ABOUT ME

-

Today
-
Yesterday
-
Total
-
  • Burp Suite ์„ค์น˜ ๋ฐ ์‚ฌ์šฉ - Windows 64 bit
    SECURITY/Webhacking 2021. 2. 17. 16:44

    1. Burp Suite ์„ค์น˜ํ•˜๊ธฐ

    ํŠน๋ณ„ํ•œ ๋‚ด์šฉ ์—†๋‹ค. ๊ทธ๋ƒฅ ์„ค์น˜ ํ”„๋กœ๊ทธ๋žจ ๋‹ค์šด๋ฐ›๊ณ  ์„ค์น˜ํ•˜๋ฉด ๋œ๋‹ค.

    ์ต์ˆ™ํ•˜์‹  ๋ถ„๋“ค์€ ํŒจ์Šค~

     

    1) ๊ณต์‹ ์‚ฌ์ดํŠธ์— ๋“ค์–ด๊ฐ€์„œ ๋‹ค์šด๋ฐ›๋Š”๋‹ค.

    (Community 2021.2.1 ์„ ๋‹ค์šด๋ฐ›์•˜๋‹ค. ๊ฐ€์žฅ ์ตœ์‹ ๊บผ)

     

    2) ๋‹ค์šด๋ฐ›์€ ํŒŒ์ผ์„ ์‹คํ–‰์‹œ์ผœ์„œ ์„ค์น˜ํ•œ๋‹ค.

    3) ๋.

     

     

    2. Burp Suite ์‚ฌ์šฉํ•˜๊ธฐ

     

    1) Burp Suite Community Edition ์‹คํ–‰

     

     

    2) Proxy ์„ค์ •์„ ํ•ด์ค€๋‹ค.

    Proxy -> Options -> Interface ์—์„œ 127.0.0.1:8080 ์œผ๋กœ ์„ค์ •ํ•ด์ค€๋‹ค.

     

    ๋˜ ๋‚ด๋ ค๋ณด๋ฉด Intercept Clinent Requests ๋ž‘ Intercept Server Responses ๊ฐ€ ์žˆ๋Š”๋ฐ ๋‘˜๋‹ค ์ฒดํฌํ•ด์ค€๋‹ค!

     

     

    3) ์‚ฌ์šฉํ•˜๋Š” ์›น๋ธŒ๋ผ์šฐ์ €์—์„œ Proxy ์„ค์ •์„ํ•ด์ค€๋‹ค. 

    3-1) Chrome & Window 10

     

    ์ปดํ“จํ„ฐ ํ”„๋ก์‹œ ์„ค์ • ์—ด๊ธฐ์—์„œ ์ˆ˜๋™ ํ”„๋ก์‹œ ์„ค์ •์„ ํ•ด์ค€๋‹ค.

    (์œ„์— ํ•ด๋†“์€ ๊ฒƒ๊ณผ ๊ฐ™์€ ์ •๋ณด๋กœ)

     

    (์ฃผ์˜! ์ €์žฅ ๊ผญ ๋ˆ„๋ฅด๊ธฐ.)

     

     

    4) Porxy -> Intercept ์—์„œ Intercept is on ์ƒํƒœ์—์„œ Request/Response ๋ฅผ Intercept ํ•  ์ˆ˜ ์žˆ๋‹ค ~~

     

     

    Request ๋ฅผ ํ•˜๊ณ  ๋ณ€์กฐํ•  ๊ฒŒ ์žˆ์œผ๋ฉด ๋ณ€์กฐ์‹œํ‚จ ๋’ค์— Forward ๋ฅผ ๋ˆ„๋ฅด๋ฉด ๋œ๋‹ค ใ…Žใ…Ž

     

    ํ”„๋ก์‹œ๋ฅผ ์—ด์–ด๋‘๊ณ  ์›น๋ธŒ๋ผ์šฐ์ €๋ฅผ ์‹คํ–‰์‹œํ‚ค๋ฉด ํŽ˜์ด์ง€ ๋กœ๋”ฉ์ด ์•ˆ๋˜๋Š”๋ฐ, ์ด๊ฒŒ ๋ฐ”๋กœ Request ๋ฅผ intercept ํ•œ ๊ฒƒ์ด๋‹ค.

    ์›ํ•˜๋Š” ๊ฒƒ์„ ์‹คํ–‰ํ•˜๊ณ  forward ๋ฅผ ํ•ด์ฃผ๋ฉด์„œ ํ”„๋ก์‹œ๋ฅผ ์ด์šฉํ•˜์ž ~

     

    ๋˜ ํ•œ ๊ฐ€์ง€! 

    Burp Suite ๋Š” ๊ธฐ๋ณธ์ ์œผ๋กœ https ๋Š” ์•ˆ๋œ๋‹ค.. ์ ‘๊ทผ์ด ์•ˆ๋จ.

    ์ด๊ฑฐ๋Š” ๋”ฐ๋กœ ์„ค์ •ํ•ด์ค˜์•ผ ํ•œ๋‹ค (์ธ์ฆ์„œ)

    'SECURITY > Webhacking' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

    Webhacking.kr :: old-43๋ฒˆ  (0) 2021.02.17
    Webhacking.kr :: old-41๋ฒˆ  (0) 2021.02.17
    Webhacking.kr :: old-12๋ฒˆ  (0) 2021.02.16
    Webhacking.kr :: old-59๋ฒˆ  (0) 2021.02.16
    Webhacking.kr :: old-36๋ฒˆ  (0) 2021.02.16

    ๋Œ“๊ธ€

Designed by Tistory.