注入。实验环境基于 OWASP Broken Web Applications 虚拟机(含 Google Gruyere、Mutillidae、WackoPicko、Badstore.net),全程以 Burp Suite 代理演示。
- 发布时间
- 收录时间
Skip to content