1 import requests
 2 import re
 3 def target_url(scan_url):
 4     xssstring = '<script>alert(1)</script>'
 5     response = requests.get(scan_url)
 6     head = response.headers
 7     #print(head)
 8     #print(head.values())
 9     for i in head.values():
10         if re.search('.*__jsluid',i):
11             print(scan_url+':该网站用的知道创宇家的waf')
12             return
13 if __name__ == '__main__':
14     scan_url=input("请输入网址:")
15     target_url(scan_url)      

简单的说就是想办法让目标域名告警,正则匹配响应包里的关键词

 

相关文章: