宝塔用户_miveqc 发表于 2025-8-21 11:43:43

为啥有的IP老师被cc过滤掉啊

Virgil 发表于 2025-8-26 10:00:07

客户反馈误报

宝塔用户_bwscku 发表于 2025-8-27 11:44:20

forum.php?mod=image&aid=196781&size=300x300&key=bb91562c59899654&nocache=yes&type=fixnone

宝塔用户_bwscku 发表于 2025-8-27 11:49:39

Nginx防火墙 9.7.7参数正常经常误报拦截sql注入和PHP代码执行

无疆云 发表于 2025-9-2 20:05:49

blob:https://www.bt.cn/7ad83473-09c1-4ab4-b270-e458f32a4049

无疆云 发表于 2025-9-2 20:12:01

blob:https://www.bt.cn/fd0fdacd-0dc5-4dd8-ab69-75bc3b2f8bfc

yangmo 发表于 2025-9-3 09:14:04

GET /bdftp/136214.html HTTP/1.1
accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
referer: https://m.baidu.com/
accept-encoding: gzip, deflate
accept-language: zh-CN,zh;q=0.9,en-US;q=0.8,en;q=0.7
sec-fetch-site: cross-site
sec-fetch-mode: navigate
sec-fetch-dest: document
user-agent: Mozilla/5.0 (Linux; Android 15; PHK110 Build/AP3A.240617.008; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/97.0.4692.98 Mobile Safari/537.36 T7/15.19 SP-engine/3.49.0 bd_dvt/0 baiduboxapp/15.23.0.11 (Baidu; P1 15) NABar/1.0
purpose: prefetch
x-forwarded-for: 240e:471:40b0:2862:d444:55ff:fe74:d26e
x-requested-with: com.baidu.searchbox
host: 3g.99bdf.com
x-cuid: 8F813F607B0BE3068CEF96520FA00F5D|VXKWXPETL
x-from-h3-trnet: true
x-bd-traceid: b7c65fd6f0f0434d98590f9460ff88c6
upgrade-insecure-requests: 1
x-t5-auth: 11872527

yangmo 发表于 2025-9-3 09:14:46

yangmo 发表于 2025-9-3 09:14
GET /bdftp/136214.html HTTP/1.1
accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/ ...

这是不是误报啊?

ma2019 发表于 2025-9-3 10:57:33

本帖最后由 ma2019 于 2025-9-3 11:01 编辑

提交post有拦截,提示http包未结尾,实际上浏览器上header上看是有前面有------后面--结尾的。不过在拦截记录上看只有前面的而且是---了,同时fom-data的选项也是关闭的。还会有这个拦截


POST /***/***/yukaikai?id=37 HTTP/1.1
sec-ch-ua-platform: "Windows"
host: ****.cn
sec-fetch-dest: empty
sec-fetch-site: same-origin
x-csrf-token: B0KnNoAyusakIcqSJhuq24031MXXeDs6jrl_k1cuBk1eI8Ni0VSMiOZxksFFSNqTxwOah5xPWkDIzz3KGnliew==
content-type: multipart/form-data; boundary=----WebKitFormBoundarywIGCbvVYNtBbfcLW
cookie: _csrf=0202bb981943c7e21

页: 1 2 3 4 [5]
查看完整版本: 误报提交入口