Python 服务器请求伪造

Python 服务器请求伪造

一般情况下,攻击者无法绕过waf向内网发送恶意请求,达到攻击目的。攻击者通过伪造服务器请求与内网进行交互,从而达到探测内网,对内网进行攻击的目的(与多种攻击方式相结合)。

import json
import time
from datetime import datetime
from datetime import timedelta
import requests


def get_data(url):
    proxy = '127.0.0.1:1087'
    proxies = {
        'http': 'http://' + proxy,
        'https': 'https://' + proxy
    }
    headers = {
        'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.100 Safari/537.36'
    }
    try:
        print(url)
        respone = requests.get(url, headers=headers, proxies=proxies, timeout=3)
        if respone.status_code == 200:
            print(respone.text) #打印返回内容
            return respone.text
        return None
    except requests.exceptions.ConnectionError as e:
        print('error:', e.args)


def parse_data(html):
    data = json.loads(html)['cmts'] #把其他类型的对象转为Python对象
    comments = []
    for item in data:
        comment = {
            'id': item['id'],
            'nickName': item['nickName'],
            'cityName': item['cityName'] if 'cityName' in item else '',
            'content': item['content'].replace('\n', ' ', 10),
            'score': item['score'],
            'startTime': item['startTime']

        }
        comments.append(comment)
    return comments


def save_to_txt():
    start_time = datetime.now().strftime('%Y-%m-%d %H:%M:%S') #打印现在时间
    print(start_time)
    end_time = '2021-12-25 00:00:00'
    while start_time > end_time:
        url = 'http://m.maoyan.com/mmdb/comments/movie/1203084.json?_v_=yes&offset=0&startTime=' + start_time.replace(
            ' ', '%20') #进行验证
        try:
            html = get_data(url)
        except Exception as e:
            time.sleep(0.5)
            html = get_data(url)
        else:
            time.sleep(0.1)
        comments = parse_data(html)
        print(comments)
        start_time = comments[14]['startTime']
        start_time = datetime.strftime(start_time, '%Y-%m-%d %H:%M:%S') + timedelta(seconds=-1)
        start_time = datetime.strftime(start_time, '%Y-%m-%d %H:%M:%S')

        for item in comments:
            with open('data.txt', 'a', encoding='utf-8') as f:
                f.write(str(item['id']) + ',' + item['nickName'] + ',' + item['cityName'] + ',' + item[
                    'content'] + ',' + str(item['score']) + ',' + item['startTime'] + '\n')


if __name__ == '__main__':
    save_to_txt()

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值