当前位置:网站首页>Penetration information collection steps (simplified version)
Penetration information collection steps (simplified version)
2022-06-25 04:53:00 【Key_ Words】
First step : Domain name information collection
1.whois Information Service 、 Record information inquiry
Relevant inquiry address :
Check the inner eye :https://www.tianyancha.com/
ICP Record inquiry network :http://www.beianbeian.com/
National enterprise credit information publicity system :http://www.gsxt.gov.cn/index.html
Love station filing query :https://icp.aizhan.com
The second step : Subdomain collection
1. Side station and C Segment online query address :
http://www.webscan.cc/
https://phpinfo.me/bing.php
2. Use sub domain name excavator and other software
The third step : Fingerprint identification of websites
1. Website CMS
Relevant inquiry address :
http://www.yunsee.cn/finger.html
https://whatweb.net/
http://whatweb.bugscaner.com/look/
2. The server (Linux/Windows)
utilize URL Case judgment 、 utilize ping Address determination 、 utilize nmap -O or -A To test
3. Containers (Apache/Nginx/Tomcat/IIS)
4. Script (php/jsp/asp/aspx)
According to the website URL To judge 、 Using Google grammar :site:xxx filetype:php 、 According to Firefox To determine
5. database (Mysql(3306)/Oracle(1521)/Accees/Mqlserver(1433))
Step four : Host scan 、 Port scanning
Nessus The use of scanners
https://blog.csdn.net/qq_36119192/article/details/82852117
The common ones are 135 、137 、138 、139 、445, Vulnerabilities often break out in these ports . Port scanning tools have (Nmap、masscan)
Step five : Website missed scanning
Use AWVS、Appscan、NESSUSS And so on .
Step six : Website sensitive directories and files
Use wwwscan、 The imperial sword scans the directory
边栏推荐
- JDBC (IV)
- After the newly assigned variable of the applet is modified, the original variable will also be modified
- 融合CDN,为客户打造极致服务体验!
- SOC验证环境的启动方式
- CTF_ Web: Changan cup-2021 old but a little new & asuka
- Startup mode of SoC verification environment
- Successfully solved: selenium common. exceptions. TimeoutException: Message: timeout: Timed out receiving message from
- 「 每日一练,快乐水题 」1108. IP 地址无效化
- Codeforces Round #802 (Div. 2) C D
- parallel recovery slave next change & parallel recovery push change
猜你喜欢

File upload vulnerability shooting range upload labs learning (pass1-pass5)

《QDebug 2022年6月》

The solution of wechat applet switchtab unable to take parameters

leetcode1221. Split balance string

Web3 DAPP user experience best practices

Concat() in JS

ASEMI三相整流桥的工作原理

ROS2/DDS/QoS/主题的记录

绝了!自动点赞,我用 PyAutoGUI!

哪个编程语言实现hello world最烦琐?
随机推荐
epplus复制模板后打印区域变小的问题
【Keil】ADuCM4050官方库的GPIO输出宏定义
Fun CMD command line~
本轮压力测试下,DeFi协议们表现如何?
PostgreSQL database Wal - RM_ HEAP_ ID logging action
基于SSH实现的学生成绩管理系统
三角形类(构造与析构)
[untitled]
《QDebug 2022年6月》
Region of Halcon: generation of multiple regions (3)
buuctf(re)
Swift rapid development
Student achievement management system based on SSH
绝了!自动点赞,我用 PyAutoGUI!
魔法猪系统重装大师怎么使用
DMA double buffer mode of stm32
At the age of 30, I began to learn programming by myself. Is it still time for me to have difficulties at home?
Vscade setting clang format
Huawei Hongmeng development lesson 4
[image fusion] image fusion based on MATLAB directional discrete cosine transform and principal component analysis [including Matlab source code 1907]