XSS mining
It includes the following processes:
information collection
the first step is information collection, which can find out a series of information about the website according to the website URL. Through the URL, we can find the IP of the website, the website operating system, script language, whether there are other websites on the server and so on
vulnerability detection
when we have collected enough information, we will start to detect the vulnerability of the website. Detect whether there are some common web vulnerabilities in the website, such as SQL injection
exploit
after detecting the vulnerability of the website, it is necessary to exploit the vulnerability. Different vulnerabilities have different tools. Many times, it is difficult for us to get webshell through one vulnerability. We often need to combine several vulnerabilities to get webshell
intranet penetration
when we can communicate with the intranet host, we will start the intranet penetration. Nmap can be used to scan the intranet host, detect the online host, and detect the operating system, open port and other information
there may also be intranet servers for intranet use, which can be further infiltrated to get their permissions
trace removal
after achieving the goal, sometimes it's just for blacking in the website, hanging black pages and showing off; Or leave a back door on the website, as a broiler, go for a stroll when you have nothing to do; Or put in the Trojan horse
write penetration test report
after completing the penetration test, it is necessary to write the penetration test report for this penetration test. Clearly write where there are loopholes, as well as loophole repair methods. In order to facilitate the website administrator to repair these vulnerabilities and risks according to our penetration test report, and prevent from being attacked by hackers
LR
peeling + engineering
earning thousands of grams a day in NGL
FS / SS / MS
FM + tailoring
you also earn a lot of money in FB
SM
alchemy
FM
sq
FM + digging grass
or
digging grass + engineering
FB
with XS
STSM
running maps
different ways of making money
ZS
if you often go to FB
FM + mining / grass digging
dig grass + mining without FB
DZ
FM + mining / grass digging
DZ make money mainly by brushing the box
unpacking equipment
listen to my former friends say
at least one point card a day
LR
peeling + engineering
earning thousands of g every day in NGL
FS / SS / MS
FM + tailoring
getting a lot of income
SM
alchemy
FM
sq
FM + digging grass
or
digging grass + engineering
FB
with XS
STSM
running maps
different ways of making money
ZS
if you often get off FB
FM + mining / grass digging
if you don't go down to FB, dig grass + mining
DZ
FM + mining / grass digging
DZ mainly makes money by brushing boxes
breaking down box opening equipment
listen to my former friends say
at least one point card a day