目标网站:
aHR0cHM6Ly9xLjEwanFrYS5jb20uY24v
一、抓包分析
携带了cookie,每次请求的cookie都不一样,且不携带cookie不能成功返回数据
data:image/s3,"s3://crabby-images/82318/823189af9c0a614b4ec5060006d73f8815c61d54" alt=""
hook Cookie代码
javascript
_cookie = document.cookie
Object.defineProperty(document, 'cookie', {
get(){
console.log('正在获取cookie,', _cookie)
return _cookie
},
set(value){
debugger;
console.log('正在设置cookie,', value)
if (value.indexOf("v") != -1) {
debugger ;
}
_cookie = value
}
})
新建代码,拷贝hook代码并保存运行
成功hook到cookie
data:image/s3,"s3://crabby-images/1324a/1324a1def93d3e1baabf9ca8f5f17ebfa18664a1" alt=""
向上跟栈,发现是update方法进行更新的
data:image/s3,"s3://crabby-images/f78a5/f78a5195c30eeb7f506d2637eff6e87ce10ca64d" alt=""
进入方法内部
data:image/s3,"s3://crabby-images/a4394/a43940702e2a8470da57ce91ea31645da8806b8d" alt=""
方法所用到的S在前面就已经定义了,而且是个自执行方法
data:image/s3,"s3://crabby-images/58ed9/58ed988d483b87a2969bca090d4d4113d12e10d9" alt=""
直接拷贝整个js文件到本地
data:image/s3,"s3://crabby-images/0fab2/0fab2758bcafa91fe6805febd0bb34ccc6ef624d" alt=""
定义全局变量GG,用于导出O方法
data:image/s3,"s3://crabby-images/ac3cc/ac3ccdba42b6f6860104b4c214b7a4fea0e65684" alt=""
缺失环境
data:image/s3,"s3://crabby-images/c3929/c39293386e4e015f0b261ec597e7e4902831295d" alt=""
补环境代理
javascript
function environment(obj) {
return new Proxy(obj, {
set(target, p, value, receiver){
console.log('set:', p)
return Reflect.set(...arguments)
},
get(target, p, receiver){
console.log("get:", p);
return target[p];
}
})
}
environment(window)
补上这些环境
data:image/s3,"s3://crabby-images/d9711/d971162feaffe67ec30c142a65dea3c007dfdbb4" alt=""
生成的cookie
data:image/s3,"s3://crabby-images/898bb/898bbd58b28c67d06232a7a5903128cc5dc59e6b" alt=""
本地调用
data:image/s3,"s3://crabby-images/152bb/152bb134445ab65ac780beaca299c90e3cf75b6c" alt=""
文章仅提供技术交流学习,不可对目标服务器造成伤害