Millet Fan Tool series eight: Millet fan ultra vires vulnerability Detection Tool

Source: Internet
Author: User

Mi fan Ultra-vires vulnerability detection tools are mainly to detect the site over-privileged vulnerability tools.

Principle:

This tool has three browsers built in, three browsers are completely independent, currently using the chrome kernel, we can use different users to login to the target website for three browsers, or

Set different cookies for three browsers, and then have them go to the same URL at the same time or send the same request, observe the three browser page changes, add this URL or the request

Only administrators can access, then the three browser users who are logged on without administrator rights but access to normal can be an unauthorized vulnerability. The interface is as follows:

There are two main modes of operation:

One, 2, 3rd browser is synchronized with browser number 1th.

In this case we only need to operate browser number 1th, 2, 3rd browser will follow the 1th browser to access the same address, so that we can set the number of users in the 1th browser higher privileges to detect vertical ultra vires.

Set the same level of user for three browsers to detect level of authority.

Second, all browsers and tables are synchronized.

This situation is mainly for Ajax, post, mobile app, etc., turn on the agent function, similar to burp, browser or mobile app settings agent for this tool, will catch all requests, and then we click on any request in the table, three

The browser will send this request in its own capacity, as well as observing the page changes to determine if there is an excess of authority.

Note: Currently this tool uses the Jxbrowser component, which is a chargeable component, the evaluation version of the liscense can only be used for one months at a time, after expiration requires

To jxbrowser the official application for a new liscense to replace the old lisence, or to modify the system time to expire before the time, replace the following file:

The Liscence expiration time is viewed as follows:

: Http://pan.baidu.com/s/1c1NDSVe file name Privilegecheck.jar is currently only a version of Windows, other versions later.

Millet Fan Tool series eight: Millet fan ultra vires vulnerability Detection Tool

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.