渗透测试-AES数据包解密(干货|干货|干货)

admin 2023年2月21日10:10:04渗透测试-AES数据包解密(干货|干货|干货)已关闭评论99 views字数 4088阅读13分37秒阅读模式

1.提出冗余文件,找到aes加密主体文件

这里测试的是小程序包,无法用浏览器打开,所以我们想看js文件的话,在此处将js限制取掉。

图片

2.找到加密主体文件后,搜索关键字randomS,获取加密方式

图片

3.进行响应体加密替换,写死加密秘钥

a=d.randomString(16);a=d.randomString(16);a="1234567812345678";

图片

4.此时拦截数据包,数据包如下

图片

5.使用秘钥进行解密

图片

6.解密后的数据

图片

这个包做的限制还是比较好的,如果只改

businessNo:0126202302175700022489

的话,手机号不匹配会把数据清空。手机号和businessNo对应后,数据就被修改了。

附带一下加密的数据包

VXabRUv2LhUqj9Ii/YzKC+ymO22m8oKpiUQs7TeUO7uCqvdZTPZIyw8a4TUHZ5Si8JqlMRSoMkfCgupYE/pHM8iTcjcf8pO2xpo+THuvsCiBWrBTbnFF1/p7HH7pMqBpaGv4uROhxG20RoBH/T8CfJIDNpdj6rpPieIVNfUNjbNTsERqnCOMJLprhtmuusLjP4Y5R+nXxjy65ON1BolCxNj+mD3qb0K8Qw2EKizjr4xQpHb3GxmZian0TLsBASGnc7y32I1vRm+pdhjG1YaDsigpIlXhD/i5zMBP6qS/w45bCQSeqIGCWoDoKs0IXjJz32yvZYs4RGIEAixfTF0CwdRkgUSKg8aZE6/W4oxJMJJfpMpK0lhd6tUmHsDs0qVd6lIVQjRINJJ4fgsyuL95OMxDPwnrWYtjilYNkEiP40drevE+8RtDlZCa8KHU2sIP+kl4BDwYZH6KI4ehKCEfpYel2vZ6R/5CFfFgA33hT1LuhNVB2JojT+k+dbwEAB2CVIoy1MtjmeWI7A+aO46RkHil0CecR1/OTFGH9REBWUPPwWt7g97l2Pt8Qe8FfoWihJixkWjNBq5VSZoFkYNFXscbFHeWh4MN8xSzHoHQruJCDAT1ERTuuPGDDkdqHrVDnOw/+E0kXgsM4YJPdZxWMCX3uh4TAEMOL4kGeOhAWpCKepfTWV6ZtuKRdZBPPoffkpCPi/1W0qKHpMYkUvCuZQkgtsBAKi/PojlJ3I++dYmSkI+L/VbSooekxiRS8K5lnjWF4OdaaGWj8HgREiRsGIbRvgfptpMNTWscL/tY+VInE71BOI3CXvjekJ1j4pirO/5BSKr+wgrX/0oNct5YuV7Np+JjdMWgz1Ui3RF4dimV9Jux29lb8taFP0LwRkbZMqavBK1VWQe62cw86bxiPx/0wh90zVal8KEpJl4fVk+WFsZitt3HwdziC1s7swcKLG4pQg5kQGPkAbAS0ZtFJsD1jCheYGlYnVrs4BjvPMXHXyYmwz/F0IiY+VoA5pQy2SD3dPE91VdcUfLCq+EPi0P3OCGTqOne+XyR1zPHqlj30MdHZVAe0lvB7+pgNPfmVcCxriqvLFeSKOy/S+zETe0MgVf1dVM6//jPPbn1Mx3NDVDba9QDeDUZyqjsWe2py1Ap09/DOD+r+7EPiEKWjEAYO78bMCyNEEOY7MJHyva6sObXLxzjRbE1ZopRs0+aUlBZ+N3Q5KdVTxqlyWS5UnKHoZVB80aseqMjBYOa1GyDpgOa2sw8l2SR+MjoJSZ1c7CUKGZYNLLM28a3rAWQ5i7SZkQUK5RQIDg8rem5p+P60vz41rsLei4Szmerm5zPDoOfZP5+w9is837OCS4fNlkFgelEOebTEbO1U9lPzr4itYteY12I+oqV9g6TW2vyi8w1pIGhSisz6Ckz3dXCwdzAJdUK5UDFcC7eHa5PshZSZWfWp6xEtP9QiKyvv8Jj/w/CQUNvwre3pLJFA2V55rvWzTkrWpmOKzrVI+E2E6xVOVI64F/tjbbI2NdpV40Ui9he0QQBRMnkxWf2fdF6uU7Rk0cfjU0m87iPkAN99nI+owkbAe3AGl3//fYEamDIAuGvMgcan68Lk1t4XAE3CA5R1YFfUDHxjbhLJxoMPUy20YJZD2xyKUNtylbSvYH1DI/n4AixNnUHSBRT7bnxnRe1Tfy6eQXDwJnGh2e7IxSlOYcSJuth6AET3HQ8z6elMjW6HjUPfuBNlsCycoGlqVcbtVQb0DUuRRTtX2j3ypRGqndtw6S4k+1VH5CwRDnRaxIHUqOfbjABKbgIh5ZmrkP3OCGTqOne+XyR1zPHqlgSDicrsk61OS9E0M0mciWdCAFu7dhyXqpV2JONt5RN7tkiyjPXRHasXDmHSuVP358vlOfAmGCynEVqv3LREcBp3hig2ytlnRsUQmRnEKiHG3JFIv2apWQ2tNB01A0u0sIV7a8WxHYfRZlIoruKsmkgERkSiyIBvPJPvsIewDS36uOj3FHgQM1MjnZ2SCUNDLj1NQ4us8TQ5+UOSiQ4FHnTgQx63ftKeWfdTbyVEN5SZFrQE9RipKGbOotBRfwIJdnpKz6C30FZaN+z588CK/kiOvdK20+HgmzAGdjhmnexY8v4+nsMn2bh9f6TuPAh37QXgcWXv4SQ/piNQ0EVn3jRly4BziBom+tIVpinJJ2vZ7QTFf48KsfLSPjD5bopurYkF9aaP7molV8UH3RJU+StytN18LUMhhsEhNMmEmNGyfP/oP46gaZoduWNMknOusu4RwzuYxq3k6S8eW/Is93UzZlpnIJ54KTCXAgYmPL43MrqEOYB/85mKCA0j9WfPbyNIfoa4qhQPWtw0He13mfLXix7XFqoGqHhnvXrH+D9d65nfq0Nbss1HE/h6tSu0DXPLSSkKmqfQuijh3pjFpzyGVwkrp/uVI5RrfjmbJyZM7JxB1jqE4/4a0gKosDjOXO94UU1pw81qKB5IkchW37tIjIDnuPRSvSLdb1wN9E7lWi8FRvZYAhWrp1XMuRZZvzl+wIj+ksgplhTZjtMQe6xwrw/3xXEtN5/bS798muQevqw4DJPnuXmcyjl/OSZJHHc/0mHmASowp6p8KizSJfbBgcfZCa0Tzdaxyl6rPAZh0MFOP24O+h1GmBwbiFG6dgRSPFzxAaKJgZS9pdEEuh0lASRTLWFfqVAVKiw29T0ZRwwk0NCYhzwdohiP8iOz1hP0eOwKHWKhs4WN5BPKzH3MSFHaUMxfZauvAPBPy5gzLwbhOknNT2EW7tJQwKMFI0sPKRvJx6PI9JMWjYb4EaJS0Xt2vdCd8nJ9euG4H865IhEm2xqio7dvzYeooqa9IJL16wA+7X0183hr2hHtoQX8vKRbI5oX7VVKaMuhIlc7OZ7B4CFKEQ6kcRavPuJz1LMfFKO8RWLMDbdFHI5GCWPhlbymWa10fzGeKwNsgYl2KzEj2x0b2hfEMHLlf1K8lRyTf1czlKb/svQfb9Izo0H5L3YnFSCm9UXrqiKwFPb3FAhvu2k94wMkq2EbidRpNroZK9Z5ys2yNZwioYu9LHs5gKOfKfL+HGHM3txf8AaRxc8BwvB9kOkkkZV42TzxhrWCmSVx1N6wWYKjBNUUuWnUAph8LE7FJfwsHXRo0TvAdppHAw0BLoMLeLBurbVKqH/T22TTsNDgOgUWf4lkIoDHm4LgLjpLli0G0xp7Nf/QICywjyZAmTSUCpVeOQZTzMQixN5DBjGrmj+eYetfr2XbB5hw+iWNLYuOw7iKd+DS+9n6B+ElbA5lGoQdn/YxeJpgAnC/SmT0QUPzZcu9DDhOxggF/muHY+PrfVBJLxShlo00/DjKK2dfCJh10jU5gIo4Ron/xUimKIU1Or7004TfxGMxdfLnUVHGfxJULb+WuQR+YPls5wHL/YsZlDCi+N6R2g564vfexXOjgMOx4yMf0vGCN0gD2BtHaHSWZW15EHDlAeKqtjG+Mgm3jWJJBP2foueF39YtmVeL98iY5+mvrwGVHX6bCvX6Y/UzwBdzo6ovy/qaBDqzgUcLda5tWzT5GefC/hHqTBd5Hj5+XQqMbkSi3MZHlqLH/JJ+8pW2osET6wXW0t+0gLre4u3RCtlUdGiUXyXPqbw+fHZHmlm0KS4LyDcbpFb4shoFXXgOEmhQD1z91VFKQFkHTNWyPvichMutViPrJLpiI0GXF988SBa0AyAC4PCMk5j8XdGJwxIiblBjYc8wZtnpFfYsASnb7gDBWA+Ihcp/aVPWUbm

  • 左青龙
  • 微信扫一扫
  • weinxin
  • 右白虎
  • 微信扫一扫
  • weinxin
admin
  • 本文由 发表于 2023年2月21日10:10:04
  • 转载请保留本文链接(CN-SEC中文网:感谢原作者辛苦付出):
                   渗透测试-AES数据包解密(干货|干货|干货)http://cn-sec.com/archives/1562274.html