1 import requests
2 import re
3 def target_url(scan_url):
4 xssstring = '<script>alert(1)</script>'
5 response = requests.get(scan_url)
6 head = response.headers
7 #print(head)
8 #print(head.values())
9 for i in head.values():
10 if re.search('.*__jsluid',i):
11 print(scan_url+':该网站用的知道创宇家的waf')
12 return
13 if __name__ == '__main__':
14 scan_url=input("请输入网址:")
15 target_url(scan_url)
简单的说就是想办法让目标域名告警,正则匹配响应包里的关键词