首页
社区
课程
招聘
[原创]某出行平台网页参数wsgsig
发表于: 2天前 414

[原创]某出行平台网页参数wsgsig

2天前
414

声明
本文章中所有内容仅供学习交流使用,不用于其他任何目的,抓包内容、敏感网址、数据接口等均已做脱敏处理,严禁用于商业用途和非法用途,否则由

此产生的一切后果均与作者无关!

部分python代码

url = "d39K9s2c8@1M7s2y4Q4x3@1q4Q4x3V1k6Q4x3V1k6W2L8X3g2J5k6%4W2Q4x3X3g2^5K9h3q4G2K9Y4g2C8k6h3A6A6i4K6u0W2j5$3!0E0i4K6u0r3M7%4c8S2N6r3W2G2L8W2)9J5k6r3q4H3K9g2)9J5c8Y4y4@1j5i4c8A6L8$3&6Q4x3V1k6Y4k6i4c8G2L8X3g2A6L8X3k6G2i4K6t1$3M7i4g2G2N6q4)9K6b7R3`.`.
params = {
    "channel": "wx",
    "openid": "general_app",
    "mobiletype": "microsoft_microsoft",
    "nettype": "wifi",
    "amChannel": "50051",
    "ttid": "wx",
    .............................
}
cp = execjs.compile(open('dd05.js','r',encoding='utf-8').read())
result = cp.call('dd05', params)
params['wsgsig'] = result

response = requests.get(url, headers=headers, params=params)


print(response.text)
print(response)

c48K9s2c8@1M7s2y4Q4x3@1q4Q4x3V1k6Q4x3V1k6U0M7$3c8F1K9h3#2Y4i4K6u0W2j5$3&6Q4x3V1k6J5k6h3I4W2j5i4y4W2i4K6u0r3j5X3I4G2k6#2)9#2k6X3g2V1K9i4c8G2M7W2)9#2k6X3S2@1L8h3I4Q4x3V1k6J5k6h3I4W2j5i4y4W2x3W2)9J5k6e0c8Q4x3X3f1$3i4K6u0r3j5$3E0W2k6r3W2@1L8%4u0Q4x3V1k6H3L8s2g2Y4K9h3&6K6i4K6u0r3N6$3W2V1k6$3g2@1i4K6u0r3K9h3#2S2k6$3g2K6i4K6u0r3K9r3q4F1k6r3I4W2i4K6u0W2M7r3&6Y4i4K6t1&6i4K6y4n7">图片错误

url = "c79K9s2c8@1M7s2y4Q4x3@1q4Q4x3V1k6Q4x3V1k6W2L8X3g2J5k6%4W2Q4x3X3g2^5K9h3q4G2K9Y4g2C8k6h3A6A6i4K6u0W2j5$3!0E0i4K6u0r3M7%4c8S2N6r3W2G2L8W2)9J5k6r3q4H3K9g2)9J5c8Y4y4@1j5i4c8A6L8$3&6Q4x3V1k6Y4k6i4c8G2L8X3g2A6L8X3k6G2i4K6t1$3M7i4g2G2N6q4)9K6b7R3`.`.
params = {
    "channel": "wx",
    "openid": "general_app",
    "mobiletype": "microsoft_microsoft",
    "nettype": "wifi",
    "amChannel": "50051",
    "ttid": "wx",
    .............................
}
cp = execjs.compile(open('dd05.js','r',encoding='utf-8').read())
result = cp.call('dd05', params)
params['wsgsig'] = result

response = requests.get(url, headers=headers, params=params)


print(response.text)
print(response)

结果

386K9s2c8@1M7s2y4Q4x3@1q4Q4x3V1k6Q4x3V1k6U0M7$3c8F1K9h3#2Y4i4K6u0W2j5$3&6Q4x3V1k6J5k6h3I4W2j5i4y4W2i4K6u0r3j5X3I4G2k6#2)9#2k6X3g2V1K9i4c8G2M7W2)9#2k6X3S2@1L8h3I4Q4x3V1k6J5k6h3I4W2j5i4y4W2x3W2)9J5k6e0c8Q4x3X3f1$3i4K6u0r3j5$3E0W2k6r3W2@1L8%4u0Q4x3V1k6H3L8s2g2Y4K9h3&6K6i4K6u0r3N6$3W2V1k6$3g2@1i4K6u0r3K9h3#2S2k6$3g2K6i4K6u0r3K9r3q4F1k6r3I4W2i4K6u0W2M7r3&6Y4i4K6t1&6i4K6y4n7">图片错误编辑

总结

1.出于安全考虑,本章未提供完整流程,调试环节省略较多,只提供大致思路,具体细节要你自己还原,相信你也能调试出来。



[培训]Windows内核深度攻防:从Hook技术到Rootkit实战!

收藏
免费 0
支持
分享
最新回复 (1)
雪    币: 104
活跃值: (7782)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
2
广告引流贴
1天前
0
游客
登录 | 注册 方可回帖
返回