官术网_书友最值得收藏!

Scope inclusion versus exclusion

The target scope works on URL patterns. URL patterns can either be inclusive or exclusive. An inclusive pattern will allow all URLs matching the pattern to go through. An exclusive pattern will disallow all URLs matching the pattern from proceeding further. To match the scope, Burp Suite matches URLs to the patterns defined in the included list first. This allows us to add targets easily in scope. Once a target URL pattern is matched, it is checked against in the exclusion list. This is done to ensure that we don't inadvertently trigger critical functionality. For example, if we want to attack everything and not get logged out, we can exclude the Logout page. If some functionality triggers automated e-mails to thousands of users, we don't want to annoy the users by sending e-mails while testing by mistake. We should explicitly put the mentioned URLs in the exclusion list.

Spending some quality time figuring out the scope, adding the required target URLs, and ensuring that our inclusion and exclusion lists will ensure, will save us a lot of time and effort while using the other tools of the Suite. This might also be mandatory based on the testing activity we are planning to do. I highly recommend you to get comfortable using Target Scope.

主站蜘蛛池模板: 邵东县| 麻江县| 天长市| 铁岭县| 长宁区| 南郑县| 芦溪县| 隆安县| 泽州县| 兴仁县| 翼城县| 鄱阳县| 阳新县| 邵阳县| 莒南县| 神木县| 石泉县| 岐山县| 龙南县| 桐梓县| 柞水县| 姚安县| 贺州市| 会昌县| 托克逊县| 鹤岗市| 建德市| 漳州市| 胶州市| 宁津县| 酉阳| 广水市| 凌源市| 越西县| 白河县| 武汉市| 新乐市| 玉门市| 山东省| 格尔木市| 安丘市|