越权浏览
原名:bypassing-authentication-with-forced-browsing
发现并访问未受保护的页面、API 和管理接口。
- 分类
- 开发提效
- 版本
- v1.0
- 作者
- 弈韬(@ra1nzzz)
- 下载
- 1
- 收藏
- 0
- 发布
- 2026-08-18
- 更新
- 2026-08-25
- TRACE 评分
- 2.8 / 5
内容概览
- During authorized penetration tests to discover hidden or unprotected administrative pages - When testing whether authentication is consistently enforced across all application endpoints - For identifying backup files, configuration files, and debug interfaces left exposed in production - When assessing access control on API endpoints that should require authentication - During security audits to validate that all sensitive resources enforce session validation - Authorization : Written penetration testing agreement covering directory enumeration - ffuf : Fast web fuzzer (go install github.com/ffuf/ffuf/v2@latest) - Gobuster : Directory brute-force tool (apt install gobuster) - Burp Suite : For intercepting and analyzing requests and responses - Wordlists : SecLists collection (git clone https://github.com/danielmiessler/SecLists.git) - Target access : Network connectivity and valid tes…