$ jython Jython 2.7.1 (default:0df7adb1b397, Jun 30 2017, 19:02:43) [Java HotSpot(TM) 64-Bit Server VM (Oracle Corporation)] on java1.8.0_201 Type "help", "copyright", "credits" or "license"for more information. >>>
# dawn @ dawndeMacBook-Pro in /usr/local/Cellar/jython/2.7.1/libexec/bin [15:25:00] $ ./pip install flask Requirement already satisfied: flask in /usr/local/Cellar/jython/2.7.1/libexec/Lib/site-packages Requirement already satisfied: itsdangerous>=0.24 in /usr/local/Cellar/jython/2.7.1/libexec/Lib/site-packages (from flask) Requirement already satisfied: Werkzeug>=0.14 in /usr/local/Cellar/jython/2.7.1/libexec/Lib/site-packages (from flask) Requirement already satisfied: Jinja2>=2.10 in /usr/local/Cellar/jython/2.7.1/libexec/Lib/site-packages (from flask) Requirement already satisfied: click>=5.1 in /usr/local/Cellar/jython/2.7.1/libexec/Lib/site-packages (from flask) Requirement already satisfied: MarkupSafe>=0.23 in /usr/local/Cellar/jython/2.7.1/libexec/Lib/site-packages (from Jinja2>=2.10->flask) You are using pip version 9.0.1, however version 19.0.3 is available. You should consider upgrading via the 'pip install --upgrade pip'command.
然后新建一个flask_session_attack.py,开始写代码了。。
Jython代码编写
首先引入burp的接口
1 2 3 4 5
from burp import IBurpExtender from burp import IContextMenuFactory from burp import IBurpExtenderCallbacks from burp import IHttpRequestResponse from burp import IHttpListener