@Humbert
2017-12-23T16:20:49.000000Z
字数 3404
阅读 1789
请求:http://202.114.34.15/reader/hwthau.php
注意获得了PHPSESSID1
未使用Account.ccnu.edu.cn的header

General:
Request URL:http://202.114.34.15/reader/hwthau.php
Request Method:GET
Status Code:302 Moved Temporarily
Remote Address:202.114.34.15:80
Referrer Policy:no-referrer-when-downgrade
Response Headers:
Cache-Control:no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection:Keep-Alive
Content-Type:text/html; charset=UTF-8
Date:Sat, 23 Dec 2017 15
Expires:Thu, 19 Nov 1981 08
Keep-Alive:timeout=5, max=100
Location:https
Pragma:no-cache
Server:Apache/2.4.25 (Win64) mod_fcgid/2.3.9
Set-Cookie:PHPSESSID=nl6eq0oj7m4cp4t3oks8tcgls0; path=/; HttpOnly
Transfer-Encoding:chunked
X-Frame-Options:SAMEORIGIN
X-Powered-By:PHP/5.6.30
Request Headers:
Accept:text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,/;q=0.8
Accept-Encoding:gzip, deflate
Accept-Language:en,zh-CN;q=0.9,zh;q=0.8
Cache-Control:no-cache
Connection:keep-alive
Host:202.114.34.15
Pragma:no-cache
Upgrade-Insecure-Requests:1
User-Agent:Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.75 Safari/537.36
拿Account.ccnu.edu.cn的Cookie来获取一个带有ticket的Location

General:
Request URL:https://account.ccnu.edu.cn/cas/login?service=http%3A%2F%2F202.114.34.15%2Freader%2Fhwthau.php
Request Method:GET
Status Code:302
Remote Address:202.114.33.163
Referrer Policy:no-referrer-when-downgrade
Response:
Cache-Control:no-cache
Cache-Control:no-store
Connection:keep-alive
Content-Length:0
Date:Sat, 23 Dec 2017 07:36:02 GMT
Expires:Thu, 01 Jan 1970 00:00:00 GMT
Location:http://202.114.34.15/reader/hwthau.php?ticket=ST-36448-zblL6auEjhsRPoD3JwRe-account.ccnu.edu.cn
Pragma:no-cache
Server:nginx/1.9.9
Request:
Accept:text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,/;q=0.8
Accept-Encoding:gzip, deflate, br
Accept-Language:en,zh-CN;q=0.9,zh;q=0.8
Cache-Control:no-cache
Connection:keep-alive
Cookie:CASPRIVACY=; CASTGC=TGT-17154-uegb5xgf0anCikBeQhPN4jVrVy1nL63IDbQ0IBFHh6k6LSwmRi-account.ccnu.edu.cn; JSESSIONID=4413558B4A240EDE673E2E3FFC1D370B3vQiiR
Host:account.ccnu.edu.cn
Pragma:no-cache
Upgrade-Insecure-Requests:1
User-Agent:Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.75 Safari/537.36
获取PHPSESSID, 而这个PHPSESSID 其实就是Step2中转发用的Ticket 得来的


General:
Request URL:http://202.114.34.15/reader/hwthau.php?ticket=ST-36448-zblL6auEjhsRPoD3JwRe-account.ccnu.edu.cn
Request Method:GET
Status Code:302 Moved Temporarily
Remote Address:202.114.34.15:80
Referrer Policy:no-referrer-when-downgrade
Response:
Cache-Control:no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection:Keep-Alive
Content-Length:0
Content-Type:text/html; charset=UTF-8
Date:Sat, 23 Dec 2017 15:35:03 GMT
Expires:Thu, 19 Nov 1981 08:52:00 GMT
Keep-Alive:timeout=5, max=99
Location:http://202.114.34.15/reader/hwthau.php
Pragma:no-cache
Server:Apache/2.4.25 (Win64) mod_fcgid/2.3.9
Set-Cookie:PHPSESSID=ST-36448-zblL6auEjhsRPoD3JwRe-accountccnueducn; path=/; HttpOnly
X-Frame-Options:SAMEORIGIN
X-Powered-By:PHP/5.6.30
Request:
Accept:text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,/;q=0.8
Accept-Encoding:gzip, deflate
Accept-Language:en,zh-CN;q=0.9,zh;q=0.8
Cache-Control:no-cache
Connection:keep-alive
Cookie:PHPSESSID=nl6eq0oj7m4cp4t3oks8tcgls0
Host:202.114.34.15
Pragma:no-cache
Upgrade-Insecure-Requests:1
User-Agent:Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.75 Safari/537.36
这一步貌似没用

最后一步,貌似也没用
