BurpLoader 初次体验

1 篇文章 0 订阅

第一次使用这个神器,自己试试了 记下简单的过程
用的是Chrome 然后设置代理服务器为本地
这里写图片描述
下载BurpLoader.jar 是java写的 所以jdk环境是必须的
启动java -jar BurpLoader.jar
启动之后的界面
举个简单的例子啊
我们要抓个包试试
设置代理之后这里写图片描述
随便点开一个页面就会抓包信息,开启代理模式
这里写图片描述
打开网页:http://blog.csdn.net/elsery/article/details/51085138
这里写图片描述
不用再多解释了把,提交表单的时候也能抓到,也可以修改值,所以注意安全,后台判断最安全.
抓包代码为

GET /elsery/article/details/51085138 HTTP/1.1
Host: blog.csdn.net
Cache-Control: max-age=0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36
Accept-Encoding: gzip, deflate, sdch
Accept-Language: zh-CN,zh;q=0.8
Cookie: uuid_tt_dd=-1878423435616956437_20151108; bdshare_firstime=1447559580920; __gads=ID=8a016c1715dce17d:T=1447559593:S=ALNI_MaPBKttzpRjCwMhCzFhIcaE7JliuA; __qca=P0-1746198333-1447559582277; lzstat_uv=13781287953403473492|3017872; __utma=17226283.1507013861.1447559579.1457609612.1457609612.1; __utmz=17226283.1457609612.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); cache_cart_num=0; uuid=28a3c9b6-259a-4044-b442-735c39064091; _message_m=epvxv1lhgrffgzibxxevsw1o; _ga=GA1.2.1507013861.1447559579; UserName=elsery; UserInfo=ev8QLaqSUQSvxu5T6KKCXlJ4Fkhu%2BRq6x88p0nrzXeDyNwcQIjIpDdv8%2BUwqJ5vlVvfajtCL9LEQ7YHiAo4M9mBBNUjdFX2OH4S%2B57m%2Fivs2Zz%2BuIiovvnsHIy8CrWlQ; UserNick=elsery; AU=248; UN=elsery; UE="bao1993@foxmail.com"; BT=1460167217937; access-token=e7096f3b-d13e-49bc-af10-9d1fa82e650f; __message_district_code=000000; avh=50955898%2c51085138; dc_tos=o5cieg; dc_session_id=1460170024409; __message_sys_msg_id=0; __message_gu_msg_id=0; __message_cnel_msg_id=0; __message_in_school=0
If-None-Match: W/"ded33cd57f8a90731e89f8dd9c71cf39"

这都可以伪装,但是对于https 我还没研究看看

国外网友基于faketime做的burp loader的unlimited版本. 需要一堆dll或者so. 详情见如下描述,没有分的可以去github上找. ======================== BurpUnlimited version 1.7.26 release 1.0 + Created by: mxcx@fosec.vn + Email: mxcxvn@gmail.com + Based on: BurpLoader by larry_lau + Github: https://github.com/mxcxvn/BurpUnlimited it's opensource ======================== This project is NOT intended to replace BurpLoader. It just EXTENDS BurpLoader's license! To run the project from the command line: java -javaagent:BurpUnlimited.jar -agentpath:lib/libfaketime -jar BurpUnlimited.jar or double click on BurpUnlimited.jar (set permision before) ## Notes: - There are some requirements files in lib at current folder: + burpsuite_pro_v1.7.26.jar is main object + libfaketime* Lib for hook time activation. Sourcecode is at https://github.com/faketime-java/faketime - For windows, vcredist is required: https://www.microsoft.com/en-gb/download/details.aspx?id=48145 - The folder for_windows_if_you_dont_wanna_install_vcredist is for anyone who don't wana install vcredist, please chose the file for x64 or x86, rename to vcruntime140.dll and copy to BurpUnlimited.jar's folder - To have no unexpected error, please leave all file in the folders which have not any space character (including java binary file in case not run with default java). - This version is tested run stable on MACOSX 64 bit, Ubuntu 64 bit, Windows 64 and 32 bit. If you have any error in starting, please try some ways: + Change manually your datetime to before 01/10/2017 + Build your own libfaketime, sourcecode is at https://github.com/faketime-java/faketime + Or contact me mxcxvn@gmail.com ## Hash MD5 version release 1 BurpUnlimited.jar 5cf68ad0cc2d4ee265d0da1469decf21 lib/ burpsuite_pro_v1.7.26.jar 5d1cbbebc7fb59a399ae7bcacbe05f74 libfaketime32.dll e3842711a065b672dec322c4140b950f libfaketime32.jnilib d2b62d06a972035149bfdefe1605c041 libfaketime32.so 5c2baa272037207533d74faa4291e91d libfaketime64.dll 6659efeee9698609a9ffd9ea8c9d07d1 libfaketime64.jnilib ff3dbde6a28f1c59d829cf5665c8e628 libfaketime64.so 5c2baa272037207533d74faa4291e91d for_windows_if_you_dont_wanna_install_vcredist/ vcruntime140_x32.dll b77eeaeaf5f8493189b89852f3a7a712 vcruntime140_x64.dll 6c2c88ff1b3da84b44d23a253a06c01b
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值