{"id":1759,"date":"2026-03-05T11:05:08","date_gmt":"2026-03-05T03:05:08","guid":{"rendered":"http:\/\/www.preluna.xyz\/?p=1759"},"modified":"2026-03-05T14:45:36","modified_gmt":"2026-03-05T06:45:36","slug":"18d","status":"publish","type":"post","link":"http:\/\/www.preluna.xyz\/index.php\/2026\/03\/05\/18d\/preluna\/text\/","title":{"rendered":"\u4fe1\u606f\u6536\u96c6-Web\u5e94\u7528&amp;\u642d\u5efa\u67b6\u6784&amp;\u6307\u7eb9\u8bc6\u522b&amp;WAF\u5224\u65ad&amp;\u871c\u7f50\u6392\u9664&amp;\u5f00\u53d1\u6846\u67b6&amp;\u7ec4\u4ef6\u5e94\u7528"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">\u4fe1\u606f\u6536\u96c6-Web\u5e94\u7528-\u67b6\u6784\u5206\u6790&amp;\u6307\u7eb9\u8bc6\u522b<\/h2>\n\n\n\n<h2 class=\"wp-block-heading\">\u4e00\u3001\u7f51\u7edc\u6280\u672f\u6808\u8ba4\u77e5\u91cd\u6784<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">1.1 \u6a21\u5757\u6982\u5ff5\u89e3\u91ca<\/h3>\n\n\n\n<p>\u7f51\u7edc\u6280\u672f\u6808\u8ba4\u77e5\u91cd\u6784\uff0c\u662f\u4ece\u4fe1\u606f\u6536\u96c6\u89d2\u5ea6\u91cd\u65b0\u68b3\u7406 Web \u5e94\u7528\uff08Web Application\uff09\u6240\u4f9d\u8d56\u7684\u6280\u672f\u7ec4\u4ef6\u53ca\u5176\u5728\u4ea4\u4e92\u8fc7\u7a0b\u4e2d\u5448\u73b0\u4fe1\u606f\u7684\u65b9\u5f0f\u3002\u5176\u76ee\u7684\u5728\u4e8e\u5e2e\u52a9\u5de5\u7a0b\u5e08\u7406\u89e3\u5178\u578b Web \u5e94\u7528\u7684\u6280\u672f\u5c42\u6b21\u6784\u6210\u3001\u5404\u5c42\u6b21\u7279\u5f81\u66b4\u9732\u4f4d\u7f6e\uff0c\u4ee5\u53ca\u8fd9\u4e9b\u7279\u5f81\u4e3a\u4f55\u53ef\u7528\u4e8e\u8bc6\u522b\u3002\u8be5\u6a21\u5757\u89e3\u51b3\u201c\u8bc6\u522b\u4ec0\u4e48\u201d\u548c\u201c\u4fe1\u606f\u4ece\u54ea\u6765\u201d\u7684\u95ee\u9898\uff0c\u4e3a\u540e\u7eed\u6280\u672f\u6307\u7eb9\u8bc6\u522b\u5efa\u7acb\u57fa\u7840\u8ba4\u77e5\u6846\u67b6\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">1.2 \u6280\u672f\u539f\u7406\u8bf4\u660e<\/h3>\n\n\n\n<p>Web \u5e94\u7528\u57fa\u4e8e TCP\/IP \u534f\u8bae\u6808\uff08TCP\/IP Protocol Stack\uff09\uff0c\u4e0a\u5c42\u4f7f\u7528 HTTP\/HTTPS \u534f\u8bae\u901a\u4fe1\u3002\u5ba2\u6237\u7aef\u8bf7\u6c42\u65f6\uff0c\u670d\u52a1\u5668\u54cd\u5e94\u4e2d\u5305\u542b\u7531\u4e0d\u540c\u6280\u672f\u7ec4\u4ef6\u751f\u6210\u7684\u4fe1\u606f\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u7f51\u7edc\u5c42\u4e0e\u4f20\u8f93\u5c42<\/strong>\uff1a\u5f00\u653e\u7aef\u53e3\u3001TLS \u8bc1\u4e66\u3001TCP\/IP \u534f\u8bae\u6808\u884c\u4e3a\u53ef\u53cd\u6620\u64cd\u4f5c\u7cfb\u7edf\u3001\u4e2d\u95f4\u4ef6\u7c7b\u578b\u3002<\/li>\n\n\n\n<li><strong>\u5e94\u7528\u5c42\u534f\u8bae<\/strong>\uff1aHTTP \u54cd\u5e94\u5934\u4e2d\u7684 <code>Server<\/code>\u3001<code>X-Powered-By<\/code>\u3001<code>Set-Cookie<\/code> \u7b49\u5b57\u6bb5\u76f4\u63a5\u66b4\u9732 Web \u670d\u52a1\u5668\u3001\u540e\u7aef\u8bed\u8a00\u3001\u5e94\u7528\u6846\u67b6\u4fe1\u606f\u3002<\/li>\n\n\n\n<li><strong>\u5185\u5bb9\u5448\u73b0\u5c42<\/strong>\uff1aHTML \u6587\u6863\u4e2d\u7684 <code>&lt;meta&gt;<\/code> \u6807\u7b7e\u3001JavaScript \u5e93\u7279\u5f81\u3001CSS \u7c7b\u540d\u3001\u7279\u5b9a\u6ce8\u91ca\u7b49\u53ef\u63ed\u793a\u524d\u7aef\u6846\u67b6\u3001CMS\u3001\u7b2c\u4e09\u65b9\u670d\u52a1\u3002<\/li>\n\n\n\n<li><strong>\u884c\u4e3a\u7279\u5f81\u5c42<\/strong>\uff1aURL \u8def\u7531\u98ce\u683c\u3001\u9519\u8bef\u9875\u9762\u683c\u5f0f\u3001\u4f1a\u8bdd\u7ba1\u7406\u65b9\u5f0f\u7b49\u9690\u542b\u6280\u672f\u4fe1\u606f\u3002<\/li>\n<\/ul>\n\n\n\n<p>\u8be5\u8bbe\u8ba1\u521d\u8877\u662f\u4fbf\u4e8e\u8c03\u8bd5\u548c\u517c\u5bb9\u6027\uff0c\u4f46\u4e5f\u4e3a\u6280\u672f\u8bc6\u522b\u63d0\u4f9b\u4e86\u6570\u636e\u6765\u6e90\u3002\u7406\u89e3\u4fe1\u606f\u4ea7\u751f\u539f\u7406\uff0c\u624d\u80fd\u6709\u76ee\u7684\u5730\u91c7\u96c6\u5206\u6790\u3002\u3010\u8865\u5145\u8bf4\u660e\uff1aHTTP \u54cd\u5e94\u5934\u7684\u5b9a\u4e49\u548c\u884c\u4e3a\u53c2\u8003 HTTP\/1.1 \u6807\u51c6\uff08IETF RFC 9110\uff09\u3011<\/p>\n\n\n\n<p><strong>\u56fe1-1\uff1aWeb\u6280\u672f\u6808\u5c42\u6b21\u4e0e\u4fe1\u606f\u66b4\u9732\u793a\u610f\u56fe<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/03\/Web\u6280\u672f\u6808\u5c42\u6b21\u4e0e\u4fe1\u606f\u66b4\u9732\u793a\u610f\u56fe-1024x275.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"275\" data-original=\"http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/03\/Web\u6280\u672f\u6808\u5c42\u6b21\u4e0e\u4fe1\u606f\u66b4\u9732\u793a\u610f\u56fe-1024x275.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1761\"  sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/div><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">1.3 \u5728\u7cfb\u7edf\u4e2d\u7684\u4f4d\u7f6e<\/h3>\n\n\n\n<p>\u672c\u6a21\u5757\u4f5c\u4e3a Web \u5e94\u7528\u67b6\u6784\u5206\u6790\u7684\u8d77\u70b9\uff0c\u4e0d\u76f4\u63a5\u8fdb\u884c\u6570\u636e\u91c7\u96c6\uff0c\u800c\u662f\u6784\u5efa\u5bf9 Web \u6280\u672f\u6808\u7684\u6574\u4f53\u8ba4\u77e5\u6846\u67b6\u3002\u540e\u7eed\u6a21\u5757\u201c\u63a2\u67e5\u76ee\u6807\u4e0e\u4efb\u52a1\u786e\u7acb\u201d\u5c06\u57fa\u4e8e\u6b64\u6a21\u578b\u8bbe\u5b9a\u5177\u4f53\u76ee\u6807\uff0c\u201c\u5e94\u7528\u67b6\u6784\u5c42\u6b21\u62c6\u89e3\u201d\u5219\u7ec6\u5316\u5404\u5c42\u6b21\u8bc6\u522b\u70b9\u3002\u56e0\u6b64\uff0c\u672c\u6a21\u5757\u4f4d\u4e8e\u6700\u524d\u7aef\uff0c\u4e3a\u540e\u7eed\u6b65\u9aa4\u63d0\u4f9b\u7406\u8bba\u652f\u6491\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">1.4 \u53ef\u6267\u884c\u547d\u4ee4\u6216\u67e5\u8be2\u65b9\u5f0f<\/h3>\n\n\n\n<p>\u4ee5\u5b89\u5168\u6d4b\u8bd5\u76ee\u6807 <code>example.com<\/code> \u548c <code>httpbin.org<\/code> \u4e3a\u4f8b\uff0c\u6f14\u793a\u67e5\u770b\u6280\u672f\u4fe1\u606f\u7684\u547d\u4ee4\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># \u67e5\u770bHTTP\u54cd\u5e94\u5934\uff0c\u91cd\u70b9\u5173\u6ce8Server\u3001X-Powered-By\u7b49\u5b57\u6bb5\ncurl -I https:\/\/example.com\n\n# \u67e5\u770b\u5b8c\u6574HTTP\u54cd\u5e94\uff0c\u5305\u62ec\u5934\u90e8\u548c\u4e3b\u4f53\uff08\u4e3b\u4f53\u5305\u542bHTML\u7279\u5f81\uff09\ncurl -s https:\/\/httpbin.org\/ | head -n 20\n\n# \u4f7f\u7528\u6d4f\u89c8\u5668\u5f00\u53d1\u8005\u5de5\u5177\uff08F12\uff09\u7684\u201c\u7f51\u7edc\u201d\u6807\u7b7e\uff0c\u5237\u65b0\u9875\u9762\u67e5\u770b\u8bf7\u6c42\/\u54cd\u5e94\u8be6\u60c5\n\n# \u4f7f\u7528openssl\u83b7\u53d6TLS\u8bc1\u4e66\u4fe1\u606f\uff0c\u53ef\u80fd\u66b4\u9732\u670d\u52a1\u5668\u8f6f\u4ef6\nopenssl s_client -connect example.com:443 -servername example.com 2&gt;\/dev\/null | openssl x509 -text | grep -E \"Subject:|Issuer:|DNS:\"<\/code><\/pre>\n\n\n\n<p>\u3010\u8865\u5145\u8bf4\u660e\uff1a<code>curl -I<\/code> \u53d1\u9001 HEAD \u8bf7\u6c42\u83b7\u53d6\u5934\u90e8\uff0c<code>curl -s<\/code> \u542f\u7528\u9759\u9ed8\u6a21\u5f0f\u3002<code>openssl s_client<\/code> \u6d4b\u8bd5 SSL\/TLS \u8fde\u63a5\uff0c\u7ba1\u9053\u81f3 <code>openssl x509 -text<\/code> \u89e3\u6790\u5e76\u8f93\u51fa\u8bc1\u4e66\u8be6\u7ec6\u4fe1\u606f\u3002\u4f9d\u636e\uff1acurl man page\uff1bOpenSSL Documentation\u3002\u3011<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">1.5 \u5de5\u5177\u5bf9\u6bd4\u8868<\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u5de5\u5177<\/th><th>\u9002\u7528\u573a\u666f<\/th><th>\u4f18\u70b9<\/th><th>\u5c40\u9650<\/th><\/tr><\/thead><tbody><tr><td>\u6d4f\u89c8\u5668\u5f00\u53d1\u8005\u5de5\u5177<\/td><td>\u624b\u5de5\u5feb\u901f\u5206\u6790\u524d\u7aef\u7279\u5f81<\/td><td>\u56fe\u5f62\u5316\u3001\u5b9e\u65f6\u67e5\u770bDOM\u3001\u7f51\u7edc\u8bf7\u6c42\u3001Cookie<\/td><td>\u96be\u4ee5\u81ea\u52a8\u5316\uff0c\u4e0d\u9002\u5408\u6279\u91cf\u5904\u7406<\/td><\/tr><tr><td>curl<\/td><td>\u547d\u4ee4\u884c\u83b7\u53d6\u539f\u59cb\u54cd\u5e94<\/td><td>\u8f7b\u91cf\u3001\u811a\u672c\u5316\u3001\u53ef\u5b9a\u5236\u8bf7\u6c42\u5934<\/td><td>\u9700\u624b\u52a8\u89e3\u6790\u8f93\u51fa\uff0c\u5bf9JavaScript\u6e32\u67d3\u5185\u5bb9\u65e0\u6548<\/td><\/tr><tr><td>wget<\/td><td>\u4e0b\u8f7d\u6574\u4e2a\u9875\u9762\u6216\u9012\u5f52\u5206\u6790<\/td><td>\u53ef\u9012\u5f52\u83b7\u53d6\u8d44\u6e90\uff0c\u652f\u6301\u955c\u50cf<\/td><td>\u529f\u80fd\u504f\u91cd\u4e0b\u8f7d\uff0c\u7279\u5f81\u63d0\u53d6\u9700\u989d\u5916\u5904\u7406\uff0c\u4e0ecurl\u5b9a\u4f4d\u4e0d\u540c<\/td><\/tr><tr><td>openssl<\/td><td>\u83b7\u53d6TLS\u8bc1\u4e66\u7ec6\u8282<\/td><td>\u80fd\u53d1\u73b0Web\u670d\u52a1\u5668\u7c7b\u578b\u3001\u8bc1\u4e66\u53d1\u884c\u8005<\/td><td>\u4ec5\u9002\u7528\u4e8eHTTPS\u7ad9\u70b9\uff0c\u4fe1\u606f\u6709\u9650<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">1.6 \u6807\u51c6\u64cd\u4f5c\u6b65\u9aa4<\/h3>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u6253\u5f00\u76ee\u6807\u7ad9\u70b9<\/strong>\uff1a\u5728\u6d4f\u89c8\u5668\u4e2d\u8bbf\u95ee <code>http:\/\/httpbin.org<\/code>\u3002<\/li>\n\n\n\n<li><strong>\u6253\u5f00\u5f00\u53d1\u8005\u5de5\u5177<\/strong>\uff1a\u6309F12\uff0c\u5207\u6362\u5230\u201c\u7f51\u7edc(Network)\u201d\u6807\u7b7e\uff0c\u5237\u65b0\u9875\u9762\u3002<\/li>\n\n\n\n<li><strong>\u67e5\u770b\u54cd\u5e94\u5934<\/strong>\uff1a\u70b9\u51fb\u7b2c\u4e00\u4e2a\u8bf7\u6c42\uff08\u901a\u5e38\u4e3a\u6587\u6863\u672c\u8eab\uff09\uff0c\u5728\u201c\u54cd\u5e94\u5934(Response Headers)\u201d\u90e8\u5206\u8bb0\u5f55 <code>server<\/code>\u3001<code>access-control-allow-origin<\/code> \u7b49\u5b57\u6bb5\u3002<\/li>\n\n\n\n<li><strong>\u67e5\u770b\u9875\u9762\u6e90\u7801<\/strong>\uff1a\u53f3\u952e\u67e5\u770b\u9875\u9762\u6e90\u4ee3\u7801\uff0c\u641c\u7d22 <code>&lt;meta<\/code>\u3001<code>&lt;script&gt;<\/code> \u7b49\u6807\u7b7e\uff0c\u5bfb\u627e\u6846\u67b6\u6807\u8bc6\uff08\u5982 <code>csrf-token<\/code>\u3001<code>_ga<\/code>\uff09\u3002<\/li>\n\n\n\n<li><strong>\u4f7f\u7528 curl \u83b7\u53d6\u5934\u4fe1\u606f<\/strong>\uff1a\u5728\u7ec8\u7aef\u6267\u884c <code>curl -I https:\/\/httpbin.org<\/code>\uff0c\u5bf9\u6bd4\u4e0e\u6d4f\u89c8\u5668\u4e2d\u770b\u5230\u7684\u4fe1\u606f\u3002<\/li>\n\n\n\n<li><strong>\u6574\u7406\u89c2\u5bdf\u4fe1\u606f<\/strong>\uff1a\u5217\u51fa\u53ef\u80fd\u7684\u6280\u672f\u7ec4\u4ef6\uff08\u5982 gunicorn\u3001Python\u3001\u67d0\u4e9b JavaScript \u5e93\uff09\u3002<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">1.7 \u5982\u4f55\u9a8c\u8bc1\u7ed3\u679c\u771f\u5b9e\u6027<\/h3>\n\n\n\n<p><strong>\u9a8c\u8bc1\u903b\u8f91<\/strong>\uff1a\u5bf9\u4e8e\u516c\u5f00\u6d4b\u8bd5\u7ad9\u70b9\uff0c\u53ef\u901a\u8fc7\u67e5\u9605\u5b98\u65b9\u6587\u6863\u6216\u5df2\u77e5\u6280\u672f\u6808\u8fdb\u884c\u6bd4\u5bf9\u3002\u4f8b\u5982\uff0c<code>httpbin.org<\/code> \u5b98\u65b9\u6587\u6863\u8bf4\u660e\u5176\u57fa\u4e8e Python + Gunicorn\u3002\u82e5\u54cd\u5e94\u5934\u4e2d\u51fa\u73b0 <code>server: gunicorn\/19.9.0<\/code>\uff0c\u4e14\u54cd\u5e94\u4f53\u5305\u542b Python \u98ce\u683c\u8f93\u51fa\uff0c\u5219\u53ef\u786e\u8ba4\u89c2\u5bdf\u7ed3\u679c\u4e0e\u771f\u5b9e\u6280\u672f\u6808\u4e00\u81f4\u3002<br><strong>\u5224\u65ad\u4f9d\u636e<\/strong>\uff1a\u591a\u4e2a\u72ec\u7acb\u6765\u6e90\uff08\u54cd\u5e94\u5934\u3001\u9875\u9762\u5185\u5bb9\u3001TLS \u8bc1\u4e66\uff09\u6307\u5411\u540c\u4e00\u6280\u672f\u65f6\uff0c\u771f\u5b9e\u6027\u9ad8\u3002\u82e5\u51fa\u73b0\u77db\u76fe\uff08\u5982\u58f0\u79f0 Apache \u4f46\u9875\u9762\u5305\u542b IIS \u6ce8\u91ca\uff09\uff0c\u9700\u8fdb\u4e00\u6b65\u5206\u6790\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">1.8 \u5e38\u89c1\u9519\u8bef\u4e0e\u6392\u67e5\u65b9\u5f0f<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u9519\u8bef1<\/strong>\uff1a\u4ec5\u4f9d\u8d56 <code>Server<\/code> \u5934\u5224\u65ad\u6280\u672f\u6808\u3002<code>Server<\/code> \u5934\u53ef\u88ab\u4fee\u6539\u6216\u9690\u85cf\uff0c\u4e14\u53ea\u53cd\u6620 Web \u670d\u52a1\u5668\uff0c\u4e0d\u53cd\u6620\u540e\u7aef\u8bed\u8a00\u6216\u6846\u67b6\u3002<\/li>\n\n\n\n<li><strong>\u6392\u67e5<\/strong>\uff1a\u7ed3\u5408\u5176\u4ed6\u7279\u5f81\uff0c\u5982 Cookie \u540d\uff08<code>PHPSESSID<\/code> \u6697\u793a PHP\uff0c<code>JSESSIONID<\/code> \u6697\u793a Java\uff09\u3001URL \u540e\u7f00\uff08<code>.php<\/code>\u3001<code>.asp<\/code>\uff09\u3002<\/li>\n\n\n\n<li><strong>\u9519\u8bef2<\/strong>\uff1a\u5c06 CDN \u6216\u4ee3\u7406\u7279\u5f81\u8bef\u8ba4\u4e3a\u6e90\u7ad9\u7279\u5f81\u3002\u4f8b\u5982\uff0c<code>Server: cloudflare<\/code> \u8868\u793a\u4f7f\u7528 CloudFlare CDN\uff0c\u5e76\u975e\u771f\u5b9e\u6e90\u7ad9\u3002<\/li>\n\n\n\n<li><strong>\u6392\u67e5<\/strong>\uff1a\u5c1d\u8bd5\u76f4\u63a5\u8fde\u63a5\u6e90\u7ad9 IP\uff08\u9700\u5148\u901a\u8fc7 DNS \u89e3\u6790\u6216\u5386\u53f2\u6570\u636e\u83b7\u5f97\uff09\uff0c\u6216\u4f7f\u7528\u975e\u6807\u51c6\u7aef\u53e3\u7ed5\u8fc7\u4ee3\u7406\u3002<\/li>\n\n\n\n<li><strong>\u9519\u8bef3<\/strong>\uff1a\u5ffd\u7565\u52a8\u6001\u6e32\u67d3\u5185\u5bb9\u3002\u67d0\u4e9b\u5355\u9875\u5e94\u7528\uff08SPA\uff09\u521d\u59cb HTML \u4e2d\u51e0\u4e4e\u65e0\u7279\u5f81\uff0c\u9700\u5206\u6790 JavaScript \u52a0\u8f7d\u540e\u7684 DOM\u3002<\/li>\n\n\n\n<li><strong>\u6392\u67e5<\/strong>\uff1a\u4f7f\u7528\u6d4f\u89c8\u5668\u5f00\u53d1\u8005\u5de5\u5177\u7684\u5143\u7d20\u9762\u677f\u67e5\u770b\u6700\u7ec8\u6e32\u67d3\u540e\u7684 DOM \u6811\uff0c\u6216\u4f7f\u7528 Headless \u6d4f\u89c8\u5668\uff08\u5982 Puppeteer\uff09\u83b7\u53d6\u52a8\u6001\u5185\u5bb9\u3002<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">1.9 \u5408\u89c4\u8fb9\u754c\u8bf4\u660e<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u4f7f\u7528\u573a\u666f<\/strong>\uff1a\u4ec5\u7528\u4e8e\u5bf9\u81ea\u6709\u7cfb\u7edf\u3001\u5df2\u83b7\u6388\u6743\u7684\u6d4b\u8bd5\u76ee\u6807\u6216\u516c\u5f00\u6d4b\u8bd5\u7ad9\u70b9\uff08\u5982 <code>example.com<\/code>\u3001<code>httpbin.org<\/code>\uff09\u8fdb\u884c\u5b66\u4e60\u7814\u7a76\u3002<\/li>\n\n\n\n<li><strong>\u7f51\u7edc\u5b89\u5168\u89c6\u89d2<\/strong>\uff1a<\/li>\n\n\n\n<li><strong>\u98ce\u9669<\/strong>\uff1a\u672a\u7ecf\u6388\u6743\u5bf9\u76ee\u6807\u8fdb\u884c\u63a2\u67e5\u53ef\u80fd\u8fdd\u53cd\u6cd5\u5f8b\u6cd5\u89c4\u6216\u670d\u52a1\u6761\u6b3e\u3002\u5373\u4f7f\u4ec5\u4f7f\u7528 <code>curl<\/code>\uff0c\u4e5f\u53ef\u80fd\u88ab\u65e5\u5fd7\u8bb0\u5f55\u5e76\u89c6\u4e3a\u626b\u63cf\u884c\u4e3a\u3002<\/li>\n\n\n\n<li><strong>\u5c40\u9650<\/strong>\uff1a\u4ec5\u51ed\u5916\u90e8\u4fe1\u606f\u65e0\u6cd5\u5b8c\u5168\u786e\u5b9a\u6280\u672f\u6808\uff0c\u53ef\u80fd\u5b58\u5728\u8bef\u5224\uff0c\u9700\u7ed3\u5408\u5185\u90e8\u6587\u6863\u6216\u6388\u6743\u6d4b\u8bd5\u8fdb\u4e00\u6b65\u9a8c\u8bc1\u3002<\/li>\n\n\n\n<li><strong>\u7f13\u89e3\u63aa\u65bd<\/strong>\uff1a\u59cb\u7ec8\u5728\u6388\u6743\u8303\u56f4\u5185\u64cd\u4f5c\uff0c\u4f7f\u7528\u6d4b\u8bd5\u57df\u540d\u6216\u672c\u5730\u73af\u5883\uff1b\u9075\u5b88 <code>robots.txt<\/code>\uff1b\u8bbe\u7f6e\u5408\u7406\u8bf7\u6c42\u9891\u7387\uff0c\u907f\u514d\u5bf9\u76ee\u6807\u9020\u6210\u538b\u529b\u3002<\/li>\n\n\n\n<li><strong>\u672c\u6a21\u5757\u51b3\u7b56\u6307\u5357<\/strong>\uff1a<\/li>\n\n\n\n<li><strong>\u9002\u7528\u573a\u666f<\/strong>\uff1a\u9700\u8981\u521d\u6b65\u4e86\u89e3\u4e00\u4e2a\u6388\u6743\u76ee\u6807\u7684\u6280\u672f\u6784\u6210\uff0c\u4ee5\u89c4\u5212\u6df1\u5165\u6d4b\u8bd5\u65f6\u3002<\/li>\n\n\n\n<li><strong>\u66ff\u4ee3\u65b9\u6848<\/strong>\uff1a\u82e5\u5df2\u62e5\u6709\u76ee\u6807\u7684\u6280\u672f\u6587\u6863\u6216\u4ee3\u7801\u6743\u9650\uff0c\u5219\u65e0\u9700\u901a\u8fc7\u5916\u90e8\u63a2\u67e5\u3002<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">1.10 \u672c\u6a21\u5757\u9636\u6bb5\u6027\u5c0f\u7ed3<\/h3>\n\n\n\n<p>\u672c\u6a21\u5757\u5b8c\u6210\u4e86\u5bf9 Web \u5e94\u7528\u6280\u672f\u5c42\u6b21\u7684\u8ba4\u77e5\u91cd\u6784\uff0c\u660e\u786e\u4e86\u5404\u5c42\u6b21\u53ef\u80fd\u66b4\u9732\u7684\u4fe1\u606f\u6e90\u3002\u7406\u89e3\u5916\u90e8\u670d\u52a1\u901a\u8fc7\u534f\u8bae\u3001\u5185\u5bb9\u3001\u884c\u4e3a\u900f\u9732\u6280\u672f\u7ec4\u6210\uff0c\u662f\u540e\u7eed\u63a2\u67e5\u52a8\u4f5c\u7684\u57fa\u7840\u3002\u4e0b\u4e00\u6a21\u5757\u5c06\u6b63\u5f0f\u786e\u7acb\u63a2\u67e5\u76ee\u6807\uff0c\u5c06\u8ba4\u77e5\u8f6c\u5316\u4e3a\u5177\u4f53\u4efb\u52a1\u6e05\u5355\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u4e8c\u3001\u63a2\u67e5\u76ee\u6807\u4e0e\u4efb\u52a1\u786e\u7acb<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">2.1 \u6a21\u5757\u6982\u5ff5\u89e3\u91ca<\/h3>\n\n\n\n<p>\u63a2\u67e5\u76ee\u6807\u4e0e\u4efb\u52a1\u786e\u7acb\uff0c\u662f\u6307\u5728\u6280\u672f\u4fe1\u606f\u6536\u96c6\u524d\uff0c\u660e\u786e\u4ece\u76ee\u6807 Web \u5e94\u7528\u4e2d\u83b7\u53d6\u7684\u5177\u4f53\u6280\u672f\u4fe1\u606f\uff0c\u5e76\u5c06\u8fd9\u4e9b\u4fe1\u606f\u7ec4\u7ec7\u4e3a\u53ef\u64cd\u4f5c\u7684\u4efb\u52a1\u3002\u5176\u89e3\u51b3\u201c\u9700\u8981\u5f97\u5230\u4ec0\u4e48\u201d\u7684\u95ee\u9898\uff0c\u4f8b\u5982\u786e\u5b9a Web \u670d\u52a1\u5668\u7c7b\u578b\u3001\u540e\u7aef\u7f16\u7a0b\u8bed\u8a00\u3001\u524d\u7aef\u6846\u67b6\u3001\u6570\u636e\u5e93\u7c7b\u578b\u3001\u4e2d\u95f4\u4ef6\u7248\u672c\u7b49\u3002\u786e\u7acb\u4efb\u52a1\u540e\uff0c\u540e\u7eed\u62c6\u89e3\u548c\u65b9\u6cd5\u5efa\u6a21\u624d\u80fd\u6709\u7684\u653e\u77e2\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">2.2 \u6280\u672f\u539f\u7406\u8bf4\u660e<\/h3>\n\n\n\n<p>\u63a2\u67e5\u4efb\u52a1\u786e\u7acb\u57fa\u4e8e\u4e00\u4e2a\u6838\u5fc3\u903b\u8f91\uff1a\u76ee\u6807\u5bf9\u5916\u63d0\u4f9b\u670d\u52a1\u65f6\u9700\u9075\u5faa\u516c\u5f00\u534f\u8bae\uff08\u5982 HTTP\uff09\uff0c\u800c\u534f\u8bae\u5b9e\u73b0\u7ec6\u8282\u56e0\u6280\u672f\u6808\u4e0d\u540c\u5b58\u5728\u5dee\u5f02\u3002\u901a\u8fc7\u8bbe\u8ba1\u7279\u5b9a\u67e5\u8be2\uff08\u5982\u53d1\u9001\u7279\u5b9a HTTP \u8bf7\u6c42\u3001\u63a2\u6d4b\u7279\u5b9a\u7aef\u53e3\u3001\u5206\u6790\u7279\u5b9a\u54cd\u5e94\u6a21\u5f0f\uff09\u53ef\u63a8\u65ad\u5185\u90e8\u6280\u672f\u6784\u6210\u3002\u8fd9\u4e00\u8fc7\u7a0b\u7c7b\u4f3c\u9ed1\u76d2\u6d4b\u8bd5\uff0c\u4ece\u6709\u9650\u5916\u90e8\u54cd\u5e94\u4e2d\u6700\u5927\u7a0b\u5ea6\u8fd8\u539f\u5185\u90e8\u6784\u9020\u3002\u8bbe\u8ba1\u63a2\u67e5\u4efb\u52a1\u65f6\u9700\u8003\u8651\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u4fe1\u606f\u7c7b\u578b<\/strong>\uff1a\u9759\u6001\u4fe1\u606f\uff08\u54cd\u5e94\u5934\u3001HTML\uff09\u548c\u52a8\u6001\u4fe1\u606f\uff08\u7279\u5b9a\u8def\u5f84\u54cd\u5e94\u3001\u9519\u8bef\u4fe1\u606f\uff09\u3002<\/li>\n\n\n\n<li><strong>\u63a2\u67e5\u6df1\u5ea6<\/strong>\uff1a\u4ece\u7aef\u53e3\u5f00\u653e\u5230\u5e94\u7528\u5c42\u7ec6\u8282\uff0c\u5206\u5c42\u9012\u8fdb\u3002<\/li>\n\n\n\n<li><strong>\u4efb\u52a1\u4f18\u5148\u7ea7<\/strong>\uff1a\u4fe1\u606f\u83b7\u53d6\u96be\u6613\u5ea6\u4e0d\u540c\uff0c\u9700\u8bbe\u5b9a\u4f18\u5148\u7ea7\u3002<\/li>\n<\/ul>\n\n\n\n<p><strong>\u56fe2-1\uff1a\u63a2\u67e5\u76ee\u6807\u786e\u7acb\u6d41\u7a0b\u56fe<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/03\/\u63a2\u67e5\u76ee\u6807\u786e\u7acb\u6d41\u7a0b\u56fe-366x1024.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"366\" height=\"1024\" data-original=\"http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/03\/\u63a2\u67e5\u76ee\u6807\u786e\u7acb\u6d41\u7a0b\u56fe-366x1024.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1762\"  sizes=\"auto, (max-width: 366px) 100vw, 366px\" \/><\/div><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">2.3 \u5728\u7cfb\u7edf\u4e2d\u7684\u4f4d\u7f6e<\/h3>\n\n\n\n<p>\u5728\u5b8c\u6210\u6280\u672f\u6808\u7406\u8bba\u8ba4\u77e5\u540e\uff0c\u672c\u6a21\u5757\u5c06\u7406\u8bba\u8f6c\u5316\u4e3a\u5177\u4f53\u76ee\u6807\u3002\u5b83\u4e3a\u63a5\u4e0b\u6765\u7684\u201c\u5e94\u7528\u67b6\u6784\u5c42\u6b21\u62c6\u89e3\u201d\u63d0\u4f9b\u5f85\u62c6\u89e3\u7684\u7ef4\u5ea6\uff08\u524d\u7aef\u3001\u540e\u7aef\u3001\u6570\u636e\u5e93\u7b49\uff09\uff0c\u5e76\u4e3a\u201c\u7ec4\u4ef6\u8bc6\u522b\u65b9\u6cd5\u5efa\u6a21\u201d\u5b9a\u4e49\u9700\u8981\u8bc6\u522b\u7684\u7ec4\u4ef6\u5217\u8868\u3002\u56e0\u6b64\uff0c\u672c\u6a21\u5757\u8d77\u5230\u627f\u4e0a\u542f\u4e0b\u4f5c\u7528\uff0c\u5c06\u8ba4\u77e5\u8f6c\u5316\u4e3a\u5b9e\u9645\u4efb\u52a1\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">2.4 \u53ef\u6267\u884c\u547d\u4ee4\u6216\u67e5\u8be2\u65b9\u5f0f<\/h3>\n\n\n\n<p>\u4ee5\u5b89\u5168\u6d4b\u8bd5\u76ee\u6807 <code>scanme.nmap.org<\/code> \u548c <code>httpbin.org<\/code> \u4e3a\u4f8b\uff0c\u5c55\u793a\u786e\u7acb\u63a2\u67e5\u76ee\u6807\u5e76\u6267\u884c\u521d\u6b65\u626b\u63cf\u7684\u547d\u4ee4\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># \u7aef\u53e3\u626b\u63cf\uff0c\u786e\u5b9a\u5f00\u653e\u670d\u52a1\uff08\u4e3a\u540e\u7eed\u5e94\u7528\u5c42\u63a2\u67e5\u51c6\u5907\uff09\nnmap -p- --min-rate 1000 scanme.nmap.org\n\n# \u670d\u52a1\u7248\u672c\u63a2\u6d4b\uff0c\u83b7\u53d6\u66f4\u8be6\u7ec6\u7684\u670d\u52a1\u4fe1\u606f\nnmap -sV -p 80,443 scanme.nmap.org\n\n# HTTP\u670d\u52a1\u6307\u7eb9\u63a2\u6d4b\uff0c\u4f7f\u7528whatweb\u8fdb\u884c\u7efc\u5408\u8bc6\u522b\nwhatweb http:\/\/scanme.nmap.org\n\n# \u68c0\u67e5\u7279\u5b9a\u8def\u5f84\u662f\u5426\u5b58\u5728\uff08\u5982\/robots.txt\uff0c\/phpinfo.php\uff09\ncurl -I http:\/\/scanme.nmap.org\/robots.txt<\/code><\/pre>\n\n\n\n<p>\u3010\u8865\u5145\u8bf4\u660e\uff1a<code>nmap -p-<\/code> \u626b\u63cf 1-65535 \u6240\u6709 TCP \u7aef\u53e3\uff0c<code>--min-rate 1000<\/code> \u63a7\u5236\u53d1\u5305\u901f\u7387\u4e0d\u4f4e\u4e8e 1000 \u5305\/\u79d2\u3002<code>-sV<\/code> \u7528\u4e8e\u7248\u672c\u63a2\u6d4b\u3002whatweb \u662f Web \u6307\u7eb9\u8bc6\u522b\u5de5\u5177\u3002\u4f9d\u636e\uff1aNmap Reference Guide\uff1bWhatweb GitHub Repository\u3002\u3011<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">2.5 \u5de5\u5177\u5bf9\u6bd4\u8868<\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u5de5\u5177<\/th><th>\u9002\u7528\u573a\u666f<\/th><th>\u4f18\u70b9<\/th><th>\u5c40\u9650<\/th><\/tr><\/thead><tbody><tr><td>nmap<\/td><td>\u7aef\u53e3\u626b\u63cf\u4e0e\u670d\u52a1\u7248\u672c\u8bc6\u522b<\/td><td>\u529f\u80fd\u5f3a\u5927\u3001\u793e\u533a\u652f\u6301\u597d\u3001\u811a\u672c\u4e30\u5bcc<\/td><td>\u626b\u63cf\u901f\u5ea6\u8f83\u6162\uff08\u5168\u7aef\u53e3\uff09\uff0c\u53ef\u80fd\u88abIDS\u68c0\u6d4b<\/td><\/tr><tr><td>masscan<\/td><td>\u5927\u89c4\u6a21\u7aef\u53e3\u626b\u63cf<\/td><td>\u6781\u901f\uff0c\u9002\u5408\u4e92\u8054\u7f51\u8303\u56f4\u626b\u63cf<\/td><td>\u7ed3\u679c\u53ef\u80fd\u4e0d\u51c6\u786e\uff0c\u529f\u80fd\u5355\u4e00<\/td><\/tr><tr><td>whatweb<\/td><td>Web\u5e94\u7528\u6307\u7eb9\u8bc6\u522b<\/td><td>\u8bc6\u522b\u51c6\u786e\uff0c\u63d2\u4ef6\u4e30\u5bcc\uff0c\u53ef\u5b9a\u5236<\/td><td>\u4ec5\u9488\u5bf9Web\u670d\u52a1\uff0c\u4e0d\u6d89\u53ca\u5e95\u5c42\u7f51\u7edc<\/td><\/tr><tr><td>telnet\/netcat<\/td><td>\u624b\u52a8\u63a2\u6d4b\u670d\u52a1 Banner<\/td><td>\u7b80\u5355\u76f4\u63a5\uff0c\u53ef\u7528\u4e8e\u9a8c\u8bc1<\/td><td>\u9700\u4eba\u5de5\u4ea4\u4e92\uff0c\u4e0d\u9002\u5408\u6279\u91cf<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">2.6 \u6807\u51c6\u64cd\u4f5c\u6b65\u9aa4<\/h3>\n\n\n\n<p>\u6309\u7167\u56fe2-1\u7684\u63a2\u67e5\u76ee\u6807\u786e\u7acb\u6d41\u7a0b\uff0c\u5404\u6b65\u9aa4\u5177\u4f53\u547d\u4ee4\u5982\u4e0b\uff1a<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u5b9a\u4e49\u63a2\u67e5\u8303\u56f4<\/strong>\uff1a\u786e\u5b9a\u76ee\u6807\u57df\u540d\uff08\u5982 <code>scanme.nmap.org<\/code>\uff09\u548c IP\uff08\u5982\u6709\uff09\u3002<\/li>\n\n\n\n<li><strong>\u7aef\u53e3\u626b\u63cf<\/strong>\uff1a<code>nmap -p- scanme.nmap.org<\/code><\/li>\n\n\n\n<li><strong>\u670d\u52a1\u7248\u672c\u8bc6\u522b<\/strong>\uff1a<code>nmap -sV -p 80,443 scanme.nmap.org<\/code><\/li>\n\n\n\n<li><strong>Web\u5e94\u7528\u521d\u6b65\u63a2\u67e5<\/strong>\uff1a<code>whatweb http:\/\/scanme.nmap.org<\/code><\/li>\n\n\n\n<li><strong>\u4eba\u5de5\u9a8c\u8bc1\u5173\u952e\u70b9<\/strong>\uff1a\u4f7f\u7528 curl \u8bbf\u95ee\u5e38\u89c1\u8def\u5f84\uff0c\u5982 <code>curl -I http:\/\/scanme.nmap.org\/robots.txt<\/code><\/li>\n\n\n\n<li><strong>\u6c47\u603b\u4efb\u52a1\u5217\u8868<\/strong>\uff1a\u6839\u636e\u521d\u6b65\u63a2\u67e5\u7ed3\u679c\uff0c\u5217\u51fa\u9700\u8981\u6df1\u5165\u786e\u8ba4\u7684\u7ec4\u4ef6\uff08\u4f8b\u5982\uff1a\u89c2\u5bdf\u5230 Apache\/2.4.7\uff0c\u9700\u8fdb\u4e00\u6b65\u786e\u8ba4 PHP \u7248\u672c\uff09\u3002<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">2.7 \u5982\u4f55\u9a8c\u8bc1\u7ed3\u679c\u771f\u5b9e\u6027<\/h3>\n\n\n\n<p><strong>\u9a8c\u8bc1\u903b\u8f91<\/strong>\uff1a\u5bf9\u4e8e\u6d4b\u8bd5\u76ee\u6807 <code>scanme.nmap.org<\/code>\uff0c\u53ef\u67e5\u9605 Nmap \u5b98\u65b9\u6587\u6863\u6216\u8bba\u575b\uff0c\u4e86\u89e3\u5176\u5df2\u77e5\u914d\u7f6e\u3002\u5b9e\u9645\u4e0a\uff0c<code>scanme.nmap.org<\/code> \u8fd0\u884c Apache \u548c\u4e00\u4e9b\u57fa\u672c\u670d\u52a1\u3002\u5bf9\u6bd4 nmap \u7248\u672c\u63a2\u6d4b\u7ed3\u679c\u4e0e\u5df2\u77e5\u4fe1\u606f\uff0c\u82e5\u4e00\u81f4\u5219\u8bf4\u660e\u63a2\u67e5\u6709\u6548\u3002\u5bf9\u4e8e\u5176\u4ed6\u76ee\u6807\uff0c\u53ef\u4f7f\u7528\u591a\u4e2a\u5de5\u5177\u4ea4\u53c9\u9a8c\u8bc1\uff0c\u4f8b\u5982 whatweb \u548c nmap \u7684 http-server-info \u811a\u672c\u7ed3\u679c\u5e94\u76f8\u4e92\u5370\u8bc1\u3002<br><strong>\u5224\u65ad\u4f9d\u636e<\/strong>\uff1a\u82e5\u591a\u4e2a\u5de5\u5177\u5747\u62a5\u544a\u540c\u4e00\u7248\u672c\u4fe1\u606f\uff0c\u4e14\u4eba\u5de5\u68c0\u67e5\u54cd\u5e94\u5934\u4e5f\u80fd\u770b\u5230\u7c7b\u4f3c\u5b57\u6bb5\uff0c\u5219\u771f\u5b9e\u6027\u8f83\u9ad8\u3002\u82e5\u51fa\u73b0\u4e0d\u4e00\u81f4\uff0c\u9700\u68c0\u67e5\u7f51\u7edc\u4e2d\u95f4\u8bbe\u5907\uff08\u5982\u8d1f\u8f7d\u5747\u8861\uff09\u662f\u5426\u5e72\u6270\u54cd\u5e94\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">2.8 \u5e38\u89c1\u9519\u8bef\u4e0e\u6392\u67e5\u65b9\u5f0f<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u9519\u8bef1<\/strong>\uff1a\u5ffd\u7565\u975e\u6807\u51c6\u7aef\u53e3\u4e0a\u7684 Web \u670d\u52a1\uff0c\u5982 8080\u30018443 \u53ef\u80fd\u8fd0\u884c\u53e6\u4e00\u5957 Web \u5e94\u7528\u3002<\/li>\n\n\n\n<li><strong>\u6392\u67e5<\/strong>\uff1a\u5bf9\u6240\u6709\u5f00\u653e\u7aef\u53e3\u5c1d\u8bd5 HTTP \u8bf7\u6c42\uff0c\u4f7f\u7528 nmap \u7684 <code>-sV<\/code> \u81ea\u52a8\u8bc6\u522b\uff0c\u6216\u811a\u672c\u6279\u91cf\u8fde\u63a5\u6d4b\u8bd5\u3002<\/li>\n\n\n\n<li><strong>\u9519\u8bef2<\/strong>\uff1a\u8fc7\u5ea6\u4f9d\u8d56\u81ea\u52a8\u5316\u5de5\u5177\uff0c\u9519\u8fc7\u91cd\u8981\u7ec6\u8282\u3002\u4f8b\u5982 whatweb \u53ef\u80fd\u65e0\u6cd5\u8bc6\u522b\u67d0\u4e9b\u5b9a\u5236\u5316\u6846\u67b6\u3002<\/li>\n\n\n\n<li><strong>\u6392\u67e5<\/strong>\uff1a\u7ed3\u5408\u624b\u52a8\u5206\u6790\uff0c\u4f7f\u7528\u6d4f\u89c8\u5668\u8bbf\u95ee\uff0c\u67e5\u770b\u6e90\u4ee3\u7801\uff0c\u5bfb\u627e\u81ea\u5b9a\u4e49\u6807\u8bc6\u3002<\/li>\n\n\n\n<li><strong>\u9519\u8bef3<\/strong>\uff1a\u5c06\u8d1f\u8f7d\u5747\u8861\u6216\u53cd\u5411\u4ee3\u7406\u6807\u8bc6\u8bef\u8ba4\u4e3a\u771f\u5b9e\u540e\u7aef\u3002\u4f8b\u5982 <code>Server: nginx<\/code> \u53ef\u80fd\u662f\u53cd\u5411\u4ee3\u7406\uff0c\u771f\u5b9e\u540e\u7aef\u4e3a Apache\u3002<\/li>\n\n\n\n<li><strong>\u6392\u67e5<\/strong>\uff1a\u5c1d\u8bd5\u8bbf\u95ee\u4e0d\u5b58\u5728\u8def\u5f84\uff0c\u89c2\u5bdf 404 \u9519\u8bef\u9875\u9762\u7279\u5f81\uff1b\u6216\u4f7f\u7528 HTTP\/1.0\u3001\u4e0d\u540c Host \u5934\u7ed5\u5f00\u4ee3\u7406\uff08\u5728\u6388\u6743\u8303\u56f4\u5185\uff09\u3002<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">2.9 \u5408\u89c4\u8fb9\u754c\u8bf4\u660e<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u4f7f\u7528\u573a\u666f<\/strong>\uff1a\u672c\u6a21\u5757\u6d89\u53ca\u7684\u7aef\u53e3\u626b\u63cf\u548c\u670d\u52a1\u63a2\u6d4b\u4ec5\u9002\u7528\u4e8e\u5df2\u83b7\u660e\u786e\u6388\u6743\u7684\u7cfb\u7edf\uff0c\u6216\u4f7f\u7528\u516c\u5171\u6d4b\u8bd5\u76ee\u6807\uff08\u5982 <code>scanme.nmap.org<\/code>\uff09\u3002<\/li>\n\n\n\n<li><strong>\u7f51\u7edc\u5b89\u5168\u89c6\u89d2<\/strong>\uff1a\u7aef\u53e3\u626b\u63cf\u5728\u67d0\u4e9b\u5730\u533a\u88ab\u89c6\u4e3a\u653b\u51fb\u524d\u5146\uff0c\u53ef\u80fd\u89e6\u53d1\u6cd5\u5f8b\u7ea0\u7eb7\u3002\u5373\u4f7f\u5bf9 <code>scanme.nmap.org<\/code>\uff0c\u4e5f\u5e94\u9075\u5b88\u5176\u4f7f\u7528\u6761\u6b3e\uff08\u901a\u5e38\u5141\u8bb8\u626b\u63cf\uff09\u3002nmap \u7248\u672c\u63a2\u6d4b\u57fa\u4e8e\u5df2\u77e5\u7b7e\u540d\uff0c\u5bf9\u5b9a\u5236\u5316\u670d\u52a1\u53ef\u80fd\u5931\u6548\uff0c\u4ea7\u751f\u8bef\u62a5\u3002<\/li>\n\n\n\n<li><strong>\u7f13\u89e3\u63aa\u65bd<\/strong>\uff1a\u59cb\u7ec8\u4ece\u6388\u6743\u76ee\u6807\u5f00\u59cb\uff1b\u8bbe\u7f6e\u626b\u63cf\u901f\u7387\u9650\u5236\uff08<code>--max-rate<\/code>\uff09\uff1b\u4f7f\u7528\u66f4\u9690\u853d\u7684\u626b\u63cf\u65b9\u5f0f\uff08\u5982 <code>-sS<\/code> \u534a\u8fde\u63a5\u626b\u63cf\uff09\u4ee5\u51cf\u5c11\u65e5\u5fd7\u8bb0\u5f55\uff0c\u4f46\u9700\u786e\u4fdd\u5728\u6388\u6743\u8303\u56f4\u5185\u3002<\/li>\n\n\n\n<li><strong>\u672c\u6a21\u5757\u51b3\u7b56\u6307\u5357<\/strong>\uff1a<\/li>\n\n\n\n<li><strong>\u9002\u7528\u573a\u666f<\/strong>\uff1a\u9700\u8981\u7cfb\u7edf\u6027\u5730\u4e86\u89e3\u4e00\u4e2a\u672a\u77e5 Web \u5e94\u7528\u7684\u6280\u672f\u6784\u6210\uff0c\u4e14\u5df2\u83b7\u6388\u6743\u65f6\u3002<\/li>\n\n\n\n<li><strong>\u66ff\u4ee3\u65b9\u6848<\/strong>\uff1a\u82e5\u76ee\u6807\u5df2\u63d0\u4f9b\u6280\u672f\u6587\u6863\uff0c\u5219\u65e0\u9700\u4e3b\u52a8\u626b\u63cf\uff0c\u53ef\u76f4\u63a5\u8fdb\u5165\u7ec4\u4ef6\u8bc6\u522b\u9a8c\u8bc1\u9636\u6bb5\u3002<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">2.10 \u672c\u6a21\u5757\u9636\u6bb5\u6027\u5c0f\u7ed3<\/h3>\n\n\n\n<p>\u672c\u6a21\u5757\u660e\u786e\u4e86\u8981\u4ece\u76ee\u6807 Web \u5e94\u7528\u4e2d\u6536\u96c6\u7684\u6280\u672f\u4fe1\u606f\uff0c\u5e76\u901a\u8fc7\u7aef\u53e3\u626b\u63cf\u548c\u521d\u6b65\u6307\u7eb9\u8bc6\u522b\u83b7\u5f97\u521d\u6b65\u6e05\u5355\u3002\u8be5\u6e05\u5355\u6210\u4e3a\u540e\u7eed\u6df1\u5165\u62c6\u89e3\u548c\u5206\u6790\u7684\u8f93\u5165\u3002\u4e0b\u4e00\u6a21\u5757\u5c06\u628a\u6e05\u5355\u6620\u5c04\u5230\u5177\u4f53\u5e94\u7528\u67b6\u6784\u5c42\u6b21\u4e0a\uff0c\u4ee5\u4fbf\u6709\u6761\u7406\u5730\u8fdb\u884c\u8bc6\u522b\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u4e09\u3001\u5e94\u7528\u67b6\u6784\u5c42\u6b21\u62c6\u89e3<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">3.1 \u6a21\u5757\u6982\u5ff5\u89e3\u91ca<\/h3>\n\n\n\n<p>\u5e94\u7528\u67b6\u6784\u5c42\u6b21\u62c6\u89e3\uff0c\u662f\u6307\u5c06\u5b8c\u6574 Web \u5e94\u7528\u6309\u6280\u672f\u804c\u80fd\u5212\u5206\u4e3a\u82e5\u5e72\u5c42\u6b21\uff0c\u4f8b\u5982\u524d\u7aef\u5c42\u3001\u540e\u7aef\u5c42\u3001\u6570\u636e\u5c42\u3001\u4e2d\u95f4\u4ef6\u5c42\u3001\u64cd\u4f5c\u7cfb\u7edf\u5c42\uff0c\u5e76\u9488\u5bf9\u6bcf\u4e00\u5c42\u5206\u6790\u53ef\u80fd\u66b4\u9732\u7684\u7279\u5f81\u4fe1\u606f\u3002\u5176\u89e3\u51b3\u201c\u5982\u4f55\u7cfb\u7edf\u5316\u7ec4\u7ec7\u8bc6\u522b\u4efb\u52a1\u201d\u7684\u95ee\u9898\uff0c\u907f\u514d\u96f6\u6563\u6536\u96c6\u7279\u5f81\u800c\u9057\u6f0f\u91cd\u8981\u7ec4\u4ef6\u3002\u901a\u8fc7\u5c42\u6b21\u5316\u62c6\u89e3\uff0c\u53ef\u786e\u4fdd\u8986\u76d6\u6240\u6709\u53ef\u80fd\u7684\u6280\u672f\u7ec4\u4ef6\uff0c\u5e76\u7406\u89e3\u5404\u5c42\u4e4b\u95f4\u7684\u4f9d\u8d56\u5173\u7cfb\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">3.2 \u6280\u672f\u539f\u7406\u8bf4\u660e<\/h3>\n\n\n\n<p>\u73b0\u4ee3 Web \u5e94\u7528\u666e\u904d\u91c7\u7528\u5206\u5c42\u67b6\u6784\uff0c\u6bcf\u4e00\u5c42\u627f\u62c5\u4e0d\u540c\u804c\u8d23\uff0c\u4e14\u901a\u5e38\u7531\u4e0d\u540c\u6280\u672f\u5b9e\u73b0\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u524d\u7aef\u5c42\uff08\u5ba2\u6237\u7aef\uff09<\/strong>\uff1a\u8d1f\u8d23\u7528\u6237\u754c\u9762\u4e0e\u4ea4\u4e92\uff0c\u5305\u62ec HTML\/CSS\/JavaScript \u6846\u67b6\uff08\u5982 React\u3001Vue\u3001Angular\uff09\u3001UI \u5e93\u3001\u9759\u6001\u8d44\u6e90\u670d\u52a1\u5668\u7b49\u3002\u7279\u5f81\u51fa\u73b0\u5728 HTML \u7ed3\u6784\u3001JavaScript \u53d8\u91cf\u3001CSS \u7c7b\u540d\u3001Source Map \u7b49\u3002<\/li>\n\n\n\n<li><strong>\u540e\u7aef\u5c42\uff08\u670d\u52a1\u5668\u7aef\uff09<\/strong>\uff1a\u5904\u7406\u4e1a\u52a1\u903b\u8f91\uff0c\u5305\u62ec\u7f16\u7a0b\u8bed\u8a00\uff08PHP\u3001Java\u3001Python\u3001Node.js \u7b49\uff09\u3001Web \u6846\u67b6\uff08Django\u3001Spring\u3001Rails \u7b49\uff09\u3001\u5e94\u7528\u670d\u52a1\u5668\uff08Tomcat\u3001uWSGI \u7b49\uff09\u3002\u7279\u5f81\u51fa\u73b0\u5728\u54cd\u5e94\u5934\uff08\u5982 <code>X-Powered-By<\/code>\uff09\u3001Cookie\uff08\u5982 <code>JSESSIONID<\/code>\uff09\u3001URL \u8def\u7531\u6a21\u5f0f\u3001\u9519\u8bef\u9875\u9762\u7b49\u3002<\/li>\n\n\n\n<li><strong>\u6570\u636e\u5c42<\/strong>\uff1a\u5b58\u50a8\u548c\u7ba1\u7406\u6570\u636e\uff0c\u5305\u62ec\u6570\u636e\u5e93\u7cfb\u7edf\uff08MySQL\u3001PostgreSQL\u3001MongoDB \u7b49\uff09\u3001\u7f13\u5b58\u7cfb\u7edf\uff08Redis\u3001Memcached\uff09\u3001\u641c\u7d22\u5f15\u64ce\uff08Elasticsearch\uff09\u3002\u7279\u5f81\u53ef\u80fd\u901a\u8fc7 SQL \u9519\u8bef\u4fe1\u606f\u3001\u7279\u5b9a\u7aef\u53e3\u66b4\u9732\u3001API \u54cd\u5e94\u683c\u5f0f\u7b49\u6cc4\u9732\u3002<\/li>\n\n\n\n<li><strong>\u4e2d\u95f4\u4ef6\u5c42<\/strong>\uff1a\u63d0\u4f9b\u901a\u7528\u670d\u52a1\uff0c\u5305\u62ec Web \u670d\u52a1\u5668\uff08Nginx\u3001Apache\uff09\u3001\u6d88\u606f\u961f\u5217\uff08RabbitMQ\uff09\u3001\u53cd\u5411\u4ee3\u7406\/\u8d1f\u8f7d\u5747\u8861\uff08HAProxy\uff09\u3002\u7279\u5f81\u51fa\u73b0\u5728 <code>Server<\/code> \u5934\u3001\u54cd\u5e94\u5934\u6dfb\u52a0\u5b57\u6bb5\uff08\u5982 <code>Via<\/code>\uff09\u3001\u7279\u5b9a HTTP \u884c\u4e3a\u3002<\/li>\n\n\n\n<li><strong>\u64cd\u4f5c\u7cfb\u7edf\u5c42<\/strong>\uff1a\u5e95\u5c42\u7cfb\u7edf\u73af\u5883\uff08Linux\u3001Windows\uff09\u3002\u7279\u5f81\u53ef\u901a\u8fc7 TTL \u503c\u3001TCP\/IP \u6808\u884c\u4e3a\u3001TLS \u6307\u7eb9\u3001\u6587\u4ef6\u8def\u5f84\u98ce\u683c\uff08Windows \u53cd\u659c\u6760 vs Linux \u6b63\u659c\u6760\uff09\u7b49\u63a8\u65ad\u3002<\/li>\n<\/ul>\n\n\n\n<p>\u6bcf\u4e00\u5c42\u7684\u6280\u672f\u9009\u62e9\u90fd\u4f1a\u5728\u4ea4\u4e92\u8fc7\u7a0b\u4e2d\u7559\u4e0b\u75d5\u8ff9\uff0c\u5c42\u6b21\u62c6\u89e3\u5c31\u662f\u5c06\u75d5\u8ff9\u5f52\u7c7b\uff0c\u4ee5\u4fbf\u540e\u7eed\u9488\u5bf9\u6027\u5730\u5efa\u7acb\u8bc6\u522b\u89c4\u5219\u3002<\/p>\n\n\n\n<p><strong>\u56fe3-1\uff1a\u5e94\u7528\u67b6\u6784\u5c42\u6b21\u62c6\u89e3\u56fe<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/03\/\u5e94\u7528\u67b6\u6784\u5c42\u6b21\u62c6\u89e3\u56fe-1024x75.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"75\" data-original=\"http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/03\/\u5e94\u7528\u67b6\u6784\u5c42\u6b21\u62c6\u89e3\u56fe-1024x75.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1763\"  sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/div><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">3.3 \u5728\u7cfb\u7edf\u4e2d\u7684\u4f4d\u7f6e<\/h3>\n\n\n\n<p>\u5728\u786e\u5b9a\u63a2\u67e5\u76ee\u6807\u6e05\u5355\u540e\uff0c\u672c\u6a21\u5757\u5c06\u6e05\u5355\u4e2d\u7684\u6bcf\u4e00\u9879\u6280\u672f\u5f52\u7c7b\u5230\u76f8\u5e94\u67b6\u6784\u5c42\u6b21\uff0c\u5f62\u6210\u5c42\u6b21\u5316\u7684\u201c\u5f85\u8bc6\u522b\u9879\u201d\u5217\u8868\u3002\u8fd9\u4e3a\u540e\u7eed\u201c\u7ec4\u4ef6\u8bc6\u522b\u65b9\u6cd5\u5efa\u6a21\u201d\u63d0\u4f9b\u4e86\u6e05\u6670\u7ef4\u5ea6\uff1a\u9700\u8981\u4e3a\u6bcf\u4e00\u5c42\u8bbe\u8ba1\u8bc6\u522b\u65b9\u6cd5\u3002\u56e0\u6b64\uff0c\u672c\u6a21\u5757\u662f\u4efb\u52a1\u5206\u89e3\u7684\u5173\u952e\u6b65\u9aa4\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">3.4 \u53ef\u6267\u884c\u547d\u4ee4\u6216\u67e5\u8be2\u65b9\u5f0f<\/h3>\n\n\n\n<p>\u4ee5 <code>httpbin.org<\/code> \u4e3a\u4f8b\uff0c\u6f14\u793a\u4ece\u5404\u5c42\u6b21\u63d0\u53d6\u7279\u5f81\u7684\u547d\u4ee4\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># \u524d\u7aef\u5c42\uff1a\u67e5\u770b\u9875\u9762\u6e90\u7801\u4e2d\u7684JavaScript\u5e93\u548c\u6846\u67b6\u7279\u5f81\ncurl -s https:\/\/httpbin.org | grep -i \"script\\|library\\|framework\"\n\n# \u540e\u7aef\u5c42\uff1a\u67e5\u770b\u54cd\u5e94\u5934\uff0c\u5bfb\u627e\u540e\u7aef\u8bed\u8a00\u6807\u8bb0\ncurl -I https:\/\/httpbin.org | grep -i \"x-powered-by\\|server\"\n\n# \u6570\u636e\u5c42\uff1a\u5c1d\u8bd5\u89e6\u53d1\u6570\u636e\u5e93\u9519\u8bef\uff08\u4ec5\u9650\u6388\u6743\u6d4b\u8bd5\uff09\uff0c\u4f8b\u5982\u901a\u8fc7\u6ce8\u5165\u7279\u6b8a\u5b57\u7b26\uff0c\u4f46\u6b64\u5904\u4ec5\u505a\u6982\u5ff5\u6f14\u793a\n# \u5bf9httpbin.org\u7684\u7279\u5b9a\u7aef\u70b9\u53d1\u9001\u975e\u6cd5\u53c2\u6570\uff0c\u89c2\u5bdf\u9519\u8bef\u54cd\u5e94\ncurl -s \"https:\/\/httpbin.org\/get?param='\"\n\n# \u4e2d\u95f4\u4ef6\u5c42\uff1a\u67e5\u770bServer\u5934\u548cVia\u5934\ncurl -I https:\/\/httpbin.org | grep -i \"server\\|via\"\n\n# \u64cd\u4f5c\u7cfb\u7edf\u5c42\uff1a\u901a\u8fc7TTL\u503c\u63a8\u6d4b\uff08\u4f7f\u7528ping\uff09\nping -c 1 httpbin.org | grep ttl<\/code><\/pre>\n\n\n\n<p>\u3010\u8865\u5145\u8bf4\u660e\uff1a<code>ping<\/code> \u547d\u4ee4\u7684 TTL \u503c\u53ef\u4f5c\u4e3a\u63a8\u65ad\u64cd\u4f5c\u7cfb\u7edf\u7684\u53c2\u8003\u4e4b\u4e00\uff0cLinux \u9ed8\u8ba4\u8d77\u59cb TTL \u901a\u5e38\u4e3a 64\uff0cWindows \u4e3a 128\u3002\u4f9d\u636e\uff1aLinux ping man page\u3002\u3011<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">3.5 \u5de5\u5177\u5bf9\u6bd4\u8868<\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u5de5\u5177<\/th><th>\u9002\u7528\u5c42\u6b21<\/th><th>\u4f18\u70b9<\/th><th>\u5c40\u9650<\/th><\/tr><\/thead><tbody><tr><td>curl<\/td><td>\u524d\u7aef\/\u540e\u7aef\/\u4e2d\u95f4\u4ef6<\/td><td>\u901a\u7528\u6027\u5f3a\uff0c\u53ef\u83b7\u53d6\u539f\u59cb\u6570\u636e<\/td><td>\u9700\u4eba\u5de5\u89e3\u6790\u7279\u5f81<\/td><\/tr><tr><td>\u6d4f\u89c8\u5668\u5f00\u53d1\u8005\u5de5\u5177<\/td><td>\u524d\u7aef<\/td><td>\u53ef\u89c6\u5316\u67e5\u770bDOM\u3001\u7f51\u7edc\u8bf7\u6c42\u3001\u63a7\u5236\u53f0<\/td><td>\u4e0d\u6613\u81ea\u52a8\u5316<\/td><\/tr><tr><td>nmap\u811a\u672c\uff08\u5982http-headers, http-title\uff09<\/td><td>\u540e\u7aef\/\u4e2d\u95f4\u4ef6<\/td><td>\u81ea\u52a8\u5316\u63d0\u53d6\u5e38\u89c1\u4fe1\u606f<\/td><td>\u811a\u672c\u8986\u76d6\u9762\u6709\u9650<\/td><\/tr><tr><td>wappalyzer\u6d4f\u89c8\u5668\u63d2\u4ef6<\/td><td>\u5168\u5c42\u6b21<\/td><td>\u4e00\u952e\u8bc6\u522b\uff0c\u96c6\u6210\u5ea6\u9ad8<\/td><td>\u4f9d\u8d56\u6d4f\u89c8\u5668\uff0c\u53ef\u80fd\u6f0f\u62a5<\/td><\/tr><tr><td>whatweb<\/td><td>\u5168\u5c42\u6b21<\/td><td>\u547d\u4ee4\u884c\u5de5\u5177\uff0c\u63d2\u4ef6\u4e30\u5bcc<\/td><td>\u90e8\u5206\u8bc6\u522b\u9700\u66f4\u65b0\u6307\u7eb9\u5e93<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">3.6 \u6807\u51c6\u64cd\u4f5c\u6b65\u9aa4<\/h3>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u6536\u96c6\u539f\u59cb\u6570\u636e<\/strong>\uff1a\u4f7f\u7528 curl \u83b7\u53d6\u76ee\u6807\u9996\u9875\u7684\u5b8c\u6574\u54cd\u5e94\u5934\u548c\u54cd\u5e94\u4f53\uff0c\u4fdd\u5b58\u4e3a\u6587\u4ef6\u3002<\/li>\n\n\n\n<li><strong>\u524d\u7aef\u5c42\u5206\u6790<\/strong>\uff1a<\/li>\n<\/ol>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u67e5\u770b HTML \u5934\u90e8\uff0c\u5bfb\u627e <code>&lt;meta name=\"generator\"<\/code> \u7b49\u6807\u7b7e\u3002<\/li>\n\n\n\n<li>\u641c\u7d22 <code>&lt;script&gt;<\/code> \u6807\u7b7e\uff0c\u63d0\u53d6 src \u5c5e\u6027\u4e2d\u7684\u5e93\u540d\uff08\u5982 <code>jquery.min.js<\/code>\u3001<code>vue.js<\/code>\uff09\u3002<\/li>\n\n\n\n<li>\u67e5\u770b DOM \u7ed3\u6784\u4e2d\u7684 <code>data-<\/code> \u5c5e\u6027\u6216\u7279\u5b9a\u7c7b\u540d\uff08\u5982 <code>react-root<\/code>\uff09\u3002<\/li>\n<\/ul>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u540e\u7aef\u5c42\u5206\u6790<\/strong>\uff1a<\/li>\n<\/ol>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u67e5\u770b\u54cd\u5e94\u5934\u4e2d\u7684 <code>Server<\/code>\u3001<code>X-Powered-By<\/code>\u3001<code>X-AspNet-Version<\/code> \u7b49\u5b57\u6bb5\u3002<\/li>\n\n\n\n<li>\u68c0\u67e5 Cookie\uff0c\u5982 <code>PHPSESSID<\/code>\u3001<code>JSESSIONID<\/code>\u3001<code>ASP.NET_SessionId<\/code>\u3002<\/li>\n\n\n\n<li>\u8bbf\u95ee\u5e38\u89c1\u7684\u7279\u5b9a\u8def\u5f84\uff08\u5982 <code>.git<\/code>\u3001<code>\/.env<\/code>\uff09\u6216\u6269\u5c55\u540d\uff08<code>.php<\/code>\u3001<code>.asp<\/code>\uff09\uff0c\u89c2\u5bdf\u54cd\u5e94\u3002<\/li>\n<\/ul>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u6570\u636e\u5c42\u5206\u6790<\/strong>\uff1a<\/li>\n<\/ol>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u5c1d\u8bd5\u8f93\u5165\u7279\u6b8a\u5b57\u7b26\uff08\u5982\u5355\u5f15\u53f7\uff09\u5230\u53c2\u6570\u4e2d\uff0c\u89c2\u5bdf\u662f\u5426\u8fd4\u56de\u6570\u636e\u5e93\u9519\u8bef\u3002<\/li>\n\n\n\n<li>\u68c0\u67e5\u5f00\u653e\u7684\u7aef\u53e3\uff08\u5982 3306\u300127017\uff09\u662f\u5426\u5bf9\u5916\u66b4\u9732\u3002<\/li>\n<\/ul>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u4e2d\u95f4\u4ef6\u5c42\u5206\u6790<\/strong>\uff1a<\/li>\n<\/ol>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u67e5\u770b <code>Server<\/code> \u5934\u7ec6\u8282\uff0c\u786e\u5b9a\u5177\u4f53\u8f6f\u4ef6\u53ca\u7248\u672c\u3002<\/li>\n\n\n\n<li>\u68c0\u67e5 <code>Via<\/code>\u3001<code>X-Cache<\/code> \u7b49\u5934\u90e8\uff0c\u5224\u65ad\u662f\u5426\u5b58\u5728\u53cd\u5411\u4ee3\u7406\u3002<\/li>\n<\/ul>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u64cd\u4f5c\u7cfb\u7edf\u5c42\u5206\u6790<\/strong>\uff1a<\/li>\n<\/ol>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u4f7f\u7528 <code>ping<\/code> \u83b7\u53d6 TTL \u503c\uff0c\u521d\u6b65\u5224\u65ad\u7cfb\u7edf\uff08Windows TTL\u2248128\uff0cLinux\u224864\uff09\u3002<\/li>\n\n\n\n<li>\u5206\u6790\u9519\u8bef\u9875\u9762\u4e2d\u7684\u8def\u5f84\u5206\u9694\u7b26\uff08<code>\\<\/code> \u6216 <code>\/<\/code>\uff09\u3002<\/li>\n<\/ul>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u6c47\u603b\u5c42\u6b21\u7279\u5f81<\/strong>\uff1a\u5c06\u5404\u5c42\u89c2\u5bdf\u5230\u7684\u7279\u5f81\u586b\u5165\u5c42\u6b21\u5206\u6790\u8868\u3002<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">3.7 \u5982\u4f55\u9a8c\u8bc1\u7ed3\u679c\u771f\u5b9e\u6027<\/h3>\n\n\n\n<p><strong>\u9a8c\u8bc1\u903b\u8f91<\/strong>\uff1a\u5bf9\u4e8e\u6bcf\u4e00\u5c42\u8bc6\u522b\u51fa\u7684\u7279\u5f81\uff0c\u5e94\u5bfb\u627e\u81f3\u5c11\u4e24\u4e2a\u72ec\u7acb\u8bc1\u636e\u3002\u4f8b\u5982\uff0c\u540e\u7aef\u8bed\u8a00\u662f PHP \u7684\u8bc1\u636e\u5305\u62ec\uff1a<code>X-Powered-By: PHP\/7.4<\/code>\u3001Cookie \u4e2d\u5305\u542b <code>PHPSESSID<\/code>\u3001URL \u4e2d\u51fa\u73b0 <code>.php<\/code> \u540e\u7f00\u3001\u9519\u8bef\u9875\u9762\u663e\u793a PHP \u8bed\u6cd5\u9519\u8bef\u3002\u5982\u679c\u53ea\u6709\u5355\u4e00\u8bc1\u636e\uff0c\u53ef\u80fd\u662f\u8bef\u62a5\uff08\u5982 CDN \u4f2a\u9020\u7684\u5934\u90e8\uff09\u3002<br><strong>\u5224\u65ad\u4f9d\u636e<\/strong>\uff1a\u4ea4\u53c9\u9a8c\u8bc1\u5404\u5de5\u5177\u7ed3\u679c\uff0c\u5e76\u53c2\u8003\u5df2\u77e5\u6280\u672f\u6808\uff08\u5982\u5b98\u65b9\u6587\u6863\uff09\u3002\u5bf9\u4e8e\u6d4b\u8bd5\u76ee\u6807\uff0c\u53ef\u4e3b\u52a8\u6784\u5efa\u6d4b\u8bd5\u73af\u5883\u9a8c\u8bc1\u7279\u5f81\u4e0e\u6280\u672f\u7684\u5bf9\u5e94\u5173\u7cfb\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">3.8 \u5e38\u89c1\u9519\u8bef\u4e0e\u6392\u67e5\u65b9\u5f0f<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u9519\u8bef1<\/strong>\uff1a\u6df7\u6dc6\u524d\u7aef\u6846\u67b6\u4e0e\u540e\u7aef\u6846\u67b6\u3002\u4f8b\u5982\uff0cReact \u662f\u524d\u7aef\u6846\u67b6\uff0c\u4f46\u670d\u52a1\u7aef\u6e32\u67d3\u4e5f\u53ef\u80fd\u4ea7\u751f\u7c7b\u4f3c\u7279\u5f81\u3002<\/li>\n\n\n\n<li><strong>\u6392\u67e5<\/strong>\uff1a\u68c0\u67e5\u7279\u5f81\u51fa\u73b0\u4e0a\u4e0b\u6587\uff0c\u662f\u5728 HTML \u6e90\u7801\u4e2d\uff08\u670d\u52a1\u7aef\u8f93\u51fa\uff09\u8fd8\u662f\u52a8\u6001\u6e32\u67d3\uff08\u9700\u6267\u884c JS\uff09\u3002<\/li>\n\n\n\n<li><strong>\u9519\u8bef2<\/strong>\uff1a\u5ffd\u7565\u9690\u85cf\u5c42\uff0c\u5982\u4f7f\u7528\u4e86 API \u7f51\u5173\uff0c\u7f51\u5173\u672c\u8eab\u53ef\u80fd\u6539\u53d8\u54cd\u5e94\u5934\u3002<\/li>\n\n\n\n<li><strong>\u6392\u67e5<\/strong>\uff1a\u5c1d\u8bd5\u76f4\u63a5\u8fde\u63a5\u540e\u7aef IP\uff08\u9700\u5148\u83b7\u5f97\u6388\u6743\u548c\u7f51\u7edc\u53ef\u8fbe\u6027\uff09\u3002<\/li>\n\n\n\n<li><strong>\u9519\u8bef3<\/strong>\uff1a\u6570\u636e\u5c42\u8bc6\u522b\u8fc7\u5ea6\u4f9d\u8d56\u9519\u8bef\u4fe1\u606f\uff0c\u4f46\u73b0\u4ee3\u5e94\u7528\u53ef\u80fd\u81ea\u5b9a\u4e49\u9519\u8bef\u9875\u9762\uff0c\u4e0d\u66b4\u9732\u6570\u636e\u5e93\u7ec6\u8282\u3002<\/li>\n\n\n\n<li><strong>\u6392\u67e5<\/strong>\uff1a\u4f7f\u7528\u66f4\u9ad8\u7ea7\u7684\u6280\u672f\uff0c\u5982\u65f6\u95f4\u76f2\u6ce8\uff08\u4ec5\u9650\u4e8e\u6388\u6743\u6d4b\u8bd5\uff09\uff0c\u6216\u5206\u6790 API \u54cd\u5e94\u7684\u4e00\u81f4\u6027\u3002<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">3.9 \u5408\u89c4\u8fb9\u754c\u8bf4\u660e<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u4f7f\u7528\u573a\u666f<\/strong>\uff1a\u4ec5\u9002\u7528\u4e8e\u5df2\u6388\u6743\u6d4b\u8bd5\u6216\u516c\u5f00\u6d4b\u8bd5\u73af\u5883\u3002\u4e3b\u52a8\u89e6\u53d1\u9519\u8bef\u4fe1\u606f\u53ef\u80fd\u8fdd\u53cd\u670d\u52a1\u6761\u6b3e\uff0c\u5e94\u8c28\u614e\u3002<\/li>\n\n\n\n<li><strong>\u7f51\u7edc\u5b89\u5168\u89c6\u89d2<\/strong>\uff1a\u5c1d\u8bd5 SQL \u6ce8\u5165\u7b49\u884c\u4e3a\u5373\u4f7f\u662f\u4e3a\u4e86\u6307\u7eb9\u8bc6\u522b\uff0c\u4e5f\u53ef\u80fd\u88ab\u89c6\u4e3a\u653b\u51fb\uff0c\u5bfc\u81f4\u6cd5\u5f8b\u8d23\u4efb\u3002\u901a\u8fc7\u9519\u8bef\u4fe1\u606f\u63a8\u65ad\u6570\u636e\u5e93\u7c7b\u578b\u4e0d\u4e00\u5b9a\u51c6\u786e\uff0c\u56e0\u4e3a\u9519\u8bef\u53ef\u80fd\u6765\u81ea\u5e94\u7528\u5c42\u800c\u975e\u6570\u636e\u5e93\u3002<\/li>\n\n\n\n<li><strong>\u7f13\u89e3\u63aa\u65bd<\/strong>\uff1a\u5728\u6388\u6743\u8303\u56f4\u5185\u660e\u786e\u5141\u8bb8\u7684\u6d4b\u8bd5\u65b9\u6cd5\uff1b\u4f18\u5148\u4f7f\u7528\u975e\u4fb5\u5165\u5f0f\u65b9\u6cd5\uff08\u5982\u5206\u6790\u7aef\u53e3\u3001\u54cd\u5e94\u5934\uff09\uff1b\u4f7f\u7528\u4e13\u95e8\u7684\u6559\u5b66\u73af\u5883\uff08\u5982 Damn Vulnerable Web Application\uff09\u7ec3\u4e60\u3002<\/li>\n\n\n\n<li><strong>\u672c\u6a21\u5757\u51b3\u7b56\u6307\u5357<\/strong>\uff1a<\/li>\n\n\n\n<li><strong>\u9002\u7528\u573a\u666f<\/strong>\uff1a\u9700\u8981\u5168\u9762\u4e86\u89e3\u76ee\u6807\u7684\u6280\u672f\u67b6\u6784\uff0c\u4ee5\u4fbf\u8fdb\u884c\u540e\u7eed\u5b89\u5168\u8bc4\u4f30\u6216\u517c\u5bb9\u6027\u6d4b\u8bd5\u65f6\u3002<\/li>\n\n\n\n<li><strong>\u66ff\u4ee3\u65b9\u6848<\/strong>\uff1a\u82e5\u76ee\u6807\u662f\u5185\u90e8\u7cfb\u7edf\uff0c\u53ef\u76f4\u63a5\u67e5\u9605\u8bbe\u8ba1\u6587\u6863\uff0c\u65e0\u9700\u901a\u8fc7\u5916\u90e8\u63a2\u6d4b\u3002<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">3.10 \u672c\u6a21\u5757\u9636\u6bb5\u6027\u5c0f\u7ed3<\/h3>\n\n\n\n<p>\u5e94\u7528\u67b6\u6784\u5c42\u6b21\u62c6\u89e3\u4f7f\u5de5\u7a0b\u5e08\u80fd\u7cfb\u7edf\u5ba1\u89c6 Web \u5e94\u7528\u7684\u6280\u672f\u6784\u6210\uff0c\u5c06\u96f6\u6563\u7279\u5f81\u5f52\u7c7b\u5230\u524d\u7aef\u3001\u540e\u7aef\u3001\u6570\u636e\u3001\u4e2d\u95f4\u4ef6\u3001\u64cd\u4f5c\u7cfb\u7edf\u7b49\u5c42\u6b21\uff0c\u5f62\u6210\u5c42\u6b21\u5206\u660e\u7684\u8bc6\u522b\u4efb\u52a1\u3002\u63a5\u4e0b\u6765\uff0c\u5c06\u9488\u5bf9\u6bcf\u4e00\u5c42\u6784\u5efa\u5177\u4f53\u7684\u7ec4\u4ef6\u8bc6\u522b\u65b9\u6cd5\uff0c\u5c06\u7279\u5f81\u8f6c\u5316\u4e3a\u53ef\u5339\u914d\u7684\u89c4\u5219\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u56db\u3001\u7ec4\u4ef6\u8bc6\u522b\u65b9\u6cd5\u5efa\u6a21<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">4.1 \u6a21\u5757\u6982\u5ff5\u89e3\u91ca<\/h3>\n\n\n\n<p>\u7ec4\u4ef6\u8bc6\u522b\u65b9\u6cd5\u5efa\u6a21\uff0c\u662f\u6307\u6784\u5efa\u4e00\u5957\u57fa\u4e8e\u591a\u6e90\u6570\u636e\u7684\u3001\u903b\u8f91\u4e25\u8c28\u7684\u6280\u672f\u7ec4\u4ef6\u8bc6\u522b\u6846\u67b6\u3002\u5176\u89e3\u51b3\u201c\u5982\u4f55\u51c6\u786e\u4ece\u7279\u5f81\u6570\u636e\u4e2d\u8bc6\u522b\u51fa\u5177\u4f53\u6280\u672f\u7ec4\u4ef6\u53ca\u5176\u7248\u672c\u201d\u7684\u95ee\u9898\u3002\u8be5\u6a21\u578b\u901a\u5e38\u5305\u542b\u7279\u5f81\u91c7\u96c6\u3001\u7279\u5f81\u63d0\u53d6\u3001\u89c4\u5219\u5339\u914d\u3001\u7f6e\u4fe1\u5ea6\u8bc4\u4f30\u7b49\u73af\u8282\u3002\u5efa\u6a21\u7684\u76ee\u7684\u662f\u4f7f\u8bc6\u522b\u8fc7\u7a0b\u53ef\u91cd\u590d\u3001\u53ef\u6269\u5c55\uff0c\u5e76\u80fd\u5904\u7406\u6a21\u7cca\u6216\u51b2\u7a81\u7684\u4fe1\u606f\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">4.2 \u6280\u672f\u539f\u7406\u8bf4\u660e<\/h3>\n\n\n\n<p>\u7ec4\u4ef6\u8bc6\u522b\u672c\u8d28\u662f\u6a21\u5f0f\u5339\u914d\u95ee\u9898\u3002\u6bcf\u4e2a\u6280\u672f\u7ec4\u4ef6\uff08\u5982 Apache\u3001Nginx\u3001Django\uff09\u5728\u8fd0\u884c\u65f6\u4f1a\u4ea7\u751f\u4e00\u7ec4\u72ec\u7279\u7684\u7279\u5f81\uff08\u6307\u7eb9\uff09\u3002\u8fd9\u4e9b\u7279\u5f81\u53ef\u8868\u73b0\u4e3a\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u786e\u5b9a\u6027\u7279\u5f81<\/strong>\uff1a\u5982\u54cd\u5e94\u5934\u4e2d\u7684 <code>Server: Apache\/2.4.41<\/code>\uff0c\u76f4\u63a5\u7ed9\u51fa\u7ec4\u4ef6\u540d\u548c\u7248\u672c\u3002<\/li>\n\n\n\n<li><strong>\u6982\u7387\u6027\u7279\u5f81<\/strong>\uff1a\u5982 Cookie \u540d\u79f0 <code>_ga<\/code> \u901a\u5e38\u4e0e Google Analytics \u76f8\u5173\uff0c\u4f46\u975e 100% \u786e\u5b9a\u3002<\/li>\n\n\n\n<li><strong>\u590d\u5408\u7279\u5f81<\/strong>\uff1a\u591a\u4e2a\u7279\u5f81\u7ec4\u5408\u53ef\u663e\u8457\u63d0\u9ad8\u51c6\u786e\u6027\uff0c\u4f8b\u5982\u540c\u65f6\u5339\u914d <code>X-Powered-By: PHP\/7.4<\/code> \u548c <code>PHPSESSID<\/code>\uff0c\u5219 PHP \u7684\u7f6e\u4fe1\u5ea6\u6781\u9ad8\u3002<\/li>\n<\/ul>\n\n\n\n<p>\u8bc6\u522b\u65b9\u6cd5\u5efa\u6a21\u7684\u6838\u5fc3\u662f\u5efa\u7acb\u7279\u5f81\u5e93\uff08\u6307\u7eb9\u5e93\uff09\uff0c\u5e76\u8bbe\u8ba1\u5339\u914d\u7b97\u6cd5\u3002\u5e38\u7528\u65b9\u6cd5\u6709\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u6b63\u5219\u8868\u8fbe\u5f0f\u5339\u914d<\/strong>\uff1a\u5bf9\u54cd\u5e94\u5934\u3001HTML \u5185\u5bb9\u8fdb\u884c\u6b63\u5219\u641c\u7d22\u3002<\/li>\n\n\n\n<li><strong>\u5173\u952e\u5b57\u54c8\u5e0c<\/strong>\uff1a\u5feb\u901f\u5339\u914d\u5e38\u89c1\u7ec4\u4ef6\u540d\u79f0\u3002<\/li>\n\n\n\n<li><strong>\u7248\u672c\u63d0\u53d6\u7b97\u6cd5<\/strong>\uff1a\u4ece\u7279\u5b9a\u4f4d\u7f6e\u63d0\u53d6\u7248\u672c\u53f7\u5e76\u8fdb\u884c\u8303\u56f4\u5224\u65ad\u3002<\/li>\n\n\n\n<li><strong>\u673a\u5668\u5b66\u4e60\u5206\u7c7b<\/strong>\uff1a\u9002\u7528\u4e8e\u7279\u5f81\u590d\u6742\u3001\u4e0d\u6613\u624b\u5de5\u5b9a\u4e49\u89c4\u5219\u7684\u60c5\u51b5\uff0c\u4f46\u5728 Web \u6307\u7eb9\u9886\u57df\u4ecd\u4ee5\u89c4\u5219\u4e3a\u4e3b\u3002<\/li>\n<\/ul>\n\n\n\n<p>\u6a21\u578b\u8bbe\u8ba1\u9700\u5e73\u8861\u51c6\u786e\u7387\u4e0e\u53ec\u56de\u7387\uff0c\u907f\u514d\u89c4\u5219\u8fc7\u4e8e\u5bbd\u6cdb\uff08\u5bfc\u81f4\u8bef\u62a5\uff09\u6216\u8fc7\u4e8e\u4e25\u683c\uff08\u5bfc\u81f4\u6f0f\u62a5\uff09\u3002<\/p>\n\n\n\n<p><strong>\u56fe4-1\uff1a\u7ec4\u4ef6\u8bc6\u522b\u65b9\u6cd5\u5efa\u6a21\u6d41\u7a0b\u56fe<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/03\/\u7ec4\u4ef6\u8bc6\u522b\u65b9\u6cd5\u5efa\u6a21\u6d41\u7a0b\u56fe-385x1024.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"385\" height=\"1024\" data-original=\"http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/03\/\u7ec4\u4ef6\u8bc6\u522b\u65b9\u6cd5\u5efa\u6a21\u6d41\u7a0b\u56fe-385x1024.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1764\"  sizes=\"auto, (max-width: 385px) 100vw, 385px\" \/><\/div><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">4.3 \u5728\u7cfb\u7edf\u4e2d\u7684\u4f4d\u7f6e<\/h3>\n\n\n\n<p>\u5728\u5c42\u6b21\u62c6\u89e3\u4e4b\u540e\uff0c\u9700\u8981\u4e3a\u6bcf\u4e00\u5c42\u7684\u6bcf\u4e2a\u6f5c\u5728\u7ec4\u4ef6\u5efa\u7acb\u8bc6\u522b\u89c4\u5219\u3002\u672c\u6a21\u5757\u6784\u5efa\u8fd9\u4e9b\u89c4\u5219\uff0c\u5f62\u6210\u53ef\u6267\u884c\u7684\u8bc6\u522b\u903b\u8f91\u3002\u540e\u7eed\u7684\u201c\u4fe1\u606f\u91c7\u96c6\u6d41\u7a0b\u5236\u5b9a\u201d\u5c06\u5229\u7528\u8fd9\u5957\u903b\u8f91\u5bf9\u91c7\u96c6\u6570\u636e\u8fdb\u884c\u5339\u914d\u3002\u56e0\u6b64\uff0c\u672c\u6a21\u5757\u662f\u6574\u4e2a\u6307\u7eb9\u8bc6\u522b\u7cfb\u7edf\u7684\u6838\u5fc3\u5f15\u64ce\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">4.4 \u53ef\u6267\u884c\u547d\u4ee4\u6216\u67e5\u8be2\u65b9\u5f0f<\/h3>\n\n\n\n<p>\u6f14\u793a\u5982\u4f55\u7f16\u5199\u7b80\u5355\u6307\u7eb9\u89c4\u5219\u5e76\u4f7f\u7528\u811a\u672c\u8fdb\u884c\u5339\u914d\uff08\u4ee5 Python \u4e3a\u4f8b\uff0c\u4f7f\u7528\u6d4b\u8bd5\u76ee\u6807 <code>httpbin.org<\/code>\uff09\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># 1. \u91c7\u96c6\u76ee\u6807\u54cd\u5e94\ncurl -s -I -X GET https:\/\/httpbin.org &gt; headers.txt\ncurl -s https:\/\/httpbin.org &gt; body.txt\n\n# 2. \u4f7f\u7528grep\u6a21\u62df\u89c4\u5219\u5339\u914d\uff08\u7b80\u5355\u7684\u6b63\u5219\uff09\n# \u5339\u914dServer\u5934\u5305\u542bgunicorn\ngrep -i \"server: gunicorn\" headers.txt\n\n# 3. \u7f16\u5199\u7b80\u5355Python\u811a\u672c\u8fdb\u884c\u590d\u5408\u5339\u914d (fingerprint.py)<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code># fingerprint.py \u793a\u4f8b\u5185\u5bb9\nimport re\n\nwith open('headers.txt') as f:\n    headers = f.read().lower()\nwith open('body.txt') as f:\n    body = f.read().lower()\n\ndef check_fingerprint(component, rules):\n    score = 0\n    for rule in rules:\n        if re.search(rule, headers) or re.search(rule, body):\n            score += 1\n    return score\n\n# \u5b9a\u4e49PHP\u6307\u7eb9\u89c4\u5219\nphp_rules = &#91;'x-powered-by: php', 'phpsessid', r'\\.php\\b']\nphp_score = check_fingerprint('php', php_rules)\nprint(f'PHP \u7f6e\u4fe1\u5ea6: {php_score}\/{len(php_rules)}')<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">4.5 \u5de5\u5177\u5bf9\u6bd4\u8868<\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u5de5\u5177\/\u65b9\u6cd5<\/th><th>\u9002\u7528\u573a\u666f<\/th><th>\u4f18\u70b9<\/th><th>\u5c40\u9650<\/th><\/tr><\/thead><tbody><tr><td>\u624b\u52a8\u7f16\u5199\u6b63\u5219<\/td><td>\u5c0f\u89c4\u6a21\u5b9a\u5236\u5316\u8bc6\u522b<\/td><td>\u7075\u6d3b\u3001\u53ef\u7cbe\u7ec6\u63a7\u5236<\/td><td>\u7ef4\u62a4\u6210\u672c\u9ad8\uff0c\u9700\u719f\u6089\u7279\u5f81<\/td><\/tr><tr><td>\u5f00\u6e90\u6307\u7eb9\u5e93\uff08\u5982 Wappalyzer apps.json\uff09<\/td><td>\u901a\u7528Web\u6307\u7eb9\u8bc6\u522b<\/td><td>\u793e\u533a\u7ef4\u62a4\uff0c\u8986\u76d6\u5e7f<\/td><td>\u4e0d\u4e00\u5b9a\u9002\u914d\u7279\u5b9a\u76ee\u6807\uff0c\u66f4\u65b0\u6ede\u540e<\/td><\/tr><tr><td>\u4e13\u7528\u6307\u7eb9\u8bc6\u522b\u6846\u67b6\uff08\u5982 Recog\uff09<\/td><td>\u9700\u8981\u7ed3\u6784\u5316\u6307\u7eb9\u7ba1\u7406<\/td><td>\u683c\u5f0f\u7edf\u4e00\uff0c\u6613\u4e8e\u6269\u5c55<\/td><td>\u5b66\u4e60\u66f2\u7ebf\uff0c\u9700\u96c6\u6210\u5230\u73b0\u6709\u6d41\u7a0b<\/td><\/tr><tr><td>\u673a\u5668\u5b66\u4e60\u5206\u7c7b\u5668<\/td><td>\u7279\u5f81\u6a21\u7cca\u3001\u96be\u4ee5\u5b9a\u4e49\u89c4\u5219\u65f6<\/td><td>\u53ef\u81ea\u52a8\u5b66\u4e60\u7279\u5f81<\/td><td>\u9700\u5927\u91cf\u6807\u6ce8\u6570\u636e\uff0c\u89e3\u91ca\u6027\u5dee<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">4.6 \u6807\u51c6\u64cd\u4f5c\u6b65\u9aa4<\/h3>\n\n\n\n<p>\u6309\u7167\u56fe4-1\u7684\u5efa\u6a21\u6d41\u7a0b\uff0c\u5404\u6b65\u9aa4\u5177\u4f53\u64cd\u4f5c\u5982\u4e0b\uff1a<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u786e\u5b9a\u5f85\u8bc6\u522b\u7ec4\u4ef6\u5217\u8868<\/strong>\uff1a\u6839\u636e\u5c42\u6b21\u62c6\u89e3\uff0c\u5217\u51fa\u53ef\u80fd\u5b58\u5728\u7684\u7ec4\u4ef6\uff08\u5982 Apache\u3001Nginx\u3001PHP\u3001MySQL \u7b49\uff09\u3002<\/li>\n\n\n\n<li><strong>\u6536\u96c6\u7ec4\u4ef6\u6307\u7eb9\u7279\u5f81<\/strong>\uff1a<\/li>\n<\/ol>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u67e5\u9605\u5b98\u65b9\u6587\u6863\u3001\u793e\u533a\u77e5\u8bc6\u5e93\u3001\u5df2\u6709\u6307\u7eb9\u5e93\uff08\u5982 Wappalyzer \u7684 apps.json\uff09\u3002<\/li>\n\n\n\n<li>\u5728\u6d4b\u8bd5\u73af\u5883\u4e2d\u5b89\u88c5\u5bf9\u5e94\u7ec4\u4ef6\uff0c\u89c2\u5bdf\u5176\u4ea7\u751f\u7684\u7279\u5f81\u3002<\/li>\n\n\n\n<li>\u6536\u96c6\u516c\u5f00\u7684\u6307\u7eb9\u6570\u636e\uff08\u5982\u6765\u81ea Netcraft\u3001BuiltWith\uff09\u3002<\/li>\n<\/ul>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u8bbe\u8ba1\u7279\u5f81\u89c4\u5219<\/strong>\uff1a<\/li>\n<\/ol>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u6bcf\u6761\u89c4\u5219\u5e94\u5305\u542b\uff1a\u7ec4\u4ef6\u540d\u79f0\u3001\u7279\u5f81\u7c7b\u578b\uff08header\/html\/cookie\uff09\u3001\u5339\u914d\u6a21\u5f0f\uff08\u6b63\u5219\/\u5b57\u7b26\u4e32\uff09\u3001\u6743\u91cd\u3002<\/li>\n\n\n\n<li>\u793a\u4f8b\uff1a<code>{ \"name\": \"jQuery\", \"type\": \"script\", \"pattern\": \"jquery[-.]([\\\\d.]+)\\\\.js\", \"version_group\": 1 }<\/code><\/li>\n<\/ul>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u5b9e\u73b0\u5339\u914d\u5f15\u64ce<\/strong>\uff1a<\/li>\n<\/ol>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u7f16\u5199\u811a\u672c\u6216\u4f7f\u7528\u73b0\u6709\u5de5\u5177\uff0c\u52a0\u8f7d\u89c4\u5219\uff0c\u5bf9\u76ee\u6807\u54cd\u5e94\u6570\u636e\u8fdb\u884c\u5339\u914d\u3002<\/li>\n\n\n\n<li>\u652f\u6301\u7ec4\u5408\u89c4\u5219\uff0c\u8ba1\u7b97\u7f6e\u4fe1\u5ea6\u3002<\/li>\n<\/ul>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u6d4b\u8bd5\u4e0e\u8c03\u4f18<\/strong>\uff1a<\/li>\n<\/ol>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u4f7f\u7528\u5df2\u77e5\u6280\u672f\u6808\u7684\u6d4b\u8bd5\u76ee\u6807\u9a8c\u8bc1\u89c4\u5219\u51c6\u786e\u6027\u3002<\/li>\n\n\n\n<li>\u8c03\u6574\u89c4\u5219\u6743\u91cd\uff0c\u51cf\u5c11\u8bef\u62a5\/\u6f0f\u62a5\u3002<\/li>\n<\/ul>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u6587\u6863\u5316<\/strong>\uff1a\u8bb0\u5f55\u6bcf\u6761\u89c4\u5219\u7684\u6765\u6e90\u3001\u6d4b\u8bd5\u7ed3\u679c\u3001\u66f4\u65b0\u65e5\u671f\u3002<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">4.7 \u5982\u4f55\u9a8c\u8bc1\u7ed3\u679c\u771f\u5b9e\u6027<\/h3>\n\n\n\n<p><strong>\u9a8c\u8bc1\u903b\u8f91<\/strong>\uff1a\u9488\u5bf9\u6bcf\u4e2a\u8bc6\u522b\u51fa\u7684\u7ec4\u4ef6\uff0c\u81f3\u5c11\u5e94\u6709\u4e24\u6761\u4ee5\u4e0a\u72ec\u7acb\u7279\u5f81\u652f\u6301\u3002\u4f8b\u5982\uff0c\u8bc6\u522b\u51fa Nginx\uff0c\u7279\u5f81\u53ef\u5305\u62ec\uff1a<code>Server: nginx<\/code>\u3001404 \u9875\u9762\u5305\u542b <code>nginx<\/code>\u3001\u7279\u5b9a\u9519\u8bef\u53f7 <code>413 Request Entity Too Large<\/code> \u7684\u54cd\u5e94\u683c\u5f0f\u7b49\u3002\u5bf9\u4e8e\u7248\u672c\u53f7\uff0c\u5e94\u68c0\u67e5\u662f\u5426\u5b58\u5728\u7248\u672c\u63d0\u53d6\u7279\u5f81\uff0c\u5e76\u4e0e\u5176\u4ed6\u7279\u5f81\uff08\u5982\u7279\u5b9a\u6f0f\u6d1e\u7684\u54cd\u5e94\uff09\u4ea4\u53c9\u9a8c\u8bc1\u3002<br><strong>\u5224\u65ad\u4f9d\u636e<\/strong>\uff1a\u82e5\u4ec5\u6709\u4e00\u6761\u7279\u5f81\u5339\u914d\uff0c\u5219\u6807\u8bb0\u4e3a\u201c\u5f85\u786e\u8ba4\u201d\uff1b\u82e5\u4e24\u6761\u53ca\u4ee5\u4e0a\uff0c\u5219\u8ba4\u5b9a\u4e3a\u9ad8\u7f6e\u4fe1\u5ea6\u3002\u6700\u7ec8\u53ef\u901a\u8fc7\u4eba\u5de5\u9a8c\u8bc1\u6216\u67e5\u9605\u6587\u6863\u786e\u8ba4\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">4.8 \u5e38\u89c1\u9519\u8bef\u4e0e\u6392\u67e5\u65b9\u5f0f<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u9519\u8bef1<\/strong>\uff1a\u89c4\u5219\u8fc7\u4e8e\u5bbd\u6cdb\uff0c\u5bfc\u81f4\u8bef\u62a5\u3002\u4f8b\u5982\uff0c\u7528 <code>php<\/code> \u5339\u914d\u54cd\u5e94\u5934\u4e2d\u7684 <code>PHP<\/code>\uff0c\u4f46\u53ef\u80fd\u51fa\u73b0\u5728\u6ce8\u91ca\u4e2d\u3002<\/li>\n\n\n\n<li><strong>\u6392\u67e5<\/strong>\uff1a\u9650\u5b9a\u5339\u914d\u4f4d\u7f6e\uff0c\u4f8b\u5982\u53ea\u5339\u914d\u54cd\u5e94\u5934\u6216\u7279\u5b9a HTML \u6807\u7b7e\u5185\uff1b\u4f7f\u7528\u8bcd\u8fb9\u754c <code>\\b<\/code>\u3002<\/li>\n\n\n\n<li><strong>\u9519\u8bef2<\/strong>\uff1a\u89c4\u5219\u8fc7\u4e8e\u4e25\u683c\uff0c\u5bfc\u81f4\u6f0f\u62a5\u3002\u4f8b\u5982\uff0c\u8981\u6c42\u7cbe\u786e\u7248\u672c\u53f7\uff0c\u4f46\u76ee\u6807\u53ef\u80fd\u81ea\u5b9a\u4e49\u7248\u672c\u6216\u9690\u85cf\u3002<\/li>\n\n\n\n<li><strong>\u6392\u67e5<\/strong>\uff1a\u4f7f\u7528\u4e0d\u5305\u542b\u7248\u672c\u53f7\u7684\u901a\u7528\u89c4\u5219\u4f5c\u4e3a\u5907\u7528\uff0c\u5e76\u8bbe\u7f6e\u7f6e\u4fe1\u5ea6\u964d\u7ea7\u3002<\/li>\n\n\n\n<li><strong>\u9519\u8bef3<\/strong>\uff1a\u5ffd\u7565\u7279\u5f81\u7684\u53ef\u4f2a\u9020\u6027\u3002\u4f8b\u5982\uff0c<code>X-Powered-By<\/code> \u53ef\u8f7b\u6613\u4fee\u6539\u6216\u5220\u9664\u3002<\/li>\n\n\n\n<li><strong>\u6392\u67e5<\/strong>\uff1a\u4e0d\u4f9d\u8d56\u53ef\u4f2a\u9020\u7279\u5f81\uff0c\u7ed3\u5408\u66f4\u9690\u853d\u7684\u7279\u5f81\uff08\u5982\u7279\u5b9a URL \u8def\u5f84\u3001Cookie \u751f\u6210\u7b97\u6cd5\uff09\u3002<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">4.9 \u5408\u89c4\u8fb9\u754c\u8bf4\u660e<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u4f7f\u7528\u573a\u666f<\/strong>\uff1a\u5efa\u6a21\u8fc7\u7a0b\u672c\u8eab\u4e0d\u6d89\u53ca\u5bf9\u76ee\u6807\u7684\u64cd\u4f5c\uff0c\u5c5e\u4e8e\u77e5\u8bc6\u6784\u5efa\u3002\u4f46\u91c7\u96c6\u6307\u7eb9\u7279\u5f81\u65f6\uff0c\u9700\u8bbf\u95ee\u6d4b\u8bd5\u73af\u5883\u6216\u5408\u6cd5\u516c\u5f00\u6570\u636e\u3002<\/li>\n\n\n\n<li><strong>\u7f51\u7edc\u5b89\u5168\u89c6\u89d2<\/strong>\uff1a\u82e5\u4f7f\u7528\u672a\u7ecf\u6388\u6743\u7684\u7b2c\u4e09\u65b9\u6307\u7eb9\u5e93\uff0c\u53ef\u80fd\u5b58\u5728\u7248\u6743\u6216\u6570\u636e\u5408\u89c4\u95ee\u9898\u3002\u4efb\u4f55\u89c4\u5219\u5e93\u90fd\u65e0\u6cd5\u8986\u76d6\u6240\u6709\u53ef\u80fd\u7684\u7ec4\u4ef6\u548c\u7248\u672c\uff0c\u9700\u6301\u7eed\u66f4\u65b0\u3002<\/li>\n\n\n\n<li><strong>\u7f13\u89e3\u63aa\u65bd<\/strong>\uff1a\u4f7f\u7528\u5f00\u6e90\u3001\u5408\u89c4\u7684\u6570\u636e\u6e90\uff1b\u5efa\u7acb\u81ea\u5df1\u7684\u6d4b\u8bd5\u73af\u5883\uff0c\u907f\u514d\u4f9d\u8d56\u4e0d\u53ef\u9760\u6765\u6e90\u3002<\/li>\n\n\n\n<li><strong>\u672c\u6a21\u5757\u51b3\u7b56\u6307\u5357<\/strong>\uff1a<\/li>\n\n\n\n<li><strong>\u9002\u7528\u573a\u666f<\/strong>\uff1a\u9700\u8981\u81ea\u52a8\u5316\u8bc6\u522b\u5927\u91cf\u76ee\u6807\uff0c\u6216\u9700\u8981\u4fdd\u8bc1\u8bc6\u522b\u7ed3\u679c\u53ef\u91cd\u590d\u6027\u65f6\u3002<\/li>\n\n\n\n<li><strong>\u66ff\u4ee3\u65b9\u6848<\/strong>\uff1a\u82e5\u53ea\u662f\u4e34\u65f6\u624b\u52a8\u5206\u6790\u4e00\u4e24\u4e2a\u76ee\u6807\uff0c\u53ef\u76f4\u63a5\u4f7f\u7528\u73b0\u6709\u5de5\u5177\uff08\u5982 whatweb\uff09\u800c\u4e0d\u81ea\u884c\u5efa\u6a21\u3002<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">4.10 \u672c\u6a21\u5757\u9636\u6bb5\u6027\u5c0f\u7ed3<\/h3>\n\n\n\n<p>\u7ec4\u4ef6\u8bc6\u522b\u65b9\u6cd5\u5efa\u6a21\u5c06\u7ecf\u9a8c\u8f6c\u5316\u4e3a\u53ef\u6267\u884c\u89c4\u5219\uff0c\u662f\u6280\u672f\u6307\u7eb9\u8bc6\u522b\u8d70\u5411\u5de5\u7a0b\u5316\u7684\u5173\u952e\u4e00\u6b65\u3002\u901a\u8fc7\u5efa\u7acb\u7279\u5f81\u5e93\u548c\u5339\u914d\u7b97\u6cd5\uff0c\u53ef\u7cfb\u7edf\u5316\u5730\u4ece\u539f\u59cb\u54cd\u5e94\u4e2d\u63d0\u53d6\u6280\u672f\u4fe1\u606f\u3002\u63a5\u4e0b\u6765\uff0c\u9700\u5236\u5b9a\u5b8c\u6574\u7684\u4fe1\u606f\u91c7\u96c6\u6d41\u7a0b\uff0c\u5c06\u8fd9\u4e9b\u65b9\u6cd5\u5e94\u7528\u5230\u5b9e\u9645\u6570\u636e\u91c7\u96c6\u4e2d\uff0c\u5b9e\u73b0\u4ece\u76ee\u6807\u5230\u8bc6\u522b\u7ed3\u679c\u7684\u5168\u8fc7\u7a0b\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u4e94\u3001\u4fe1\u606f\u91c7\u96c6\u6d41\u7a0b\u5236\u5b9a<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">5.1 \u6a21\u5757\u6982\u5ff5\u89e3\u91ca<\/h3>\n\n\n\n<p>\u4fe1\u606f\u91c7\u96c6\u6d41\u7a0b\u5236\u5b9a\uff0c\u662f\u6307\u8bbe\u8ba1\u4e00\u5957\u4ece\u76ee\u6807 Web \u5e94\u7528\u4e2d\u83b7\u53d6\u539f\u59cb\u6570\u636e\uff08\u5982 HTTP \u54cd\u5e94\u3001\u7aef\u53e3\u4fe1\u606f\u3001\u8bc1\u4e66\u7b49\uff09\u7684\u7cfb\u7edf\u5316\u6b65\u9aa4\uff0c\u4ee5\u4fbf\u540e\u7eed\u8fdb\u884c\u7ec4\u4ef6\u8bc6\u522b\u3002\u5176\u89e3\u51b3\u201c\u5982\u4f55\u9ad8\u6548\u3001\u5168\u9762\u5730\u83b7\u53d6\u7528\u4e8e\u6307\u7eb9\u8bc6\u522b\u7684\u6570\u636e\u201d\u7684\u95ee\u9898\u3002\u6d41\u7a0b\u901a\u5e38\u5305\u62ec\u88ab\u52a8\u4fe1\u606f\u6536\u96c6\u548c\u4e3b\u52a8\u4fe1\u606f\u6536\u96c6\u4e24\u79cd\u65b9\u5f0f\uff0c\u5e76\u8003\u8651\u6570\u636e\u6e05\u6d17\u3001\u53bb\u91cd\u3001\u5b58\u50a8\u7b49\u73af\u8282\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">5.2 \u6280\u672f\u539f\u7406\u8bf4\u660e<\/h3>\n\n\n\n<p>\u4fe1\u606f\u91c7\u96c6\u53ef\u6309\u4e0e\u76ee\u6807\u4ea4\u4e92\u7684\u7a0b\u5ea6\u5206\u4e3a\u4e24\u7c7b\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u88ab\u52a8\u4fe1\u606f\u6536\u96c6<\/strong>\uff1a\u4e0d\u76f4\u63a5\u5411\u76ee\u6807\u53d1\u9001\u8bf7\u6c42\uff0c\u800c\u662f\u901a\u8fc7\u7b2c\u4e09\u65b9\u6e20\u9053\u83b7\u53d6\u4fe1\u606f\u3002\u4f8b\u5982\uff1a<\/li>\n\n\n\n<li>\u641c\u7d22\u5f15\u64ce\u7f13\u5b58\uff08Google\u3001Bing\uff09<\/li>\n\n\n\n<li>\u516c\u5f00\u5b58\u6863\uff08Archive.org\uff09<\/li>\n\n\n\n<li>\u8bc1\u4e66\u900f\u660e\u5ea6\u65e5\u5fd7\uff08crt.sh\uff09<\/li>\n\n\n\n<li>DNS \u8bb0\u5f55\uff08DNSdumpster\uff09<br>\u88ab\u52a8\u6536\u96c6\u7684\u4f18\u52bf\u662f\u65e0\u75d5\u3001\u5b89\u5168\uff0c\u4f46\u4fe1\u606f\u53ef\u80fd\u8fc7\u65f6\u6216\u4e0d\u5b8c\u6574\u3002<\/li>\n\n\n\n<li><strong>\u4e3b\u52a8\u4fe1\u606f\u6536\u96c6<\/strong>\uff1a\u76f4\u63a5\u5411\u76ee\u6807\u53d1\u9001\u5404\u7c7b\u63a2\u6d4b\u8bf7\u6c42\uff0c\u83b7\u53d6\u5b9e\u65f6\u54cd\u5e94\u3002\u4f8b\u5982\uff1a<\/li>\n\n\n\n<li>\u7aef\u53e3\u626b\u63cf<\/li>\n\n\n\n<li>HTTP \u8bf7\u6c42\uff08\u5404\u79cd\u65b9\u6cd5\u3001\u8def\u5f84\u3001\u53c2\u6570\uff09<\/li>\n\n\n\n<li>TLS \u63e1\u624b<br>\u4e3b\u52a8\u6536\u96c6\u80fd\u83b7\u5f97\u6700\u65b0\u6570\u636e\uff0c\u4f46\u53ef\u80fd\u7559\u4e0b\u65e5\u5fd7\uff0c\u4e14\u9700\u6ce8\u610f\u8bf7\u6c42\u9891\u7387\u3002<\/li>\n<\/ul>\n\n\n\n<p>\u6d41\u7a0b\u5236\u5b9a\u9700\u7ed3\u5408\u4e24\u79cd\u65b9\u5f0f\uff0c\u5148\u88ab\u52a8\u540e\u4e3b\u52a8\uff0c\u5148\u5e7f\u6cdb\u540e\u7cbe\u7ec6\uff0c\u4ee5\u51cf\u5c11\u5bf9\u76ee\u6807\u7684\u5f71\u54cd\u5e76\u63d0\u9ad8\u6548\u7387\u3002<\/p>\n\n\n\n<p><strong>\u56fe5-1\uff1a\u4fe1\u606f\u91c7\u96c6\u6d41\u7a0b\u56fe\uff08\u88ab\u52a8+\u4e3b\u52a8\uff09<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/03\/\u4fe1\u606f\u91c7\u96c6\u6d41\u7a0b\u56fe-981x1024.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"981\" height=\"1024\" data-original=\"http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/03\/\u4fe1\u606f\u91c7\u96c6\u6d41\u7a0b\u56fe-981x1024.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1766\"  sizes=\"auto, (max-width: 981px) 100vw, 981px\" \/><\/div><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">5.3 \u5728\u7cfb\u7edf\u4e2d\u7684\u4f4d\u7f6e<\/h3>\n\n\n\n<p>\u672c\u6a21\u5757\u4f4d\u4e8e\u65b9\u6cd5\u5efa\u6a21\u4e4b\u540e\uff0c\u7efc\u5408\u5b9e\u8df5\u4e4b\u524d\u3002\u5b83\u5c06\u524d\u5e8f\u6784\u5efa\u7684\u8bc6\u522b\u65b9\u6cd5\u5e94\u7528\u4e8e\u5b9e\u9645\u6570\u636e\u83b7\u53d6\uff0c\u4e3a\u6700\u7ec8\u7684\u6280\u672f\u6808\u8fd8\u539f\u63d0\u4f9b\u539f\u59cb\u7d20\u6750\u3002\u540c\u65f6\uff0c\u6d41\u7a0b\u4e2d\u5b9a\u4e49\u7684\u91c7\u96c6\u6df1\u5ea6\u548c\u5e7f\u5ea6\u5c06\u76f4\u63a5\u5f71\u54cd\u540e\u7eed\u8bc6\u522b\u7684\u5b8c\u6574\u6027\u548c\u51c6\u786e\u6027\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">5.4 \u53ef\u6267\u884c\u547d\u4ee4\u6216\u67e5\u8be2\u65b9\u5f0f<\/h3>\n\n\n\n<p>\u4ee5 <code>example.com<\/code> \u548c <code>scanme.nmap.org<\/code> \u4e3a\u4f8b\uff0c\u5c55\u793a\u88ab\u52a8\u4e0e\u4e3b\u52a8\u91c7\u96c6\u7684\u547d\u4ee4\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># \u88ab\u52a8\u6536\u96c6\uff1a\u67e5\u8be2\u8bc1\u4e66\u900f\u660e\u5ea6\u65e5\u5fd7\uff08\u4f7f\u7528curl\u8c03\u7528crt.sh API\uff09\ncurl -s \"https:\/\/crt.sh\/?q=%.example.com&amp;output=json\" | jq .\n\n# \u88ab\u52a8\u6536\u96c6\uff1a\u67e5\u8be2DNS\u8bb0\u5f55\ndig example.com ANY +short\nnslookup example.com\n\n# \u4e3b\u52a8\u6536\u96c6\uff1aHTTP\u57fa\u672c\u8bf7\u6c42\uff08\u4f7f\u7528httpx\u6279\u91cf\u63a2\u6d4b\u5e38\u89c1\u8def\u5f84\uff09\necho \"http:\/\/example.com\" | httpx -paths \/robots.txt -status-code -content-length\n\n# \u4e3b\u52a8\u6536\u96c6\uff1a\u4f7f\u7528nmap\u626b\u63cf\u7aef\u53e3\nnmap -p 80,443,8080 scanme.nmap.org\n\n# \u4e3b\u52a8\u6536\u96c6\uff1a\u4f7f\u7528whatweb\u83b7\u53d6\u6307\u7eb9\nwhatweb -a 3 http:\/\/scanme.nmap.org<\/code><\/pre>\n\n\n\n<p>\u3010\u8865\u5145\u8bf4\u660e\uff1a<code>crt.sh<\/code> \u662f\u8bc1\u4e66\u900f\u660e\u5ea6\u65e5\u5fd7\u67e5\u8be2\u7f51\u7ad9\uff0c\u63d0\u4f9b\u516c\u5171 API\u3002<code>httpx<\/code> \u662f\u591a\u529f\u80fd HTTP \u5de5\u5177\u5305\uff0c\u7528\u4e8e\u63a2\u6d3b\u548c\u8def\u5f84\u63a2\u6d4b\u3002<code>jq<\/code> \u7528\u4e8e\u5904\u7406 JSON \u6570\u636e\u3002\u4f9d\u636e\uff1acrt.sh \u5b98\u65b9\u7f51\u7ad9\uff1bhttpx GitHub Repository\uff1bjq Manual\u3002\u3011<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">5.5 \u5de5\u5177\u5bf9\u6bd4\u8868<\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u5de5\u5177<\/th><th>\u91c7\u96c6\u7c7b\u578b<\/th><th>\u4f18\u70b9<\/th><th>\u5c40\u9650<\/th><\/tr><\/thead><tbody><tr><td>crt.sh (curl)<\/td><td>\u88ab\u52a8\uff08\u8bc1\u4e66\uff09<\/td><td>\u6570\u636e\u4e30\u5bcc\uff0c\u53ef\u53d1\u73b0\u5b50\u57df\u540d<\/td><td>\u9700\u89e3\u6790JSON\uff0c\u7ed3\u679c\u53ef\u80fd\u5305\u542b\u8fc7\u671f\u8bc1\u4e66<\/td><\/tr><tr><td>theHarvester<\/td><td>\u88ab\u52a8\uff08\u641c\u7d22\u5f15\u64ce\u3001PGP\u7b49\uff09<\/td><td>\u96c6\u6210\u591a\u79cd\u6e90\uff0c\u53ef\u83b7\u53d6\u90ae\u7bb1\u3001\u5b50\u57df<\/td><td>\u4f9d\u8d56\u5916\u90e8\u6e90\u53ef\u7528\u6027\uff0c\u53ef\u80fd\u88ab\u5c01<\/td><\/tr><tr><td>dnsrecon<\/td><td>\u88ab\u52a8\/\u4e3b\u52a8\uff08DNS\uff09<\/td><td>DNS\u679a\u4e3e\u3001\u533a\u57df\u4f20\u9001\u68c0\u67e5<\/td><td>\u533a\u57df\u4f20\u9001\u901a\u5e38\u88ab\u7981\u6b62<\/td><\/tr><tr><td>nmap<\/td><td>\u4e3b\u52a8\uff08\u7aef\u53e3\u3001\u670d\u52a1\uff09<\/td><td>\u529f\u80fd\u5f3a\u5927\uff0c\u811a\u672c\u4e30\u5bcc<\/td><td>\u626b\u63cf\u65f6\u95f4\u957f\uff0c\u6613\u88ab\u53d1\u73b0<\/td><\/tr><tr><td>httpx<\/td><td>\u4e3b\u52a8\uff08HTTP\u63a2\u6d3b\uff09<\/td><td>\u5feb\u901f\u5e76\u53d1\u63a2\u6d4b\uff0c\u652f\u6301\u591a\u79cd\u534f\u8bae<\/td><td>\u9700\u5148\u77e5\u9053\u7aef\u53e3\uff0c\u53ef\u80fd\u6f0f\u6389\u975e\u6807\u51c6\u670d\u52a1<\/td><\/tr><tr><td>gau<\/td><td>\u88ab\u52a8+\u4e3b\u52a8\uff08\u83b7\u53d6\u5df2\u77e5URL\uff09<\/td><td>\u4ece\u591a\u4e2a\u6e90\u6536\u96c6\u5386\u53f2URL<\/td><td>\u8f93\u51fa\u53ef\u80fd\u5305\u542b\u5927\u91cf\u566a\u58f0<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">5.6 \u6807\u51c6\u64cd\u4f5c\u6b65\u9aa4<\/h3>\n\n\n\n<p>\u6309\u7167\u56fe5-1\u7684\u4fe1\u606f\u91c7\u96c6\u6d41\u7a0b\uff0c\u5404\u6b65\u9aa4\u5177\u4f53\u64cd\u4f5c\u5982\u4e0b\uff1a<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u786e\u5b9a\u91c7\u96c6\u76ee\u6807<\/strong>\uff1a\u660e\u786e\u76ee\u6807\u57df\u540d\/IP \u5217\u8868\uff0c\u5e76\u786e\u8ba4\u6d4b\u8bd5\u6388\u6743\u3002<\/li>\n\n\n\n<li><strong>\u88ab\u52a8\u4fe1\u606f\u6536\u96c6<\/strong>\uff1a<\/li>\n<\/ol>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u4f7f\u7528 crt.sh \u67e5\u8be2\u76ee\u6807\u57df\u540d\u8bc1\u4e66\uff0c\u83b7\u53d6\u5b50\u57df\u540d\u5217\u8868\uff1a<code>curl -s \"https:\/\/crt.sh\/?q=%.example.com&amp;output=json\" | jq .<\/code><\/li>\n\n\n\n<li>\u4f7f\u7528\u641c\u7d22\u5f15\u64ce\u641c\u7d22 <code>site:example.com<\/code> \u6536\u96c6\u516c\u5f00\u9875\u9762\u3002<\/li>\n\n\n\n<li>\u4f7f\u7528 theHarvester \u7b49\u5de5\u5177\u6536\u96c6\u90ae\u7bb1\u3001\u5b50\u57df\u7b49\u3002<\/li>\n\n\n\n<li>\u67e5\u8be2 DNS \u8bb0\u5f55\uff08A\u3001MX\u3001TXT\u3001NS \u7b49\uff09\uff1a<code>dig example.com ANY +short<\/code><\/li>\n<\/ul>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u4e3b\u52a8\u4fe1\u606f\u6536\u96c6\uff08\u57fa\u7840\u5c42\uff09<\/strong>\uff1a<\/li>\n<\/ol>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u5bf9\u76ee\u6807 IP \u8fdb\u884c\u7aef\u53e3\u626b\u63cf\uff0c\u8bc6\u522b\u5f00\u653e\u7aef\u53e3\u53ca\u670d\u52a1\uff1a<code>nmap -sV scanme.nmap.org<\/code><\/li>\n\n\n\n<li>\u5bf9\u53d1\u73b0\u7684 Web \u7aef\u53e3\u8fdb\u884c HTTP \u63a2\u6d3b\uff0c\u83b7\u53d6\u54cd\u5e94\u5934\u4e0e\u72b6\u6001\u7801\uff1a<code>httpx -path \/ -status-code<\/code><\/li>\n<\/ul>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u4e3b\u52a8\u4fe1\u606f\u6536\u96c6\uff08\u5e94\u7528\u5c42\uff09<\/strong>\uff1a<\/li>\n<\/ol>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u4f7f\u7528 httpx \u6216\u81ea\u5b9a\u4e49\u811a\u672c\uff0c\u5bf9\u5e38\u89c1 Web \u8def\u5f84\uff08\u5982 <code>\/admin<\/code>\u3001<code>\/api<\/code>\u3001<code>\/backup<\/code>\uff09\u8fdb\u884c\u6a21\u7cca\u6d4b\u8bd5\uff08\u9700\u6ce8\u610f\u9891\u7387\uff09\uff1a<code>ffuf -u http:\/\/example.com\/FUZZ -w wordlist.txt<\/code><\/li>\n\n\n\n<li>\u83b7\u53d6\u6bcf\u4e2a\u6709\u6548\u8def\u5f84\u7684\u5b8c\u6574\u54cd\u5e94\uff08\u5934+\u4e3b\u4f53\uff09\u3002<\/li>\n\n\n\n<li>\u83b7\u53d6 TLS \u8bc1\u4e66\u8be6\u7ec6\u4fe1\u606f\uff08\u82e5\u4f7f\u7528 HTTPS\uff09\uff1a<code>openssl s_client -connect example.com:443<\/code><\/li>\n<\/ul>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u6570\u636e\u6e05\u6d17\u4e0e\u5b58\u50a8<\/strong>\uff1a<\/li>\n<\/ol>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u53bb\u9664\u91cd\u590d\u54cd\u5e94\uff0c\u5408\u5e76\u76f8\u540c URL \u7684\u6570\u636e\u3002<\/li>\n\n\n\n<li>\u5c06\u54cd\u5e94\u5934\u3001\u54cd\u5e94\u4f53\u3001\u7aef\u53e3\u4fe1\u606f\u3001\u8bc1\u4e66\u4fe1\u606f\u7b49\u5b58\u5165\u7ed3\u6784\u5316\u5b58\u50a8\uff08\u5982 JSON \u6587\u4ef6\u3001\u6570\u636e\u5e93\uff09\u3002<\/li>\n<\/ul>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u6570\u636e\u8d28\u91cf\u68c0\u67e5<\/strong>\uff1a\u786e\u4fdd\u91c7\u96c6\u7684\u6570\u636e\u8986\u76d6\u6240\u6709\u9884\u671f\u5c42\u6b21\uff0c\u5fc5\u8981\u65f6\u8865\u5145\u91c7\u96c6\u3002<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">5.7 \u5982\u4f55\u9a8c\u8bc1\u7ed3\u679c\u771f\u5b9e\u6027<\/h3>\n\n\n\n<p><strong>\u9a8c\u8bc1\u903b\u8f91<\/strong>\uff1a\u901a\u8fc7\u5bf9\u6bd4\u88ab\u52a8\u4e0e\u4e3b\u52a8\u6570\u636e\u7684\u4e00\u81f4\u6027\uff0c\u4ee5\u53ca\u591a\u6e90\u6570\u636e\u7684\u4ea4\u53c9\u5370\u8bc1\u3002\u4f8b\u5982\uff0ccrt.sh \u53d1\u73b0\u7684\u5b50\u57df\u540d\u5e94\u80fd\u901a\u8fc7 DNS \u89e3\u6790\u5e76\u8fd4\u56de\u6709\u6548\u54cd\u5e94\uff1b\u7aef\u53e3\u626b\u63cf\u53d1\u73b0\u7684 Web \u670d\u52a1\u5e94\u80fd\u901a\u8fc7 HTTP \u8bf7\u6c42\u9a8c\u8bc1\u3002\u82e5\u67d0\u5b50\u57df\u540d\u5728\u88ab\u52a8\u6536\u96c6\u4e2d\u5b58\u5728\u4f46\u5728\u4e3b\u52a8\u63a2\u6d4b\u4e2d\u65e0\u54cd\u5e94\uff0c\u53ef\u80fd\u662f\u5df2\u4e0b\u7ebf\u6216\u9700\u7279\u6b8a\u7aef\u53e3\u3002<br><strong>\u5224\u65ad\u4f9d\u636e<\/strong>\uff1a\u6240\u6709\u91c7\u96c6\u7684\u6570\u636e\u5e94\u80fd\u590d\u73b0\u3002\u9009\u53d6\u82e5\u5e72\u5173\u952e\u6570\u636e\u8fdb\u884c\u624b\u5de5\u9a8c\u8bc1\uff0c\u786e\u4fdd\u5de5\u5177\u91c7\u96c6\u65e0\u8bef\u3002\u5bf9\u4e8e\u6d4b\u8bd5\u76ee\u6807\uff0c\u53ef\u53c2\u8003\u5b98\u65b9\u6587\u6863\u786e\u8ba4\u6570\u636e\u5b8c\u6574\u6027\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">5.8 \u5e38\u89c1\u9519\u8bef\u4e0e\u6392\u67e5\u65b9\u5f0f<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u9519\u8bef1<\/strong>\uff1a\u88ab\u52a8\u6536\u96c6\u4f9d\u8d56\u7684\u5916\u90e8\u6e90\u4e0d\u7a33\u5b9a\u6216\u8fd4\u56de\u8fc7\u671f\u6570\u636e\u3002<\/li>\n\n\n\n<li><strong>\u6392\u67e5<\/strong>\uff1a\u4f7f\u7528\u591a\u4e2a\u6e90\u4ea4\u53c9\u9a8c\u8bc1\uff0c\u5e76\u5173\u6ce8\u6570\u636e\u7684\u65f6\u95f4\u6233\u3002<\/li>\n\n\n\n<li><strong>\u9519\u8bef2<\/strong>\uff1a\u4e3b\u52a8\u6536\u96c6\u65f6\u8bf7\u6c42\u9891\u7387\u8fc7\u9ad8\uff0c\u89e6\u53d1\u76ee\u6807\u9632\u62a4\u673a\u5236\uff08\u5982 WAF \u5c01 IP\uff09\u6216\u5bfc\u81f4\u670d\u52a1\u4e0d\u7a33\u5b9a\u3002<\/li>\n\n\n\n<li><strong>\u6392\u67e5<\/strong>\uff1a\u8bbe\u7f6e\u5408\u7406\u7684\u5ef6\u8fdf\uff08&#8211;delay\uff09\uff0c\u4f7f\u7528\u4ee3\u7406\u6c60\u8f6e\u6362 IP\uff08\u9700\u6388\u6743\uff09\uff0c\u6216\u964d\u4f4e\u5e76\u53d1\u3002<\/li>\n\n\n\n<li><strong>\u9519\u8bef3<\/strong>\uff1a\u6570\u636e\u5b58\u50a8\u6df7\u4e71\uff0c\u4e22\u5931\u5173\u8054\u4fe1\u606f\uff08\u5982\u54ea\u4e2a\u54cd\u5e94\u5bf9\u5e94\u54ea\u4e2a URL\uff09\u3002<\/li>\n\n\n\n<li><strong>\u6392\u67e5<\/strong>\uff1a\u5efa\u7acb\u660e\u786e\u7684\u76ee\u5f55\u7ed3\u6784\u6216\u6570\u636e\u5e93\u8868\uff0c\u6bcf\u6761\u8bb0\u5f55\u5305\u542b\u6e90 URL\u3001\u65f6\u95f4\u6233\u3001\u8bf7\u6c42\u5934\u7b49\u4fe1\u606f\u3002<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">5.9 \u5408\u89c4\u8fb9\u754c\u8bf4\u660e<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u4f7f\u7528\u573a\u666f<\/strong>\uff1a\u4fe1\u606f\u91c7\u96c6\u5fc5\u987b\u5728\u6388\u6743\u8303\u56f4\u5185\u8fdb\u884c\u3002\u5bf9\u4e8e\u516c\u5171\u6d4b\u8bd5\u76ee\u6807\uff0c\u5e94\u9075\u5b88\u5176\u6761\u6b3e\uff08\u5982 scanme.nmap.org \u5141\u8bb8\u626b\u63cf\uff09\u3002<\/li>\n\n\n\n<li><strong>\u7f51\u7edc\u5b89\u5168\u89c6\u89d2<\/strong>\uff1a\u4e3b\u52a8\u6536\u96c6\u53ef\u80fd\u88ab\u76ee\u6807\u89c6\u4e3a\u6076\u610f\u626b\u63cf\uff0c\u5bfc\u81f4 IP \u88ab\u5c01\u751a\u81f3\u6cd5\u5f8b\u8ffd\u8d23\u3002\u5373\u4f7f\u662f\u88ab\u52a8\u6536\u96c6\uff0c\u8fc7\u5ea6\u4f7f\u7528 API \u4e5f\u53ef\u80fd\u8fdd\u53cd\u670d\u52a1\u6761\u6b3e\u3002\u88ab\u52a8\u6536\u96c6\u53ef\u80fd\u65e0\u6cd5\u83b7\u5f97\u6700\u65b0\u6570\u636e\uff0c\u4e3b\u52a8\u6536\u96c6\u53ef\u80fd\u88ab\u68c0\u6d4b\u3002<\/li>\n\n\n\n<li><strong>\u7f13\u89e3\u63aa\u65bd<\/strong>\uff1a\u5728\u6388\u6743\u5408\u540c\u4e2d\u660e\u786e\u91c7\u96c6\u65b9\u6cd5\uff1b\u4f7f\u7528\u6d4b\u8bd5\u4e13\u7528\u76ee\u6807\uff1b\u8bbe\u7f6e\u91c7\u96c6\u901f\u7387\u9650\u5236\uff1b\u4f18\u5148\u4f7f\u7528\u88ab\u52a8\u65b9\u5f0f\u3002<\/li>\n\n\n\n<li><strong>\u672c\u6a21\u5757\u51b3\u7b56\u6307\u5357<\/strong>\uff1a<\/li>\n\n\n\n<li><strong>\u9002\u7528\u573a\u666f<\/strong>\uff1a\u9700\u8981\u83b7\u53d6\u6700\u65b0\u3001\u6700\u5168\u9762\u7684\u76ee\u6807\u6570\u636e\u4ee5\u8fdb\u884c\u540e\u7eed\u5206\u6790\u65f6\u3002<\/li>\n\n\n\n<li><strong>\u66ff\u4ee3\u65b9\u6848<\/strong>\uff1a\u82e5\u53ea\u9700\u5df2\u77e5\u7684\u5c11\u91cf\u4fe1\u606f\uff0c\u53ef\u76f4\u63a5\u4f7f\u7528\u6d4f\u89c8\u5668\u8bbf\u95ee\uff0c\u65e0\u9700\u7cfb\u7edf\u5316\u91c7\u96c6\u3002<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">5.10 \u672c\u6a21\u5757\u9636\u6bb5\u6027\u5c0f\u7ed3<\/h3>\n\n\n\n<p>\u4fe1\u606f\u91c7\u96c6\u6d41\u7a0b\u5236\u5b9a\u5c06\u7406\u8bba\u65b9\u6cd5\u8f6c\u5316\u4e3a\u5b9e\u9645\u64cd\u4f5c\uff0c\u901a\u8fc7\u88ab\u52a8\u548c\u4e3b\u52a8\u7ed3\u5408\u7684\u65b9\u5f0f\uff0c\u7cfb\u7edf\u5316\u5730\u83b7\u53d6\u76ee\u6807\u591a\u7ef4\u5ea6\u6570\u636e\u3002\u8fd9\u4e9b\u6570\u636e\u5c06\u6210\u4e3a\u540e\u7eed\u7ec4\u4ef6\u8bc6\u522b\u7684\u8f93\u5165\u3002\u5728\u6b63\u5f0f\u6267\u884c\u91c7\u96c6\u524d\uff0c\u5fc5\u987b\u5148\u660e\u786e\u63a2\u67e5\u8fb9\u754c\u548c\u98ce\u9669\u63a7\u5236\u7b56\u7565\uff0c\u786e\u4fdd\u6d41\u7a0b\u5408\u6cd5\u3001\u5b89\u5168\u3002\u4e0b\u4e00\u6a21\u5757\u5c06\u91cd\u70b9\u8ba8\u8bba\u8fd9\u4e9b\u5408\u89c4\u4e0e\u98ce\u9669\u95ee\u9898\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u516d\u3001\u63a2\u67e5\u8fb9\u754c\u4e0e\u98ce\u9669\u63a7\u5236<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">6.1 \u6a21\u5757\u6982\u5ff5\u89e3\u91ca<\/h3>\n\n\n\n<p>\u63a2\u67e5\u8fb9\u754c\u4e0e\u98ce\u9669\u63a7\u5236\uff0c\u662f\u6307\u5728\u6267\u884c\u6280\u672f\u63a2\u67e5\u524d\uff0c\u754c\u5b9a\u54ea\u4e9b\u884c\u4e3a\u5141\u8bb8\uff0c\u54ea\u4e9b\u7981\u6b62\uff0c\u5e76\u91c7\u53d6\u76f8\u5e94\u63aa\u65bd\u964d\u4f4e\u5bf9\u76ee\u6807\u7cfb\u7edf\u7684\u8d1f\u9762\u5f71\u54cd\u548c\u6cd5\u5f8b\u98ce\u9669\u3002\u5176\u89e3\u51b3\u201c\u5982\u4f55\u786e\u4fdd\u63a2\u67e5\u884c\u4e3a\u5408\u6cd5\u3001\u5408\u89c4\u3001\u5b89\u5168\u201d\u7684\u95ee\u9898\u3002\u6838\u5fc3\u5185\u5bb9\u5305\u62ec\uff1a\u83b7\u53d6\u6388\u6743\u3001\u754c\u5b9a\u6d4b\u8bd5\u8303\u56f4\u3001\u8bbe\u7f6e\u626b\u63cf\u901f\u7387\u3001\u8bc6\u522b\u8bef\u5224\u98ce\u9669\u3001\u5236\u5b9a\u5e94\u6025\u8ba1\u5212\u7b49\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">6.2 \u6280\u672f\u539f\u7406\u8bf4\u660e<\/h3>\n\n\n\n<p>\u4ece\u6280\u672f\u5c42\u9762\uff0c\u4efb\u4f55\u4e3b\u52a8\u63a2\u6d4b\u90fd\u4f1a\u5728\u76ee\u6807\u7cfb\u7edf\u7559\u4e0b\u75d5\u8ff9\uff0c\u53ef\u80fd\u88ab\u65e5\u5fd7\u8bb0\u5f55\u3001\u89e6\u53d1\u5165\u4fb5\u68c0\u6d4b\u7cfb\u7edf\u3001\u8017\u5c3d\u8d44\u6e90\u6216\u5bfc\u81f4\u670d\u52a1\u5f02\u5e38\u3002\u4ece\u6cd5\u5f8b\u5c42\u9762\uff0c\u672a\u7ecf\u6388\u6743\u7684\u626b\u63cf\u53ef\u80fd\u8fdd\u53cd\u8ba1\u7b97\u673a\u5b89\u5168\u6cd5\u89c4\uff08\u5982\u4e2d\u56fd\u7684\u300a\u7f51\u7edc\u5b89\u5168\u6cd5\u300b\u3001\u7f8e\u56fd\u7684 CFAA\uff09\u3002\u56e0\u6b64\uff0c\u98ce\u9669\u63a7\u5236\u9700\u4ece\u6280\u672f\u548c\u6cd5\u5f8b\u4e24\u4e2a\u7ef4\u5ea6\u8bbe\u8ba1\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u6280\u672f\u98ce\u9669\u63a7\u5236<\/strong>\uff1a<\/li>\n\n\n\n<li>\u901f\u7387\u9650\u5236\uff1a\u63a7\u5236\u8bf7\u6c42\u9891\u7387\uff0c\u907f\u514d DoS\u3002<\/li>\n\n\n\n<li>\u626b\u63cf\u7b56\u7565\uff1a\u5148\u8f7b\u91cf\u540e\u6df1\u5ea6\uff0c\u907f\u514d\u7a81\u53d1\u5927\u91cf\u8bf7\u6c42\u3002<\/li>\n\n\n\n<li>\u767d\u540d\u5355\u673a\u5236\uff1a\u4ec5\u5bf9\u6388\u6743 IP\/\u57df\u540d\u8fdb\u884c\u6d4b\u8bd5\u3002<\/li>\n\n\n\n<li><strong>\u6cd5\u5f8b\u98ce\u9669\u63a7\u5236<\/strong>\uff1a<\/li>\n\n\n\n<li>\u4e66\u9762\u6388\u6743\uff1a\u83b7\u53d6\u76ee\u6807\u6240\u6709\u8005\u660e\u786e\u7684\u6d4b\u8bd5\u8bb8\u53ef\u3002<\/li>\n\n\n\n<li>\u8303\u56f4\u9650\u5b9a\uff1a\u5728\u6388\u6743\u8303\u56f4\u5185\u64cd\u4f5c\uff0c\u4e0d\u5f97\u8d8a\u754c\u3002<\/li>\n\n\n\n<li>\u6570\u636e\u4fdd\u62a4\uff1a\u5bf9\u6536\u96c6\u5230\u7684\u6570\u636e\u4fdd\u5bc6\uff0c\u4e0d\u6cc4\u9732\u654f\u611f\u4fe1\u606f\u3002<\/li>\n<\/ul>\n\n\n\n<p>\u6b64\u5916\uff0c\u8fd8\u9700\u8003\u8651\u6307\u7eb9\u8bc6\u522b\u672c\u8eab\u7684\u8bef\u5224\u98ce\u9669\uff0c\u907f\u514d\u5c06\u8bef\u5224\u7ed3\u679c\u4f5c\u4e3a\u6700\u7ec8\u7ed3\u8bba\uff0c\u9020\u6210\u540e\u7eed\u51b3\u7b56\u5931\u8bef\u3002<\/p>\n\n\n\n<p><strong>\u56fe6-1\uff1a\u63a2\u67e5\u8fb9\u754c\u4e0e\u98ce\u9669\u63a7\u5236\u6d41\u7a0b<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/03\/\u63a2\u67e5\u8fb9\u754c\u4e0e\u98ce\u9669\u63a7\u5236\u6d41\u7a0b-526x1024.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"526\" height=\"1024\" data-original=\"http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/03\/\u63a2\u67e5\u8fb9\u754c\u4e0e\u98ce\u9669\u63a7\u5236\u6d41\u7a0b-526x1024.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1767\"  sizes=\"auto, (max-width: 526px) 100vw, 526px\" \/><\/div><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">6.3 \u5728\u7cfb\u7edf\u4e2d\u7684\u4f4d\u7f6e<\/h3>\n\n\n\n<p>\u672c\u6a21\u5757\u4f4d\u4e8e\u4fe1\u606f\u91c7\u96c6\u6d41\u7a0b\u4e4b\u524d\uff0c\u662f\u4efb\u4f55\u5b9e\u9645\u63a2\u67e5\u6d3b\u52a8\u7684\u524d\u7f6e\u6761\u4ef6\u3002\u5b83\u786e\u4fdd\u524d\u5e8f\u6240\u6709\u6a21\u5757\u7684\u7406\u8bba\u548c\u65b9\u6cd5\u80fd\u5728\u5408\u6cd5\u3001\u5b89\u5168\u7684\u524d\u63d0\u4e0b\u5e94\u7528\u4e8e\u771f\u5b9e\u76ee\u6807\u3002\u540c\u65f6\uff0c\u5b83\u4e5f\u8d2f\u7a7f\u6574\u4e2a\u63a2\u67e5\u8fc7\u7a0b\uff0c\u9700\u52a8\u6001\u8c03\u6574\u63a7\u5236\u7b56\u7565\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">6.4 \u53ef\u6267\u884c\u547d\u4ee4\u6216\u67e5\u8be2\u65b9\u5f0f<\/h3>\n\n\n\n<p>\u5c55\u793a\u5982\u4f55\u5728\u4e3b\u52a8\u626b\u63cf\u4e2d\u5e94\u7528\u901f\u7387\u63a7\u5236\u548c\u8303\u56f4\u9650\u5b9a\uff08\u4ee5 nmap \u548c httpx \u4e3a\u4f8b\uff09\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># nmap \u901f\u7387\u63a7\u5236\uff1a--max-rate 10 \u8868\u793a\u6bcf\u79d2\u6700\u591a\u53d1\u900110\u4e2a\u5305\nnmap -p 80,443 --max-rate 10 scanme.nmap.org\n\n# nmap \u4ec5\u626b\u63cf\u6307\u5b9aIP\uff0c\u907f\u514d\u8d85\u51fa\u8303\u56f4\nnmap -iL target.txt --excludefile exclude.txt\n\n# httpx \u5e76\u53d1\u63a7\u5236\uff1a-t 10 \u8868\u793a10\u4e2a\u5e76\u53d1\u7ebf\u7a0b\necho \"http:\/\/example.com\" | httpx -t 10 -path \/ -status-code\n\n# \u4f7f\u7528--delay\u63a7\u5236\u8bf7\u6c42\u95f4\u9694\uff08nmap\u53ef\u7528\uff0chttpx\u4e0d\u652f\u6301\uff0c\u53ef\u7528ffuf\u4ee3\u66ff\uff09\nffuf -u http:\/\/example.com\/FUZZ -w wordlist.txt -p 0.5  # \u5ef6\u8fdf0.5\u79d2<\/code><\/pre>\n\n\n\n<p>\u3010\u8865\u5145\u8bf4\u660e\uff1anmap \u7684 <code>--max-rate<\/code> \u63a7\u5236\u6700\u5927\u53d1\u5305\u901f\u7387\uff0c<code>--scan-delay<\/code> \u53ef\u63a7\u5236\u8bf7\u6c42\u95f4\u9694\u3002ffuf \u7684 <code>-p<\/code> \u53c2\u6570\u7528\u4e8e\u8bbe\u7f6e\u8bf7\u6c42\u5ef6\u8fdf\u3002\u4f9d\u636e\uff1aNmap Reference Guide\uff1bffuf GitHub Repository\u3002\u3011<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">6.5 \u5de5\u5177\u5bf9\u6bd4\u8868<\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u63a7\u5236\u9879<\/th><th>\u5de5\u5177\/\u65b9\u6cd5<\/th><th>\u4f18\u70b9<\/th><th>\u5c40\u9650<\/th><\/tr><\/thead><tbody><tr><td>\u901f\u7387\u9650\u5236<\/td><td>nmap &#8211;max-rate, &#8211;min-rate<\/td><td>\u7cbe\u7ec6\u63a7\u5236\u53d1\u5305\u901f\u7387<\/td><td>\u5bf9\u67d0\u4e9b\u626b\u63cf\u6a21\u5f0f\u53ef\u80fd\u4e0d\u9002\u7528<\/td><\/tr><tr><td>\u5e76\u53d1\u63a7\u5236<\/td><td>httpx -t, ffuf -t<\/td><td>\u63a7\u5236\u5e76\u53d1\u6570\uff0c\u51cf\u8f7b\u76ee\u6807\u538b\u529b<\/td><td>\u5e76\u53d1\u4e0d\u7b49\u4e8e\u901f\u7387\uff0c\u4ecd\u9700\u7ed3\u5408\u5ef6\u8fdf<\/td><\/tr><tr><td>\u8bf7\u6c42\u95f4\u9694<\/td><td>ffuf -p, nmap &#8211;scan-delay<\/td><td>\u7cbe\u786e\u63a7\u5236\u6bcf\u4e2a\u8bf7\u6c42\u95f4\u9694<\/td><td>\u964d\u4f4e\u626b\u63cf\u901f\u5ea6<\/td><\/tr><tr><td>\u8303\u56f4\u9650\u5b9a<\/td><td>nmap -iL, &#8211;exclude<\/td><td>\u660e\u786e\u6307\u5b9a\u76ee\u6807\uff0c\u907f\u514d\u8d8a\u754c<\/td><td>\u9700\u9884\u5148\u51c6\u5907\u5217\u8868<\/td><\/tr><tr><td>\u6388\u6743\u8bb0\u5f55<\/td><td>\u65e0\u547d\u4ee4\uff0c\u9760\u6587\u6863<\/td><td>\u6cd5\u5f8b\u4f9d\u636e<\/td><td>\u9700\u4eba\u5de5\u7ef4\u62a4<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">6.6 \u6807\u51c6\u64cd\u4f5c\u6b65\u9aa4<\/h3>\n\n\n\n<p>\u6309\u7167\u56fe6-1\u7684\u98ce\u9669\u63a7\u5236\u6d41\u7a0b\uff0c\u5404\u6b65\u9aa4\u5177\u4f53\u64cd\u4f5c\u5982\u4e0b\uff1a<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u83b7\u53d6\u660e\u786e\u6388\u6743<\/strong>\uff1a<\/li>\n<\/ol>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u4e0e\u76ee\u6807\u6240\u6709\u8005\u7b7e\u8ba2\u6d4b\u8bd5\u5408\u540c\u6216\u83b7\u5f97\u4e66\u9762\u8bb8\u53ef\uff0c\u660e\u786e\u6d4b\u8bd5\u8303\u56f4\u3001\u65f6\u95f4\u3001\u65b9\u6cd5\u3002<\/li>\n\n\n\n<li>\u5bf9\u4e8e\u516c\u5171\u6d4b\u8bd5\u76ee\u6807\uff0c\u786e\u8ba4\u5176\u4f7f\u7528\u6761\u6b3e\u5141\u8bb8\u4e3b\u52a8\u626b\u63cf\u3002<\/li>\n<\/ul>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u5b9a\u4e49\u6d4b\u8bd5\u8303\u56f4<\/strong>\uff1a<\/li>\n<\/ol>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u786e\u5b9a\u5141\u8bb8\u6d4b\u8bd5\u7684 IP \u6bb5\u3001\u57df\u540d\u5217\u8868\u3002<\/li>\n\n\n\n<li>\u5217\u51fa\u7981\u6b62\u6d4b\u8bd5\u7684\u8d44\u4ea7\uff08\u5982\u751f\u4ea7\u6570\u636e\u5e93\u3001\u654f\u611f\u63a5\u53e3\uff09\u3002<\/li>\n<\/ul>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u9009\u62e9\u63a7\u5236\u7b56\u7565<\/strong>\uff1a<\/li>\n<\/ol>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u6839\u636e\u76ee\u6807\u7684\u91cd\u8981\u6027\u548c\u7f51\u7edc\u73af\u5883\uff0c\u8bbe\u5b9a\u5408\u7406\u7684\u8bf7\u6c42\u901f\u7387\uff08\u5982\u6bcf\u79d2 10-50 \u4e2a\u5305\uff09\u3002<\/li>\n\n\n\n<li>\u51b3\u5b9a\u4f7f\u7528\u4ee3\u7406\u8f6e\u6362\u6216\u56fa\u5b9a IP\uff08\u901a\u5e38\u56fa\u5b9a IP \u66f4\u6613\u83b7\u5f97\u6388\u6743\uff09\u3002<\/li>\n<\/ul>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u6267\u884c\u521d\u6b65\u63a2\u67e5<\/strong>\uff1a<\/li>\n<\/ol>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u5148\u4f7f\u7528\u4f4e\u901f\u7387\u3001\u975e\u4fb5\u5165\u5f0f\u65b9\u6cd5\uff08\u5982 ping\u3001traceroute\uff09\u786e\u8ba4\u7f51\u7edc\u8fde\u901a\u6027\u3002<\/li>\n\n\n\n<li>\u518d\u9010\u6b65\u589e\u52a0\u63a2\u67e5\u6df1\u5ea6\uff0c\u5e76\u6301\u7eed\u76d1\u63a7\u76ee\u6807\u54cd\u5e94\u72b6\u6001\u3002<\/li>\n<\/ul>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u76d1\u63a7\u4e0e\u8c03\u6574<\/strong>\uff1a<\/li>\n<\/ol>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u5728\u626b\u63cf\u8fc7\u7a0b\u4e2d\u89c2\u5bdf\u76ee\u6807\u662f\u5426\u51fa\u73b0\u5f02\u5e38\uff08\u54cd\u5e94\u53d8\u6162\u3001\u8fd4\u56de\u9519\u8bef\uff09\uff0c\u5982\u6709\u5219\u7acb\u5373\u964d\u4f4e\u901f\u7387\u6216\u6682\u505c\u3002<\/li>\n\n\n\n<li>\u8bb0\u5f55\u6240\u6709\u8bf7\u6c42\u65e5\u5fd7\uff0c\u4fbf\u4e8e\u4e8b\u540e\u5ba1\u8ba1\u3002<\/li>\n<\/ul>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u8bef\u5224\u98ce\u9669\u63a7\u5236<\/strong>\uff1a<\/li>\n<\/ol>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u5bf9\u8bc6\u522b\u51fa\u7684\u6280\u672f\u7ec4\u4ef6\uff0c\u4f7f\u7528\u591a\u4e2a\u5de5\u5177\u6216\u65b9\u6cd5\u4ea4\u53c9\u9a8c\u8bc1\u3002<\/li>\n\n\n\n<li>\u5bf9\u4e8e\u4e0d\u786e\u5b9a\u6027\u9ad8\u7684\u7ed3\u679c\uff0c\u6807\u8bb0\u4e3a\u201c\u9700\u4eba\u5de5\u786e\u8ba4\u201d\u3002<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">6.7 \u5982\u4f55\u9a8c\u8bc1\u7ed3\u679c\u771f\u5b9e\u6027<\/h3>\n\n\n\n<p><strong>\u9a8c\u8bc1\u903b\u8f91<\/strong>\uff1a\u98ce\u9669\u63a7\u5236\u7684\u6709\u6548\u6027\u53ef\u901a\u8fc7\u4ee5\u4e0b\u65b9\u5f0f\u9a8c\u8bc1\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u901f\u7387\u63a7\u5236\u662f\u5426\u751f\u6548\uff1a\u68c0\u67e5\u626b\u63cf\u65e5\u5fd7\uff0c\u786e\u8ba4\u8bf7\u6c42\u95f4\u9694\u662f\u5426\u7b26\u5408\u8bbe\u5b9a\u503c\u3002<\/li>\n\n\n\n<li>\u662f\u5426\u8d8a\u754c\uff1a\u5bf9\u6bd4\u626b\u63cf\u76ee\u6807\u5217\u8868\u4e0e\u6388\u6743\u8303\u56f4\uff0c\u786e\u8ba4\u65e0\u8d85\u51fa\u3002<\/li>\n\n\n\n<li>\u5bf9\u76ee\u6807\u5f71\u54cd\uff1a\u626b\u63cf\u524d\u540e\u5bf9\u6bd4\u76ee\u6807\u670d\u52a1\u7684\u54cd\u5e94\u65f6\u95f4\u3001\u53ef\u7528\u6027\uff0c\u65e0\u660e\u663e\u53d8\u5316\u5219\u63a7\u5236\u6709\u6548\u3002<br><strong>\u5224\u65ad\u4f9d\u636e<\/strong>\uff1a\u82e5\u626b\u63cf\u8fc7\u7a0b\u4e2d\u672a\u89e6\u53d1\u76ee\u6807\u8b66\u62a5\uff08\u5982 WAF \u62e6\u622a\uff09\u3001\u672a\u5bfc\u81f4\u670d\u52a1\u4e0d\u53ef\u7528\uff0c\u4e14\u6240\u6709\u64cd\u4f5c\u5747\u5728\u6388\u6743\u8303\u56f4\u5185\uff0c\u5219\u98ce\u9669\u63a7\u5236\u6210\u529f\u3002<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">6.8 \u5e38\u89c1\u9519\u8bef\u4e0e\u6392\u67e5\u65b9\u5f0f<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u9519\u8bef1<\/strong>\uff1a\u8ba4\u4e3a\u83b7\u5f97\u6388\u6743\u540e\u5c31\u65e0\u9700\u901f\u7387\u63a7\u5236\u3002\u5373\u4f7f\u6388\u6743\uff0c\u8fc7\u5ea6\u626b\u63cf\u4ecd\u53ef\u80fd\u5bfc\u81f4\u670d\u52a1\u5f02\u5e38\uff0c\u635f\u5bb3\u4fe1\u4efb\u3002<\/li>\n\n\n\n<li><strong>\u6392\u67e5<\/strong>\uff1a\u59cb\u7ec8\u8bbe\u5b9a\u5408\u7406\u901f\u7387\uff0c\u5e76\u51c6\u5907\u5e94\u6025\u8054\u7cfb\u65b9\u5f0f\uff0c\u4ee5\u4fbf\u51fa\u73b0\u95ee\u9898\u65f6\u7acb\u5373\u505c\u6b62\u3002<\/li>\n\n\n\n<li><strong>\u9519\u8bef2<\/strong>\uff1a\u5ffd\u7565\u7b2c\u4e09\u65b9\u670d\u52a1\u7684\u5f71\u54cd\u3002\u4f8b\u5982\uff0c\u4f7f\u7528\u4e86 CDN \u7684\u76ee\u6807\uff0c\u626b\u63cf CDN \u8282\u70b9\u4e0d\u4f1a\u5f71\u54cd\u6e90\u7ad9\uff0c\u4f46\u53ef\u80fd\u89e6\u53d1 CDN \u7684 DDoS \u9632\u62a4\u3002<\/li>\n\n\n\n<li><strong>\u6392\u67e5<\/strong>\uff1a\u4e86\u89e3\u76ee\u6807\u67b6\u6784\uff0c\u9488\u5bf9\u6e90\u7ad9 IP \u8fdb\u884c\u626b\u63cf\uff1b\u6216\u4e8b\u5148\u901a\u77e5 CDN \u670d\u52a1\u5546\uff08\u5982\u6709\u53ef\u80fd\uff09\u3002<\/li>\n\n\n\n<li><strong>\u9519\u8bef3<\/strong>\uff1a\u8bef\u5224\u98ce\u9669\u53ea\u5173\u6ce8\u6280\u672f\u5c42\u9762\uff0c\u5ffd\u7565\u6cd5\u5f8b\u5c42\u9762\u3002\u4f8b\u5982\uff0c\u6536\u96c6\u5230\u7684\u6570\u636e\u53ef\u80fd\u5305\u542b\u4e2a\u4eba\u9690\u79c1\uff0c\u5b58\u50a8\u4e0d\u5f53\u4f1a\u8fdd\u89c4\u3002<\/li>\n\n\n\n<li><strong>\u6392\u67e5<\/strong>\uff1a\u5bf9\u6536\u96c6\u7684\u6570\u636e\u8fdb\u884c\u8131\u654f\u5904\u7406\uff0c\u5e76\u9075\u5b88\u6570\u636e\u4fdd\u62a4\u6cd5\u89c4\u3002<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">6.9 \u5408\u89c4\u8fb9\u754c\u8bf4\u660e<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u4f7f\u7528\u573a\u666f<\/strong>\uff1a\u4efb\u4f55\u5bf9\u975e\u516c\u5f00\u7cfb\u7edf\u7684\u4e3b\u52a8\u63a2\u67e5\u90fd\u5fc5\u987b\u4e8b\u5148\u83b7\u5f97\u6388\u6743\u3002\u672c\u6a21\u5757\u5f3a\u8c03\u7684\u8fb9\u754c\u63a7\u5236\u4ec5\u9002\u7528\u4e8e\u6388\u6743\u6d4b\u8bd5\u3002<\/li>\n\n\n\n<li><strong>\u7f51\u7edc\u5b89\u5168\u89c6\u89d2<\/strong>\uff1a\u5373\u4f7f\u6709\u6388\u6743\uff0c\u4e5f\u53ef\u80fd\u56e0\u64cd\u4f5c\u5931\u8bef\u5bfc\u81f4\u8d8a\u754c\u8bbf\u95ee\u3002\u4f8b\u5982\uff0c\u89e3\u6790\u51fa\u7684\u5b50\u57df\u540d\u6307\u5411\u672a\u6388\u6743 IP\u3002\u6388\u6743\u672c\u8eab\u4e0d\u80fd\u5b8c\u5168\u514d\u9664\u8d23\u4efb\uff0c\u4ecd\u9700\u9075\u5faa\u884c\u4e1a\u6700\u4f73\u5b9e\u8df5\u3002<\/li>\n\n\n\n<li><strong>\u7f13\u89e3\u63aa\u65bd<\/strong>\uff1a\u5728\u6d4b\u8bd5\u8ba1\u5212\u4e2d\u660e\u786e\u201c\u82e5\u53d1\u73b0\u8d85\u51fa\u8303\u56f4\u7684\u8d44\u4ea7\uff0c\u7acb\u5373\u505c\u6b62\u5e76\u62a5\u544a\u201d\u3002<\/li>\n\n\n\n<li><strong>\u672c\u6a21\u5757\u51b3\u7b56\u6307\u5357<\/strong>\uff1a<\/li>\n\n\n\n<li><strong>\u9002\u7528\u573a\u666f<\/strong>\uff1a\u6240\u6709\u6d89\u53ca\u4e3b\u52a8\u63a2\u67e5\u7684\u6d3b\u52a8\u5f00\u59cb\u524d\uff0c\u5fc5\u987b\u8fdb\u884c\u8fb9\u754c\u4e0e\u98ce\u9669\u63a7\u5236\u8bbe\u8ba1\u3002<\/li>\n\n\n\n<li><strong>\u66ff\u4ee3\u65b9\u6848<\/strong>\uff1a\u82e5\u4ec5\u4f7f\u7528\u88ab\u52a8\u6536\u96c6\u4e14\u4e0d\u6d89\u53ca\u4efb\u4f55\u4e3b\u52a8\u8bf7\u6c42\uff0c\u98ce\u9669\u8f83\u5c0f\uff0c\u4f46\u4ecd\u9700\u6ce8\u610f\u6570\u636e\u5408\u89c4\u3002<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">6.10 \u672c\u6a21\u5757\u9636\u6bb5\u6027\u5c0f\u7ed3<\/h3>\n\n\n\n<p>\u63a2\u67e5\u8fb9\u754c\u4e0e\u98ce\u9669\u63a7\u5236\u662f\u4e13\u4e1a\u5b89\u5168\u5de5\u7a0b\u5e08\u7684\u5fc5\u5907\u7d20\u517b\u3002\u5b83\u4e0d\u4ec5\u4fdd\u62a4\u76ee\u6807\u7cfb\u7edf\u514d\u53d7\u610f\u5916\u635f\u5bb3\uff0c\u4e5f\u4fdd\u62a4\u6d4b\u8bd5\u8005\u81ea\u8eab\u514d\u53d7\u6cd5\u5f8b\u98ce\u9669\u3002\u5728\u660e\u786e\u98ce\u9669\u63a7\u5236\u63aa\u65bd\u540e\uff0c\u53ef\u5b89\u5168\u8fdb\u5165\u7efc\u5408\u5b9e\u8df5\u73af\u8282\uff0c\u5c06\u524d\u5e8f\u6240\u6709\u77e5\u8bc6\u548c\u6d41\u7a0b\u6574\u5408\u8d77\u6765\uff0c\u5bf9\u4e00\u4e2a\u6388\u6743\u76ee\u6807\u8fdb\u884c\u5b8c\u6574\u7684\u6280\u672f\u6808\u8fd8\u539f\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u4e03\u3001\u6280\u672f\u6808\u8fd8\u539f\u7efc\u5408\u5b9e\u8df5<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">7.1 \u6a21\u5757\u6982\u5ff5\u89e3\u91ca<\/h3>\n\n\n\n<p>\u6280\u672f\u6808\u8fd8\u539f\u7efc\u5408\u5b9e\u8df5\uff0c\u662f\u6307\u5c06\u524d\u516d\u4e2a\u6a21\u5757\u7684\u7406\u8bba\u3001\u65b9\u6cd5\u548c\u6d41\u7a0b\u7efc\u5408\u8fd0\u7528\uff0c\u5bf9\u4e00\u4e2a\u771f\u5b9e\u7684\u6388\u6743\u6d4b\u8bd5\u76ee\u6807\u8fdb\u884c\u7aef\u5230\u7aef\u7684\u6280\u672f\u6808\u9006\u5411\u8fd8\u539f\uff0c\u5e76\u8f93\u51fa\u5b8c\u6574\u7684\u5206\u6790\u62a5\u544a\u3002\u5176\u89e3\u51b3\u201c\u5982\u4f55\u5c06\u788e\u7247\u5316\u7684\u77e5\u8bc6\u6574\u5408\u6210\u5b8c\u6574\u7684\u5b9e\u6218\u80fd\u529b\u201d\u7684\u95ee\u9898\u3002\u901a\u8fc7\u672c\u6a21\u5757\u6f14\u7ec3\uff0c\u5de5\u7a0b\u5e08\u80fd\u719f\u7ec3\u638c\u63e1\u4ece\u4fe1\u606f\u6536\u96c6\u5230\u6280\u672f\u8bc6\u522b\u7684\u5168\u8fc7\u7a0b\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">7.2 \u6280\u672f\u539f\u7406\u8bf4\u660e<\/h3>\n\n\n\n<p>\u6280\u672f\u6808\u8fd8\u539f\u7684\u6838\u5fc3\u539f\u7406\u662f\u201c\u591a\u6e90\u4fe1\u606f\u878d\u5408\u201d\u3002\u5355\u4e00\u6765\u6e90\u4fe1\u606f\u53ef\u80fd\u5b58\u5728\u8bef\u5dee\u6216\u7f3a\u5931\uff0c\u901a\u8fc7\u7ed3\u5408\u7aef\u53e3\u626b\u63cf\u3001HTTP \u54cd\u5e94\u5206\u6790\u3001TLS \u8bc1\u4e66\u3001DNS \u8bb0\u5f55\u3001\u88ab\u52a8\u6570\u636e\u7b49\u591a\u79cd\u6570\u636e\u6e90\uff0c\u5e76\u5bf9\u540c\u4e00\u7ec4\u4ef6\u8fdb\u884c\u591a\u91cd\u9a8c\u8bc1\uff0c\u53ef\u6700\u5927\u7a0b\u5ea6\u8fd8\u539f\u771f\u5b9e\u60c5\u51b5\u3002\u4f8b\u5982\uff0c\u8981\u786e\u5b9a\u540e\u7aef\u8bed\u8a00\u662f Python\uff0c\u53ef\u4ece\u4ee5\u4e0b\u8bc1\u636e\u4e2d\u7efc\u5408\u5224\u65ad\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u54cd\u5e94\u5934 <code>X-Powered-By: Python\/3.8<\/code><\/li>\n\n\n\n<li>URL \u8def\u7531\u98ce\u683c\u4e3a <code>\/api\/v1\/resource<\/code>\uff08\u5e38\u89c1 RESTful \u6846\u67b6\uff09<\/li>\n\n\n\n<li>\u9519\u8bef\u9875\u9762\u5305\u542b <code>Django<\/code> \u8c03\u8bd5\u4fe1\u606f<\/li>\n\n\n\n<li>Cookie \u5305\u542b <code>csrftoken<\/code><\/li>\n\n\n\n<li>\u67d0\u4e2a\u7279\u5b9a\u8def\u5f84\u8fd4\u56de 404 \u65f6\uff0c\u9875\u9762\u5305\u542b <code>&lt;title&gt;Page not found (404)&lt;\/title&gt;<\/code>\uff08Django \u9ed8\u8ba4\u6a21\u677f\uff09<\/li>\n\n\n\n<li>\u88ab\u52a8\u6536\u96c6\u4e2d\u53d1\u73b0\u9879\u76ee\u4f7f\u7528 <code>pip<\/code> \u7684\u4f9d\u8d56\u6587\u4ef6\u6cc4\u9732<\/li>\n<\/ul>\n\n\n\n<p>\u7efc\u5408\u5b9e\u8df5\u5c31\u662f\u8fd0\u7528\u8fd9\u4e9b\u7ebf\u7d22\uff0c\u901a\u8fc7\u903b\u8f91\u63a8\u7406\u548c\u5de5\u5177\u8f85\u52a9\uff0c\u5f62\u6210\u9ad8\u7f6e\u4fe1\u5ea6\u7684\u7ed3\u8bba\u3002<\/p>\n\n\n\n<p><strong>\u56fe7-1\uff1a\u6280\u672f\u6808\u8fd8\u539f\u7efc\u5408\u5b9e\u8df5\u6d41\u7a0b\u56fe<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/03\/\u6280\u672f\u6808\u8fd8\u539f\u7efc\u5408\u5b9e\u8df5\u6d41\u7a0b\u56fe-392x1024.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"392\" height=\"1024\" data-original=\"http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/03\/\u6280\u672f\u6808\u8fd8\u539f\u7efc\u5408\u5b9e\u8df5\u6d41\u7a0b\u56fe-392x1024.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1768\"  sizes=\"auto, (max-width: 392px) 100vw, 392px\" \/><\/div><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">7.3 \u5728\u7cfb\u7edf\u4e2d\u7684\u4f4d\u7f6e<\/h3>\n\n\n\n<p>\u672c\u6a21\u5757\u662f\u6574\u4e2a\u8bfe\u7a0b\u4f53\u7cfb\u7684\u7ec8\u70b9\uff0c\u5c06\u6240\u6709\u524d\u7f6e\u6a21\u5757\u4e32\u8054\u8d77\u6765\u3002\u5b83\u65e2\u662f\u77e5\u8bc6\u68c0\u9a8c\uff0c\u4e5f\u662f\u6280\u80fd\u8bad\u7ec3\u3002\u901a\u8fc7\u672c\u6a21\u5757\uff0c\u5de5\u7a0b\u5e08\u5c06\u5efa\u7acb\u8d77\u5b8c\u6574\u7684\u5de5\u7a0b\u5316\u601d\u7ef4\uff0c\u4e3a\u540e\u7eed\u6e17\u900f\u6d4b\u8bd5\u3001\u5b89\u5168\u5f00\u53d1\u6216\u8fd0\u7ef4\u5de5\u4f5c\u6253\u4e0b\u575a\u5b9e\u57fa\u7840\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">7.4 \u53ef\u6267\u884c\u547d\u4ee4\u6216\u67e5\u8be2\u65b9\u5f0f<\/h3>\n\n\n\n<p>\u4ee5\u6388\u6743\u6d4b\u8bd5\u76ee\u6807 <code>scanme.nmap.org<\/code> \u4e3a\u4f8b\uff0c\u6f14\u793a\u7efc\u5408\u5b9e\u8df5\u4e2d\u7684\u5173\u952e\u547d\u4ee4\uff08\u6ce8\u610f\uff1a\u5b9e\u9645\u4f7f\u7528\u65f6\u9700\u786e\u4fdd\u6388\u6743\uff09\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># 1. \u88ab\u52a8\u6536\u96c6\uff1a\u67e5\u8be2\u8bc1\u4e66\u65e5\u5fd7\ncurl -s \"https:\/\/crt.sh\/?q=%.scanme.nmap.org&amp;output=json\" | jq .\n\n# 2. DNS\u4fe1\u606f\ndig scanme.nmap.org ANY +short\n\n# 3. \u7aef\u53e3\u626b\u63cf\nnmap -p- --min-rate 1000 scanme.nmap.org\n\n# 4. \u670d\u52a1\u7248\u672c\u63a2\u6d4b\nnmap -sV -p 80,9929,31337 scanme.nmap.org\n\n# 5. Web\u6307\u7eb9\u8bc6\u522b\nwhatweb -a 3 http:\/\/scanme.nmap.org\n\n# 6. \u6df1\u5165HTTP\u5206\u6790\ncurl -I http:\/\/scanme.nmap.org\ncurl -s http:\/\/scanme.nmap.org | grep -i \"meta\\|script\"\n\n# 7. \u76ee\u5f55\u679a\u4e3e\uff08\u4f4e\u901f\u7387\uff09\nffuf -u http:\/\/scanme.nmap.org\/FUZZ -w \/usr\/share\/wordlists\/dirb\/common.txt -p 0.2 -t 5\n\n# 8. TLS\u8bc1\u4e66\u83b7\u53d6\uff08\u5982\u679c443\u5f00\u653e\uff09\nopenssl s_client -connect scanme.nmap.org:443 -servername scanme.nmap.org 2&gt;\/dev\/null | openssl x509 -text<\/code><\/pre>\n\n\n\n<p>\u3010\u8865\u5145\u8bf4\u660e\uff1a<code>nmap -p-<\/code> \u626b\u63cf\u6240\u6709\u7aef\u53e3\uff0c<code>--min-rate 1000<\/code> \u8bbe\u7f6e\u6700\u5c0f\u53d1\u5305\u901f\u7387\u3002ffuf \u7684 <code>-p<\/code> \u548c <code>-t<\/code> \u5206\u522b\u63a7\u5236\u5ef6\u8fdf\u548c\u5e76\u53d1\u3002\u6240\u6709\u547d\u4ee4\u5747\u5e94\u5728\u6388\u6743\u8303\u56f4\u5185\u4f7f\u7528\u3002\u4f9d\u636e\uff1aNmap Reference Guide\uff1bffuf GitHub Repository\uff1bcrt.sh \u5b98\u65b9\u7f51\u7ad9\u3002\u3011<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">7.5 \u5de5\u5177\u5bf9\u6bd4\u8868<\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u5de5\u5177<\/th><th>\u5e94\u7528\u9636\u6bb5<\/th><th>\u4f5c\u7528<\/th><th>\u4e0e\u5176\u4ed6\u5de5\u5177\u7684\u534f\u4f5c<\/th><\/tr><\/thead><tbody><tr><td>crt.sh<\/td><td>\u88ab\u52a8\u6536\u96c6<\/td><td>\u53d1\u73b0\u5b50\u57df\u540d<\/td><td>\u4e3a\u7aef\u53e3\u626b\u63cf\u63d0\u4f9b\u66f4\u591a\u76ee\u6807<\/td><\/tr><tr><td>dig\/nslookup<\/td><td>\u88ab\u52a8\u6536\u96c6<\/td><td>\u83b7\u53d6DNS\u8bb0\u5f55<\/td><td>\u786e\u8ba4\u57df\u540d\u89e3\u6790\uff0c\u8f85\u52a9\u5b50\u57df\u9a8c\u8bc1<\/td><\/tr><tr><td>nmap<\/td><td>\u4e3b\u52a8\u6536\u96c6<\/td><td>\u7aef\u53e3\u4e0e\u670d\u52a1\u63a2\u6d4b<\/td><td>\u8f93\u51fa\u5f00\u653e\u7aef\u53e3\uff0c\u4e3a\u540e\u7eedHTTP\u63a2\u6d4b\u63d0\u4f9b\u5165\u53e3<\/td><\/tr><tr><td>whatweb<\/td><td>\u4e3b\u52a8\u6536\u96c6<\/td><td>\u521d\u6b65Web\u6307\u7eb9<\/td><td>\u5feb\u901f\u83b7\u5f97\u6982\u89c8\uff0c\u6307\u5bfc\u6df1\u5165\u5206\u6790<\/td><\/tr><tr><td>ffuf<\/td><td>\u4e3b\u52a8\u6536\u96c6<\/td><td>\u76ee\u5f55\/\u6587\u4ef6\u679a\u4e3e<\/td><td>\u53d1\u73b0\u9690\u85cf\u8def\u5f84\uff0c\u53ef\u80fd\u66b4\u9732\u66f4\u591a\u7279\u5f81<\/td><\/tr><tr><td>curl<\/td><td>\u4e3b\u52a8\u6536\u96c6<\/td><td>\u624b\u52a8\u9a8c\u8bc1<\/td><td>\u83b7\u53d6\u539f\u59cb\u54cd\u5e94\uff0c\u7528\u4e8e\u89c4\u5219\u5339\u914d<\/td><\/tr><tr><td>openssl<\/td><td>\u4e3b\u52a8\u6536\u96c6<\/td><td>TLS\u8bc1\u4e66\u5206\u6790<\/td><td>\u83b7\u53d6\u670d\u52a1\u5668\u8bc1\u4e66\u7ec6\u8282<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">7.6 \u6807\u51c6\u64cd\u4f5c\u6b65\u9aa4<\/h3>\n\n\n\n<p>\u6309\u7167\u56fe7-1\u7684\u7efc\u5408\u5b9e\u8df5\u6d41\u7a0b\uff0c\u5404\u6b65\u9aa4\u5177\u4f53\u64cd\u4f5c\u5982\u4e0b\uff1a<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u51c6\u5907\u9636\u6bb5<\/strong>\uff1a<\/li>\n<\/ol>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u786e\u8ba4\u76ee\u6807 <code>scanme.nmap.org<\/code> \u7684\u6388\u6743\uff08\u67e5\u9605\u5176\u5b98\u7f51\uff0c\u5141\u8bb8\u626b\u63cf\uff09\u3002<\/li>\n\n\n\n<li>\u51c6\u5907\u6d4b\u8bd5\u673a\u73af\u5883\uff0c\u5b89\u88c5\u6240\u9700\u5de5\u5177\uff08nmap, whatweb, ffuf, curl, jq \u7b49\uff09\u3002<\/li>\n\n\n\n<li>\u521b\u5efa\u9879\u76ee\u76ee\u5f55\uff0c\u7528\u4e8e\u5b58\u50a8\u6240\u6709\u8f93\u51fa\u3002<\/li>\n<\/ul>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u88ab\u52a8\u4fe1\u606f\u6536\u96c6<\/strong>\uff1a<\/li>\n<\/ol>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u8fd0\u884c <code>curl -s \"https:\/\/crt.sh\/?q=%.scanme.nmap.org&amp;output=json\" | jq . &gt; crt.json<\/code>\u3002<\/li>\n\n\n\n<li>\u8fd0\u884c <code>dig scanme.nmap.org ANY +short &gt; dns.txt<\/code>\u3002<\/li>\n\n\n\n<li>\u5206\u6790\u8f93\u51fa\uff0c\u6ce8\u610f\u5b50\u57df\u540d\uff08\u5982 <code>www.scanme.nmap.org<\/code>\uff09\u3001CNAME\u3001TXT \u8bb0\u5f55\u7b49\u3002<\/li>\n<\/ul>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u4e3b\u52a8\u7f51\u7edc\u5c42\u63a2\u6d4b<\/strong>\uff1a<\/li>\n<\/ol>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u8fd0\u884c <code>nmap -p- --min-rate 1000 scanme.nmap.org -oN nmap_allports.txt<\/code>\u3002<\/li>\n\n\n\n<li>\u67e5\u770b\u7ed3\u679c\uff0c\u8bb0\u5f55\u5f00\u653e\u7aef\u53e3\uff1a22, 80, 9929, 31337 \u7b49\u3002<\/li>\n\n\n\n<li>\u5bf9\u5f00\u653e\u7aef\u53e3\u8fdb\u884c\u670d\u52a1\u7248\u672c\u63a2\u6d4b\uff1a<code>nmap -sV -p 22,80,9929,31337 scanme.nmap.org -oN nmap_versions.txt<\/code>\u3002<\/li>\n<\/ul>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Web\u5e94\u7528\u63a2\u6d4b<\/strong>\uff1a<\/li>\n<\/ol>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u5bf9 80 \u7aef\u53e3\u8fd0\u884c <code>whatweb -a 3 http:\/\/scanme.nmap.org &gt; whatweb.txt<\/code>\u3002<\/li>\n\n\n\n<li>\u624b\u52a8\u4f7f\u7528 <code>curl -I http:\/\/scanme.nmap.org<\/code> \u67e5\u770b\u54cd\u5e94\u5934\u3002<\/li>\n\n\n\n<li>\u4f7f\u7528 <code>curl -s http:\/\/scanme.nmap.org | grep -i \"meta\\|script\"<\/code> \u63d0\u53d6\u5173\u952e\u5185\u5bb9\u3002<\/li>\n\n\n\n<li>\u5bf9 443 \u7aef\u53e3\uff08\u82e5\u5f00\u653e\uff09\u6267\u884c TLS \u5206\u6790\uff1a<code>openssl s_client -connect scanme.nmap.org:443 -servername scanme.nmap.org 2&gt;\/dev\/null | openssl x509 -text &gt; cert.txt<\/code>\u3002<\/li>\n<\/ul>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u76ee\u5f55\u679a\u4e3e<\/strong>\uff1a<\/li>\n<\/ol>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u4f7f\u7528 ffuf \u5bf9 80 \u7aef\u53e3\u8fdb\u884c\u4f4e\u901f\u7387\u76ee\u5f55\u679a\u4e3e\uff1a<code>ffuf -u http:\/\/scanme.nmap.org\/FUZZ -w \/usr\/share\/wordlists\/dirb\/common.txt -p 0.2 -t 5 -o ffuf.json<\/code>\u3002<\/li>\n\n\n\n<li>\u5206\u6790\u7ed3\u679c\uff0c\u6ce8\u610f\u72b6\u6001\u7801 200\u3001403\u3001301 \u7684\u8def\u5f84\uff0c\u5e76\u624b\u52a8\u8bbf\u95ee\u9a8c\u8bc1\u3002<\/li>\n<\/ul>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u6570\u636e\u6574\u7406\u4e0e\u5206\u6790<\/strong>\uff1a<\/li>\n<\/ol>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u5c06\u5404\u5de5\u5177\u8f93\u51fa\u6c47\u603b\u5230\u4e00\u5f20\u8868\u683c\u4e2d\uff0c\u6309\u5c42\u6b21\u5f52\u7c7b\u3002<\/li>\n\n\n\n<li>\u5e94\u7528\u7ec4\u4ef6\u8bc6\u522b\u65b9\u6cd5\uff0c\u5bf9\u6bcf\u4e2a\u5c42\u6b21\u8fdb\u884c\u6280\u672f\u63a8\u65ad\u3002\n<ul class=\"wp-block-list\">\n<li>\u524d\u7aef\uff1a\u67e5\u770b whatweb \u662f\u5426\u8bc6\u522b\u51fa\u524d\u7aef\u5e93\u3002<\/li>\n\n\n\n<li>\u540e\u7aef\uff1a\u4ece\u54cd\u5e94\u5934\u3001\u9519\u8bef\u9875\u9762\u63a8\u65ad\uff08\u53ef\u80fd\u4e3a Apache \u9ed8\u8ba4\u9875\u9762\uff09\u3002<\/li>\n\n\n\n<li>\u64cd\u4f5c\u7cfb\u7edf\uff1a\u4ece TTL\uff08ping \u5f97\u5230 64\uff09\u63a8\u65ad Linux\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>\u4ea4\u53c9\u9a8c\u8bc1\uff1a\u4f8b\u5982\uff0cnmap \u62a5\u544a Apache \u7248\u672c\uff0cwhatweb \u62a5\u544a Apache\uff0c\u54cd\u5e94\u5934\u4e5f\u663e\u793a Apache\uff0c\u5219\u4e00\u81f4\u3002<\/li>\n<\/ul>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u751f\u6210\u62a5\u544a<\/strong>\uff1a<\/li>\n<\/ol>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u7f16\u5199\u62a5\u544a\uff0c\u5305\u542b\uff1a\u76ee\u6807\u4fe1\u606f\u3001\u91c7\u96c6\u65b9\u6cd5\u3001\u5404\u5c42\u6b21\u8bc6\u522b\u7ed3\u679c\u3001\u7f6e\u4fe1\u5ea6\u8bc4\u4f30\u3001\u8bc1\u636e\u622a\u56fe\/\u547d\u4ee4\u8f93\u51fa\u3002<\/li>\n\n\n\n<li>\u5bf9\u4e0d\u786e\u5b9a\u7684\u7ec4\u4ef6\u8fdb\u884c\u8bf4\u660e\uff0c\u5e76\u7ed9\u51fa\u5efa\u8bae\uff08\u5982\u9700\u8981\u5185\u90e8\u786e\u8ba4\uff09\u3002<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">7.7 \u5982\u4f55\u9a8c\u8bc1\u7ed3\u679c\u771f\u5b9e\u6027<\/h3>\n\n\n\n<p><strong>\u9a8c\u8bc1\u903b\u8f91<\/strong>\uff1a\u5bf9\u4e8e <code>scanme.nmap.org<\/code>\uff0c\u53ef\u67e5\u9605 Nmap \u5b98\u65b9\u6587\u6863\uff0c\u786e\u8ba4\u5176\u8fd0\u884c\u7684\u670d\u52a1\u3002\u5b9e\u9645\u4e0a\uff0c<code>scanme.nmap.org<\/code> \u8fd0\u884c Apache\u3001SSH \u53ca\u4e00\u4e9b\u6d4b\u8bd5\u670d\u52a1\u3002\u5c06\u5206\u6790\u7ed3\u679c\u4e0e\u516c\u5f00\u4fe1\u606f\u5bf9\u6bd4\uff0c\u82e5\u57fa\u672c\u4e00\u81f4\uff0c\u5219\u9a8c\u8bc1\u6210\u529f\u3002<br><strong>\u5224\u65ad\u4f9d\u636e<\/strong>\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u5404\u5de5\u5177\u8f93\u51fa\u4e00\u81f4\uff08\u5982\u90fd\u62a5\u544a Apache\/2.4.7\uff09\u3002<\/li>\n\n\n\n<li>\u4eba\u5de5\u68c0\u67e5\u54cd\u5e94\u5934\u3001\u9875\u9762\u5185\u5bb9\u4e0e Apache \u9ed8\u8ba4\u7279\u5f81\u76f8\u7b26\u3002<\/li>\n\n\n\n<li>\u6ca1\u6709\u51fa\u73b0\u76f8\u4e92\u77db\u76fe\u7684\u8bc1\u636e\u3002<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">7.8 \u5e38\u89c1\u9519\u8bef\u4e0e\u6392\u67e5\u65b9\u5f0f<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u9519\u8bef1<\/strong>\uff1a\u5ffd\u7565\u975e\u6807\u51c6\u7aef\u53e3\u4e0a\u7684\u670d\u52a1\u3002\u4f8b\u5982\uff0c\u7aef\u53e3 9929 \u53ef\u80fd\u8fd0\u884c nping echo \u670d\u52a1\uff0c\u4f46\u5e76\u975e Web \u670d\u52a1\u3002<\/li>\n\n\n\n<li><strong>\u6392\u67e5<\/strong>\uff1a\u5bf9\u6240\u6709\u7aef\u53e3\u8fdb\u884c\u534f\u8bae\u8bc6\u522b\uff0c\u4e0d\u5047\u8bbe 80\/443 \u662f\u552f\u4e00\u7684 Web \u7aef\u53e3\u3002<\/li>\n\n\n\n<li><strong>\u9519\u8bef2<\/strong>\uff1a\u8fc7\u5ea6\u4f9d\u8d56\u81ea\u52a8\u5316\u5de5\u5177\uff0c\u6f0f\u6389\u4eba\u5de5\u53d1\u73b0\u7684\u7ec6\u8282\u3002\u4f8b\u5982\uff0cffuf \u53ef\u80fd\u6ca1\u627e\u5230\u9690\u85cf\u76ee\u5f55\uff0c\u4f46\u624b\u52a8\u67e5\u770b robots.txt \u53d1\u73b0 <code>\/secret<\/code>\u3002<\/li>\n\n\n\n<li><strong>\u6392\u67e5<\/strong>\uff1a\u5728\u81ea\u52a8\u5316\u540e\uff0c\u52a1\u5fc5\u8fdb\u884c\u4eba\u5de5\u62bd\u67e5\uff0c\u7279\u522b\u662f\u5e38\u89c1\u654f\u611f\u8def\u5f84\u3002<\/li>\n\n\n\n<li><strong>\u9519\u8bef3<\/strong>\uff1a\u672a\u5bf9\u7ed3\u679c\u8fdb\u884c\u4ea4\u53c9\u9a8c\u8bc1\uff0c\u5bfc\u81f4\u8bef\u5224\u3002\u4f8b\u5982\uff0c\u82e5 CDN \u8fd4\u56de\u4e86\u9519\u8bef\u7684 <code>Server<\/code> \u5934\u3002<\/li>\n\n\n\n<li><strong>\u6392\u67e5<\/strong>\uff1a\u5c1d\u8bd5\u76f4\u63a5\u8fde\u63a5 IP\uff08\u82e5\u6388\u6743\u5141\u8bb8\uff09\uff0c\u6216\u4f7f\u7528\u5176\u4ed6\u65b9\u6cd5\uff08\u5982 HTTP\/2 \u6307\u7eb9\uff09\u8f85\u52a9\u5224\u65ad\u3002<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">7.9 \u5408\u89c4\u8fb9\u754c\u8bf4\u660e<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u4f7f\u7528\u573a\u666f<\/strong>\uff1a\u672c\u5b9e\u8df5\u5fc5\u987b\u57fa\u4e8e\u6388\u6743\u76ee\u6807\u8fdb\u884c\u3002<code>scanme.nmap.org<\/code> \u660e\u786e\u5141\u8bb8\u626b\u63cf\uff0c\u662f\u5408\u6cd5\u76ee\u6807\u3002<\/li>\n\n\n\n<li><strong>\u7f51\u7edc\u5b89\u5168\u89c6\u89d2<\/strong>\uff1a\u5373\u4f7f\u76ee\u6807\u5141\u8bb8\u626b\u63cf\uff0c\u5927\u89c4\u6a21\u76ee\u5f55\u679a\u4e3e\u4ecd\u53ef\u80fd\u88ab\u89c6\u4e3a\u653b\u51fb\uff0c\u5efa\u8bae\u63a7\u5236\u901f\u7387\u3002\u7efc\u5408\u5b9e\u8df5\u53ef\u80fd\u65e0\u6cd5 100% \u8fd8\u539f\u6240\u6709\u6280\u672f\u7ec6\u8282\uff0c\u5c24\u5176\u662f\u5185\u90e8\u7ec4\u4ef6\uff08\u5982\u6570\u636e\u5e93\u7c7b\u578b\uff09\u3002<\/li>\n\n\n\n<li><strong>\u7f13\u89e3\u63aa\u65bd<\/strong>\uff1a\u5728\u62a5\u544a\u4e2d\u660e\u786e\u6307\u51fa\u4e0d\u786e\u5b9a\u6027\uff0c\u5e76\u5efa\u8bae\u901a\u8fc7\u5185\u90e8\u6587\u6863\u6216\u6388\u6743\u6df1\u5ea6\u6d4b\u8bd5\u8fdb\u4e00\u6b65\u786e\u8ba4\u3002<\/li>\n\n\n\n<li><strong>\u672c\u6a21\u5757\u51b3\u7b56\u6307\u5357<\/strong>\uff1a<\/li>\n\n\n\n<li><strong>\u9002\u7528\u573a\u666f<\/strong>\uff1a\u9700\u8981\u5168\u9762\u4e86\u89e3\u76ee\u6807\u6280\u672f\u6808\u4ee5\u8fdb\u884c\u5b89\u5168\u8bc4\u4f30\u6216\u517c\u5bb9\u6027\u6d4b\u8bd5\u65f6\uff0c\u4e14\u5df2\u83b7\u6388\u6743\u3002<\/li>\n\n\n\n<li><strong>\u66ff\u4ee3\u65b9\u6848<\/strong>\uff1a\u82e5\u76ee\u6807\u5df2\u63d0\u4f9b\u8be6\u7ec6\u6280\u672f\u6587\u6863\uff0c\u5219\u65e0\u9700\u8fdb\u884c\u6b64\u7efc\u5408\u5b9e\u8df5\u3002<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">7.10 \u672c\u6a21\u5757\u9636\u6bb5\u6027\u5c0f\u7ed3<\/h3>\n\n\n\n<p>\u901a\u8fc7\u6280\u672f\u6808\u8fd8\u539f\u7efc\u5408\u5b9e\u8df5\uff0c\u5b8c\u6574\u6f14\u7ec3\u4e86\u4ece\u4fe1\u606f\u6536\u96c6\u5230\u6280\u672f\u8bc6\u522b\u7684\u5168\u8fc7\u7a0b\uff0c\u5c06\u524d\u516d\u4e2a\u6a21\u5757\u7684\u77e5\u8bc6\u878d\u4f1a\u8d2f\u901a\u3002\u5de5\u7a0b\u5e08\u4e0d\u4ec5\u5b66\u4f1a\u64cd\u4f5c\u5de5\u5177\uff0c\u66f4\u91cd\u8981\u7684\u662f\u638c\u63e1\u4e86\u7cfb\u7edf\u5316\u5206\u6790\u65b9\u6cd5\u548c\u98ce\u9669\u63a7\u5236\u610f\u8bc6\u3002\u8fd9\u79cd\u80fd\u529b\u662f\u4ece\u4e8b Web \u5b89\u5168\u3001\u8fd0\u7ef4\u5f00\u53d1\u3001\u67b6\u6784\u8bbe\u8ba1\u7b49\u5de5\u4f5c\u7684\u91cd\u8981\u57fa\u7840\u3002\u81f3\u6b64\uff0c\u6574\u4e2a\u201cWeb \u5e94\u7528\u67b6\u6784\u5206\u6790\u4e0e\u6307\u7eb9\u8bc6\u522b\u201d\u7684\u5de5\u7a0b\u5316\u6559\u5b66\u6a21\u5757\u7ed3\u675f\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u53c2\u8003\u4e0e\u8fdb\u4e00\u6b65\u9605\u8bfb<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>curl man page<\/strong>\uff1a\u672c\u6587\u4e2d\u6240\u6709 <code>curl<\/code> \u547d\u4ee4\u7684\u8bed\u6cd5\u548c\u53c2\u6570\u4f9d\u636e\u3002\u8be5\u624b\u518c\u8be6\u7ec6\u8bf4\u660e\u4e86 <code>-I<\/code>\u3001<code>-s<\/code>\u3001<code>-k<\/code> \u7b49\u9009\u9879\u7684\u7528\u6cd5\u3002<\/li>\n\n\n\n<li><strong>Nmap Reference Guide<\/strong>\uff1a\u672c\u6587\u4e2d <code>nmap<\/code> \u7aef\u53e3\u626b\u63cf\u3001\u670d\u52a1\u7248\u672c\u63a2\u6d4b\uff08<code>-sV<\/code>\uff09\u3001\u901f\u7387\u63a7\u5236\uff08<code>--min-rate<\/code>, <code>--max-rate<\/code>\uff09\u7b49\u6280\u672f\u7ec6\u8282\u7684\u6765\u6e90\u3002\u8be5\u6307\u5357\u7531 Nmap \u5b98\u65b9\u7ef4\u62a4\uff0c\u6db5\u76d6\u4e86\u6240\u6709\u626b\u63cf\u6280\u672f\u548c\u811a\u672c\u7528\u6cd5\u3002<\/li>\n\n\n\n<li><strong>OpenSSL Documentation<\/strong>\uff1a\u672c\u6587\u4e2d <code>openssl s_client<\/code> \u548c <code>x509<\/code> \u547d\u4ee4\u7528\u4e8e TLS \u8bc1\u4e66\u83b7\u53d6\u548c\u89e3\u6790\u7684\u4f9d\u636e\u3002OpenSSL \u5b98\u65b9\u6587\u6863\u63d0\u4f9b\u4e86\u6240\u6709\u5b50\u547d\u4ee4\u548c\u53c2\u6570\u7684\u5b8c\u6574\u8bf4\u660e\u3002<\/li>\n\n\n\n<li><strong>crt.sh Certificate Search<\/strong>\uff1a\u672c\u6587\u4e2d\u88ab\u52a8\u6536\u96c6\u8bc1\u4e66\u4fe1\u606f\u6240\u4f7f\u7528\u7684 <code>crt.sh<\/code> \u5728\u7ebf\u670d\u52a1\u3002\u8be5\u7f51\u7ad9\u63d0\u4f9b\u4e86\u901a\u8fc7\u57df\u540d\u3001\u6307\u7eb9\u7b49\u67e5\u8be2\u8bc1\u4e66\u900f\u660e\u65e5\u5fd7\u7684\u63a5\u53e3\u3002<\/li>\n\n\n\n<li><strong>ffuf &#8211; Fuzz Faster U Fool GitHub Repository<\/strong>\uff1a\u672c\u6587\u4e2d\u76ee\u5f55\u679a\u4e3e\u5de5\u5177 <code>ffuf<\/code> \u7684\u5b98\u65b9\u4ed3\u5e93\uff0c\u5305\u542b\u4e86 <code>-p<\/code>\uff08\u5ef6\u8fdf\uff09\u3001<code>-t<\/code>\uff08\u7ebf\u7a0b\uff09\u7b49\u53c2\u6570\u7684\u8be6\u7ec6\u8bf4\u660e\u548c\u4f7f\u7528\u793a\u4f8b\u3002<\/li>\n\n\n\n<li><strong>Wappalyzer GitHub Repository<\/strong>\uff1a\u672c\u6587\u5de5\u5177\u5bf9\u6bd4\u8868\u4e2d\u63d0\u5230\u7684 Wappalyzer \u6307\u7eb9\u8bc6\u522b\u5de5\u5177\u7684\u5f00\u6e90\u4ed3\u5e93\uff0c\u5305\u542b\u5176\u6307\u7eb9\u89c4\u5219\uff08<code>apps.json<\/code>\uff09\u7684\u5b9a\u4e49\u65b9\u5f0f\u3002<\/li>\n\n\n\n<li><strong>Whatweb GitHub Repository<\/strong>\uff1a\u672c\u6587\u4e2d\u4f7f\u7528\u7684 <code>whatweb<\/code> \u6307\u7eb9\u8bc6\u522b\u5de5\u5177\u7684\u5b98\u65b9\u4ed3\u5e93\uff0c\u63d0\u4f9b\u4e86\u63d2\u4ef6\u5f00\u53d1\u548c\u4f7f\u7528\u7684\u8be6\u7ec6\u6587\u6863\u3002<\/li>\n\n\n\n<li><strong>httpx GitHub Repository<\/strong>\uff1a\u672c\u6587\u4e2d\u7528\u4e8e HTTP \u63a2\u6d3b\u7684 <code>httpx<\/code> \u5de5\u5177\u7684\u5b98\u65b9\u4ed3\u5e93\uff0c\u8bf4\u660e\u4e86\u5176\u591a\u534f\u8bae\u652f\u6301\u548c\u5e76\u53d1\u63a7\u5236\u673a\u5236\u3002<\/li>\n\n\n\n<li><strong>IETF RFC 9110 &#8211; HTTP Semantics<\/strong>\uff1a\u672c\u6587 1.2 \u8282\u4e2d\u5173\u4e8e HTTP \u54cd\u5e94\u5934\u5b9a\u4e49\u548c\u884c\u4e3a\u7684\u6280\u672f\u539f\u7406\u4f9d\u636e\u3002\u8be5\u6587\u6863\u662f\u5f53\u524d HTTP\/1.1 \u548c HTTP\/2 \u7684\u8bed\u4e49\u6807\u51c6\u3002<\/li>\n\n\n\n<li><strong>IETF RFC 1035 &#8211; Domain Names<\/strong>\uff1a\u672c\u6587 DNS \u67e5\u8be2\u76f8\u5173\u547d\u4ee4\uff08<code>dig<\/code>, <code>nslookup<\/code>\uff09\u7684\u5e95\u5c42\u534f\u8bae\u6807\u51c6\uff0c\u63d0\u4f9b\u4e86\u57df\u540d\u7cfb\u7edf\u5b9e\u73b0\u7684\u6280\u672f\u80cc\u666f\u3002<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u4fe1\u606f\u6536\u96c6-Web\u5e94\u7528-\u67b6\u6784\u5206\u6790&amp;WAF&amp;\u871c\u7f50<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">\u8ba4\u77e5\u57fa\u7840\u91cd\u6784<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">\u6a21\u5757\u6982\u5ff5\u89e3\u91ca<\/h4>\n\n\n\n<p>\u4fe1\u606f\u6536\u96c6\u521d\u671f\uff0c\u4e00\u4e2a\u5e38\u89c1\u7684\u601d\u7ef4\u9677\u9631\u662f\u9677\u5165\u70b9\u72b6\u601d\u7ef4\uff0c\u4ec5\u5173\u6ce8\u5355\u4e2aIP\u3001\u7aef\u53e3\u6216\u9875\u9762\uff0c\u800c\u5ffd\u7565\u4e86Web\u5e94\u7528\u4f5c\u4e3a\u5b8c\u6574\u7cfb\u7edf\u7684\u6574\u4f53\u67b6\u6784\u3002\u672c\u6a21\u5757\u65e8\u5728\u5e2e\u52a9\u60a8\u5efa\u7acb\u7cfb\u7edf\u6027\u7684\u67b6\u6784\u8ba4\u77e5\uff0c\u6df1\u5165\u7406\u89e3Web\u5e94\u7528\u4e2dDNS\u3001CDN\u3001\u8d1f\u8f7d\u5747\u8861\u3001Web\u670d\u52a1\u5668\u3001\u5e94\u7528\u6846\u67b6\u3001\u6570\u636e\u5e93\u3001\u7f13\u5b58\u3001WAF\u3001\u871c\u7f50\u7b49\u6838\u5fc3\u7ec4\u4ef6\u95f4\u7684\u4ea4\u4e92\u903b\u8f91\u3002\u53ea\u6709\u4ece\u5168\u5c40\u89c6\u89d2\u51fa\u53d1\uff0c\u540e\u7eed\u6536\u96c6\u5230\u7684\u4fe1\u606f\u624d\u80fd\u88ab\u6b63\u786e\u5173\u8054\u548c\u89e3\u8bfb\uff0c\u907f\u514d\u56e0\u5b64\u7acb\u7684\u6570\u636e\u70b9\u800c\u505a\u51fa\u9519\u8bef\u5224\u65ad\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u6280\u672f\u539f\u7406\u8bf4\u660e<\/h4>\n\n\n\n<p>Web\u5e94\u7528\u5728\u672c\u8d28\u4e0a\u662f\u4e00\u4e2a\u591a\u5c42\u3001\u591a\u7ec4\u4ef6\u7684\u5206\u5e03\u5f0f\u7cfb\u7edf\uff0c\u5176\u5e95\u5c42\u901a\u4fe1\u903b\u8f91\u9075\u5faa\u4e00\u6761\u5b8c\u6574\u7684\u201c\u8bf7\u6c42-\u54cd\u5e94\u201d\u94fe\u3002\u9632\u62a4\u8bbe\u5907\uff08\u5982WAF\uff09\u548c\u6b3a\u9a97\u9632\u5fa1\u7cfb\u7edf\uff08\u5982\u871c\u7f50\uff09\u901a\u5e38\u4ee5\u4e32\u8054\u6216\u65c1\u8def\u7684\u65b9\u5f0f\u90e8\u7f72\u4e8e\u6b64\u94fe\u8def\u4e2d\u3002\u8fd9\u79cd\u8bbe\u8ba1\u65e8\u5728\u5e73\u8861\u6027\u80fd\u3001\u53ef\u7528\u6027\u4e0e\u5b89\u5168\u6027\uff1aWAF\u90e8\u7f72\u4e8e\u6d41\u91cf\u5165\u53e3\uff0c\u8d1f\u8d23\u8fc7\u6ee4\u6076\u610f\u8bf7\u6c42\uff1b\u871c\u7f50\u5219\u6a21\u62df\u771f\u5b9e\u670d\u52a1\uff0c\u7528\u4e8e\u8bf1\u6355\u548c\u5206\u6790\u653b\u51fb\u8005\u884c\u4e3a\u3002\u6df1\u523b\u7406\u89e3\u6bcf\u4e2a\u7ec4\u4ef6\u5728\u8bf7\u6c42\u94fe\u4e2d\u7684\u4f4d\u7f6e\uff0c\u662f\u6211\u4eec\u65e5\u540e\u901a\u8fc7\u5916\u90e8\u7279\u5f81\u63a8\u65ad\u5176\u5185\u90e8\u5b58\u5728\u7684\u57fa\u7840\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u5728\u7cfb\u7edf\u4e2d\u7684\u4f4d\u7f6e<\/h4>\n\n\n\n<p>\u672c\u6a21\u5757\u4f5c\u4e3a\u6574\u4e2a\u8bfe\u7a0b\u7684\u8d77\u70b9\uff0c\u65e8\u5728\u6784\u5efa\u4fe1\u606f\u6536\u96c6\u6240\u5fc5\u9700\u7684\u601d\u7ef4\u6846\u67b6\u3002\u540e\u7eed\u6240\u6709\u6a21\u5757\uff0c\u5305\u62ec\u95ee\u9898\u5b9a\u4e49\u3001\u7ed3\u6784\u62c6\u89e3\u3001\u65b9\u6cd5\u6a21\u578b\u3001\u64cd\u4f5c\u8def\u5f84\u7b49\uff0c\u90fd\u5c06\u4ee5\u6b64\u7cfb\u7edf\u6027\u8ba4\u77e5\u4e3a\u57fa\u77f3\u3002\u901a\u8fc7\u5b66\u4e60\u672c\u6a21\u5757\uff0c\u60a8\u5c06\u521d\u6b65\u5f62\u6210\u201c\u67b6\u6784\u89c6\u89d2\u201d\uff0c\u4ece\u800c\u80fd\u591f\u5c06\u65e5\u540e\u6536\u96c6\u5230\u7684\u96f6\u6563\u6570\u636e\u70b9\uff0c\u6709\u6548\u5730\u7ec4\u7ec7\u6210\u4e00\u5e45\u5b8c\u6574\u7684\u76ee\u6807\u67b6\u6784\u89c6\u56fe\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u53ef\u6267\u884c\u547d\u4ee4\u6216\u67e5\u8be2\u65b9\u5f0f<\/h4>\n\n\n\n<p>\u672c\u6a21\u5757\u4fa7\u91cd\u4e8e\u8ba4\u77e5\u6784\u5efa\uff0c\u4f46\u6211\u4eec\u53ef\u4ee5\u901a\u8fc7\u4e00\u4e9b\u7b80\u5355\u7684\u547d\u4ee4\u884c\u5de5\u5177\u6765\u521d\u6b65\u611f\u53d7\u7ec4\u4ef6\u95f4\u7684\u4ea4\u4e92\u8fc7\u7a0b\u3002\u4f8b\u5982\uff0c\u4f7f\u7528<code>dig<\/code>\u89c2\u5bdfDNS\u89e3\u6790\u8fc7\u7a0b\uff0c\u6216\u4f7f\u7528<code>curl -I<\/code>\u89c2\u5bdf\u54cd\u5e94\u5934\u4e2d\u53ef\u80fd\u66b4\u9732\u7684\u7ec4\u4ef6\u4fe1\u606f\u3002\u4ee5\u4e0b\u547d\u4ee4\u4ee5\u5b89\u5168\u6d4b\u8bd5\u76ee\u6807<code>example.com<\/code>\u548c<code>httpbin.org<\/code>\u4e3a\u4f8b\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># \u89c2\u5bdfDNS\u89e3\u6790\uff0c\u67e5\u770bA\u8bb0\u5f55\u3001CNAME\u7b49\uff0c\u7528\u4e8e\u63a8\u65adCDN\u6216\u8d1f\u8f7d\u5747\u8861\u7684\u5b58\u5728\ndig example.com A\n\n# \u4f7f\u7528curl\u67e5\u770b\u54cd\u5e94\u5934\uff0c\u8bc6\u522bServer\u5b57\u6bb5\u3001Set-Cookie\u7b49\u6f5c\u5728\u7684\u6280\u672f\u6307\u7eb9\ncurl -I https:\/\/example.com\n\n# \u8bbf\u95eehttpbin.org\uff0c\u89c2\u5bdf\u5176\u54cd\u5e94\u5934\u4e2d\u7684\u7279\u5f81\uff08\u5982Via\u5934\u53ef\u80fd\u6307\u793a\u4ee3\u7406\u6216CDN\uff09\ncurl -I https:\/\/httpbin.org<\/code><\/pre>\n\n\n\n<h4 class=\"wp-block-heading\">\u5de5\u5177\u5bf9\u6bd4\u8868<\/h4>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u5de5\u5177<\/th><th>\u9002\u7528\u573a\u666f<\/th><th>\u4f18\u70b9<\/th><th>\u5c40\u9650<\/th><\/tr><\/thead><tbody><tr><td><code>dig<\/code><\/td><td>DNS\u67e5\u8be2\uff0c\u5206\u6790\u57df\u540d\u89e3\u6790\u8def\u5f84<\/td><td>\u6807\u51c6DNS\u5de5\u5177\uff0c\u7ed3\u679c\u8be6\u7ec6\uff0c\u652f\u6301\u591a\u79cd\u8bb0\u5f55\u7c7b\u578b<\/td><td>\u4ec5\u9650DNS\u5c42\u4fe1\u606f\uff0c\u65e0\u6cd5\u76f4\u63a5\u63a8\u65ad\u4e0a\u5c42\u7ec4\u4ef6<\/td><\/tr><tr><td><code>curl<\/code><\/td><td>HTTP\u8bf7\u6c42\uff0c\u5206\u6790\u54cd\u5e94\u5934\/\u54cd\u5e94\u4f53<\/td><td>\u7075\u6d3b\uff0c\u53ef\u6a21\u62df\u5404\u79cd\u8bf7\u6c42\u65b9\u6cd5\uff0c\u67e5\u770b\u8be6\u7ec6\u4ea4\u4e92<\/td><td>\u5355\u6b21\u8bf7\u6c42\uff0c\u65e0\u6cd5\u81ea\u52a8\u5316\u6279\u91cf\u6536\u96c6<\/td><\/tr><tr><td><code>nslookup<\/code><\/td><td>\u7b80\u5355DNS\u67e5\u8be2<\/td><td>Windows\/Linux\u901a\u7528\uff0c\u64cd\u4f5c\u7b80\u5355<\/td><td>\u4fe1\u606f\u91cf\u8f83\u5c11\uff0c\u4e0d\u5982<code>dig<\/code>\u7075\u6d3b<\/td><\/tr><tr><td><code>browser DevTools<\/code><\/td><td>\u6d4f\u89c8\u5668\u5f00\u53d1\u8005\u5de5\u5177\uff0c\u89c2\u5bdf\u7f51\u7edc\u8bf7\u6c42<\/td><td>\u56fe\u5f62\u5316\u754c\u9762\uff0c\u53ef\u67e5\u770b\u5b8c\u6574\u8bf7\u6c42\u94fe\u3001Cookies\u3001\u7f13\u5b58<\/td><td>\u4f9d\u8d56\u56fe\u5f62\u73af\u5883\uff0c\u4e0d\u4fbf\u4e8e\u811a\u672c\u5316<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h4 class=\"wp-block-heading\">\u6807\u51c6\u64cd\u4f5c\u6b65\u9aa4<\/h4>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u9009\u62e9\u6d4b\u8bd5\u76ee\u6807<\/strong>\uff1a\u4f8b\u5982\uff0c<code>example.com<\/code>\u3002<\/li>\n\n\n\n<li><strong>\u6267\u884cDNS\u67e5\u8be2<\/strong>\uff1a\u4f7f\u7528<code>dig<\/code>\u83b7\u53d6\u8be5\u57df\u540d\u7684A\u8bb0\u5f55\u3001CNAME\u3001NS\u8bb0\u5f55\uff0c\u5206\u6790\u662f\u5426\u5b58\u5728CDN\uff08\u5982CNAME\u6307\u5411CDN\u57df\u540d\uff09\u3002<\/li>\n\n\n\n<li><strong>\u5206\u6790HTTP\u54cd\u5e94\u5934<\/strong>\uff1a\u4f7f\u7528<code>curl -I<\/code>\u53d1\u9001HEAD\u8bf7\u6c42\uff0c\u8bb0\u5f55\u5e76\u5173\u6ce8<code>Server<\/code>\u3001<code>X-Powered-By<\/code>\u3001<code>Set-Cookie<\/code>\u7b49\u5b57\u6bb5\u3002<\/li>\n\n\n\n<li><strong>\u63a2\u6d4b\u5e38\u89c1\u8def\u5f84<\/strong>\uff1a\u5c1d\u8bd5\u8bbf\u95ee\u5982<code>\/robots.txt<\/code>\u7b49\u5e38\u89c1\u6587\u4ef6\uff0c\u89c2\u5bdf\u54cd\u5e94\u5185\u5bb9\u662f\u5426\u5305\u542b\u6280\u672f\u67b6\u6784\u7ebf\u7d22\u3002<\/li>\n\n\n\n<li><strong>\u5229\u7528\u6d4f\u89c8\u5668\u5de5\u5177<\/strong>\uff1a\u4f7f\u7528\u6d4f\u89c8\u5668\u5f00\u53d1\u8005\u5de5\u5177\u5237\u65b0\u9875\u9762\uff0c\u89c2\u5bdf\u201c\u7f51\u7edc\u201d\u6807\u7b7e\u9875\u4e2d\u7684\u8d44\u6e90\u52a0\u8f7d\u57df\u540d\uff0c\u5224\u65ad\u662f\u5426\u6d89\u53ca\u591a\u4e2a\u5b50\u57df\u6216\u7b2c\u4e09\u65b9CDN\u3002<\/li>\n\n\n\n<li><strong>\u521d\u6b65\u4fe1\u606f\u6574\u7406<\/strong>\uff1a\u5c06\u6536\u96c6\u5230\u7684\u4fe1\u606f\u6574\u7406\u4e3a\u7b80\u5355\u7684\u7ec4\u4ef6\u5217\u8868\uff08\u4f8b\u5982\uff1aDNS\u670d\u52a1\u5546\u3001Web\u670d\u52a1\u5668\u7c7b\u578b\u3001\u662f\u5426\u4f7f\u7528CDN\uff09\u3002<\/li>\n<\/ol>\n\n\n\n<h4 class=\"wp-block-heading\">\u5982\u4f55\u9a8c\u8bc1\u7ed3\u679c\u771f\u5b9e\u6027<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u9a8c\u8bc1\u903b\u8f91<\/strong>\uff1a\u901a\u8fc7\u591a\u79cd\u5de5\u5177\uff08\u5982<code>dig<\/code>\u4e0e<code>nslookup<\/code>\uff09\u5bf9\u6bd4DNS\u89e3\u6790\u7ed3\u679c\u662f\u5426\u4e00\u81f4\uff1b\u901a\u8fc7<code>curl<\/code>\u4e0e\u6d4f\u89c8\u5668\u5f00\u53d1\u8005\u5de5\u5177\u5bf9\u6bd4\u54cd\u5e94\u5934\u4fe1\u606f\u662f\u5426\u76f8\u540c\u3002\u5bf9\u4e8e\u63a8\u65ad\u51fa\u7684\u7ec4\u4ef6\uff0c\u53ef\u8fdb\u4e00\u6b65\u67e5\u627e\u516c\u5f00\u8d44\u6599\uff08\u5982\u5b98\u65b9\u6587\u6863\uff09\u6765\u786e\u8ba4\u5176\u9ed8\u8ba4\u7279\u5f81\u3002<\/li>\n\n\n\n<li><strong>\u8f93\u51fa\u5224\u65ad\u4f9d\u636e<\/strong>\uff1a\u4f8b\u5982\uff0c\u82e5\u54cd\u5e94\u5934\u4e2d\u5305\u542b<code>Server: nginx<\/code>\uff0c\u5219\u53ef\u521d\u6b65\u63a8\u65adWeb\u670d\u52a1\u5668\u4e3aNginx\uff1b\u82e5\u89e3\u6790\u51faCNAME\u6307\u5411<code>example.com.cdn.cloudflare.net<\/code>\uff0c\u5219\u53ef\u63a8\u65ad\u4f7f\u7528\u4e86Cloudflare CDN\uff08\u6b64\u5904\u4ec5\u4f5c\u903b\u8f91\u8bf4\u660e\uff0c\u975e\u7edd\u5bf9\uff09\u3002<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">\u5e38\u89c1\u9519\u8bef\u4e0e\u6392\u67e5\u65b9\u5f0f<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u9519\u8bef<\/strong>\uff1a\u4ec5\u51ed\u5355\u4e00\u8bf7\u6c42\u5934\u4e2d\u7684<code>Server<\/code>\u5b57\u6bb5\u5c31\u786e\u5b9a\u6574\u4e2a\u6280\u672f\u6808\uff0c\u5ffd\u7565\u4e86WAF\u53ef\u80fd\u4fee\u6539\u6216\u9690\u85cf<code>Server<\/code>\u5934\u7684\u60c5\u51b5\u3002<\/li>\n\n\n\n<li><strong>\u6392\u67e5<\/strong>\uff1a\u4f7f\u7528\u4e0d\u540c\u7684\u8bf7\u6c42\u65b9\u6cd5\uff08\u5982POST\uff09\u6216\u8bbf\u95ee\u975e\u6807\u51c6\u8def\u5f84\uff0c\u89c2\u5bdf<code>Server<\/code>\u5934\u662f\u5426\u53d8\u5316\uff1b\u7ed3\u5408\u591a\u4e2a\u7279\u5f81\uff08\u5982Cookie\u540d\u3001\u54cd\u5e94\u4f53\u7279\u5b9a\u5185\u5bb9\uff09\u8fdb\u884c\u4ea4\u53c9\u9a8c\u8bc1\u3002<\/li>\n\n\n\n<li><strong>\u9519\u8bef<\/strong>\uff1a\u5c06CDN\u8282\u70b9\u7684IP\u8bef\u8ba4\u4e3a\u662f\u6e90\u7ad9IP\u3002<\/li>\n\n\n\n<li><strong>\u6392\u67e5<\/strong>\uff1a\u4f7f\u7528\u591a\u5730DNS\u89e3\u6790\u670d\u52a1\u6216\u67e5\u8be2\u5386\u53f2DNS\u8bb0\u5f55\uff0c\u5224\u65ad\u662f\u5426\u5b58\u5728\u591a\u4e2aIP\u4e14\u5f52\u5c5e\u4e8e\u4e0d\u540c\u7684ASN\uff1b\u5c1d\u8bd5\u76f4\u63a5\u8bbf\u95eeIP\u768480\/443\u7aef\u53e3\uff0c\u89c2\u5bdf\u54cd\u5e94\u5185\u5bb9\u662f\u5426\u4e0e\u901a\u8fc7\u57df\u540d\u8bbf\u95ee\u65f6\u4e00\u81f4\u3002<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">\u5408\u89c4\u8fb9\u754c\u8bf4\u660e<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u7f51\u7edc\u5b89\u5168\u89c6\u89d2<\/strong>\uff1a\u672c\u6a21\u5757\u4ec5\u6d89\u53ca\u516c\u5f00\u53ef\u83b7\u53d6\u7684\u4fe1\u606f\uff08DNS\u3001HTTP\u5934\uff09\uff0c\u4e0d\u6d89\u53ca\u4e3b\u52a8\u626b\u63cf\u6216\u6f0f\u6d1e\u63a2\u6d4b\uff0c\u98ce\u9669\u8f83\u4f4e\u3002\u4f46\u4ecd\u9700\u6ce8\u610f\uff0c\u8fc7\u4e8e\u9891\u7e41\u7684DNS\u67e5\u8be2\u53ef\u80fd\u88ab\u89c6\u4e3a\u4fa6\u5bdf\u884c\u4e3a\uff0c\u67d0\u4e9b\u7ec4\u7ec7\u7684\u76d1\u63a7\u7b56\u7565\u53ef\u80fd\u4f1a\u8bb0\u5f55\u6b64\u7c7b\u6d3b\u52a8\u3002<\/li>\n\n\n\n<li><strong>\u98ce\u9669<\/strong>\uff1a\u65e0\u76f4\u63a5\u653b\u51fb\u98ce\u9669\uff0c\u4f46\u5927\u91cf\u67e5\u8be2\u53ef\u80fd\u89e6\u53d1CDN\u6216WAF\u7684\u901f\u7387\u9650\u5236\u673a\u5236\u3002<\/li>\n\n\n\n<li><strong>\u7f13\u89e3\u63aa\u65bd<\/strong>\uff1a\u5408\u7406\u63a7\u5236\u67e5\u8be2\u9891\u7387\uff0c\u6216\u4f7f\u7528\u516c\u5f00\u7684DNS\u89e3\u6790\u670d\u52a1\uff08\u5982<code>8.8.8.8<\/code>\uff09\uff0c\u907f\u514d\u76f4\u63a5\u5411\u76ee\u6807\u6743\u5a01DNS\u670d\u52a1\u5668\u53d1\u9001\u5927\u91cf\u8bf7\u6c42\u3002<\/li>\n\n\n\n<li><strong>\u51b3\u7b56\u6307\u5357<\/strong>\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u5fc5\u987b\u7528<\/strong>\uff1a\u5728\u4fe1\u606f\u6536\u96c6\u5f00\u59cb\u524d\uff0c\u5e94\u901a\u8fc7\u672c\u6a21\u5757\u5efa\u7acb\u5bf9\u76ee\u6807\u67b6\u6784\u7684\u521d\u6b65\u8ba4\u77e5\uff0c\u4ee5\u6307\u5bfc\u540e\u7eed\u7684\u6df1\u5165\u63a2\u6d4b\u5de5\u4f5c\u3002<\/li>\n\n\n\n<li><strong>\u66ff\u4ee3<\/strong>\uff1a\u82e5\u76ee\u6807\u660e\u786e\u4e3a\u5355\u4e00\u9759\u6001\u7ad9\u70b9\u4e14\u6280\u672f\u6808\u5df2\u77e5\uff0c\u53ef\u8df3\u8fc7\u672c\u6a21\u5757\u4e2d\u7684\u67d0\u4e9b\u64cd\u4f5c\u6b65\u9aa4\uff0c\u4f46\u7cfb\u7edf\u6027\u601d\u7ef4\u4ecd\u9700\u4fdd\u7559\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">\u672c\u6a21\u5757\u5c0f\u7ed3<\/h4>\n\n\n\n<p>\u672c\u6a21\u5757\u5f15\u5bfc\u60a8\u4ece\u70b9\u72b6\u601d\u7ef4\u8f6c\u5411\u7cfb\u7edf\u601d\u7ef4\u3002\u901a\u8fc7\u7406\u89e3Web\u5e94\u7528\u5404\u7ec4\u4ef6\u7684\u4ea4\u4e92\u903b\u8f91\uff0c\u4e3a\u540e\u7eed\u7684\u67b6\u6784\u4fe1\u606f\u6536\u96c6\u5960\u5b9a\u4e86\u575a\u5b9e\u7684\u8ba4\u77e5\u57fa\u7840\u3002\u501f\u52a9\u7b80\u5355\u7684DNS\u548cHTTP\u67e5\u8be2\uff0c\u6211\u4eec\u5df2\u7ecf\u53ef\u4ee5\u521d\u6b65\u52fe\u52d2\u51fa\u76ee\u6807\u7684\u6280\u672f\u8f6e\u5ed3\u3002\u63a5\u4e0b\u6765\uff0c\u6211\u4eec\u5c06\u8fdb\u5165\u4e0b\u4e00\u6a21\u5757\uff0c<strong>\u660e\u786e\u4fe1\u606f\u6536\u96c6\u9636\u6bb5\u7684\u5177\u4f53\u95ee\u9898\u4e0e\u76ee\u6807<\/strong>\uff0c\u5c06\u62bd\u8c61\u7684\u8ba4\u77e5\u8f6c\u5316\u4e3a\u53ef\u6267\u884c\u7684\u4efb\u52a1\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">\u95ee\u9898\u4e0e\u76ee\u6807\u660e\u786e<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">\u6a21\u5757\u6982\u5ff5\u89e3\u91ca<\/h4>\n\n\n\n<p>\u5728\u4fe1\u606f\u6536\u96c6\u9636\u6bb5\uff0c\u53e6\u4e00\u4e2a\u5e38\u89c1\u95ee\u9898\u662f\u6f2b\u65e0\u76ee\u7684\u5730\u6536\u96c6\u6570\u636e\uff0c\u5bfc\u81f4\u6548\u7387\u4f4e\u4e0b\u6216\u9057\u6f0f\u5173\u952e\u4fe1\u606f\u3002\u672c\u6a21\u5757\u7684\u6838\u5fc3\u4efb\u52a1\uff0c\u5c31\u662f\u5e2e\u52a9\u60a8\u754c\u5b9a\u6e05\u6670\u7684\u4fe1\u606f\u6536\u96c6\u76ee\u6807\uff1a\u8bc6\u522bWeb\u5e94\u7528\u7684\u6280\u672f\u6808\uff08\u7f16\u7a0b\u8bed\u8a00\u3001\u6846\u67b6\u3001\u4e2d\u95f4\u4ef6\uff09\u3001\u53d1\u73b0\u7f51\u7edc\u62d3\u6251\uff08\u8d1f\u8f7d\u5747\u8861\u3001CDN\uff09\u3001\u68c0\u6d4b\u5b89\u5168\u9632\u62a4\u7ec4\u4ef6\uff08WAF\u3001IPS\uff09\u4ee5\u53ca\u8bc6\u522b\u6b3a\u9a97\u9632\u5fa1\u7cfb\u7edf\uff08\u871c\u7f50\uff09\u7b49\u3002\u53ea\u6709\u660e\u786e\u4e86\u201c\u8981\u627e\u4ec0\u4e48\u201d\uff0c\u540e\u7eed\u9009\u62e9\u7684\u65b9\u6cd5\u548c\u8fdb\u884c\u7684\u64cd\u4f5c\u624d\u80fd\u505a\u5230\u6709\u7684\u653e\u77e2\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u6280\u672f\u539f\u7406\u8bf4\u660e<\/h4>\n\n\n\n<p>\u4fe1\u606f\u6536\u96c6\u7684\u5e95\u5c42\u903b\u8f91\u662f\u201c\u66b4\u9732\u9762\u5206\u6790\u201d\u3002\u4efb\u4f55Web\u5e94\u7528\u5728\u63d0\u4f9b\u670d\u52a1\u65f6\uff0c\u90fd\u4f1a\u4e0d\u53ef\u907f\u514d\u5730\u66b4\u9732\u4e00\u4e9b\u4fe1\u606f\uff0c\u5982\u54cd\u5e94\u5934\u4e2d\u7684<code>Server<\/code>\u5b57\u6bb5\u3001\u9519\u8bef\u9875\u9762\u7684\u5806\u6808\u4fe1\u606f\u3001Cookie\u7684\u547d\u540d\u89c4\u8303\u3001URL\u7684\u7ed3\u6784\u7279\u5f81\u7b49\u3002\u653b\u51fb\u8005\u6216\u5b89\u5168\u6d4b\u8bd5\u4eba\u5458\u6b63\u662f\u5229\u7528\u8fd9\u4e9b\u201c\u4fe1\u606f\u6cc4\u6f0f\u201d\u6765\u63a8\u65ad\u5185\u90e8\u67b6\u6784\u3002\u540c\u65f6\uff0c\u4f5c\u4e3a\u9632\u62a4\u624b\u6bb5\u7684WAF\u548c\u871c\u7f50\uff0c\u4e5f\u4f1a\u5728\u4ea4\u4e92\u8fc7\u7a0b\u4e2d\u7559\u4e0b\u72ec\u7279\u7684\u6307\u7eb9\uff08\u5982WAF\u7684\u62e6\u622a\u9875\u9762\u3001\u871c\u7f50\u7684\u54cd\u5e94\u5ef6\u8fdf\u7279\u5f81\uff09\u3002\u56e0\u6b64\uff0c\u5728\u76ee\u6807\u660e\u786e\u540e\uff0c\u6211\u4eec\u9700\u8981\u6709\u9488\u5bf9\u6027\u5730\u6536\u96c6\u8fd9\u4e9b\u66b4\u9732\u4fe1\u606f\uff0c\u4ee5\u56de\u7b54\u4ee5\u4e0b\u6838\u5fc3\u95ee\u9898\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u5e94\u7528\u4f7f\u7528\u4e86\u54ea\u4e9b\u6280\u672f\u7ec4\u4ef6\uff1f<\/li>\n\n\n\n<li>\u5404\u7ec4\u4ef6\u7684\u7248\u672c\u662f\u5426\u5b58\u5728\u5df2\u77e5\u6f0f\u6d1e\uff1f<\/li>\n\n\n\n<li>\u662f\u5426\u5b58\u5728WAF\uff0c\u5176\u7c7b\u578b\u53ca\u89c4\u5219\u5f3a\u5ea6\u5982\u4f55\uff1f<\/li>\n\n\n\n<li>\u662f\u5426\u5b58\u5728\u871c\u7f50\uff0c\u5982\u4f55\u533a\u5206\u771f\u5b9e\u670d\u52a1\u4e0e\u6b3a\u9a97\u670d\u52a1\uff1f<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">\u5728\u7cfb\u7edf\u4e2d\u7684\u4f4d\u7f6e<\/h4>\n\n\n\n<p>\u672c\u6a21\u5757\u627f\u63a5\u4e0a\u4e00\u6a21\u5757\u201c\u8ba4\u77e5\u57fa\u7840\u91cd\u6784\u201d\uff0c\u5c06\u62bd\u8c61\u7684\u7cfb\u7edf\u8ba4\u77e5\u8f6c\u5316\u4e3a\u5177\u4f53\u3001\u53ef\u6267\u884c\u7684\u4fe1\u606f\u6536\u96c6\u76ee\u6807\u3002\u5b83\u660e\u786e\u4e86\u5728\u63a5\u4e0b\u6765\u7684\u201c\u5173\u952e\u7ed3\u6784\u62c6\u89e3\u201d\u4e2d\u9700\u8981\u91cd\u70b9\u5173\u6ce8\u7684\u8981\u7d20\uff0c\u4ee5\u53ca\u540e\u7eed\u201c\u65b9\u6cd5\u6a21\u578b\u5efa\u7acb\u201d\u9700\u8981\u89e3\u51b3\u7684\u95ee\u9898\u3002\u6ca1\u6709\u6e05\u6670\u7684\u76ee\u6807\uff0c\u4efb\u4f55\u64cd\u4f5c\u8def\u5f84\u90fd\u5c06\u662f\u76f2\u76ee\u7684\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u53ef\u6267\u884c\u547d\u4ee4\u6216\u67e5\u8be2\u65b9\u5f0f<\/h4>\n\n\n\n<p>\u5728\u76ee\u6807\u660e\u786e\u4e4b\u540e\uff0c\u6211\u4eec\u53ef\u4ee5\u901a\u8fc7\u4e00\u4e9b\u7b80\u5355\u7684\u63a2\u6d4b\u547d\u4ee4\u6765\u9a8c\u8bc1\u76ee\u6807\u7684\u54cd\u5e94\u7279\u5f81\uff0c\u4e3a\u540e\u7eed\u7684\u6df1\u5165\u5206\u6790\u63d0\u4f9b\u7ebf\u7d22\u3002\u4f8b\u5982\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># \u6d4b\u8bd5\u76ee\u6807\u662f\u5426\u5bf9\u6076\u610f\u8bf7\u6c42\u6709\u7279\u6b8a\u54cd\u5e94\uff08\u53ef\u80fd\u66b4\u9732WAF\u7684\u5b58\u5728\uff09\ncurl -I \"https:\/\/httpbin.org\/?id=1'\"\n\n# \u68c0\u67e5\u5e38\u89c1\u7ba1\u7406\u540e\u53f0\u8def\u5f84\u662f\u5426\u5b58\u5728\uff0c\u5176\u54cd\u5e94\u53ef\u80fd\u66b4\u9732\u5e94\u7528\u7c7b\u578b\ncurl -I https:\/\/example.com\/admin\n\n# \u4f7f\u7528wafw00f\u5de5\u5177\u521d\u6b65\u68c0\u6d4bWAF\uff08\u9700\u9884\u5148\u5b89\u88c5\uff09\nwafw00f https:\/\/example.com<\/code><\/pre>\n\n\n\n<h4 class=\"wp-block-heading\">\u5de5\u5177\u5bf9\u6bd4\u8868<\/h4>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u5de5\u5177<\/th><th>\u9002\u7528\u573a\u666f<\/th><th>\u4f18\u70b9<\/th><th>\u5c40\u9650<\/th><\/tr><\/thead><tbody><tr><td><code>curl<\/code><\/td><td>\u624b\u52a8\u6d4b\u8bd5\u7279\u5b9a\u8bf7\u6c42<\/td><td>\u7075\u6d3b\uff0c\u53ef\u6784\u9020\u4efb\u610f\u8bf7\u6c42\u5934\/\u53c2\u6570<\/td><td>\u6548\u7387\u4f4e\uff0c\u4e0d\u9002\u5408\u6279\u91cf\u6d4b\u8bd5<\/td><\/tr><tr><td><code>wafw00f<\/code><\/td><td>\u81ea\u52a8\u68c0\u6d4bWAF\u7c7b\u578b<\/td><td>\u4e13\u95e8\u9488\u5bf9WAF\u6307\u7eb9\u8bc6\u522b\uff0c\u7ed3\u679c\u8f83\u4e3a\u51c6\u786e<\/td><td>\u53ea\u80fd\u8bc6\u522bWAF\uff0c\u65e0\u6cd5\u68c0\u6d4b\u871c\u7f50<\/td><\/tr><tr><td><code>whatweb<\/code><\/td><td>\u8bc6\u522bWeb\u6280\u672f\u6808<\/td><td>\u63d2\u4ef6\u4e30\u5bcc\uff0c\u80fd\u8bc6\u522bCMS\u3001\u6846\u67b6\u3001\u670d\u52a1\u5668\u7b49<\/td><td>\u53ef\u80fd\u88abWAF\u62e6\u622a\uff0c\u4ea7\u751f\u8bef\u62a5<\/td><\/tr><tr><td><code>nmap<\/code> + \u811a\u672c<\/td><td>\u626b\u63cf\u5f00\u653e\u7aef\u53e3\u4e0e\u670d\u52a1<\/td><td>\u7efc\u5408\u6027\u5f3a\uff0c\u53ef\u7ed3\u5408NSE\u811a\u672c\u68c0\u6d4b\u7279\u5b9a\u670d\u52a1\u4fe1\u606f<\/td><td>\u626b\u63cf\u884c\u4e3a\u6613\u88ab\u68c0\u6d4b\uff0c\u53ef\u80fd\u89e6\u53d1\u62a5\u8b66<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h4 class=\"wp-block-heading\">\u6807\u51c6\u64cd\u4f5c\u6b65\u9aa4<\/h4>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u5217\u51fa\u95ee\u9898\u6e05\u5355<\/strong>\uff1a\u660e\u786e\u672c\u6b21\u4fe1\u606f\u6536\u96c6\u9700\u8981\u89e3\u51b3\u7684\u5177\u4f53\u95ee\u9898\uff08\u4f8b\u5982\uff1aWeb\u670d\u52a1\u5668\u7c7b\u578b\u662f\u4ec0\u4e48\uff1f\u662f\u5426\u5b58\u5728WAF\uff1f\u662f\u5426\u5b58\u5728\u871c\u7f50\uff1f\uff09\u3002<\/li>\n\n\n\n<li><strong>\u5feb\u901f\u6280\u672f\u8bc6\u522b<\/strong>\uff1a\u4f7f\u7528<code>whatweb<\/code>\u5bf9<code>httpbin.org<\/code>\u8fdb\u884c\u5feb\u901f\u8bc6\u522b\uff0c\u89c2\u5bdf\u8f93\u51fa\u4e2d\u5305\u542b\u7684\u670d\u52a1\u5668\u3001\u6846\u67b6\u7b49\u4fe1\u606f\u3002<\/li>\n\n\n\n<li><strong>WAF\u521d\u6b65\u68c0\u6d4b<\/strong>\uff1a\u4f7f\u7528<code>wafw00f<\/code>\u68c0\u6d4b\u76ee\u6807\u662f\u5426\u53d7WAF\u4fdd\u62a4\uff0c\u5e76\u8bb0\u5f55\u68c0\u6d4b\u5230\u7684WAF\u7c7b\u578b\uff08\u5982\u6709\uff09\u3002<\/li>\n\n\n\n<li><strong>\u624b\u52a8\u89e6\u53d1\u9a8c\u8bc1<\/strong>\uff1a\u4f7f\u7528<code>curl<\/code>\u624b\u52a8\u6784\u9020\u4e00\u4e2a\u53ef\u7591\u8bf7\u6c42\uff08\u5982SQL\u6ce8\u5165Payload\uff09\uff0c\u89c2\u5bdf\u54cd\u5e94\u72b6\u6001\u7801\u3001\u5185\u5bb9\u957f\u5ea6\u6216\u5185\u5bb9\u672c\u8eab\u662f\u5426\u53d1\u751f\u53d8\u5316\uff0c\u4ee5\u6b64\u5224\u65ad\u662f\u5426\u5b58\u5728WAF\u62e6\u622a\u3002<\/li>\n\n\n\n<li><strong>\u68c0\u67e5\u871c\u7f50\u7279\u5f81<\/strong>\uff1a\u8bbf\u95ee\u4e00\u4e9b\u5e38\u89c1\u7684\u871c\u7f50\u7279\u5f81\u8def\u5f84\uff08\u5982<code>\/wp-admin<\/code>\u4f46\u54cd\u5e94\u4e3a200\u4e14\u5185\u5bb9\u53ef\u7591\uff09\uff0c\u8bb0\u5f55\u4efb\u4f55\u5f02\u5e38\u60c5\u51b5\u3002<\/li>\n\n\n\n<li><strong>\u6574\u7406\u521d\u6b65\u4fe1\u606f<\/strong>\uff1a\u5c06\u6536\u96c6\u5230\u7684\u521d\u6b65\u4fe1\u606f\u6574\u7406\u4e3a\u76ee\u6807\u5217\u8868\uff0c\u5e76\u4e0e\u6700\u521d\u7684\u95ee\u9898\u6e05\u5355\u8fdb\u884c\u5bf9\u6bd4\uff0c\u660e\u786e\u4e0b\u4e00\u6b65\u9700\u8981\u6df1\u5165\u6316\u6398\u7684\u4fe1\u606f\u70b9\u3002<\/li>\n<\/ol>\n\n\n\n<h4 class=\"wp-block-heading\">\u5982\u4f55\u9a8c\u8bc1\u7ed3\u679c\u771f\u5b9e\u6027<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u9a8c\u8bc1\u903b\u8f91<\/strong>\uff1a\u5bf9\u4e8e\u5de5\u5177\u7684\u8f93\u51fa\uff0c\u53ef\u4ee5\u901a\u8fc7\u591a\u6b21\u6d4b\u8bd5\u6216\u66f4\u6362\u5de5\u5177\u8fdb\u884c\u4ea4\u53c9\u9a8c\u8bc1\u3002\u4f8b\u5982\uff0c<code>wafw00f<\/code>\u68c0\u6d4b\u5230\u67d0\u6b3eWAF\u540e\uff0c\u53ef\u4ee5\u624b\u52a8\u6a21\u62df\u8be5WAF\u7684\u5df2\u77e5\u62e6\u622a\u7279\u5f81\uff08\u5982\u53d1\u9001\u7279\u5b9a\u6076\u610f\u8bf7\u6c42\uff09\uff0c\u89c2\u5bdf\u662f\u5426\u786e\u5b9e\u88ab\u62e6\u622a\uff0c\u4ee5\u6b64\u786e\u8ba4WAF\u7684\u5b58\u5728\u3002<\/li>\n\n\n\n<li><strong>\u8f93\u51fa\u5224\u65ad\u4f9d\u636e<\/strong>\uff1a\u4f8b\u5982\uff0c\u624b\u52a8\u53d1\u9001\u8bf7\u6c42<code>\/?id=1 AND 1=1<\/code>\u8fd4\u56de\u6b63\u5e38\u9875\u9762\uff0c\u800c<code>\/?id=1 AND 1=2<\/code>\u8fd4\u56de\u5f02\u5e38\uff0c\u8fd9\u66f4\u53ef\u80fd\u662f\u5e94\u7528\u81ea\u8eab\u7684\u903b\u8f91\u5dee\u5f02\uff0c\u800c\u975eWAF\u62e6\u622a\uff1b\u82e5\u8bf7\u6c42\u4e2d\u5305\u542b\u5355\u5f15\u53f7<code>'<\/code>\u65f6\u8fd4\u56de403\u9875\u9762\uff0c\u4e14\u54cd\u5e94\u4f53\u4e2d\u5305\u542b\u7279\u5b9aWAF\u7684\u540d\u79f0\uff0c\u5219WAF\u7684\u68c0\u6d4b\u7ed3\u679c\u53ef\u4fe1\u5ea6\u8f83\u9ad8\u3002<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">\u5e38\u89c1\u9519\u8bef\u4e0e\u6392\u67e5\u65b9\u5f0f<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u9519\u8bef<\/strong>\uff1a\u5c06\u5e94\u7528\u81ea\u8eab\u8fd4\u56de\u7684\u9519\u8bef\u9875\u9762\uff08\u5982500\u5185\u90e8\u9519\u8bef\uff09\u8bef\u5224\u4e3aWAF\u62e6\u622a\u3002<\/li>\n\n\n\n<li><strong>\u6392\u67e5<\/strong>\uff1a\u5bf9\u6bd4\u6b63\u5e38\u8bf7\u6c42\u4e0e\u9519\u8bef\u8bf7\u6c42\u7684\u54cd\u5e94\u5185\u5bb9\u3002\u5982\u679c\u9519\u8bef\u9875\u9762\u5305\u542b\u5e94\u7528\u6846\u67b6\u7684\u5806\u6808\u8ddf\u8e2a\u4fe1\u606f\uff0c\u5219\u5c5e\u4e8e\u5e94\u7528\u9519\u8bef\uff1b\u5982\u679c\u54cd\u5e94\u662f\u4e00\u4e2a\u98ce\u683c\u7edf\u4e00\u7684\u62e6\u622a\u9875\u9762\uff08\u5982\u201c\u60a8\u7684\u8bf7\u6c42\u5df2\u88ab\u62e6\u622a\u201d\uff09\uff0c\u5219\u5f88\u53ef\u80fd\u6765\u81eaWAF\u3002<\/li>\n\n\n\n<li><strong>\u9519\u8bef<\/strong>\uff1a\u4f9d\u8d56\u5355\u4e00\u5de5\u5177\u68c0\u6d4bWAF\uff0c\u5ffd\u7565\u4e86WAF\u53ef\u80fd\u88ab\u914d\u7f6e\u4e3a\u201c\u4ec5\u8bb0\u5f55\u201d\u6a21\u5f0f\uff08\u5373\u53ea\u8bb0\u5f55\u653b\u51fb\u65e5\u5fd7\uff0c\u4e0d\u8fdb\u884c\u62e6\u622a\uff09\u3002<\/li>\n\n\n\n<li><strong>\u6392\u67e5<\/strong>\uff1a\u4f7f\u7528\u591a\u79cd\u4e0d\u540c\u7c7b\u578b\u7684Payload\u8fdb\u884c\u6d4b\u8bd5\uff0c\u89c2\u5bdf\u662f\u5426\u5728\u67d0\u4e9b\u60c5\u51b5\u4e0b\u54cd\u5e94\u4f1a\u6709\u6240\u4e0d\u540c\uff1b\u540c\u65f6\uff0c\u7ed3\u5408\u5176\u4ed6\u4fe1\u606f\uff08\u5982Cookie\u4e2d\u662f\u5426\u5305\u542bWAF\u7684\u7279\u5b9a\u6807\u8bc6\uff09\u8fdb\u884c\u7efc\u5408\u5224\u65ad\u3002<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">\u5408\u89c4\u8fb9\u754c\u8bf4\u660e<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u7f51\u7edc\u5b89\u5168\u89c6\u89d2<\/strong>\uff1a\u672c\u6a21\u5757\u6d89\u53ca\u7684\u63a2\u6d4b\u884c\u4e3a\uff08\u5982\u53d1\u9001\u5305\u542bSQL\u6ce8\u5165\u5173\u952e\u8bcd\u7684\u8bf7\u6c42\uff09\u53ef\u80fd\u4f1a\u88ab\u76ee\u6807WAF\u8bc6\u522b\u4e3a\u653b\u51fb\u884c\u4e3a\uff0c\u4ece\u800c\u89e6\u53d1\u8b66\u62a5\u3002\u5728\u6388\u6743\u6d4b\u8bd5\u4e2d\uff0c\u5e94\u63d0\u524d\u77e5\u4f1a\u76f8\u5173\u4eba\u5458\uff0c\u6216\u4f7f\u7528<code>httpbin.org<\/code>\u8fd9\u7c7b\u516c\u5f00\u6d4b\u8bd5\u5e73\u53f0\u8fdb\u884c\u7ec3\u4e60\u3002<\/li>\n\n\n\n<li><strong>\u98ce\u9669<\/strong>\uff1a\u672a\u7ecf\u6388\u6743\u5bf9\u771f\u5b9e\u76ee\u6807\u53d1\u9001\u5305\u542b\u6076\u610fPayload\u7684\u8bf7\u6c42\u5c5e\u8fdd\u6cd5\u884c\u4e3a\u3002\u672c\u8bfe\u7a0b\u4e2d\u7684\u6240\u6709\u547d\u4ee4\u793a\u4f8b\uff0c\u4ec5\u9650\u5728\u6388\u6743\u73af\u5883\u6216\u516c\u5f00\u6d4b\u8bd5\u5e73\u53f0\u4f7f\u7528\u3002<\/li>\n\n\n\n<li><strong>\u7f13\u89e3\u63aa\u65bd<\/strong>\uff1a\u4e25\u683c\u63a7\u5236\u63a2\u6d4b\u7684\u529b\u5ea6\uff0c\u907f\u514d\u4f7f\u7528\u9ad8\u5371Payload\uff08\u5982\u8054\u5408\u67e5\u8be2\uff09\uff1b\u4f18\u5148\u4f7f\u7528\u4e13\u7528\u7684\u6d4b\u8bd5\u57df\u540d\u6216\u672c\u5730\u642d\u5efa\u7684\u6d4b\u8bd5\u73af\u5883\u3002<\/li>\n\n\n\n<li><strong>\u51b3\u7b56\u6307\u5357<\/strong>\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u5fc5\u987b\u7528<\/strong>\uff1a\u5728\u6e17\u900f\u6d4b\u8bd5\u6216\u5b89\u5168\u8bc4\u4f30\u4e2d\uff0c\u5fc5\u987b\u9996\u5148\u660e\u786e\u4fe1\u606f\u6536\u96c6\u7684\u76ee\u6807\uff0c\u5426\u5219\u540e\u7eed\u5de5\u4f5c\u5c06\u5931\u53bb\u65b9\u5411\uff0c\u6548\u7387\u4f4e\u4e0b\u3002<\/li>\n\n\n\n<li><strong>\u66ff\u4ee3<\/strong>\uff1a\u5bf9\u4e8e\u6280\u672f\u6808\u5df2\u660e\u786e\u7684\u5185\u90e8\u8bc4\u4f30\u9879\u76ee\uff0c\u53ef\u4ee5\u8df3\u8fc7\u90e8\u5206\u8bc6\u522b\u6b65\u9aa4\uff0c\u4f46\u4ecd\u9700\u786e\u8ba4\u662f\u5426\u5b58\u5728WAF\u6216\u5176\u914d\u7f6e\u662f\u5426\u53d1\u751f\u53d8\u5316\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">\u672c\u6a21\u5757\u5c0f\u7ed3<\/h4>\n\n\n\n<p>\u901a\u8fc7\u672c\u6a21\u5757\u7684\u5b66\u4e60\uff0c\u60a8\u5b66\u4f1a\u4e86\u5982\u4f55\u5c06\u7cfb\u7edf\u8ba4\u77e5\u8f6c\u5316\u4e3a\u660e\u786e\u7684\u95ee\u9898\u6e05\u5355\u548c\u53ef\u6267\u884c\u7684\u4efb\u52a1\u3002\u8fd9\u5e2e\u52a9\u60a8\u638c\u63e1\u4e86\u5229\u7528\u5de5\u5177\u548c\u624b\u52a8\u6d4b\u8bd5\uff0c\u521d\u6b65\u8bc6\u522bWeb\u5e94\u7528\u6280\u672f\u6808\u4e0e\u9632\u62a4\u63aa\u65bd\u7684\u65b9\u6cd5\u3002\u73b0\u5728\uff0c\u6211\u4eec\u5df2\u7ecf\u6e05\u695a\u4e86\u8981\u5bfb\u627e\u4ec0\u4e48\u3002\u63a5\u4e0b\u6765\uff0c\u6211\u4eec\u5c06\u8fdb\u5165<strong>\u5173\u952e\u7ed3\u6784\u62c6\u89e3<\/strong>\u6a21\u5757\uff0c\u6df1\u5165\u5256\u6790Web\u5e94\u7528\u7684\u5404\u4e2a\u5c42\u6b21\uff0c\u7ec6\u5316\u6bcf\u4e2a\u7ec4\u4ef6\u7684\u7279\u5f81\u63d0\u53d6\u65b9\u6cd5\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">\u5173\u952e\u7ed3\u6784\u62c6\u89e3<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">\u6a21\u5757\u6982\u5ff5\u89e3\u91ca<\/h4>\n\n\n\n<p>Web\u5e94\u7528\u7684\u7ed3\u6784\u53ef\u4ee5\u6309\u7167\u5176\u529f\u80fd\u5c42\u6b21\u8fdb\u884c\u62c6\u89e3\uff0c\u6bcf\u4e00\u5c42\u90fd\u62e5\u6709\u5176\u7279\u6709\u7684\u4fe1\u606f\u66b4\u9732\u7279\u5f81\u3002\u672c\u6a21\u5757\u5c06\u8be6\u7ec6\u89e3\u6784\u8fd9\u4e9b\u8981\u7d20\uff0c\u9610\u660e\u5404\u5c42\u6b21\u4e4b\u95f4\u7684\u5173\u7cfb\uff0c\u5e2e\u52a9\u60a8\u5728\u540e\u7eed\u7684\u63a2\u6d4b\u5de5\u4f5c\u4e2d\u80fd\u591f\u6309\u56fe\u7d22\u9aa5\uff0c\u4ece\u4e0d\u540c\u5c42\u9762\u7cfb\u7edf\u5730\u6536\u96c6\u4fe1\u606f\uff0c\u5e76\u5c06\u5b83\u4eec\u6709\u6548\u5730\u5173\u8054\u8d77\u6765\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u6280\u672f\u539f\u7406\u8bf4\u660e<\/h4>\n\n\n\n<p>\u5176\u5e95\u5c42\u903b\u8f91\u662f\u201c\u5206\u5c42\u534f\u8bae\u6808\u201d\u4e0e\u201c\u7ec4\u4ef6\u6307\u7eb9\u201d\u7684\u7ed3\u5408\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u7f51\u7edc\u5c42<\/strong>\u901a\u8fc7IP\u5730\u5740\u3001\u5f00\u653e\u7aef\u53e3\u3001TLS\u8bc1\u4e66\u7b49\u66b4\u9732\u4fe1\u606f\u3002<\/li>\n\n\n\n<li><strong>\u4f20\u8f93\u5c42<\/strong>\u53ef\u901a\u8fc7\u8d1f\u8f7d\u5747\u8861\u7b97\u6cd5\u4ea7\u751f\u7684\u7279\u5b9a\u884c\u4e3a\uff08\u5982\u4f1a\u8bdd\u4fdd\u6301Cookie\uff09\u6765\u63a8\u65ad\u3002<\/li>\n\n\n\n<li><strong>\u5e94\u7528\u5c42<\/strong>\u5219\u901a\u8fc7HTTP\u5934\u3001URL\u7ed3\u6784\u3001Cookie\u547d\u540d\u89c4\u8303\u3001HTML\u6ce8\u91ca\u3001\u9759\u6001\u8d44\u6e90\u8def\u5f84\u7b49\u65b9\u5f0f\u66b4\u9732\u6280\u672f\u6808\u3002<\/li>\n\n\n\n<li><strong>\u6570\u636e\u5c42<\/strong>\u53ef\u4ee5\u901a\u8fc7\u6570\u636e\u5e93\u7279\u6709\u7684\u9519\u8bef\u4fe1\u606f\u3001\u9ed8\u8ba4\u7aef\u53e3\u7684\u5f00\u653e\u60c5\u51b5\u6765\u8bc6\u522b\u3002<\/li>\n\n\n\n<li><strong>\u5b89\u5168\u5c42<\/strong>\u7ec4\u4ef6\uff08WAF\u3001\u871c\u7f50\uff09\u62e5\u6709\u5176\u72ec\u7279\u7684\u54cd\u5e94\u7279\u5f81\uff0c\u5982WAF\u62e6\u622a\u9875\u9762\u7684\u7279\u5b9aHTML\u5185\u5bb9\u3001\u871c\u7f50\u7684\u54cd\u5e94\u5ef6\u8fdf\u6a21\u5f0f\u6216\u4ea4\u4e92\u7684\u4e00\u81f4\u6027\u7b49\u3002<br>\u8fd9\u4e9b\u7279\u5f81\u4e4b\u6240\u4ee5\u5b58\u5728\uff0c\u662f\u56e0\u4e3a\u5404\u7ec4\u4ef6\u5728\u534f\u8bae\u6808\u4e2d\u5904\u4e8e\u4e0d\u540c\u4f4d\u7f6e\uff0c\u4e14\u4e3a\u4e86\u5b8c\u6210\u5176\u529f\u80fd\u5fc5\u987b\u9075\u5faa\u7279\u5b9a\u7684\u534f\u8bae\uff0c\u4ece\u800c\u4ea7\u751f\u4e86\u53ef\u4f9b\u89c2\u6d4b\u7684\u6307\u7eb9\u3002<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">\u5728\u7cfb\u7edf\u4e2d\u7684\u4f4d\u7f6e<\/h4>\n\n\n\n<p>\u672c\u6a21\u5757\u662f\u540e\u7eed\u201c\u65b9\u6cd5\u6a21\u578b\u5efa\u7acb\u201d\u548c\u201c\u64cd\u4f5c\u8def\u5f84\u5f62\u6210\u201d\u7684\u91cd\u8981\u524d\u7f6e\u77e5\u8bc6\u3002\u53ea\u6709\u6df1\u5165\u4e86\u89e3\u5404\u5c42\u6b21\u7684\u7ed3\u6784\u548c\u7279\u5f81\u540e\uff0c\u624d\u80fd\u8bbe\u8ba1\u51fa\u6709\u9488\u5bf9\u6027\u7684\u63a2\u6d4b\u65b9\u6cd5\u548c\u64cd\u4f5c\u6b65\u9aa4\u3002\u5b83\u5c06\u4e4b\u524d\u8f83\u4e3a\u6a21\u7cca\u7684\u76ee\u6807\uff08\u5982\u201c\u8bc6\u522bWAF\u201d\uff09\u5177\u4f53\u5316\u4e3a\u53ef\u64cd\u4f5c\u7684\u68c0\u6d4b\u9879\uff08\u5982\u201c\u5bfb\u627eWAF\u62e6\u622a\u9875\u9762\u4e2d\u7684\u5173\u952e\u8bcd\u201d\uff09\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u53ef\u6267\u884c\u547d\u4ee4\u6216\u67e5\u8be2\u65b9\u5f0f<\/h4>\n\n\n\n<p>\u6211\u4eec\u53ef\u4ee5\u901a\u8fc7\u5177\u4f53\u7684\u547d\u4ee4\u6765\u62c6\u89e3\u5404\u5c42\u4fe1\u606f\uff0c\u4ecd\u4ee5<code>httpbin.org<\/code>\u4e3a\u4f8b\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># \u7f51\u7edc\u5c42\uff1a\u4f7f\u7528nmap\u626b\u63cf\u5f00\u653e\u7aef\u53e3\uff08\u9700\u5728\u6388\u6743\u8303\u56f4\u5185\uff09\nnmap -p 80,443 httpbin.org\n\n# \u5e94\u7528\u5c42\uff1a\u67e5\u770b\u54cd\u5e94\u5934\u4e2d\u7684Server\u5b57\u6bb5\ncurl -I https:\/\/httpbin.org\n\n# \u5e94\u7528\u5c42\uff1a\u67e5\u770bTLS\u8bc1\u4e66\u4fe1\u606f\uff08\u53ef\u80fd\u66b4\u9732\u7ec4\u7ec7\u6216\u90e8\u95e8\u540d\u79f0\uff09\nopenssl s_client -connect httpbin.org:443 2&gt;\/dev\/null | openssl x509 -text | grep \"Subject:\"\n\n# \u6570\u636e\u5c42\uff1a\u5c1d\u8bd5\u8bbf\u95ee\u53ef\u80fd\u7684\u6570\u636e\u5e93\u7ba1\u7406\u63a5\u53e3\ncurl -I https:\/\/httpbin.org\/phpmyadmin\n\n# \u5b89\u5168\u5c42\uff1a\u4f7f\u7528wafw00f\u68c0\u6d4bWAF\nwafw00f https:\/\/httpbin.org<\/code><\/pre>\n\n\n\n<h4 class=\"wp-block-heading\">\u5de5\u5177\u5bf9\u6bd4\u8868<\/h4>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u5de5\u5177<\/th><th>\u9002\u7528\u573a\u666f<\/th><th>\u4f18\u70b9<\/th><th>\u5c40\u9650<\/th><\/tr><\/thead><tbody><tr><td><code>nmap<\/code><\/td><td>\u7aef\u53e3\u626b\u63cf\u4e0e\u670d\u52a1\u8bc6\u522b<\/td><td>\u529f\u80fd\u5f3a\u5927\uff0c\u53ef\u63a2\u6d4b\u5f00\u653e\u7aef\u53e3\u3001\u670d\u52a1\u7248\u672c<\/td><td>\u626b\u63cf\u884c\u4e3a\u660e\u663e\uff0c\u6613\u89e6\u53d1IDS\/IPS<\/td><\/tr><tr><td><code>masscan<\/code><\/td><td>\u5927\u89c4\u6a21\u7aef\u53e3\u626b\u63cf<\/td><td>\u626b\u63cf\u901f\u5ea6\u6781\u5feb\uff0c\u9002\u5408\u5168\u7f51\u8303\u56f4\u63a2\u6d4b<\/td><td>\u51c6\u786e\u6027\u76f8\u5bf9\u8f83\u4f4e\uff0c\u53ef\u80fd\u51fa\u73b0\u6f0f\u62a5<\/td><\/tr><tr><td><code>openssl s_client<\/code><\/td><td>\u5206\u6790TLS\u8bc1\u4e66<\/td><td>\u53ef\u83b7\u53d6\u8bc1\u4e66\u7684\u8be6\u7ec6\u4fe1\u606f\uff08\u9881\u53d1\u8005\u3001SAN\u7b49\uff09<\/td><td>\u9700\u624b\u52a8\u89e3\u6790\u8f93\u51fa\uff0c\u4e0d\u591f\u76f4\u89c2<\/td><\/tr><tr><td><code>whatweb<\/code><\/td><td>Web\u5e94\u7528\u6307\u7eb9\u8bc6\u522b<\/td><td>\u81ea\u52a8\u8bc6\u522bCMS\u3001JS\u5e93\u3001Web\u670d\u52a1\u5668\u7b49<\/td><td>\u8bc6\u522b\u8fc7\u7a0b\u53ef\u80fd\u53d7WAF\u5e72\u6270<\/td><\/tr><tr><td><code>wafw00f<\/code><\/td><td>WAF\u68c0\u6d4b<\/td><td>\u4e13\u95e8\u7528\u4e8e\u68c0\u6d4bWAF\u7c7b\u578b<\/td><td>\u5bf9\u4e8e\u65b0\u578b\u6216\u5b9a\u5236\u7684WAF\u53ef\u80fd\u6f0f\u62a5<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h4 class=\"wp-block-heading\">\u6807\u51c6\u64cd\u4f5c\u6b65\u9aa4<\/h4>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u7f51\u7edc\u5c42\u6536\u96c6<\/strong>\uff1a\u5728\u6388\u6743\u8303\u56f4\u5185\uff0c\u4f7f\u7528<code>nmap -sS -p 1-1000 scanme.nmap.org<\/code>\u626b\u63cf\u5e38\u89c1\u7aef\u53e3\uff0c\u8bb0\u5f55\u5f00\u653e\u7aef\u53e3\u53ca\u5176\u80cc\u540e\u7684\u670d\u52a1\u3002<\/li>\n\n\n\n<li><strong>\u4f20\u8f93\u5c42\u5206\u6790<\/strong>\uff1a\u68c0\u67e5\u662f\u5426\u5b58\u5728\u8d1f\u8f7d\u5747\u8861\u7684\u8ff9\u8c61\u3002\u4f8b\u5982\uff0c\u591a\u6b21\u8bf7\u6c42<code>https:\/\/example.com<\/code>\uff0c\u89c2\u5bdf\u54cd\u5e94\u5934\u4e2d\u662f\u5426\u6709<code>Via<\/code>\u3001<code>X-Cache<\/code>\u7b49\u5b57\u6bb5\uff0c\u6216<code>Set-Cookie<\/code>\u4e2d\u662f\u5426\u6709<code>BIGipServer<\/code>\u8fd9\u7c7b\u8d1f\u8f7d\u5747\u8861\u5668\u7279\u6709\u7684Cookie\u3002<\/li>\n\n\n\n<li><strong>\u5e94\u7528\u5c42\u63a2\u6d4b<\/strong>\uff1a\n<ul class=\"wp-block-list\">\n<li>\u4f7f\u7528<code>whatweb https:\/\/example.com<\/code>\u83b7\u53d6\u6280\u672f\u6808\u7684\u6982\u89c8\u4fe1\u606f\u3002<\/li>\n\n\n\n<li>\u4f7f\u7528<code>curl -I<\/code>\u8bb0\u5f55\u6240\u6709\u54cd\u5e94\u5934\u4fe1\u606f\u3002<\/li>\n\n\n\n<li>\u67e5\u770bHTML\u6e90\u4ee3\u7801\uff08<code>curl https:\/\/example.com<\/code>\uff09\uff0c\u5206\u6790\u5176\u4e2d\u7684\u6ce8\u91ca\u3001JavaScript\u8def\u5f84\u7b49\uff0c\u4ee5\u63a8\u65ad\u524d\u7aef\u6846\u67b6\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u6570\u636e\u5c42\u63a2\u6d4b<\/strong>\uff1a\u5c1d\u8bd5\u8bbf\u95ee\u5e38\u89c1\u7684\u6570\u636e\u5e93\u7ba1\u7406\u8def\u5f84\uff08\u5982<code>\/phpmyadmin<\/code>\u3001<code>\/adminer<\/code>\uff09\u6216\u5728\u53ef\u80fd\u5b58\u5728SQL\u6ce8\u5165\u70b9\u7684\u53c2\u6570\u540e\u6dfb\u52a0\u5f15\u53f7\uff0c\u89c2\u5bdf\u9519\u8bef\u4fe1\u606f\u4e2d\u662f\u5426\u66b4\u9732\u4e86\u6570\u636e\u5e93\u7c7b\u578b\u3002<\/li>\n\n\n\n<li><strong>\u5b89\u5168\u5c42\u8bc6\u522b<\/strong>\uff1a\n<ul class=\"wp-block-list\">\n<li>\u8fd0\u884c<code>wafw00f https:\/\/example.com<\/code>\u68c0\u6d4bWAF\u7c7b\u578b\u3002<\/li>\n\n\n\n<li>\u624b\u52a8\u6784\u9020\u4e00\u4e2a\u6076\u610f\u8bf7\u6c42\uff08\u5982<code>\/?id=1' OR '1'='1<\/code>\uff09\uff0c\u89c2\u5bdf\u54cd\u5e94\u662f\u5426\u4e3a\u62e6\u622a\u9875\u9762\uff0c\u5e76\u8bb0\u5f55\u8be5\u62e6\u622a\u9875\u7684\u7279\u5f81\uff08\u6807\u9898\u3001HTML\u5185\u5bb9\u5173\u952e\u5b57\uff09\u3002<\/li>\n\n\n\n<li>\u68c0\u67e5\u871c\u7f50\u7279\u5f81\uff0c\u5982\u54cd\u5e94\u65f6\u95f4\u5f02\u5e38\uff08\u6240\u6709\u8bf7\u6c42\u5ef6\u8fdf\u51e0\u4e4e\u76f8\u540c\uff09\u3001\u4ea4\u4e92\u8fc7\u4e8e\u5b8c\u7f8e\uff08\u6240\u6709\u4e0d\u5b58\u5728\u7684\u8def\u5f84\u90fd\u8fd4\u56de\u76f8\u540c\u5185\u5bb9\uff09\u3001Cookie\u547d\u540d\u5f02\u5e38\u7b49\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u4fe1\u606f\u6c47\u603b<\/strong>\uff1a\u5c06\u5404\u5c42\u6536\u96c6\u5230\u7684\u4fe1\u606f\u8bb0\u5f55\u5728\u8868\u683c\u4e2d\uff0c\u521d\u6b65\u5efa\u7acb\u8d77\u76ee\u6807\u7684\u5c42\u6b21\u7ed3\u6784\u56fe\u3002<\/li>\n<\/ol>\n\n\n\n<h4 class=\"wp-block-heading\">\u5982\u4f55\u9a8c\u8bc1\u7ed3\u679c\u771f\u5b9e\u6027<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u9a8c\u8bc1\u903b\u8f91<\/strong>\uff1a\u4e0d\u540c\u5c42\u6b21\u7684\u4fe1\u606f\u5e94\u80fd\u76f8\u4e92\u5370\u8bc1\u3002\u4f8b\u5982\uff0c\u5e94\u7528\u5c42\u68c0\u6d4b\u5230Apache\uff0c\u6570\u636e\u5c42\u9519\u8bef\u4fe1\u606f\u63d0\u793aMySQL\uff0c\u8fd9\u662f\u4e00\u4e2a\u5408\u7406\u7684\u6280\u672f\u6808\u7ec4\u5408\uff1b\u82e5\u5e94\u7528\u5c42\u68c0\u6d4b\u5230Nginx\uff0c\u4f46\u54cd\u5e94\u5934\u4e2d\u540c\u65f6\u51fa\u73b0\u4e86IIS\u7684<code>Server<\/code>\u5b57\u6bb5\uff0c\u5219\u53ef\u80fd\u5b58\u5728WAF\u4fee\u6539\u6216\u8d1f\u8f7d\u5747\u8861\u8f6c\u53d1\u3002\u5bf9\u4e8eWAF\uff0c\u53ef\u4ee5\u901a\u8fc7\u53d1\u9001\u4e00\u4e2a\u660e\u663e\u6076\u610f\u7684\u8bf7\u6c42\uff08\u5982<code>\/?id=&lt;script><\/code>\uff09\u6765\u89c2\u5bdf\u662f\u5426\u89e6\u53d1\u62e6\u622a\uff0c\u5e76\u7ed3\u5408\u5de5\u5177\u7684\u8f93\u51fa\u8fdb\u884c\u786e\u8ba4\u3002<\/li>\n\n\n\n<li><strong>\u8f93\u51fa\u5224\u65ad\u4f9d\u636e<\/strong>\uff1a\u4f8b\u5982\uff0cTLS\u8bc1\u4e66\u4e2d\u7684\u7ec4\u7ec7\u5b57\u6bb5\u5e94\u4e0e\u76ee\u6807\u7684\u516c\u5f00\u4fe1\u606f\u4e00\u81f4\uff1b\u4e00\u4e2a\u5305\u542b<code>&lt;!DOCTYPE html>&lt;title>WAF Block&lt;\/title><\/code>\u7279\u5f81\u7684\u62e6\u622a\u9875\u9762\uff0c\u53ef\u4ee5\u4f5c\u4e3aWAF\u5b58\u5728\u7684\u76f4\u63a5\u8bc1\u636e\u3002<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">\u5e38\u89c1\u9519\u8bef\u4e0e\u6392\u67e5\u65b9\u5f0f<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u9519\u8bef<\/strong>\uff1a\u5c06CDN\u7684\u7f13\u5b58\u8282\u70b9\u8bef\u8ba4\u4e3a\u662f\u8d1f\u8f7d\u5747\u8861\u5668\u3002<\/li>\n\n\n\n<li><strong>\u6392\u67e5<\/strong>\uff1aCDN\u901a\u5e38\u62e5\u6709\u591a\u4e2a\u904d\u5e03\u5168\u7403\u7684IP\u5730\u5740\uff0c\u800c\u8d1f\u8f7d\u5747\u8861\u5668\u901a\u5e38\u4f4d\u4e8e\u540c\u4e00\u6570\u636e\u4e2d\u5fc3\u3002\u53ef\u4ee5\u901a\u8fc7\u591a\u5730Ping\u7684\u65b9\u5f0f\uff0c\u89c2\u5bdfIP\u5730\u5740\u662f\u5426\u968f\u5730\u7406\u4f4d\u7f6e\u53d8\u5316\u6765\u5224\u65ad\u662f\u5426\u4e3aCDN\u3002<\/li>\n\n\n\n<li><strong>\u9519\u8bef<\/strong>\uff1a\u8fdb\u884c\u5e94\u7528\u5c42\u8bc6\u522b\u65f6\uff0c\u53ea\u5173\u6ce8<code>Server<\/code>\u5934\uff0c\u800c\u5ffd\u7565\u4e86<code>X-Powered-By<\/code>\u3001<code>X-AspNet-Version<\/code>\u7b49\u53ef\u80fd\u88ab\u9690\u85cf\u6216\u9057\u5fd8\u7684\u5934\u4fe1\u606f\u3002<\/li>\n\n\n\n<li><strong>\u6392\u67e5<\/strong>\uff1a\u4f7f\u7528<code>curl -v<\/code>\u663e\u793a\u6240\u6709\u54cd\u5e94\u5934\u4fe1\u606f\uff0c\u5e76\u5c1d\u8bd5\u4f7f\u7528\u4e0d\u540c\u7684User-Agent\u53d1\u8d77\u8bf7\u6c42\uff0c\u89c2\u5bdf\u54cd\u5e94\u5934\u662f\u5426\u4f1a\u53d1\u751f\u53d8\u5316\u3002<\/li>\n\n\n\n<li><strong>\u9519\u8bef<\/strong>\uff1a\u5c06\u871c\u7f50\u8bef\u5224\u4e3a\u771f\u5b9e\u670d\u52a1\u3002<\/li>\n\n\n\n<li><strong>\u6392\u67e5<\/strong>\uff1a\u871c\u7f50\u901a\u5e38\u4e0d\u63d0\u4f9b\u5b8c\u6574\u7684\u5e94\u7528\u529f\u80fd\u3002\u53ef\u4ee5\u5c1d\u8bd5\u8fdb\u884c\u4e00\u4e9b\u4ea4\u4e92\u64cd\u4f5c\uff08\u5982\u8868\u5355\u63d0\u4ea4\uff09\uff0c\u89c2\u5bdf\u5176\u4e1a\u52a1\u903b\u8f91\u662f\u5426\u5408\u7406\uff1b\u6216\u8005\u5bf9\u6bd4\u4e0d\u540c\u8def\u5f84\u7684\u54cd\u5e94\u65f6\u95f4\uff0c\u871c\u7f50\u53ef\u80fd\u5bf9\u6240\u6709\u8def\u5f84\u90fd\u8fd4\u56de\u76f8\u540c\u7684\u5185\u5bb9\u3002<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">\u5408\u89c4\u8fb9\u754c\u8bf4\u660e<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u7f51\u7edc\u5b89\u5168\u89c6\u89d2<\/strong>\uff1a\u7aef\u53e3\u626b\u63cf\uff08\u5c24\u5176\u662f\u5168\u7aef\u53e3\u626b\u63cf\uff09\u53ef\u80fd\u88ab\u89c6\u4e3a\u5177\u6709\u653b\u51fb\u6027\u7684\u884c\u4e3a\uff0c\u5728\u8fdb\u884c\u6388\u6743\u6d4b\u8bd5\u524d\uff0c\u5fc5\u987b\u83b7\u5f97\u5ba2\u6237\u7684\u4e66\u9762\u8bb8\u53ef\u3002\u867d\u7136TLS\u8bc1\u4e66\u4fe1\u606f\u662f\u516c\u5f00\u7684\uff0c\u4f46\u5927\u89c4\u6a21\u6279\u91cf\u6536\u96c6\u4ecd\u53ef\u80fd\u8fdd\u53cd\u76ee\u6807\u7f51\u7ad9\u7684\u670d\u52a1\u6761\u6b3e\u3002<\/li>\n\n\n\n<li><strong>\u98ce\u9669<\/strong>\uff1a\u672a\u7ecf\u6388\u6743\u8fdb\u884c\u626b\u63cf\u53ef\u80fd\u5f15\u53d1\u6cd5\u5f8b\u7ea0\u7eb7\uff0c\u6216\u89e6\u53d1\u76ee\u6807\u7684\u53cd\u5236\u63aa\u65bd\uff08\u5982IP\u5c01\u7981\uff09\u3002<\/li>\n\n\n\n<li><strong>\u7f13\u89e3\u63aa\u65bd<\/strong>\uff1a\u5efa\u8bae\u4f18\u5148\u4f7f\u7528\u672c\u5730\u642d\u5efa\u7684\u6d4b\u8bd5\u73af\u5883\u6216\u516c\u5f00\u7684\u6d4b\u8bd5\u5e73\u53f0\uff08\u5982<code>scanme.nmap.org<\/code>\u3001<code>httpbin.org<\/code>\uff09\u8fdb\u884c\u7ec3\u4e60\u3002\u5728\u771f\u5b9e\u7684\u6388\u6743\u6d4b\u8bd5\u4e2d\uff0c\u5e94\u4e25\u683c\u63a7\u5236\u626b\u63cf\u901f\u7387\uff0c\u907f\u514d\u5bf9\u76ee\u6807\u4e1a\u52a1\u9020\u6210\u5f71\u54cd\u3002<\/li>\n\n\n\n<li><strong>\u51b3\u7b56\u6307\u5357<\/strong>\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u5fc5\u987b\u7528<\/strong>\uff1a\u5728\u8fdb\u884c\u5168\u9762\u7684\u5b89\u5168\u8bc4\u4f30\u65f6\uff0c\u5fc5\u987b\u5bf9\u5404\u5c42\u7ed3\u6784\u8fdb\u884c\u62c6\u89e3\uff0c\u5426\u5219\u53ef\u80fd\u4f1a\u9057\u6f0f\u9690\u85cf\u5728\u975e\u6807\u51c6\u7aef\u53e3\u6216\u7ec4\u4ef6\u4e2d\u7684\u5b89\u5168\u6f0f\u6d1e\u3002<\/li>\n\n\n\n<li><strong>\u66ff\u4ee3<\/strong>\uff1a\u5982\u679c\u8bc4\u4f30\u8303\u56f4\u4ec5\u9650\u4e8eWeb\u5e94\u7528\u672c\u8eab\uff08\u800c\u975e\u7f51\u7edc\u57fa\u7840\u8bbe\u65bd\uff09\uff0c\u53ef\u4ee5\u8df3\u8fc7\u7f51\u7edc\u5c42\u626b\u63cf\uff0c\u76f4\u63a5\u8fdb\u884c\u5e94\u7528\u5c42\u7684\u8bc6\u522b\u5de5\u4f5c\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">\u672c\u6a21\u5757\u5c0f\u7ed3<\/h4>\n\n\n\n<p>\u901a\u8fc7\u5bf9Web\u5e94\u7528\u8fdb\u884c\u5206\u5c42\u62c6\u89e3\uff0c\u6211\u4eec\u7cfb\u7edf\u5730\u68b3\u7406\u4e86\u4ece\u7f51\u7edc\u5230\u5b89\u5168\u5404\u5c42\u9762\u7684\u6f5c\u5728\u4fe1\u606f\u66b4\u9732\u9762\uff0c\u5e76\u638c\u63e1\u4e86\u76f8\u5e94\u7684\u63a2\u6d4b\u547d\u4ee4\u548c\u5de5\u5177\u3002\u8fd9\u4e9b\u7ed3\u6784\u5316\u7684\u4fe1\u606f\u4e3a\u6211\u4eec\u4e0b\u4e00\u9636\u6bb5<strong>\u5efa\u7acb\u65b9\u6cd5\u6a21\u578b<\/strong>\u63d0\u4f9b\u4e86\u4e30\u5bcc\u7684\u7d20\u6750\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">\u65b9\u6cd5\u6a21\u578b\u5efa\u7acb<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">\u6a21\u5757\u6982\u5ff5\u89e3\u91ca<\/h4>\n\n\n\n<p>\u5f53\u6211\u4eec\u62e5\u6709\u4e86\u7ecf\u8fc7\u62c6\u89e3\u7684\u7ed3\u6784\u8981\u7d20\u540e\uff0c\u63a5\u4e0b\u6765\u9700\u8981\u4e00\u5957\u7cfb\u7edf\u7684\u65b9\u6cd5\u8bba\uff0c\u6765\u6307\u5bfc\u6211\u4eec\u9ad8\u6548\u3001\u51c6\u786e\u5730\u6536\u96c6\u8fd9\u4e9b\u67b6\u6784\u4fe1\u606f\u3002\u672c\u6a21\u5757\u5c06\u4ecb\u7ecd\u56db\u79cd\u6838\u5fc3\u7684\u65b9\u6cd5\u6a21\u578b\uff1a<strong>\u4e3b\u52a8\u63a2\u6d4b\u3001\u88ab\u52a8\u76d1\u542c\u3001\u516c\u5f00\u4fe1\u606f\u641c\u96c6\u3001\u9519\u8bef\u8bf1\u5bfc\u5206\u6790<\/strong>\u3002\u6bcf\u79cd\u65b9\u6cd5\u90fd\u6709\u5176\u9002\u7528\u7684\u573a\u666f\u548c\u56fa\u6709\u7684\u5c40\u9650\u6027\uff0c\u5b66\u4e60\u8005\u9700\u8981\u6839\u636e\u76ee\u6807\u7c7b\u578b\u548c\u6d4b\u8bd5\u9636\u6bb5\uff0c\u7075\u6d3b\u9009\u62e9\u5408\u9002\u7684\u7b56\u7565\u7ec4\u5408\u3002\u65b9\u6cd5\u6a21\u578b\u7684\u5efa\u7acb\uff0c\u5c06\u4f7f\u6211\u4eec\u7684\u4fe1\u606f\u6536\u96c6\u5de5\u4f5c\u4ece\u968f\u673a\u7684\u6d4b\u8bd5\u8f6c\u53d8\u4e3a\u6709\u7b56\u7565\u7684\u4fa6\u5bdf\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u6280\u672f\u539f\u7406\u8bf4\u660e<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u4e3b\u52a8\u63a2\u6d4b<\/strong>\uff1a\u901a\u8fc7\u5411\u76ee\u6807\u53d1\u9001\u7cbe\u5fc3\u6784\u9020\u7684\u8bf7\u6c42\uff0c\u5e76\u6839\u636e\u5176\u54cd\u5e94\u5dee\u5f02\u6765\u63a8\u65ad\u5185\u90e8\u7ec4\u4ef6\u3002\u5176\u539f\u7406\u5728\u4e8e\uff0c\u4e0d\u540c\u7684\u7ec4\u4ef6\u5bf9\u7279\u5b9a\u8f93\u5165\u7684\u5904\u7406\u65b9\u5f0f\u4e0d\u540c\uff08\u4f8b\u5982\uff0cWAF\u4f1a\u62e6\u622a\u6076\u610f\u8bf7\u6c42\uff0c\u800c\u5e94\u7528\u5219\u4e0d\u4f1a\uff09\u3002\u4f18\u70b9\u662f\u76f4\u63a5\u3001\u53ef\u63a7\uff1b\u7f3a\u70b9\u662f\u53ef\u80fd\u89e6\u53d1\u9632\u5fa1\u673a\u5236\u3002<\/li>\n\n\n\n<li><strong>\u88ab\u52a8\u76d1\u542c<\/strong>\uff1a\u901a\u8fc7\u5206\u6790\u6b63\u5e38\u7684\u6d41\u91cf\uff08\u5982\u6d4f\u89c8\u5668\u8bbf\u95ee\u4ea7\u751f\u7684\u6570\u636e\u3001\u516c\u5f00\u53ef\u7528\u7684\u6570\u636e\uff09\u6765\u83b7\u53d6\u4fe1\u606f\uff0c\u6574\u4e2a\u8fc7\u7a0b\u4e0d\u4e3b\u52a8\u5411\u76ee\u6807\u53d1\u9001\u4efb\u4f55\u8bf7\u6c42\u3002\u5176\u539f\u7406\u662f\uff0c\u7ec4\u4ef6\u4fe1\u606f\u53ef\u80fd\u9690\u542b\u5728\u54cd\u5e94\u5934\u3001HTML\u6ce8\u91ca\u3001JS\u6587\u4ef6\u6216Cookie\u4e2d\u3002\u4f18\u70b9\u662f\u65e0\u75d5\u3001\u5b89\u5168\uff1b\u7f3a\u70b9\u662f\u83b7\u53d6\u7684\u4fe1\u606f\u91cf\u6709\u9650\u3002<\/li>\n\n\n\n<li><strong>\u516c\u5f00\u4fe1\u606f\u641c\u96c6<\/strong>\uff1a\u5229\u7528\u641c\u7d22\u5f15\u64ce\u3001\u4ee3\u7801\u6258\u7ba1\u5e73\u53f0\u3001\u5386\u53f2\u5b58\u6863\u7f51\u7ad9\u7b49\u516c\u5f00\u8d44\u6e90\uff0c\u6316\u6398\u4e0e\u76ee\u6807\u67b6\u6784\u76f8\u5173\u7684\u7ebf\u7d22\u3002\u5176\u539f\u7406\u662f\uff0c\u5f00\u53d1\u6216\u8fd0\u7ef4\u4eba\u5458\u53ef\u80fd\u5728\u65e0\u610f\u4e2d\u66b4\u9732\u4e86\u6280\u672f\u6808\u4fe1\u606f\uff08\u5982\u5728GitHub\u4e0a\u6cc4\u9732\u4e86\u914d\u7f6e\u6587\u4ef6\uff09\u3002\u4f18\u70b9\u662f\u4fe1\u606f\u91cf\u5927\uff1b\u7f3a\u70b9\u662f\u9700\u8981\u4e00\u5b9a\u7684\u641c\u7d22\u6280\u5de7\uff0c\u4e14\u53ef\u80fd\u6d89\u53ca\u9690\u79c1\u8fb9\u754c\u3002<\/li>\n\n\n\n<li><strong>\u9519\u8bef\u8bf1\u5bfc\u5206\u6790<\/strong>\uff1a\u901a\u8fc7\u6545\u610f\u89e6\u53d1\u9519\u8bef\uff08\u5982\u8bbf\u95ee\u4e0d\u5b58\u5728\u7684\u8def\u5f84\uff09\uff0c\u89c2\u5bdf\u76ee\u6807\u8fd4\u56de\u7684\u9519\u8bef\u9875\u9762\u4e2d\u662f\u5426\u6cc4\u9732\u4e86\u5806\u6808\u4fe1\u606f\u6216\u6570\u636e\u5e93\u7c7b\u578b\u3002\u5176\u539f\u7406\u662f\uff0c\u9ed8\u8ba4\u7684\u9519\u8bef\u5904\u7406\u673a\u5236\u53ef\u80fd\u4f1a\u66b4\u9732\u5185\u90e8\u8def\u5f84\u3001\u7248\u672c\u53f7\u7b49\u654f\u611f\u4fe1\u606f\u3002\u4f18\u70b9\u662f\u80fd\u76f4\u63a5\u83b7\u53d6\u5185\u90e8\u7ec6\u8282\uff1b\u7f3a\u70b9\u662f\u53ef\u80fd\u88abWAF\u62e6\u622a\uff0c\u6216\u76ee\u6807\u5e94\u7528\u5df2\u81ea\u5b9a\u4e49\u4e86\u9519\u8bef\u9875\u9762\u3002<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">\u5728\u7cfb\u7edf\u4e2d\u7684\u4f4d\u7f6e<\/h4>\n\n\n\n<p>\u672c\u6a21\u5757\u4f4d\u4e8e\u201c\u5173\u952e\u7ed3\u6784\u62c6\u89e3\u201d\u4e4b\u540e\uff0c\u201c\u64cd\u4f5c\u8def\u5f84\u5f62\u6210\u201d\u4e4b\u524d\u3002\u5b83\u7684\u4f5c\u7528\u662f\u5c06\u524d\u4e00\u6b65\u62c6\u89e3\u51fa\u7684\u5404\u4e2a\u8981\u7d20\uff0c\u4e0e\u5177\u4f53\u7684\u4fe1\u606f\u6536\u96c6\u65b9\u6cd5\u4e00\u4e00\u5bf9\u5e94\u8d77\u6765\uff0c\u4e3a\u540e\u7eed\u5236\u5b9a\u8be6\u7ec6\u7684\u64cd\u4f5c\u6b65\u9aa4\u63d0\u4f9b\u575a\u5b9e\u7684\u7406\u8bba\u4f9d\u636e\u3002\u4f8b\u5982\uff0c\u8bc6\u522bWAF\u53ef\u4ee5\u7ed3\u5408\u4e3b\u52a8\u63a2\u6d4b\uff08\u53d1\u9001\u6076\u610f\u8bf7\u6c42\uff09\u548c\u88ab\u52a8\u76d1\u542c\uff08\u5206\u6790\u62e6\u622a\u9875\u7279\u5f81\uff09\u4e24\u79cd\u65b9\u6cd5\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u53ef\u6267\u884c\u547d\u4ee4\u6216\u67e5\u8be2\u65b9\u5f0f<\/h4>\n\n\n\n<p>\u4ee5\u4e0b\u547d\u4ee4\u5206\u522b\u6f14\u793a\u4e86\u4e0d\u540c\u65b9\u6cd5\u7684\u5e94\u7528\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># \u4e3b\u52a8\u63a2\u6d4b\uff1a\u4f7f\u7528curl\u53d1\u9001\u4e00\u4e2a\u5305\u542bSQL\u6ce8\u5165\u7279\u5f81\u7684\u53ef\u7591\u8bf7\u6c42\uff0c\u89c2\u5bdfWAF\u662f\u5426\u4f1a\u62e6\u622a\ncurl -I \"https:\/\/httpbin.org\/anything?q=1' UNION SELECT NULL--\"\n\n# \u88ab\u52a8\u76d1\u542c\uff1a\u4f7f\u7528\u6d4f\u89c8\u5668\u8bbf\u95ee\u76ee\u6807\uff0c\u5728\u5f00\u53d1\u8005\u5de5\u5177\u7684\u201c\u7f51\u7edc\u201d\u6807\u7b7e\u4e2d\uff0c\u67e5\u770b\u6240\u6709\u54cd\u5e94\u5934\u548cCookie\uff0c\u8bb0\u5f55\u4e0bServer\u3001X-Powered-By\u7b49\u4fe1\u606f\n\n# \u516c\u5f00\u4fe1\u606f\u641c\u96c6\uff1a\u4f7f\u7528\u641c\u7d22\u5f15\u64ce\u7684\u7279\u5b9a\u8bed\u6cd5\u8fdb\u884c\u641c\u7d22\uff0c\u4f8b\u5982 site:example.com inurl:phpinfo.php\n\n# \u9519\u8bef\u8bf1\u5bfc\u5206\u6790\uff1a\u8bbf\u95ee\u4e00\u4e2a\u4e0d\u5b58\u5728\u7684\u8def\u5f84\uff0c\u89c2\u5bdf404\u9875\u9762\u662f\u5426\u66b4\u9732\u4e86\u670d\u52a1\u5668\u4fe1\u606f\ncurl https:\/\/httpbin.org\/nonexistent<\/code><\/pre>\n\n\n\n<h4 class=\"wp-block-heading\">\u5de5\u5177\u5bf9\u6bd4\u8868<\/h4>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u65b9\u6cd5<\/th><th>\u5de5\u5177\u793a\u4f8b<\/th><th>\u4f18\u70b9<\/th><th>\u5c40\u9650<\/th><\/tr><\/thead><tbody><tr><td>\u4e3b\u52a8\u63a2\u6d4b<\/td><td><code>curl<\/code>, <code>nmap<\/code>, <code>sqlmap<\/code>\uff08\u4ec5\u68c0\u6d4b\u6a21\u5f0f\uff09<\/td><td>\u53ef\u63a7\u6027\u5f3a\uff0c\u53ef\u5b9a\u5411\u83b7\u53d6\u7279\u5b9a\u4fe1\u606f<\/td><td>\u6613\u89e6\u53d1\u9632\u5fa1\u7cfb\u7edf\uff0c\u53ef\u80fd\u88ab\u8bb0\u5f55\u65e5\u5fd7<\/td><\/tr><tr><td>\u88ab\u52a8\u76d1\u542c<\/td><td>\u6d4f\u89c8\u5668DevTools, Wireshark<\/td><td>\u65e0\u75d5\u64cd\u4f5c\uff0c\u4e0d\u4ea7\u751f\u4efb\u4f55\u5b89\u5168\u98ce\u9669<\/td><td>\u53ea\u80fd\u83b7\u53d6\u5230\u5df2\u7ecf\u66b4\u9732\u7684\u4fe1\u606f<\/td><\/tr><tr><td>\u516c\u5f00\u4fe1\u606f\u641c\u96c6<\/td><td>Google, GitHub, Shodan<\/td><td>\u53ef\u80fd\u53d1\u73b0\u610f\u60f3\u4e0d\u5230\u7684\u654f\u611f\u4fe1\u606f<\/td><td>\u4f9d\u8d56\u641c\u7d22\u5f15\u64ce\u7684\u66f4\u65b0\uff0c\u4fe1\u606f\u53ef\u80fd\u8fc7\u65f6<\/td><\/tr><tr><td>\u9519\u8bef\u8bf1\u5bfc\u5206\u6790<\/td><td><code>curl<\/code>, Burp Suite<\/td><td>\u53ef\u83b7\u53d6\u5e94\u7528\u5185\u90e8\u8def\u5f84\u548c\u7248\u672c\u4fe1\u606f<\/td><td>\u53ef\u80fd\u88ab\u81ea\u5b9a\u4e49\u7684\u9519\u8bef\u9875\u9762\u6240\u63a9\u76d6<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h4 class=\"wp-block-heading\">\u6807\u51c6\u64cd\u4f5c\u6b65\u9aa4<\/h4>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u786e\u5b9a\u76ee\u6807\u8303\u56f4<\/strong>\uff1a\u660e\u786e\u672c\u6b21\u8981\u6536\u96c6\u7684\u7ec4\u4ef6\u6e05\u5355\uff08\u5982WAF\u7c7b\u578b\u3001\u6570\u636e\u5e93\u7248\u672c\uff09\u3002<\/li>\n\n\n\n<li><strong>\u9009\u62e9\u65b9\u6cd5\u7ec4\u5408<\/strong>\uff1a\u6839\u636e\u76ee\u6807\u7279\u70b9\u5236\u5b9a\u7b56\u7565\u3002\u4f8b\u5982\uff0c\u5148\u8fdb\u884c\u88ab\u52a8\u76d1\u542c\uff08\u8bbf\u95ee\u9996\u9875\u3001\u767b\u5f55\u9875\uff09\uff0c\u8bb0\u5f55\u6240\u6709\u54cd\u5e94\u5934\u548c\u9759\u6001\u8d44\u6e90\u4fe1\u606f\uff1b\u518d\u8fdb\u884c\u4e3b\u52a8\u63a2\u6d4b\uff08\u53d1\u9001\u51e0\u4e2a\u5e38\u89c1\u7684\u6076\u610fPayload\uff09\uff0c\u89c2\u5bdf\u662f\u5426\u4f1a\u89e6\u53d1WAF\uff1b\u6700\u540e\u5c1d\u8bd5\u9519\u8bef\u8bf1\u5bfc\uff08\u8bbf\u95ee\u4e0d\u5b58\u5728\u7684\u8def\u5f84\uff09\uff0c\u5206\u6790\u5176404\u9875\u9762\u3002<\/li>\n\n\n\n<li><strong>\u6267\u884c\u4e3b\u52a8\u63a2\u6d4b<\/strong>\uff1a\u4f7f\u7528<code>curl<\/code>\u9010\u4e2a\u6d4b\u8bd5\u5e38\u89c1\u7684WAF\u7ed5\u8fc7Payload\uff08\u5982\u5927\u5c0f\u5199\u53d8\u5f02\u3001\u7f16\u7801\u6df7\u6dc6\uff09\uff0c\u5e76\u8bb0\u5f55\u6bcf\u6b21\u8bf7\u6c42\u7684\u54cd\u5e94\u72b6\u6001\u7801\u548c\u5185\u5bb9\u957f\u5ea6\u53d8\u5316\u3002<\/li>\n\n\n\n<li><strong>\u6267\u884c\u516c\u5f00\u4fe1\u606f\u641c\u96c6<\/strong>\uff1a\u5728Google\u4e2d\u5c1d\u8bd5\u641c\u7d22<code>intitle:\"index of\" \"phpinfo.php\" site:example.com<\/code>\uff0c\u4ee5\u53d1\u73b0\u53ef\u80fd\u6cc4\u9732\u7684\u6587\u4ef6\u3002<\/li>\n\n\n\n<li><strong>\u6267\u884c\u9519\u8bef\u8bf1\u5bfc<\/strong>\uff1a\u8bbf\u95ee\u4e00\u4e2a\u968f\u673a\u751f\u6210\u7684\u4e0d\u5b58\u5728\u7684\u8def\u5f84\uff0c\u5982<code>\/asdf1234.php<\/code>\uff0c\u89c2\u5bdf\u54cd\u5e94\u5185\u5bb9\u4e2d\u662f\u5426\u5305\u542b<code>Apache<\/code>\u3001<code>Nginx<\/code>\u6216<code>PHP<\/code>\u7b49\u7248\u672c\u4fe1\u606f\u3002<\/li>\n\n\n\n<li><strong>\u8fdb\u884c\u4ea4\u53c9\u9a8c\u8bc1<\/strong>\uff1a\u5c06\u4e3b\u52a8\u63a2\u6d4b\u5f97\u5230\u7684WAF\u7c7b\u578b\uff0c\u4e0e\u4ece\u516c\u5f00\u4fe1\u606f\u4e2d\u53ef\u80fd\u63d0\u53ca\u7684\u8be5\u76ee\u6807\u4f7f\u7528\u7684\u9632\u62a4\u670d\u52a1\u8fdb\u884c\u5bf9\u6bd4\uff0c\u786e\u8ba4\u5176\u4e00\u81f4\u6027\u3002<\/li>\n\n\n\n<li><strong>\u8bb0\u5f55\u65b9\u6cd5\u6709\u6548\u6027<\/strong>\uff1a\u5728\u6700\u7ec8\u7684\u62a5\u544a\u4e2d\uff0c\u6ce8\u660e\u6bcf\u79cd\u65b9\u6cd5\u83b7\u53d6\u5230\u7684\u4fe1\u606f\u53ca\u5176\u7f6e\u4fe1\u5ea6\u3002<\/li>\n<\/ol>\n\n\n\n<h4 class=\"wp-block-heading\">\u5982\u4f55\u9a8c\u8bc1\u7ed3\u679c\u771f\u5b9e\u6027<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u9a8c\u8bc1\u903b\u8f91<\/strong>\uff1a\u5f53\u591a\u79cd\u4e0d\u540c\u7684\u65b9\u6cd5\u90fd\u6307\u5411\u540c\u4e00\u4e2a\u4fe1\u606f\u65f6\uff0c\u8be5\u4fe1\u606f\u7684\u53ef\u4fe1\u5ea6\u5c31\u975e\u5e38\u9ad8\u3002\u4f8b\u5982\uff0c\u4e3b\u52a8\u63a2\u6d4b\u53d1\u73b0\u4e86WAF\u62e6\u622a\u884c\u4e3a\uff0c\u88ab\u52a8\u76d1\u542c\u4e2d\u62e6\u622a\u9875\u7684HTML\u7279\u5f81\u4e0e\u67d0\u6b3e\u77e5\u540dWAF\u4e00\u81f4\uff0c\u540c\u65f6\u516c\u5f00\u4fe1\u606f\u4e2d\u4e5f\u63d0\u5230\u8be5\u76ee\u6807\u4f7f\u7528\u4e86\u8fd9\u6b3eWAF\uff0c\u90a3\u4e48\u7ed3\u8bba\u5c31\u975e\u5e38\u53ef\u9760\u3002<\/li>\n\n\n\n<li><strong>\u8f93\u51fa\u5224\u65ad\u4f9d\u636e<\/strong>\uff1a\u4f8b\u5982\uff0c\u4e3b\u52a8\u63a2\u6d4b\u65f6\u53d1\u9001<code>\/?id=1'<\/code>\u8fd4\u56de\u4e86403\u72b6\u6001\u7801\uff0c\u4e14\u54cd\u5e94\u4f53\u4e2d\u5305\u542b<code>ModSecurity<\/code>\u5b57\u6837\uff0c\u53ef\u4ee5\u5224\u65ad\u4e3aModSecurity WAF\uff1b\u540c\u65f6\uff0c\u88ab\u52a8\u76d1\u542c\u4e2d\u54cd\u5e94\u5934\u7684<code>Server<\/code>\u5b57\u6bb5\u4e3a<code>Apache<\/code>\uff0c\u4e24\u8005\u76f8\u4e92\u5370\u8bc1\u3002<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">\u5e38\u89c1\u9519\u8bef\u4e0e\u6392\u67e5\u65b9\u5f0f<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u9519\u8bef<\/strong>\uff1a\u4e3b\u52a8\u63a2\u6d4b\u65f6\u4f7f\u7528\u4e86\u8fc7\u4e8e\u660e\u663e\u7684\u653b\u51fbPayload\uff0c\u5bfc\u81f4WAF\u5c01\u7981\u4e86IP\uff0c\u5f71\u54cd\u540e\u7eed\u6240\u6709\u6d4b\u8bd5\u3002<\/li>\n\n\n\n<li><strong>\u6392\u67e5<\/strong>\uff1a\u4f18\u5148\u4f7f\u7528\u4f4e\u98ce\u9669\u7684Payload\uff08\u5982\u4e00\u4e2a\u5355\u72ec\u7684\u5f15\u53f7<code>'<\/code>\uff09\u8fdb\u884c\u6d4b\u8bd5\u3002\u5982\u679c\u89e6\u53d1\u4e86\u62e6\u622a\uff0c\u5e94\u6682\u505c\u63a2\u6d4b\uff0c\u6216\u66f4\u6362\u4ee3\u7406IP\uff0c\u6216\uff08\u5728\u6388\u6743\u6d4b\u8bd5\u4e2d\uff09\u53ca\u65f6\u901a\u77e5\u7ba1\u7406\u5458\u3002<\/li>\n\n\n\n<li><strong>\u9519\u8bef<\/strong>\uff1a\u8fdb\u884c\u516c\u5f00\u4fe1\u606f\u641c\u96c6\u65f6\uff0c\u8bef\u5c06\u7b2c\u4e09\u65b9\u6d4b\u8bd5\u7f51\u7ad9\u7684\u7f13\u5b58\u5185\u5bb9\u5f53\u4f5c\u76ee\u6807\u672c\u8eab\u7684\u4fe1\u606f\u3002<\/li>\n\n\n\n<li><strong>\u6392\u67e5<\/strong>\uff1a\u4ed4\u7ec6\u9a8c\u8bc1\u4fe1\u606f\u6765\u6e90\u7684\u65f6\u6548\u6027\u548c\u57df\u540d\uff0c\u786e\u4fdd\u5176\u4e3a\u5b98\u65b9\u57df\u540d\u6216\u53ef\u4fe1\u7684\u5b58\u6863\u670d\u52a1\u3002<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">\u5408\u89c4\u8fb9\u754c\u8bf4\u660e<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u7f51\u7edc\u5b89\u5168\u89c6\u89d2<\/strong>\uff1a\u4e3b\u52a8\u63a2\u6d4b\u53ef\u80fd\u88ab\u76ee\u6807\u89c6\u4e3a\u653b\u51fb\u884c\u4e3a\uff0c\u5c24\u5176\u662f\u5728\u4f7f\u7528\u81ea\u52a8\u5316\u5de5\u5177\u65f6\u3002\u516c\u5f00\u4fe1\u606f\u641c\u96c6\u4e5f\u53ef\u80fd\u65e0\u610f\u4e2d\u8bbf\u95ee\u5230\u975e\u516c\u5f00\u6570\u636e\uff08\u5982GitHub\u4e0a\u7684\u79c1\u6709\u4ed3\u5e93\u6cc4\u9732\uff09\uff0c\u9700\u6ce8\u610f\u6cd5\u5f8b\u8fb9\u754c\u3002<\/li>\n\n\n\n<li><strong>\u98ce\u9669<\/strong>\uff1a\u672a\u7ecf\u6388\u6743\u7684\u4e3b\u52a8\u63a2\u6d4b\u53ef\u80fd\u5bfc\u81f4\u6cd5\u5f8b\u8d23\u4efb\uff1b\u516c\u5f00\u4fe1\u606f\u641c\u96c6\u53ef\u80fd\u8fdd\u53cd\u76ee\u6807\u7f51\u7ad9\u7684\u670d\u52a1\u6761\u6b3e\u3002<\/li>\n\n\n\n<li><strong>\u7f13\u89e3\u63aa\u65bd<\/strong>\uff1a\u6240\u6709\u64cd\u4f5c\u5fc5\u987b\u5728\u660e\u786e\u7684\u6388\u6743\u8303\u56f4\u5185\u8fdb\u884c\uff1b\u4f18\u5148\u4f7f\u7528\u516c\u5f00\u6d4b\u8bd5\u5e73\u53f0\u8fdb\u884c\u7ec3\u4e60\u3002\u5bf9\u4e8e\u771f\u5b9e\u76ee\u6807\uff0c\u82e5\u65e0\u4e66\u9762\u8bb8\u53ef\uff0c\u5e94\u4ec5\u9650\u4e8e\u88ab\u52a8\u76d1\u542c\u548c\u516c\u5f00\u4fe1\u606f\u641c\u96c6\u3002<\/li>\n\n\n\n<li><strong>\u51b3\u7b56\u6307\u5357<\/strong>\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u5fc5\u987b\u7528<\/strong>\uff1a\u5728\u4e13\u4e1a\u7684\u6e17\u900f\u6d4b\u8bd5\u4e2d\uff0c\u5fc5\u987b\u7ed3\u5408\u591a\u79cd\u65b9\u6cd5\uff0c\u56e0\u4e3a\u5355\u4e00\u65b9\u6cd5\u65e0\u6cd5\u8986\u76d6\u6240\u6709\u7684\u4fe1\u606f\u7ef4\u5ea6\u3002<\/li>\n\n\n\n<li><strong>\u66ff\u4ee3<\/strong>\uff1a\u5982\u679c\u5df2\u7ecf\u660e\u786e\u77e5\u9053\u76ee\u6807\u7684\u6280\u672f\u6808\uff0c\u4e14\u65e0\u9700\u786e\u8ba4\u7ec6\u8282\uff0c\u53ef\u4ee5\u51cf\u5c11\u4e3b\u52a8\u63a2\u6d4b\u7684\u5f3a\u5ea6\uff0c\u4fa7\u91cd\u4e8e\u88ab\u52a8\u76d1\u542c\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">\u672c\u6a21\u5757\u5c0f\u7ed3<\/h4>\n\n\n\n<p>\u672c\u6a21\u5757\u4e3a\u60a8\u5efa\u7acb\u4e86\u56db\u79cd\u6838\u5fc3\u7684\u4fe1\u606f\u6536\u96c6\u65b9\u6cd5\u6a21\u578b\uff0c\u4f7f\u60a8\u80fd\u591f\u6839\u636e\u4e0d\u540c\u7684\u573a\u666f\u7075\u6d3b\u9009\u62e9\u7b56\u7565\u3002\u65b9\u6cd5\u6a21\u578b\u7684\u5efa\u7acb\uff0c\u5c06\u524d\u671f\u7684\u7406\u8bba\u77e5\u8bc6\u8f6c\u5316\u4e3a\u4e86\u53ef\u64cd\u4f5c\u7684\u884c\u52a8\u6307\u5357\u3002\u5728\u4e0b\u4e00\u6a21\u5757\uff0c\u6211\u4eec\u5c06\u57fa\u4e8e\u8fd9\u4e9b\u65b9\u6cd5\uff0c\u5f62\u6210\u4e00\u5957\u5177\u4f53\u7684\u3001\u4e00\u6b65\u6b65\u7684\u64cd\u4f5c\u8def\u5f84\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">\u64cd\u4f5c\u8def\u5f84\u5f62\u6210<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">\u6a21\u5757\u6982\u5ff5\u89e3\u91ca<\/h4>\n\n\n\n<p>\u62e5\u6709\u4e86\u65b9\u6cd5\u6a21\u578b\u540e\uff0c\u6211\u4eec\u9700\u8981\u5c06\u5b83\u4eec\u7ec4\u7ec7\u6210\u4e00\u4e2a\u7cfb\u7edf\u5316\u7684\u63a2\u6d4b\u6d41\u7a0b\uff0c\u8fd9\u4fbf\u662f\u64cd\u4f5c\u8def\u5f84\u3002\u672c\u6a21\u5757\u5c06\u4e3a\u60a8\u5236\u5b9a\u4e00\u6761\u4ece\u4fe1\u606f\u6536\u96c6\u5f00\u59cb\u5230\u7ed3\u675f\u7684\u5b8c\u6574\u6b65\u9aa4\uff0c\u6db5\u76d6\u57df\u540d\u89e3\u6790\u3001\u7aef\u53e3\u626b\u63cf\u3001\u670d\u52a1\u8bc6\u522b\u3001\u76ee\u5f55\u63a2\u6d4b\u3001WAF\u6307\u7eb9\u8bc6\u522b\u3001\u871c\u7f50\u8bc6\u522b\u7b49\u5173\u952e\u73af\u8282\uff0c\u786e\u4fdd\u6bcf\u4e00\u6b65\u90fd\u6709\u660e\u786e\u7684\u76ee\u7684\u548c\u8f93\u51fa\uff0c\u907f\u514d\u91cd\u590d\u52b3\u52a8\u6216\u5173\u952e\u4fe1\u606f\u9057\u6f0f\u3002\u8fd9\u6761\u64cd\u4f5c\u8def\u5f84\u7684\u8bbe\u8ba1\u9075\u5faa <strong>\u201c\u7531\u5916\u5411\u5185\u3001\u7531\u6d45\u5165\u6df1\u201d<\/strong> \u7684\u539f\u5219\uff0c\u5373\u5148\u4ece\u98ce\u9669\u6700\u4f4e\u7684\u4fe1\u606f\u5f00\u59cb\u6536\u96c6\uff0c\u518d\u9010\u6b65\u6df1\u5165\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u6280\u672f\u539f\u7406\u8bf4\u660e<\/h4>\n\n\n\n<p>\u64cd\u4f5c\u8def\u5f84\u7684\u5e95\u5c42\u903b\u8f91\u662f <strong>\u201c\u4fe1\u606f\u589e\u76ca\u201d<\/strong>\u548c <strong>\u201c\u98ce\u9669\u63a7\u5236\u201d<\/strong> \u7684\u5e73\u8861\u3002\u6211\u4eec\u4ece\u6700\u5916\u5c42\u3001\u6700\u4e0d\u5bb9\u6613\u89e6\u53d1\u9632\u5fa1\u7684\u4fe1\u606f\u5f00\u59cb\uff08\u5982DNS\u3001\u8bc1\u4e66\uff09\uff1b\u7136\u540e\u9010\u6b65\u6df1\u5165\u5230\u53ef\u80fd\u89e6\u53d1IDS\u7684\u7aef\u53e3\u626b\u63cf\u3001\u53ef\u80fd\u88ab\u65e5\u5fd7\u8bb0\u5f55\u7684\u670d\u52a1\u8bc6\u522b\u3001\u53ef\u80fd\u89e6\u53d1WAF\u89c4\u5219\u7684\u76ee\u5f55\u63a2\u6d4b\uff1b\u6700\u540e\u624d\u662f\u53ef\u80fd\u5f15\u53d1\u53cd\u5236\u7684WAF\u6307\u7eb9\u548c\u871c\u7f50\u8bc6\u522b\u3002\u6bcf\u4e00\u6b65\u7684\u7ed3\u679c\u90fd\u5c06\u7528\u4e8e\u8c03\u6574\u540e\u7eed\u7b56\u7565\u3002\u4f8b\u5982\uff0c\u4e00\u65e6\u53d1\u73b0WAF\u7684\u5b58\u5728\uff0c\u540e\u7eed\u63a2\u6d4b\u5c31\u9700\u8981\u964d\u4f4e\u901f\u7387\u3001\u4f7f\u7528\u66f4\u9690\u853d\u7684Payload\u3002\u8fd9\u79cd\u8bbe\u8ba1\u65e8\u5728\u6700\u5927\u5316\u4fe1\u606f\u6536\u96c6\u6548\u7387\u7684\u540c\u65f6\uff0c\u6700\u5c0f\u5316\u88ab\u76ee\u6807\u963b\u65ad\u7684\u98ce\u9669\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u5728\u7cfb\u7edf\u4e2d\u7684\u4f4d\u7f6e<\/h4>\n\n\n\n<p>\u672c\u6a21\u5757\u662f\u201c\u65b9\u6cd5\u6a21\u578b\u5efa\u7acb\u201d\u7684\u5177\u4f53\u5316\u4ea7\u7269\uff0c\u5b83\u5c06\u65b9\u6cd5\u8bba\u8f6c\u5316\u4e3a\u4e00\u7cfb\u5217\u53ef\u6267\u884c\u7684\u6b65\u9aa4\u5e8f\u5217\u3002\u5b83\u76f4\u63a5\u6307\u5bfc\u60a8\u8fdb\u884c\u5b9e\u9645\u64cd\u4f5c\uff0c\u5e76\u4e3a\u540e\u7eed\u7684\u201c\u98ce\u9669\u4e0e\u8fb9\u754c\u63a7\u5236\u201d\u63d0\u4f9b\u4e86\u5177\u4f53\u7684\u4e0a\u4e0b\u6587\u3002\u672c\u6a21\u5757\u7684\u8f93\u51fa\uff0c\u5c06\u662f\u4e0b\u4e00\u6a21\u5757\uff08\u98ce\u9669\u63a7\u5236\uff09\u7684\u8f93\u5165\uff0c\u4e5f\u662f\u6700\u7ec8\u201c\u80fd\u529b\u6574\u5408\u8f93\u51fa\u201d\u7684\u6570\u636e\u6765\u6e90\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u53ef\u6267\u884c\u547d\u4ee4\u6216\u67e5\u8be2\u65b9\u5f0f<\/h4>\n\n\n\n<p>\u4ee5\u4e0b\u662f\u4e00\u4e2a\u7b80\u5316\u7684\u64cd\u4f5c\u8def\u5f84\u793a\u4f8b\uff0c\u76ee\u6807\u4e3a<code>example.com<\/code>\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># Step 1: DNS \u4fe1\u606f\u6536\u96c6\n# \u6ce8\u610f\uff1adig ANY \u67e5\u8be2\u5728\u5b9e\u9645\u4e2d\u5e38\u88ab\u9012\u5f52\u670d\u52a1\u5668\u9650\u5236\uff0c\u66f4\u53ef\u9760\u7684\u65b9\u5f0f\u662f\u9010\u4e00\u67e5\u8be2\u5e38\u89c1\u8bb0\u5f55\u7c7b\u578b\u3002\ndig example.com A +noall +answer\ndig example.com MX +noall +answer\ndig example.com TXT +noall +answer\n\n# Step 2: \u57fa\u4e8eDNS\u7ed3\u679c\uff0c\u4f7f\u7528nmap\u626b\u63cf\u5e38\u89c1\u7aef\u53e3\uff08\u9700\u6388\u6743\uff09\nnmap -sS -p 80,443,8080,8443 example.com\n\n# Step 3: Web\u670d\u52a1\u8bc6\u522b\nwhatweb https:\/\/example.com\n\n# Step 4: WAF\u68c0\u6d4b\nwafw00f https:\/\/example.com\n\n# Step 5: \u76ee\u5f55\u679a\u4e3e\uff08\u4f7f\u7528dirb\uff0c\u6ce8\u610f\u63a7\u5236\u901f\u7387\uff09\ndirb https:\/\/example.com \/usr\/share\/wordlists\/dirb\/common.txt -r -z 100\n\n# Step 6: \u871c\u7f50\u7279\u5f81\u68c0\u6d4b\uff08\u5982\u68c0\u67e5\u54cd\u5e94\u4e00\u81f4\u6027\uff09\nfor path in \/ \/admin \/login \/wp-admin; do\n    curl -s -o \/dev\/null -w \"%{http_code} %{time_total}\\n\" https:\/\/example.com$path\ndone<\/code><\/pre>\n\n\n\n<p><strong>\u3010\u8865\u5145\u8bf4\u660e\u3011<\/strong>\uff1a\u4f7f\u7528<code>dig ANY<\/code>\u67e5\u8be2\u5728\u5b9e\u9645\u4e2d\u5e38\u88ab\u9012\u5f52\u670d\u52a1\u5668\u9650\u5236\uff0c\u8fd4\u56de\u7ed3\u679c\u53ef\u80fd\u4e0d\u5b8c\u6574\u3002\u66f4\u53ef\u9760\u7684\u65b9\u5f0f\u662f\u9010\u4e00\u67e5\u8be2\u5e38\u89c1\u8bb0\u5f55\u7c7b\u578b\uff08A\u3001AAAA\u3001MX\u3001TXT\u7b49\uff09\uff0c\u6b64\u884c\u4e3a\u4f9d\u636e\u4e3aIETF RFC 9619\u5bf9DNS\u67e5\u8be2\u7684\u89c4\u8303\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u5de5\u5177\u5bf9\u6bd4\u8868\uff08\u9488\u5bf9\u8def\u5f84\u4e2d\u7684\u6b65\u9aa4\uff09<\/h4>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u6b65\u9aa4<\/th><th>\u5de5\u5177<\/th><th>\u4f5c\u7528<\/th><th>\u66ff\u4ee3\u5de5\u5177<\/th><\/tr><\/thead><tbody><tr><td>DNS\u6536\u96c6<\/td><td><code>dig<\/code><\/td><td>\u83b7\u53d6A\/AAAA\/CNAME\/MX\u7b49\u8bb0\u5f55<\/td><td><code>nslookup<\/code>, <code>host<\/code><\/td><\/tr><tr><td>\u7aef\u53e3\u626b\u63cf<\/td><td><code>nmap<\/code><\/td><td>\u53d1\u73b0\u5f00\u653e\u7aef\u53e3\u53ca\u670d\u52a1<\/td><td><code>masscan<\/code>, <code>rustscan<\/code><\/td><\/tr><tr><td>Web\u6307\u7eb9<\/td><td><code>whatweb<\/code><\/td><td>\u8bc6\u522bWeb\u6280\u672f\u6808<\/td><td><code>Wappalyzer<\/code>\uff08\u6d4f\u89c8\u5668\u63d2\u4ef6\uff09<\/td><\/tr><tr><td>WAF\u68c0\u6d4b<\/td><td><code>wafw00f<\/code><\/td><td>\u68c0\u6d4bWAF\u7c7b\u578b<\/td><td><code>identywaf<\/code><\/td><\/tr><tr><td>\u76ee\u5f55\u679a\u4e3e<\/td><td><code>dirb<\/code><\/td><td>\u53d1\u73b0\u9690\u85cf\u76ee\u5f55\u548c\u6587\u4ef6<\/td><td><code>gobuster<\/code>, <code>ffuf<\/code><\/td><\/tr><tr><td>\u871c\u7f50\u68c0\u6d4b<\/td><td><code>curl<\/code><\/td><td>\u5206\u6790\u54cd\u5e94\u65f6\u95f4\/\u5185\u5bb9\u4e00\u81f4\u6027<\/td><td>\u81ea\u5b9a\u4e49Python\u811a\u672c<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h4 class=\"wp-block-heading\">\u6807\u51c6\u64cd\u4f5c\u6b65\u9aa4<\/h4>\n\n\n\n<p><strong>Web\u5e94\u7528\u67b6\u6784\u4fe1\u606f\u6536\u96c6\u64cd\u4f5c\u8def\u5f84\u6d41\u7a0b\u56fe<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/03\/Web\u5e94\u7528\u67b6\u6784\u4fe1\u606f\u6536\u96c6\u64cd\u4f5c\u8def\u5f84\u6d41\u7a0b\u56fe-192x1024.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"192\" height=\"1024\" data-original=\"http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/03\/Web\u5e94\u7528\u67b6\u6784\u4fe1\u606f\u6536\u96c6\u64cd\u4f5c\u8def\u5f84\u6d41\u7a0b\u56fe-192x1024.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1772\"  sizes=\"auto, (max-width: 192px) 100vw, 192px\" \/><\/div><\/figure>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u4fe1\u606f\u6536\u96c6\u51c6\u5907<\/strong>\uff1a\u786e\u5b9a\u76ee\u6807\u57df\u540d\uff08\u5982<code>example.com<\/code>\uff09\uff0c\u8bb0\u5f55\u5f00\u59cb\u65f6\u95f4\uff0c\u5e76\u518d\u6b21\u786e\u8ba4\u6388\u6743\u8303\u56f4\u3002<\/li>\n\n\n\n<li><strong>\u7b2c\u4e00\u6b65\uff1a\u57fa\u7840\u4fe1\u606f\u6536\u96c6<\/strong>\uff1a\n<ul class=\"wp-block-list\">\n<li>\u4f7f\u7528<code>dig<\/code>\u5206\u522b\u67e5\u8be2DNS\u7684A\u3001CNAME\u3001MX\u7b49\u8bb0\u5f55\u3002<\/li>\n\n\n\n<li>\u82e5\u76ee\u6807\u652f\u6301HTTPS\uff0c\u4f7f\u7528<code>openssl s_client<\/code>\u83b7\u53d6TLS\u8bc1\u4e66\u4fe1\u606f\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u7b2c\u4e8c\u6b65\uff1a\u7aef\u53e3\u626b\u63cf<\/strong>\uff1a\n<ul class=\"wp-block-list\">\n<li>\u8fd0\u884c<code>nmap -sS -p 1-1000 -T4 --open target.com<\/code>\uff08<strong>\u6ce8\u610f<\/strong>\uff1a<code>-T4<\/code>\u53ef\u80fd\u8fc7\u5feb\uff0c\u53ef\u6839\u636e\u7f51\u7edc\u72b6\u51b5\u548c\u98ce\u63a7\u8981\u6c42\u964d\u4e3a<code>-T3<\/code>\uff0c\u5e76\u8003\u8651\u4f7f\u7528<code>--max-rate<\/code>\u8fdb\u4e00\u6b65\u63a7\u5236\u901f\u7387\uff09\u3002<\/li>\n\n\n\n<li>\u8bb0\u5f55\u6240\u6709\u5f00\u653e\u7684\u7aef\u53e3\u53ca\u5176\u5bf9\u5e94\u7684\u5e38\u89c1\u670d\u52a1\uff08\u598280\/http, 443\/https\uff09\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u7b2c\u4e09\u6b65\uff1a\u670d\u52a1\u6307\u7eb9\u8bc6\u522b<\/strong>\uff1a\n<ul class=\"wp-block-list\">\n<li>\u5bf9\u6bcf\u4e00\u4e2a\u5f00\u653e\u7684Web\u670d\u52a1\u7aef\u53e3\uff0c\u4f7f\u7528<code>whatweb http:\/\/target.com:port<\/code>\u8fdb\u884c\u6280\u672f\u6808\u8bc6\u522b\u3002<\/li>\n\n\n\n<li>\u4f7f\u7528<code>curl -I<\/code>\u6536\u96c6Web\u670d\u52a1\u7684\u54cd\u5e94\u5934\uff0c\u91cd\u70b9\u5173\u6ce8<code>Server<\/code>\u3001<code>X-Powered-By<\/code>\u3001<code>Set-Cookie<\/code>\u7b49\u5b57\u6bb5\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u7b2c\u56db\u6b65\uff1aWAF\u8bc6\u522b<\/strong>\uff1a\n<ul class=\"wp-block-list\">\n<li>\u8fd0\u884c<code>wafw00f https:\/\/target.com<\/code>\uff0c\u8bb0\u5f55\u5176\u8f93\u51fa\u7ed3\u679c\u3002<\/li>\n\n\n\n<li>\u624b\u52a8\u53d1\u9001\u51e0\u4e2a\u7b80\u5355\u7684\u53ef\u7591\u8bf7\u6c42\uff08\u5982<code>\/?id=1'<\/code>\uff09\uff0c\u89c2\u5bdf\u662f\u5426\u89e6\u53d1\u62e6\u622a\uff0c\u5e76\u8bb0\u5f55\u62e6\u622a\u9875\u9762\u7684\u7279\u5f81\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u7b2c\u4e94\u6b65\uff1a\u76ee\u5f55\u679a\u4e3e\uff08\u53ef\u9009\uff09<\/strong>\uff1a\n<ul class=\"wp-block-list\">\n<li>\u4f7f\u7528<code>gobuster dir -u https:\/\/target.com -w \/usr\/share\/wordlists\/dirb\/common.txt -t 10 -z 1000<\/code>\u3002<\/li>\n\n\n\n<li>\u6839\u636e\u4e0a\u4e00\u6b65\u662f\u5426\u53d1\u73b0WAF\uff0c\u52a8\u6001\u8c03\u6574\u7ebf\u7a0b\u6570\uff08<code>-t<\/code>\uff09\u548c\u5ef6\u8fdf\uff08<code>-z<\/code>\uff09\uff0c\u907f\u514d\u5bf9\u76ee\u6807\u9020\u6210\u8fc7\u5927\u538b\u529b\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u7b2c\u516d\u6b65\uff1a\u871c\u7f50\u7279\u5f81\u68c0\u67e5<\/strong>\uff1a\n<ul class=\"wp-block-list\">\n<li>\u7f16\u5199\u4e00\u4e2a\u7b80\u5355\u7684\u5faa\u73af\u811a\u672c\uff0c\u8bbf\u95ee\u591a\u4e2a\u4e0d\u540c\u7684\u8def\u5f84\uff0c\u8bb0\u5f55\u6bcf\u4e2a\u8bf7\u6c42\u7684HTTP\u72b6\u6001\u7801\u548c\u54cd\u5e94\u65f6\u95f4\uff0c\u5206\u6790\u662f\u5426\u5b58\u5728\u5f02\u5e38\u6a21\u5f0f\uff08\u4f8b\u5982\uff0c\u6240\u6709\u8def\u5f84\u90fd\u8fd4\u56de\u76f8\u540c\u5185\u5bb9\uff0c\u6216\u54cd\u5e94\u65f6\u95f4\u6052\u5b9a\u4e14\u6781\u77ed\uff09\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u6570\u636e\u6574\u7406<\/strong>\uff1a\u5c06\u4ee5\u4e0a\u5404\u6b65\u9aa4\u7684\u8f93\u51fa\u7ed3\u679c\u6c47\u603b\u5230\u4e00\u4e2a\u7edf\u4e00\u7684\u8868\u683c\u4e2d\uff0c\u5e76\u6807\u8bb0\u6bcf\u6761\u4fe1\u606f\u7684\u6765\u6e90\u548c\u53ef\u4fe1\u5ea6\u3002<\/li>\n<\/ol>\n\n\n\n<h4 class=\"wp-block-heading\">\u5982\u4f55\u9a8c\u8bc1\u7ed3\u679c\u771f\u5b9e\u6027<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u9a8c\u8bc1\u903b\u8f91<\/strong>\uff1a\u64cd\u4f5c\u8def\u5f84\u4e2d\u7684\u6bcf\u4e00\u6b65\u90fd\u5e94\u80fd\u88ab\u590d\u73b0\u6216\u901a\u8fc7\u5176\u4ed6\u65b9\u5f0f\u4ea4\u53c9\u9a8c\u8bc1\u3002\u4f8b\u5982\uff0c\u7aef\u53e3\u626b\u63cf\u7684\u7ed3\u679c\u53ef\u4ee5\u4e0e\u5728\u7ebf\u670d\u52a1\uff08\u5982Shodan\uff09\u7684\u5386\u53f2\u6570\u636e\u8fdb\u884c\u7c97\u7565\u5bf9\u6bd4\uff1bWAF\u8bc6\u522b\u7684\u7ed3\u679c\u53ef\u4ee5\u901a\u8fc7\u624b\u52a8\u53d1\u9001Payload\u6765\u9a8c\u8bc1\uff1b\u76ee\u5f55\u679a\u4e3e\u53d1\u73b0\u7684\u8def\u5f84\u53ef\u4ee5\u901a\u8fc7\u624b\u52a8\u8bbf\u95ee\u6765\u786e\u8ba4\u5176\u662f\u5426\u771f\u5b9e\u5b58\u5728\u3002<\/li>\n\n\n\n<li><strong>\u8f93\u51fa\u5224\u65ad\u4f9d\u636e<\/strong>\uff1a\u5982\u679c\u76ee\u5f55\u679a\u4e3e\u5de5\u5177\u62a5\u544a\u67d0\u4e2a\u8def\u5f84\u8fd4\u56de200\u72b6\u6001\u7801\uff0c\u4f46\u624b\u52a8\u8bbf\u95ee\u53d1\u73b0\u9875\u9762\u5185\u5bb9\u662fWAF\u7684\u201c\u8bbf\u95ee\u88ab\u62d2\u7edd\u201d\u9875\u9762\uff0c\u90a3\u4e48\u8be5\u76ee\u5f55\u679a\u4e3e\u7ed3\u679c\u5f88\u53ef\u80fd\u662f\u5047\u9633\u6027\u2014\u2014\u5b9e\u9645\u8def\u5f84\u53ef\u80fd\u4e0d\u5b58\u5728\uff0c\u800c\u662fWAF\u5bf9\u6240\u6709\u4e0d\u5b58\u5728\u7684\u8def\u5f84\u8fd4\u56de\u4e86\u7edf\u4e00\u7684\u62e6\u622a\u9875\u9762\u3002<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">\u5e38\u89c1\u9519\u8bef\u4e0e\u6392\u67e5\u65b9\u5f0f<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u9519\u8bef<\/strong>\uff1a\u7aef\u53e3\u626b\u63cf\u4f7f\u7528\u9ed8\u8ba4\u7684\u8f83\u9ad8\u901f\u7387\uff08\u5982<code>-T4<\/code>\uff09\u5bfc\u81f4\u7f51\u7edc\u4e22\u5305\uff0c\u4ece\u800c\u6f0f\u6389\u4e86\u4e00\u4e9b\u5b9e\u9645\u4e0a\u5f00\u653e\u7684\u7aef\u53e3\u3002<\/li>\n\n\n\n<li><strong>\u6392\u67e5<\/strong>\uff1a\u964d\u4f4e\u626b\u63cf\u901f\u7387\uff08\u5982<code>-T3<\/code>\uff09\u91cd\u65b0\u626b\u63cf\uff0c\u6216\u4f7f\u7528<code>masscan<\/code>\u7b49\u4e0d\u540c\u7684\u5de5\u5177\u8fdb\u884c\u9a8c\u8bc1\u3002<\/li>\n\n\n\n<li><strong>\u9519\u8bef<\/strong>\uff1a\u76ee\u5f55\u679a\u4e3e\u65f6\u7ebf\u7a0b\u6570\u8bbe\u7f6e\u8fc7\u9ad8\uff0c\u5bfc\u81f4\u6e90IP\u88abWAF\u5c01\u7981\u3002<\/li>\n\n\n\n<li><strong>\u6392\u67e5<\/strong>\uff1a\u4f7f\u7528\u4ee3\u7406\u6c60\u8f6e\u6362IP\uff0c\u6216\u7b49\u5f85IP\u89e3\u5c01\u540e\uff0c\u5728\u540e\u7eed\u63a2\u6d4b\u4e2d\u589e\u52a0\u8bf7\u6c42\u5ef6\u8fdf\uff08\u5982\u4f7f\u7528<code>-z<\/code>\u53c2\u6570\uff09\u3002<\/li>\n\n\n\n<li><strong>\u9519\u8bef<\/strong>\uff1a\u5c06\u8d1f\u8f7d\u5747\u8861\u5668\u7684Cookie\uff08\u5982<code>BIGipServer<\/code>\uff09\u8bef\u8ba4\u4e3a\u662fWAF\u7684\u6307\u7eb9\u3002<\/li>\n\n\n\n<li><strong>\u6392\u67e5<\/strong>\uff1a\u67e5\u770bCookie\u7684\u503c\u7684\u683c\u5f0f\u3002\u8d1f\u8f7d\u5747\u8861\u5668\u7684Cookie\u901a\u5e38\u5305\u542b\u7ecf\u8fc7\u7f16\u7801\u7684\u670d\u52a1\u5668IP\u6216\u7aef\u53e3\u4fe1\u606f\uff0c\u800cWAF\u7684Cookie\u53ef\u80fd\u5305\u542b\u4f1a\u8bddID\u6216\u5b89\u5168\u6807\u8bb0\u3002<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">\u5408\u89c4\u8fb9\u754c\u8bf4\u660e<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u7f51\u7edc\u5b89\u5168\u89c6\u89d2<\/strong>\uff1a\u76ee\u5f55\u679a\u4e3e\u3001\u7aef\u53e3\u626b\u63cf\u7b49\u4e3b\u52a8\u63a2\u6d4b\u884c\u4e3a\uff0c\u5f88\u53ef\u80fd\u8fdd\u53cd\u76ee\u6807\u7f51\u7ad9\u7684\u670d\u52a1\u6761\u6b3e\uff0c\u5c24\u5176\u662f\u5728\u672a\u7ecf\u6388\u6743\u7684\u60c5\u51b5\u4e0b\u3002\u5728\u6388\u6743\u6d4b\u8bd5\u4e2d\uff0c\u5fc5\u987b\u63d0\u524d\u4e0e\u5ba2\u6237\u786e\u8ba4\u5141\u8bb8\u7684\u63a2\u6d4b\u6df1\u5ea6\u548c\u901f\u7387\u3002<\/li>\n\n\n\n<li><strong>\u98ce\u9669<\/strong>\uff1a\u76ee\u5f55\u679a\u4e3e\u53ef\u80fd\u4f1a\u53d1\u73b0\u4e00\u4e9b\u654f\u611f\u6587\u4ef6\uff08\u5982\u914d\u7f6e\u6587\u4ef6\u5907\u4efd\uff09\u3002\u5982\u679c\u4e0b\u8f7d\u5e76\u67e5\u770b\u8fd9\u4e9b\u6587\u4ef6\u7684\u5185\u5bb9\uff0c\u53ef\u80fd\u6d89\u53ca\u6570\u636e\u6cc4\u9732\u7684\u98ce\u9669\u3002<\/li>\n\n\n\n<li><strong>\u7f13\u89e3\u63aa\u65bd<\/strong>\uff1a\u6240\u6709\u63a2\u6d4b\u6d3b\u52a8\u5e94\u5728\u6d4b\u8bd5\u73af\u5883\u4e2d\u8fdb\u884c\u6a21\u62df\u3002\u82e5\u5728\u6388\u6743\u6d4b\u8bd5\u4e2d\u53d1\u73b0\u4e86\u654f\u611f\u6587\u4ef6\uff0c\u5e94\u7acb\u5373\u5411\u5ba2\u6237\u62a5\u544a\uff0c\u800c\u4e0d\u5e94\u64c5\u81ea\u4e0b\u8f7d\u6216\u67e5\u770b\u5176\u5185\u5bb9\u3002<\/li>\n\n\n\n<li><strong>\u51b3\u7b56\u6307\u5357<\/strong>\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u5fc5\u987b\u7528<\/strong>\uff1a\u5728\u8fdb\u884c\u5168\u9762\u7684\u6e17\u900f\u6d4b\u8bd5\u65f6\uff0c\u5e94\u5f53\u6267\u884c\u6b64\u64cd\u4f5c\u8def\u5f84\uff0c\u4ee5\u5168\u9762\u4e86\u89e3\u76ee\u6807\u7684\u653b\u51fb\u9762\u3002<\/li>\n\n\n\n<li><strong>\u66ff\u4ee3<\/strong>\uff1a\u5982\u679c\u6d4b\u8bd5\u8303\u56f4\u4ec5\u9650\u4e8eWeb\u5e94\u7528\u7684\u4e1a\u52a1\u903b\u8f91\uff08\u800c\u975e\u5e95\u5c42\u57fa\u7840\u8bbe\u65bd\uff09\uff0c\u53ef\u4ee5\u8df3\u8fc7\u7aef\u53e3\u626b\u63cf\u548c\u76ee\u5f55\u679a\u4e3e\uff0c\u76f4\u63a5\u8fdb\u5165\u5e94\u7528\u5c42\u6d4b\u8bd5\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">\u672c\u6a21\u5757\u5c0f\u7ed3<\/h4>\n\n\n\n<p>\u672c\u6a21\u5757\u5c06\u524d\u5e8f\u7684\u65b9\u6cd5\u8bba\u8f6c\u5316\u4e3a\u4e86\u4e00\u4e2a\u6e05\u6670\u3001\u53ef\u6267\u884c\u7684\u64cd\u4f5c\u8def\u5f84\u3002\u8fd9\u6761\u8def\u5f84\u4ece\u5916\u5230\u5185\u3001\u4ece\u4f4e\u98ce\u9669\u5230\u9ad8\u98ce\u9669\uff0c\u786e\u4fdd\u4e86\u4fe1\u606f\u6536\u96c6\u5de5\u4f5c\u7684\u7cfb\u7edf\u6027\u548c\u5b89\u5168\u6027\u3002\u60a8\u53ef\u4ee5\u6309\u7167\u6b64\u8def\u5f84\u9010\u6b65\u64cd\u4f5c\uff0c\u4ee5\u83b7\u5f97\u5168\u9762\u4e14\u51c6\u786e\u7684\u76ee\u6807\u67b6\u6784\u4fe1\u606f\u3002\u5728\u64cd\u4f5c\u8fc7\u7a0b\u4e2d\uff0c\u9700\u8981\u65f6\u523b\u6ce8\u610f\u6f5c\u5728\u7684\u98ce\u9669\uff0c\u4e0b\u4e00\u6a21\u5757\u6211\u4eec\u5c06\u4e13\u95e8\u63a2\u8ba8<strong>\u5982\u4f55\u63a7\u5236\u8fd9\u4e9b\u98ce\u9669<\/strong>\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">\u98ce\u9669\u4e0e\u8fb9\u754c\u63a7\u5236<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">\u6a21\u5757\u6982\u5ff5\u89e3\u91ca<\/h4>\n\n\n\n<p>\u5728\u4fe1\u606f\u6536\u96c6\u8fc7\u7a0b\u4e2d\uff0c\u4e3b\u52a8\u63a2\u6d4b\u884c\u4e3a\u53ef\u80fd\u4f1a\u89e6\u53d1\u76ee\u6807\u7684\u5b89\u5168\u9632\u5fa1\u673a\u5236\uff08\u5982WAF\u62e6\u622a\u3001\u871c\u7f50\u8bb0\u5f55\uff09\uff0c\u751a\u81f3\u5bfc\u81f4\u6d4b\u8bd5IP\u88ab\u5c01\u7981\uff0c\u5f15\u53d1\u6cd5\u5f8b\u540e\u679c\u3002\u672c\u6a21\u5757\u65e8\u5728\u5e2e\u52a9\u60a8\u8bc6\u522b\u8fd9\u4e9b\u9632\u5fa1\u7cfb\u7edf\u7684\u5e72\u6270\uff0c\u8bbe\u5b9a\u5b89\u5168\u7684\u63a2\u6d4b\u8fb9\u754c\u3002\u901a\u8fc7\u5b66\u4e60\u901f\u7387\u63a7\u5236\u3001\u6d41\u91cf\u4f2a\u88c5\u3001\u6388\u6743\u786e\u8ba4\u7b49\u6280\u672f\uff0c\u786e\u4fdd\u4fe1\u606f\u6536\u96c6\u8fc7\u7a0b\u59cb\u7ec8\u5728\u5408\u6cd5\u3001\u5408\u89c4\u3001\u53ef\u63a7\u7684\u8303\u56f4\u5185\u8fdb\u884c\uff0c\u907f\u514d\u5bf9\u76ee\u6807\u9020\u6210\u8ba1\u5212\u5916\u7684\u8d1f\u9762\u5f71\u54cd\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u6280\u672f\u539f\u7406\u8bf4\u660e<\/h4>\n\n\n\n<p>\u9632\u5fa1\u7cfb\u7edf\uff08WAF\u3001IPS\u3001\u871c\u7f50\uff09\u7684\u6838\u5fc3\u539f\u7406\u662f\u57fa\u4e8e\u89c4\u5219\u5339\u914d\u6216\u884c\u4e3a\u5206\u6790\u6765\u8bc6\u522b\u6076\u610f\u6d41\u91cf\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>WAF<\/strong> \u901a\u5e38\u4f1a\u68c0\u6d4b\u8bf7\u6c42\u4e2d\u662f\u5426\u5305\u542b\u653b\u51fb\u7279\u5f81\uff08\u5982SQL\u6ce8\u5165\u7684\u5173\u952e\u5b57\uff09\uff0c\u4e00\u65e6\u5339\u914d\u5373\u8fdb\u884c\u62e6\u622a\u3002<\/li>\n\n\n\n<li><strong>\u871c\u7f50<\/strong> \u5219\u4f1a\u8bb0\u5f55\u653b\u51fb\u8005\u7684\u6240\u6709\u884c\u4e3a\uff0c\u5e76\u53ef\u80fd\u8fd4\u56de\u7cbe\u5fc3\u6784\u9020\u7684\u865a\u5047\u4fe1\u606f\u6765\u8ff7\u60d1\u653b\u51fb\u8005\u3002<br>\u56e0\u6b64\uff0c\u6211\u4eec\u7684\u63a2\u6d4b\u884c\u4e3a\u5fc5\u987b\u8003\u8651\u4ee5\u4e0b\u51e0\u70b9\uff1a<\/li>\n\n\n\n<li><strong>\u901f\u7387\u63a7\u5236<\/strong>\uff1a\u8fc7\u9ad8\u7684\u8bf7\u6c42\u9891\u7387\u4f1a\u88ab\u89c6\u4e3a\u626b\u63cf\u6216\u81ea\u52a8\u5316\u653b\u51fb\uff0c\u4ece\u800c\u89e6\u53d1\u76ee\u6807\u7684\u901f\u7387\u9650\u5236\u673a\u5236\u3002<\/li>\n\n\n\n<li><strong>\u7279\u5f81\u9690\u85cf<\/strong>\uff1a\u901a\u8fc7\u4f7f\u7528\u968f\u673a\u7684User-Agent\u3001\u5728\u8bf7\u6c42\u95f4\u52a0\u5165\u5ef6\u8fdf\u3001\u5bf9Payload\u8fdb\u884c\u53d8\u5f02\uff08\u5982\u5927\u5c0f\u5199\u8f6c\u6362\u3001URL\u7f16\u7801\uff09\u7b49\u65b9\u6cd5\uff0c\u53ef\u80fd\u7ed5\u8fc7\u4e00\u4e9b\u7b80\u5355\u7684\u68c0\u6d4b\u89c4\u5219\u3002<\/li>\n\n\n\n<li><strong>\u8fb9\u754c\u8bbe\u5b9a<\/strong>\uff1a\u5728\u6d4b\u8bd5\u5f00\u59cb\u524d\uff0c\u5fc5\u987b\u660e\u786e\u54ea\u4e9b\u64cd\u4f5c\u662f\u5141\u8bb8\u7684\uff08\u5982\u6388\u6743\u8303\u56f4\u5185\u7684\u63a2\u6d4b\uff09\uff0c\u54ea\u4e9b\u662f\u7edd\u5bf9\u4e0d\u80fd\u89e6\u78b0\u7684\u7ea2\u7ebf\uff08\u5982\u6f0f\u6d1e\u5229\u7528\u3001\u6570\u636e\u7be1\u6539\uff09\u3002<\/li>\n\n\n\n<li><strong>\u6cd5\u5f8b\u8fb9\u754c<\/strong>\uff1a\u672a\u7ecf\u6388\u6743\uff0c\u5bf9\u4efb\u4f55\u975e\u516c\u5f00\u76ee\u6807\u8fdb\u884c\u4e3b\u52a8\u63a2\u6d4b\uff0c\u90fd\u53ef\u80fd\u89e6\u72af\u5f53\u5730\u6cd5\u5f8b\u6cd5\u89c4\u3002<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">\u5728\u7cfb\u7edf\u4e2d\u7684\u4f4d\u7f6e<\/h4>\n\n\n\n<p>\u867d\u7136\u672c\u6a21\u5757\u5728\u8bfe\u7a0b\u4e2d\u88ab\u5b89\u6392\u5728\u64cd\u4f5c\u8def\u5f84\u4e4b\u540e\u8fdb\u884c\u9610\u8ff0\uff0c\u4f46\u5728\u5b9e\u9645\u63a2\u6d4b\u4e2d\uff0c\u98ce\u9669\u63a7\u5236\u610f\u8bc6\u5e94\u8d2f\u7a7f\u59cb\u7ec8\u3002\u5b83\u5f3a\u8c03\u5728\u8fdb\u884c\u6bcf\u4e00\u6b65\u64cd\u4f5c\u524d\uff0c\u90fd\u5fc5\u987b\u8003\u8651\u5176\u53ef\u80fd\u5e26\u6765\u7684\u98ce\u9669\u3002\u53ea\u6709\u786e\u4fdd\u6570\u636e\u672a\u88ab\u9632\u5fa1\u7cfb\u7edf\u201c\u6c61\u67d3\u201d\uff0c\u6211\u4eec\u624d\u80fd\u57fa\u4e8e\u8fd9\u4e9b\u6570\u636e\u751f\u6210\u51c6\u786e\u53ef\u9760\u7684\u76ee\u6807\u67b6\u6784\u89c6\u56fe\uff0c\u8fd9\u4e5f\u662f\u4e0b\u4e00\u6a21\u5757\u201c\u80fd\u529b\u6574\u5408\u8f93\u51fa\u201d\u7684\u524d\u63d0\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u53ef\u6267\u884c\u547d\u4ee4\u6216\u67e5\u8be2\u65b9\u5f0f<\/h4>\n\n\n\n<p>\u98ce\u9669\u63a7\u5236\u4e3b\u8981\u901a\u8fc7\u914d\u7f6e\u5de5\u5177\u7684\u53c2\u6570\u548c\u654f\u9510\u89c2\u5bdf\u76ee\u6807\u7684\u53cd\u9988\u6765\u5b9e\u73b0\u3002\u4f8b\u5982\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># \u63a7\u5236nmap\u626b\u63cf\u901f\u7387\uff08--max-rate 10 \u8868\u793a\u6bcf\u79d2\u6700\u591a\u53d1\u900110\u4e2a\u6570\u636e\u5305\uff09\nnmap -sS -p 1-1000 --max-rate 10 example.com\n\n# \u4f7f\u7528curl\u65f6\u968f\u673a\u5316User-Agent\uff08\u4f7f\u7528-A\u53c2\u6570\uff09\ncurl -A \"Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36\" -I https:\/\/example.com\n\n# \u76ee\u5f55\u679a\u4e3e\u65f6\u589e\u52a0\u5ef6\u8fdf\uff08-z 1000 \u8868\u793a\u5ef6\u8fdf1000\u6beb\u79d2\uff09\ngobuster dir -u https:\/\/example.com -w wordlist.txt -t 1 -z 1000\n\n# \u4f7f\u7528\u4ee3\u7406\u8f6e\u6362\uff08\u9700\u63d0\u524d\u914d\u7f6e\u597d\u4ee3\u7406\u6c60\uff09\ncurl -x http:\/\/proxy:port https:\/\/example.com<\/code><\/pre>\n\n\n\n<h4 class=\"wp-block-heading\">\u5de5\u5177\u5bf9\u6bd4\u8868\uff08\u98ce\u9669\u63a7\u5236\u76f8\u5173\u529f\u80fd\uff09<\/h4>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u5de5\u5177<\/th><th>\u63a7\u5236\u529f\u80fd<\/th><th>\u4f18\u70b9<\/th><th>\u5c40\u9650<\/th><\/tr><\/thead><tbody><tr><td><code>nmap<\/code><\/td><td><code>--max-rate<\/code>, <code>--scan-delay<\/code><\/td><td>\u53ef\u4ee5\u7cbe\u786e\u63a7\u5236\u7f51\u7edc\u5c42\u7684\u53d1\u5305\u901f\u7387<\/td><td>\u5bf9\u5e94\u7528\u5c42\uff08HTTP\uff09\u7684\u8bf7\u6c42\u901f\u7387\u63a7\u5236\uff0c\u9700\u914d\u5408\u5176\u4ed6\u5de5\u5177<\/td><\/tr><tr><td><code>curl<\/code><\/td><td><code>--limit-rate<\/code>, <code>-A<\/code>, <code>-x<\/code><\/td><td>\u53ef\u4ee5\u7075\u6d3b\u63a7\u5236\u5355\u4e2a\u8bf7\u6c42\u7684\u5934\u4fe1\u606f\u3001\u901f\u7387\u548c\u4ee3\u7406<\/td><td>\u4ec5\u80fd\u63a7\u5236\u5355\u4e2a\u8bf7\u6c42\uff0c\u4e0d\u9002\u7528\u4e8e\u5927\u89c4\u6a21\u81ea\u52a8\u5316\u626b\u63cf<\/td><\/tr><tr><td><code>gobuster<\/code><\/td><td><code>-t<\/code>\uff08\u7ebf\u7a0b\u6570\uff09\u3001<code>-z<\/code>\uff08\u5ef6\u8fdf\u6beb\u79d2\uff09<\/td><td>\u5185\u7f6e\u5ef6\u8fdf\u63a7\u5236\u53c2\u6570\uff0c\u7b80\u5355\u6613\u7528<\/td><td>\u5ef6\u8fdf\u5355\u4f4d\u4e3a\u6beb\u79d2\uff0c\u9700\u8981\u6839\u636e\u7f51\u7edc\u60c5\u51b5\u5408\u7406\u8bbe\u7f6e<\/td><\/tr><tr><td><code>ffuf<\/code><\/td><td><code>-t<\/code>\u3001<code>-p<\/code>\uff08\u5ef6\u8fdf\uff09<\/td><td>\u652f\u6301\u591a\u79cd\u5ef6\u8fdf\u7b56\u7565\uff08\u5982\u968f\u673a\u5ef6\u8fdf\uff09\uff0c\u529f\u80fd\u5f3a\u5927<\/td><td>\u914d\u7f6e\u76f8\u5bf9\u590d\u6742<\/td><\/tr><tr><td><code>Burp Suite<\/code><\/td><td>Intruder\u6a21\u5757\u7684Throttle<\/td><td>\u56fe\u5f62\u5316\u754c\u9762\uff0c\u53ef\u76f4\u89c2\u5730\u914d\u7f6e\u8bf7\u6c42\u5ef6\u8fdf\u548c\u7ebf\u7a0b\u6570<\/td><td>\u4f9d\u8d56\u56fe\u5f62\u754c\u9762\uff0c\u4e0d\u4fbf\u4e8e\u65e0\u5934\u73af\u5883\u4e0b\u7684\u81ea\u52a8\u5316\u96c6\u6210<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h4 class=\"wp-block-heading\">\u6807\u51c6\u64cd\u4f5c\u6b65\u9aa4<\/h4>\n\n\n\n<p><strong>\u98ce\u9669\u63a7\u5236\u4e0e\u81ea\u9002\u5e94\u8c03\u6574\u6d41\u7a0b\u56fe<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/03\/\u98ce\u9669\u63a7\u5236\u4e0e\u81ea\u9002\u5e94\u8c03\u6574\u6d41\u7a0b\u56fe-440x1024.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"440\" height=\"1024\" data-original=\"http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/03\/\u98ce\u9669\u63a7\u5236\u4e0e\u81ea\u9002\u5e94\u8c03\u6574\u6d41\u7a0b\u56fe-440x1024.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1774\"  sizes=\"auto, (max-width: 440px) 100vw, 440px\" \/><\/div><\/figure>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u660e\u786e\u6388\u6743\u8303\u56f4<\/strong>\uff1a\u5728\u5f00\u59cb\u4efb\u4f55\u63a2\u6d4b\u524d\uff0c\u52a1\u5fc5\u786e\u8ba4\u76ee\u6807\u662f\u5426\u5728\u6388\u6743\u8303\u56f4\u5185\uff0c\u4ee5\u53ca\u5ba2\u6237\u5141\u8bb8\u7684\u63a2\u6d4b\u6df1\u5ea6\uff08\u5982\u662f\u5426\u5141\u8bb8\u76ee\u5f55\u679a\u4e3e\u3001\u7aef\u53e3\u626b\u63cf\uff09\u3002<\/li>\n\n\n\n<li><strong>\u8bbe\u5b9a\u63a2\u6d4b\u901f\u7387<\/strong>\uff1a\u6839\u636e\u76ee\u6807\u7684\u91cd\u8981\u6027\u548c\u7f51\u7edc\u72b6\u51b5\uff0c\u8bbe\u5b9a\u4e00\u4e2a\u5408\u7406\u7684\u901f\u7387\u4e0a\u9650\u3002\u4f8b\u5982\uff0c\u7aef\u53e3\u626b\u63cf\u4e0d\u8d85\u8fc710\u5305\/\u79d2\uff0c\u76ee\u5f55\u679a\u4e3e\u4e0d\u8d85\u8fc71\u8bf7\u6c42\/\u79d2\u3002<\/li>\n\n\n\n<li><strong>\u968f\u673a\u5316\u8bf7\u6c42\u7279\u5f81<\/strong>\uff1a\u4f7f\u7528\u968f\u673a\u7684User-Agent\u3001Referer\u7b49HTTP\u5934\uff0c\u907f\u514d\u6240\u6709\u8bf7\u6c42\u7684\u6a21\u5f0f\u8fc7\u4e8e\u5355\u4e00\uff0c\u6613\u4e8e\u88ab\u8bc6\u522b\u4e3a\u626b\u63cf\u5668\u3002<\/li>\n\n\n\n<li><strong>\u542f\u7528\u5ef6\u8fdf\u673a\u5236<\/strong>\uff1a\u5728\u4f7f\u7528\u7684\u5de5\u5177\u4e2d\u914d\u7f6e\u8bf7\u6c42\u95f4\u7684\u5ef6\u8fdf\u53c2\u6570\uff0c\u5982<code>gobuster -z 2000<\/code>\uff082\u79d2\u5ef6\u8fdf\uff09\u3002<\/li>\n\n\n\n<li><strong>\u76d1\u63a7\u54cd\u5e94\u53d8\u5316<\/strong>\uff1a\u5728\u63a2\u6d4b\u8fc7\u7a0b\u4e2d\uff0c\u5bc6\u5207\u5173\u6ce8\u54cd\u5e94\u7684\u72b6\u6001\u7801\u548c\u5185\u5bb9\u662f\u5426\u53d1\u751f\u7a81\u7136\u53d8\u5316\uff08\u5982\u6240\u6709\u8bf7\u6c42\u90fd\u8fd4\u56de403\uff09\u3002\u4e00\u65e6\u51fa\u73b0\u5f02\u5e38\uff0c\u5e94\u7acb\u5373\u6682\u505c\uff0c\u5206\u6790\u662f\u5426\u88ab\u5c01\u7981\u3002<\/li>\n\n\n\n<li><strong>\u4f7f\u7528\u4ee3\u7406\u6216VPN\uff08\u53ef\u9009\uff09<\/strong>\uff1a\u5982\u9700\u9690\u85cf\u771f\u5b9eIP\uff0c\u53ef\u4ee5\u4f7f\u7528\u5408\u89c4\u7684\u4ee3\u7406\u6216VPN\uff0c\u4f46\u9700\u6ce8\u610f\u4ee3\u7406\u670d\u52a1\u7684\u7a33\u5b9a\u6027\uff0c\u907f\u514d\u56e0\u4ee3\u7406\u6545\u969c\u5bfc\u81f4\u6570\u636e\u4e22\u5931\u3002<\/li>\n\n\n\n<li><strong>\u8bb0\u5f55\u88ab\u62e6\u622a\u60c5\u51b5<\/strong>\uff1a\u5982\u679c\u89e6\u53d1\u4e86WAF\u62e6\u622a\uff0c\u5e94\u8be6\u7ec6\u8bb0\u5f55\u62e6\u622a\u9875\u7684\u7279\u5f81\uff0c\u8fd9\u6709\u52a9\u4e8e\u540e\u7eed\u5206\u6790\uff0c\u5e76\u6307\u5bfc\u6211\u4eec\u8c03\u6574\u7b56\u7565\uff08\u5982\u66f4\u6362Payload\u3001\u8fdb\u4e00\u6b65\u964d\u4f4e\u901f\u7387\uff09\u3002<\/li>\n\n\n\n<li><strong>\u7ed3\u675f\u63a2\u6d4b\u540e\u6e05\u7406<\/strong>\uff1a\u6240\u6709\u63a2\u6d4b\u4efb\u52a1\u5b8c\u6210\u540e\uff0c\u5e94\u505c\u6b62\u6240\u6709\u5de5\u5177\uff0c\u786e\u4fdd\u6ca1\u6709\u6b8b\u7559\u7684\u8fdb\u7a0b\u5728\u540e\u53f0\u8fd0\u884c\u3002<\/li>\n<\/ol>\n\n\n\n<h4 class=\"wp-block-heading\">\u5982\u4f55\u9a8c\u8bc1\u7ed3\u679c\u771f\u5b9e\u6027<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u9a8c\u8bc1\u903b\u8f91<\/strong>\uff1a\u901a\u8fc7\u5bf9\u6bd4\u201c\u6b63\u5e38\u8bbf\u95ee\u201d\uff08\u5982\u4f7f\u7528\u5e38\u89c4\u6d4f\u89c8\u5668\u8bbf\u95ee\uff09\u4e0e\u201c\u63a2\u6d4b\u8bbf\u95ee\u201d\u7684\u54cd\u5e94\uff0c\u53ef\u4ee5\u5224\u65ad\u662f\u5426\u5b58\u5728\u9632\u5fa1\u5e72\u6270\u3002\u4f8b\u5982\uff0c\u5982\u679c\u63a2\u6d4b\u65f6\u6240\u6709\u8bf7\u6c42\u90fd\u8fd4\u56de403\uff0c\u800c\u7528\u6d4f\u89c8\u5668\u8bbf\u95ee\u5374\u5b8c\u5168\u6b63\u5e38\uff0c\u5219\u8bf4\u660e\u6211\u4eec\u7684IP\u5f88\u53ef\u80fd\u88ab\u5c01\u7981\u6216\u89e6\u53d1\u4e86WAF\u89c4\u5219\u3002<\/li>\n\n\n\n<li><strong>\u8f93\u51fa\u5224\u65ad\u4f9d\u636e<\/strong>\uff1a\u5982\u679c\u5728\u63a2\u6d4b\u8fc7\u7a0b\u4e2d\uff0c\u54cd\u5e94\u7801\u4ece200\u7a81\u7136\u8f6c\u53d8\u4e3a403\uff0c\u4e14\u54cd\u5e94\u4f53\u5185\u5bb9\u53d8\u4e3a\u4e00\u4e2a\u5178\u578b\u7684WAF\u62e6\u622a\u9875\u9762\uff0c\u5219\u53ef\u4ee5\u786e\u8ba4\u4e3a\u89e6\u53d1\u4e86\u9632\u5fa1\u3002\u6b64\u65f6\uff0c\u4e4b\u524d\u83b7\u53d6\u7684\u63a2\u6d4b\u7ed3\u679c\u53ef\u80fd\u5df2\u88ab\u201c\u6c61\u67d3\u201d\uff08\u5982\u76ee\u5f55\u679a\u4e3e\u7684\u7ed3\u679c\u53ef\u80fd\u4e0d\u51c6\u786e\uff09\uff0c\u9700\u8981\u5728\u62a5\u544a\u4e2d\u7279\u522b\u8bf4\u660e\u3002<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">\u5e38\u89c1\u9519\u8bef\u4e0e\u6392\u67e5\u65b9\u5f0f<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u9519\u8bef<\/strong>\uff1a\u63a2\u6d4b\u901f\u7387\u8fc7\u5feb\u5bfc\u81f4IP\u88ab\u5c01\u7981\uff0c\u5374\u672a\u80fd\u53ca\u65f6\u5bdf\u89c9\uff0c\u540e\u7eed\u7684\u6240\u6709\u8bf7\u6c42\u90fd\u88ab\u62e6\u622a\uff0c\u5bfc\u81f4\u8bef\u4ee5\u4e3a\u76ee\u6807\u670d\u52a1\u65e0\u54cd\u5e94\u3002<\/li>\n\n\n\n<li><strong>\u6392\u67e5<\/strong>\uff1a\u4f7f\u7528\u4e00\u4e2a\u5907\u7528IP\uff08\u5982\u624b\u673a\u70ed\u70b9\uff09\u6216\u901a\u8fc7\u4ee3\u7406\u91cd\u65b0\u5c1d\u8bd5\u8bbf\u95ee\u76ee\u6807\uff0c\u786e\u8ba4\u76ee\u6807\u670d\u52a1\u662f\u5426\u4ecd\u7136\u6b63\u5e38\u3002\u5982\u679c\u5907\u7528IP\u53ef\u4ee5\u8bbf\u95ee\uff0c\u5219\u8bc1\u5b9e\u539fIP\u5df2\u88ab\u5c01\u7981\u3002<\/li>\n\n\n\n<li><strong>\u9519\u8bef<\/strong>\uff1a\u4f7f\u7528\u4e86\u9ed8\u8ba4\u6216\u8fc7\u4e8e\u8001\u65e7\u7684User-Agent\uff0c\u88abWAF\u8f7b\u6613\u5730\u8bc6\u522b\u4e3a\u626b\u63cf\u5668\u3002<\/li>\n\n\n\n<li><strong>\u6392\u67e5<\/strong>\uff1a\u4f7f\u7528\u5f53\u524d\u4e3b\u6d41\u6d4f\u89c8\u5668\u7684User-Agent\uff0c\u5e76\u51c6\u5907\u4e00\u4e2a\u5217\u8868\u8fdb\u884c\u968f\u673a\u8f6e\u6362\uff0c\u907f\u514d\u4f7f\u7528\u90a3\u4e9b\u4f17\u6240\u5468\u77e5\u4e0e\u9ed1\u5ba2\u5de5\u5177\u5173\u8054\u7684User-Agent\u3002<\/li>\n\n\n\n<li><strong>\u9519\u8bef<\/strong>\uff1a\u76ee\u5f55\u679a\u4e3e\u65f6\uff0cWAF\u5bf9\u67d0\u4e9b\u654f\u611f\u8def\u5f84\uff08\u5982<code>\/admin<\/code>\uff09\u8fd4\u56de\u4e86\u4e00\u4e2a\u5047\u7684200\u72b6\u6001\u7801\uff08\u5b9e\u9645\u4e0a\u662f\u5176\u62e6\u622a\u9875\u9762\uff09\uff0c\u5bfc\u81f4\u8bef\u5224\u8be5\u8def\u5f84\u771f\u5b9e\u5b58\u5728\u3002<\/li>\n\n\n\n<li><strong>\u6392\u67e5<\/strong>\uff1a\u624b\u52a8\u8bbf\u95ee\u8fd9\u4e9b\u88ab\u62a5\u544a\u4e3a\u5b58\u5728\u7684\u8def\u5f84\uff0c\u4ed4\u7ec6\u5bf9\u6bd4\u5176\u9875\u9762\u5185\u5bb9\u4e0e\u76ee\u6807\u5e94\u7528\u9996\u9875\u6216\u6b63\u5e38\u9875\u9762\u662f\u5426\u4e00\u81f4\u3002\u5982\u679c\u9875\u9762\u5185\u5bb9\u5305\u542b\u201c\u62e6\u622a\u201d\u3001\u201c\u62d2\u7edd\u201d\u7b49\u5173\u952e\u8bcd\uff0c\u5219\u4e3a\u5047\u9633\u6027\u3002<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">\u5408\u89c4\u8fb9\u754c\u8bf4\u660e<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u7f51\u7edc\u5b89\u5168\u89c6\u89d2<\/strong>\uff1a\u98ce\u9669\u63a7\u5236\u4e0d\u4ec5\u4ec5\u662f\u6280\u672f\u95ee\u9898\uff0c\u66f4\u662f\u6cd5\u5f8b\u548c\u804c\u4e1a\u9053\u5fb7\u7684\u4f53\u73b0\u3002\u672a\u7ecf\u6388\u6743\u7684\u4e3b\u52a8\u63a2\u6d4b\uff0c\u5373\u4f7f\u901f\u7387\u63a7\u5236\u5f97\u518d\u597d\uff0c\u4e5f\u53ef\u80fd\u89e6\u72af\u300a\u7f51\u7edc\u5b89\u5168\u6cd5\u300b\u7b49\u76f8\u5173\u6cd5\u89c4\uff0c\u5e26\u6765\u4e25\u91cd\u7684\u6cd5\u5f8b\u540e\u679c\u3002<\/li>\n\n\n\n<li><strong>\u98ce\u9669<\/strong>\uff1a\u5373\u4f7f\u5728\u6388\u6743\u6d4b\u8bd5\u4e2d\uff0c\u8fc7\u5ea6\u7684\u63a2\u6d4b\u4e5f\u53ef\u80fd\u5bfc\u81f4\u76ee\u6807\u4e1a\u52a1\u4e2d\u65ad\uff0c\u9020\u6210\u5b9e\u9645\u7684\u7ecf\u6d4e\u635f\u5931\uff0c\u6d4b\u8bd5\u65b9\u9700\u4e3a\u6b64\u627f\u62c5\u8d23\u4efb\u3002<\/li>\n\n\n\n<li><strong>\u7f13\u89e3\u63aa\u65bd<\/strong>\uff1a\u59cb\u7ec8\u5728\u6388\u6743\u8303\u56f4\u5185\u8c28\u614e\u64cd\u4f5c\uff1b\u4e0e\u5ba2\u6237\u660e\u786e\u6d4b\u8bd5\u7684\u65f6\u95f4\u7a97\u53e3\u548c\u7d27\u6025\u8054\u7cfb\u4eba\uff1b\u5728\u6d4b\u8bd5\u73af\u5883\u4e2d\u5145\u5206\u6f14\u7ec3\u540e\u518d\u5bf9\u771f\u5b9e\u76ee\u6807\u8fdb\u884c\u64cd\u4f5c\uff1b\u82e5\u6709\u6743\u9650\uff0c\u63a2\u6d4b\u524d\u505a\u597d\u76ee\u6807\u7cfb\u7edf\u7684\u5907\u4efd\u3002<\/li>\n\n\n\n<li><strong>\u51b3\u7b56\u6307\u5357<\/strong>\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u5fc5\u987b\u7528<\/strong>\uff1a\u5728\u4efb\u4f55\u5f62\u5f0f\u7684\u4e3b\u52a8\u63a2\u6d4b\u4e2d\uff0c\u90fd\u5fc5\u987b\u5e94\u7528\u98ce\u9669\u63a7\u5236\u63aa\u65bd\uff0c\u8fd9\u662f\u4e13\u4e1a\u5b89\u5168\u6d4b\u8bd5\u4eba\u5458\u7684\u57fa\u672c\u7d20\u517b\u3002<\/li>\n\n\n\n<li><strong>\u66ff\u4ee3<\/strong>\uff1a\u5982\u679c\u53ea\u9700\u8981\u6536\u96c6\u88ab\u52a8\u4fe1\u606f\uff08\u5982DNS\u3001\u8bc1\u4e66\uff09\uff0c\u5219\u65e0\u9700\u8fdb\u884c\u4e25\u683c\u7684\u98ce\u9669\u63a7\u5236\uff0c\u4f46\u4ecd\u9700\u9075\u5b88\u57fa\u672c\u7684\u6cd5\u5f8b\u8fb9\u754c\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">\u672c\u6a21\u5757\u5c0f\u7ed3<\/h4>\n\n\n\n<p>\u672c\u6a21\u5757\u5f3a\u8c03\u4e86\u4fe1\u606f\u6536\u96c6\u8fc7\u7a0b\u4e2d\u98ce\u9669\u63a7\u5236\u7684\u91cd\u8981\u6027\uff0c\u5e76\u63d0\u4f9b\u4e86\u5177\u4f53\u7684\u6280\u672f\u624b\u6bb5\u548c\u64cd\u4f5c\u6d41\u7a0b\u3002\u5b66\u4e60\u8005\u5e94\u5f53\u517b\u6210\u201c\u5148\u5b9a\u8fb9\u754c\uff0c\u540e\u884c\u63a2\u6d4b\u201d\u7684\u804c\u4e1a\u4e60\u60ef\uff0c\u786e\u4fdd\u6bcf\u4e00\u6b21\u6d4b\u8bd5\u6d3b\u52a8\u90fd\u5728\u5408\u6cd5\u5408\u89c4\u7684\u6846\u67b6\u5185\u8fdb\u884c\u3002\u7ecf\u8fc7\u4e25\u683c\u7684\u98ce\u9669\u63a7\u5236\uff0c\u6211\u4eec\u6536\u96c6\u5230\u7684\u4fe1\u606f\u5c06\u66f4\u52a0\u53ef\u9760\u3002\u63a5\u4e0b\u6765\uff0c\u6211\u4eec\u5c06\u8fdb\u5165\u6700\u540e\u4e00\u4e2a\u6a21\u5757\uff0c\u628a\u8fd9\u4e9b\u7ecf\u8fc7\u9a8c\u8bc1\u7684\u4fe1\u606f<strong>\u6574\u5408\u6210\u6700\u7ec8\u7684\u67b6\u6784\u89c6\u56fe\uff0c\u5e76\u89c4\u5212\u540e\u7eed\u7684\u6d4b\u8bd5\u5de5\u4f5c<\/strong>\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">\u80fd\u529b\u6574\u5408\u8f93\u51fa<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">\u6a21\u5757\u6982\u5ff5\u89e3\u91ca<\/h4>\n\n\n\n<p>\u4fe1\u606f\u6536\u96c6\u7684\u6700\u7ec8\u76ee\u7684\uff0c\u5e76\u975e\u4ec5\u4ec5\u83b7\u5f97\u4e00\u5806\u96f6\u6563\u7684\u6570\u636e\u70b9\uff0c\u800c\u662f\u8981\u5f62\u6210\u5bf9\u76ee\u6807\u67b6\u6784\u7684\u5168\u9762\u3001\u6df1\u5165\u7684\u7406\u89e3\uff0c\u5e76\u57fa\u4e8e\u6b64\u89c4\u5212\u540e\u7eed\u7684\u6d4b\u8bd5\u6216\u8bc4\u4f30\u7b56\u7565\u3002\u672c\u6a21\u5757\u5c06\u6574\u5408\u524d\u516d\u4e2a\u6a21\u5757\u6240\u6536\u96c6\u7684\u591a\u6e90\u4fe1\u606f\uff08\u5305\u62ecDNS\u3001\u7aef\u53e3\u3001\u6280\u672f\u6808\u3001WAF\u7c7b\u578b\u3001\u871c\u7f50\u7279\u5f81\u7b49\uff09\uff0c\u751f\u6210\u4e00\u4efd\u7ed3\u6784\u5316\u7684\u67b6\u6784\u89c6\u56fe\uff08\u5982\u62d3\u6251\u56fe\u3001\u7ec4\u4ef6\u6e05\u5355\uff09\u3002\u540c\u65f6\uff0c\u6211\u4eec\u5c06\u6839\u636e\u8fd9\u4efd\u89c6\u56fe\u8bc6\u522b\u51fa\u7684\u8584\u5f31\u70b9\u6216\u5173\u952e\u7ec4\u4ef6\uff0c\u89c4\u5212\u4e0b\u4e00\u6b65\u7684\u6d4b\u8bd5\u65b9\u5411\uff08\u4f8b\u5982\uff0c\u9488\u5bf9\u7279\u5b9a\u7248\u672c\u7ec4\u4ef6\u7684\u6f0f\u6d1e\u5229\u7528\u3001\u6216\u5bfb\u627e\u7ed5\u8fc7WAF\u7684\u7b56\u7565\uff09\u3002\u80fd\u529b\u6574\u5408\u8f93\u51fa\u7684\u5b8c\u6210\uff0c\u6807\u5fd7\u7740\u4fe1\u606f\u6536\u96c6\u9636\u6bb5\u7684\u6b63\u5f0f\u7ed3\u675f\uff0c\u4ee5\u53ca\u6df1\u5165\u6d4b\u8bd5\u9636\u6bb5\u7684\u5f00\u59cb\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u6280\u672f\u539f\u7406\u8bf4\u660e<\/h4>\n\n\n\n<p>\u6574\u5408\u8fc7\u7a0b\u7684\u5e95\u5c42\u903b\u8f91\u662f <strong>\u201c\u5173\u8054\u5206\u6790\u201d<\/strong> \u548c <strong>\u201c\u51b3\u7b56\u652f\u6301\u201d<\/strong> \u3002\u6765\u81ea\u4e0d\u540c\u6765\u6e90\u7684\u4fe1\u606f\u53ef\u80fd\u4f1a\u76f8\u4e92\u5370\u8bc1\uff0c\u4e5f\u53ef\u80fd\u76f8\u4e92\u77db\u76fe\u3002\u6211\u4eec\u9700\u8981\u901a\u8fc7\u903b\u8f91\u63a8\u7406\uff0c\u5254\u9664\u5e72\u6270\u4fe1\u606f\uff0c\u8fd8\u539f\u51fa\u6700\u63a5\u8fd1\u771f\u5b9e\u7684\u67b6\u6784\u3002\u4f8b\u5982\uff0c\u5982\u679c\u4e3b\u52a8\u63a2\u6d4b\u53d1\u73b0\u4e86WAF\uff0c\u88ab\u52a8\u76d1\u542c\u4e2d\u62e6\u622a\u9875\u7684\u7279\u5f81\u53c8\u4e0e\u67d0\u6b3e\u77e5\u540dWAF\u543b\u5408\uff0c\u90a3\u4e48WAF\u7684\u7c7b\u578b\u5c31\u53ef\u4ee5\u88ab\u786e\u8ba4\u3002\u5982\u679cTLS\u8bc1\u4e66\u4e2d\u7684\u7ec4\u7ec7\u4fe1\u606f\u4e0eDNS\u89e3\u6790\u51fa\u7684IP\u6240\u5c5e\u7684ASN\u4e0d\u7b26\uff0c\u5219\u5f88\u53ef\u80fd\u6d89\u53caCDN\u6216\u4e91\u6258\u7ba1\u670d\u52a1\u3002\u6574\u5408\u540e\u7684\u89c6\u56fe\u80fd\u5e2e\u52a9\u6211\u4eec\u5feb\u901f\u5b9a\u4f4d\u5173\u952e\u8d44\u4ea7\uff08\u5982\u7ba1\u7406\u540e\u53f0\u3001\u6570\u636e\u5e93\u63a5\u53e3\uff09\u548c\u6f5c\u5728\u5f31\u70b9\uff08\u5982\u8fc7\u65f6\u7684\u7ec4\u4ef6\u7248\u672c\u3001\u53ef\u80fd\u5b58\u5728\u7ed5\u8fc7\u7684WAF\u89c4\u5219\uff09\u3002\u540e\u7eed\u7684\u89c4\u5212\u5219\u9075\u5faa <strong>\u201c\u653b\u51fb\u9762\u6700\u5927\u5316\u201d<\/strong> \u539f\u5219\uff0c\u4f18\u5148\u6d4b\u8bd5\u90a3\u4e9b\u66b4\u9732\u9762\u5927\u4e14\u53ef\u80fd\u5b58\u5728\u8106\u5f31\u6027\u7684\u7ec4\u4ef6\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u5728\u7cfb\u7edf\u4e2d\u7684\u4f4d\u7f6e<\/h4>\n\n\n\n<p>\u672c\u6a21\u5757\u662f\u6574\u4e2a\u201c\u4fe1\u606f\u6536\u96c6-\u67b6\u6784\u5206\u6790\u201d\u8bfe\u7a0b\u7684\u6536\u5c3e\u4e4b\u4f5c\uff0c\u540c\u65f6\u4e5f\u662f\u540e\u7eed\u6e17\u900f\u6d4b\u8bd5\uff08\u6216\u5b89\u5168\u8bc4\u4f30\uff09\u5de5\u4f5c\u7684\u8d77\u70b9\u3002\u5b83\u5c06\u4e4b\u524d\u6536\u96c6\u5230\u7684\u6240\u6709\u96f6\u6563\u6570\u636e\u70b9\u4e32\u8054\u8d77\u6765\uff0c\u5f62\u6210\u6709\u4ef7\u503c\u7684\u77e5\u8bc6\uff0c\u4e3a\u4e0b\u4e00\u9636\u6bb5\u7684\u6f0f\u6d1e\u6316\u6398\u3001\u6743\u9650\u63d0\u5347\u7b49\u4efb\u52a1\u63d0\u4f9b\u51b3\u7b56\u4f9d\u636e\u3002\u81f3\u6b64\uff0c\u4fe1\u606f\u6536\u96c6\u9636\u6bb5\u7684\u5de5\u7a0b\u95ed\u73af\u6b63\u5f0f\u5b8c\u6210\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u53ef\u6267\u884c\u547d\u4ee4\u6216\u67e5\u8be2\u65b9\u5f0f<\/h4>\n\n\n\n<p>\u4fe1\u606f\u6574\u5408\u672c\u8eab\u4e0d\u6d89\u53ca\u65b0\u7684\u63a2\u6d4b\u547d\u4ee4\uff0c\u4f46\u6211\u4eec\u53ef\u4ee5\u901a\u8fc7\u7f16\u5199\u4e00\u4e9b\u7b80\u5355\u7684\u811a\u672c\u6765\u8f85\u52a9\u6570\u636e\u6574\u7406\u3002\u4f8b\u5982\uff0c\u7f16\u5199Shell\u811a\u672c\u4ece\u5404\u5de5\u5177\u7684\u8f93\u51fa\u4e2d\u63d0\u53d6\u5173\u952e\u5b57\u6bb5\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>#!\/bin\/bash\n# \u793a\u4f8b\u811a\u672c\uff1a\u63d0\u53d6wafw00f\u7ed3\u679c\u4e2d\u7684WAF\u540d\u79f0\nwafw00f https:\/\/example.com 2&gt;\/dev\/null | grep \"is behind\" | awk '{print $NF}'\n\n# \u793a\u4f8b\u811a\u672c\uff1a\u63d0\u53d6whatweb\u7ed3\u679c\u4e2d\u7684\u670d\u52a1\u5668\u4fe1\u606f\nwhatweb https:\/\/example.com --log-verbose=tmp.log &amp;&amp; cat tmp.log | grep \"Server\"<\/code><\/pre>\n\n\n\n<p>\u5bf9\u4e8e\u6700\u7ec8\u7684\u67b6\u6784\u56fe\u7ed8\u5236\uff0c\u66f4\u9ad8\u7ea7\u7684\u505a\u6cd5\u662f\u4f7f\u7528\u7ed8\u56fe\u5de5\u5177\uff08\u5982<code>draw.io<\/code>\u3001<code>Visio<\/code>\uff09\u8fdb\u884c\u624b\u5de5\u7ed8\u5236\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u5de5\u5177\u5bf9\u6bd4\u8868\uff08\u4fe1\u606f\u6574\u5408\u5de5\u5177\uff09<\/h4>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u5de5\u5177<\/th><th>\u9002\u7528\u573a\u666f<\/th><th>\u4f18\u70b9<\/th><th>\u5c40\u9650<\/th><\/tr><\/thead><tbody><tr><td>\u6587\u672c\u7f16\u8f91\u5668\/Excel<\/td><td>\u624b\u5de5\u6574\u7406\u5c11\u91cf\u6570\u636e<\/td><td>\u7075\u6d3b\uff0c\u4e0a\u624b\u5feb\uff0c\u9002\u5408\u5c0f\u578b\u9879\u76ee<\/td><td>\u6548\u7387\u4f4e\uff0c\u96be\u4ee5\u5904\u7406\u548c\u5206\u6790\u5927\u91cf\u6570\u636e<\/td><\/tr><tr><td><code>jq<\/code><\/td><td>\u5904\u7406JSON\u683c\u5f0f\u7684\u5de5\u5177\u8f93\u51fa<\/td><td>\u53ef\u5b9e\u73b0\u81ea\u52a8\u5316\u6570\u636e\u63d0\u53d6\uff0c\u9002\u5408\u7f16\u5199\u811a\u672c<\/td><td>\u9700\u8981\u5de5\u5177\u652f\u6301JSON\u683c\u5f0f\u8f93\u51fa\uff0c\u4e14\u9700\u5b66\u4e60<code>jq<\/code>\u8bed\u6cd5<\/td><\/tr><tr><td><code>grep<\/code>\/<code>awk<\/code><\/td><td>\u4ece\u6587\u672c\u65e5\u5fd7\u4e2d\u63d0\u53d6\u4fe1\u606f<\/td><td>\u5feb\u901f\u3001\u7b80\u5355\uff0c\u65e0\u9700\u989d\u5916\u5b89\u88c5<\/td><td>\u5bf9\u590d\u6742\u7684\u7ed3\u6784\u5316\u6587\u672c\u5904\u7406\u80fd\u529b\u6709\u9650<\/td><\/tr><tr><td>\u601d\u7ef4\u5bfc\u56fe\u8f6f\u4ef6<\/td><td>\u7ed8\u5236\u67b6\u6784\u56fe\u3001\u7ec4\u4ef6\u5173\u7cfb\u56fe<\/td><td>\u76f4\u89c2\u6e05\u6670\uff0c\u4fbf\u4e8e\u56e2\u961f\u4ea4\u6d41\u548c\u6c47\u62a5<\/td><td>\u65e0\u6cd5\u81ea\u52a8\u751f\u6210\uff0c\u9700\u624b\u5de5\u7ed8\u5236\u548c\u66f4\u65b0<\/td><\/tr><tr><td>Dradis\/Maltego<\/td><td>\u4e13\u4e1a\u6e17\u900f\u6d4b\u8bd5\u4fe1\u606f\u7ba1\u7406\u5e73\u53f0<\/td><td>\u96c6\u6210\u591a\u79cd\u5de5\u5177\u8f93\u51fa\uff0c\u53ef\u81ea\u52a8\u8fdb\u884c\u6570\u636e\u5173\u8054<\/td><td>\u5b66\u4e60\u6210\u672c\u9ad8\uff0c\u90e8\u5206\u9ad8\u7ea7\u529f\u80fd\u53ef\u80fd\u9700\u8981\u4ed8\u8d39<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h4 class=\"wp-block-heading\">\u6807\u51c6\u64cd\u4f5c\u6b65\u9aa4<\/h4>\n\n\n\n<p><strong>\u4fe1\u606f\u6574\u5408\u4e0e\u89c4\u5212\u6d41\u7a0b\u56fe<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/03\/\u4fe1\u606f\u6574\u5408\u4e0e\u89c4\u5212\u6d41\u7a0b\u56fe-490x1024.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"490\" height=\"1024\" data-original=\"http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/03\/\u4fe1\u606f\u6574\u5408\u4e0e\u89c4\u5212\u6d41\u7a0b\u56fe-490x1024.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1773\"  sizes=\"auto, (max-width: 490px) 100vw, 490px\" \/><\/div><\/figure>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u6570\u636e\u6c47\u603b<\/strong>\uff1a\u5c06\u524d\u516d\u4e2a\u6a21\u5757\u4e2d\u8bb0\u5f55\u7684\u6240\u6709\u4fe1\u606f\uff0c\u6574\u7406\u5230\u4e00\u4efd\u7edf\u4e00\u7684\u6587\u6863\u4e2d\uff0c\u5185\u5bb9\u5305\u62ec\u4f46\u4e0d\u9650\u4e8e\uff1a\n<ul class=\"wp-block-list\">\n<li>DNS\u89e3\u6790\u7ed3\u679c\uff08A\u3001CNAME\u3001MX\u7b49\uff09<\/li>\n\n\n\n<li>\u5f00\u653e\u7684\u7aef\u53e3\u53ca\u5176\u670d\u52a1\u7248\u672c<\/li>\n\n\n\n<li>Web\u6280\u672f\u6808\uff08Web\u670d\u52a1\u5668\u3001\u7f16\u7a0b\u8bed\u8a00\u3001\u6846\u67b6\uff09<\/li>\n\n\n\n<li>WAF\u68c0\u6d4b\u7ed3\u679c\uff08\u7c7b\u578b\u3001\u62e6\u622a\u9875\u7279\u5f81\uff09<\/li>\n\n\n\n<li>\u871c\u7f50\u7684\u53ef\u7591\u7279\u5f81<\/li>\n\n\n\n<li>\u76ee\u5f55\u679a\u4e3e\u53d1\u73b0\u7684\u654f\u611f\u8def\u5f84<\/li>\n\n\n\n<li>\u9519\u8bef\u4fe1\u606f\u4e2d\u6cc4\u9732\u7684\u7ec6\u8282<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u4fe1\u606f\u9a8c\u8bc1\u4e0e\u6e05\u6d17<\/strong>\uff1a\u5254\u9664\u76f8\u4e92\u77db\u76fe\u7684\u4fe1\u606f\uff0c\u5e76\u5bf9\u7f6e\u4fe1\u5ea6\u8f83\u4f4e\u7684\u63a8\u6d4b\u8fdb\u884c\u6807\u6ce8\u3002\u4f8b\u5982\uff0c\u5982\u679c<code>whatweb<\/code>\u68c0\u6d4b\u5230Apache\uff0c\u4f46<code>curl<\/code>\u663e\u793a\u7684<code>Server<\/code>\u5934\u4e3aCloudflare\uff0c\u5219\u4e24\u8005\u90fd\u5e94\u4fdd\u7559\uff0c\u5e76\u8bf4\u660e\u53ef\u80fd\u5b58\u5728CDN\u3002<\/li>\n\n\n\n<li><strong>\u7ed8\u5236\u67b6\u6784\u89c6\u56fe<\/strong>\uff1a\u4f7f\u7528\u56fe\u8868\u5de5\u5177\uff0c\u7ed8\u5236\u51fa\u4e00\u4efd\u6e05\u6670\u7684\u5206\u5c42\u67b6\u6784\u56fe\uff0c\u5e94\u5305\u542b\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u5916\u5c42<\/strong>\uff1aDNS\u3001CDN\u3001\u8d1f\u8f7d\u5747\u8861\u5668<\/li>\n\n\n\n<li><strong>\u4e2d\u95f4\u5c42<\/strong>\uff1aWeb\u670d\u52a1\u5668\u3001WAF<\/li>\n\n\n\n<li><strong>\u5185\u5c42<\/strong>\uff1a\u5e94\u7528\u670d\u52a1\u5668\u3001\u6570\u636e\u5e93\u3001\u7f13\u5b58\u7cfb\u7edf<\/li>\n\n\n\n<li><strong>\u6b3a\u9a97\u5c42<\/strong>\uff1a\u871c\u7f50\uff08\u6807\u6ce8\u4e3a\u53ef\u7591\uff09<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u5206\u6790\u8584\u5f31\u70b9<\/strong>\uff1a\u7ed3\u5408\u7ed8\u5236\u7684\u89c6\u56fe\uff0c\u6807\u6ce8\u51fa\u53ef\u80fd\u5b58\u5728\u6f0f\u6d1e\u7684\u7ec4\u4ef6\uff0c\u4f8b\u5982\uff1a\u7248\u672c\u8fc7\u4f4e\u7684Apache\u3001\u672a\u6388\u6743\u7684\u7ba1\u7406\u754c\u9762\u3001\u53ef\u80fd\u7ed5\u8fc7WAF\u7684\u7279\u5b9a\u8def\u5f84\u7b49\u3002<\/li>\n\n\n\n<li><strong>\u89c4\u5212\u540e\u7eed\u6d4b\u8bd5<\/strong>\uff1a\u57fa\u4e8e\u8584\u5f31\u70b9\u5206\u6790\uff0c\u5236\u5b9a\u4e0b\u4e00\u6b65\u7684\u5177\u4f53\u6d4b\u8bd5\u8ba1\u5212\uff0c\u4f8b\u5982\uff1a\n<ul class=\"wp-block-list\">\n<li>\u5bf9\u7279\u5b9a\u7aef\u53e3\u4e0a\u7684\u670d\u52a1\u8fdb\u884c\u6f0f\u6d1e\u626b\u63cf\u3002<\/li>\n\n\n\n<li>\u9488\u5bf9\u8bc6\u522b\u51fa\u7684WAF\u7c7b\u578b\uff0c\u7814\u7a76\u5e76\u5c1d\u8bd5\u7ed5\u8fc7\u6280\u5de7\u3002<\/li>\n\n\n\n<li>\u5c1d\u8bd5\u8bbf\u95ee\u53d1\u73b0\u7684\u7ba1\u7406\u540e\u53f0\uff0c\u8fdb\u884c\u5f31\u53e3\u4ee4\u6d4b\u8bd5\u3002<\/li>\n\n\n\n<li>\u82e5\u786e\u8ba4\u5b58\u5728\u871c\u7f50\uff0c\u8c03\u6574\u540e\u7eed\u7684\u4ea4\u4e92\u7b56\u7565\uff0c\u907f\u514d\u88ab\u8be6\u7ec6\u8bb0\u5f55\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u7f16\u5199\u4fe1\u606f\u6536\u96c6\u62a5\u544a<\/strong>\uff1a\u5c06\u6700\u7ec8\u7684\u6574\u5408\u7ed3\u679c\u548c\u540e\u7eed\u6d4b\u8bd5\u8ba1\u5212\uff0c\u6574\u7406\u6210\u4e00\u4efd\u6b63\u5f0f\u7684\u62a5\u544a\uff0c\u4f9b\u56e2\u961f\u6216\u5ba2\u6237\u5ba1\u9605\u3002<\/li>\n<\/ol>\n\n\n\n<h4 class=\"wp-block-heading\">\u5982\u4f55\u9a8c\u8bc1\u7ed3\u679c\u771f\u5b9e\u6027<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u9a8c\u8bc1\u903b\u8f91<\/strong>\uff1a\u6574\u5408\u540e\u7684\u67b6\u6784\u89c6\u56fe\u5e94\u5f53\u662f\u4e00\u4e2a\u81ea\u6d3d\u7684\u6574\u4f53\uff0c\u80fd\u591f\u89e3\u91ca\u6211\u4eec\u5728\u63a2\u6d4b\u8fc7\u7a0b\u4e2d\u89c2\u5bdf\u5230\u7684\u6240\u6709\u73b0\u8c61\u3002\u4f8b\u5982\uff0c\u5982\u679c\u89c6\u56fe\u4e2d\u5305\u542bWAF\uff0c\u90a3\u4e48\u5b83\u5e94\u8be5\u80fd\u89e3\u91ca\u4e3a\u4ec0\u4e48\u67d0\u4e9b\u8bf7\u6c42\u4f1a\u88ab\u62e6\u622a\uff1b\u5982\u679c\u5305\u542bCDN\uff0c\u5219\u5e94\u80fd\u89e3\u91ca\u4e3a\u4ec0\u4e48\u591a\u5730Ping\u7684\u7ed3\u679c\u4f1a\u4e0d\u4e00\u81f4\u3002\u6700\u540e\uff0c\u53ef\u4ee5\u901a\u8fc7\u4e00\u4e2a\u7b80\u5355\u7684\u6d4b\u8bd5\u6765\u9a8c\u8bc1\u89c6\u56fe\u7684\u51c6\u786e\u6027\uff1a\u6bd4\u5982\uff0c\u9884\u671f\u67d0\u4e2a\u7aef\u53e3\u662f\u6570\u636e\u5e93\uff0c\u5728\u6388\u6743\u73af\u5883\u4e0b\u5c1d\u8bd5\u8fde\u63a5\uff0c\u770b\u662f\u5426\u8fd4\u56de\u4e86\u6570\u636e\u5e93\u7684\u5178\u578b\u7279\u5f81\u3002<\/li>\n\n\n\n<li><strong>\u8f93\u51fa\u5224\u65ad\u4f9d\u636e<\/strong>\uff1a\u5982\u679c\u6240\u6709\u7684\u4fe1\u606f\u90fd\u80fd\u5728\u89c6\u56fe\u4e2d\u627e\u5230\u5176\u5408\u7406\u7684\u4f4d\u7f6e\uff0c\u5e76\u4e14\u6ca1\u6709\u903b\u8f91\u77db\u76fe\uff0c\u90a3\u4e48\u8fd9\u4efd\u89c6\u56fe\u7684\u53ef\u4fe1\u5ea6\u5c31\u975e\u5e38\u9ad8\u3002\u540e\u7eed\u7684\u6d4b\u8bd5\u7ed3\u679c\u5982\u679c\u4e0e\u89c6\u56fe\u7684\u9884\u6d4b\u4e00\u81f4\uff0c\u5219\u5c06\u8fdb\u4e00\u6b65\u9a8c\u8bc1\u5176\u6b63\u786e\u6027\u3002<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">\u5e38\u89c1\u9519\u8bef\u4e0e\u6392\u67e5\u65b9\u5f0f<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u9519\u8bef<\/strong>\uff1a\u5728\u8fdb\u884c\u4fe1\u606f\u6574\u5408\u65f6\uff0c\u5ffd\u7565\u4e86WAF\u53ef\u80fd\u4f1a\u9690\u85cf\u771f\u5b9e\u7684<code>Server<\/code>\u5934\uff0c\u4ece\u800c\u5bfc\u81f4\u8bef\u5224\u5e94\u7528\u670d\u52a1\u5668\u4e3aCDN\u6216WAF\u672c\u8eab\u3002<\/li>\n\n\n\n<li><strong>\u6392\u67e5<\/strong>\uff1a\u7efc\u5408\u5206\u6790\u591a\u4e2a\u8bf7\u6c42\u5934\u3002\u4f8b\u5982\uff0c<code>Server<\/code>\u5934\u4e3a<code>cloudflare<\/code>\uff0c\u4f46<code>X-Powered-By<\/code>\u5934\u5374\u663e\u793a\u4e3a<code>PHP<\/code>\uff0c\u90a3\u4e48\u771f\u5b9e\u670d\u52a1\u5668\u5f88\u53ef\u80fd\u662fApache\u6216Nginx\uff0c\u800cCDN\uff08Cloudflare\uff09\u4f4d\u4e8e\u5176\u524d\u7aef\u3002<\/li>\n\n\n\n<li><strong>\u9519\u8bef<\/strong>\uff1a\u5c06\u871c\u7f50\u8fd4\u56de\u7684\u865a\u5047\u4fe1\u606f\u5f53\u6210\u4e86\u771f\u5b9e\u7684\u7ec4\u4ef6\uff08\u4f8b\u5982\uff0c\u871c\u7f50\u6a21\u62df\u8fd4\u56de\u4e86\u4e00\u4e2aPHP\u7248\u672c\u53f7\uff09\u3002<\/li>\n\n\n\n<li><strong>\u6392\u67e5<\/strong>\uff1a\u871c\u7f50\u901a\u5e38\u65e0\u6cd5\u5b8c\u7f8e\u6a21\u62df\u4e00\u4e2a\u5b8c\u6574\u5e94\u7528\u7684\u6240\u6709\u529f\u80fd\u3002\u53ef\u4ee5\u5c1d\u8bd5\u8fdb\u884c\u66f4\u6df1\u5ea6\u7684\u4ea4\u4e92\uff08\u5982\u8868\u5355\u63d0\u4ea4\u3001\u72b6\u6001\u4fdd\u6301\uff09\uff0c\u770b\u5176\u4e1a\u52a1\u903b\u8f91\u662f\u5426\u80fd\u8fde\u8d2f\u6267\u884c\u3002\u5982\u679c\u6240\u6709\u8def\u5f84\u90fd\u8fd4\u56de\u8fd1\u4e4e\u76f8\u540c\u7684\u5185\u5bb9\uff0c\u5219\u9ad8\u5ea6\u6000\u7591\u662f\u871c\u7f50\u3002<\/li>\n\n\n\n<li><strong>\u9519\u8bef<\/strong>\uff1a\u76ee\u5f55\u679a\u4e3e\u53d1\u73b0\u4e86\u5927\u91cf\u8def\u5f84\uff0c\u4f46\u672a\u80fd\u6709\u6548\u533a\u5206\u54ea\u4e9b\u662f\u771f\u5b9e\u7684\u5e94\u7528\u8def\u5f84\uff0c\u54ea\u4e9b\u662fWAF\u8fd4\u56de\u7684\u5047\u9633\u6027\u54cd\u5e94\u3002<\/li>\n\n\n\n<li><strong>\u6392\u67e5<\/strong>\uff1a\u624b\u52a8\u8bbf\u95ee\u90a3\u4e9b\u53ef\u7591\u7684\u8def\u5f84\uff0c\u67e5\u770b\u9875\u9762\u7684\u6807\u9898\u3001\u5185\u5bb9\u662f\u5426\u4e0e\u76ee\u6807\u5e94\u7528\u7684\u6838\u5fc3\u4e1a\u52a1\u76f8\u5173\u3002\u6beb\u4e0d\u76f8\u5173\u7684\u5185\u5bb9\uff0c\u5f88\u53ef\u80fd\u662fWAF\u6216\u871c\u7f50\u7684\u865a\u5047\u54cd\u5e94\u3002<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">\u5408\u89c4\u8fb9\u754c\u8bf4\u660e<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u7f51\u7edc\u5b89\u5168\u89c6\u89d2<\/strong>\uff1a\u4fe1\u606f\u6574\u5408\u672c\u8eab\u4e0d\u4ea7\u751f\u65b0\u7684\u5b89\u5168\u98ce\u9669\u3002\u4f46\u6574\u5408\u540e\u7684\u89c6\u56fe\u53ef\u80fd\u5305\u542b\u9ad8\u5ea6\u654f\u611f\u7684\u4fe1\u606f\uff08\u5982\u6570\u636e\u5e93\u7684\u5185\u7f51IP\u3001\u7ba1\u7406\u540e\u53f0\u7684\u771f\u5b9e\u8def\u5f84\uff09\uff0c\u5fc5\u987b\u59a5\u5584\u4fdd\u7ba1\uff0c\u4e25\u9632\u6cc4\u9732\u3002<\/li>\n\n\n\n<li><strong>\u98ce\u9669<\/strong>\uff1a\u5982\u679c\u8fd9\u4efd\u8be6\u7ec6\u7684\u67b6\u6784\u89c6\u56fe\u843d\u5165\u6076\u610f\u653b\u51fb\u8005\u624b\u4e2d\uff0c\u5c06\u6210\u4e3a\u4ed6\u4eec\u6781\u4f73\u7684\u653b\u51fb\u84dd\u56fe\u3002<\/li>\n\n\n\n<li><strong>\u7f13\u89e3\u63aa\u65bd<\/strong>\uff1a\u5bf9\u6700\u7ec8\u7684\u62a5\u544a\u8fdb\u884c\u52a0\u5bc6\u5b58\u50a8\uff0c\u5e76\u4e25\u683c\u9650\u5236\u8bbf\u95ee\u6743\u9650\uff0c\u4ec5\u5bf9\u5fc5\u8981\u7684\u6388\u6743\u4eba\u5458\u5f00\u653e\u3002\u5728\u62a5\u544a\u4e2d\uff0c\u53ef\u4ee5\u5bf9\u5173\u952e\u7684\u5185\u90e8IP\u548c\u654f\u611f\u8def\u5f84\u8fdb\u884c\u8131\u654f\u5904\u7406\u3002<\/li>\n\n\n\n<li><strong>\u51b3\u7b56\u6307\u5357<\/strong>\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u5fc5\u987b\u7528<\/strong>\uff1a\u5728\u4e13\u4e1a\u7684\u6e17\u900f\u6d4b\u8bd5\u670d\u52a1\u4e2d\uff0c\u8fdb\u884c\u4fe1\u606f\u6574\u5408\u4e0e\u540e\u7eed\u89c4\u5212\u662f\u5fc5\u4e0d\u53ef\u5c11\u7684\u73af\u8282\uff0c\u5426\u5219\u6574\u4e2a\u6d4b\u8bd5\u8fc7\u7a0b\u5c06\u5931\u53bb\u65b9\u5411\uff0c\u53d8\u5f97\u76f2\u76ee\u800c\u4f4e\u6548\u3002<\/li>\n\n\n\n<li><strong>\u66ff\u4ee3<\/strong>\uff1a\u5bf9\u4e8e\u65f6\u95f4\u7d27\u8feb\u7684\u5feb\u901f\u5b89\u5168\u8bc4\u4f30\uff0c\u53ef\u4ee5\u9002\u5f53\u7b80\u5316\u6574\u5408\u8fc7\u7a0b\uff0c\u4f46\u81f3\u5c11\u4e5f\u5e94\u4ea7\u51fa\u4e00\u4efd\u5173\u952e\u8d44\u4ea7\u6e05\u5355\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">\u672c\u6a21\u5757\u5c0f\u7ed3<\/h4>\n\n\n\n<p>\u672c\u6a21\u5757\u5b8c\u6210\u4e86\u4fe1\u606f\u6536\u96c6\u9636\u6bb5\u7684\u6700\u540e\u4e00\u6b65\uff0c\u4e5f\u662f\u6700\u4e3a\u5173\u952e\u7684\u4e00\u6b65\u2014\u2014\u5c06\u96f6\u6563\u7684\u6570\u636e\u6574\u5408\u4e3a\u6709\u4ef7\u503c\u7684\u67b6\u6784\u77e5\u8bc6\uff0c\u5e76\u4ee5\u6b64\u89c4\u5212\u672a\u6765\u7684\u884c\u52a8\u3002\u81f3\u6b64\uff0c\u6211\u4eec\u8d70\u5b8c\u4e86\u4ece\u5efa\u7acb\u7cfb\u7edf\u6027\u8ba4\u77e5\u3001\u660e\u786e\u76ee\u6807\u3001\u7ed3\u6784\u5316\u62c6\u89e3\u3001\u638c\u63e1\u79d1\u5b66\u65b9\u6cd5\u3001\u9075\u5faa\u89c4\u8303\u64cd\u4f5c\u3001\u6267\u884c\u4e25\u683c\u98ce\u9669\u63a7\u5236\uff0c\u5230\u6700\u7ec8\u6574\u5408\u8f93\u51fa\u7684\u5168\u8fc7\u7a0b\u3002\u901a\u8fc7\u8fd9\u4e00\u5957\u5b8c\u6574\u7684\u5de5\u7a0b\u5316\u6d41\u7a0b\uff0c\u60a8\u5df2\u7ecf\u5177\u5907\u4e86\u72ec\u7acb\u5b8c\u6210Web\u5e94\u7528\u67b6\u6784\u4fe1\u606f\u6536\u96c6\u9636\u6bb5\u5de5\u4f5c\u7684\u4e13\u4e1a\u80fd\u529b\u3002\u4e0b\u4e00\u9636\u6bb5\uff0c\u6211\u4eec\u5c06\u8fdb\u5165\u6f0f\u6d1e\u63a2\u6d4b\u4e0e\u5229\u7528\u7684\u9886\u57df\uff0c\u4f46\u90a3\u5c06\u662f\u53e6\u4e00\u95e8\u8bfe\u7a0b\u7684\u4e3b\u9898\u4e86\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u53c2\u8003\u4e0e\u8fdb\u4e00\u6b65\u9605\u8bfb<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>IETF RFC 9619 &#8211; In the DNS, QDCOUNT Is (Usually) One<\/strong>: \u672c\u6587\u4e2dDNS\u67e5\u8be2\u884c\u4e3a\u4e0e\u534f\u8bae\u57fa\u7840\u7684\u4e3b\u8981\u4f9d\u636e\u3002<\/li>\n\n\n\n<li><strong>WAFW00F Official Repository<\/strong>: \u672c\u6587\u4e2dWAF\u68c0\u6d4b\u5de5\u5177<code>wafw00f<\/code>\u7684\u547d\u4ee4\u793a\u4f8b\u4e0e\u529f\u80fd\u8bf4\u660e\u6765\u6e90\u3002<\/li>\n\n\n\n<li><strong>OWASP Web Application Firewall<\/strong>: Web\u5e94\u7528\u9632\u706b\u5899(WAF)\u5b9a\u4e49\u4e0e\u6280\u672f\u539f\u7406\u7684\u6743\u5a01\u53c2\u8003\u3002<\/li>\n\n\n\n<li><strong>PortSwigger Burp Suite Documentation<\/strong>: \u672c\u6587\u4e2d\u8d1f\u8f7d\u5747\u8861Cookie\u8bc6\u522b\u3001\u98ce\u9669\u63a7\u5236\u529f\u80fd\uff08Intruder Throttle\uff09\u53ca\u9519\u8bef\u8bf1\u5bfc\u5206\u6790\u7684\u53c2\u8003\u4f9d\u636e\u3002<\/li>\n\n\n\n<li><strong>curl man page<\/strong>: \u672c\u6587\u4e2d\u6240\u6709<code>curl<\/code>\u547d\u4ee4\u7684\u8bed\u6cd5\u3001\u53c2\u6570\uff08<code>-I<\/code>, <code>-A<\/code>, <code>-x<\/code>, <code>--limit-rate<\/code>\uff09\u53ca\u884c\u4e3a\u63cf\u8ff0\u7684\u6280\u672f\u53c2\u8003\u3002<\/li>\n\n\n\n<li><strong>Nmap Network Scanning Official Documentation<\/strong>: \u672c\u6587\u4e2d<code>nmap<\/code>\u7aef\u53e3\u626b\u63cf\u3001\u901f\u7387\u63a7\u5236\uff08<code>--max-rate<\/code>\uff09\u53ca\u5b89\u5168\u6d4b\u8bd5\u5b9e\u8df5\u7684\u6280\u672f\u4f9d\u636e\u3002<\/li>\n\n\n\n<li><strong>IETF RFC 1035 &#8211; Domain Names &#8211; Implementation and Specification<\/strong>: DNS\u57fa\u7840\u534f\u8bae\u7684\u6838\u5fc3\u89c4\u8303\uff0c\u4e0eRFC 9619\u5171\u540c\u6784\u6210DNS\u67e5\u8be2\u7684\u7406\u8bba\u57fa\u7840\u3002<\/li>\n\n\n\n<li><strong>curl Official Website<\/strong>: \u672c\u6587\u4e2d<code>curl<\/code>\u5de5\u5177\u7684\u7075\u6d3b\u6027\u4e0e\u57fa\u7840\u7528\u6cd5\u63cf\u8ff0\u7684\u6765\u6e90\u3002<\/li>\n\n\n\n<li><strong>Nmap Reference Guide<\/strong>: \u672c\u6587\u4e2d<code>nmap<\/code>\u5de5\u5177\u529f\u80fd\u3001\u626b\u63cf\u6280\u672f\u4e0e\u5b89\u5168\u6ce8\u610f\u4e8b\u9879\u7684\u6743\u5a01\u53c2\u8003\u3002<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u4fe1\u606f\u6536\u96c6-Web\u5e94\u7528-\u67b6\u6784\u5206\u6790&amp;\u6846\u67b6\u7ec4\u4ef6\u8bc6\u522b<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">\u4e00\u3001\u91cd\u6784\u5e94\u7528\u67b6\u6784\u8ba4\u77e5\u524d\u63d0<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">1. \u6a21\u5757\u6982\u5ff5\u89e3\u91ca<\/h4>\n\n\n\n<p>\u8fdb\u884c\u6280\u672f\u63a2\u67e5\u524d\uff0c\u9996\u5148\u9700\u8981\u7406\u89e3\u76ee\u6807\u5e94\u7528\u5e76\u975e\u4e00\u4e2a monolithic\uff08\u5355\u4f53\uff09\u9ed1\u8272\u76d2\u5b50\uff0c\u800c\u662f\u4e00\u4e2a\u7531\u591a\u79cd\u670d\u52a1\u7ec4\u4ef6\u3001\u901a\u8fc7\u7f51\u7edc\u534f\u8bae\u8fdb\u884c\u4fe1\u606f\u4ea4\u6362\u7684\u5206\u5e03\u5f0f\u7cfb\u7edf\u3002\u672c\u6a21\u5757\u89e3\u51b3\u201c\u770b\u4ec0\u4e48\u201d\u548c\u201c\u5728\u54ea\u513f\u770b\u201d\u7684\u95ee\u9898\uff0c\u76ee\u6807\u662f\u5c06\u89c6\u89d2\u4ece\u201c\u5355\u4e00\u4e3b\u673a\u201d\u5207\u6362\u5230\u201c\u5206\u5e03\u5f0f\u5e94\u7528\u67b6\u6784\u201d\uff0c\u4e3a\u540e\u7eed\u7279\u5f81\u8bc6\u522b\u5efa\u7acb\u6b63\u786e\u5750\u6807\u7cfb\u3002\u5b83\u660e\u786e\u4e86\u63a2\u67e5\u7684\u5e95\u5c42\u903b\u8f91\uff1a\u6211\u4eec\u662f\u5728\u7406\u89e3\u4e00\u4e2a\u7531\u5404\u79cd\u7ec4\u4ef6\u6784\u6210\u7684\u751f\u6001\u7cfb\u7edf\uff0c\u800c\u975e\u653b\u51fb\u4e00\u53f0\u673a\u5668\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">2. \u6280\u672f\u539f\u7406\u8bf4\u660e<\/h4>\n\n\n\n<p>\u73b0\u4ee3 Web \u5e94\u7528\u67b6\u6784\u57fa\u4e8e\u5206\u5c42\u548c\u5fae\u670d\u52a1\u8bbe\u8ba1\u7406\u5ff5\u3002\u5728\u7f51\u7edc\u4e03\u5c42\u6a21\u578b\uff08OSI \u6a21\u578b\uff09\u4e2d\uff0cHTTP\/HTTPS\uff08\u5e94\u7528\u5c42\uff09\u662f\u8868\u8c61\uff0c\u4f46\u5176\u5e95\u5c42\u4f9d\u8d56 TCP\/IP\uff08\u4f20\u8f93\u5c42\uff09\u7684\u7aef\u53e3\u901a\u4fe1\u3001DNS\uff08\u5e94\u7528\u5c42\uff09\u7684\u57df\u540d\u89e3\u6790\uff0c\u4ee5\u53ca\u53ef\u80fd\u7684 CDN\uff08\u5185\u5bb9\u5206\u53d1\u7f51\u7edc\uff09\u3001\u8d1f\u8f7d\u5747\u8861\u5668\u7b49\u4e2d\u95f4\u4ef6\u3002\u5176\u6838\u5fc3\u662f\u201c\u8bf7\u6c42-\u54cd\u5e94\u201d\u6a21\u578b\uff1a\u5ba2\u6237\u7aef\u53d1\u9001\u8bf7\u6c42\uff0c\u7ecf\u8fc7\u7f51\u7edc\u5230\u8fbe\u670d\u52a1\u7aef\uff0c\u670d\u52a1\u7aef\u7684\u5404\u4e2a\u7ec4\u4ef6\uff08\u5982 Web \u670d\u52a1\u5668\u3001\u5e94\u7528\u6846\u67b6\u3001\u6570\u636e\u5e93\uff09\u534f\u540c\u5904\u7406\uff0c\u6700\u7ec8\u8fd4\u56de\u54cd\u5e94\u3002\u63a2\u67e5\u5373\u901a\u8fc7\u6784\u9020\u7279\u5b9a\u8bf7\u6c42\uff0c\u89c2\u5bdf\u548c\u5206\u6790\u54cd\u5e94\u4e2d\u7684\u7279\u5f81\uff0c\u9006\u5411\u63a8\u5bfc\u51fa\u80cc\u540e\u7ec4\u4ef6\u7684\u6784\u6210\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">3. \u5728\u7cfb\u7edf\u4e2d\u7684\u4f4d\u7f6e<\/h4>\n\n\n\n<p>\u6b64\u6a21\u5757\u662f\u6574\u4e2a\u63a2\u67e5\u6d41\u7a0b\u7684\u57fa\u77f3\uff0c\u4f4d\u4e8e\u6240\u6709\u64cd\u4f5c\u4e4b\u524d\u3002\u5b83\u4e0d\u76f4\u63a5\u4ea7\u751f\u53ef\u6267\u884c\u547d\u4ee4\uff0c\u800c\u662f\u5efa\u7acb\u4e00\u5957\u601d\u7ef4\u6a21\u578b\u3002\u540e\u7eed\u7684\u201c\u754c\u5b9a\u76ee\u6807\u201d\u3001\u201c\u89e3\u6790\u7279\u5f81\u201d\u7b49\u6a21\u5757\uff0c\u5747\u5728\u6b64\u8ba4\u77e5\u524d\u63d0\u4e0b\u5c55\u5f00\u3002\u6ca1\u6709\u8fd9\u4e2a\u524d\u63d0\uff0c\u540e\u7eed\u63a2\u67e5\u5c06\u7f3a\u4e4f\u7cfb\u7edf\u6027\uff0c\u96be\u4ee5\u5f62\u6210\u6709\u6548\u4f53\u7cfb\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">4. \u53ef\u6267\u884c\u547d\u4ee4\u6216\u67e5\u8be2\u65b9\u5f0f<\/h4>\n\n\n\n<p>\u867d\u7136\u6ca1\u6709\u76f4\u63a5\u7684\u63a2\u67e5\u547d\u4ee4\uff0c\u4f46\u53ef\u4ee5\u901a\u8fc7\u57fa\u7840\u547d\u4ee4\u5b9e\u8df5\u201c\u7ec4\u4ef6\u5206\u79bb\u201d\u7684\u89c2\u5bdf\u89c6\u89d2\u3002\u4f8b\u5982\uff0c\u4f7f\u7528 <code>dig<\/code> \u89c2\u5bdf\u57df\u540d\u89e3\u6790\uff0c\u53ef\u4ee5\u770b\u5230\u5e94\u7528\u67b6\u6784\u4e2d\u7684\u7b2c\u4e00\u4e2a\u7ec4\u4ef6\uff1aDNS\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># \u89c2\u5bdf\u4e00\u4e2a\u57df\u540d\u80cc\u540e\u7684IP\u5730\u5740\uff0c\u601d\u8003\u662f\u5426\u6709\u591a\u4e2aIP\uff08\u8d1f\u8f7d\u5747\u8861\u6216CDN\uff09\ndig example.com\n\n# \u8ddf\u8e2a\u4e00\u4e2aHTTP\u8bf7\u6c42\u7684\u5b8c\u6574\u7f51\u7edc\u8def\u5f84\n# Linux \u6216 macOS \u7cfb\u7edf\ntraceroute example.com\n# Windows \u7cfb\u7edf\ntracert example.com<\/code><\/pre>\n\n\n\n<p>\u8fd9\u4e9b\u547d\u4ee4\u6709\u52a9\u4e8e\u7406\u89e3\u4e00\u4e2a\u7b80\u5355\u7684 <code>example.com<\/code> \u80cc\u540e\u53ef\u80fd\u6d89\u53ca\u590d\u6742\u7684\u7f51\u7edc\u8def\u5f84\u548c\u591a\u53f0\u7269\u7406\/\u865a\u62df\u8bbe\u5907\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">5. \u5de5\u5177\u5bf9\u6bd4\u8868<\/h4>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u5de5\u5177<\/th><th>\u9002\u7528\u573a\u666f<\/th><th>\u4f18\u70b9<\/th><th>\u5c40\u9650<\/th><\/tr><\/thead><tbody><tr><td><code>dig<\/code> \/ <code>nslookup<\/code><\/td><td>DNS \u89e3\u6790\u67e5\u8be2\uff0c\u63a2\u67e5\u57df\u540d\u80cc\u540e\u7684IP\u548c\u8bb0\u5f55\u7c7b\u578b<\/td><td>\u6807\u51c6\u534f\u8bae\u5de5\u5177\uff0c\u4fe1\u606f\u51c6\u786e\uff0c\u51e0\u4e4e\u6240\u6709\u7cfb\u7edf\u9884\u88c5<\/td><td>\u4ec5\u9650DNS\u5c42\uff0c\u65e0\u6cd5\u770b\u5230\u5e94\u7528\u5c42\u7ec4\u4ef6<\/td><\/tr><tr><td><code>traceroute<\/code> \/ <code>tracert<\/code><\/td><td>\u7f51\u7edc\u8def\u5f84\u8ffd\u8e2a\uff0c\u63a2\u67e5\u4e2d\u95f4\u7f51\u7edc\u8282\u70b9<\/td><td>\u76f4\u89c2\u5c55\u793a\u7f51\u7edc\u8def\u5f84\uff0c\u5e2e\u52a9\u7406\u89e3\u7f51\u7edc\u62d3\u6251<\/td><td>\u7ed3\u679c\u53ef\u80fd\u56e0\u9632\u706b\u5899\u6216ICMP\u5c4f\u853d\u800c\u4e0d\u5b8c\u6574<\/td><\/tr><tr><td>\u6d4f\u89c8\u5668\u5f00\u53d1\u8005\u5de5\u5177 (F12)<\/td><td>\u5206\u6790\u524d\u7aefHTTP\u8bf7\u6c42\u4e0e\u54cd\u5e94\uff0c\u89c2\u5bdf\u8d44\u6e90\u52a0\u8f7d<\/td><td>\u56fe\u5f62\u5316\u754c\u9762\uff0c\u4fe1\u606f\u5168\u9762\uff0c\u80fd\u76f4\u89c2\u770b\u5230\u8bf7\u6c42\u5934\u3001\u54cd\u5e94\u5934\u3001Cookie\u7b49<\/td><td>\u5c40\u9650\u4e8e\u5ba2\u6237\u7aef\u53ef\u89c1\u7684\u4ea4\u4e92\uff0c\u65e0\u6cd5\u63a2\u6d4b\u670d\u52a1\u7aef\u914d\u7f6e<\/td><\/tr><tr><td><code>curl<\/code><\/td><td>\u547d\u4ee4\u884cHTTP\u8bf7\u6c42\u5de5\u5177\uff0c\u7cbe\u7ec6\u63a7\u5236\u8bf7\u6c42\u7ec6\u8282<\/td><td>\u7075\u6d3b\u5f3a\u5927\uff0c\u53ef\u81ea\u5b9a\u4e49\u8bf7\u6c42\u5934\u3001\u65b9\u6cd5\u3001Body\uff0c\u4fbf\u4e8e\u811a\u672c\u5316<\/td><td>\u9700\u8981\u4e00\u5b9a\u7684\u547d\u4ee4\u884c\u57fa\u7840\uff0c\u5bf9HTTPS\u8bc1\u4e66\u5904\u7406\u9700\u8981\u989d\u5916\u53c2\u6570<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h4 class=\"wp-block-heading\">6. \u6807\u51c6\u64cd\u4f5c\u6b65\u9aa4<\/h4>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u9009\u62e9\u4e00\u4e2a\u76ee\u6807<\/strong>\uff1a\u4ee5\u4e00\u4e2a\u4f60\u62e5\u6709\u6216\u6709\u6743\u6d4b\u8bd5\u7684Web\u5e94\u7528\u4e3a\u4f8b\uff0c\u5982\u672c\u5730\u6d4b\u8bd5\u7ad9\u70b9 <code>test.local<\/code>\uff0c\u6216\u516c\u5f00\u6d4b\u8bd5\u7ad9 <code>httpbin.org<\/code>\u3002<\/li>\n\n\n\n<li><strong>\u6253\u5f00\u6d4f\u89c8\u5668\u5f00\u53d1\u8005\u5de5\u5177<\/strong>\uff1a\u6309F12\uff0c\u5207\u6362\u5230\u201c\u7f51\u7edc (Network)\u201d\u6807\u7b7e\u3002<\/li>\n\n\n\n<li><strong>\u8bbf\u95ee\u76ee\u6807\u5e76\u89c2\u5bdf<\/strong>\uff1a\u5728\u6d4f\u89c8\u5668\u5730\u5740\u680f\u8f93\u5165 <code>http:\/\/httpbin.org<\/code> \u5e76\u56de\u8f66\u3002\u89c2\u5bdf\u5f00\u53d1\u8005\u5de5\u5177\u4e2d\u6355\u83b7\u7684\u8bf7\u6c42\u5217\u8868\u3002<\/li>\n\n\n\n<li><strong>\u5206\u6790\u7b2c\u4e00\u4e2a\u8bf7\u6c42<\/strong>\uff1a\u70b9\u51fb\u7b2c\u4e00\u4e2a\u8bf7\u6c42\uff08\u901a\u5e38\u662f\u6587\u6863\u672c\u8eab\uff09\uff0c\u67e5\u770b\u201c\u8bf7\u6c42\u5934 (Request Headers)\u201d\u548c\u201c\u54cd\u5e94\u5934 (Response Headers)\u201d\u3002<\/li>\n\n\n\n<li><strong>\u601d\u8003\u7ec4\u4ef6<\/strong>\uff1a\u54cd\u5e94\u5934\u4e2d\u7684 <code>Server<\/code> \u5b57\u6bb5\uff08\u5982\u679c\u6709\uff09\u53ef\u80fd\u63ed\u793a\u4e86Web\u670d\u52a1\u5668\u8f6f\u4ef6\u3002\u9875\u9762\u6e32\u67d3\u51fa\u7684\u590d\u6742\u529f\u80fd\uff08\u5982\u8868\u5355\u63d0\u4ea4\u3001\u6570\u636e\u67e5\u8be2\uff09\u6697\u793a\u4e86\u540e\u7aef\u5e94\u7528\u6846\u67b6\u548c\u6570\u636e\u5e93\u7684\u5b58\u5728\u3002<\/li>\n<\/ol>\n\n\n\n<h4 class=\"wp-block-heading\">7. \u5982\u4f55\u9a8c\u8bc1\u7ed3\u679c\u771f\u5b9e\u6027<\/h4>\n\n\n\n<p><strong>\u9a8c\u8bc1\u903b\u8f91<\/strong>\uff1a\u6b64\u9636\u6bb5\u4e0d\u9a8c\u8bc1\u5177\u4f53\u7ec4\u4ef6\u7684\u201c\u771f\u5b9e\u6027\u201d\uff0c\u800c\u662f\u9a8c\u8bc1\u201c\u5e94\u7528\u7531\u591a\u7ec4\u4ef6\u6784\u6210\u201d\u8fd9\u4e2a<strong>\u8ba4\u77e5\u6a21\u578b\u7684\u771f\u5b9e\u6027<\/strong>\u3002<br><strong>\u5224\u65ad\u4f9d\u636e<\/strong>\uff1a\u89c2\u5bdf\u5230\u7684\u73b0\u8c61\u662f\u5426\u53ef\u4ee5\u7528\u591a\u7ec4\u4ef6\u6a21\u578b\u6765\u89e3\u91ca\u3002\u4f8b\u5982\uff0c\u770b\u5230\u4e00\u4e2a\u767b\u5f55\u9875\u9762\uff0c\u4e0d\u5e94\u7b80\u5355\u5f52\u7ed3\u4e3a\u201c\u8fd9\u662f\u53f0Linux\u670d\u52a1\u5668\u201d\uff0c\u800c\u5e94\u63a8\u65ad\u4e3a\u201c\u8fd9\u5f88\u53ef\u80fd\u662f\u4e00\u4e2a\u7531\u524d\u7aef\u9875\u9762\u3001\u540e\u7aefAPI\uff08\u5904\u7406\u767b\u5f55\u903b\u8f91\uff09\u548c\u6570\u636e\u5e93\uff08\u5b58\u50a8\u7528\u6237\u51ed\u8bc1\uff09\u6784\u6210\u7684\u7cfb\u7edf\u201d\u3002\u8fd9\u79cd\u63a8\u65ad\u662f\u540e\u7eed\u6b65\u9aa4\u7684\u57fa\u7840\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">8. \u5e38\u89c1\u9519\u8bef\u4e0e\u6392\u67e5\u65b9\u5f0f<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u9519\u8bef<\/strong>\uff1a\u5c06Web\u5e94\u7528\u7b49\u540c\u4e8eWeb\u670d\u52a1\u5668\u3002<\/li>\n\n\n\n<li><strong>\u6392\u67e5<\/strong>\uff1a\u63d0\u9192\u81ea\u5df1Web\u670d\u52a1\u5668\u53ea\u662f\u5165\u53e3\u3002\u52a8\u6001\u5185\u5bb9\u3001\u6837\u5f0f\u3001\u56fe\u7247\u3001API\u63a5\u53e3\u5747\u7531\u4e0d\u540c\u7ec4\u4ef6\u6216\u670d\u52a1\u63d0\u4f9b\u3002\u5c1d\u8bd5\u7981\u7528\u6d4f\u89c8\u5668\u4e2d\u7684JavaScript\uff0c\u89c2\u5bdf\u9875\u9762\u529f\u80fd\u662f\u5426\u7f3a\u5931\uff0c\u8fd9\u6709\u52a9\u4e8e\u533a\u5206\u524d\u7aef\u548c\u540e\u7aef\u7ec4\u4ef6\u7684\u804c\u8d23\u3002<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">9. \u5408\u89c4\u8fb9\u754c\u8bf4\u660e<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u4f7f\u7528\u573a\u666f<\/strong>\uff1a\u672c\u6a21\u5757\u4ec5\u7528\u4e8e\u5efa\u7acb\u5185\u90e8\u77e5\u8bc6\u4f53\u7cfb\u548c\u601d\u7ef4\u8bad\u7ec3\uff0c\u4e0d\u6d89\u53ca\u4efb\u4f55\u5b9e\u9645\u76ee\u6807\u7cfb\u7edf\u7684\u626b\u63cf\u6216\u63a2\u6d4b\u3002<\/li>\n\n\n\n<li><strong>\u7f51\u7edc\u5b89\u5168\u89c6\u89d2<\/strong>\uff1a\u98ce\u9669\u5728\u4e8e\uff0c\u82e5\u8fd0\u7ef4\u4eba\u5458\u7f3a\u4e4f\u201c\u5206\u5e03\u5f0f\u201d\u89c6\u89d2\uff0c\u53ef\u80fd\u9519\u8bef\u914d\u7f6e\u5b89\u5168\u7b56\u7565\uff08\u5982\u53ea\u4fdd\u62a4Web\u670d\u52a1\u5668\u800c\u5ffd\u7565\u540e\u7aefAPI\u6216\u6570\u636e\u5e93\u8bbf\u95ee\u63a7\u5236\uff09\u3002\u7f13\u89e3\u63aa\u65bd\u662f\u8fdb\u884c\u5168\u9762\u7684\u8d44\u4ea7\u76d8\u70b9\u3002<\/li>\n\n\n\n<li><strong>\u51b3\u7b56\u6307\u5357<\/strong>\uff1a\u5728\u5b66\u4e60\u4efb\u4f55\u65b0\u5e94\u7528\u67b6\u6784\u65f6\uff0c\u5efa\u8bae\u9996\u5148\u8fdb\u884c\u6b64\u601d\u7ef4\u91cd\u6784\u3002\u8fd9\u662f\u6240\u6709\u540e\u7eed\u5206\u6790\u5de5\u4f5c\u7684\u524d\u63d0\uff0c\u65e0\u66ff\u4ee3\u65b9\u6848\u3002<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">10. \u672c\u6a21\u5757\u9636\u6bb5\u6027\u5c0f\u7ed3<\/h4>\n\n\n\n<p>\u6211\u4eec\u4ece\u5355\u4e00\u4e3b\u673a\u7684\u56fa\u6709\u601d\u7ef4\u4e2d\u8d70\u51fa\uff0c\u5efa\u7acb\u4e86\u5e94\u7528\u7531\u591a\u7ec4\u4ef6\u6784\u6210\u7684\u8ba4\u77e5\u6a21\u578b\u3002\u73b0\u5728\u660e\u786e\u4e86\u5e94\u5728\u54ea\u4e9b\u7ef4\u5ea6\uff08\u7f51\u7edc\u3001\u534f\u8bae\u3001\u7ec4\u4ef6\uff09\u4e0a\u89c2\u5bdf\u3002\u63a5\u4e0b\u6765\uff0c\u6211\u4eec\u5c06\u8fd9\u79cd\u5b8f\u89c2\u8ba4\u77e5\u8f6c\u5316\u4e3a\u5177\u4f53\u7684\u63a2\u67e5\u76ee\u6807\uff0c\u5b66\u4e60\u5982\u4f55\u754c\u5b9a\u63a2\u67e5\u7684\u8303\u56f4\u548c\u91cd\u70b9\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u4e8c\u3001\u754c\u5b9a\u63a2\u67e5\u76ee\u6807\u4e0e\u8303\u56f4<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">1. \u6a21\u5757\u6982\u5ff5\u89e3\u91ca<\/h4>\n\n\n\n<p>\u627f\u63a5\u4e0a\u4e00\u6a21\u5757\u5bf9\u5e94\u7528\u67b6\u6784\u7684\u8ba4\u77e5\u91cd\u6784\uff0c\u73b0\u5728\u6211\u4eec\u9700\u8981\u5c06\u5b8f\u89c2\u89c6\u89d2\u8f6c\u5316\u4e3a\u53ef\u64cd\u4f5c\u7684\u4efb\u52a1\u6e05\u5355\u3002\u9762\u5bf9\u590d\u6742\u5e94\u7528\u67b6\u6784\uff0c\u4e0d\u53ef\u80fd\u4e5f\u65e0\u5fc5\u8981\u5bf9\u6240\u6709\u7ec4\u4ef6\u8fdb\u884c\u540c\u7b49\u6df1\u5ea6\u63a2\u67e5\u3002\u672c\u6a21\u5757\u7684\u6838\u5fc3\u4efb\u52a1\u662f\u201c\u5212\u5b9a\u8fb9\u754c\u201d\uff0c\u5373\u660e\u786e\u9700\u8981\u8bc6\u522b\u7684\u7ec4\u4ef6\u7c7b\u578b\uff08\u5982 Web \u670d\u52a1\u5668\u3001\u4e2d\u95f4\u4ef6\u3001\u5f00\u53d1\u6846\u67b6\u3001\u6570\u636e\u5e93\u3001API \u7f51\u5173\u7b49\uff09\u53ca\u5176\u5728\u5e94\u7528\u670d\u52a1\u4e2d\u7684\u5177\u4f53\u89d2\u8272\u3002\u8fd9\u6709\u52a9\u4e8e\u805a\u7126\u8d44\u6e90\uff0c\u907f\u514d\u5728\u6d77\u91cf\u4fe1\u606f\u4e2d\u8ff7\u5931\u65b9\u5411\uff0c\u786e\u4fdd\u540e\u7eed\u63a2\u67e5\u9ad8\u6548\u4e14\u6709\u9488\u5bf9\u6027\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">2. \u6280\u672f\u539f\u7406\u8bf4\u660e<\/h4>\n\n\n\n<p>\u5178\u578b Web \u5e94\u7528\u8bf7\u6c42\u6d41\u7a0b\u5982\u4e0b\uff1a\u5ba2\u6237\u7aef -&gt; (CDN) -&gt; (\u8d1f\u8f7d\u5747\u8861\u5668) -&gt; Web \u670d\u52a1\u5668 -&gt; \u5e94\u7528\u6846\u67b6 -&gt; \u6570\u636e\u5e93\u3002\u94fe\u6761\u4e0a\u7684\u6bcf\u4e2a\u73af\u8282\u90fd\u662f\u6f5c\u5728\u7684\u63a2\u67e5\u76ee\u6807\u3002\u6280\u672f\u539f\u7406\u5728\u4e8e\uff0c\u4e0d\u540c\u7ec4\u4ef6\u5728\u8bf7\u6c42-\u54cd\u5e94\u751f\u547d\u5468\u671f\u4e2d\u626e\u6f14\u4e0d\u540c\u89d2\u8272\uff0c\u56e0\u6b64\u5b83\u4eec\u7559\u4e0b\u7684\u201c\u6307\u7eb9\u201d\u5206\u5e03\u5728\u4e0d\u540c\u7684\u6570\u636e\u5c42\u9762\u3002\u4f8b\u5982\uff0cWeb \u670d\u52a1\u5668\u7684\u6307\u7eb9\u5e38\u5728\u54cd\u5e94\u5934\u7684 <code>Server<\/code> \u5b57\u6bb5\uff0c\u800c\u5e94\u7528\u6846\u67b6\u7684\u6307\u7eb9\u53ef\u80fd\u85cf\u5728 Cookie \u7684\u683c\u5f0f\u3001\u7279\u5b9a\u7684 URL \u8def\u5f84\u6216 HTML \u6ce8\u91ca\u4e2d\u3002\u754c\u5b9a\u76ee\u6807\u5373\u6839\u636e\u76ee\u7684\uff08\u5982\u5b89\u5168\u8bc4\u4f30\u3001\u517c\u5bb9\u6027\u6d4b\u8bd5\u3001\u8d44\u4ea7\u68b3\u7406\uff09\uff0c\u9009\u62e9\u94fe\u6761\u4e0a\u6700\u5173\u5fc3\u7684\u73af\u8282\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">3. \u5728\u7cfb\u7edf\u4e2d\u7684\u4f4d\u7f6e<\/h4>\n\n\n\n<p>\u672c\u6a21\u5757\u7d27\u63a5\u5728\u201c\u91cd\u6784\u8ba4\u77e5\u201d\u4e4b\u540e\uff0c\u662f\u5c06\u5b8f\u89c2\u8ba4\u77e5\u8f6c\u5316\u4e3a\u5177\u4f53\u64cd\u4f5c\u6e05\u5355\u7684\u7b2c\u4e00\u6b65\u3002\u5b83\u544a\u77e5\u201c\u89e3\u6790\u7279\u5f81\u201d\u6a21\u5757\u5e94\u89e3\u6790\u54ea\u4e9b\u7ec4\u4ef6\u7684\u7279\u5f81\uff0c\u5e76\u4e3a\u540e\u7eed\u201c\u6784\u5efa\u8bc6\u522b\u6a21\u578b\u201d\u63d0\u4f9b\u8f93\u5165\u9879\uff0c\u8d77\u5230\u627f\u4e0a\u542f\u4e0b\u7684\u201c\u8fc7\u6ee4\u5668\u201d\u4f5c\u7528\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">4. \u53ef\u6267\u884c\u547d\u4ee4\u6216\u67e5\u8be2\u65b9\u5f0f<\/h4>\n\n\n\n<p>\u5728\u6b64\u9636\u6bb5\uff0c\u901a\u8fc7\u521d\u6b65\u4fe1\u606f\u6536\u96c6\u547d\u4ee4\u5e2e\u52a9\u201c\u754c\u5b9a\u8303\u56f4\u201d\uff0c\u800c\u975e\u6df1\u5165\u8bc6\u522b\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># \u4f7f\u7528 curl \u67e5\u770b\u54cd\u5e94\u5934\uff0c\u521d\u6b65\u5224\u65ad\u5b58\u5728\u54ea\u4e9b\u7ec4\u4ef6\uff08\u5982 Server, Set-Cookie \u7b49\uff09\ncurl -I http:\/\/httpbin.org\n\n# \u4f7f\u7528 nmap \u5bf9\u76ee\u6807\u8fdb\u884c\u7aef\u53e3\u626b\u63cf\uff0c\u53d1\u73b0\u5f00\u653e\u4e86\u54ea\u4e9b\u670d\u52a1\uff08\u4e0d\u4ec5\u4ec5\u662f80\/443\uff09\n# scanme.nmap.org \u662f\u5b98\u65b9\u63d0\u4f9b\u7684\u5408\u6cd5\u6d4b\u8bd5\u76ee\u6807\nnmap -p- scanme.nmap.org\n\n# \u4f7f\u7528 whatweb \u8fdb\u884c\u521d\u6b65\u7684\u3001\u5bbd\u6cdb\u7684\u5e94\u7528\u8bc6\u522b\uff0c\u5b83\u4f1a\u5217\u51fa\u5b83\u8ba4\u4e3a\u5b58\u5728\u7684\u7ec4\u4ef6\nwhatweb http:\/\/httpbin.org<\/code><\/pre>\n\n\n\n<p>\u901a\u8fc7\u89c2\u5bdf\u8fd9\u4e9b\u547d\u4ee4\u7684\u8f93\u51fa\uff0c\u53ef\u4ee5\u5217\u51fa\u4e00\u4e2a\u521d\u6b65\u7684\u201c\u7ec4\u4ef6\u6e05\u5355\u201d\uff0c\u4f8b\u5982\uff1a\u53ef\u80fd\u6709\u4e00\u4e2a Web \u670d\u52a1\u5668\uff08nginx\uff09\uff0c\u53ef\u80fd\u6709\u4e00\u4e2a Python \u6846\u67b6\uff08\u901a\u8fc7 <code>httpbin<\/code> \u7684\u54cd\u5e94\u7279\u5f81\uff09\uff0c\u53ef\u80fd\u8fd8\u6709\u522b\u7684\u7aef\u53e3\uff08\u5982 22\/ssh\uff09\u8fd0\u884c\u7740\u5176\u4ed6\u670d\u52a1\u3002\u8fd9\u5c31\u662f\u521d\u6b65\u754c\u5b9a\u7684\u63a2\u67e5\u76ee\u6807\u8303\u56f4\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">5. \u5de5\u5177\u5bf9\u6bd4\u8868<\/h4>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u5de5\u5177<\/th><th>\u9002\u7528\u573a\u666f<\/th><th>\u4f18\u70b9<\/th><th>\u5c40\u9650<\/th><\/tr><\/thead><tbody><tr><td><code>curl -I<\/code><\/td><td>\u5feb\u901f\u67e5\u770bHTTP\u54cd\u5e94\u5934\uff0c\u8bc6\u522bWeb\u670d\u52a1\u5668\u548c Cookies<\/td><td>\u7b80\u5355\u5feb\u901f\uff0c\u51e0\u4e4e\u65e0\u5904\u4e0d\u5728<\/td><td>\u4fe1\u606f\u91cf\u6709\u9650\uff0c\u65e0\u6cd5\u63a2\u6d4b\u6df1\u5c42\u6846\u67b6\u548c\u7ec4\u4ef6<\/td><\/tr><tr><td><code>nmap<\/code><\/td><td>\u7aef\u53e3\u626b\u63cf\uff0c\u53d1\u73b0\u76ee\u6807\u4e3b\u673a\u4e0a\u6240\u6709\u5f00\u653e\u7684TCP\/UDP\u7aef\u53e3<\/td><td>\u7f51\u7edc\u5c42\u53d1\u73b0\u7684\u5229\u5668\uff0c\u80fd\u7ed8\u5236\u51fa\u670d\u52a1\u7684\u201c\u66b4\u9732\u9762\u201d<\/td><td>\u901f\u5ea6\u8f83\u6162\uff08\u5c24\u5176\u662f\u5168\u7aef\u53e3\u626b\u63cf\uff09\uff0c\u65e0\u6cd5\u8bc6\u522b\u5e94\u7528\u5c42\u5177\u4f53\u7248\u672c<\/td><\/tr><tr><td><code>whatweb<\/code><\/td><td>\u5e94\u7528\u5c42\u6307\u7eb9\u8bc6\u522b\uff0c\u4e3b\u52a8\u63a2\u6d4bWeb\u5e94\u7528\u53ca\u5176\u7ec4\u4ef6<\/td><td>\u81ea\u52a8\u5316\u7a0b\u5ea6\u9ad8\uff0c\u63d2\u4ef6\u4e30\u5bcc\uff0c\u80fd\u8bc6\u522b\u5927\u91cfCMS\u3001\u6846\u67b6\u3001\u5e93<\/td><td>\u53ef\u80fd\u4ea7\u751f\u8bef\u62a5\uff0c\u5bf9\u81ea\u5b9a\u4e49\u5e94\u7528\u7684\u8bc6\u522b\u80fd\u529b\u5f31<\/td><\/tr><tr><td><code>wappalyzer<\/code> (\u6d4f\u89c8\u5668\u63d2\u4ef6)<\/td><td>\u88ab\u52a8\u5206\u6790\uff0c\u5728\u6d4f\u89c8\u7f51\u9875\u65f6\u8bc6\u522b\u6240\u4f7f\u7528\u7684\u6280\u672f\u6808<\/td><td>\u65b9\u4fbf\u5feb\u6377\uff0c\u7ed3\u679c\u76f4\u89c2\uff0c\u4e0d\u5f71\u54cd\u76ee\u6807\u670d\u52a1\u5668<\/td><td>\u4ec5\u5206\u6790\u5ba2\u6237\u7aef\u53ef\u89c1\u5185\u5bb9\uff0c\u65e0\u6cd5\u63a2\u6d4b\u670d\u52a1\u7aef\u914d\u7f6e<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h4 class=\"wp-block-heading\">6. \u6807\u51c6\u64cd\u4f5c\u6b65\u9aa4<\/h4>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u8bbe\u5b9a\u76ee\u6807<\/strong>\uff1a\u5047\u8bbe\u76ee\u6807\u4e3a\u5168\u9762\u4e86\u89e3 <code>http:\/\/test.local<\/code> \u6d4b\u8bd5\u5e94\u7528\u7684\u6280\u672f\u6808\u3002<\/li>\n\n\n\n<li><strong>\u7f51\u7edc\u5c42\u8303\u56f4\u754c\u5b9a<\/strong>\uff1a\u6267\u884c <code>nmap -sV -T4 test.local<\/code>\u3002<code>-sV<\/code> \u53c2\u6570\u5c1d\u8bd5\u63a2\u6d4b\u670d\u52a1\u7248\u672c\uff0c\u5e2e\u52a9\u786e\u8ba4\u5f00\u653e\u7aef\u53e3\u4e0a\u8fd0\u884c\u7684\u670d\u52a1\u7c7b\u578b\uff08\u5982 <code>Apache httpd<\/code>, <code>MySQL<\/code>\uff09\u3002<\/li>\n\n\n\n<li><strong>\u5e94\u7528\u5c42\u8303\u56f4\u754c\u5b9a<\/strong>\uff1a\u6267\u884c <code>whatweb http:\/\/test.local<\/code> \u6216\u4f7f\u7528 Wappalyzer \u8bbf\u95ee\u8be5\u7ad9\u70b9\u3002\u8bb0\u5f55\u6240\u6709\u88ab\u8bc6\u522b\u51fa\u7684\u7ec4\u4ef6\uff0c\u65e0\u8bba\u7f6e\u4fe1\u5ea6\u9ad8\u4f4e\u3002<\/li>\n\n\n\n<li><strong>\u624b\u52a8\u5206\u6790\u8865\u5145<\/strong>\uff1a\u5728\u6d4f\u89c8\u5668\u4e2d\u6253\u5f00\u5f00\u53d1\u8005\u5de5\u5177\uff0c\u67e5\u770b\u6240\u6709\u52a0\u8f7d\u7684\u8d44\u6e90\uff08JS, CSS, \u56fe\u7247\uff09\u3002\u8fd9\u4e9b\u8d44\u6e90\u7684\u8def\u5f84\u6709\u65f6\u4f1a\u66b4\u9732\u6240\u4f7f\u7528\u7684\u6846\u67b6\u6216\u5e93\uff08\u5982 <code>\/static\/js\/jquery.min.js<\/code> \u6697\u793a jQuery \u5e93\uff09\u3002<\/li>\n\n\n\n<li><strong>\u5f62\u6210\u521d\u59cb\u6e05\u5355<\/strong>\uff1a\u7efc\u5408\u4ee5\u4e0a\u4fe1\u606f\uff0c\u5217\u51fa\u63a5\u4e0b\u6765\u9700\u8981\u91cd\u70b9\u63a2\u67e5\u7684\u7ec4\u4ef6\u6e05\u5355\uff0c\u4f8b\u5982\uff1a[Web\u670d\u52a1\u5668: Apache?, \u540e\u7aef\u8bed\u8a00: PHP?, \u524d\u7aef\u5e93: jQuery, \u6570\u636e\u5e93: MySQL?]\u3002<\/li>\n<\/ol>\n\n\n\n<h4 class=\"wp-block-heading\">7. \u5982\u4f55\u9a8c\u8bc1\u7ed3\u679c\u771f\u5b9e\u6027<\/h4>\n\n\n\n<p><strong>\u9a8c\u8bc1\u903b\u8f91<\/strong>\uff1a\u901a\u8fc7\u4e0d\u540c\u6765\u6e90\u3001\u4e0d\u540c\u7c7b\u578b\u7684\u4fe1\u606f\u8fdb\u884c\u4ea4\u53c9\u9a8c\u8bc1\uff0c\u5224\u65ad\u521d\u6b65\u6e05\u5355\u7684\u5408\u7406\u6027\u3002<br><strong>\u5224\u65ad\u4f9d\u636e<\/strong>\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><code>nmap<\/code> \u53d1\u73b080\u7aef\u53e3\u5f00\u653e\uff0c\u670d\u52a1\u662f Apache\u3002\u8fd9\u4e0e <code>whatweb<\/code> \u62a5\u544a\u7684 <code>Apache<\/code> \u543b\u5408\uff0c\u63d0\u9ad8\u53ef\u4fe1\u5ea6\u3002<\/li>\n\n\n\n<li><code>whatweb<\/code> \u62a5\u544a\u4e86 <code>PHP<\/code>\uff0c\u540c\u65f6 <code>curl<\/code> \u67e5\u770b\u9875\u9762 URL \u53ef\u80fd\u5305\u542b <code>.php<\/code> \u540e\u7f00\uff0c\u8fd9\u4e5f\u662f\u4e00\u79cd\u4ea4\u53c9\u9a8c\u8bc1\u3002<\/li>\n\n\n\n<li>\u82e5 <code>nmap<\/code> \u672a\u53d1\u73b03306\u7aef\u53e3\u5f00\u653e\uff0c\u4f46\u521d\u6b65\u6e05\u5355\u91cc\u5374\u6709 MySQL\uff0c\u5219\u9700\u8981\u601d\u8003\uff1a\u6570\u636e\u5e93\u662f\u5426\u5728\u5185\u7f51\u4e0d\u5bf9\u5916\u66b4\u9732\uff1f\u6216\u5224\u65ad\u6709\u8bef\uff1f\u8fd9\u6307\u5f15\u4e86\u4e0b\u4e00\u6b65\u63a2\u67e5\u65b9\u5411\u3002<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">8. \u5e38\u89c1\u9519\u8bef\u4e0e\u6392\u67e5\u65b9\u5f0f<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u9519\u8bef<\/strong>\uff1a\u8303\u56f4\u5b9a\u5f97\u8fc7\u5927\u6216\u8fc7\u5c0f\u3002\u8fc7\u5927\u5bfc\u81f4\u4fe1\u606f\u8fc7\u8f7d\uff0c\u8fc7\u5c0f\u5bfc\u81f4\u9057\u6f0f\u5173\u952e\u7ec4\u4ef6\u3002<\/li>\n\n\n\n<li><strong>\u6392\u67e5<\/strong>\uff1a\u9075\u5faa\u201c\u5148\u5bbd\u540e\u7a84\u201d\u539f\u5219\u3002\u5148\u7528 <code>nmap -p-<\/code> \u626b\u6240\u6709\u7aef\u53e3\uff0c\u518d\u7528 <code>-sV<\/code> \u6df1\u5165\u63a2\u6d4b\u3002\u82e5\u53d1\u73b0\u67d0\u4e2a\u9884\u671f\u7ec4\u4ef6\uff08\u5982\u6570\u636e\u5e93\uff09\u672a\u51fa\u73b0\u5728\u521d\u59cb\u6e05\u5355\u4e2d\uff0c\u9700\u8003\u8651\u7f51\u7edc\u9694\u79bb\u6216\u670d\u52a1\u9690\u85cf\u7684\u53ef\u80fd\u6027\u3002<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">9. \u5408\u89c4\u8fb9\u754c\u8bf4\u660e<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u4f7f\u7528\u573a\u666f<\/strong>\uff1a\u672c\u6a21\u5757\u7684\u64cd\u4f5c\u5e94\u7528\u4e8e\u4f60\u62e5\u6709\u5408\u6cd5\u6388\u6743\u7684\u7cfb\u7edf\uff0c\u6216\u660e\u786e\u5141\u8bb8\u6d4b\u8bd5\u7684\u516c\u5171\u76ee\u6807\uff08\u5982 <code>scanme.nmap.org<\/code>\uff09\u3002<\/li>\n\n\n\n<li><strong>\u7f51\u7edc\u5b89\u5168\u89c6\u89d2<\/strong>\uff1a\u98ce\u9669\u5728\u4e8e\uff0c\u672a\u7ecf\u6388\u6743\u7684\u7aef\u53e3\u626b\u63cf\u53ef\u80fd\u88ab\u89c6\u4e3a\u653b\u51fb\u524d\u594f\u6216\u6076\u610f\u884c\u4e3a\uff0c\u89e6\u53d1\u76ee\u6807\u7cfb\u7edf\u7684\u5165\u4fb5\u68c0\u6d4b\u7cfb\u7edf\uff08IDS\uff09\u6216\u9632\u706b\u5899\u544a\u8b66\u3002\u7f13\u89e3\u63aa\u65bd\u662f\u4e25\u683c\u5728\u6388\u6743\u8303\u56f4\u5185\u64cd\u4f5c\uff0c\u5e76\u4f7f\u7528\u9002\u5f53\u7684\u626b\u63cf\u901f\u7387\uff08\u5982 <code>nmap -T2<\/code>\uff09\u4ee5\u51cf\u5c11\u4fb5\u6270\u6027\u3002<\/li>\n\n\n\n<li><strong>\u51b3\u7b56\u6307\u5357<\/strong>\uff1a\u5f53\u9700\u8981\u4e86\u89e3\u4e00\u4e2a\u672a\u77e5\u7cfb\u7edf\u7684\u201c\u66b4\u9732\u9762\u201d\u65f6\uff0c\u5efa\u8bae\u6267\u884c\u6b64\u6a21\u5757\u3002\u82e5\u5df2\u901a\u8fc7\u5176\u4ed6\u65b9\u5f0f\u83b7\u5f97\u51c6\u786e\u7684\u8d44\u4ea7\u6e05\u5355\uff0c\u5219\u53ef\u8df3\u8fc7\u6b64\u6b65\u9aa4\uff0c\u76f4\u63a5\u8fdb\u884c\u6df1\u5165\u8bc6\u522b\u3002<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">10. \u672c\u6a21\u5757\u9636\u6bb5\u6027\u5c0f\u7ed3<\/h4>\n\n\n\n<p>\u6211\u4eec\u5b66\u4f1a\u4e86\u5982\u4f55\u4ece\u6df7\u6c8c\u4fe1\u606f\u4e2d\u68b3\u7406\u51fa\u4e00\u4efd\u9700\u8981\u6df1\u5165\u63a2\u67e5\u7684\u7ec4\u4ef6\u6e05\u5355\u3002\u73b0\u5728\u660e\u786e\u4e86\u8981\u67e5\u4ec0\u4e48\uff1aWeb \u670d\u52a1\u5668\u3001\u6846\u67b6\u3001\u6570\u636e\u5e93\u7b49\u3002\u6709\u4e86\u76ee\u6807\u4e4b\u540e\uff0c\u4e0b\u4e00\u4e2a\u5173\u952e\u95ee\u9898\u662f\uff1a\u8fd9\u4e9b\u7ec4\u4ef6\u5404\u81ea\u4f1a\u7559\u4e0b\u600e\u6837\u7684\u201c\u6307\u7eb9\u201d\uff1f\u4e0b\u4e00\u6a21\u5757\u5c06\u6df1\u5165\u89e3\u6790\u670d\u52a1\u7ec4\u4ef6\u7684\u7279\u5f81\u7ed3\u6784\u3002<\/p>\n\n\n\n<p><strong>\u63a2\u67e5\u8303\u56f4\u754c\u5b9a\u8fc7\u7a0b\u793a\u610f\u56fe<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/03\/\u63a2\u67e5\u8303\u56f4\u754c\u5b9a\u8fc7\u7a0b\u793a\u610f\u56fe-1024x796.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"796\" data-original=\"http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/03\/\u63a2\u67e5\u8303\u56f4\u754c\u5b9a\u8fc7\u7a0b\u793a\u610f\u56fe-1024x796.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1777\"  sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/div><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">\u4e09\u3001\u89e3\u6790\u670d\u52a1\u7ec4\u4ef6\u7279\u5f81\u7ed3\u6784<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">1. \u6a21\u5757\u6982\u5ff5\u89e3\u91ca<\/h4>\n\n\n\n<p>\u660e\u786e\u4e86\u63a2\u67e5\u76ee\u6807\u540e\uff0c\u9700\u8981\u56de\u7b54\u4e00\u4e2a\u6838\u5fc3\u95ee\u9898\uff1a\u4e00\u4e2a\u670d\u52a1\u7ec4\u4ef6\u201c\u957f\u4ec0\u4e48\u6837\u201d\uff1f\u5373\u901a\u8fc7\u4ec0\u4e48\u65b9\u5f0f\u6765\u201c\u8ba4\u51fa\u201d\u5b83\uff1f\u672c\u6a21\u5757\u4e13\u95e8\u62c6\u89e3\u5404\u7c7b\u7ec4\u4ef6\u53ef\u88ab\u89c2\u6d4b\u7684\u3001\u72ec\u7279\u7684\u201c\u6307\u7eb9\u201d\u7279\u5f81\u3002\u8fd9\u4e9b\u7279\u5f81\u5177\u4f53\u5b58\u5728\u4e8e\u7f51\u7edc\u534f\u8bae\u4ea4\u4e92\u7684\u5404\u4e2a\u5c42\u9762\u4e2d\uff0c\u4f8b\u5982\u7279\u5b9a\u7684\u54cd\u5e94\u5934\u3001URL \u8def\u5f84\u3001HTML \u4ee3\u7801\u7ed3\u6784\u3001\u4f1a\u8bdd Cookie \u683c\u5f0f\u7b49\u3002\u7406\u89e3\u8fd9\u4e9b\u7279\u5f81\u7684\u6765\u6e90\u548c\u4f4d\u7f6e\uff0c\u662f\u51c6\u786e\u8bc6\u522b\u7ec4\u4ef6\u7684\u524d\u63d0\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">2. \u6280\u672f\u539f\u7406\u8bf4\u660e<\/h4>\n\n\n\n<p>\u670d\u52a1\u7ec4\u4ef6\u5728\u8bbe\u8ba1\u548c\u5b9e\u73b0\u65f6\uff0c\u4f1a\u9075\u5faa\u7279\u5b9a\u89c4\u8303\u6216\u4f7f\u7528\u7279\u5b9a\u5e93\/\u6846\u67b6\uff0c\u8fd9\u4e9b\u201c\u7279\u5b9a\u6027\u201d\u4e0d\u53ef\u907f\u514d\u5730\u4f1a\u66b4\u9732\u5728\u4e0e\u5176\u4ea4\u4e92\u7684\u7f51\u7edc\u6d41\u91cf\u4e2d\u3002\u6280\u672f\u539f\u7406\u53ef\u5f52\u7eb3\u4e3a\u201c\u5b9e\u73b0\u5dee\u5f02\u7684\u5fc5\u7136\u66b4\u9732\u201d\u3002<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u534f\u8bae\u5c42\u7279\u5f81<\/strong>\uff1a\u5982 HTTP\/1.1 vs HTTP\/2\uff0c<code>Server<\/code> \u5934\uff0c<code>X-Powered-By<\/code> \u5934\u7b49\uff0c\u662f\u7ec4\u4ef6\u5728\u534f\u8bae\u4ea4\u4e92\u4e2d\u4e3b\u52a8\u58f0\u660e\u6216\u88ab\u52a8\u66b4\u9732\u7684\u3002<\/li>\n\n\n\n<li><strong>\u8def\u5f84\u4e0e\u6587\u4ef6\u7279\u5f81<\/strong>\uff1a\u8bb8\u591a\u6846\u67b6\u6216 CMS\uff08\u5185\u5bb9\u7ba1\u7406\u7cfb\u7edf\uff09\u5728\u5b89\u88c5\u540e\uff0c\u4f1a\u5728\u7279\u5b9a\u8def\u5f84\u4e0b\u9057\u7559\u7279\u5b9a\u6587\u4ef6\uff08\u5982 <code>readme.html<\/code>, <code>phpinfo.php<\/code>, <code>wp-login.php<\/code>\uff09\u3002\u8bbf\u95ee\u8fd9\u4e9b\u8def\u5f84\uff0c\u82e5\u5f97\u5230\u9884\u671f\u54cd\u5e94\uff0c\u5373\u53ef\u786e\u8ba4\u7ec4\u4ef6\u3002<\/li>\n\n\n\n<li><strong>\u5185\u5bb9\u7279\u5f81<\/strong>\uff1aHTML \u6e90\u4ee3\u7801\u4e2d\u7684\u7279\u5b9a\u6ce8\u91ca\uff08<code>&lt;!-- \/wordpress --><\/code>\uff09\u3001JavaScript\/CSS \u6587\u4ef6\u7684\u7279\u5b9a\u8def\u5f84\uff08<code>\/wp-content\/<\/code>\uff09\u3001\u7279\u5b9a\u683c\u5f0f\u7684 Cookie\uff08\u5982 <code>.ASPXAUTH<\/code> \u6697\u793a ASP.NET\uff09\u7b49\uff0c\u90fd\u662f\u7ec4\u4ef6\u7684\u201c\u70d9\u5370\u201d\u3002<\/li>\n\n\n\n<li><strong>\u884c\u4e3a\u7279\u5f81<\/strong>\uff1a\u5bf9\u7279\u5b9a\u8f93\u5165\uff08\u5982\u7578\u5f62\u8bf7\u6c42\uff09\u7684\u54cd\u5e94\u65b9\u5f0f\uff0c\u4e5f\u53ef\u4f5c\u4e3a\u7279\u5f81\uff0c\u4f46\u901a\u5e38\u7528\u4e8e\u66f4\u6df1\u5ea6\u7684\u7814\u7a76\uff0c\u6807\u51c6\u63a2\u67e5\u4e2d\u8f83\u5c11\u4f7f\u7528\u3002<\/li>\n<\/ol>\n\n\n\n<h4 class=\"wp-block-heading\">3. \u5728\u7cfb\u7edf\u4e2d\u7684\u4f4d\u7f6e<\/h4>\n\n\n\n<p>\u672c\u6a21\u5757\u662f\u201c\u7279\u5f81\u8bc6\u522b\u65b9\u6cd5\u201d\u7684\u57fa\u7840\u539f\u6599\u5e93\u3002\u5b83\u5c06\u201c\u63a2\u67e5\u76ee\u6807\u201d\uff08\u5982 Web \u670d\u52a1\u5668\uff09\u4e0e\u201c\u53ef\u89c2\u6d4b\u73b0\u8c61\u201d\uff08\u5982 <code>Server: nginx<\/code>\uff09\u5173\u8054\u8d77\u6765\u3002\u540e\u7eed\u7684\u201c\u6784\u5efa\u8bc6\u522b\u6a21\u578b\u201d\uff0c\u672c\u8d28\u4e0a\u662f\u5bf9\u6b64\u539f\u6599\u5e93\u4e2d\u7684\u7279\u5f81\u8fdb\u884c\u63d0\u53d6\u3001\u5f52\u7eb3\u548c\u5339\u914d\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">4. \u53ef\u6267\u884c\u547d\u4ee4\u6216\u67e5\u8be2\u65b9\u5f0f<\/h4>\n\n\n\n<p>\u6b64\u9636\u6bb5\u901a\u8fc7\u6784\u9020\u7279\u5b9a\u8bf7\u6c42\u6765\u201c\u63d0\u53d6\u201d\u7279\u5f81\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># 1. \u63d0\u53d6\u54cd\u5e94\u5934\u7279\u5f81\ncurl -I http:\/\/httpbin.org\/anything\n\n# 2. \u63d0\u53d6\u7279\u5b9a\u8def\u5f84\u7279\u5f81 (\u68c0\u67e5\u662f\u5426\u5b58\u5728 favicon.ico\uff0c\u6709\u65f6\u5176hash\u503c\u53ef\u8bc6\u522b\u6846\u67b6)\ncurl -s -o \/dev\/null -w \"%{http_code}\" http:\/\/httpbin.org\/favicon.ico\n\n# 3. \u63d0\u53d6HTML\u5185\u5bb9\u4e2d\u7684\u7279\u5f81\ncurl -s http:\/\/httpbin.org\/ | grep -i \"generator\" # \u67e5\u627e generator \u5143\u6807\u7b7e\n\n# 4. \u63d0\u53d6Cookie\u7279\u5f81\ncurl -I -c - http:\/\/httpbin.org\/cookies\/set?name=value # -c - \u4f1a\u8f93\u51faCookie\u4fe1\u606f<\/code><\/pre>\n\n\n\n<h4 class=\"wp-block-heading\">5. \u5de5\u5177\u5bf9\u6bd4\u8868<\/h4>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u5de5\u5177<\/th><th>\u9002\u7528\u573a\u666f<\/th><th>\u4f18\u70b9<\/th><th>\u5c40\u9650<\/th><\/tr><\/thead><tbody><tr><td><code>curl<\/code><\/td><td>\u7cbe\u7ec6\u63d0\u53d6\u7279\u5b9a\u8bf7\u6c42\u7684\u54cd\u5e94\u5934\u548c Body \u5185\u5bb9<\/td><td>\u7075\u6d3b\uff0c\u53ef\u7cbe\u786e\u63a7\u5236\u8bf7\u6c42\uff0c\u6613\u4e8e\u811a\u672c\u5316\u5206\u6790<\/td><td>\u624b\u52a8\u5206\u6790\u6548\u7387\u4f4e\uff0c\u4e0d\u9002\u5408\u6279\u91cf\u63d0\u53d6<\/td><\/tr><tr><td>\u6d4f\u89c8\u5668\u5f00\u53d1\u8005\u5de5\u5177<\/td><td>\u56fe\u5f62\u5316\u5206\u6790\u9875\u9762\u7ed3\u6784\u3001\u7f51\u7edc\u8bf7\u6c42\u3001Cookie\u3001\u5b58\u50a8<\/td><td>\u76f4\u89c2\u5c55\u793a\uff0c\u4fbf\u4e8e\u67e5\u770b DOM \u7ed3\u6784\u548c\u8d44\u6e90\u4f9d\u8d56<\/td><td>\u4e0d\u9002\u5408\u81ea\u52a8\u5316\uff0c\u4f9d\u8d56\u56fe\u5f62\u754c\u9762<\/td><\/tr><tr><td>Burp Suite (Repeater)<\/td><td>\u624b\u52a8\u5206\u6790\u548c\u91cd\u653e\u8bf7\u6c42\uff0c\u89c2\u5bdf\u4e0d\u540c\u8f93\u5165\u4e0b\u7684\u54cd\u5e94\u53d8\u5316<\/td><td>\u4e13\u4e1a\u7684 HTTP \u5206\u6790\u5de5\u5177\uff0c\u53ef\u62e6\u622a\u3001\u4fee\u6539\u3001\u91cd\u653e\u8bf7\u6c42<\/td><td>\u529f\u80fd\u5f3a\u5927\u4f46\u5b66\u4e60\u66f2\u7ebf\u8f83\u9661\uff0c\u9700\u914d\u7f6e\u4ee3\u7406<\/td><\/tr><tr><td>\u4e13\u7528\u6307\u7eb9\u8bc6\u522b\u5de5\u5177 (\u5982 wappalyzer-cli)<\/td><td>\u6279\u91cf\u3001\u81ea\u52a8\u5316\u63d0\u53d6\u548c\u5339\u914d\u5e38\u89c1\u7279\u5f81<\/td><td>\u5185\u7f6e\u5927\u91cf\u7279\u5f81\u5e93\uff0c\u6548\u7387\u9ad8<\/td><td>\u5bf9\u672a\u77e5\u6216\u81ea\u5b9a\u4e49\u7ec4\u4ef6\u7684\u7279\u5f81\u63d0\u53d6\u80fd\u529b\u4e3a\u96f6<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h4 class=\"wp-block-heading\">6. \u6807\u51c6\u64cd\u4f5c\u6b65\u9aa4<\/h4>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u9009\u5b9a\u76ee\u6807\u7ec4\u4ef6<\/strong>\uff1a\u4ee5\u4e4b\u524d\u6e05\u5355\u4e2d\u7684\u201cWeb \u670d\u52a1\u5668\u201d\u4e3a\u4f8b\u3002<\/li>\n\n\n\n<li><strong>\u63d0\u53d6\u534f\u8bae\u5c42\u7279\u5f81<\/strong>\uff1a\u4f7f\u7528 <code>curl -I http:\/\/test.local<\/code>\uff0c\u91cd\u70b9\u5173\u6ce8 <code>Server<\/code> \u5934\u3002<br><code>bash curl -I http:\/\/test.local # \u5047\u8bbe\u8f93\u51fa: Server: Apache\/2.4.41 (Ubuntu)<\/code><\/li>\n\n\n\n<li><strong>\u63d0\u53d6\u5185\u5bb9\u5c42\u7279\u5f81<\/strong>\uff1a\u4f7f\u7528 <code>curl -s http:\/\/test.local\/ | grep -i \"apache\"<\/code>\uff0c\u67e5\u627e\u9875\u9762\u4e2d\u662f\u5426\u5305\u542b apache \u7684\u9ed8\u8ba4\u9875\u9762\u6216\u6807\u8bc6\u3002<\/li>\n\n\n\n<li><strong>\u63d0\u53d6\u8def\u5f84\u5c42\u7279\u5f81<\/strong>\uff1a\u5c1d\u8bd5\u8bbf\u95ee\u4e00\u4e9b\u5e38\u89c1\u7684 Web \u670d\u52a1\u5668\u72b6\u6001\u9875\uff0c\u5982 <code>\/server-status<\/code> (Apache) \u6216 <code>\/nginx_status<\/code> (Nginx)\u3002<br><code>bash curl -o \/dev\/null -w \"%{http_code}\\n\" http:\/\/test.local\/server-status # \u82e5\u8fd4\u56de 200 \u6216 403\uff08\u800c\u975e 404\uff09\uff0c\u8bf4\u660e\u8be5\u8def\u5f84\u5b58\u5728\uff0c\u8fd9\u662f\u4e00\u4e2a\u8f85\u52a9\u7279\u5f81\u3002<\/code><\/li>\n\n\n\n<li><strong>\u8bb0\u5f55\u7279\u5f81<\/strong>\uff1a\u5c06\u6240\u6709\u89c2\u5bdf\u5230\u7684\u7279\u5f81\uff08<code>Server<\/code> \u5934\u3001\u7279\u5b9a\u8def\u5f84\u7684\u54cd\u5e94\u7801\u3001\u9875\u9762\u5185\u7684\u7279\u5b9a\u5b57\u7b26\u4e32\uff09\u8bb0\u5f55\u4e0b\u6765\uff0c\u5f62\u6210\u8be5\u7ec4\u4ef6\u7684\u7279\u5f81\u5411\u91cf\u3002<\/li>\n<\/ol>\n\n\n\n<h4 class=\"wp-block-heading\">7. \u5982\u4f55\u9a8c\u8bc1\u7ed3\u679c\u771f\u5b9e\u6027<\/h4>\n\n\n\n<p><strong>\u9a8c\u8bc1\u903b\u8f91<\/strong>\uff1a\u5355\u4e00\u7279\u5f81\u53ef\u80fd\u88ab\u4f2a\u9020\u6216\u8bef\u8bfb\uff0c\u591a\u4e2a\u72ec\u7acb\u6765\u6e90\u7684\u7279\u5f81\u76f8\u4e92\u5370\u8bc1\uff0c\u53ef\u5927\u5927\u63d0\u9ad8\u5224\u65ad\u7684\u7f6e\u4fe1\u5ea6\u3002<br><strong>\u5224\u65ad\u4f9d\u636e<\/strong>\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u5f3a\u7279\u5f81<\/strong>\uff1a<code>Server: Apache\/2.4.41<\/code> \u662f\u76f4\u63a5\u8bc1\u636e\u3002<\/li>\n\n\n\n<li><strong>\u5f31\u7279\u5f81<\/strong>\uff1a<code>\/server-status<\/code> \u8fd4\u56de <code>403 Forbidden<\/code>\uff08\u5b58\u5728\u4f46\u7981\u6b62\u8bbf\u95ee\uff09\u662f\u8f83\u5f31\u8bc1\u636e\uff0c\u56e0\u7ba1\u7406\u5458\u53ef\u80fd\u81ea\u5b9a\u4e49\u8def\u5f84\u3002<\/li>\n\n\n\n<li><strong>\u7efc\u5408\u5224\u65ad<\/strong>\uff1a\u82e5 <code>Server<\/code> \u5934\u662f Apache\uff0c<code>\/server-status<\/code> \u8fd4\u56de\u975e 404\uff0c\u4e14\u9ed8\u8ba4\u9875\u9762\u5305\u542b Apache \u5b57\u6837\uff0c\u5219\u53ef\u9ad8\u7f6e\u4fe1\u5ea6\u786e\u8ba4\u3002<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">8. \u5e38\u89c1\u9519\u8bef\u4e0e\u6392\u67e5\u65b9\u5f0f<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u9519\u8bef<\/strong>\uff1a\u8fc7\u5ea6\u4f9d\u8d56\u5355\u4e00\u7279\u5f81\uff0c\u5c24\u5176\u662f\u5bb9\u6613\u88ab\u4f2a\u9020\u7684 <code>Server<\/code> \u5934\u3002<\/li>\n\n\n\n<li><strong>\u6392\u67e5<\/strong>\uff1a\u4e0d\u8981\u4ec5\u770b <code>Server<\/code> \u5934\u3002\u5f88\u591a\u7ba1\u7406\u5458\u4f1a\u4fee\u6539\u5b83\u4ee5\u201c\u9690\u85cf\u201d\u4fe1\u606f\u3002\u6b64\u65f6\u9700\u901a\u8fc7\u5176\u4ed6\u7279\u5f81\uff08\u5982\u8def\u5f84\u3001\u6587\u4ef6\u3001\u7279\u5b9a\u9875\u9762\u7684 HTML \u7ed3\u6784\uff09\u7efc\u5408\u5224\u65ad\u3002\u4f8b\u5982\uff0c\u5373\u4f7f <code>Server<\/code> \u5934\u88ab\u6539\u6210 <code>Microsoft-IIS\/8.5<\/code>\uff0c\u82e5\u5176\u54cd\u5e94\u5927\u5c0f\u5199\u654f\u611f\u884c\u4e3a\uff08\u5982 <code>\/index.php<\/code> \u548c <code>\/index.Php<\/code> \u8fd4\u56de\u4e0d\u540c\u7ed3\u679c\uff09\u662f Linux \u7cfb\u7edf\u7684\u7279\u5f81\uff0c\u5c31\u53ef\u80fd\u5b58\u5728\u77db\u76fe\u3002<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">9. \u5408\u89c4\u8fb9\u754c\u8bf4\u660e<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u4f7f\u7528\u573a\u666f<\/strong>\uff1a\u5728\u83b7\u5f97\u6388\u6743\u540e\uff0c\u5bf9\u81ea\u5df1\u7684\u5e94\u7528\u6216\u6d4b\u8bd5\u76ee\u6807\u8fdb\u884c\u6280\u672f\u6808\u5206\u6790\uff0c\u7528\u4e8e\u6f0f\u6d1e\u7ba1\u7406\u3001\u7248\u672c\u5408\u89c4\u6027\u68c0\u67e5\u6216\u6027\u80fd\u4f18\u5316\u3002<\/li>\n\n\n\n<li><strong>\u7f51\u7edc\u5b89\u5168\u89c6\u89d2<\/strong>\uff1a\u98ce\u9669\u5728\u4e8e\uff0c\u7279\u5f81\u5206\u6790\u7684\u8fc7\u7a0b\u672c\u8eab\u662f\u5728\u6536\u96c6\u76ee\u6807\u7cfb\u7edf\u4fe1\u606f\uff0c\u8fd9\u4e9b\u4fe1\u606f\u53ef\u80fd\u88ab\u6076\u610f\u5229\u7528\u3002\u4f46\u7279\u5f81\u66b4\u9732\u662f\u7cfb\u7edf\u8fd0\u884c\u7684\u5ba2\u89c2\u4e8b\u5b9e\uff0c\u5b8c\u5168\u7684\u201c\u4fe1\u606f\u9690\u85cf\u201d\u5728\u6280\u672f\u4e0a\u662f\u56f0\u96be\u7684\u3002\u7f13\u89e3\u63aa\u65bd\u662f\uff0c\u5bf9\u4e8e\u751f\u4ea7\u7cfb\u7edf\uff0c\u6700\u5c0f\u5316\u66b4\u9732\u4fe1\u606f\uff0c\u5982\u5173\u95ed\u4e0d\u5fc5\u8981\u7684 <code>Server<\/code> \u5934\u6216\u9519\u8bef\u8be6\u60c5\u3002<\/li>\n\n\n\n<li><strong>\u51b3\u7b56\u6307\u5357<\/strong>\uff1a\u5f53\u9700\u8981\u7cbe\u786e\u786e\u8ba4\u67d0\u4e2a\u7ec4\u4ef6\u7684\u5177\u4f53\u7248\u672c\u65f6\uff0c\u5efa\u8bae\u6267\u884c\u6b64\u6a21\u5757\u3002\u82e5\u53ea\u9700\u7c97\u7565\u4e86\u89e3\uff0c\u53ef\u4f7f\u7528\u81ea\u52a8\u5316\u5de5\u5177\uff08\u5982 whatweb\uff09\u4ee3\u66ff\u624b\u52a8\u63d0\u53d6\u3002<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">10. \u672c\u6a21\u5757\u9636\u6bb5\u6027\u5c0f\u7ed3<\/h4>\n\n\n\n<p>\u73b0\u5728\uff0c\u6211\u4eec\u6709\u4e86\u201c\u7ec4\u4ef6\u7279\u5f81\u6e05\u5355\u201d\uff0c\u77e5\u9053\u6bcf\u4e2a\u7ec4\u4ef6\u4f1a\u7559\u4e0b\u54ea\u4e9b\u75d5\u8ff9\u3002\u4f46\u9762\u5bf9\u672a\u77e5\u5e94\u7528\uff0c\u9700\u7cfb\u7edf\u5316\u65b9\u6cd5\u5c06\u8fd9\u4e9b\u7279\u5f81\u7ec4\u7ec7\u6210\u53ef\u590d\u7528\u7684\u8bc6\u522b\u6a21\u578b\u3002\u4e0b\u4e00\u6a21\u5757\u5c06\u6784\u5efa\u7279\u5f81\u8bc6\u522b\u65b9\u6cd5\u6a21\u578b\u3002<\/p>\n\n\n\n<p><strong>\u7ec4\u4ef6\u7279\u5f81\u6765\u6e90\u5206\u5c42\u6a21\u578b<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/03\/\u7ec4\u4ef6\u7279\u5f81\u6765\u6e90\u5206\u5c42\u6a21\u578b-1024x775.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"775\" data-original=\"http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/03\/\u7ec4\u4ef6\u7279\u5f81\u6765\u6e90\u5206\u5c42\u6a21\u578b-1024x775.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1778\"  sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/div><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">\u56db\u3001\u6784\u5efa\u7279\u5f81\u8bc6\u522b\u65b9\u6cd5\u6a21\u578b<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">1. \u6a21\u5757\u6982\u5ff5\u89e3\u91ca<\/h4>\n\n\n\n<p>\u62e5\u6709\u5927\u91cf\u201c\u7ec4\u4ef6\u7279\u5f81\u201d\uff08\u5982 <code>Server: nginx<\/code> \u662f nginx \u7684\u7279\u5f81\uff0c<code>\/wp-content\/<\/code> \u662f WordPress \u7684\u7279\u5f81\uff09\u540e\uff0c\u9700\u8981\u4e00\u5957\u7cfb\u7edf\u5316\u7684\u65b9\u6cd5\u6765\u7ec4\u7ec7\u3001\u5339\u914d\u548c\u5224\u65ad\u8fd9\u4e9b\u7279\u5f81\u3002\u672c\u6a21\u5757\u7684\u76ee\u6807\u662f\u4ece\u201c\u624b\u5de5\u4f5c\u574a\u201d\u5f0f\u7684\u9010\u4e2a\u7279\u5f81\u6bd4\u5bf9\uff0c\u5347\u7ea7\u4e3a\u201c\u5de5\u4e1a\u5316\u201d\u7684\u6a21\u578b\u5316\u8bc6\u522b\u3002\u6211\u4eec\u5c06\u5b66\u4e60\u5982\u4f55\u6784\u5efa\u53ef\u6269\u5c55\u7684\u3001\u9ad8\u6548\u7684\u201c\u6307\u7eb9\u5e93\u201d\u548c\u5339\u914d\u903b\u8f91\uff0c\u4f7f\u8bc6\u522b\u8fc7\u7a0b\u81ea\u52a8\u5316\u3001\u6807\u51c6\u5316\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">2. \u6280\u672f\u539f\u7406\u8bf4\u660e<\/h4>\n\n\n\n<p>\u7279\u5f81\u8bc6\u522b\u65b9\u6cd5\u6a21\u578b\u7684\u6838\u5fc3\u662f\u201c\u6a21\u5f0f\u5339\u914d\u201d\u3002\u5176\u5e95\u5c42\u903b\u8f91\u662f\u5c06\u201c\u7ec4\u4ef6\u201d\u4e0e\u4e00\u7ec4\u201c\u7279\u5f81\u89c4\u5219\u201d\u8fdb\u884c\u5173\u8054\u3002\u5178\u578b\u8bc6\u522b\u6a21\u578b\u5305\u542b\u4e24\u90e8\u5206\uff1a<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u6307\u7eb9\u5e93 (Fingerprint Database)<\/strong>\uff1a\u4e00\u4e2a\u7ed3\u6784\u5316\u7684\u6570\u636e\u5b58\u50a8\uff0c\u5176\u4e2d\u6bcf\u6761\u8bb0\u5f55\u4ee3\u8868\u4e00\u4e2a\u7ec4\u4ef6\uff0c\u5e76\u5305\u542b\u4e00\u4e2a\u6216\u591a\u4e2a\u7279\u5f81\u89c4\u5219\u3002\u6bcf\u6761\u89c4\u5219\u5b9a\u4e49\u4e86\u201c\u5728\u4ec0\u4e48\u4f4d\u7f6e\uff08\u5982 HTTP \u5934\u3001HTML \u5185\u5bb9\u3001\u7279\u5b9a URL \u8def\u5f84\uff09\u201d\uff0c\u201c\u5339\u914d\u4ec0\u4e48\u6a21\u5f0f\uff08\u5982\u6b63\u5219\u8868\u8fbe\u5f0f\u3001\u5b57\u7b26\u4e32\u3001\u72b6\u6001\u7801\uff09\u201d\u3002<\/li>\n\n\n\n<li><strong>\u5339\u914d\u5f15\u64ce (Matching Engine)<\/strong>\uff1a\u7a0b\u5e8f\u903b\u8f91\uff0c\u63a5\u6536\u4ece\u76ee\u6807\u7cfb\u7edf\u91c7\u96c6\u7684\u539f\u59cb\u6570\u636e\uff08\u54cd\u5e94\u5934\u3001HTML\u3001\u6587\u4ef6\u5217\u8868\u7b49\uff09\uff0c\u904d\u5386\u6307\u7eb9\u5e93\u4e2d\u7684\u89c4\u5219\u3002\u5f53\u4e00\u6761\u89c4\u5219\u88ab\u5339\u914d\u65f6\uff0c\u7ed9\u5bf9\u5e94\u7ec4\u4ef6\u589e\u52a0\u201c\u7f6e\u4fe1\u5ea6\u5206\u6570\u201d\u3002\u6700\u540e\uff0c\u6839\u636e\u603b\u5206\u6216\u5339\u914d\u5230\u7684\u5173\u952e\u89c4\u5219\uff0c\u5224\u65ad\u76ee\u6807\u4e0a\u8fd0\u884c\u4e86\u54ea\u4e9b\u7ec4\u4ef6\u53ca\u53ef\u80fd\u7248\u672c\u3002<\/li>\n<\/ol>\n\n\n\n<h4 class=\"wp-block-heading\">3. \u5728\u7cfb\u7edf\u4e2d\u7684\u4f4d\u7f6e<\/h4>\n\n\n\n<p>\u672c\u6a21\u5757\u662f\u6574\u4e2a\u63a2\u67e5\u6d41\u7a0b\u7684\u201c\u5927\u8111\u201d\u548c\u201c\u5fc3\u810f\u201d\u3002\u5b83\u5c06\u201c\u7279\u5f81\u7ed3\u6784\u201d\uff08\u6a21\u5757\u4e09\uff09\u8f6c\u5316\u4e3a\u53ef\u6267\u884c\u7684\u8bc6\u522b\u903b\u8f91\u3002\u5176\u8f93\u51fa\uff08\u8bc6\u522b\u7ed3\u679c\uff09\u662f\u540e\u7eed\u201c\u64cd\u4f5c\u6d41\u7a0b\u201d\uff08\u6a21\u5757\u4e94\uff09\u7684\u76f4\u63a5\u8f93\u5165\u3002\u6ca1\u6709\u8fd9\u4e2a\u6a21\u578b\uff0c\u63a2\u67e5\u6d3b\u52a8\u5c06\u505c\u7559\u5728\u96f6\u6563\u3001\u975e\u7ed3\u6784\u5316\u7684\u6c34\u5e73\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">4. \u53ef\u6267\u884c\u547d\u4ee4\u6216\u67e5\u8be2\u65b9\u5f0f<\/h4>\n\n\n\n<p>\u672c\u6a21\u5757\u4e0d\u76f4\u63a5\u4ea7\u751f\u547d\u4ee4\uff0c\u800c\u662f\u7406\u89e3\u73b0\u6709\u5de5\u5177\u80cc\u540e\u7684\u903b\u8f91\u3002\u901a\u8fc7\u5206\u6790\u73b0\u6210\u7684\u6307\u7eb9\u8bc6\u522b\u5de5\u5177\uff08\u5982 <code>whatweb<\/code> \u6216 <code>Wappalyzer<\/code>\uff09\u7684\u8f93\u51fa\u6765\u7406\u89e3\u5176\u6a21\u578b\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># \u4f7f\u7528 whatweb \u5e76\u542f\u7528\u8be6\u7ec6\u8f93\u51fa\uff0c\u89c2\u5bdf\u5176\u5339\u914d\u8fc7\u7a0b\nwhatweb --verbose http:\/\/httpbin.org<\/code><\/pre>\n\n\n\n<p>\u4f60\u5c06\u770b\u5230\u7c7b\u4f3c\u8f93\u51fa\uff08\u7b80\u5316\u7248\uff09\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>WhatWeb report for http:\/\/httpbin.org\nStatus    : 200 OK\nTitle     : httpbin.org\nIP        : 54.xxx.xxx.xxx\nCountry   : UNITED STATES, US\n\nPlugins Detected:\n&#91; Cookies ] : \u6709 _ga, _gid \u7b49\uff0c\u53ef\u80fd\u4f7f\u7528\u4e86Google Analytics\u3002\n&#91; HTTPServer ] : \u6709 gunicorn\n&#91; ... ]<\/code><\/pre>\n\n\n\n<p>\u8fd9\u91cc\u7684\u6bcf\u4e2a <code>[ Plugin ]<\/code> \u672c\u8d28\u4e0a\u662f\u4e00\u7ec4\u7279\u5f81\u89c4\u5219\u3002<code>whatweb<\/code> \u7684\u5339\u914d\u5f15\u64ce\u5c06\u91c7\u96c6\u5230\u7684\u6570\u636e\u4e0e\u8fd9\u4e9b\u89c4\u5219\u4e00\u4e00\u6bd4\u5bf9\uff0c\u6700\u7ec8\u6c47\u603b\u51fa\u68c0\u6d4b\u5230\u7684\u63d2\u4ef6\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">5. \u5de5\u5177\u5bf9\u6bd4\u8868<\/h4>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u5de5\u5177\/\u6a21\u578b<\/th><th>\u9002\u7528\u573a\u666f<\/th><th>\u4f18\u70b9<\/th><th>\u5c40\u9650<\/th><\/tr><\/thead><tbody><tr><td>WhatWeb<\/td><td>\u4e3b\u52a8\u5f0f\u3001\u547d\u4ee4\u884c\u4e0b\u7684 Web \u6307\u7eb9\u8bc6\u522b<\/td><td>\u63d2\u4ef6\u6570\u91cf\u5e9e\u5927\uff0c\u5339\u914d\u903b\u8f91\u7075\u6d3b\uff08\u652f\u6301\u6b63\u5219\u3001\u7248\u672c\u53f7\u63d0\u53d6\uff09\uff0c\u7ed3\u679c\u8be6\u7ec6<\/td><td>\u901f\u5ea6\u76f8\u5bf9\u8f83\u6162\uff0c\u53ef\u80fd\u4ea7\u751f\u8f83\u591a\u8bef\u62a5<\/td><\/tr><tr><td>Wappalyzer<\/td><td>\u88ab\u52a8\u5f0f\u3001\u6d4f\u89c8\u5668\u6269\u5c55\u6216 API \u8c03\u7528<\/td><td>\u7ed3\u679c\u7b80\u6d01\u660e\u4e86\uff0c\u4e0e\u6d4f\u89c8\u5668\u96c6\u6210\u597d\uff0c\u9002\u5408\u5feb\u901f\u6d4f\u89c8\u65f6\u4f7f\u7528<\/td><td>\u8986\u76d6\u8303\u56f4\u76f8\u5bf9 WhatWeb \u5c0f\uff0c\u6df1\u5ea6\u4e0d\u591f<\/td><\/tr><tr><td>BuiltWith<\/td><td>\u5728\u7ebf\/API \u670d\u52a1\uff0c\u4e13\u6ce8\u4e8e\u6280\u672f\u6808\u5206\u6790<\/td><td>\u6570\u636e\u5168\u9762\uff0c\u80fd\u8bc6\u522b\u5f88\u591a\u7b2c\u4e09\u65b9\u670d\u52a1\u3001\u5206\u6790\u5de5\u5177\u3001CDN \u7b49<\/td><td>\u4f9d\u8d56\u5176\u4e91\u7aef\u6570\u636e\u5e93\uff0c\u6709\u9690\u79c1\u98ce\u9669\uff0c\u90e8\u5206\u529f\u80fd\u4ed8\u8d39<\/td><\/tr><tr><td>\u81ea\u5efa\u6307\u7eb9\u5e93 + \u5339\u914d\u811a\u672c<\/td><td>\u9488\u5bf9\u7279\u5b9a\u5185\u90e8\u5e94\u7528\u6216\u6846\u67b6\u8fdb\u884c\u5b9a\u5236\u5316\u8bc6\u522b<\/td><td>\u9ad8\u5ea6\u53ef\u63a7\uff0c\u7cbe\u51c6\u5339\u914d\u5185\u90e8\u7279\u6709\u7ec4\u4ef6<\/td><td>\u5f00\u53d1\u6210\u672c\u9ad8\uff0c\u9700\u6301\u7eed\u7ef4\u62a4\u6307\u7eb9\u5e93<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h4 class=\"wp-block-heading\">6. \u6807\u51c6\u64cd\u4f5c\u6b65\u9aa4\uff08\u4ee5\u7406\u89e3 WhatWeb \u7684\u6a21\u578b\u4e3a\u4f8b\uff09<\/h4>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u9009\u62e9\u76ee\u6807<\/strong>\uff1a<code>http:\/\/test.local<\/code><\/li>\n\n\n\n<li><strong>\u8fd0\u884c\u57fa\u7840\u8bc6\u522b<\/strong>\uff1a<code>whatweb http:\/\/test.local<\/code>\uff0c\u83b7\u53d6\u6982\u8981\u62a5\u544a\u3002<\/li>\n\n\n\n<li><strong>\u542f\u7528\u8be6\u7ec6\u6a21\u5f0f<\/strong>\uff1a<code>whatweb --verbose http:\/\/test.local > whatweb_verbose.log<\/code>\uff0c\u5c06\u8be6\u7ec6\u8f93\u51fa\u4fdd\u5b58\u5230\u6587\u4ef6\u3002<\/li>\n\n\n\n<li><strong>\u5206\u6790\u65e5\u5fd7<\/strong>\uff1a\u6253\u5f00\u65e5\u5fd7\u6587\u4ef6\uff0c\u5bfb\u627e <code>[:]<\/code> \u6807\u8bb0\u3002\u6bcf\u4e2a\u88ab\u68c0\u6d4b\u5230\u7684\u63d2\u4ef6\u540d\u540e\u9762\uff0c\u901a\u5e38\u4f1a\u8ddf\u7740\u5339\u914d\u5230\u7684\u5177\u4f53\u7279\u5f81\u3002\u4f8b\u5982\uff1a<br><code>HTTPServer [ : Apache (2.4.41) ] : Apache: Server header: Apache\/2.4.41 (Ubuntu)<\/code><br>\u8fd9\u884c\u65e5\u5fd7\u63ed\u793a\u4e86 <code>HTTPServer<\/code> \u63d2\u4ef6\u7684\u8bc6\u522b\u8fc7\u7a0b\uff1a\u5b83\u5339\u914d\u5230\u4e86 <code>Server<\/code> \u5934\u4e2d\u7684\u5b57\u7b26\u4e32\uff0c\u5e76\u4ece\u4e2d\u63d0\u53d6\u4e86\u7248\u672c\u53f7 <code>2.4.41<\/code>\u3002<\/li>\n\n\n\n<li><strong>\u5f52\u7eb3\u6a21\u578b<\/strong>\uff1a\u901a\u8fc7\u6b64\u5206\u6790\uff0c\u7406\u89e3 WhatWeb \u7684\u6a21\u578b\uff1a\u5b83\u6709\u4e00\u4e2a\u540d\u4e3a <code>HTTPServer<\/code> \u7684\u63d2\u4ef6\uff0c\u5305\u542b\u4e00\u6761\u89c4\u5219\uff1a\u201c\u68c0\u67e5\u54cd\u5e94\u5934\u4e2d <code>Server<\/code> \u5b57\u6bb5\u7684\u503c\uff0c\u82e5\u5305\u542b <code>Apache<\/code>\uff0c\u5219\u62a5\u544a <code>HTTPServer<\/code> \u7ec4\u4ef6\uff0c\u5e76\u5c1d\u8bd5\u7528\u6b63\u5219\u8868\u8fbe\u5f0f <code>Apache\/([\\d.]+)<\/code> \u63d0\u53d6\u7248\u672c\u53f7\u3002\u201d<\/li>\n<\/ol>\n\n\n\n<h4 class=\"wp-block-heading\">7. \u5982\u4f55\u9a8c\u8bc1\u7ed3\u679c\u771f\u5b9e\u6027<\/h4>\n\n\n\n<p><strong>\u9a8c\u8bc1\u903b\u8f91<\/strong>\uff1a\u9a8c\u8bc1\u8bc6\u522b\u6a21\u578b\u7684\u51c6\u786e\u6027\uff0c\u9700\u901a\u8fc7\u201c\u5df2\u77e5\u6837\u672c\u201d\u6d4b\u8bd5\u3002<br><strong>\u5224\u65ad\u4f9d\u636e<\/strong>\uff1a<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u6b63\u6837\u672c\u6d4b\u8bd5<\/strong>\uff1a\u5728\u5df2\u77e5\u8fd0\u884c Apache \u7684\u6d4b\u8bd5\u673a\u4e0a\u8fd0\u884c <code>whatweb<\/code>\uff0c\u770b\u80fd\u5426\u6b63\u786e\u8bc6\u522b\u51fa Apache \u53ca\u5176\u7248\u672c\u3002\u82e5\u6b63\u786e\uff0c\u8bf4\u660e\u6a21\u578b\u4e2d\u7684 Apache \u6307\u7eb9\u89c4\u5219\u6709\u6548\u3002<\/li>\n\n\n\n<li><strong>\u8d1f\u6837\u672c\u6d4b\u8bd5<\/strong>\uff1a\u5728\u5df2\u77e5\u8fd0\u884c Nginx \u7684\u6d4b\u8bd5\u673a\u4e0a\u8fd0\u884c <code>whatweb<\/code>\uff0c\u786e\u4fdd\u4e0d\u8bef\u62a5\u4e3a Apache\u3002\u82e5\u8bef\u62a5\uff0c\u8bf4\u660e\u89c4\u5219\u533a\u5206\u5ea6\u4e0d\u591f\uff0c\u9700\u4f18\u5316\u3002<\/li>\n\n\n\n<li><strong>\u4ea4\u53c9\u9a8c\u8bc1<\/strong>\uff1a\u5c06 <code>whatweb<\/code> \u7684\u8bc6\u522b\u7ed3\u679c\u4e0e\u6a21\u5757\u4e09\u624b\u52a8\u63d0\u53d6\u7684\u7279\u5f81\u5bf9\u6bd4\uff0c\u770b\u662f\u5426\u4e00\u81f4\u3002<\/li>\n<\/ol>\n\n\n\n<h4 class=\"wp-block-heading\">8. \u5e38\u89c1\u9519\u8bef\u4e0e\u6392\u67e5\u65b9\u5f0f<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u9519\u8bef<\/strong>\uff1a\u6a21\u578b\u8fc7\u62df\u5408\u6216\u6b20\u62df\u5408\u3002\u5373\u6307\u7eb9\u89c4\u5219\u8fc7\u4e8e\u4e25\u683c\uff08\u4e00\u70b9\u5c0f\u5dee\u5f02\u5c31\u5339\u914d\u4e0d\u4e0a\uff09\u6216\u8fc7\u4e8e\u5bbd\u6cdb\uff08\u628a\u5176\u4ed6\u7ec4\u4ef6\u4e5f\u5339\u914d\u8fdb\u6765\uff09\u3002<\/li>\n\n\n\n<li><strong>\u6392\u67e5<\/strong>\uff1a\u5f53\u53d1\u73b0\u8bef\u62a5\u6216\u6f0f\u62a5\u65f6\uff0c\u9700\u8c03\u6574\u6307\u7eb9\u5e93\u89c4\u5219\u3002\u4f8b\u5982\uff0c\u82e5 <code>Server: Apache<\/code> \u88ab\u6539\u6210 <code>Server: Custom-Server<\/code>\uff0c\u4f9d\u8d56 <code>Server<\/code> \u5934\u7684\u6a21\u578b\u5c31\u4f1a\u5931\u6548\u3002\u6b64\u65f6\u9700\u5728\u6a21\u578b\u4e2d\u589e\u52a0\u65b0\u89c4\u5219\uff0c\u5982\u68c0\u67e5 <code>\/manual<\/code> \u8def\u5f84\u662f\u5426\u5b58\u5728\uff08Apache \u7684\u5e38\u89c1\u6587\u6863\u8def\u5f84\uff09\u3002<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">9. \u5408\u89c4\u8fb9\u754c\u8bf4\u660e<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u4f7f\u7528\u573a\u666f<\/strong>\uff1a\u6784\u5efa\u548c\u7ef4\u62a4\u5185\u90e8\u8d44\u4ea7\u6307\u7eb9\u5e93\uff0c\u7528\u4e8e\u81ea\u52a8\u5316\u8d44\u4ea7\u53d1\u73b0\u548c\u7248\u672c\u7ba1\u7406\uff0c\u662f DevSecOps \u5b9e\u8df5\u4e2d\u7684\u4e00\u73af\u3002<\/li>\n\n\n\n<li><strong>\u7f51\u7edc\u5b89\u5168\u89c6\u89d2<\/strong>\uff1a\u98ce\u9669\u5728\u4e8e\uff0c\u4e00\u4e2a\u8fc7\u4e8e\u7cbe\u786e\u548c\u5f3a\u5927\u7684\u6307\u7eb9\u5e93\u82e5\u843d\u5165\u653b\u51fb\u8005\u624b\u4e2d\uff0c\u4f1a\u6210\u4e3a\u9ad8\u6548\u653b\u51fb\u7684\u5e2e\u51f6\u3002\u56e0\u6b64\uff0c\u6307\u7eb9\u5e93\u672c\u8eab\u662f\u9700\u8981\u4fdd\u62a4\u7684\u654f\u611f\u8d44\u4ea7\u3002\u7f13\u89e3\u63aa\u65bd\u662f\uff0c\u5bf9\u6307\u7eb9\u5e93\u7684\u8bbf\u95ee\u8fdb\u884c\u4e25\u683c\u6743\u9650\u63a7\u5236\u3002<\/li>\n\n\n\n<li><strong>\u51b3\u7b56\u6307\u5357<\/strong>\uff1a\u5f53\u9700\u8981\u5b9a\u671f\u3001\u81ea\u52a8\u5316\u5730\u5bf9\u5927\u89c4\u6a21\u8d44\u4ea7\u8fdb\u884c\u6280\u672f\u6808\u76d8\u70b9\u65f6\uff0c\u5efa\u8bae\u6784\u5efa\u6216\u5f15\u5165\u6b64\u7c7b\u7279\u5f81\u8bc6\u522b\u6a21\u578b\u3002\u82e5\u53ea\u662f\u5076\u5c14\u3001\u4e34\u65f6\u5730\u5206\u6790\u4e00\u4e24\u4e2a\u7ad9\u70b9\uff0c\u4f7f\u7528\u73b0\u6210\u81ea\u52a8\u5316\u5de5\u5177\u5373\u53ef\uff0c\u65e0\u9700\u81ea\u5efa\u6a21\u578b\u3002<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">10. \u672c\u6a21\u5757\u9636\u6bb5\u6027\u5c0f\u7ed3<\/h4>\n\n\n\n<p>\u6211\u4eec\u5b8c\u6210\u4e86\u63a2\u67e5\u80fd\u529b\u7684\u201c\u5927\u8111\u201d\u5efa\u8bbe\uff0c\u7406\u89e3\u4e86\u5982\u4f55\u7cfb\u7edf\u5316\u5730\u7ec4\u7ec7\u548c\u5339\u914d\u7279\u5f81\u3002\u73b0\u5728\u6709\u4e86\u601d\u7ef4\u6a21\u578b\u548c\u5de5\u5177\uff0c\u63a5\u4e0b\u6765\u9700\u5c06\u5176\u4e32\u8054\u6210\u4e00\u5957\u6807\u51c6\u5316\u7684\u3001\u53ef\u91cd\u590d\u6267\u884c\u7684\u63a2\u67e5\u64cd\u4f5c\u6d41\u7a0b\u3002\u4e0b\u4e00\u6a21\u5757\u5c06\u5236\u5b9a\u4ece\u91c7\u96c6\u5230\u9a8c\u8bc1\u7684\u5b8c\u6574\u8def\u5f84\u3002<\/p>\n\n\n\n<p><strong>\u7279\u5f81\u8bc6\u522b\u6a21\u578b\u67b6\u6784\u56fe<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/03\/\u7279\u5f81\u8bc6\u522b\u6a21\u578b\u67b6\u6784\u56fe-1024x173.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"173\" data-original=\"http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/03\/\u7279\u5f81\u8bc6\u522b\u6a21\u578b\u67b6\u6784\u56fe-1024x173.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1779\"  sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/div><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">\u4e94\u3001\u5f62\u6210\u63a2\u67e5\u64cd\u4f5c\u6d41\u7a0b\u8def\u5f84<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">1. \u6a21\u5757\u6982\u5ff5\u89e3\u91ca<\/h4>\n\n\n\n<p>\u672c\u6a21\u5757\u89e3\u51b3\u201c\u5982\u4f55\u4e00\u6b65\u6b65\u505a\u201d\u7684\u95ee\u9898\u3002\u5728\u524d\u51e0\u4e2a\u6a21\u5757\u4e2d\uff0c\u6211\u4eec\u5206\u522b\u5b66\u4e60\u4e86\u8ba4\u77e5\u3001\u76ee\u6807\u3001\u7279\u5f81\u548c\u6a21\u578b\u3002\u73b0\u5728\u9700\u8981\u5c06\u8fd9\u4e9b\u96f6\u6563\u7684\u201c\u77e5\u8bc6\u70b9\u201d\u548c\u201c\u5de5\u5177\u70b9\u201d\u4e32\u8054\u6210\u4e00\u4e2a\u8fde\u8d2f\u7684\u3001\u95ed\u73af\u7684\u5de5\u7a0b\u5316\u64cd\u4f5c\u6d41\u7a0b\u3002\u8be5\u6d41\u7a0b\u5c06\u6307\u5bfc\u4f60\u4ece\u63a5\u5230\u63a2\u67e5\u4efb\u52a1\u5f00\u59cb\uff0c\u5230\u6700\u7ec8\u62ff\u5230\u53ef\u9760\u7ed3\u679c\u4e3a\u6b62\uff0c\u6bcf\u4e00\u6b65\u505a\u4ec0\u4e48\u3001\u7528\u4ec0\u4e48\u5de5\u5177\u3001\u5982\u4f55\u51b3\u7b56\uff0c\u5747\u6709\u7ae0\u53ef\u5faa\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">2. \u6280\u672f\u539f\u7406\u8bf4\u660e<\/h4>\n\n\n\n<p>\u6807\u51c6\u63a2\u67e5\u6d41\u7a0b\u9075\u5faa\u201c\u4fe1\u606f\u91c7\u96c6 -&gt; \u5206\u6790\u5904\u7406 -&gt; \u9a8c\u8bc1\u786e\u8ba4\u201d\u7684\u95ed\u73af\u903b\u8f91\u3002\u5176\u5e95\u5c42\u539f\u7406\u662f\u9010\u6b65\u6536\u655b\u7684\u51b3\u7b56\u6811\u3002<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u4fe1\u606f\u91c7\u96c6\u9636\u6bb5<\/strong>\uff1a\u901a\u8fc7\u88ab\u52a8\uff08\u5982\u76d1\u542c\u7f51\u7edc\u6d41\u91cf\uff09\u6216\u4e3b\u52a8\uff08\u5982\u53d1\u9001\u63a2\u6d4b\u5305\uff09\u65b9\u5f0f\uff0c\u83b7\u53d6\u76ee\u6807\u7cfb\u7edf\u7684\u539f\u59cb\u54cd\u5e94\u6570\u636e\u3002\u5e7f\u5ea6\u4f18\u5148\uff0c\u76ee\u6807\u662f\u201c\u5c3d\u53ef\u80fd\u591a\u5730\u83b7\u53d6\u201d\u3002<\/li>\n\n\n\n<li><strong>\u5206\u6790\u5904\u7406\u9636\u6bb5<\/strong>\uff1a\u5c06\u539f\u59cb\u6570\u636e\u8f93\u5165\u201c\u7279\u5f81\u8bc6\u522b\u6a21\u578b\u201d\uff08\u6a21\u5757\u56db\uff09\uff0c\u5229\u7528\u6307\u7eb9\u5e93\u8fdb\u884c\u6a21\u5f0f\u5339\u914d\uff0c\u5c06\u6570\u636e\u8f6c\u5316\u4e3a\u201c\u5019\u9009\u7ec4\u4ef6\u5217\u8868\u201d\u3002\u6b64\u65f6\u53ef\u80fd\u6709\u591a\u4e2a\u5019\u9009\uff0c\u4e14\u7f6e\u4fe1\u5ea6\u4e0d\u4e00\u3002<\/li>\n\n\n\n<li><strong>\u9a8c\u8bc1\u786e\u8ba4\u9636\u6bb5<\/strong>\uff1a\u9488\u5bf9\u201c\u5019\u9009\u7ec4\u4ef6\u5217\u8868\u201d\u4e2d\u7f6e\u4fe1\u5ea6\u4e0d\u9ad8\u6216\u5173\u952e\u7684\u7ec4\u4ef6\uff0c\u8fdb\u884c\u5b9a\u5411\u7684\u3001\u6df1\u5ea6\u7684\u4e8c\u6b21\u63a2\u6d4b\uff0c\u4f7f\u7528\u6a21\u5757\u4e09\u4e2d\u5b66\u5230\u7684\u624b\u5de5\u63d0\u53d6\u7279\u5f81\u65b9\u6cd5\uff0c\u5bf9\u81ea\u52a8\u5316\u7ed3\u679c\u8fdb\u884c\u4eba\u5de5\u6838\u5b9e\uff0c\u6700\u7ec8\u5f62\u6210\u9ad8\u7f6e\u4fe1\u5ea6\u7684\u201c\u786e\u8ba4\u7ec4\u4ef6\u6e05\u5355\u201d\u3002<\/li>\n<\/ol>\n\n\n\n<h4 class=\"wp-block-heading\">3. \u5728\u7cfb\u7edf\u4e2d\u7684\u4f4d\u7f6e<\/h4>\n\n\n\n<p>\u672c\u6a21\u5757\u662f\u6574\u4e2a\u8bfe\u7a0b\u7684\u64cd\u4f5c\u6838\u5fc3\uff0c\u662f\u524d\u4e09\u4e2a\u6a21\u5757\uff08\u8ba4\u77e5\u3001\u76ee\u6807\u3001\u7279\u5f81\uff09\u77e5\u8bc6\u7684\u7efc\u5408\u8fd0\u7528\uff0c\u4e5f\u662f\u540e\u4e24\u4e2a\u6a21\u5757\uff08\u98ce\u9669\u63a7\u5236\u3001\u7ed3\u679c\u6574\u5408\uff09\u7684\u5b9e\u8df5\u57fa\u7840\u3002\u5b83\u5c06\u7406\u8bba\u77e5\u8bc6\u843d\u5730\u4e3a\u53ef\u6267\u884c\u7684\u52a8\u4f5c\uff0c\u662f\u8fde\u63a5\u201c\u77e5\u9053\u201d\u548c\u201c\u505a\u5230\u201d\u7684\u6865\u6881\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">4. \u53ef\u6267\u884c\u547d\u4ee4\u6216\u67e5\u8be2\u65b9\u5f0f<\/h4>\n\n\n\n<p>\u5c06\u6574\u4e2a\u6d41\u7a0b\u4e32\u8d77\u6765\uff0c\u5f62\u6210\u4e00\u5957\u8fde\u8d2f\u7684\u547d\u4ee4\u5e8f\u5217\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># 1. \u4fe1\u606f\u91c7\u96c6\u9636\u6bb5\n# 1.1 \u7aef\u53e3\u626b\u63cf (\u5e7f\u5ea6)\nnmap -p- --min-rate 1000 -oN nmap_ports.txt test.local\n\n# 1.2 \u670d\u52a1\u7248\u672c\u63a2\u6d4b (\u6df1\u5ea6)\nnmap -sV -p $(grep open nmap_ports.txt | cut -d'\/' -f1 | tr '\\n' ',') -oN nmap_versions.txt test.local\n\n# 1.3 \u57fa\u7840Web\u4fe1\u606f\u91c7\u96c6 (\u4f7f\u7528curl\u6216httpx)\ncurl -I http:\/\/test.local &gt; curl_headers.txt\ncurl -s http:\/\/test.local &gt; curl_body.html\n\n# 2. \u5206\u6790\u5904\u7406\u9636\u6bb5\n# 2.1 \u8fd0\u884c\u81ea\u52a8\u5316\u6307\u7eb9\u8bc6\u522b\nwhatweb -a 3 http:\/\/test.local &gt; whatweb_result.txt\n\n# 2.2 \u4f7f\u7528\u5de5\u5177\u5206\u6790HTML (\u4f8b\u5982\uff0c\u63d0\u53d6\u6240\u6709\u5f15\u7528\u7684JS\/CSS)\ngrep -Eoi 'src=\"&#91;^\"]+\"|href=\"&#91;^\"]+\"' curl_body.html | grep -E '\\.js|\\.css' &gt; resources.txt\n\n# 3. \u9a8c\u8bc1\u786e\u8ba4\u9636\u6bb5\n# 3.1 \u9488\u5bf9 whatweb \u62a5\u544a\u7684\u7591\u4f3c Apache \u7248\u672c\uff0c\u9a8c\u8bc1 \/server-status\ncurl -o \/dev\/null -w \"HTTP Code: %{http_code}\\n\" http:\/\/test.local\/server-status\n\n# 3.2 \u9488\u5bf9 whatweb \u62a5\u544a\u7684\u7591\u4f3c PHP\uff0c\u9a8c\u8bc1 phpinfo() \u6587\u4ef6\ncurl -L http:\/\/test.local\/phpinfo.php | grep -i \"php version\" || echo \"phpinfo.php not found\"\n\n# 3.3 \u9a8c\u8bc1\u53d1\u73b0\u7684 JS \u5e93\u7248\u672c (\u4f8b\u5982\uff0c\u68c0\u67e5 jquery.js \u7684\u5185\u5bb9)\ncurl -s http:\/\/test.local\/static\/jquery.min.js | head -n 5<\/code><\/pre>\n\n\n\n<h4 class=\"wp-block-heading\">5. \u5de5\u5177\u5bf9\u6bd4\u8868<\/h4>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u6d41\u7a0b\u9636\u6bb5<\/th><th>\u63a8\u8350\u5de5\u5177<\/th><th>\u5907\u9009\u5de5\u5177<\/th><th>\u6838\u5fc3\u4efb\u52a1<\/th><\/tr><\/thead><tbody><tr><td>\u4fe1\u606f\u91c7\u96c6 (\u7f51\u7edc\u5c42)<\/td><td><code>nmap<\/code><\/td><td><code>masscan<\/code> (\u6781\u901f\u626b\u63cf), <code>rustscan<\/code> (\u9ad8\u6548)<\/td><td>\u53d1\u73b0\u5f00\u653e\u7aef\u53e3\u548c\u670d\u52a1<\/td><\/tr><tr><td>\u4fe1\u606f\u91c7\u96c6 (\u5e94\u7528\u5c42)<\/td><td><code>curl<\/code>, <code>httpx<\/code><\/td><td>Burp Suite (\u624b\u52a8), Chrome DevTools<\/td><td>\u83b7\u53d6\u54cd\u5e94\u5934\u3001HTML\u3001\u8d44\u6e90\u5217\u8868<\/td><\/tr><tr><td>\u5206\u6790\u5904\u7406<\/td><td><code>whatweb<\/code>, <code>wappalyzer-cli<\/code><\/td><td>\u81ea\u5199 Python \u811a\u672c (\u7ed3\u5408 <code>requests<\/code> \u548c <code>re<\/code> \u5e93)<\/td><td>\u81ea\u52a8\u5316\u6307\u7eb9\u5339\u914d\uff0c\u751f\u6210\u5019\u9009\u6e05\u5355<\/td><\/tr><tr><td>\u9a8c\u8bc1\u786e\u8ba4<\/td><td><code>curl<\/code>, Burp Suite Repeater<\/td><td>\u6d4f\u89c8\u5668\u624b\u52a8\u8bbf\u95ee<\/td><td>\u9488\u5bf9\u5019\u9009\u6e05\u5355\u8fdb\u884c\u4eba\u5de5\u6838\u5b9e\uff0c\u6392\u9664\u8bef\u62a5<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h4 class=\"wp-block-heading\">6. \u6807\u51c6\u64cd\u4f5c\u6b65\u9aa4<\/h4>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u4efb\u52a1\u63a5\u6536\u4e0e\u8303\u56f4\u786e\u8ba4<\/strong>\uff1a\u660e\u786e\u76ee\u6807\u4e3a <code>test.local<\/code>\uff0c\u786e\u8ba4\u62e5\u6709\u6d4b\u8bd5\u6388\u6743\u3002<\/li>\n\n\n\n<li><strong>\u7f51\u7edc\u5c42\u4fe1\u606f\u91c7\u96c6<\/strong>\uff1a\u6267\u884c <code>nmap -p- -sV -T4 test.local -oA nmap_testlocal<\/code>\uff0c\u5c06\u7ed3\u679c\u4fdd\u5b58\u3002<\/li>\n\n\n\n<li><strong>\u5e94\u7528\u5c42\u4fe1\u606f\u91c7\u96c6<\/strong>\uff1a\u5728\u6d4f\u89c8\u5668\u4e2d\u8bbf\u95ee <code>http:\/\/test.local<\/code>\uff0c\u6253\u5f00\u5f00\u53d1\u8005\u5de5\u5177\uff0c\u67e5\u770b\u7f51\u7edc\u8bf7\u6c42\u3002\u540c\u65f6\u4f7f\u7528 <code>curl<\/code> \u4fdd\u5b58\u9996\u9875 HTML \u548c\u54cd\u5e94\u5934\u3002<\/li>\n\n\n\n<li><strong>\u81ea\u52a8\u5316\u5206\u6790<\/strong>\uff1a\u8fd0\u884c <code>whatweb -a 3 http:\/\/test.local<\/code>\uff0c\u8bb0\u5f55\u5176\u8f93\u51fa\u3002<\/li>\n\n\n\n<li><strong>\u521d\u6b65\u7ed3\u679c\u6574\u7406<\/strong>\uff1a\u5c06 <code>nmap<\/code> \u7684 <code>-sV<\/code> \u7ed3\u679c\u548c <code>whatweb<\/code> \u7684\u7ed3\u679c\u5408\u5e76\uff0c\u5f62\u6210\u521d\u6b65\u7ec4\u4ef6\u6e05\u5355\uff0c\u6807\u6ce8\u7f6e\u4fe1\u5ea6\uff08\u9ad8\/\u4e2d\/\u4f4e\uff09\u3002<\/li>\n\n\n\n<li><strong>\u6df1\u5ea6\u9a8c\u8bc1<\/strong>\uff1a\u9488\u5bf9\u6e05\u5355\u4e2d\u7684\u6bcf\u4e2a\u7ec4\u4ef6\uff0c\u5c24\u5176\u662f\u7f6e\u4fe1\u5ea6\u4e3a\u201c\u4e2d\u201d\u7684\uff0c\u4f7f\u7528 <code>curl<\/code> \u6784\u9020\u7279\u5b9a\u8bf7\u6c42\uff08\u5982\u8bbf\u95ee\u7279\u5b9a\u8def\u5f84\u3001\u68c0\u67e5\u7279\u5b9a\u6587\u4ef6 hash\uff09\u8fdb\u884c\u9a8c\u8bc1\u3002\u4f8b\u5982\uff0c\u82e5 <code>whatweb<\/code> \u62a5\u544a\u53ef\u80fd\u4e3a Drupal\uff0c\u5219\u5c1d\u8bd5\u8bbf\u95ee <code>\/CHANGELOG.txt<\/code>\u3002<\/li>\n\n\n\n<li><strong>\u7ed3\u679c\u786e\u8ba4\u4e0e\u8bb0\u5f55<\/strong>\uff1a\u5c06\u9a8c\u8bc1\u540e\u7684\u7ed3\u679c\u66f4\u65b0\u5230\u6e05\u5355\uff0c\u5e76\u8bb0\u5f55\u9a8c\u8bc1\u8fc7\u7a0b\u548c\u5224\u65ad\u4f9d\u636e\u3002\u6700\u7ec8\u8f93\u51fa\u4e00\u4efd\u300atest.local \u5e94\u7528\u6280\u672f\u6808\u5206\u6790\u62a5\u544a\u300b\u3002<\/li>\n<\/ol>\n\n\n\n<h4 class=\"wp-block-heading\">7. \u5982\u4f55\u9a8c\u8bc1\u7ed3\u679c\u771f\u5b9e\u6027<\/h4>\n\n\n\n<p><strong>\u9a8c\u8bc1\u903b\u8f91<\/strong>\uff1a\u6574\u4e2a\u6d41\u7a0b\u7684\u6700\u7ec8\u7ed3\u679c\u9700\u901a\u8fc7\u201c\u53ef\u590d\u73b0\u7684\u3001\u591a\u89d2\u5ea6\u7684\u8bc1\u636e\u94fe\u201d\u8bc1\u660e\u5176\u771f\u5b9e\u6027\u3002<br><strong>\u5224\u65ad\u4f9d\u636e<\/strong>\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u8bc1\u636e\u94fe<\/strong>\uff1a\u6700\u7ec8\u7ed3\u8bba\u4e0d\u80fd\u5b64\u7acb\u3002\u4f8b\u5982\uff0c\u7ed3\u8bba\u4e3a\u201cApache 2.4.41\u201d\u3002\u8bc1\u636e\u94fe\u5e94\u5305\u62ec\uff1a<code>nmap -sV<\/code> \u62a5\u544a\u4e86 Apache 2.4.41\uff0c<code>curl -I<\/code> \u7684 <code>Server<\/code> \u5934\u4e0e\u4e4b\u5339\u914d\uff0c\u4e14 <code>\/server-status<\/code> \u8def\u5f84\u5b58\u5728\u4e14\u8fd4\u56de 403\uff0c\u4e0e Apache \u9ed8\u8ba4\u884c\u4e3a\u4e00\u81f4\u3002<\/li>\n\n\n\n<li><strong>\u53ef\u590d\u73b0\u6027<\/strong>\uff1a\u76f8\u540c\u6761\u4ef6\u4e0b\u91cd\u590d\u6267\u884c\u6b65\u9aa4 3-6\uff0c\u5e94\u80fd\u5f97\u5230\u76f8\u540c\u6216\u76f8\u8fd1\u7ed3\u8bba\u3002<\/li>\n\n\n\n<li><strong>\u903b\u8f91\u4e00\u81f4\u6027<\/strong>\uff1a\u6240\u6709\u7ec4\u4ef6\u7684\u7ed3\u8bba\u5e94\u903b\u8f91\u81ea\u6d3d\u3002\u4f8b\u5982\uff0c\u8bc6\u522b\u51fa\u540e\u7aef\u662f ASP.NET\uff0c\u4f46 <code>Server<\/code> \u5934\u5374\u662f <code>nginx<\/code>\uff0c\u5e76\u4e0d\u77db\u76fe\uff0c\u53ef\u80fd nginx \u662f\u53cd\u5411\u4ee3\u7406\uff0c\u80cc\u540e\u662f IIS\uff0c\u53cd\u800c\u63ed\u793a\u66f4\u590d\u6742\u67b6\u6784\u3002<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">8. \u5e38\u89c1\u9519\u8bef\u4e0e\u6392\u67e5\u65b9\u5f0f<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u9519\u8bef<\/strong>\uff1a\u8df3\u8fc7\u9a8c\u8bc1\u786e\u8ba4\u9636\u6bb5\uff0c\u5b8c\u5168\u4fe1\u4efb\u81ea\u52a8\u5316\u5de5\u5177\u7ed3\u679c\u3002<\/li>\n\n\n\n<li><strong>\u6392\u67e5<\/strong>\uff1a\u5f53\u540e\u7eed\u64cd\u4f5c\uff08\u5982\u6f0f\u6d1e\u5229\u7528\uff09\u57fa\u4e8e\u9519\u8bef\u8bc6\u522b\u7ed3\u679c\u5931\u8d25\u65f6\uff0c\u5e94\u56de\u6eaf\u81f3\u6b64\u6d41\u7a0b\u3002\u91cd\u65b0\u6267\u884c\u6b65\u9aa4 6\uff0c\u624b\u52a8\u9a8c\u8bc1\u5de5\u5177\u8f93\u51fa\u3002\u4f8b\u5982\uff0c\u82e5 <code>whatweb<\/code> \u62a5\u544a\u4e86\u9519\u8bef\u7684 CMS \u7248\u672c\uff0c\u5bfc\u81f4\u540e\u7eed\u5229\u7528\u7684 EXP \u65e0\u6548\uff0c\u624b\u52a8\u9a8c\u8bc1\u7248\u672c\u6587\u4ef6\uff08\u5982 <code>readme.html<\/code>\uff09\u5373\u53ef\u53d1\u73b0\u95ee\u9898\u3002<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">9. \u5408\u89c4\u8fb9\u754c\u8bf4\u660e<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u4f7f\u7528\u573a\u666f<\/strong>\uff1a\u6b64\u6d41\u7a0b\u5e94\u7528\u4e8e\u5f00\u53d1\u73af\u5883\u6d4b\u8bd5\u3001\u5185\u90e8\u8d44\u4ea7\u76d8\u70b9\uff0c\u4ee5\u53ca\u83b7\u5f97\u6388\u6743\u7684\u6e17\u900f\u6d4b\u8bd5\u9879\u76ee\u4e2d\u3002<\/li>\n\n\n\n<li><strong>\u7f51\u7edc\u5b89\u5168\u89c6\u89d2<\/strong>\uff1a\u98ce\u9669\u5728\u4e8e\uff0c\u6d41\u7a0b\u4e2d\u7684\u4e3b\u52a8\u626b\u63cf\uff08\u7279\u522b\u662f <code>nmap<\/code> \u5168\u7aef\u53e3\u626b\u63cf\u548c <code>whatweb<\/code> \u7684 aggressive \u6a21\u5f0f <code>-a 3<\/code>\uff09\u53ef\u80fd\u5bf9\u8001\u65e7\u6216\u8106\u5f31\u7cfb\u7edf\u9020\u6210\u538b\u529b\uff0c\u751a\u81f3\u5f15\u53d1\u62d2\u7edd\u670d\u52a1\u3002\u7f13\u89e3\u63aa\u65bd\u662f\uff0c\u5728\u975e\u751f\u4ea7\u73af\u5883\u6216\u4e1a\u52a1\u4f4e\u5cf0\u671f\u8fdb\u884c\uff0c\u5e76\u6839\u636e\u76ee\u6807\u91cd\u8981\u6027\u8c03\u6574\u626b\u63cf\u901f\u7387\u548c\u5f3a\u5ea6\u3002<\/li>\n\n\n\n<li><strong>\u51b3\u7b56\u6307\u5357<\/strong>\uff1a\u5f53\u9700\u8981\u5168\u9762\u3001\u7cfb\u7edf\u5730\u4e86\u89e3\u5e94\u7528\u7684\u6280\u672f\u6784\u6210\u65f6\uff0c\u5efa\u8bae\u9075\u5faa\u6b64\u6d41\u7a0b\u3002\u82e5\u53ea\u9700\u5feb\u901f\u786e\u8ba4\u5df2\u77e5\u4fe1\u606f\uff08\u5982\u9a8c\u8bc1\u67d0\u4e2a\u7ec4\u4ef6\u7248\u672c\uff09\uff0c\u53ef\u8df3\u8fc7\u91c7\u96c6\u9636\u6bb5\uff0c\u76f4\u63a5\u6267\u884c\u9a8c\u8bc1\u6b65\u9aa4\u3002<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">10. \u672c\u6a21\u5757\u9636\u6bb5\u6027\u5c0f\u7ed3<\/h4>\n\n\n\n<p>\u6211\u4eec\u62e5\u6709\u4e86\u4e00\u5957\u5b8c\u6574\u7684\u3001\u53ef\u91cd\u590d\u7684\u63a2\u67e5\u64cd\u4f5c\u6d41\u7a0b\u3002\u901a\u8fc7\u6b64\u6d41\u7a0b\uff0c\u53ef\u4ee5\u7cfb\u7edf\u5730\u83b7\u53d6\u5e94\u7528\u7684\u6280\u672f\u6808\u4fe1\u606f\u3002\u4f46\u5728\u5b9e\u9645\u64cd\u4f5c\u4e2d\uff0c\u53ef\u80fd\u9047\u5230\u5404\u79cd\u5e72\u6270\u56e0\u7d20\uff0c\u5982 WAF\uff08Web \u5e94\u7528\u9632\u706b\u5899\uff09\u3001\u626b\u63cf\u901f\u7387\u9650\u5236\uff0c\u4ee5\u53ca\u6cd5\u5f8b\u6388\u6743\u8fb9\u754c\u3002\u4e0b\u4e00\u6a21\u5757\u5c06\u89e3\u51b3\u5982\u4f55\u63a7\u5236\u8fd9\u4e9b\u98ce\u9669\uff0c\u786e\u4fdd\u63a2\u67e5\u6d3b\u52a8\u7684\u5b89\u5168\u4e0e\u5408\u89c4\u3002<\/p>\n\n\n\n<p><strong>\u6807\u51c6\u5316\u63a2\u67e5\u64cd\u4f5c\u6d41\u7a0b\u95ed\u73af\u56fe<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/03\/\u6807\u51c6\u5316\u63a2\u67e5\u64cd\u4f5c\u6d41\u7a0b\u95ed\u73af\u56fe-834x1024.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"834\" height=\"1024\" data-original=\"http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/03\/\u6807\u51c6\u5316\u63a2\u67e5\u64cd\u4f5c\u6d41\u7a0b\u95ed\u73af\u56fe-834x1024.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1780\"  sizes=\"auto, (max-width: 834px) 100vw, 834px\" \/><\/div><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">\u516d\u3001\u63a7\u5236\u63a2\u67e5\u6d3b\u52a8\u98ce\u9669\u8fb9\u754c<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">1. \u6a21\u5757\u6982\u5ff5\u89e3\u91ca<\/h4>\n\n\n\n<p>\u63a2\u67e5\u6d3b\u52a8\u5982\u540c\u5728\u672a\u77e5\u6d77\u57df\u822a\u884c\uff0c\u65e2\u6709\u6697\u7901\uff08\u6280\u672f\u5e72\u6270\uff09\uff0c\u4e5f\u6709\u9886\u6d77\u57fa\u7ebf\uff08\u6cd5\u5f8b\u8fb9\u754c\uff09\u3002\u672c\u6a21\u5757\u7684\u6838\u5fc3\u4efb\u52a1\u662f\u8bc6\u522b\u5e76\u7ba1\u7406\u63a2\u67e5\u8fc7\u7a0b\u4e2d\u53ef\u80fd\u9047\u5230\u7684\u5404\u79cd\u98ce\u9669\uff0c\u5305\u62ec\u6280\u672f\u5c42\u9762\u7684\u98ce\u9669\uff08\u5982\u89e6\u53d1\u9632\u62a4\u7cfb\u7edf\u3001\u5f71\u54cd\u4e1a\u52a1\u7a33\u5b9a\u6027\uff09\uff0c\u4ee5\u53ca\u5408\u89c4\u5c42\u9762\u7684\u98ce\u9669\uff08\u5982\u8d8a\u6743\u64cd\u4f5c\u3001\u6cd5\u5f8b\u7ea0\u7eb7\uff09\u3002\u76ee\u7684\u662f\u786e\u4fdd\u63a2\u67e5\u6d3b\u52a8\u5728\u53ef\u63a7\u3001\u5b89\u5168\u3001\u5408\u6cd5\u7684\u8303\u56f4\u5185\u8fdb\u884c\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">2. \u6280\u672f\u539f\u7406\u8bf4\u660e<\/h4>\n\n\n\n<p>\u98ce\u9669\u63a7\u5236\u7684\u539f\u7406\u57fa\u4e8e\u201c\u6700\u5c0f\u5e72\u9884\u201d\u548c\u201c\u6388\u6743\u786e\u8ba4\u201d\u3002<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u6280\u672f\u98ce\u9669\u63a7\u5236<\/strong>\uff1a\u6838\u5fc3\u662f\u201c\u901f\u7387\u63a7\u5236\u201d\u548c\u201c\u89c4\u907f\u7b56\u7565\u201d\u3002\u4e3b\u52a8\u626b\u63cf\u4f1a\u4ea7\u751f\u5927\u91cf\u6d41\u91cf\u548c\u8bf7\u6c42\uff0c\u53ef\u80fd\u88ab IDS\/IPS\uff08\u5165\u4fb5\u68c0\u6d4b\/\u9632\u5fa1\u7cfb\u7edf\uff09\u68c0\u6d4b\u4e3a\u653b\u51fb\uff0c\u6216\u8017\u5c3d\u76ee\u6807\u8d44\u6e90\u3002\u56e0\u6b64\uff0c\u9700\u63a7\u5236\u53d1\u5305\u901f\u7387\uff08\u5982 <code>nmap -T2<\/code>\uff09\uff0c\u5fc5\u8981\u65f6\u4f7f\u7528\u4ee3\u7406\u6216\u5206\u5e03\u5f0f\u626b\u63cf\u5206\u6563\u6d41\u91cf\u3002\u540c\u65f6\uff0c\u8bc6\u522b\u5e76\u7ed5\u8fc7\u7b80\u5355\u7684 WAF \u89c4\u5219\uff0c\u907f\u514d\u56e0\u89e6\u53d1\u5c01\u9501\u800c\u5bfc\u81f4\u540e\u7eed\u8bf7\u6c42\u88ab\u62d2\u7edd\u3002\u8fd9\u5e76\u975e\u4e3a\u4e86\u653b\u51fb\uff0c\u800c\u662f\u4e3a\u4e86\u5728\u6388\u6743\u8303\u56f4\u5185\u5b8c\u6210\u5b8c\u6574\u8bc4\u4f30\u3002<\/li>\n\n\n\n<li><strong>\u5408\u89c4\u98ce\u9669\u63a7\u5236<\/strong>\uff1a\u6838\u5fc3\u662f\u201c\u6388\u6743\u4e66\u201d\u548c\u201c\u8fb9\u754c\u786e\u8ba4\u201d\u3002\u6240\u6709\u63a2\u67e5\u6d3b\u52a8\u5fc5\u987b\u6709\u660e\u786e\u7684\u3001\u4e66\u9762\u7684\u6388\u6743\uff0c\u660e\u786e\u6388\u6743\u8303\u56f4\uff08\u54ea\u4e9b IP\u3001\u54ea\u4e9b\u7aef\u53e3\u3001\u54ea\u4e9b\u65f6\u95f4\u6bb5\uff09\u3002\u8fd9\u662f\u533a\u5206\u5b89\u5168\u8bc4\u4f30\u4e0e\u7f51\u7edc\u72af\u7f6a\u7684\u552f\u4e00\u754c\u9650\u3002<\/li>\n<\/ol>\n\n\n\n<h4 class=\"wp-block-heading\">3. \u5728\u7cfb\u7edf\u4e2d\u7684\u4f4d\u7f6e<\/h4>\n\n\n\n<p>\u672c\u6a21\u5757\u662f\u4e00\u4e2a\u201c\u5b89\u5168\u62a4\u680f\u201d\u548c\u201c\u8d28\u91cf\u63a7\u5236\u73af\u201d\uff0c\u8d2f\u7a7f\u4e8e\u6574\u4e2a\u63a2\u67e5\u6d41\u7a0b\u59cb\u7ec8\u3002\u5b83\u4e0d\u4ea7\u751f\u76f4\u63a5\u63a2\u67e5\u7ed3\u679c\uff0c\u4f46\u6307\u5bfc\u548c\u7ea6\u675f\u6240\u6709\u63a2\u67e5\u884c\u4e3a\u3002\u4ece\u6a21\u5757\u4e8c\u7684\u201c\u754c\u5b9a\u8303\u56f4\u201d\u5f00\u59cb\uff0c\u5230\u6a21\u5757\u4e94\u7684\u201c\u64cd\u4f5c\u6d41\u7a0b\u201d\uff0c\u5747\u9700\u5728\u672c\u6a21\u5757\u7684\u98ce\u9669\u63a7\u5236\u539f\u5219\u4e0b\u8fdb\u884c\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">4. \u53ef\u6267\u884c\u547d\u4ee4\u6216\u67e5\u8be2\u65b9\u5f0f<\/h4>\n\n\n\n<p>\u6b64\u5904\u7684\u547d\u4ee4\u6f14\u793a\u5982\u4f55\u201c\u63a7\u5236\u201d\u98ce\u9669\uff0c\u800c\u975e\u201c\u9020\u6210\u201d\u98ce\u9669\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># 1. \u6280\u672f\u98ce\u9669\u63a7\u5236\uff1a\u9650\u5236\u626b\u63cf\u901f\u5ea6 (\u4f7f\u7528 nmap \u7684 -T \u53c2\u6570\u548c --max-rate)\n# -T0 (\u504f\u6267\u7684) \u5230 -T5 (\u75af\u72c2\u7684)\uff0c\u901a\u5e38 -T2 (\u793c\u8c8c\u7684) \u6216 -T3 (\u666e\u901a\u7684) \u7528\u4e8e\u5e38\u89c4\u8bc4\u4f30\nnmap -sV -T2 --max-rate 50 scanme.nmap.org\n\n# 2. \u6280\u672f\u98ce\u9669\u63a7\u5236\uff1a\u4f7f\u7528\u4f2a\u9020\u7684 User-Agent \u4ee5\u51cf\u5c11\u88abWAF\u5c01\u9501\u7684\u6982\u7387 (curl)\ncurl -A \"Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/90.0.4430.212 Safari\/537.36\" -I http:\/\/test.local\n\n# 3. \u6280\u672f\u98ce\u9669\u63a7\u5236\uff1a\u901a\u8fc7\u4ee3\u7406\u8fdb\u884c\u626b\u63cf\uff0c\u9690\u85cf\u771f\u5b9e\u6e90IP (nmap)\n# \u5047\u8bbe\u6709\u4e00\u4e2a SOCKS5 \u4ee3\u7406\u5728 127.0.0.1:1080\n# nmap \u672c\u8eab\u4e0d\u652f\u6301 SOCKS\uff0c\u4f46\u53ef\u4f7f\u7528 proxychains\n# proxychains nmap -sT -Pn -p 80,443 test.local\n\n# 4. \u5408\u89c4\u98ce\u9669\u63a7\u5236\uff1a\u5728\u5f00\u59cb\u4efb\u4f55\u5de5\u4f5c\u524d\uff0c\u5c06\u6388\u6743\u4e66\u548c\u8303\u56f4\u5b9a\u4e49\u5199\u5728\u9879\u76ee\u8bb0\u5f55\u4e2d (\u65e0\u547d\u4ee4\uff0c\u6b64\u4e3a\u6d41\u7a0b)\necho \"Authorization received for scanning test.local from 2024-01-01 to 2024-01-31. Scope: 10.0.0.0\/24, ports 1-65535.\" &gt; authorization_record.txt<\/code><\/pre>\n\n\n\n<h4 class=\"wp-block-heading\">5. \u5de5\u5177\u5bf9\u6bd4\u8868<\/h4>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u63a7\u5236\u7c7b\u578b<\/th><th>\u5de5\u5177\/\u65b9\u6cd5<\/th><th>\u4f18\u70b9<\/th><th>\u5c40\u9650<\/th><\/tr><\/thead><tbody><tr><td>\u626b\u63cf\u901f\u7387\u63a7\u5236<\/td><td><code>nmap -T&lt;0-5&gt;<\/code>\uff0c <code>--max-rate<\/code><\/td><td>\u5185\u7f6e\u4e8enmap\uff0c\u7b80\u5355\u6709\u6548<\/td><td>\u5bf9\u65f6\u95f4\u654f\u611f\u7684\u626b\u63cf\uff08\u5982\u6f0f\u6d1e\u626b\u63cf\uff09\u6548\u679c\u5dee<\/td><\/tr><tr><td>\u6e90IP\u9690\u85cf<\/td><td><code>proxychains<\/code> + \u4ee3\u7406<\/td><td>\u53ef\u6709\u6548\u9690\u85cf\u771f\u5b9eIP\uff0c\u7ed5\u8fc7\u57fa\u4e8eIP\u7684\u5c01\u9501<\/td><td>\u914d\u7f6e\u590d\u6742\uff0c\u53ef\u80fd\u964d\u4f4e\u626b\u63cf\u901f\u5ea6\uff0c\u90e8\u5206\u534f\u8bae\u4e0d\u652f\u6301<\/td><\/tr><tr><td>User-Agent \u4f2a\u9020<\/td><td><code>curl -A<\/code>, <code>wget -U<\/code><\/td><td>\u7b80\u5355\uff0c\u80fd\u7ed5\u8fc7\u6700\u57fa\u7840\u7684 WAF \u68c0\u67e5<\/td><td>\u65e0\u6cd5\u7ed5\u8fc7\u57fa\u4e8e\u884c\u4e3a\u5206\u6790\u7684 WAF<\/td><\/tr><tr><td>\u5ef6\u8fdf\/\u6296\u52a8<\/td><td><code>nmap --scan-delay &lt;time&gt;<\/code><\/td><td>\u4f7f\u626b\u63cf\u6d41\u91cf\u66f4\u50cf\u4eba\u5de5\u8bbf\u95ee\uff0c\u964d\u4f4e IDS \u544a\u8b66\u6982\u7387<\/td><td>\u6781\u5927\u589e\u52a0\u626b\u63cf\u65f6\u95f4<\/td><\/tr><tr><td>\u6388\u6743\u7ba1\u7406<\/td><td>\u4e66\u9762\u6388\u6743\u4e66\u3001\u90ae\u4ef6\u786e\u8ba4<\/td><td>\u6cd5\u5f8b\u5c42\u9762\u7684\u552f\u4e00\u6709\u6548\u51ed\u8bc1<\/td><td>\u65e0\u6cd5\u63a7\u5236\u6280\u672f\u98ce\u9669\uff0c\u4f9d\u8d56\u4e8e\u4eba\u7684\u5408\u89c4\u610f\u8bc6<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h4 class=\"wp-block-heading\">6. \u6807\u51c6\u64cd\u4f5c\u6b65\u9aa4<\/h4>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u83b7\u53d6\u5e76\u786e\u8ba4\u6388\u6743<\/strong>\uff1a\u8fdb\u884c\u4efb\u4f55\u626b\u63cf\u524d\uff0c\u5fc5\u987b\u83b7\u5f97\u76ee\u6807\u7cfb\u7edf\u6240\u6709\u8005\u6216\u7ba1\u7406\u5458\u7684\u660e\u786e\u4e66\u9762\u6388\u6743\uff0c\u5e76\u4ed4\u7ec6\u6838\u5bf9\u6388\u6743\u8303\u56f4\uff08IP\u3001\u57df\u540d\u3001\u6d4b\u8bd5\u65f6\u95f4\uff09\u3002<\/li>\n\n\n\n<li><strong>\u5236\u5b9a\u98ce\u9669\u63a7\u5236\u8ba1\u5212<\/strong>\uff1a\u6839\u636e\u76ee\u6807\u91cd\u8981\u6027\uff08\u751f\u4ea7\u73af\u5883\u3001\u6d4b\u8bd5\u73af\u5883\uff09\uff0c\u9009\u62e9\u626b\u63cf\u901f\u7387\u3002\u5bf9\u751f\u4ea7\u7cfb\u7edf\uff0c\u91c7\u7528 <code>-T2<\/code> \u6216 <code>--max-rate 50<\/code>\uff1b\u5bf9\u6d4b\u8bd5\u73af\u5883\uff0c\u53ef\u91c7\u7528\u66f4\u5feb\u7684 <code>-T4<\/code>\u3002<\/li>\n\n\n\n<li><strong>\u914d\u7f6e\u89c4\u907f\u7b56\u7565<\/strong>\uff1a\u5728 <code>curl<\/code> \u6216\u626b\u63cf\u5668\u914d\u7f6e\u4e2d\uff0c\u8bbe\u7f6e\u5408\u7406\u7684 <code>User-Agent<\/code>\uff0c\u907f\u514d\u4f7f\u7528\u9ed8\u8ba4\u7684\u3001\u6613\u88ab\u8bc6\u522b\u7684 UA\u3002<\/li>\n\n\n\n<li><strong>\u5c0f\u8303\u56f4\u8bd5\u70b9<\/strong>\uff1a\u4e0d\u8981\u4e00\u5f00\u59cb\u5c31\u5bf9\u6574\u4e2a IP \u6bb5\u5927\u89c4\u6a21\u626b\u63cf\u3002\u5148\u9009\u53d6\u4e00\u4e2a IP \u6216\u7aef\u53e3\u8fdb\u884c\u63a2\u6d4b\uff0c\u89c2\u5bdf\u76ee\u6807\u53cd\u5e94\uff0c\u786e\u8ba4\u672a\u89e6\u53d1\u5c01\u9501\u6216\u544a\u8b66\u540e\uff0c\u518d\u9010\u6b65\u6269\u5927\u8303\u56f4\u3002<\/li>\n\n\n\n<li><strong>\u6301\u7eed\u76d1\u63a7<\/strong>\uff1a\u626b\u63cf\u8fc7\u7a0b\u4e2d\uff0c\u76d1\u63a7\u626b\u63cf\u5de5\u5177\u7684\u53cd\u9988\u3002\u82e5\u51fa\u73b0\u5927\u91cf\u8d85\u65f6\u6216\u8fde\u63a5\u62d2\u7edd\uff0c\u53ef\u80fd\u89e6\u53d1\u4e86\u76ee\u6807\u9632\u62a4\uff0c\u5e94\u7acb\u5373\u6682\u505c\u626b\u63cf\uff0c\u5206\u6790\u539f\u56e0\u3002<\/li>\n\n\n\n<li><strong>\u8bb0\u5f55\u6240\u6709\u64cd\u4f5c<\/strong>\uff1a\u8be6\u7ec6\u8bb0\u5f55\u626b\u63cf\u7684\u8d77\u6b62\u65f6\u95f4\u3001\u4f7f\u7528\u7684\u547d\u4ee4\u3001\u626b\u63cf\u7684\u76ee\u6807\u8303\u56f4\uff0c\u4ee5\u5907\u5408\u89c4\u5ba1\u67e5\u3002<\/li>\n<\/ol>\n\n\n\n<h4 class=\"wp-block-heading\">7. \u5982\u4f55\u9a8c\u8bc1\u7ed3\u679c\u771f\u5b9e\u6027<\/h4>\n\n\n\n<p><strong>\u9a8c\u8bc1\u903b\u8f91<\/strong>\uff1a\u9a8c\u8bc1\u98ce\u9669\u63a7\u5236\u63aa\u65bd\u662f\u5426\u6709\u6548\uff0c\u5e76\u975e\u770b\u201c\u662f\u5426\u6210\u529f\u653b\u51fb\u201d\uff0c\u800c\u662f\u770b\u201c\u662f\u5426\u6210\u529f\u907f\u5f00\u9632\u5fa1\u4e14\u5b8c\u6210\u4e86\u4efb\u52a1\u201d\u3002<br><strong>\u5224\u65ad\u4f9d\u636e<\/strong>\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u901f\u7387\u63a7\u5236\u6709\u6548<\/strong>\uff1a\u626b\u63cf\u7ed3\u675f\u540e\uff0c\u68c0\u67e5\u76ee\u6807\u670d\u52a1\u5668\u7684\u8bbf\u95ee\u65e5\u5fd7\u3002\u82e5\u8bf7\u6c42\u95f4\u9694\u5747\u5300\u4e14\u9891\u7387\u8f83\u4f4e\uff0c\u672a\u5f62\u6210\u660e\u663e\u8bbf\u95ee\u5cf0\u503c\uff0c\u8bf4\u660e\u901f\u7387\u63a7\u5236\u6709\u6548\u3002<\/li>\n\n\n\n<li><strong>\u89c4\u907f\u7b56\u7565\u6709\u6548<\/strong>\uff1a\u82e5\u6574\u4e2a\u626b\u63cf\u8fc7\u7a0b\u4e2d\uff0c\u672a\u89e6\u53d1\u4efb\u4f55\u6765\u81ea\u76ee\u6807\u7cfb\u7edf\u7684\u201c\u8bbf\u95ee\u88ab\u62d2\u7edd\u201d\u6216\u201cIP\u88ab\u5c01\u201d\u63d0\u793a\uff0c\u4e14\u6210\u529f\u83b7\u53d6\u4e86\u6240\u9700\u4fe1\u606f\uff0c\u8bf4\u660e\u5f53\u524d\u89c4\u907f\u7b56\u7565\u6682\u65f6\u6709\u6548\u3002<\/li>\n\n\n\n<li><strong>\u5408\u89c4\u6027\u9a8c\u8bc1<\/strong>\uff1a\u6709\u660e\u786e\u7684\u6388\u6743\u8bb0\u5f55\uff0c\u4e14\u626b\u63cf\u8bb0\u5f55\uff08IP\u3001\u65f6\u95f4\uff09\u5b8c\u5168\u5728\u6388\u6743\u8303\u56f4\u4e4b\u5185\u3002<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">8. \u5e38\u89c1\u9519\u8bef\u4e0e\u6392\u67e5\u65b9\u5f0f<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u9519\u8bef<\/strong>\uff1a\u8fc7\u5ea6\u4f9d\u8d56\u6280\u672f\u89c4\u907f\uff0c\u800c\u5ffd\u89c6\u5408\u89c4\u6388\u6743\u3002<\/li>\n\n\n\n<li><strong>\u6392\u67e5<\/strong>\uff1a\u4e00\u65e6\u6536\u5230\u76ee\u6807\u7cfb\u7edf\u7684\u6295\u8bc9\u6216\u8b66\u544a\uff0c\u5e94\u7acb\u5373\u505c\u6b62\u6240\u6709\u6d3b\u52a8\u3002\u9996\u8981\u68c0\u67e5\u6388\u6743\u4e66\u3002\u82e5\u65e0\u6388\u6743\uff0c\u4e00\u5207\u6280\u672f\u8ba8\u8bba\u5747\u65e0\u610f\u4e49\u3002\u82e5\u6709\u6388\u6743\uff0c\u5e94\u8054\u5408\u6cd5\u52a1\u4e0e\u5bf9\u65b9\u6c9f\u901a\uff0c\u660e\u786e\u6388\u6743\u7684\u5408\u6cd5\u6027\u3002<\/li>\n\n\n\n<li><strong>\u9519\u8bef<\/strong>\uff1a\u626b\u63cf\u901f\u7387\u8bbe\u7f6e\u8fc7\u4f4e\uff0c\u5bfc\u81f4\u626b\u63cf\u65f6\u95f4\u8fc7\u957f\uff0c\u5f71\u54cd\u9879\u76ee\u8fdb\u5ea6\u3002<\/li>\n\n\n\n<li><strong>\u6392\u67e5<\/strong>\uff1a\u5e73\u8861\u98ce\u9669\u4e0e\u6548\u7387\u3002\u82e5\u9879\u76ee\u7d27\u6025\u4e14\u76ee\u6807\u975e\u6838\u5fc3\u7cfb\u7edf\uff0c\u53ef\u9002\u5f53\u63d0\u9ad8\u901f\u7387\uff0c\u6216\u91c7\u7528\u5206\u5e03\u5f0f\u626b\u63cf\uff0c\u7528\u591a\u53f0\u673a\u5668\u5206\u62c5\u4efb\u52a1\u3002<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">9. \u5408\u89c4\u8fb9\u754c\u8bf4\u660e<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u4f7f\u7528\u573a\u666f<\/strong>\uff1a\u6240\u6709\u6d89\u53ca\u5411\u76ee\u6807\u7cfb\u7edf\u53d1\u9001\u975e\u6b63\u5e38\u4e1a\u52a1\u6d41\u7a0b\u4ea7\u751f\u7684\u6570\u636e\u5305\u7684\u884c\u4e3a\uff0c\u5747\u9700\u6267\u884c\u672c\u6a21\u5757\u7684\u98ce\u9669\u63a7\u5236\u6d41\u7a0b\u3002<\/li>\n\n\n\n<li><strong>\u7f51\u7edc\u5b89\u5168\u89c6\u89d2<\/strong>\uff1a\u98ce\u9669\u662f\u53cc\u5411\u7684\u3002\u5bf9\u76ee\u6807\u7cfb\u7edf\u7684\u4fb5\u5165\u6027\u6d4b\u8bd5\u662f\u98ce\u9669\uff1b\u5bf9\u6211\u4eec\u81ea\u8eab\u800c\u8a00\uff0c\u672a\u7ecf\u6388\u6743\u7684\u626b\u63cf\u884c\u4e3a\u4e5f\u4f7f\u6211\u4eec\u9762\u4e34\u6cd5\u5f8b\u98ce\u9669\u548c\u804c\u4e1a\u58f0\u8a89\u98ce\u9669\u3002\u7f13\u89e3\u63aa\u65bd\u662f\u4e25\u683c\u9075\u5b88\u201c\u6388\u6743\u4e3a\u5148\u201d\u539f\u5219\u3002<\/li>\n\n\n\n<li><strong>\u51b3\u7b56\u6307\u5357<\/strong>\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u4f55\u65f6\u5fc5\u987b\u7528\uff1f<\/strong>\uff1a\u4efb\u4f55\u65f6\u5019\uff0c\u53ea\u8981\u63a2\u67e5\u6d3b\u52a8\u53ef\u80fd\u5bf9\u76ee\u6807\u7cfb\u7edf\u9020\u6210\u5f71\u54cd\uff08\u5305\u62ec\u4ea7\u751f\u65e5\u5fd7\uff09\uff0c\u6216\u5728\u975e\u4f60 100% \u62e5\u6709\u7684\u7f51\u7edc\/\u7cfb\u7edf\u4e0a\u8fdb\u884c\u3002<\/li>\n\n\n\n<li><strong>\u4f55\u65f6\u53ef\u653e\u5bbd\uff1f<\/strong>\uff1a\u5f53\u76ee\u6807\u662f\u4f60\u5b8c\u5168\u62e5\u6709\u548c\u63a7\u5236\u7684\u672c\u5730\u865a\u62df\u673a\uff0c\u4e14\u4e0e\u5916\u754c\u7f51\u7edc\u9694\u79bb\u65f6\uff0c\u53ef\u9002\u5f53\u653e\u5bbd\u98ce\u9669\u63a7\u5236\uff08\u5982\u4f7f\u7528 <code>-T5<\/code>\uff09\uff0c\u4f46\u4ecd\u5efa\u8bae\u4fdd\u6301\u826f\u597d\u7684\u8bb0\u5f55\u4e60\u60ef\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">10. \u672c\u6a21\u5757\u9636\u6bb5\u6027\u5c0f\u7ed3<\/h4>\n\n\n\n<p>\u5728\u5b66\u4f1a\u201c\u5982\u4f55\u505a\u201d\u4e4b\u540e\uff0c\u6211\u4eec\u53c8\u638c\u63e1\u4e86\u201c\u5982\u4f55\u5b89\u5168\u3001\u5408\u89c4\u5730\u505a\u201d\u3002\u98ce\u9669\u63a7\u5236\u786e\u4fdd\u4e86\u63a2\u67e5\u6d3b\u52a8\u7684\u4e13\u4e1a\u6027\u548c\u8d1f\u8d23\u4efb\u3002\u73b0\u5728\uff0c\u6211\u4eec\u80fd\u591f\u5b89\u5168\u3001\u7cfb\u7edf\u5730\u83b7\u53d6\u5173\u4e8e\u5e94\u7528\u67b6\u6784\u7684\u51c6\u786e\u4fe1\u606f\u3002\u4e0b\u4e00\u6a21\u5757\u5c06\u6574\u5408\u63a2\u67e5\u7ed3\u679c\u4e0e\u7b56\u7565\u8f93\u51fa\uff0c\u5c06\u4fe1\u606f\u8f6c\u5316\u4e3a\u51b3\u7b56\u3002<\/p>\n\n\n\n<p><strong>\u63a2\u67e5\u6d3b\u52a8\u53cc\u5411\u98ce\u9669\u63a7\u5236\u6a21\u578b<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/03\/\u63a2\u67e5\u6d3b\u52a8\u53cc\u5411\u98ce\u9669\u63a7\u5236\u6a21\u578b-1024x857.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"857\" data-original=\"http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/03\/\u63a2\u67e5\u6d3b\u52a8\u53cc\u5411\u98ce\u9669\u63a7\u5236\u6a21\u578b-1024x857.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1781\"  sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/div><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">\u4e03\u3001\u6574\u5408\u63a2\u67e5\u7ed3\u679c\u4e0e\u7b56\u7565\u8f93\u51fa<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">1. \u6a21\u5757\u6982\u5ff5\u89e3\u91ca<\/h4>\n\n\n\n<p>\u63a2\u67e5\u7684\u6700\u7ec8\u76ee\u7684\u5e76\u975e\u5f97\u5230\u4e00\u4efd\u6280\u672f\u6e05\u5355\uff0c\u800c\u662f\u6307\u5bfc\u540e\u7eed\u51b3\u7b56\u548c\u884c\u52a8\u3002\u672c\u6a21\u5757\u7684\u6838\u5fc3\u4efb\u52a1\u662f\u5c06\u524d\u516d\u4e2a\u6a21\u5757\u4ea7\u751f\u7684\u96f6\u6563\u4fe1\u606f\uff08\u7aef\u53e3\u3001\u670d\u52a1\u3001\u7248\u672c\u3001\u6846\u67b6\u3001\u4e2d\u95f4\u4ef6\uff09\u8fdb\u884c\u6574\u5408\u3001\u6e05\u6d17\u3001\u7ed3\u6784\u5316\uff0c\u5f62\u6210\u6709\u5546\u4e1a\u4ef7\u503c\u7684\u201c\u5e94\u7528\u6280\u672f\u6808\u6e05\u5355\u201d\u3002\u66f4\u91cd\u8981\u7684\u662f\uff0c\u5c06\u8fd9\u4efd\u6e05\u5355\u4e0e\u7279\u5b9a\u7684\u201c\u540e\u7eed\u884c\u52a8\u7b56\u7565\u201d\u5173\u8054\uff0c\u4f8b\u5982\uff1a\u53d1\u73b0\u8fc7\u671f\u7ec4\u4ef6\u7248\u672c\u5e94\u5347\u7ea7\uff0c\u53d1\u73b0\u4e0d\u5b89\u5168\u914d\u7f6e\u5e94\u52a0\u56fa\uff0c\u53d1\u73b0\u672a\u77e5\u5f00\u653e\u7aef\u53e3\u5e94\u6838\u67e5\u3002\u5c06\u201c\u4fe1\u606f\u201d\u8f6c\u5316\u4e3a\u201c\u51b3\u7b56\u201d\uff0c\u5b8c\u6210\u5de5\u7a0b\u95ed\u73af\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">2. \u6280\u672f\u539f\u7406\u8bf4\u660e<\/h4>\n\n\n\n<p>\u672c\u6a21\u5757\u7684\u6838\u5fc3\u662f\u201c\u4fe1\u606f\u5173\u8054\u201d\u4e0e\u201c\u7b56\u7565\u6620\u5c04\u201d\u3002\u5176\u5e95\u5c42\u903b\u8f91\u662f\u4e00\u4e2a\u51b3\u7b56\u652f\u6301\u7cfb\u7edf\u3002<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u4fe1\u606f\u7ed3\u6784\u5316<\/strong>\uff1a\u5c06\u63a2\u67e5\u7ed3\u679c\uff08\u5982 <code>nmap<\/code> \u7684 XML \u8f93\u51fa\u3001<code>whatweb<\/code> \u7684 JSON \u8f93\u51fa\uff09\u89e3\u6790\u5e76\u5b58\u50a8\u5230\u7edf\u4e00\u6570\u636e\u5e93\u4e2d\u3002\u6bcf\u6761\u8bb0\u5f55\u5e94\u5305\u542b\uff1a\u7ec4\u4ef6\u540d\u79f0\u3001\u7248\u672c\u3001\u53d1\u73b0\u4f4d\u7f6e\uff08IP\/URL\uff09\u3001\u7f6e\u4fe1\u5ea6\u3001\u53d1\u73b0\u65f6\u95f4\u7b49\u3002<\/li>\n\n\n\n<li><strong>\u7b56\u7565\u6620\u5c04<\/strong>\uff1a\u5efa\u7acb\u201c\u7ec4\u4ef6-\u7b56\u7565\u201d\u77e5\u8bc6\u5e93\u3002\u4f8b\u5982\uff0c\u77e5\u8bc6\u5e93\u5b9a\u4e49\uff1a\u201c\u82e5 Apache \u7248\u672c &lt; 2.4.50\uff0c\u5219\u5efa\u8bae\u5347\u7ea7\u201d\u3002\u5f53\u63a2\u67e5\u7ed3\u679c\u4e2d\u6709 Apache 2.4.41 \u65f6\uff0c\u7cfb\u7edf\u81ea\u52a8\u5173\u8054\u51fa\u201c\u5347\u7ea7\u201d\u7b56\u7565\u3002<\/li>\n\n\n\n<li><strong>\u4f18\u5148\u7ea7\u6392\u5e8f<\/strong>\uff1a\u5e76\u975e\u6240\u6709\u95ee\u9898\u5747\u9700\u7acb\u5373\u5904\u7406\u3002\u6839\u636e\u8d44\u4ea7\u7684\u4e1a\u52a1\u91cd\u8981\u6027\u3001\u7ec4\u4ef6\u7684\u98ce\u9669\u7b49\u7ea7\uff08\u5982\u9ad8\u5371\u6f0f\u6d1e\u3001\u662f\u5426\u66b4\u9732\u5728\u516c\u7f51\uff09\uff0c\u5bf9\u5173\u8054\u51fa\u7684\u7b56\u7565\u8fdb\u884c\u4f18\u5148\u7ea7\u6392\u5e8f\uff0c\u751f\u6210\u53ef\u6267\u884c\u7684\u884c\u52a8\u8def\u7ebf\u56fe\u3002<\/li>\n<\/ol>\n\n\n\n<h4 class=\"wp-block-heading\">3. \u5728\u7cfb\u7edf\u4e2d\u7684\u4f4d\u7f6e<\/h4>\n\n\n\n<p>\u672c\u6a21\u5757\u662f\u6574\u4e2a\u63a2\u67e5\u6d41\u7a0b\u7684\u7ec8\u70b9\uff0c\u4e5f\u662f\u540e\u7eed\u6240\u6709\u5b89\u5168\u6216\u8fd0\u7ef4\u5de5\u4f5c\u7684\u8d77\u70b9\u3002\u5b83\u5b8c\u6210\u4e86\u4ece\u201c\u6570\u636e\u201d\u5230\u201c\u4fe1\u606f\u201d\u518d\u5230\u201c\u77e5\u8bc6\u201d\u7684\u5347\u534e\uff0c\u4e3a\u6f0f\u6d1e\u7ba1\u7406\u3001\u914d\u7f6e\u7ba1\u7406\u3001\u653b\u51fb\u9762\u7ba1\u7406\u7b49\u63d0\u4f9b\u7cbe\u51c6\u8f93\u5165\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">4. \u53ef\u6267\u884c\u547d\u4ee4\u6216\u67e5\u8be2\u65b9\u5f0f<\/h4>\n\n\n\n<p>\u6b64\u9636\u6bb5\u66f4\u591a\u6d89\u53ca\u6570\u636e\u5904\u7406\u548c\u62a5\u544a\u751f\u6210\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># 1. \u5c06 nmap \u7ed3\u679c\u8f6c\u6362\u4e3a\u53ef\u5904\u7406\u7684\u683c\u5f0f (\u4f8b\u5982 XML)\nnmap -sV -oX nmap_results.xml test.local\n\n# 2. \u4f7f\u7528\u5de5\u5177\u89e3\u6790 XML \u5e76\u63d0\u53d6\u5173\u952e\u4fe1\u606f (\u4f7f\u7528 Python \u811a\u672c\u6216\u547d\u4ee4\u884c\u5de5\u5177\u5982 xmlstarlet)\n# \u4f7f\u7528 xmlstarlet \u63d0\u53d6\u5f00\u653e\u7684\u7aef\u53e3\u548c\u670d\u52a1\nxmlstarlet sel -t -m \"\/\/port&#91;state\/@state='open']\" -v \"concat(@portid, '\/', service\/@name)\" -n nmap_results.xml\n\n# 3. \u5c06 whatweb \u7684\u7ed3\u679c\u4ee5 JSON \u683c\u5f0f\u8f93\u51fa\uff0c\u4fbf\u4e8e\u7a0b\u5e8f\u89e3\u6790\nwhatweb --log-json=whatweb_results.json http:\/\/test.local\n\n# 4. \u6a21\u62df\u4e00\u4e2a\u7b80\u5355\u7684\u7b56\u7565\u5173\u8054 (\u4f2a\u4ee3\u7801\uff0c\u9700\u7528 Python \u7b49\u5b9e\u73b0)\n# \u5047\u8bbe\u6211\u4eec\u6709\u4e00\u4e2a vulnerability_db.json \u5305\u542b\u7248\u672c\u6f0f\u6d1e\u4fe1\u606f\n# python -c \"\n# import json\n# with open('nmap_results.xml') as f: ... \n# # \u4f2a\u903b\u8f91: \u82e5\u7aef\u53e380\u670d\u52a1\u662fapache\uff0c\u7248\u672c2.4.41\uff0c\u5219\u5728vuln_db\u4e2d\u67e5\u627e\u5bf9\u5e94\u98ce\u9669\n# print('Apache 2.4.41 \u5b58\u5728\u591a\u4e2a\u5df2\u77e5\u6f0f\u6d1e\uff0c\u5efa\u8bae\u5347\u7ea7\u81f3 2.4.50 \u4ee5\u4e0a')\n# \"\n\n# 5. \u751f\u6210\u6700\u7ec8\u62a5\u544a\necho \"\u751f\u6210 Markdown \u6216 HTML \u683c\u5f0f\u7684\u6574\u5408\u62a5\u544a\uff0c\u5305\u542b\u8d44\u4ea7\u6e05\u5355\u3001\u98ce\u9669\u7b49\u7ea7\u3001\u5904\u7f6e\u5efa\u8bae\u3002\"<\/code><\/pre>\n\n\n\n<h4 class=\"wp-block-heading\">5. \u5de5\u5177\u5bf9\u6bd4\u8868<\/h4>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u5de5\u5177\/\u65b9\u6cd5<\/th><th>\u9002\u7528\u573a\u666f<\/th><th>\u4f18\u70b9<\/th><th>\u5c40\u9650<\/th><\/tr><\/thead><tbody><tr><td>\u624b\u52a8\u6574\u7406 (Excel\/\u8bb0\u4e8b\u672c)<\/td><td>\u4e34\u65f6\u3001\u5c0f\u89c4\u6a21\u3001\u4e00\u6b21\u6027\u7684\u63a2\u67e5\u4efb\u52a1<\/td><td>\u7b80\u5355\u76f4\u89c2\uff0c\u65e0\u9700\u5b66\u4e60\u65b0\u5de5\u5177<\/td><td>\u6548\u7387\u4f4e\uff0c\u6613\u51fa\u9519\uff0c\u65e0\u6cd5\u81ea\u52a8\u5316\uff0c\u4e0d\u9002\u5408\u89c4\u6a21\u5316<\/td><\/tr><tr><td><code>nmap<\/code> + <code>grep<\/code>\/<code>awk<\/code><\/td><td>\u5feb\u901f\u4ece\u6587\u672c\u8f93\u51fa\u4e2d\u63d0\u53d6\u4fe1\u606f<\/td><td>\u5feb\u901f\uff0c\u5229\u7528\u73b0\u6709\u547d\u4ee4\u884c\u5de5\u5177<\/td><td>\u5904\u7406\u590d\u6742\u7684 XML\/JSON \u80fd\u529b\u5f31\uff0c\u903b\u8f91\u8868\u8fbe\u80fd\u529b\u6709\u9650<\/td><\/tr><tr><td>\u4e13\u4e1a\u89e3\u6790\u5de5\u5177 (<code>xmlstarlet<\/code>, <code>jq<\/code>)<\/td><td>\u4ece\u7ed3\u6784\u5316\u6570\u636e (XML, JSON) \u4e2d\u63d0\u53d6\u4fe1\u606f<\/td><td>\u5f3a\u5927\uff0c\u4e13\u4e3a\u6570\u636e\u89e3\u6790\u8bbe\u8ba1\uff0c\u9002\u5408\u811a\u672c\u5316<\/td><td>\u9700\u8981\u5b66\u4e60\u65b0\u7684\u547d\u4ee4\u8bed\u6cd5<\/td><\/tr><tr><td>\u5b89\u5168\u8fd0\u8425\u5e73\u53f0\/\u8d44\u4ea7\u7ba1\u7406\u5e73\u53f0 (\u5982 Archery, CMDB)<\/td><td>\u4f01\u4e1a\u7ea7\u3001\u6301\u7eed\u5316\u7684\u8d44\u4ea7\u7ba1\u7406\u4e0e\u98ce\u9669\u8ddf\u8e2a<\/td><td>\u81ea\u52a8\u5316\u3001\u53ef\u89c6\u5316\u3001\u6d41\u7a0b\u5316\uff0c\u53ef\u4e0e\u6f0f\u6d1e\u5e93\u8054\u52a8<\/td><td>\u90e8\u7f72\u548c\u7ef4\u62a4\u6210\u672c\u9ad8\uff0c\u9002\u7528\u4e8e\u5927\u578b\u7ec4\u7ec7<\/td><\/tr><tr><td>\u81ea\u5199\u811a\u672c (Python + Pandas)<\/td><td>\u5b9a\u5236\u5316\u5206\u6790\u3001\u590d\u6742\u6570\u636e\u5173\u8054\u3001\u62a5\u544a\u751f\u6210<\/td><td>\u6700\u7075\u6d3b\uff0c\u53ef\u6ee1\u8db3\u4efb\u4f55\u5b9a\u5236\u5316\u9700\u6c42<\/td><td>\u5f00\u53d1\u6210\u672c\u9ad8\uff0c\u5bf9\u7f16\u7a0b\u80fd\u529b\u6709\u8981\u6c42<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h4 class=\"wp-block-heading\">6. \u6807\u51c6\u64cd\u4f5c\u6b65\u9aa4<\/h4>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u6570\u636e\u6c47\u603b<\/strong>\uff1a\u6536\u96c6\u6a21\u5757\u4e94\u4e2d\u4ea7\u751f\u7684\u6240\u6709\u539f\u59cb\u6570\u636e\u6587\u4ef6\uff1a<code>nmap_ports.txt<\/code>\uff0c <code>nmap_versions.xml<\/code>\uff0c <code>whatweb_result.json<\/code>\uff0c <code>curl_headers.txt<\/code>\u3002<\/li>\n\n\n\n<li><strong>\u6570\u636e\u7ed3\u6784\u5316<\/strong>\uff1a\u4f7f\u7528 Python \u811a\u672c\uff08\u6216 <code>jq<\/code> + <code>xmlstarlet<\/code>\uff09\u5c06\u6240\u6709\u6570\u636e\u89e3\u6790\uff0c\u5408\u5e76\u5230\u4e00\u4e2a\u7edf\u4e00\u8868\u683c\u4e2d\u3002\u4f8b\u5982\uff0cCSV \u6587\u4ef6\uff0c\u5217\u540d\u5305\u62ec\uff1a<code>IP<\/code>, <code>\u7aef\u53e3<\/code>, <code>\u534f\u8bae<\/code>, <code>\u670d\u52a1\u540d<\/code>, <code>\u670d\u52a1\u7248\u672c<\/code>, <code>Web\u670d\u52a1\u5668<\/code>, <code>\u5e94\u7528\u6846\u67b6<\/code>, <code>\u524d\u7aef\u5e93<\/code>\u7b49\u3002<\/li>\n\n\n\n<li><strong>\u6570\u636e\u6e05\u6d17\u4e0e\u53bb\u91cd<\/strong>\uff1a\u5904\u7406\u4e0d\u540c\u5de5\u5177\u95f4\u53ef\u80fd\u51fa\u73b0\u7684\u77db\u76fe\u4fe1\u606f\uff08\u5982\u7248\u672c\u4e0d\u4e00\u81f4\uff09\u3002\u4f8b\u5982\uff0c\u82e5 <code>nmap<\/code> \u62a5\u544a\u7684 Apache \u7248\u672c\u662f 2.2.22\uff0c\u800c <code>whatweb<\/code> \u62a5\u544a\u7684\u662f 2.2.22 (Ubuntu)\uff0c\u5e94\u4ee5\u66f4\u8be6\u7ec6\u7684 <code>whatweb<\/code> \u7ed3\u679c\u4e3a\u51c6\uff0c\u5e76\u8bb0\u5f55\u77db\u76fe\u70b9\u3002<\/li>\n\n\n\n<li><strong>\u5173\u8054\u98ce\u9669\u4e0e\u7b56\u7565<\/strong>\uff1a\u5c06\u6e05\u6d17\u540e\u7684\u6e05\u5355\u4e0e\u9884\u5b9a\u4e49\u7684\u7b56\u7565\u77e5\u8bc6\u5e93\uff08\u53ef\u4ee5\u662f\u7b80\u5355\u7684 <code>if-else<\/code> \u5217\u8868\u6216\u6f0f\u6d1e\u6570\u636e\u5e93\uff09\u8fdb\u884c\u6bd4\u5bf9\u3002\u4f8b\u5982\uff1a\n<ul class=\"wp-block-list\">\n<li><code>\u82e5 (\u670d\u52a1\u540d == 'openssh' and \u7248\u672c &lt; '7.5') \u5219 \u8f93\u51fa \"\u5efa\u8bae\u5347\u7ea7 OpenSSH\"<\/code><\/li>\n\n\n\n<li><code>\u82e5 (Web\u670d\u52a1\u5668 == 'Apache' and \u7248\u672c in list_of_vulnerable_versions) \u5219 \u8f93\u51fa \"\u5efa\u8bae Apache \u6253\u8865\u4e01\u6216\u5347\u7ea7\"<\/code><\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u751f\u6210\u6574\u5408\u62a5\u544a<\/strong>\uff1a\u5c06\u6700\u7ec8\u7ed3\u6784\u5316\u6e05\u5355\u548c\u5173\u8054\u51fa\u7684\u7b56\u7565\u5efa\u8bae\uff0c\u6574\u7406\u6210\u6613\u8bfb\u7684\u62a5\u544a\u3002\u62a5\u544a\u5e94\u5305\u542b\uff1a\u6267\u884c\u6458\u8981\u3001\u8be6\u7ec6\u8d44\u4ea7\u6e05\u5355\u3001\u98ce\u9669\u53d1\u73b0\uff08\u6309\u4e25\u91cd\u6027\u6392\u5e8f\uff09\u3001\u5177\u4f53\u5904\u7f6e\u5efa\u8bae\u3002<\/li>\n\n\n\n<li><strong>\u7ed3\u679c\u5b58\u6863\u4e0e\u79fb\u4ea4<\/strong>\uff1a\u5c06\u539f\u59cb\u6570\u636e\u3001\u5904\u7406\u811a\u672c\u3001\u6700\u7ec8\u62a5\u544a\u4e00\u5e76\u5b58\u6863\uff0c\u5e76\u79fb\u4ea4\u7ed9\u76f8\u5173\u56e2\u961f\uff08\u5982\u8fd0\u7ef4\u3001\u5f00\u53d1\u3001\u5b89\u5168\uff09\u8ddf\u8fdb\u5904\u7406\u3002<\/li>\n<\/ol>\n\n\n\n<h4 class=\"wp-block-heading\">7. \u5982\u4f55\u9a8c\u8bc1\u7ed3\u679c\u771f\u5b9e\u6027<\/h4>\n\n\n\n<p><strong>\u9a8c\u8bc1\u903b\u8f91<\/strong>\uff1a\u9a8c\u8bc1\u6700\u7ec8\u8f93\u51fa\u7684\u62a5\u544a\u662f\u5426\u51c6\u786e\u53cd\u6620\u76ee\u6807\u7cfb\u7edf\u7684\u771f\u5b9e\u60c5\u51b5\uff0c\u4e14\u63d0\u51fa\u7684\u7b56\u7565\u662f\u5426\u5408\u7406\u3002<br><strong>\u5224\u65ad\u4f9d\u636e<\/strong>\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u51c6\u786e\u6027\u9a8c\u8bc1<\/strong>\uff1a\u968f\u673a\u62bd\u53d6\u62a5\u544a\u4e2d\u7684 3-5 \u6761\u5173\u952e\u4fe1\u606f\uff0c\u56de\u5230\u76ee\u6807\u7cfb\u7edf\u4e0a\uff0c\u4f7f\u7528\u6a21\u5757\u4e09\u7684\u624b\u52a8\u9a8c\u8bc1\u65b9\u6cd5\u590d\u6838\u3002\u82e5\u5168\u90e8\u5339\u914d\uff0c\u5219\u62a5\u544a\u51c6\u786e\u5ea6\u8f83\u9ad8\u3002<\/li>\n\n\n\n<li><strong>\u7b56\u7565\u5408\u7406\u6027\u9a8c\u8bc1<\/strong>\uff1a\u4e0e\u7cfb\u7edf\u7ba1\u7406\u5458\u6216\u5f00\u53d1\u4eba\u5458\u5f00\u4f1a\u8bc4\u5ba1\u62a5\u544a\u4e2d\u7684\u5904\u7f6e\u5efa\u8bae\u3002\u4f8b\u5982\uff0c\u5efa\u8bae\u5347\u7ea7\u67d0\u4e2a\u5e93\uff0c\u4f46\u8be5\u5e93\u53ef\u80fd\u56e0\u517c\u5bb9\u6027\u95ee\u9898\u65e0\u6cd5\u5347\u7ea7\u3002\u6b64\u8ba8\u8bba\u672c\u8eab\u5373\u80fd\u9a8c\u8bc1\u7b56\u7565\u5728\u7279\u5b9a\u4e1a\u52a1\u73af\u5883\u4e0b\u7684\u5408\u7406\u6027\u3002\u6700\u7ec8\u7b56\u7565\u9700\u7ed3\u5408\u4e1a\u52a1\u5b9e\u9645\u8c03\u6574\u3002<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">8. \u5e38\u89c1\u9519\u8bef\u4e0e\u6392\u67e5\u65b9\u5f0f<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u9519\u8bef<\/strong>\uff1a\u53ea\u7f57\u5217\u6570\u636e\uff0c\u4e0d\u63d0\u4f9b\u7b56\u7565\u3002\u62a5\u544a\u4ec5\u662f\u4e00\u4efd\u6280\u672f\u6e05\u5355\uff0c\u672a\u544a\u77e5\u8bfb\u8005\u201c\u8fd9\u4ee3\u8868\u4ec0\u4e48\u98ce\u9669\u201d\u53ca\u201c\u63a5\u4e0b\u6765\u8be5\u600e\u4e48\u505a\u201d\u3002<\/li>\n\n\n\n<li><strong>\u6392\u67e5<\/strong>\uff1a\u5728\u62a5\u544a\u7f16\u5199\u9636\u6bb5\uff0c\u5f3a\u5236\u4e3a\u6bcf\u4e2a\u53d1\u73b0\u7684\u7ec4\u4ef6\u6216\u7248\u672c\u601d\u8003\u5176\u4e1a\u52a1\u6216\u5b89\u5168\u542b\u4e49\u3002\u5373\u4f7f\u65e0\u81ea\u52a8\u5316\u7b56\u7565\u5e93\uff0c\u4e5f\u5e94\u5728\u62a5\u544a\u4e2d\u52a0\u5165\u201c\u5907\u6ce8\u201d\u6216\u201c\u5efa\u8bae\u201d\u5217\uff0c\u5199\u4e0b\u4eba\u5de5\u5224\u65ad\u7684\u521d\u6b65\u610f\u89c1\u3002<\/li>\n\n\n\n<li><strong>\u9519\u8bef<\/strong>\uff1a\u5ffd\u7565\u7ed3\u679c\u7684\u4e0a\u4e0b\u6587\u3002\u4f8b\u5982\uff0c\u62a5\u544a\u4e86\u4e00\u4e2a\u5f00\u653e\u7684 Redis \u6570\u636e\u5e93\u7aef\u53e3\uff0c\u4f46\u672a\u8bf4\u660e\u5b83\u662f\u7ed1\u5728\u516c\u7f51 IP \u4e0a\u8fd8\u662f\u5185\u7f51 IP \u4e0a\uff0c\u5bfc\u81f4\u7b56\u7565\u5efa\u8bae\u5931\u51c6\uff08\u516c\u7f51\u5e94\u5f3a\u5236\u4e0b\u7ebf\uff0c\u5185\u7f51\u5219\u53ef\u80fd\u53ea\u9700\u52a0\u56fa\u8bbf\u95ee\u63a7\u5236\uff09\u3002<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">9. \u5408\u89c4\u8fb9\u754c\u8bf4\u660e<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u4f7f\u7528\u573a\u666f<\/strong>\uff1a\u672c\u6a21\u5757\u9002\u7528\u4e8e\u4efb\u4f55\u9700\u8981\u5c06\u6280\u672f\u53d1\u73b0\u8f6c\u5316\u4e3a\u4e1a\u52a1\u51b3\u7b56\u7684\u573a\u666f\uff0c\u5982\u5b89\u5168\u98ce\u9669\u8bc4\u4f30\u62a5\u544a\u3001\u7cfb\u7edf\u4e0a\u7ebf\u524d\u5b89\u5168\u68c0\u67e5\u3001\u5b63\u5ea6\u8d44\u4ea7\u76d8\u70b9\u62a5\u544a\u3002<\/li>\n\n\n\n<li><strong>\u7f51\u7edc\u5b89\u5168\u89c6\u89d2<\/strong>\uff1a\u98ce\u9669\u5728\u4e8e\uff0c\u4e00\u4efd\u8be6\u7ec6\u3001\u51c6\u786e\u7684\u62a5\u544a\u672c\u8eab\u5c31\u662f\u9ad8\u5ea6\u654f\u611f\u4fe1\u606f\u3002\u82e5\u62a5\u544a\u6cc4\u9732\uff0c\u7b49\u4e8e\u4e3a\u653b\u51fb\u8005\u63d0\u4f9b\u4e86\u4e00\u4efd\u8be6\u5c3d\u7684\u201c\u653b\u51fb\u8def\u7ebf\u56fe\u201d\u3002\u56e0\u6b64\uff0c\u62a5\u544a\u7684\u5b58\u50a8\u3001\u4f20\u8f93\u548c\u5206\u53d1\u5fc5\u987b\u4e25\u683c\u9075\u5b88\u6570\u636e\u4fdd\u5bc6\u89c4\u5b9a\uff0c\u8fdb\u884c\u52a0\u5bc6\u548c\u6743\u9650\u63a7\u5236\u3002<\/li>\n\n\n\n<li><strong>\u51b3\u7b56\u6307\u5357<\/strong>\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u4f55\u65f6\u5fc5\u987b\u7528\uff1f<\/strong>\uff1a\u5728\u4efb\u4f55\u9700\u8981\u5411\u975e\u6280\u672f\u4eba\u5458\uff08\u5982\u7ba1\u7406\u5c42\u3001\u5ba2\u6237\uff09\u6c47\u62a5\u63a2\u67e5\u6210\u679c\u65f6\uff0c\u5efa\u8bae\u8fdb\u884c\u6574\u5408\u4e0e\u7b56\u7565\u8f93\u51fa\u3002\u5728\u9700\u8981\u9a71\u52a8\u540e\u7eed\u52a0\u56fa\u6216\u4fee\u590d\u5de5\u4f5c\u65f6\uff0c\u4e5f\u5fc5\u987b\u6267\u884c\u6b64\u6b65\u9aa4\u3002<\/li>\n\n\n\n<li><strong>\u4f55\u65f6\u53ef\u8df3\u8fc7\uff1f<\/strong>\uff1a\u82e5\u63a2\u67e5\u6d3b\u52a8\u4ec5\u4f5c\u4e3a\u4e2a\u4eba\u6280\u672f\u7ec3\u4e60\uff0c\u6216\u7528\u4e8e\u4e34\u65f6\u8c03\u8bd5\u81ea\u5df1\u7684\u7a0b\u5e8f\uff0c\u90a3\u4e48\u53ea\u9700\u539f\u59cb\u6570\u636e\u5373\u53ef\uff0c\u65e0\u9700\u6574\u5408\u8f93\u51fa\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">10. \u672c\u6a21\u5757\u9636\u6bb5\u6027\u5c0f\u7ed3<\/h4>\n\n\n\n<p>\u81f3\u6b64\uff0c\u6211\u4eec\u5b8c\u6210\u4e86\u6574\u4e2a\u201c\u5e94\u7528\u670d\u52a1\u63a2\u67e5\u80fd\u529b\u201d\u7684\u95ed\u73af\u3002\u4ece\u5efa\u7acb\u8ba4\u77e5\u6846\u67b6\u5f00\u59cb\uff0c\u5b66\u4f1a\u754c\u5b9a\u76ee\u6807\u3001\u89e3\u6790\u7279\u5f81\u3001\u6784\u5efa\u6a21\u578b\u3001\u5f62\u6210\u6d41\u7a0b\u3001\u63a7\u5236\u98ce\u9669\uff0c\u6700\u7ec8\u5c06\u4fe1\u606f\u6574\u5408\u4e3a\u53ef\u6307\u5bfc\u884c\u52a8\u7684\u7b56\u7565\u3002\u8fd9\u4e03\u9879\u80fd\u529b\u4e0d\u4ec5\u6559\u4f1a\u4e86\u5de5\u5177\u4f7f\u7528\uff0c\u66f4\u91cd\u8981\u7684\u662f\u5851\u9020\u4e86\u4f5c\u4e3a\u5b89\u5168\u5de5\u7a0b\u5e08\u6216\u8fd0\u7ef4\u5f00\u53d1\u4eba\u5458\u7684\u4e13\u4e1a\u601d\u7ef4\u65b9\u5f0f\u2014\u2014\u4e00\u79cd\u7cfb\u7edf\u6027\u3001\u5de5\u7a0b\u5316\u3001\u8d1f\u8d23\u4efb\u7684\u89e3\u51b3\u95ee\u9898\u7684\u65b9\u6cd5\u3002\u5e0c\u671b\u8fd9\u5957\u65b9\u6cd5\u8bba\u80fd\u6210\u4e3a\u4f60\u6280\u672f\u5de5\u5177\u7bb1\u4e2d\u7684\u6838\u5fc3\u652f\u67f1\u3002<\/p>\n\n\n\n<p><strong>\u63a2\u67e5\u7ed3\u679c\u6574\u5408\u4e0e\u7b56\u7565\u8f93\u51fa\u6d41\u7a0b<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/03\/\u63a2\u67e5\u7ed3\u679c\u6574\u5408\u4e0e\u7b56\u7565\u8f93\u51fa\u6d41\u7a0b-226x1024.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"226\" height=\"1024\" data-original=\"http:\/\/www.preluna.xyz\/wp-content\/uploads\/2026\/03\/\u63a2\u67e5\u7ed3\u679c\u6574\u5408\u4e0e\u7b56\u7565\u8f93\u51fa\u6d41\u7a0b-226x1024.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1782\"  sizes=\"auto, (max-width: 226px) 100vw, 226px\" \/><\/div><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">\u53c2\u8003\u4e0e\u8fdb\u4e00\u6b65\u9605\u8bfb<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Nmap Reference Guide<\/strong>: \u672c\u6587\u4e2d\u6240\u6709 <code>nmap<\/code> \u547d\u4ee4\uff08\u7aef\u53e3\u626b\u63cf\u3001\u7248\u672c\u63a2\u6d4b\u3001\u626b\u63cf\u901f\u7387\u63a7\u5236\uff09\u7684\u4e3b\u8981\u4f9d\u636e\u3002<\/li>\n\n\n\n<li><strong>curl Documentation<\/strong>: \u672c\u6587\u4e2d\u6240\u6709 <code>curl<\/code> \u547d\u4ee4\uff08\u67e5\u770b\u54cd\u5e94\u5934\u3001\u63d0\u53d6\u7279\u5f81\u3001User-Agent \u4f2a\u9020\uff09\u7684\u5b98\u65b9\u53c2\u8003\u3002<\/li>\n\n\n\n<li><strong>WhatWeb Project<\/strong>: \u672c\u6587\u4e2d <code>whatweb<\/code> \u6307\u7eb9\u8bc6\u522b\u5de5\u5177\u53ca\u5176\u8be6\u7ec6\u6a21\u5f0f\u5206\u6790\u7684\u529f\u80fd\u6765\u6e90\u3002<\/li>\n\n\n\n<li><strong>IETF RFC 1035 &#8211; Domain Names &#8211; Implementation and Specification<\/strong>: DNS \u57fa\u7840\u534f\u8bae\uff08<code>dig<\/code> \u547d\u4ee4\uff09\u7684\u6743\u5a01\u5b9a\u4e49\u3002 \uff08\u6838\u5fc3\u884c\u4e3a\u81ea 1987 \u5e74\u4ee5\u6765\u672a\u53d1\u751f\u91cd\u5927\u53d8\u5316\uff09<\/li>\n\n\n\n<li><strong>RFC 9619 &#8211; In the DNS, QDCOUNT Is (Usually) One<\/strong>: DNS \u534f\u8bae\u6700\u65b0\u66f4\u65b0\uff0c\u786e\u8ba4\u4e86 <code>dig<\/code> \u7b49\u67e5\u8be2\u884c\u4e3a\u7684\u534f\u8bae\u6807\u51c6\u3002<\/li>\n\n\n\n<li><strong>Proxychains Project<\/strong>: \u672c\u6587\u4e2d\u901a\u8fc7\u4ee3\u7406\u9690\u85cf\u6e90 IP \u7684 <code>proxychains<\/code> \u5de5\u5177\u6765\u6e90\u3002\u5efa\u8bae\u8bfb\u8005\u8bbf\u95ee\u5b98\u65b9\u6700\u65b0\u6587\u6863\u4ee5\u786e\u8ba4\u5f53\u524d\u73af\u5883\u517c\u5bb9\u6027\u3002<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u4fe1\u606f\u6536\u96c6-Web\u5e94\u7528-\u67b6\u6784\u5206\u6790&amp;\u6307\u7eb9\u8bc6\u522b \u4e00\u3001\u7f51\u7edc\u6280\u672f\u6808\u8ba4\u77e5\u91cd\u6784 1.1 \u6a21\u5757\u6982\u5ff5\u89e3\u91ca \u7f51\u7edc\u6280\u672f\u6808\u8ba4\u77e5 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[54],"tags":[],"class_list":["post-1759","post","type-post","status-publish","format-standard","hentry","category-text"],"_links":{"self":[{"href":"http:\/\/www.preluna.xyz\/index.php\/wp-json\/wp\/v2\/posts\/1759","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.preluna.xyz\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.preluna.xyz\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.preluna.xyz\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/www.preluna.xyz\/index.php\/wp-json\/wp\/v2\/comments?post=1759"}],"version-history":[{"count":5,"href":"http:\/\/www.preluna.xyz\/index.php\/wp-json\/wp\/v2\/posts\/1759\/revisions"}],"predecessor-version":[{"id":1783,"href":"http:\/\/www.preluna.xyz\/index.php\/wp-json\/wp\/v2\/posts\/1759\/revisions\/1783"}],"wp:attachment":[{"href":"http:\/\/www.preluna.xyz\/index.php\/wp-json\/wp\/v2\/media?parent=1759"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.preluna.xyz\/index.php\/wp-json\/wp\/v2\/categories?post=1759"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.preluna.xyz\/index.php\/wp-json\/wp\/v2\/tags?post=1759"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}