Mi fan Ultra-vires vulnerability detection tools are mainly to detect the site over-privileged vulnerability tools.
Principle:
This tool has three browsers built in, three browsers are completely independent, currently using the chrome kernel, we can use different users to login to the target website for three browsers, or
Set different cookies for three browsers, and then have them go to the same URL at the same time or send the same request, observe the three browser page changes, add this URL or the request
Only administrators can access, then the three browser users who are logged on without administrator rights but access to normal can be an unauthorized vulnerability. The interface is as follows:
There are two main modes of operation:
One, 2, 3rd browser is synchronized with browser number 1th.
In this case we only need to operate browser number 1th, 2, 3rd browser will follow the 1th browser to access the same address, so that we can set the number of users in the 1th browser higher privileges to detect vertical ultra vires.
Set the same level of user for three browsers to detect level of authority.
Second, all browsers and tables are synchronized.
This situation is mainly for Ajax, post, mobile app, etc., turn on the agent function, similar to burp, browser or mobile app settings agent for this tool, will catch all requests, and then we click on any request in the table, three
The browser will send this request in its own capacity, as well as observing the page changes to determine if there is an excess of authority.
Note: Currently this tool uses the Jxbrowser component, which is a chargeable component, the evaluation version of the liscense can only be used for one months at a time, after expiration requires
To jxbrowser the official application for a new liscense to replace the old lisence, or to modify the system time to expire before the time, replace the following file:
The Liscence expiration time is viewed as follows:
: Http://pan.baidu.com/s/1c1NDSVe file name Privilegecheck.jar is currently only a version of Windows, other versions later.
Millet Fan Tool series eight: Millet fan ultra vires vulnerability Detection Tool