|
5精币
post接口:
?service=smarthos.yygh.ApiDoctorService.yspbinfo
====例子1====
post的数据:
{"format":"JSON","oper":"127.0.0.1","random":"1234","spid":"1001","channel":"31","orgid":"33010100031","docId":"630c1ffbe4b0b4ab0b49dd94","deptId":"630c1fdde4b0b4ab0b49dd77","wlmzState":null,"ysType":0,"bdate":null,"edate":null,"service":"smarthos.yygh.ApiDoctorService.yspbinfo","token":null,"hosId":"3301010003"}
得到的sign签名为:
6d35c5dcc2c02bc9d7d343e0cde28cab
====例子2====
post的数据:
{"format":"JSON","oper":"127.0.0.1","random":"1234","spid":"1001","channel":"31","orgid":"33010100031","docId":"630c2002e4b0b4ab0b49deec","deptId":"630c1fdde4b0b4ab0b49dd77","wlmzState":null,"ysType":0,"bdate":null,"edate":null,"service":"smarthos.yygh.ApiDoctorService.yspbinfo","token":null,"hosId":"3301010003"}
得到的sign签名为:
86353a356093a10388915c865d1c0dca
sign与时间戳无关,上几天抓包的数据,今天还能用,感觉就是跟接口和post的数据有关,不知道咋算的,求助大佬们
补充内容 (2024-10-13 13:47):
可能我没说清楚,我的意思是,我判断这个sign,应该是post的数据经过运算得到的,就是不知道具体是怎么运算的
补充内容 (2024-10-13 13:55):
就是已知post数据:
经过“一系列计算”,可得sign=6d35c5dcc2c02bc9d7d343e0cde28cab
求这个“一些列计算”
并且我确定,sign只跟post的这些参数有关 |
最佳答案
查看完整内容
app 拉 jadx看 exe就逆向 web如果js没混淆就是最简单的。流程都一样,搜索字符串挨个分析
|