> For the complete documentation index, see [llms.txt](https://hacking-notes.jord4n.pro/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://hacking-notes.jord4n.pro/zh/hacking-tools/web/web-recon-and-bypass-resources.md).

# Web 侦察与绕过资源

将这些资源用于 Web 面发现、技术指纹识别、Payload 研究、WAF 检测、WAF 绕过参考以及快速概念验证支持。

## 工具与资源

<table data-card-size="large" data-column-title-hidden data-view="cards" data-full-width="false" data-search="false"><thead><tr><th>名称</th><th>描述</th><th data-type="content-ref">官方链接</th><th data-hidden data-card-cover data-type="image">封面图片</th></tr></thead><tbody><tr><td><strong>Web 模糊测试</strong></td><td>用于发现隐藏目录、文件、参数和暴露资源的内部方法。</td><td><a href="/pages/63fd481f8ed47c55bcdb0d23fa4d6bbd8c9dfeb9">/pages/63fd481f8ed47c55bcdb0d23fa4d6bbd8c9dfeb9</a></td><td><a href="/files/ebb1e5d164bca3d0bd14d013bc633ebbbcab557f">/files/ebb1e5d164bca3d0bd14d013bc633ebbbcab557f</a></td></tr><tr><td><strong>Web 指纹分析</strong></td><td>用于识别技术、框架、CMS、服务器和暴露版本的内部方法。</td><td><a href="/pages/5f4a5b84b513075412c2db843b94146221d0e25d">/pages/5f4a5b84b513075412c2db843b94146221d0e25d</a></td><td><a href="/files/1141565cdb3bbea35185d7fbac15fb872854dfd8">/files/1141565cdb3bbea35185d7fbac15fb872854dfd8</a></td></tr><tr><td><strong>子域</strong></td><td>用于通过被动、主动和公共来源技术发现子域名的内部方法。</td><td><a href="/pages/72589566bb64139b03f42051fab0c95bc4923696">/pages/72589566bb64139b03f42051fab0c95bc4923696</a></td><td><a href="/files/c581cbc9ba898707a21cac26cb818c87fda15980">/files/c581cbc9ba898707a21cac26cb818c87fda15980</a></td></tr><tr><td><strong>Google 语法搜索</strong></td><td>用于查找已收录文件、暴露面板、备份和公开 Web 资产的内部方法。</td><td><a href="/pages/6142228cb3b04dc6108419ca3c21ae887f3c44f3">/pages/6142228cb3b04dc6108419ca3c21ae887f3c44f3</a></td><td><a href="/files/f7b88c50528523fd88f087f229d8618a165148e2">/files/f7b88c50528523fd88f087f229d8618a165148e2</a></td></tr><tr><td><strong>PayloadsAllTheThings</strong></td><td>包含 Payload 示例和安全测试方法说明的参考仓库。</td><td><a href="https://github.com/swisskyrepo/PayloadsAllTheThings">https://github.com/swisskyrepo/PayloadsAllTheThings</a></td><td><a href="/files/f5c2a69d719209ee3ac824ad5f1e40876d529cca">/files/f5c2a69d719209ee3ac824ad5f1e40876d529cca</a></td></tr><tr><td><strong>RevShells</strong></td><td>用于受控实验室和评估流程的反向 Shell Payload 生成器和参考页面。</td><td><a href="https://www.revshells.com/">https://www.revshells.com/</a></td><td><a href="/files/530e3a3b19e83034680d539dfdd053eacc209769">/files/530e3a3b19e83034680d539dfdd053eacc209769</a></td></tr><tr><td><strong>WAFW00F</strong></td><td>检测并识别保护目标 Web 服务的 Web 应用防火墙指纹。</td><td><a href="https://github.com/EnableSecurity/wafw00f">https://github.com/EnableSecurity/wafw00f</a></td><td><a href="/files/4655aabf0bc1d11809995a8fc987e03548e34e4b">/files/4655aabf0bc1d11809995a8fc987e03548e34e4b</a></td></tr><tr><td><strong>Nemesida WAF 绕过</strong></td><td>专注于 WAF 绕过参考和 Payload 示例的仓库。</td><td><a href="https://github.com/nemesida-waf/waf-bypass">https://github.com/nemesida-waf/waf-bypass</a></td><td><a href="/files/59455c2f2d874112c350b75d73ceac2df9d8c1c4">/files/59455c2f2d874112c350b75d73ceac2df9d8c1c4</a></td></tr><tr><td><strong>waf-bypass.com</strong></td><td>用于 WAF 绕过 Payload 和示例的在线参考。</td><td><a href="https://waf-bypass.com/">https://waf-bypass.com/</a></td><td><a href="/files/92cc1bc694bf6f9ef4dc53baee87207f999ac809">/files/92cc1bc694bf6f9ef4dc53baee87207f999ac809</a></td></tr><tr><td><strong>HackTricks 点击劫持概念验证</strong></td><td>用于生成点击劫持概念验证页面的 Web 工具。</td><td><a href="https://tools.hacktricks.wiki/clickjacking-poc/index.html">https://tools.hacktricks.wiki/clickjacking-poc/index.html</a></td><td><a href="/files/e5f45da1c48ec14afeedee58970d92296aa1da9f">/files/e5f45da1c48ec14afeedee58970d92296aa1da9f</a></td></tr><tr><td><strong>HackTricks 域名配置分析器</strong></td><td>用于查看与域名相关配置的 Web 工具。</td><td><a href="https://tools.hacktricks.wiki/domain-config/index.html">https://tools.hacktricks.wiki/domain-config/index.html</a></td><td><a href="/files/7cf27c19a29dc5a261f8001b1a25f60ace086c86">/files/7cf27c19a29dc5a261f8001b1a25f60ace086c86</a></td></tr><tr><td><strong>HackTricks GitHub 泄露</strong></td><td>用于查找潜在 GitHub 暴露迹象的 Web 工具。</td><td><a href="https://tools.hacktricks.wiki/github-leaks/index.html">https://tools.hacktricks.wiki/github-leaks/index.html</a></td><td><a href="/files/c31eed89c3e49cdb513159b10cf37a71e3b41499">/files/c31eed89c3e49cdb513159b10cf37a71e3b41499</a></td></tr></tbody></table>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://hacking-notes.jord4n.pro/zh/hacking-tools/web/web-recon-and-bypass-resources.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
