对此进行调试的方法是在浏览器(您会得到 403)和您的代码(您会得到 200)中尝试,比较请求标头,然后平分差异。
--
我使用 Chrome 开发工具中的“网络”面板完成了此操作,并使用了requests,所以我可以使用print(page.request.headers)。
来自 Chrome:
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*/*;q=0.8
Accept-Encoding: gzip, deflate
Accept-Language: en-US,en;q=0.9
Cache-Control: max-age=0
Connection: keep-alive
Cookie: __test=9eea7a0d55374cb5b0673e2058581017
Host: switch-check.cf
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/67.0.3396.99 Safari/537.36
来自请求:
User-Agent python-requests/2.18.4
Accept-Encoding: gzip, deflate
Accept: */*
Connection: keep-alive
在访问这些标头之前:Chrome 请求 index.php?i=1 而不仅仅是 index.php。所以显然有一个重定向,而我没有注意。而requests 中并没有发生这种重定向,这意味着它很可能是脚本化的。
同时,我知道我说过要平分,但那里有一个 cookie 的事实立即令人怀疑。
那么,让我们看看实际的 200 响应,通过漂亮的打印机运行:
<html>
<body>
<script type="text/javascript" src="/aes.js"></script>
<script>
function toNumbers(d) {
var e = [];
d.replace(/(..)/g, function(d) {
e.push(parseInt(d, 16))
});
return e
}
function toHex() {
for (var d = [], d = 1 == arguments.length && arguments[0].constructor == Array ? arguments[0] : arguments, e = "", f = 0; f < d.length; f++) e += (16 > d[f] ? "0" : "") + d[f].toString(16);
return e.toLowerCase()
}
var a = toNumbers("f655ba9d09a112d4968c63579db590b4"),
b = toNumbers("98344c2eee86c3994890592585b49f80"),
c = toNumbers("c4ba932dbf1d8d33ca88410be4f79eb0");
document.cookie = "__test=" + toHex(slowAES.decrypt(c, 2, a, b)) + "; expires=Thu, 31-Dec-37 23:55:55 GMT; path=/";
location.href = "http://switch-check.cf/index.php?i=1";
</script>
<noscript>This site requires Javascript to work, please enable Javascript in your browser or use a browser with Javascript support</noscript>
</body>
</html>
嗯,这就是你的问题。您实际上并没有拒绝对index.php 的访问;您将返回一个带有一些 JavaScript 的 200,该 JavaScript 添加了一个随机 cookie,然后重定向到 index.php?i=1。 那是你拒绝他们的地方。
是 cookie 还是重定向触发了 403?让我们尝试使用 Requests:
>>> r = requests.get('http://switch-check.cf/index.php', headers={'Cookie': '__test=9eea7a0d55374cb5b0673e2058581017'})
>>> r.status_code
403
>>> r = requests.get('http://switch-check.cf/index.php?i=1')
>>> r.status_code
200
因此,您只是基于由 JavaScript 生成的 cookie 来禁止访问。
如果我们只是发送一个无意义的 cookie 会怎样?
>>> r = requests.get('http://switch-check.cf/index.php', headers={'Cookie': '__test=' + '0'*32})
>>> r.status_code
403
>>> r = requests.get('http://switch-check.cf/index.php', headers={'Cookie': '__test=' + str(uuid.uuid4().hex})
>>> r.status_code
403
哇。它实际上必须是 正确 cookie,即服务器所期望的那个,或者您不会被拒绝?这与您通常想要的逻辑相反。
您可以编写一些 urllib 或 requests 代码以像浏览器那样进行协作——要么运行 JS 解释器,要么解析出三个数字并 AES 并自己构建一个 cookie .但这似乎是一件愚蠢的事情。
正确的做法是更改服务器以实际禁止访问index.php,而不是返回生成特殊 cookie 的 JS 代码,让您可以根据需要被禁止访问。
你是怎么做到的?
好吧,你说:
在 .htaccess 和 php 的帮助下,我尽我所能,所有 .php 文件都被禁止访问
首先,据我所知,您认为您正在使用 Apache,并且在某处遵循一些关于如何在 Apache 中禁止访问的指南,但您实际上使用的是 nginx。 (查看回复中的 Server 标头。)
同时,我不知道你在 PHP 中做什么,但你可能得到了一些代码,这些代码旨在要求来自运行 JS 的有效浏览器的有效 cookie,这是 (a) 错误的并将其向后移动,( b) 过于复杂,并且 (c) 不是您想要的。
我不知道你这里是否有 PHP 问题,或者关于 Server Fault 的 nginx 问题,或其他问题。但这就是你需要解决的问题。