官术网_书友最值得收藏!

  • Burp Suite Essentials
  • Akash Mahajan
  • 217字
  • 2021-08-05 17:03:39

Scope inclusion versus exclusion

The target scope works on URL patterns. URL patterns can either be inclusive or exclusive. An inclusive pattern will allow all URLs matching the pattern to go through. An exclusive pattern will disallow all URLs matching the pattern from proceeding further. To match the scope, Burp Suite matches URLs to the patterns defined in the included list first. This allows us to add targets easily in scope. Once a target URL pattern is matched, it is checked against in the exclusion list. This is done to ensure that we don't inadvertently trigger critical functionality. For example, if we want to attack everything and not get logged out, we can exclude the Logout page. If some functionality triggers automated e-mails to thousands of users, we don't want to annoy the users by sending e-mails while testing by mistake. We should explicitly put the mentioned URLs in the exclusion list.

Spending some quality time figuring out the scope, adding the required target URLs, and ensuring that our inclusion and exclusion lists will ensure, will save us a lot of time and effort while using the other tools of the Suite. This might also be mandatory based on the testing activity we are planning to do. I highly recommend you to get comfortable using Target Scope.

主站蜘蛛池模板: 仁布县| 诏安县| 东乡县| 微山县| 汝城县| 若羌县| 潼关县| 柘荣县| 贡山| 清流县| 玉溪市| 泽州县| 三台县| 图片| 齐河县| 潞西市| 安康市| 桃园市| 康平县| 抚远县| 乌苏市| 吐鲁番市| 肇源县| 胶南市| 南通市| 哈巴河县| 茶陵县| 钦州市| 加查县| 慈利县| 尚志市| 垣曲县| 遂溪县| 乐山市| 仙游县| 泽州县| 清新县| 界首市| 独山县| 全椒县| 巫溪县|