{"id":155677,"date":"2020-09-07T20:08:42","date_gmt":"2020-09-07T12:08:42","guid":{"rendered":"http:\/\/4563.org\/?p=155677"},"modified":"2020-09-07T20:08:42","modified_gmt":"2020-09-07T12:08:42","slug":"%e6%8a%80%e6%9c%af%e8%ae%a8%e8%ae%ba%e6%8f%90%e4%be%9b%e5%85%ac%e5%bc%80%e9%80%8f%e4%bc%a0%e6%8e%a5%e5%8f%a3%e6%9c%89%e4%bb%80%e4%b9%88%e9%a3%8e%e9%99%a9","status":"publish","type":"post","link":"http:\/\/4563.org\/?p=155677","title":{"rendered":"[\u6280\u672f\u8ba8\u8bba]\u63d0\u4f9b\u516c\u5f00\u900f\u4f20\u63a5\u53e3\u6709\u4ec0\u4e48\u98ce\u9669?"},"content":{"rendered":"<div>\n<div>\n<div>\n<h1>                  [\u6280\u672f\u8ba8\u8bba]\u63d0\u4f9b\u516c\u5f00\u900f\u4f20\u63a5\u53e3\u6709\u4ec0\u4e48\u98ce\u9669?               <\/h1>\n<p> <\/p>\n<div>\n<div> <span>\u8cc7\u6df1\u5927\u4f6c : vertigo <\/span>  <span><i><\/i> 3<\/span> <\/div>\n<div> <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div isfirst=\"1\"> <\/p>\n<p>\u6700\u8fd1\u5728\u505a\u4e00\u4e2a\u7c7b\u4f3c\u4e2a\u4eba\u6570\u636e\u9762\u677f\u7684\u7f51\u9875\u5c0f\u4ea7\u54c1,\u671f\u671b\u7528\u6237\u53ef\u4ee5\u901a\u8fc7\u62d6\u62fd\u7684\u65b9\u5f0f\u7b80\u5355\u4e34\u65f6\u521b\u4f5c\u4e00\u4e2a\u53ef\u89c6\u5316\u9762\u677f.<\/p>\n<p>\u4e00\u4e2a\u529f\u80fd\u662f\u7528\u6237\u53ef\u4ee5\u5728\u6211\u7684\u7f51\u9875\u4e0a\u8c03\u7528\u81ea\u5df1\u5199\u7684\u63a5\u53e3<\/p>\n<p>\u4f46\u662f\u4f17\u6240\u5468\u77e5,\u8ba9\u6bcf\u4e00\u4e2a\u63a5\u5165\u7684\u7528\u6237\u505a\u4e00\u904d\u63a5\u53e3\u8de8\u57df\u5c5e\u5b9e\u6709\u70b9\u9ebb\u70e6<\/p>\n<p>\u6240\u4ee5\u6211\u8ba1\u5212\u5f00\u653e get \u548c post \u4e24\u4e2a\u63a5\u53e3,\u7528\u6237\u4f7f\u7528 ajax \u63d0\u4ea4\u8bf7\u6c42 url,methods,params\/data \u7b49\u6570\u636e\u5230\u6211\u7684\u670d\u52a1\u5668\u4e0a,\u7531\u670d\u52a1\u5668\u505a\u4e00\u4e2a\u4ee3\u7406\u8bf7\u6c42\u7528\u6237\u63d0\u4ea4\u7684 url \u5e76\u900f\u4f20\u56de\u524d\u7aef,\u8fd9\u6837\u6613\u7528\u6027\u548c\u7a33\u5b9a\u6027\u90fd\u4e0d\u9519<\/p>\n<p>\u4f46\u662f\u6211\u4e0d\u592a\u4e86\u89e3\u8fd9\u6837\u505a\u662f\u5426\u6709\u98ce\u9669,\u5982\u679c\u6709\u6076\u610f\u7528\u6237\u60f3\u8981\u653b\u51fb\u4f1a\u9020\u6210\u4ec0\u4e48\u6837\u7684\u540e\u679c<\/p>\n<p>\u8bf7\u5927\u5bb6\u8d50\u6559<\/p>\n<\/p><\/div>\n<div> <b>\u5927\u4f6c\u6709\u8a71\u8aaa<\/b> (<span>7<\/span>)        <\/div>\n<div> <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<ul>\n<li data-pid=\"3299414\" data-uid=\"2\">\n<div>\n<div>\n<div> <span>\u8cc7\u6df1\u5927\u4f6c : i0error <\/span>  <\/div>\n<div> <i title=\"\u5f15\u7528\"><\/i>  <span>          <\/span> <\/div>\n<\/p><\/div>\n<div>                                                             url \u767d\u540d\u5355\uff08\u81ea\u52a8\u5ba1\u6838\u6216\u8005\u4eba\u5de5\u5ba1\uff09\uff0c\u8bf7\u6c42\u9650\u9891                                                            <\/div>\n<\/p><\/div>\n<\/li>\n<li data-pid=\"3299415\" data-uid=\"2\">\n<div>\n<div>\n<div> <span>\u4e3b<\/span> <span>\u8cc7\u6df1\u5927\u4f6c : vertigo <\/span>  <\/div>\n<div> <i title=\"\u5f15\u7528\"><\/i>  <span>          <\/span> <\/div>\n<\/p><\/div>\n<div>                                                             @i0error \u8bf7\u6c42\u9650\u989d\u5fc5\u987b\u6709,\u6211\u662f\u8bf4\u5982\u679c\u4e0d\u9650\u5236 url,\u53ef\u4ee5\u4ece\u4ec0\u4e48\u89d2\u5ea6\u6765\u641e\u7834\u574f\u5462?                                                            <\/div>\n<\/p><\/div>\n<\/li>\n<li data-pid=\"3299416\" data-uid=\"2\">\n<div>\n<div>\n<div> <span>\u8cc7\u6df1\u5927\u4f6c : WordTian <\/span>  <\/div>\n<div> <i title=\"\u5f15\u7528\"><\/i>  <span>          <\/span> <\/div>\n<\/p><\/div>\n<div>                                                             @vertigo \u626b\u63cf\u4f60\u5185\u7f51\u5f00\u7684 web \u670d\u52a1                                                            <\/div>\n<\/p><\/div>\n<\/li>\n<li data-pid=\"3299417\" data-uid=\"2\">\n<div>\n<div>\n<div> <span>\u8cc7\u6df1\u5927\u4f6c : WordTian <\/span>  <\/div>\n<div> <i title=\"\u5f15\u7528\"><\/i>  <span>          <\/span> <\/div>\n<\/p><\/div>\n<div>                                                             @WordTian \u5173\u952e\u8bcd SSRF                                                            <\/div>\n<\/p><\/div>\n<\/li>\n<li data-pid=\"3299418\" data-uid=\"2\">\n<div>\n<div>\n<div> <span>\u4e3b<\/span> <span>\u8cc7\u6df1\u5927\u4f6c : vertigo <\/span>  <\/div>\n<div> <i title=\"\u5f15\u7528\"><\/i>  <span>          <\/span> <\/div>\n<\/p><\/div>\n<div>                                                             @WordTian \u5b50\u57df\u540d\u626b\u63cf?\u8fd9\u4e2a\u53ea\u8981\u63d0\u4f9b web \u670d\u52a1\u5c31\u4f1a\u6709\u5427                                                            <\/div>\n<\/p><\/div>\n<\/li>\n<li data-pid=\"3299419\" data-uid=\"2\">\n<div>\n<div>\n<div> <span>\u8cc7\u6df1\u5927\u4f6c : WordTian <\/span>  <\/div>\n<div> <i title=\"\u5f15\u7528\"><\/i>  <span>          <\/span> <\/div>\n<\/p><\/div>\n<div>                                                             @vertigo \u4f60\u7406\u89e3\u7684\u6709\u504f\u5dee\uff0c\u6bd4\u5982\u6211\u628a url \u8bbe\u6210 http:\/\/127.0.0.1:port\/ \u6211\u5c31\u80fd\u63a2\u6d4b\u4f60\u673a\u5668\u4e0a\u6ca1\u5bf9\u5916\u5f00\u653e\u7684 web \u670d\u52a1\uff0c\u5982\u679c\u6211\u628a 127.0.0.1 \u6362\u6210\u522b\u7684\u5185\u7f51\u5730\u5740\uff0c\u5c31\u80fd\u63a2\u6d4b\u4f60\u7684\u5185\u7f51\u670d\u52a1\u3002\u603b\u4e4b\u662f\u7ed9\u4e86\u522b\u4eba\u4e00\u4e2a\u653b\u51fb\u7684\u5165\u53e3                                                            <\/div>\n<\/p><\/div>\n<\/li>\n<li data-pid=\"3299420\" data-uid=\"2\">\n<div>\n<div>\n<div> <span>\u8cc7\u6df1\u5927\u4f6c : WordTian <\/span>  <\/div>\n<div> <i title=\"\u5f15\u7528\"><\/i>  <span>          <\/span> <\/div>\n<\/p><\/div>\n<div>                                                             \u800c\u4e14\u5982\u679c\u4f60\u6ca1\u505a\u597d\u6821\u9a8c\uff0c\u6211\u751a\u81f3\u80fd\u628a\u534f\u8bae\u6362\u6389\uff0c\u53bb\u63a2\u6d4b ftp,file,dict \u7b49\u534f\u8bae\uff0c\u653b\u51fb\u65b9\u6cd5\u592a\u591a\u4e86                                                            <\/div>\n<\/p><\/div>\n<\/li>\n<li>\n","protected":false},"excerpt":{"rendered":"<p>[\u6280\u672f\u8ba8\u8bba]\u63d0\u4f9b\u516c\u5f00\u900f\u4f20\u63a5\u53e3\u6709\u4ec0\u4e48&hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[],"tags":[],"_links":{"self":[{"href":"http:\/\/4563.org\/index.php?rest_route=\/wp\/v2\/posts\/155677"}],"collection":[{"href":"http:\/\/4563.org\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/4563.org\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/4563.org\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/4563.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=155677"}],"version-history":[{"count":0,"href":"http:\/\/4563.org\/index.php?rest_route=\/wp\/v2\/posts\/155677\/revisions"}],"wp:attachment":[{"href":"http:\/\/4563.org\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=155677"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/4563.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=155677"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/4563.org\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=155677"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}