Skip to content
P
非影
精选
最新
漏洞
研究
工具
主题
来源
搜索
搜索
🌓
English
面向安全从业者的中英双语安全研究与漏洞情报精选。
Know Your Opponent – an Inference Attack Against iOS Game Center
netspi.com
| 博客 |
#ios
|
#burp
|
#game-center
|
#inference-attack
|
#sha1
|
#email-enumeration
摘要
针对 iOS Game Center 的推理攻击:用 Burp Intruder 自动发送好友请求,借助“好友推荐”与共同好友功能返回的 SHA1 邮箱哈希进行碰撞,可枚举并确认用户的真实邮箱地址。
发布时间
2013-02-11 00:00
收录时间
2026-09-20 06:09
原文 ↗
← 上一篇
Code Review – is automated testing enough?
下一篇 →
Mobile Application Testing – Where is it?
相关内容
博客
·
netspi.com
Hacking High Scores in iOS GameCenter
通过 Burp 代理 iOS 流量,拦截 Game Center 的 submitScores 请求并把 score-value 字段改写为有符号整数最大值 9223372036844775807,即可刷出排行榜最高分,暴露 Apple 对分数提交缺乏服务端校验。
博客
·
netspi.com
使用 Burp 攻击 JavaScript Web 服务代理
介绍 JavaScript Web Service Proxy(JSWS)如何以 JavaScript 和 JSON 描述 WCF 服务的可用方法与参数,替代传统 WSDL 文件,并演示如何在 Burp 中定位和攻击这类服务端点。
博客
·
netspi.com
Java Deserialization Attacks with Burp
介绍 Burp 扩展 Java Serial Killer:借助 ysoserial 生成 Java 反序列化利用载荷,并直接在 Burp 中编辑注入被代理 HTTP 请求中的序列化对象,简化对存在反序列化漏洞应用的测试流程。
博客
·
netspi.com
Debugging Burp Extensions
讲解如何为 Burp 扩展配置 Java 远程调试:以 Wsdler 扩展为例,在 IntelliJ 中附加调试器到 Burp 进程,帮助扩展开发者定位自定义代码中的问题。
博客
·
netspi.com
拦截 iOS 原生应用流量
部分 iOS 应用因使用原生 WebSocket 而无视系统代理设置,令流量拦截变得棘手。本教程组合 Wireshark 抓包、DNS 欺骗与 Burp 中间人代理,捕获应用经非常规端口发送的敏感数据。
博客
·
netspi.com
Hacking Web Services with Burp
发布 Burp 插件 Wsdler:可直接在 Burp 中解析拦截到的 WSDL 文件并生成对应的 SOAP 操作请求,无需再经 Soap-UI 中转,简化 Web Service 渗透测试流程。
返回