首页
学习
活动
专区
圈层
工具
发布
    • 综合排序
    • 最热优先
    • 最新优先
    时间不限
  • 来自专栏cloud stdio

    【Python】记录抓包分析自动领取芝麻HTTP每日免费IP(成品+教程)

    www.zmhttp.com', "Referer": 'https://www.zmhttp.com/', 'Sec-Fetch-Dest': 'empty', 'Sec-Fetch-Mode': 'cors', 'Sec-Fetch-Site first_time=0', 'Sec-Fetch-Dest': 'empty', 'Sec-Fetch-Mode': 'cors', 'Sec-Fetch-Site': 'cross-site', ' www.zmhttp.com', "Referer": 'https://www.zmhttp.com/', 'Sec-Fetch-Dest': 'empty', 'Sec-Fetch-Mode': 'cors', 'Sec-Fetch-Site first_time=0', 'Sec-Fetch-Dest': 'empty', 'Sec-Fetch-Mode': 'cors', 'Sec-Fetch-Site': 'cross-site', ' first_time=0', 'Sec-Fetch-Dest': 'empty', 'Sec-Fetch-Mode': 'cors', 'Sec-Fetch-Site': 'cross-site', '

    47420编辑于 2023-08-08
  • 来自专栏code秘密花园

    同站 和 同源 你理解清楚了么?

    如何检查请求是否为 “同站”,“同源”,或“跨站” Chrome 发送请求时会附带一个 Sec-Fetch-Site HTTP Header 。 截至2020年4月,还没有其他浏览器支持 Sec-Fetch-Site,这个 HTTP Header 将有以下值之一: cross-site same-site same-origin none 通过检查 Sec-Fetch-Site 的值,您可以确定请求是 “同站”,“同源” 还是 “跨站”。

    3.3K20发布于 2020-06-28
  • 来自专栏HACK学习

    记一次泄露PII的漏洞挖掘经历

    Content-Length: 25 Origin: redact.com Referer: redact.com Sec-Fetch-Dest: empty Sec-Fetch-Mode: cors Sec-Fetch-Site Content-Length: 25 Origin: redact.com Referer: redact.com Sec-Fetch-Dest: empty Sec-Fetch-Mode: cors Sec-Fetch-Site

    1.2K50编辑于 2023-08-22
  • 来自专栏pai233的专栏

    如何获取洛谷的CSRF Token

    'Sec-Fetch-Dest': 'empty', 'Sec-Fetch-Mode': 'cors', 'Sec-Fetch-Site 'Sec-Fetch-Dest': 'empty', 'Sec-Fetch-Mode': 'cors', 'Sec-Fetch-Site 'Sec-Fetch-Dest': 'empty', 'Sec-Fetch-Mode': 'cors', 'Sec-Fetch-Site

    3K20编辑于 2022-01-12
  • 来自专栏漏洞复现

    kkfileview任意文件读取漏洞复现(批量化)

    application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9 Sec-Fetch-Site xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9 Sec-Fetch-Site

    3.4K20编辑于 2024-03-12
  • 来自专栏旅途散记

    流量回放工具

    application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7 Sec-Fetch-Site application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7 Sec-Fetch-Site application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7 Sec-Fetch-Site application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7 Sec-Fetch-Site application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7 Sec-Fetch-Site

    1K20编辑于 2023-10-24
  • 来自专栏cloud stdio

    自动化滇医通

    "Origin": "https://appv2.ynhdkc.com", "X-Requested-With": "com.tencent.mm", "Sec-Fetch-Site "Origin": "https://appv2.ynhdkc.com", "X-Requested-With": "com.tencent.mm", "Sec-Fetch-Site "Origin": "https://appv2.ynhdkc.com", "X-Requested-With": "com.tencent.mm", "Sec-Fetch-Site "Origin": "https://appv2.ynhdkc.com", "X-Requested-With": "com.tencent.mm", "Sec-Fetch-Site Origin": "https://appv2.ynhdkc.com", "X-Requested-With": "com.tencent.mm", "Sec-Fetch-Site

    17500编辑于 2024-05-25
  • 来自专栏精益码农

    一文看懂Cookie奥秘

    Http请求中Sec-Fetch-Site标头指示了这个属性: Sec-Fetch-Site 描述 cross-site 请求的发起源与资源源完全不相同 same-origin 请求的发起源与资源源完全相同 聊cookie为什么要提到Sec-Fetch-Site标头? 答:B站页面在请求A站资源时能否携带A站cookie(第三方cookie)不仅是一个道德问题;技术上还牵涉web安全(CSRF)。 developer.mozilla.org/en-US/docs/Web/HTTP/Cookies https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Sec-Fetch-Site

    2.3K51发布于 2020-04-16
  • 来自专栏安全学习记录

    漏洞复现-Nacos身份认证绕过

    deflate Connection: close Upgrade-Insecure-Requests: 1 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site Upgrade-Insecure-Requests": "1", "Sec-Fetch-Dest": "document", "Sec-Fetch-Mode": "navigate", "Sec-Fetch-Site Upgrade-Insecure-Requests": "1", "Sec-Fetch-Dest": "document", "Sec-Fetch-Mode": "navigate", "Sec-Fetch-Site

    4.4K20编辑于 2023-03-29
  • 来自专栏编程语言的世界

    达摩平台素材管理API逆向工程实践

    hope.demogic.com/gic-web/", "Sec-Fetch-Dest: empty", "Sec-Fetch-Mode: cors", "Sec-Fetch-Site content-center/', 'Sec-Fetch-Dest: empty', 'Sec-Fetch-Mode: cors', 'Sec-Fetch-Site content-center/', 'Sec-Fetch-Dest: empty', 'Sec-Fetch-Mode: cors', 'Sec-Fetch-Site hope.demogic.com/report/", "Sec-Fetch-Dest: empty", "Sec-Fetch-Mode: cors", "Sec-Fetch-Site headers[] = 'Sec-Fetch-Dest: empty'; $headers[] = 'Sec-Fetch-Mode: cors'; $headers[] = 'Sec-Fetch-Site

    22610编辑于 2025-07-24
  • 来自专栏FunTester

    scrapy 工作踩坑记

    keep-alive", "Host": "www.baikemy.com", "Sec-Fetch-Mode": "navigate", "Sec-Fetch-Site "Referer": meta["video_source"], "Sec-Fetch-Mode": "no-cors", "Sec-Fetch-Site

    51740发布于 2020-12-24
  • 来自专栏全栈程序员必看

    大学生在线四史脚本

    Mac OS X 11_1_0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.96 Safari/537.36', 'sec-fetch-site Mac OS X 11_1_0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.96 Safari/537.36', 'sec-fetch-site Mac OS X 11_1_0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.96 Safari/537.36', 'sec-fetch-site content-type': 'application/json;charset=UTF-8', 'origin': 'https://ssxx.univs.cn', 'sec-fetch-site content-type': 'application/json;charset=UTF-8', 'origin': 'https://ssxx.univs.cn', 'sec-fetch-site

    67220编辑于 2022-07-02
  • 来自专栏Timeline Sec

    CVE-2021-21975​:VMware vRealize SSRF复现

    CKi1yQEIlLbJAQijtskBCMS2yQEIqZ3KAQiOucoBCPjHygEIpM3KAQjc1coBCPDgygEI5JzLAQipncsB Content-Type: application/json;charset=UTF-8 Sec-Fetch-Site CKi1yQEIlLbJAQijtskBCMS2yQEIqZ3KAQiOucoBCPjHygEIpM3KAQjc1coBCPDgygEI5JzLAQipncsB Content-Type: application/json;charset=UTF-8 Sec-Fetch-Site

    1.6K20发布于 2021-05-17
  • 来自专栏Dance with GenAI

    AI网络爬虫:批量下载某个网页中的全部链接

    0 Sec-Ch-Ua-Platform: "Windows" Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: same-origin 0", "Sec-Ch-Ua-Platform": '"Windows"', "Sec-Fetch-Dest": "document", "Sec-Fetch-Mode": "navigate", "Sec-Fetch-Site

    51810编辑于 2024-07-10
  • 来自专栏Lan小站

    request请求头快速加引号

    p=3&jl=765&kw=python&kt=3 sec-fetch-dest: empty sec-fetch-mode: cors sec-fetch-site: same-site user-agent

    58710编辑于 2022-07-14
  • 来自专栏沈唁志

    Swoole v4.6 版本新特性之 Http\Request 增强

    /xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9" ["sec-fetch-site application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9\r\n Sec-Fetch-Site 0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9\r\n"; $data .= "Sec-Fetch-Site

    1.1K10发布于 2021-02-22
  • 来自专栏安全学习记录

    漏洞复现-Spring core rce排坑小结

    3889FB0765EF31079360491ABA0F4485 Upgrade-Insecure-Requests: 1 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site Connection: close Upgrade-Insecure-Requests: 1 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site 3889FB0765EF31079360491ABA0F4485 Upgrade-Insecure-Requests: 1 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site

    97130编辑于 2022-12-26
  • 来自专栏用户6838338的专栏

    【xhs】笔记更新监控,x-s、x-t、a1、web_session

    "sec-ch-ua-platform": "\"Windows\"", "origin": "https://www.xiaohongshu.com", "sec-fetch-site www.xiaohongshu.com/", "Sec-Fetch-Dest": "empty", "Sec-Fetch-Mode": "cors", "Sec-Fetch-Site

    1.3K30编辑于 2023-05-23
  • 来自专栏cloud stdio

    记一次爬取搜索引擎缩略图并保存到本地

    dyTabStr=&ie=utf-8&sid=&word=%E8%BD%A6', 'Sec-Fetch-Dest': 'empty', 'Sec-Fetch-Mode': 'cors', 'Sec-Fetch-Site dyTabStr=&ie=utf-8&sid=&word=%E8%BD%A6', 'Sec-Fetch-Dest:empty', 'Sec-Fetch-Mode:cors', 'Sec-Fetch-Site dyTabStr=&ie=utf-8&sid=&word=%E8%BD%A6', 'Sec-Fetch-Dest:empty', 'Sec-Fetch-Mode:cors', 'Sec-Fetch-Site

    48220编辑于 2023-08-08
  • 来自专栏网络安全攻防

    CVE-2021-21975:vRealize Operations Manager SSRF

    /apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9 Content-Type: application/json;charset=UTF-8 Sec-Fetch-Site /apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9 Content-Type: application/json;charset=UTF-8 Sec-Fetch-Site

    1.4K40发布于 2021-04-01
领券