官术网_书友最值得收藏!

Multiple ways to add targets to the scope

Burp has a subtab called Scope under the Target tab. The most common way to add a target to Scope is to navigate to it using your browser, find it in the Site map subtab under the Target tab, right-click on it, and select Add to scope.

For example, if we have permission to test http://download.mozilla.org, and we want to add it to the scope, we do the following:

We can always edit the URL in the URL editor window if we need to tweak it a bit or if we made any mistakes and added something we shouldn't add. Have a look at the following screenshot:

Apart from adding the URL to the scope using the context menu, we can always paste the URL of the target as well. When we paste the URL, we can choose the protocol, host/IP, port, and filename.

Loading a list of targets from a file

Loading a list of targets from a file is the most sensible way of adding targets to the scope in Burp. In most security assessment scenarios, we are already aware of exact URLs for our targets. This allows us to build a target list, which can simply be loaded into the Scope section by clicking on the Load ... button. Have a look at the following screenshot:

Once clicked, the File Browser dialog window opens and we can choose our file. The links need to be one of each line and based on their protocol, port number, path, and so on. All the fields get set up automatically. The following screenshot contains a list of sample target URLs for illustration. Note that some of the URLs in the following screenshot may not exist in reality:

主站蜘蛛池模板: 武平县| 察雅县| 安庆市| 甘南县| 延长县| 遂溪县| 武川县| 防城港市| 德化县| 屯留县| 金堂县| 通渭县| 清水河县| 于都县| 米脂县| 秦皇岛市| 安徽省| 会泽县| 林芝县| 宜兰市| 曲周县| 静乐县| 太湖县| 三门县| 石泉县| 安化县| 冀州市| 贡觉县| 荣成市| 读书| 昌宁县| 二连浩特市| 临城县| 芜湖市| 神木县| 吉林省| 西乡县| 罗源县| 茂名市| 皮山县| 宜春市|