2【学校教学系统】登录API嗅探和模仿浏览器登录

我们先要嗅探出登录所需要的登录API。然后把我们的程序伪装成浏览器,向他发送数据包,得到返回的文件

1嗅探登录API
我们使用的工具是WireShark
WireShark的使用请百度。
这里写图片描述
我们可以抓到点击登录按钮之后的紧接着的几个数据包。这里肯定有登录信息。前几个是TCP的建立过程。三次握手对吧。
这个post十分可疑。我相信我们的登录信息就在这里面。
我们打开这个包。看看详细内容
这里写图片描述
在图片里面红色的东西就是我的用户名和密码

POST /default.aspx HTTP/1.1
Host: xxxxx更改xxxx.cn
User-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:40.0) Gecko/20100101 Firefox/40.0.2 Waterfox/40.0.2
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
X-Requested-With: XMLHttpRequest
Content-Type: application/x-www-form-urlencoded; charset=UTF-8
Referer: http://xxxxx更改xxxx/default.aspx
Content-Length: 918
Cookie: ASP.NET_SessionId=kx4l4ilu5ezlhxnlohimcv4i
Connection: keep-alive
Pragma: no-cache
Cache-Control: no-cache

__EVENTTARGET=winLogin%24sfLogin%24ContentPanel1%24btnLogin&__EVENTARGUMENT=&__VIEWSTATE=%2FwEPDwULLTE4ODU0MTIxMDdkGAEFHl9fQ29udHJvbHNSZXF1aXJlUG9zdEJhY2tLZXlfXxYJBQh3aW5Mb2dpbgUQd2luTG9naW4kc2ZMb2dpbgUWd2luTG9naW4kc2ZMb2dpbiRjdGwwMAUfd2luTG9naW4kc2ZMb2dpbiR0eHRVc2VyTG9naW5JRAUcd2luTG9naW4kc2ZMb2dpbiR0eHRQYXNzd29yZAUed2luTG9naW4kc2ZMb2dpbiRjYnhTYXZlTXlJbmZvBR53aW5Mb2dpbiRzZkxvZ2luJENvbnRlbnRQYW5lbDEFJ3dpbkxvZ2luJHNmTG9naW4kQ29udGVudFBhbmVsMSRidG5Mb2dpbgUIV25kTW9kYWy%2Bbc6QsNOdH7ZtF07lnmmRBXbUK%2F7AWPgOr2Q5ybbyRQ%3D%3D&X_CHANGED=true&winLogin%24sfLogin%24txtUserLoginID=这里是用户&winLogin%24sfLogin%24txtPassword=这里是密码&winLogin_Hidden=false&WndModal_Hidden=true&X_TARGET=winLogin_sfLogin_ContentPanel1_btnLogin&winLogin_sfLogin_ctl00_Collapsed=false&winLogin_sfLogin_ContentPanel1_Collapsed=false&winLogin_sfLogin_Collapsed=false&winLogin_Collapsed=false&WndModal_Collapsed=false&X_STATE=e30%3D&X_AJAX=true

上面是包的详细文字。
其实我们可以用上面的信息伪装一下。用java写出来的程序就是下面这个样子

项目结构
这里写图片描述

//Main.java
package testSSE;

import java.io.BufferedReader;
import java.io.IOException;
import java.io.InputStreamReader;
import java.net.HttpURLConnection;
import java.util.HashMap;
import java.util.Map;

public class Main {

    public static void main(String args[]) throws Exception
    {
        Session webServer=new Session();
        Map<String, String> headers = null;
        String loginUrl = "http://已更改.cn/default.aspx";

       // Map<String, String> postData = new HashMap<String, String>();


        headers = new HashMap<String, String>();
        headers.put("Accept","*/*");
        headers.put("Accept-Encoding", "gzip, deflate");
        headers.put("Accept-Language", "zh-cn");
        headers.put("Connection", "keep-Alive");
        headers.put("User-Agent", "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)");
        headers.put("Host", "已更改.cn");
        headers.put("Cookie", "_gscu_1103646635=44570248tltbml42; _ga=GA1.3.366307833.1445157054");
        HttpURLConnection conn =webServer.post(loginUrl, null,headers);

        BufferedReader in = new BufferedReader(new InputStreamReader(conn.getInputStream(), "utf-8"));

        String inputLine = null;
        String result = null;

        while ((inputLine = in.readLine()) != null) {
            System.out.println(inputLine);
        }

    }
}
//Session.java
package testSSE;

import java.io.Serializable;
import java.net.URL;
import java.net.HttpURLConnection;

import java.util.List;
import java.util.Map;
import java.util.HashMap;
import java.util.Iterator;

import java.io.DataOutputStream;


public class Session implements Serializable {
    private Map<String, String> cookies = null;

    public Session() {
        this.cookies = new HashMap<String, String>();
    }

    public HttpURLConnection get(String url, Map<String, String> headers) throws Exception {
        URL getUrl = new URL(url);
        HttpURLConnection httpConn = (HttpURLConnection)getUrl.openConnection();

        for (Object key : headers.keySet()) {
            httpConn.setRequestProperty(key.toString(), headers.get(key).toString());
        }

        if (!cookies.isEmpty()) {
            StringBuilder sb = new StringBuilder();
            for (Object cookie : cookies.keySet()) {
                sb.append(cookie.toString()).append("=").append(cookies.get(cookie).toString())
                        .append(";");
            }
            httpConn.addRequestProperty("Cookie", sb.toString());
        }

        httpConn.connect();


        return httpConn;
    }


    public HttpURLConnection post(String url, Map<String, String> data, Map<String, String> headers) throws Exception {
        URL getUrl = new URL(url);
        HttpURLConnection httpConn = (HttpURLConnection)getUrl.openConnection();

        httpConn.setUseCaches(false);
        httpConn.setRequestMethod("POST");

        for (Object key : headers.keySet()) {
            httpConn.setRequestProperty(key.toString(), headers.get(key).toString());
        }

        if (!cookies.isEmpty()) {
            StringBuilder sb = new StringBuilder();
            for (Object cookie : cookies.keySet()) {
                sb.append(cookie.toString()).append("=").append(cookies.get(cookie).toString())
                        .append(";");
            }
            httpConn.addRequestProperty("Cookie", sb.toString());
        }

        httpConn.setDoOutput(true);
        httpConn.setDoInput(true);

        DataOutputStream wr = new DataOutputStream(httpConn.getOutputStream());
        StringBuilder sbData = new StringBuilder();
        int count = 0;
//        for (Object str : data.keySet()) {
//            count += 1;
//            if (count != data.size()) {
//                sbData.append(str.toString()).append("=").append(data.get(str).toString()).append("&");
//            } else {
//                sbData.append(str.toString()).append("=").append(data.get(str).toString());
//            }
//        }
        wr.writeBytes(
"__EVENTTARGET=winLogin%24sfLogin%24ContentPanel1%24btnLogin&__EVENTARGUMENT=&__VIEWSTATE=%2FwEPDwULL"+
"TE4ODU0MTIxMDdkGAEFHl9fQ29udHJvbHNSZXF1aXJlUG9zdEJhY2tLZXlfXxYJBQh3aW5Mb2dpbgUQd2luTG9naW4kc2ZMb2dpb"+
"gUWd2luTG9naW4kc2ZMb2dpbiRjdGwwMAUfd2luTG9naW4kc2ZMb2dpbiR0eHRVc2VyTG9naW5JRAUcd2luTG9naW4kc2ZMb2dpb"+
"iR0eHRQYXNzd29yZAUed2luTG9naW4kc2ZMb2dpbiRjYnhTYXZlTXlJbmZvBR53aW5Mb2dpbiRzZkxvZ2luJENvbnRlbnRQYW5lbDEFJ3dpbkxvZ2luJHNmTG"+
"9naW4kQ29udGVudFBhbmVsMSRidG5Mb2dpbgUIV25kTW9kYWy"+
"%2Bbc6QsNOdH7ZtF07lnmmRBXbUK%2F7AWPgOr2Q5ybbyRQ%3D%3D&X_CHANGED=true&winLogin%24sfLogin%24txtUserLoginID"+
"=这里是用户名&winLogin%24sfLogin%24txtPassword= 这里是密码&winLogin_Hidden=false&WndModal_Hidden=true&X_TARGET"+
"=winLogin_sfLogin_ContentPanel1_btnLogin&winLogin_sfLogin_ctl00_Collapsed=false&winLogin_sfLogin_ContentPanel1_Collapsed"+
"=false&winLogin_sfLogin_Collapsed=false&winLogin_Collapsed=false&WndModal_Collapsed=false&X_STATE=e30="+
"&X_AJAX=true");
        wr.flush();
        wr.close();


        return httpConn;
    }

}

我们可以运行程序了。然后结果如下
程序返回的结果

?X.enable('winLogin_sfLogin_ContentPanel1_btnLogin');var x0=X('winLogin_sfLogin_txtUserLoginID'),x1=X('winLogin_sfLogin_txtPassword');X.state(x0,{"Text":"这里是用户名"});X.state(x1,{"Text":"这里是密码"});window.location.href='/HomePage/default.aspx';

抓包的结果
这里写图片描述
看到服务器返回的是200 ok。说明我们登录成功了。。红色的请无视

接下来我们要分析如何获取登录界面和抓取登录界面的信息了。不过今天就到此为止了

=======================第一次添加===========

当我们登录完成后。服务器返回的第一个包的内容我们还要研究一下
这里写图片描述
返回的第一个包有一个set-cookie字段。这里面包含的东西就是代表我这个用户的cookie。所以我们需要把这个cookie的值记录下来。以后每次像服务器发送数据都要把这个放在cookie字段里面。这样服务器才能知道我们已经登陆过。
于是我们要更改一下代码。上面的代码已经不能用了。

我们要添加下面的代码。当收到的包里面有setcookie字段的时候,我们要记录下来。然后放到一个全局变量里面

List<String> cookieFields = httpConn.getHeaderFields().get("Set-Cookie");
        if(cookieFields!=null)
        {
            for (Object cookie : cookieFields) {
                String str = cookie.toString().split(";")[0];
                if(str.split("=")[0].equals("iflyssesse"))
                {
                    cookies.put(str.split("=")[0], str.split("=")[1]);
                }
            }
        }

下面是发送所做的更改
就是在每次发送的时候都把cookie放进去

if (!cookies.isEmpty()) {
            StringBuilder sb = new StringBuilder();
            for (Object cookie : cookies.keySet()) {
                sb.append(cookie.toString()).append("=").append(cookies.get(cookie).toString())
                .append(";");
            }
            httpConn.addRequestProperty("Cookie", sb.toString());
        }
  • 1
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值