|
发表于 2010-12-10 12:23:27
|
显示全部楼层
新疆维吾尔自治区博尔塔拉蒙古自治州
是 www.126.com ?
POST /logins.jsp?type=1&product=mail126&url=http://entry.mail.126.com/cgi/ntesdoor?hid%3D10010102%26lightweight%3D1%26verifycookie%3D1%26language%3D0%26style%3D-1%26rnd%3Djames_albert%40126.com_1291954187573&rnd=james_albert%40126.com_1291954187573&uid=james_albert@126.com HTTP/1.1
Host ssl.mail.163.com
User-Agent Mozilla/5.0 (Windows; U; Windows NT 6.1; zh-CN; rv:1.9.2.12) Gecko/20101026 Firefox/3.6.12
Accept text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8,application/json
Accept-Language zh-cn,zh;q=0.5
Accept-Encoding gzip,deflate
Accept-Charset GB2312,utf-8;q=0.7,*;q=0.7
Keep-Alive 115
Connection keep-alive
Referer http://www.126.com/
Cookie _ntes_nnid=2a6a3b728d3b16268a334dead898b9eb,0; _ntes_nuid=2a6a3b728d3b16268a334dead898b9eb; ALLYESID4=00100515011810490911863; logType=-1; nts_mail_user=james_albert:-1:1; MAIL163_SSN=james_albert; __utma=187553192.1877135767.1280732799.1281854161.1282807363.11; __utmz=187553192.1282807363.11.13.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=sp%20%E8%84%9A%E6%9C%AC%20%E8%AF%9B%E4%BB%99; vjuids=8da2fff71.12ad12fec08.0.26db235a15dab; vjlast=1283409833.1291484535.11; NEBLOG_LOGIN=0|james_albert|_fks_QqceFOvhb3ZyKsHCb2h2Lb6gRUlDk8ca2KEOjZs7yhz0hSwL1dINVA==; P_INFO=james_albert@163.com|1291388229|1|blog|11&7|xij&1291310048&blog#xij&652700#10|&0; NTES_PASSPORT=hzN6dRTR5uoxp7my0HK_SvyvsjUx7HOjpdEPn2hAxw6iwSUgzwjUnY3X5WwzPZO0bBEm70efuvqpkGW4rlJIDATH2zZxoFawJ; USERTRACK=124.119.104.230.1290705267639864; Province=0991; City=0909
Content-Type application/x-www-form-urlencoded
Content-Length 236
上面是POST
可以看到地址是
http://ssl.mail.163.com/logins.j ... ames_albert@126.com
这个地址中的参数我就不帮你分析了,下面看post参数
domain=126.com&language=0&bCookie=&username=james_albert%40126.com&savelogin=&url2=http%3A%2F%2Fmail.126.com%2Ferrorpage%2Ferr_126.htm%3Frnd%3Djames_albert%2540126.com_1291954187573&user=james_albert&password=123456789&style=-1&secure=
这个参数里面 我用的用户名是 james_albert 密码 123456789
很容易看出来在哪,另外上面还有个username=james_albert%40126.com “%40”就是“@”
还有就是参数中有不少内容在地址中有相同的,所以分析的时候要注意这些的变化。有的可能是必须的,有的可能没必要。简单看了下好像没什么关联。具体分析看你自己吧。 |
|