{"id":1371,"date":"2025-01-19T21:35:09","date_gmt":"2025-01-19T13:35:09","guid":{"rendered":"http:\/\/gzxingyu.cloud\/?p=1371"},"modified":"2025-01-19T21:35:10","modified_gmt":"2025-01-19T13:35:10","slug":"02-%e5%bc%b1%e5%8f%a3%e4%bb%a4%e5%af%86%e7%a0%81%e7%a0%b4%e8%a7%a3%e6%96%b9%e6%b3%95","status":"publish","type":"post","link":"http:\/\/gzxingyu.cloud\/index.php\/2025\/01\/19\/02-%e5%bc%b1%e5%8f%a3%e4%bb%a4%e5%af%86%e7%a0%81%e7%a0%b4%e8%a7%a3%e6%96%b9%e6%b3%95\/","title":{"rendered":"02. \u5f31\u53e3\u4ee4\u5bc6\u7801\u7834\u89e3\u65b9\u6cd5"},"content":{"rendered":"<h3>\u4e00\u3001\u5bc6\u7801\u7834\u89e3\u4ecb\u7ecd<\/h3>\n<p>\u9488\u5bf9\u4e8e\u5bc6\u7801\u7684\u6700\u5e38\u89c1\u7684\u653b\u51fb\u65b9\u5f0f\u5c31\u662f \u66b4\u529b\u7834\u89e3\uff0c\u66b4\u529b\u7834\u89e3\u7684\u539f\u7406\u5c31\u662f\u4f7f\u7528\u653b\u51fb\u8005\u81ea\u5df1\u7684\u7528\u6237\u540d\u548c\u5bc6\u7801\u5b57\u5178\uff0c\u4e0d\u65ad\u8fdb\u884c\u679a\u4e3e\uff0c\u76f4\u5230\u679a\u4e3e\u6210\u529f\u3002\u56e0\u4e3a\u7406\u8bba\u4e0a\u6765\u8bf4\uff0c\u53ea\u8981\u5b57\u5178\u8db3\u591f\u5e9e\u5927\uff0c\u679a\u4e3e\u603b\u662f\u80fd\u591f\u6210\u529f\u7684\uff01<br \/>\n\u4f46\u5b9e\u9645\u53d1\u9001\u7684\u6570\u636e\u5e76\u4e0d\u50cf\u60f3\u8c61\u4e2d\u7684\u90a3\u6837\u7b80\u5355\u2014\u2014\u201c \u6bcf\u6b21\u53ea\u5411\u670d\u52a1\u5668\u53d1\u9001\u7528\u6237\u540d\u548c\u5bc6\u7801\u5b57\u6bb5\u5373\u53ef\uff01\u201d\uff1b\u5b9e\u9645 \u60c5\u51b5\u662f\u6bcf\u6b21\u53d1\u9001\u7684\u6570\u636e\u90fd\u5fc5\u987b\u8981\u5c01\u88c5\u6210\u5b8c\u6574\u7684 HTTP \u6570\u636e\u5305\u624d\u80fd\u88ab\u670d\u52a1\u5668\u63a5\u6536\u3002 \u4f46\u662f\u4f60\u4e0d\u53ef\u80fd\u4e00\u4e2a\u4e00\u4e2a\u53bb\u624b\u52a8\u6784\u9020\u6570\u636e\u5305\uff0c\u6240\u4ee5\u5728\u5b9e\u65bd\u66b4\u529b\u7834\u89e3\u4e4b\u524d\uff0c\u6211\u4eec\u53ea\u9700\u8981\u5148\u53bb\u83b7\u53d6\u6784\u9020HTTP \u5305\u6240\u9700\u8981\u7684\u53c2\u6570\uff0c\u7136\u540e\u6254\u7ed9\u66b4\u529b\u7834\u89e3\u8f6f\u4ef6\u5de5\u5177\u6784\u9020\u6570\u636e\u5305\uff0c\u7136\u540e\u5b9e\u65bd\u653b\u51fb\u5c31\u53ef\u4ee5\u4e86\u3002<\/p>\n<h3>\u4e8c\u3001\u66b4\u529b\u7834\u89e3\u5de5\u5177<\/h3>\n<p>BurpSuite<br \/>\nHydra<br \/>\nJohn the Ripper<br \/>\nSNETCracker<\/p>\n<h3>\u4e09\u3001\u66b4\u529b\u7834\u89e3\u5b57\u5178<\/h3>\n<ul>\n<li>\u5f31\u53e3\u4ee4\u5b57\u5178<\/li>\n<li>\u521b\u5efa\u81ea\u5b9a\u4e49\u5b57\u5178<br \/>\n1.dicttools<br \/>\n<div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/gzxingyu.cloud\/wp-content\/uploads\/2025\/01\/Pasted-image-20241220213333.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"http:\/\/gzxingyu.cloud\/wp-content\/uploads\/2025\/01\/Pasted-image-20241220213333.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"Pasted image 20241220213333.png\"><\/div><br \/>\n2.pydictor<\/li>\n<\/ul>\n<pre><code>python pydictor.py -h\n\n  -h, --help            \u663e\u793a\u5e2e\u52a9\u4fe1\u606f\n  -base Type            Choose from  (d, L, c, dL, dc, Lc, dLc)\n                            d     digital             [0 - 9]\n                            L     lowercase letters   [a - z]\n                            c     capital letters     [A - Z]\n                            dL    Mix d and L         [0-9 a-z]\n                            dc    Mix d and c         [0-9 A-Z]\n                            Lc    Mix L and c         [a-z A-Z]\n                            dLc   Mix d, L and dL     [0-9 a-z A-Z]\n  -char character       \u4f7f\u7528\u81ea\u5b9a\u4e49\u5b57\u7b26\u6784\u5efa\u5b57\u5178\n  -chunk arg [arg ...]  \u4f7f\u7528multi-chunk\u6784\u5efa\u5b57\u5178\n  -extend arg [arg ...]\n                        \u6269\u5c55\u5b57\u7b26\u4e32\u5217\u8868\u6216\u6587\u4ef6\n  -plug arg [arg ...]   birthday  [\u5f00\u59cb\u65e5\u671f] [\u7ed3\u675f\u65e5\u671f], \u65f6\u95f4\u683c\u5f0f: [yyyyMMdd or ddMMyyyy(--dmy option)]\n                        ftp       [keyword1] [keyword2] ...\n                        pid4      \u4e2d\u56fd\u8eab\u4efd\u8bc1\u6700\u540e4\u4f4d\n                        pid6      \u4e2d\u56fd\u8eab\u4efd\u8bc1\u6700\u540e6\u4f4d\n                        pid8      \u4e2d\u56fd\u8eab\u4efd\u8bc1\u6700\u540e8\u4f4d\n                        scratch   [url_or_file]\n\n  --conf [file_path]    \u4f7f\u7528\u914d\u7f6e\u5b57\u7b26\u4e32\u6216\u6587\u4ef6\u6784\u5efa\u5b57\u5178\n  --sedb                \u8fdb\u5165\u793e\u4f1a\u5de5\u7a0b\u8bcd\u5178\u751f\u6210\u5668\n  -o path, --output path\n                        \u8bbe\u7f6e\u8f93\u51fa\u76ee\u5f55\u8def\u5f84\n  -tool arg [arg ...]   combiner  [dir]\n                        comparer  [minuend_file] [subtrahend_file]\n                        counter   ['v','s','vs'] [file] [view_num]\n                        handler   [file]\n                        hybrider  [file1] [file2] ...\n                        shredder  [file_or_dir]\n                        uniqbiner [dir]\n                        uniqifer  [file]\n\n  --len minlen maxlen   \u9ed8\u8ba4: min=0  max=4\n  --head prefix         \u4e3a\u9879\u76ee\u6dfb\u52a0\u5b57\u7b26\u4e32\u5934\n  --tail suffix         \u4e3a\u9879\u76ee\u6dfb\u52a0\u5b57\u7b26\u4e32\u5c3e\n  --encode encode       b16       base16 \u7f16\u7801\n                        b32       base32 \u7f16\u7801\n                        b64       base64 \u7f16\u7801\n                        des       Des\u7b97\u6cd5\u548c\u9700\u8981\u4fee\u6539\u7684\u4ee3\u7801\n                        execjs    \u6267\u884cjs\u51fd\u6570\u548c\u9700\u8981\u4fee\u6539\u4ee3\u7801\n                        hmac      Hmac\u6d88\u606f\u6458\u8981\u7b97\u6cd5\n                        md5       Md5\u6d88\u606f\u6458\u8981\u7b97\u6cd5\u8f93\u51fa32\u4e2a\u5b57\u7b26\n                        md516     Md5\u6d88\u606f\u6458\u8981\u7b97\u6cd5\u8f93\u51fa16\u4e2a\u5b57\u7b26\n                        none      \u9ed8\u8ba4\uff0c\u4e0d\u7f16\u7801\n                        rsa       Rsa\u7b97\u6cd5\uff0c\u9700\u8981\u4fee\u6539\u4ee3\u7801\n                        sha1      Sha-1\u6d88\u606f\u6458\u8981\u7b97\u6cd5\n                        sha256    Sha-256\u6d88\u606f\u6458\u8981\u7b97\u6cd5\n                        sha512    Sha-512\u6d88\u606f\u6458\u8981\u7b97\u6cd5\n                        test      \u901a\u8fc7\u4fee\u6539\u51fd\u6570\u81ea\u5b9a\u4e49\u7f16\u7801\u65b9\u6cd5\n                        url       url \u7f16\u7801\n\n  --occur letter digital special\n                        \u9ed8\u8ba4: letter &quot;&lt;=99&quot; digital &quot;&lt;=99&quot; special &quot;&lt;=99&quot;\n  --types letter digital special\n                        \u9ed8\u8ba4: letter &quot;&gt;=0&quot;  digital &quot;&gt;=0&quot;  special &quot;&gt;=0&quot;\n  --repeat letter digital special\n                        \u9ed8\u8ba4: letter &quot;&gt;=0&quot;  digital &quot;&gt;=0&quot;  special &quot;&gt;=0&quot;\n  --regex regex         \u6b63\u5219\u8868\u8fbe\u5f0f\u8fc7\u6ee4\u5668, \u9ed8\u8ba4: (.*?)\n  --level code          \u4f7f\u7528\u4ee3\u7801[1-5]\u8fc7\u6ee4\u7ed3\u679c, \u9ed8\u8ba4: 3\n  --leet code [code ...]\n                        \u9009\u62e9let\u6a21\u5f0f\u4ee3\u7801 (0, 1, 2, 11-19, 21-29)\n  --dmy                 \u4f7f\u7528 ddMMyyyy \u65f6\u95f4\u683c\u5f0f, \u9ed8\u8ba4\u65f6\u95f4\u683c\u5f0f: yyyyMMdd\n<\/code><\/pre>\n<h3>\u56db\u3001\u66b4\u529b\u7834\u89e3\u573a\u666f<\/h3>\n<h4>1.\u4e0d\u542b\u9a8c\u8bc1\u7801\u540e\u53f0<\/h4>\n<p><img decoding=\"async\" src=\"http:\/\/gzxingyu.cloud\/wp-content\/uploads\/2025\/01\/Pasted-image-20241220215057.png\" alt=\"Pasted image 20241220215057.png\"><\/p>\n<h4>2.\u4e0d\u5931\u6548\u7684\u9a8c\u8bc1\u7801<\/h4>\n<p><img decoding=\"async\" src=\"http:\/\/gzxingyu.cloud\/wp-content\/uploads\/2025\/01\/Pasted-image-20241220215125.png\" alt=\"Pasted image 20241220215125.png\"><\/p>\n<h4>3.\u5404\u79cd\u5e38\u89c1\u5e94\u7528\u7a0b\u5e8f\uff0c\u6bd4\u5982\uff1aphpmyadmin\u3001tomcat\u3001mysql<\/h4>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/gzxingyu.cloud\/wp-content\/uploads\/2025\/01\/Pasted-image-20241220215313.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"http:\/\/gzxingyu.cloud\/wp-content\/uploads\/2025\/01\/Pasted-image-20241220215313.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"Pasted image 20241220215313.png\"><\/div><br \/>\n<img decoding=\"async\" src=\"http:\/\/gzxingyu.cloud\/wp-content\/uploads\/2025\/01\/Pasted-image-20241220215330.png\" alt=\"Pasted image 20241220215330.png\"><\/p>\n<h4>4.\u5404\u79cd\u670d\u52a1\u534f\u8bae\uff1aFTP\u3001SSH\u3001RDP\u7b49<\/h4>\n","protected":false},"excerpt":{"rendered":"<p>\u4e00\u3001\u5bc6\u7801\u7834\u89e3\u4ecb\u7ecd \u9488\u5bf9\u4e8e\u5bc6\u7801\u7684\u6700\u5e38\u89c1\u7684\u653b\u51fb\u65b9\u5f0f\u5c31\u662f \u66b4\u529b\u7834\u89e3\uff0c\u66b4\u529b\u7834\u89e3\u7684\u539f\u7406\u5c31\u662f\u4f7f\u7528\u653b\u51fb\u8005\u81ea\u5df1\u7684\u7528\u6237\u540d\u548c\u5bc6\u7801\u5b57 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[49,9],"tags":[],"class_list":["post-1371","post","type-post","status-publish","format-standard","hentry","category-49","category-9"],"_links":{"self":[{"href":"http:\/\/gzxingyu.cloud\/index.php\/wp-json\/wp\/v2\/posts\/1371","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/gzxingyu.cloud\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/gzxingyu.cloud\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/gzxingyu.cloud\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/gzxingyu.cloud\/index.php\/wp-json\/wp\/v2\/comments?post=1371"}],"version-history":[{"count":1,"href":"http:\/\/gzxingyu.cloud\/index.php\/wp-json\/wp\/v2\/posts\/1371\/revisions"}],"predecessor-version":[{"id":1372,"href":"http:\/\/gzxingyu.cloud\/index.php\/wp-json\/wp\/v2\/posts\/1371\/revisions\/1372"}],"wp:attachment":[{"href":"http:\/\/gzxingyu.cloud\/index.php\/wp-json\/wp\/v2\/media?parent=1371"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/gzxingyu.cloud\/index.php\/wp-json\/wp\/v2\/categories?post=1371"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/gzxingyu.cloud\/index.php\/wp-json\/wp\/v2\/tags?post=1371"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}