当前位置:网站首页>Cookie encryption 6
Cookie encryption 6
2022-06-27 07:31:00 【Fan zhidu】
Target website :
aHR0cHM6Ly9zZWFyY2gua29uZ2Z6LmNvbS9wcm9kdWN0X3Jlc3VsdC8/a2V5PSVFNyVCQSVBMiVFNiVBNSVCQyVFNiVBMiVBNiZzdGF0dXM9MCZfc3RwbXQ9ZXlKelpXRnlZMmhmZEhsd1pTSTZJbUZqZEdsMlpTSjk=
Directly view the home page of the developer tool cookie change , The original cookie yes :


Here simulate the request , Carry three for the first time cookie There is no way to return content .

Carry the cookie

The key to encryption is randomcode
Here is a global search : The following encryption functions are found :

Redo breakpoint :
Successfully stop , Start below fiddker Simulation of the request , Discover and reshape request Of js After the request , The access was successful, but the data was not accessed successfully . Two comparisons , Found a timestamp changing in the URL request :
// for the first time
key: A dream of red mansions
status: 0
_stpmt: eyJzZWFyY2hfdHlwZSI6ImFjdGl2ZSJ9
pagenum: 1
ajaxdata: 1
type: 1
ajaxdata: 3
_: 1656124212160
// The second time
key: A dream of red mansions
status: 0
_stpmt: eyJzZWFyY2hfdHlwZSI6ImFjdGl2ZSJ9
pagenum: 1
ajaxdata: 1
type: 1
ajaxdata: 3
_: 1656126302616Contrast two times cookie, Several fields are changing :
// for the first time
randomcodekey=srck25095106235992vl8186
randomcode=095106544682
randomcodesign=Ul7zTaxI0wRjfWzrJKASPrR3LXr1lxfA633382EzQjhMBCYnBkcaLccKFCeI%2F43Jm0XWDa%2Fjt1K62lgIxAZfXQ%3D%3D
acw_tc=276082a316561218664708696e8e1319c2d6b161a0b8ae6d80c96a79ba20b5
TY_SESSION_ID=19a09479-af25-47b9-9c7e-24d28ad4df10
// The second time
randomcodekey=srck25110502685465otd318
randomcode=110502183005
randomcodesign=I8J9dQDdtXSN04NAdd%2B9r4IUDnZnoTdulHbbwk1Tj7G2UJRm6ct1bNcJuD23pUbVvYxEhIavT8Tb19IoffPumw%3D%3D
acw_tc=276082a016561263023097143ebec60beed6bc71b21fce1a014107e68089da
TY_SESSION_ID=8f5955b7-cf47-4435-adea-ad089ec3e647, Because the first request for a web address only has a template , Can't find fidder The return content in is critical xhr request
So the second request is the key . stay fidder The feedback of the content captured in is as follows :

There are four steps above , The first step of the request is equivalent to loading a template , Set up 3 individual cookie, however

Step 2 request , Although there is no setting cookie, Return any request , But in fact, key fields are set , One feature is the band cookie visit , This is a very important tip

The third step brings two cookie Field ,, The actual test is to generate the fourth... Required by step 4 cookie

The fourth step is to take cookie, Back to json Array

The fourth step is the most critical request , That is, the purpose of setting . The required fields need to be compared , use fidder Simulate the request to test .
The additional knowledge here is : sometimes hookcookie It's no use using plug-ins , It is better to use the browser directly hook, Guess what cookie Where it was generated .
2. yes , we have hook The code can be deleted directly ,js There are two functions , When accessing the first one, set the console you set cookie It's blocked .
边栏推荐
- Basic knowledge | JS Foundation
- 用XGBoost迭代读取数据集
- Speech signal processing - concept (I): time spectrum (horizontal axis: time; vertical axis: amplitude), spectrum (horizontal axis: frequency; vertical axis: amplitude) -- Fourier transform -- > time
- guava 教程收集一些案例慢慢写 google工具类
- File 与 MultipartFile概述
- MySQL
- 语音信号处理-概念(一):时谱图(横轴:时间;纵轴:幅值)、频谱图(横轴:频率;纵轴:幅值)--傅里叶变换-->时频谱图【横轴:时间;纵轴:频率;颜色深浅:幅值】
- How to write controller layer code gracefully?
- Manim math engine
- 一个人管理1000台服务器?这款自动化运维工具一定要掌握
猜你喜欢

js来打印1-100间的质数并求总个数优化版

volatile 和 synchronized 到底啥区别?

Park and unpark in unsafe
![log4j:WARN No such property [zipPermission] in org.apache.log4j.RollingFileAppender.](/img/2c/425993cef31dd4c786f9cc5ff081ef.png)
log4j:WARN No such property [zipPermission] in org.apache.log4j.RollingFileAppender.

(已解决) npm突然报错 Cannot find module ‘D:\Program Files\nodejs\node_modules\npm\bin\npm-cli.js‘

js中判断奇偶的函数,求圆面积的函数

Solve the problem of win10 wsl2 IP change

正斜杠反斜杠的由来

一個人管理1000臺服務器?這款自動化運維工具一定要掌握

C# 请问怎么在更新数据库时候调用line与rows
随机推荐
PostgreSQL encounters permission denied in Windows system
How torch.gather works
manim 数学引擎
攻防演习防御体系构建之第一篇之介绍和防守的四个阶段
mysql关于自增和不能为空
使用 Blackbox Exporter 测试网络连通性
碎煤机crusher
Sword finger offer 07 Rebuild binary tree
uview的安装和功能
From 5 seconds to 1 second, the system flies
How can the flower e-commerce 2.0 era go after the breakthrough from 0 to 1?
Stream常用操作以及原理探索
apifox学习
Speech signal processing - concept (4): Fourier transform, short-time Fourier transform, wavelet transform
boundvalueops和opsforvalue区别
Cookie加密6
jupyter notebook文件目录
【编译原理】山东大学编译原理复习提纲
POI replacing text and pictures in docx
Websocket database listening