c0ny1 / captcha-killer Goto Github PK
View Code? Open in Web Editor NEWburp验证码识别接口调用插件
burp验证码识别接口调用插件
第一步,向 url 发送参数, 生成一段 json
第二步,解析 json 取得里面的图片地址
上面这种情况怎么办, 能在 url 获取后, 给个地方写脚本吗?
识别带有空格的图片验证码,无法去除空格
如request temple:Authorization:APPCODE e9e1e81f024742b4b3a8f57afc6c283
结果:request Raw: Authorization:APPCODE
可以升级适配下新版的burp么,2020.9.2 或者增加适配jdk9+
谢谢
通过captcha-killer识别的验证码结果如何能与intruder模块联动起来呢?
应用场景:穷举存在验证码的表单。
《captcha-killer调用tesseract-ocr识别验证码》期待早日发布
不设置标签可以正常请求接口,设置标签后无法发送请求(<@IMG_RAW></@IMG_RAW>),无报错信息。
-。
大神,capatch-killer+机器学习识别验证码给你补上了,
https://zhuanlan.zhihu.com/p/240399663
某些接口的接口响应数据格式不是固定的,数据结构属性顺序不固定,所以已有的几种匹配方式就失效了。
如下某接口返回数据格式其中两种:
{
"data": {
"captchaId": "20200520:000000000041662091123",
"recognition": "YBKR"
},
"message": "",
"code": 0
}
{"code":0,"data":{"recognition":"DMXZ","captchaId":"20200520:000000000041663755582"},"message":""}
建议用json库对返回接口进行解析,然后获取特定key值的value,准确匹配到接口返回结果。
如上解析json数据获取recognition的值。
可添加一种匹配方法,直接填入验证码的key值直接去获取他的value。一劳永逸~
请使用截图和文字说明在什么场景下出现什么bug。
如果对插件有一定的了解,可以简单说下你该bug产生的可能原因,以及你认为不错的修复建议。
A declarative, efficient, and flexible JavaScript library for building user interfaces.
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
An Open Source Machine Learning Framework for Everyone
The Web framework for perfectionists with deadlines.
A PHP framework for web artisans
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
Some thing interesting about web. New door for the world.
A server is a program made to process requests and deliver data to clients.
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
Some thing interesting about visualization, use data art
Some thing interesting about game, make everyone happy.
We are working to build community through open source technology. NB: members must have two-factor auth.
Open source projects and samples from Microsoft.
Google ❤️ Open Source for everyone.
Alibaba Open Source for everyone
Data-Driven Documents codes.
China tencent open source team.