赞
踩
未经许可,不得转载。
测试一个子域名,在测试过程中,它的密码重置功能引起了我的注意。URL 如下所示:
target.com/reset-password
输入我的电子邮件,捕获的请求如下所示:
POST /reset-password HTTP/1.1 Host: target.com Connection: close Content-Length: 153 Cache-Control: max-age=0 sec-ch-ua: "Not A(Brand";v="99", "Brave";v="121", "Chromium";v="121" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Windows" Upgrade-Insecure-Requests: 1 Origin: https://target.com Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8 Sec-GPC: 1 Accept-Language: en-US,en;q=0.7 Sec-Fetch-Site: same-origin
Copyright © 2003-2013 www.wpsshop.cn 版权所有,并保留所有权利。