{"id":360,"date":"2024-01-22T16:19:28","date_gmt":"2024-01-22T08:19:28","guid":{"rendered":"https:\/\/blog.yiming1234.cn\/?p=360"},"modified":"2024-02-22T20:03:22","modified_gmt":"2024-02-22T12:03:22","slug":"%e5%ad%a6%e4%b9%a0%e7%ac%94%e8%ae%b02","status":"publish","type":"post","link":"https:\/\/blog.yiming1234.cn\/index.php\/2024\/%e5%ad%a6%e4%b9%a0%e7%ac%94%e8%ae%b02\/","title":{"rendered":"\u5b66\u4e60\u7b14\u8bb02"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">\u524d\u8a00<\/h2>\n\n\n\n<p>\u81ea\u5b66\u7f51\u7edc\u5b89\u5168\u7684\u7b2c\u4e8c\u5929<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\u6b63\u6587<\/h2>\n\n\n\n<p>\u4eca\u5929\u5c31\u4e3b\u8981\u662fWeb\u67b6\u6784\u5b89\u5168\u5206\u6790\uff0c\u8fd9\u51e0\u5929\u5168\u662f\u7406\u8bba\uff0c\u6253\u57fa\u7840<\/p>\n\n\n\n<p>\u4e3b\u8981\u662f\u9762\u5bf9\u9776\u573a\u5b9e\u5728\u4e0d\u77e5\u9053\u662f\u4ece\u4f55\u4e0b\u624b\uff0c\u78b0\u5230\u5f88\u591a\u4e1c\u897f\u90fd\u4e0d\u77e5\u9053\u662f\u4ec0\u4e48\u600e\u4e48\u7528\uff0c\u76f4\u63a5\u770b\u7b54\u6848\u53c8\u6d6a\u8d39\u8d44\u6e90\u4e86<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Web\u5de5\u4f5c\u673a\u5236<\/h3>\n\n\n\n<p><strong>P.S. <\/strong>ARP\uff08Address Resolution Protocol\uff09\u662f\u4e00\u79cd\u7f51\u7edc\u534f\u8bae\uff0c\u7528\u4e8e\u5c06IP\u5730\u5740\u89e3\u6790\u4e3a\u7269\u7406MAC\u5730\u5740\uff0c\u4ee5\u4fbf\u5728\u5c40\u57df\u7f51\u4e2d\u8fdb\u884c\u901a\u4fe1\u3002<\/p>\n\n\n\n<p>Host\u6587\u4ef6\u662f\u4e00\u4e2a\u6587\u672c\u6587\u4ef6\uff0c\u7528\u4e8e\u5728\u8ba1\u7b97\u673a\u7f51\u7edc\u4e2d\u5c06\u57df\u540d\u6620\u5c04\u5230\u76f8\u5e94\u7684IP\u5730\u5740\u3002\u5b83\u53ef\u4ee5\u88ab\u64cd\u4f5c\u7cfb\u7edf\u7528\u6765\u5728\u57df\u540d\u89e3\u6790\u4e4b\u524d\u5148\u68c0\u67e5\u672c\u5730\u7684\u6620\u5c04\u5173\u7cfb\uff0c\u4ece\u800c\u5feb\u901f\u5730\u5c06\u57df\u540d\u89e3\u6790\u4e3a\u5bf9\u5e94\u7684IP\u5730\u5740\u3002Host\u6587\u4ef6\u901a\u5e38\u4f4d\u4e8e\u64cd\u4f5c\u7cfb\u7edf\u7684\u7cfb\u7edf\u6587\u4ef6\u5939\u4e2d\uff0c\u4f8b\u5982Windows\u7cfb\u7edf\u4e2d\u7684C:\\Windows\\System32\\drivers\\etc\\hosts\u6587\u4ef6\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u67e5\u770b\u672c\u5730\u7f13\u5b58<\/li>\n\n\n\n<li>\u67e5\u770bHost\u6587\u4ef6<\/li>\n\n\n\n<li>IP\/ARP\uff08\u83b7\u53d6mac\u5730\u5740\uff09<\/li>\n\n\n\n<li>\u57df\u540dDNS\u89e3\u6790\uff08\u83b7\u53d6IP\u5730\u5740\uff09<\/li>\n\n\n\n<li>\u7f51\u5173 \u8def\u7531<\/li>\n\n\n\n<li>\u5230\u8fbe\u670d\u52a1\u5668\u4e3b\u673a<\/li>\n\n\n\n<li>\u8bbf\u95ee80 443\u7aef\u53e3<\/li>\n\n\n\n<li>3\u6b21\u63e1\u624b\u5efa\u7acb\u8fde\u63a5<\/li>\n\n\n\n<li>\u5ba2\u6237\u7aef\u53d1\u9001http\u6570\u636e\u5305<\/li>\n\n\n\n<li>\u670d\u52a1\u7aef\u8fdb\u884chttp\u54cd\u5e94\n<ul class=\"wp-block-list\">\n<li>.html\u6587\u4ef6\u76f4\u63a5\u53d1\u9001<\/li>\n\n\n\n<li>.php\u6587\u4ef6\u8fdb\u884c\u89e3\u6790\uff08e.g. MySQL\uff09<\/li>\n\n\n\n<li>.php\u8fd0\u884c\u7ed3\u679c\uff08html\uff09\u53d1\u9001<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<p>Web\u5bb9\u5668\u2014\u2014\u5e38\u89c1\u7684\u6709\uff1aApache\uff08php\uff09 IIS\uff08.net\uff09 Nginx\uff08\u53cd\u5411\u4ee3\u7406\u80fd\u9690\u85cf\u5185\u7f51IP,\u8fdb\u884c\u8d1f\u8f7d\u5747\u8861\uff09<\/p>\n\n\n\n<p>\u4e2d\u95f4\u4ef6\u670d\u52a1\u5668\u2014\u2014Apache\u670d\u52a1\u5668\u53ea\u80fd\u8fdb\u884cWeb\u670d\u52a1\uff0c\u9700\u8fde\u63a5php\u6587\u4ef6<\/p>\n\n\n\n<p>HTTP\u534f\u8bae\u2014\u2014\u8d85\u6587\u672c\u4f20\u8f93\uff0c\u6d4f\u89c8\u5668\u4e0eWeb\u670d\u52a1\u5668\u7684\u901a\u4fe1\u534f\u8bae<\/p>\n\n\n\n<p>URL\u2014\u2014\u7edf\u4e00\u8d44\u6e90\u5b9a\u4f4d\u7b26<\/p>\n\n\n\n<p>schema:\/\/login:password@address:port\/path\/to\/resource\/?query_string#fragment<\/p>\n\n\n\n<p>schema\uff08\u534f\u8bae\u5982ftp\uff0chttps\uff09login\uff08\u7528\u6237\u540d\uff0c\u9ed8\u8ba4\u53ef\u4e3a\u7a7a\uff09fragment\uff08\u951a\u70b9\uff0c\u5b9e\u73b0\u9875\u9762\u5185\u5b9a\u4f4d\uff09<\/p>\n\n\n\n<p>URL\u7f16\u7801\u2014\u2014URL\u4e2d\u5141\u8bb8\u51fa\u73b0\u5b57\u7b26\u6709\u9650\u5236\uff0c\u4f1a\u88ab\u767e\u5206\u53f7\u7f16\u7801\uff08%+ASCII\u7801\u7684\u5341\u516d\u8fdb\u5236\uff09<\/p>\n\n\n\n<p>\u62a5\u6587\u5206\u6790\u5de5\u5177\u2014\u2014HTTP\u534f\u8bae\u89c4\u8303\u8981\u6c42\uff1aF12\uff0cwireshark\uff0cfiddler\uff0cburpsuite<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">HTTP\u534f\u8bae\u89c4\u8303\u548c\u8981\u6c42<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">\u8bf7\u6c42\u62a5\u6587\u89e3\u6790<\/h4>\n\n\n\n<p>\u8bf7\u6c42\u884c\u2014\u2014\u65b9\u6cd5 \u8d44\u6e90\u8def\u5f84 \u534f\u8bae\/\u7248\u672c<\/p>\n\n\n\n<p>\u8bf7\u6c42\u5934\u2014\u2014\u62a5\u6587\u7b2c\u4e8c\u884c\u5230\u7b2c\u4e00\u4e2a\u7a7a\u884c\u4e3a\u6b62\uff08\u54cd\u5e94\u5934\u540c\u7406\uff09<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Host \u8bf7\u6c42\u8d44\u6e90\u4e3b\u673a\u7aef\u53e3\u53f7<\/li>\n\n\n\n<li>User-Agent \u6d4f\u89c8\u5668\u6307\u7eb9<\/li>\n\n\n\n<li>Refer \u5f53\u524dURL\u7684\u4e0a\u4e00\u4e2aURL\uff08\u5982\u679c\u5b58\u5728\u8df3\u8f6c\uff09<\/li>\n\n\n\n<li>Location \u91cd\u5b9a\u5411\u76ee\u6807\u9875\u9762<\/li>\n\n\n\n<li>Cookie \u8bf7\u6c42\u8005\u7684\u8eab\u4efd\u8ba4\u8bc1\u4fe1\u606f<\/li>\n\n\n\n<li>Accept-Charset \u7528\u4e8e\u6307\u5b9a\u5ba2\u6237\u7aef\u63a5\u53d7\u7684\u5b57\u7b26\u96c6<\/li>\n\n\n\n<li>Content-Type \u5411\u63a5\u6536\u65b9\u6307\u5b9a\u6570\u636e\u7c7b\u578b<\/li>\n\n\n\n<li>Content-Length \u6307\u660e\u5b9e\u4f53\u6b63\u6587\u957f\u5ea6<\/li>\n\n\n\n<li>Last-Modified \u6307\u793a\u8d44\u6e90\u6700\u540e\u4fee\u6539\u65f6\u95f4\u548c\u65e5\u671f<\/li>\n<\/ul>\n\n\n\n<p>\u8bf7\u6c42\u6b63\u6587\uff08\u8bf7\u6c42\u65b9\u5f0f\uff09<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>GET\uff0c\u8bf7\u6c42\u53d1\u9001\u8d44\u6e90\uff0c\u6ca1\u6709\u8bf7\u6c42\u6b63\u6587<\/li>\n\n\n\n<li>POST\uff0c\u63d0\u4ea4\u53c2\u6570\u8868\u5355<\/li>\n\n\n\n<li>HEAD\uff0c\u5728\u670d\u52a1\u5668\u54cd\u5e94\u4e2d\u53ea\u8fd4\u56de\u9996\u90e8<\/li>\n\n\n\n<li>PUT\uff0c\u5411\u670d\u52a1\u5668\u5199\u5165\u6587\u6863<\/li>\n\n\n\n<li>TRACE\uff0c\u56de\u663e\u6d4f\u89c8\u5668\u8bf7\u6c42<\/li>\n\n\n\n<li>OPTIONS\uff0c\u8bf7\u6c42\u544a\u77e5\u652f\u6301\u7684\u529f\u80fd<\/li>\n\n\n\n<li>DELETE\uff0c\u5220\u9664\u8bf7\u6c42\u6240\u6307\u5b9a\u7684\u8d44\u6e90<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">\u54cd\u5e94\u62a5\u6587\u89e3\u6790<\/h4>\n\n\n\n<p>\u72b6\u6001\u884c\u2014\u2014\u534f\u8bae\/\u7248\u672c \u72b6\u6001\u4ee3\u7801 \u63cf\u8ff0\u77ed\u8bed<\/p>\n\n\n\n<p>\u72b6\u6001\u4ee3\u7801 100~199\u4fe1\u606f\u6027\u72b6\u6001\u7801 200~299\u6210\u529f\u72b6\u6001\u7801 300~399\u91cd\u5b9a\u5411\u72b6\u6001\u7801 400~499\u5ba2\u6237\u7aef\u9519\u8bef\u72b6\u6001\u7801 500~599\u670d\u52a1\u5668\u9519\u8bef\u72b6\u6001\u7801<\/p>\n\n\n\n<p>\u5176\u4ed6\u540c\u7406<\/p>\n\n\n\n<p>\u540c\u6e90\u7b56\u7565\u2014\u2014URL\u4e3b\u673a\uff0cschema\uff0c\u7aef\u53e3\u53f7 \u8981\u4e00\u81f4\uff0c\u7528\u4e8e\u4fdd\u62a4iframe\u5185\u6587\u6863\uff0cajax\u7684xmlhttprequest\u8bbf\u95ee\u7684url\u4e5f\u53d7\u540c\u6e90\u7b56\u7565\u7684\u9650\u5236<\/p>\n\n\n\n<p>cross-origin denied \u7528\u4e8e\u9632\u8de8\u7ad9\u811a\u672c\uff08js\u4ee3\u7801\uff09\u653b\u51fb\uff08XSS\uff09\u2014\u2014js\u4ee3\u7801\u53ea\u80fd\u8bfb\u540c\u4e00\u4e2a\u57df\u4e0b\u9762\u7684\u7f51\u9875<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u524d\u8a00 \u81ea\u5b66\u7f51\u7edc\u5b89\u5168\u7684\u7b2c\u4e8c\u5929 \u6b63\u6587 \u4eca\u5929\u5c31\u4e3b\u8981\u662fWeb\u67b6\u6784\u5b89\u5168\u5206\u6790\uff0c\u8fd9\u51e0\u5929\u5168\u662f\u7406\u8bba\uff0c\u6253\u57fa\u7840 \u4e3b\u8981\u662f\u9762\u5bf9\u9776\u573a\u5b9e\u5728\u4e0d [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"_uf_show_specific_survey":0,"_uf_disable_surveys":false,"footnotes":""},"categories":[9],"tags":[12,37],"class_list":["post-360","post","type-post","status-publish","format-standard","hentry","category-ctfshow","tag-ctfshow","tag-knowledge-understanding"],"_links":{"self":[{"href":"https:\/\/blog.yiming1234.cn\/index.php\/wp-json\/wp\/v2\/posts\/360","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.yiming1234.cn\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.yiming1234.cn\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.yiming1234.cn\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.yiming1234.cn\/index.php\/wp-json\/wp\/v2\/comments?post=360"}],"version-history":[{"count":5,"href":"https:\/\/blog.yiming1234.cn\/index.php\/wp-json\/wp\/v2\/posts\/360\/revisions"}],"predecessor-version":[{"id":366,"href":"https:\/\/blog.yiming1234.cn\/index.php\/wp-json\/wp\/v2\/posts\/360\/revisions\/366"}],"wp:attachment":[{"href":"https:\/\/blog.yiming1234.cn\/index.php\/wp-json\/wp\/v2\/media?parent=360"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.yiming1234.cn\/index.php\/wp-json\/wp\/v2\/categories?post=360"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.yiming1234.cn\/index.php\/wp-json\/wp\/v2\/tags?post=360"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}