绕过访问
免责声明
本文档仅供学习和研究使用,请勿使用文中的技术源码用于非法用途,任何人造成的任何负面影响,与本人无关.
相关文章
相关案例
相关工具
iamj0ker/bypass-403 - 一个用来绕过403报错的简单脚本
Dheerajmadhukar/4-ZERO-3 - 403/401 Bypass Methods + Bash Automation
devploit/dontgo403 - Tool to bypass 40X response codes.
ffffffff0x/403-fuzz - 针对 403 页面的 fuzz 脚本
sting8k/BurpSuite_403Bypasser - Burpsuite Extension to bypass 403 restricted directory
lobuhi/byp4xx - Pyhton script for HTTP 40X responses bypassing. Features: Verb tampering, headers, #bugbountytips tricks and 2454 User-Agents.
ivan-sincek/forbidden - Bypass 4xx HTTP response status codes and more. Based on PycURL.
相关资源
GrrrDog/weird_proxies - Reverse proxies cheatsheet
Tips
protocol based bypass
method based bypass
HTTP Header based bypass
url character/parameter bypass
304 bypass
nginx
相关文章
Common Nginx Misconfiguration leads to Path Traversal - 当 nginx 配置不当时,可使用类似
/test../private/secret.html进行目录穿越
Tomcat
相关文章
shiro
SHIRO-682 & CVE-2020-1957 | Shiro 权限绕过漏洞
SHIRO-782 & CVE-2020-11989
CVE-2020-17523