标签:erer src for xhtml googl ica cti isp event
X-Forwarded-For:字段简称xff,表示当前请求用户IP地址。伪造方式:字段:ip,并且必须要在下面留有一行空行。
1 X-Forwarded-For:123.123.123.123
Referer:字段表示请求的源地址,也就是从哪个页面发过来的请求。伪造方式:字段:完整url地址。留一行空行。
1 Referer:https://www.google.com
get请求:伪造方式:直接在url后面加上?key=value多个参数使用&隔开。
1 https://www.google.com?a=1&b=2
post请求:伪造方式:在请求行将请求方式改为POST。请求行请求方式后面可以跟参数,并在数据包的最下面直接写上key=value。(改post最好自动修改)
1 POST /?a=1 HTTP/1.1 2 Host: 111.198.29.45:49753 3 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:70.0) Gecko/20100101 Firefox/70.0 4 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 5 Accept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2 6 Accept-Encoding: gzip, deflate 7 DNT: 1 8 Connection: close 9 Cookie: look-here=cookie.php 10 Upgrade-Insecure-Requests: 1 11 Cache-Control: max-age=0 12 Content-Type: application/x-www-form-urlencoded 13 Content-Length: 3 14 15 b=2
标签:erer src for xhtml googl ica cti isp event
原文地址:https://www.cnblogs.com/PrideAssassin/p/11559921.html