mirror of
https://github.com/Ed1s0nZ/PrivHunterAI.git
synced 2025-09-17 20:41:37 +00:00
Update README.md
This commit is contained in:
parent
9c41744789
commit
6be9a8f787
12
README.md
12
README.md
@ -44,7 +44,17 @@
|
||||
"4. 越权行为:若resB包含resA的字段(如user_id/email/balance) → 判断为越权行为(true)",
|
||||
"5. 越权行为:若返回数据均为账号A的数据 → 判断为越权行为(true)",
|
||||
"6. 无法判断:若resB.status_code为500 → 无法判断(unknown)"
|
||||
]
|
||||
],
|
||||
"深度分析模式(当快速通道未触发时执行)": {
|
||||
"结构对比": [
|
||||
"a. 字段层级对比(使用JSON Path分析嵌套结构差异)",
|
||||
"b. 关键字段匹配(如data/id/account相关字段的命名和位置)"
|
||||
],
|
||||
"语义分析": [
|
||||
"i. 数值型字段:检查是否符合同类型数据特征(如金额字段是否在合理范围)",
|
||||
"ii. 文本型字段:检查命名规范是否一致(如用户ID是否为相同格式)"
|
||||
]
|
||||
}
|
||||
}
|
||||
},
|
||||
"decision_tree": {
|
||||
|
Loading…
x
Reference in New Issue
Block a user