Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

开放自定义HOST #61

Open
XF-FS opened this issue Jun 7, 2024 · 2 comments
Open

开放自定义HOST #61

XF-FS opened this issue Jun 7, 2024 · 2 comments

Comments

@XF-FS
Copy link

XF-FS commented Jun 7, 2024

需要使用对指定的接口做fuzz,对方提供了api-doc的json文件,
本地python开启http.server
然后发起扫描,指定配置的Base Path URL为服务器地址,API Document URL为本地的API-doc地址
发起扫描的时候,发现xray会将所有的请求都打啊都本地的http.server端口上,
修改Header(通过换行可以添加多个header)栏,添加host也不生效
这个可以解决吗

@yuligesec
Copy link
Contributor

修改一下api-doc.json里的地址就行了吧

@XF-FS
Copy link
Author

XF-FS commented Jun 13, 2024

有一些情况下,当你访问这个api-doc.json文件时,插件并不能提取到指纹特征进行扫描,需要手动转发让他扫描。
使用Do Auto API Scan 功能扫描json文件的时候,自动请求的数据包中他请求的host是我自己开的python IP和端口

使用Do Targe API Scan 功能扫描json文件,测试发现,将请求转发到repeater后,target地址确实改成了修改后的Targe地址,但是xray扫描时并不会根据Targe的地址选择扫描到目标,他只根据host里的地址进行扫描

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants