๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ
  • Tried. Failed. Logged.
๐Ÿ”’์ •๋ณด๋ณด์•ˆ/๋ชจ์˜ํ•ดํ‚น

๋ชจ์˜ํ•ดํ‚น - ๋ฒ„ํ”„ ์Šค์œ„ํŠธ(Brup Suite) ์„ค์ • ๋ชจ์Œ

by Janger 2024. 8. 7.
728x90

 

 

Burp Suite ํ•œ๊ธ€ ๊นจ์ง ๋ฐฉ์ง€

 

 

1. Burp Suite๋ฅผ ์ผœ๊ณ  ์˜ค๋ฅธ์ชฝ ์ƒ๋‹จ์˜ Settings๋ฅผ ํด๋ฆญ

2. User Interface์— Message editor๋กœ ๋“ค์–ด๊ฐ€ HTTP message display์— ํ•œ๊ธ€ ํฐํŠธ(e.g. ๊ตด๋ฆผ์ฒด)๋กœ ์„ค์ •

3. Character sets์— Use a specific character set์— ์ธ์ฝ”๋”ฉ์„ UTF-8๋กœ ์„ค์ •

 

์ถœ์ฒ˜: 

https://velog.io/@dailylifecoding/Hacking-Burp-Suite-%ED%95%9C%EA%B8%80-%EA%B9%A8%EC%A7%90-%EB%B0%A9%EC%A7%80

 

 

 

Burp Suite Response Intercept ํ•˜๊ธฐ

 

1. Proxy ํƒญ์—์„œ Proxy Settings ํด๋ฆญ

2. Response interception rules์— Intercept responses on the following rules ์ฒดํฌ

 

 

 

Burp Suite์—์„œ response๊ฐ€ Intercept๊ฐ€ ์•ˆ๋˜๋Š” ๊ฒฝ์šฐ

 

์›์ธ : ์‘๋‹ต ํŒจํ‚ท์˜ ํƒ€์ž… ํ—ค๋”๊ฐ€ "text"๊ฐ€ ์•„๋‹Œ ๊ฒฝ์šฐ(e.g. json, html, application)

 

1. Response interception rules์—์„œ ์ฒซ ๋ฒˆ์งธ ๊ทœ์น™(Content type header)๋ฅผ ์ˆ˜์ •(Edit) ๋ฒ„ํŠผ์„ ๋ˆ„๋ฆ„

2. Match condition ๊ฐ’์„ (text|appication|json|html|xml|x-javascript)๋กœ ์ˆ˜์ •

 

 

 

์ถœ์ฒ˜: 

https://kk-7790.tistory.com/120

 

Burp suite์—์„œ response ๊ฐ’ ์•ˆ๋‚˜์˜ฌ๋•Œ(xml, json ๋“ฑ)

๊ฐ€๋” ์›น ์ง„๋‹จ์„ ํ•˜๋‹ค๋ณด๋ฉด ๋ฒ„ํ”„์—์„œ response(์‘๋‹ต ๊ฐ’)์ด ๋‚˜์˜ค์ง€ ์•Š๋Š” ๊ฒฝ์šฐ๊ฐ€ ์žˆ์Šต๋‹ˆ๋‹ค. ๋˜ํ•œ ์ผ๋ฐ˜์ ์ธ ํ˜•ํƒœ ์™ธ์˜ ๊ฐ’์œผ๋กœ response ๋˜๋Š” ๊ฒฝ์šฐ๊ฐ€ ์žˆ๊ธฐ๋•Œ๋ฌธ์—, ๋ฏธ๋ฆฌ ๋ฒ„ํ”„์ŠˆํŠธ์˜ ์˜ต์…˜์„ ์„ค์ •ํ•œ ๋’ค ์›น ์ทจ์•ฝ

kk-7790.tistory.com

 

 

 

728x90