工具:burpsuite+Passive Scan Client+xray
插件地址:https://github.com/c0ny1/passive-scan-client
基础操作略过,因为文章记录一下自己的操作
2 xray命令
.xray_windows_amd64.exe webscan --listen 127.0.0.1:1664 --html-output xray-testphp.html
用的DVWA靶场,效果
参考:https://github.com/lilifengcode/Burpsuite-Plugins-Usage/blob/master/Burpsuite%E6%8F%92%E4%BB%B6%E4%B9%8BPassive%20Scan%20Client%2B%E9%95%BF%E4%BA%ADxray%E6%89%AB%E6%8F%8F%E5%99%A8%E4%BD%BF%E7%94%A8%E6%96%B9%E6%B3%95.pdf