当前位置:网站首页>Goby+awvs realize attack surface detection
Goby+awvs realize attack surface detection
2022-06-24 16:07:00 【Bypass】
An expanding range of attacks against , Enterprises need to start from the perspective of attackers , Detect the enterprise's network assets from the outside , Also on Web In depth scanning of the site , Timely identify and deal with high-risk risks , Then it can effectively converge the attack surface .
Automatic detection of attack surface through some tools , To a certain extent, it can improve the work efficiency of safety personnel , This article shares Goby+AWVS Realize attack surface detection , Now let's learn .
Use scenarios : Enterprise asset detection 、web Vulnerability scanning 、 Teamwork, etc .
01、Goby Server deployment
take Goby Deploy to the server to run , You can achieve unlimited scanning , Any member can share assets only by accessing the server , Conducive to team assistance .
(1) download Goby, decompression
wget https://gobies.org/goby-linux-x64-1.9.325.zip
unzip goby-linux-x64-1.9.325.zip
(2) Background operation , Output to the specified log file
# establish .sh And write the command
/home/admin/goby-linux/golib/goby-cmd-linux -apiauth user:pass -mode api -bind 0.0.0.0:8361
# Realize screen output recording to log file
nohup sh goby.sh > info.log &
(3) Local Goby client , Server management → increase , Fill in the remote server information .
02、 linkage AWVS Vulnerability scanning
(1)Goby add-in , download AWVS plug-in unit .
(2) stay Goby, Set up → Extended settings , Fill in AWVS Of API Key And address .
AWVS Of API Key Get the location as follows :
(3) stay Goby Of Web Detection inside , See the scanned assets , You can click AWVS The button , You can start the scanning task .
(4) stay AWVS Console , You can see Goby Scanning tasks issued , And the scanning task has been completed .
(5) go back to Goby client , You can see the vulnerability scanning results , Exportable vulnerability report .
边栏推荐
- MySQL日期时间戳转换
- 60 divine vs Code plug-ins!!
- 对深度可分离卷积、分组卷积、扩张卷积、转置卷积(反卷积)的理解
- Detailed explanation of estab of Stata regression table output
- nifi从入门到实战(保姆级教程)——环境篇
- Parameterized tests guide in junit5
- D. Solve the maze (thinking +bfs) codeforces round 648 (Div. 2)
- Apple is no match for the longest selling mobile phone made in China, and has finally brought back the face of the domestic mobile phone
- Mongodb Getting started Practical Tutoriel: Learning Summary Table des matières
- How to use nested tags in thymeleaf3 Tags
猜你喜欢
Most common usage of vim editor
Cap: multiple attention mechanism, interesting fine-grained classification scheme | AAAI 2021
[cloud native | kubernetes chapter] Introduction to kubernetes Foundation (III)
The penetration of 5g users of operators is far slower than that of 4G. The popularity of 5g still depends on China Radio and television
Cap: multiple attention mechanism, interesting fine-grained classification scheme | AAAI 2021
Here comes Wi Fi 7. How strong is it?
Siggraph 2022 | truly restore the hand muscles. This time, the digital human hands have bones, muscles and skin
Wechat official account debugging and natapp environment building
One article explains Jackson configuration information in detail
[application recommendation] the hands-on experience and model selection suggestions of apifox & apipost in the recent fire
随机推荐
Convert text to hexadecimal, and reverse
ZOJ - 4104 sequence in the pocket
[my advanced OpenGL learning journey] learning notes of OpenGL coordinate system
如何轻松实现在线K歌房,与王心凌合唱《山海》
一文详解JackSon配置信息
Solution of intelligent all in one machine in expressway service area
找出隐形资产--利用Hosts碰撞突破边界
How to obtain ECS metadata
Global and Chinese markets of natural insect repellents 2022-2028: Research Report on technology, participants, trends, market size and share
Several common DoS attacks
Remain true to our original aspiration
Recommend several super practical data analysis tools
MongoDB入门实战教程:学习总结目录
Global and Chinese market of insect proof clothing 2022-2028: Research Report on technology, participants, trends, market size and share
Global and Chinese markets of stainless steel barbecue ovens 2022-2028: Research Report on technology, participants, trends, market size and share
What is a framework?
Database tools in intelij can connect but cannot display schema, tables
一文理解OpenStack网络
Mongodb Getting started Practical Tutoriel: Learning Summary Table des matières
Easy installation of Jenkins