使用 Burp Suite 进行 API 扫描
portswigger.net | 博客 | #burp-suite | #attack-surface | #rest-api | #openapi | #burp-scanner | #api-scanning
摘要
API 是常被安全团队忽视的攻击面。Burp Scanner 的爬虫为此做了改造:不再依赖网页链接,而是解析 OpenAPI v3 的 JSON 定义来枚举端点,从而对 REST API 进行自动化漏洞扫描,覆盖企业内部微服务与对外 API。
- 发布时间
- 收录时间
Skip to content