夜雨聆风 > > 办公文件 > OpenClaw教你如何快速挖掘手机端APP漏洞
当前时间: 1970-01-01 08:00:00
分类:办公文件
评论(0)
OpenClaw教你如何快速挖掘手机端APP漏洞这里不讲如何安装OpenClaw,只将如何利用龙虾,快速出洞!!!针对个人来说,还是龙虾比较方便,市面上说的其他Agent天花乱坠,使用起来,却差强人意,只有慢慢培养Agent才能找见得心应手的Agent。下面我针对如何利用OpenClaw快速挖掘安卓漏洞,做一下重点步骤讲解。在提示词中,不要写的太多,太绕,简简单单告诉它的身份即可。重点就是给它定义角色,任务经验,工作目标,消除幻觉及误报等不真实因素。比如:你的名字叫白猫,是网络安全顶级防猎专家。有十年的网络渗透测试经验,专门打击薄弱的APP,并且你对root的测试机有完全控制权。在挖掘漏洞时,请按照CNVD,漏洞厂商等标准严格挖掘。在测试验证中要避免幻觉输出,误报输出,要真实漏洞。在你不确定是否是漏洞时,按照怀疑来处理。直接在消息框中说:开始针对某某.apk进行渗透测试 它就会认真的对APP进行全方位测试,会自主接管手机进行动态分析执行到这里后,大模型就测试完成了,它也在手机上进行了智能验证第四步:出现漏洞后,可按照大模型暴的洞进行手工确认挖到一个洞就扔给它一个模板,让它按照模板格式写就行,批量写报告也没有问题。而且在大模型测试的时候,也可以让它验证一个洞写一个报告依次执行。下面是我让大模型批量写的报告和单独按照模板格式写的报告截图
基本
文件
流程
错误
SQL
调试
- 请求信息 : 2026-05-09 20:04:25 HTTP/1.1 GET : https://www.yeyulingfeng.com/a/597029.html
- 运行时间 : 0.130922s [ 吞吐率:7.64req/s ] 内存消耗:4,770.35kb 文件加载:145
- 缓存信息 : 0 reads,0 writes
- 会话信息 : SESSION_ID=f4bfa293e493af7e8910456436f451c9
- CONNECT:[ UseTime:0.000622s ] mysql:host=127.0.0.1;port=3306;dbname=wenku;charset=utf8mb4
- SHOW FULL COLUMNS FROM `fenlei` [ RunTime:0.000838s ]
- SELECT * FROM `fenlei` WHERE `fid` = 0 [ RunTime:0.002368s ]
- SELECT * FROM `fenlei` WHERE `fid` = 63 [ RunTime:0.000308s ]
- SHOW FULL COLUMNS FROM `set` [ RunTime:0.000576s ]
- SELECT * FROM `set` [ RunTime:0.000207s ]
- SHOW FULL COLUMNS FROM `article` [ RunTime:0.000599s ]
- SELECT * FROM `article` WHERE `id` = 597029 LIMIT 1 [ RunTime:0.001079s ]
- UPDATE `article` SET `lasttime` = 1778328265 WHERE `id` = 597029 [ RunTime:0.003356s ]
- SELECT * FROM `fenlei` WHERE `id` = 64 LIMIT 1 [ RunTime:0.007535s ]
- SELECT * FROM `article` WHERE `id` < 597029 ORDER BY `id` DESC LIMIT 1 [ RunTime:0.011365s ]
- SELECT * FROM `article` WHERE `id` > 597029 ORDER BY `id` ASC LIMIT 1 [ RunTime:0.001436s ]
- SELECT * FROM `article` WHERE `id` < 597029 ORDER BY `id` DESC LIMIT 10 [ RunTime:0.003030s ]
- SELECT * FROM `article` WHERE `id` < 597029 ORDER BY `id` DESC LIMIT 10,10 [ RunTime:0.006081s ]
- SELECT * FROM `article` WHERE `id` < 597029 ORDER BY `id` DESC LIMIT 20,10 [ RunTime:0.008078s ]
0.132635s