HTTP Protocol Analysis Series (vi)------Php+socket+cookie Request

Source: Internet
Author: User

Taking www.verycd.com as an example

Login wuming88888888 account in Firefox browser for sending party

Login to wuming1990 account as receiver in Chrome browser

Analyze the sender's form

Analyze submit page source code post data [PHP] view plain copy <?php require ('./http.class.php ');   $http =new http (' http://home.verycd.com/cp.php?ac=pm&op=send&touid=0&pmid=0 '); $msg =array (' Formhash ' => ' 10fe754a ', ' message ' => ' hello ', ' pmsubmit ' =>true, ' pmsubmit_btn ' => ;'   Send ', ' refer ' => ' http://home.verycd.com/space.php?do=pm&filter=privatepm ', ' username ' => ' wuming1990 '   );      File_put_contents ('./res.html ', $http->post ($msg)); ?>

Open res.html, analyze source code[PHP] View plain copy http/1.1 301 moved permanently   server: nginx   Date:  Fri, 05 Dec 2014 06:57:05 GMT   content-type: text/html    transfer-encoding: chunked   connection: close   Set-Cookie: sid= deleted; expires=thu, 01-jan-1970 00:00:01 gmt; path=/; domain=.verycd.com    Set-cookie: member_id=deleted; expires=thu, 01-jan-1970 00:00:01 gmt; path =/; domain=.verycd.com   set-cookie: member_name=deleted; expires=thu, 01- jan-1970 00:00:01 gmt; path=/; domain=.verycd.com   Set-Cookie: pass_hash= deleted; expires=thu, 01-jan-1970 00:00:01 gmt; path=/; domain=.verycd.com    set-cookie: rememberme=deleted; expires=thu, 01-jan-1970 00:00:01 gmt;  Path=/; domain=.verycd.com   set-cookie: mgroupid=deleted; expires=thu, 01-jan-1970 00:00:01  gmt; path=/; domain=.verycd.com   set-cookie: coppa=deleted; expires=thu, 01 -jan-1970 00:00:01 gmt; path=/; domain=.verycd.com   Set-Cookie: uchome_auth =deleted; expires=thu, 01-jan-1970 00:00:01 gmt; path=/; domain=.verycd.com    set-cookie: uchome_loginuser=deleted; expires=thu, 01-jan-1970 00:00:01  gmt; path=/; domain=.verycd.com   location: http://www.verycd.com/account/profile/    set-cookie: uchome__refer=cp.php%253fac%253dprofile; path=/; domain=.verycd.com       33fc  

Debug to see what you are sending.[PHP] View plain Copy this time we can analyze the error appearing in the first line    print the object    http object   (        [errno:protected] => 0       [errstr:protected]  =>        [response:protected] =>         [url:protected] => Array             (               [scheme] =>  http               [host] = > home.verycd.com               [ path] => /cp.php                [query] => ac=pm&op=send&touid=0&pmid=0                [port] => 80            )           [version:protected] => http/1.1        [fh:protected] => Resource id  #3         [line:protected] => Array             (               [0] =>  POST /cp.php HTTP/1.1           )           [header:protected] => Array             (                [0] => Host:home.verycd.com                [1] => Content-type:application/x-www-form-urlencoded                [2] => Content-length:185            )           [body:protected] = > Array            (                [0] => formhash=10fe754a&message=%e4%bd %a0%e5%a5%bd&pmsubmit=1&pmsubmit_btn=%e5%8f%91%e9%80%81&refer=http%3a%2f%2fhome.verycd.com% 2fspace.php%3fdo%3dpm%26filter%3dprivatepm&username=wuming1990            )      )   
[PHP] View Plain copy modifies our HTTP class       <pre name= "code"  class= "PHP" > //http Request class interface    interface proto{       //Connection url        function conn ($url);       //send get query         function get ();       //send post query         Function post ();       //close connection        function  close ();  }   class http implements proto{        const crlf= "\ r \ n";       protected  $errno =-1;       protected  $errstr = ';       protected  $response = ';       protected  $url =null;       protected  $version = ' http/1.1 ';       protected  $fh =null;        protected  $line =array ();       protected  $header =array ();        protected  $body =array ();              public function __construct ($url) {             $this->conn ($url);            $this-> SetHeader (' Host: '. $this->url[' host ');       }        //This method is responsible for writing request lines        protected function setline ($method) {             $this->line[0]= $method. '   $this->url[' path '. $this->url[' query ']. '   $this->version;       }   &NBSP;&NBSP;&NBsp; //This method is responsible for writing header information        public function setheader ($headerline) {             $this->header[]= $headerline;        }       //This method is responsible for writing the main information         Protected function setbody ($body) {                        $this->body[]=http_build_query ($body);        }       //Connection url        function conn ($url) {            $this->url=parse _url ($url);           //judgment Port             if (!isset ($this->url[' Port ')) {                 $this->url[' Port ']=80;           }            $this->fh=fsockopen ($this->url[' host '), $this->url[' Port '], $this->errno, $this->errstr,3);       }        //constructs a GET request data        function get () {             $this->setline (' get ');           $ This->request ();           return  $this->response;        }       //constructs POST request data         function post ($body =array ()) {           // Construction body Information             $this->setline (' POST ');                      // Set up content-type            $this->setheader (' Content-type: Application/x-www-form-urlencoded ');           //set the body information, A different place than get             $this->setbody ($body);           //Computing content-length             $this->setheader (' Content-length: strlen ($this->body[0));             $this->request ();            return  $this->response;       }        Real Request        function request () {            //putRequest line, header information, entity information    put in an array for easy stitching             $req =array_ Merge ($this->line, $this->header,array ("), $this->body,array ("));             $req =implode (Self::crlf, $req);  //      print_ R ($this);  //      echo  $req;  //       exit;           fwrite ($this->fh, $req);                        while (!feof ($this->fh)) {                 $this->response.=fread ($this->fh,1024);            }                        $this->close ();//close connection            return $ this->response;       }       //Close Connection        function close () {            Fclose ($this->fh);       }  }  



Generate the following post/cp.php?ac=pm&op=send&touid=0&pmid=0 http/1.1host:home.verycd.comcontent-type:application/ x-www-form-urlencodedcontent-length:185formhash=10fe754a&message=%e4%bd%a0%e5%a5%bd&pmsubmit=1& pmsubmit_btn=%e5%8f%91%e9%80%81&refer=http%3a%2f%2fhome.verycd.com%2fspace.php%3fdo%3dpm%26filter% 3dprivatepm&username=wuming1990[PHP] View plain copy http/1.1 200 ok   server: nginx   date: fri, 05  dec 2014 07:11:39 gmt   content-type: text/html   Transfer-Encoding:  chunked   connection: close   Set-cookie: sid=deleted; expires=thu,  01-Jan-1970 00:00:01 GMT; path=/; domain=.verycd.com   set-cookie:  Member_id=deleted; expires=thu, 01-jan-1970 00:00:01 gmt; path=/; domain=. verycd.com   set-cookie: member_name=deleted; expires=thu, 01-jan-1970 00:00:01  GMT; path=/; domain=.verycd.com   set-cookie: pass_hash=deleted; expires= thu, 01-jan-1970 00:00:01 gmt; path=/; domain=.verycd.com   Set-Cookie:  rememberme=deleted; expires=thu, 01-jan-1970 00:00:01 gmt; path=/; domain= .verycd.com   set-cookie: mgroupid=deleted; expires=thu, 01-jan-1970 00:00:01 gmt; path=/;  domain=.verycd.com   set-cookie: coppa=deleted; expires=thu, 01-jan-1970  00:00:01 gmt; path=/; domain=.verycd.com   set-cookie: uchome_auth=deleted;  expires=thu, 01-jan-1970 00:00:01 gmt; path=/; domain=.verycd.com   set-cookie: uchome_loginuser=deleted; expires=thu, 01-jan-1970 00:00:01 gmt;  path=/; domain=.verycd.com   set-cookie: uchome__refer=cp.php%253fac%253dpm; path=/;  domain=.verycd.com      indicated success, but not complete, we went on to look at the contents of the res.html    The Web page has the following contents: Indicates that you need to log in before you can operate   


How did the server know we didn't log in?

HTTP is a very important feature: stateless, there is no relationship between requests two times.

How the server remembers a customer.

Create cookies.

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.