Taking www.verycd.com as an example
Login wuming88888888 account in Firefox browser for sending party
Login to wuming1990 account as receiver in Chrome browser
Analyze the sender's form
Analyze submit page source code post data [PHP] view plain copy <?php require ('./http.class.php '); $http =new http (' http://home.verycd.com/cp.php?ac=pm&op=send&touid=0&pmid=0 '); $msg =array (' Formhash ' => ' 10fe754a ', ' message ' => ' hello ', ' pmsubmit ' =>true, ' pmsubmit_btn ' => ;' Send ', ' refer ' => ' http://home.verycd.com/space.php?do=pm&filter=privatepm ', ' username ' => ' wuming1990 ' ); File_put_contents ('./res.html ', $http->post ($msg)); ?>
Open res.html, analyze source code[PHP] View plain copy http/1.1 301 moved permanently server: nginx Date: Fri, 05 Dec 2014 06:57:05 GMT content-type: text/html transfer-encoding: chunked connection: close Set-Cookie: sid= deleted; expires=thu, 01-jan-1970 00:00:01 gmt; path=/; domain=.verycd.com Set-cookie: member_id=deleted; expires=thu, 01-jan-1970 00:00:01 gmt; path =/; domain=.verycd.com set-cookie: member_name=deleted; expires=thu, 01- jan-1970 00:00:01 gmt; path=/; domain=.verycd.com Set-Cookie: pass_hash= deleted; expires=thu, 01-jan-1970 00:00:01 gmt; path=/; domain=.verycd.com set-cookie: rememberme=deleted; expires=thu, 01-jan-1970 00:00:01 gmt; Path=/; domain=.verycd.com set-cookie: mgroupid=deleted; expires=thu, 01-jan-1970 00:00:01 gmt; path=/; domain=.verycd.com set-cookie: coppa=deleted; expires=thu, 01 -jan-1970 00:00:01 gmt; path=/; domain=.verycd.com Set-Cookie: uchome_auth =deleted; expires=thu, 01-jan-1970 00:00:01 gmt; path=/; domain=.verycd.com set-cookie: uchome_loginuser=deleted; expires=thu, 01-jan-1970 00:00:01 gmt; path=/; domain=.verycd.com location: http://www.verycd.com/account/profile/ set-cookie: uchome__refer=cp.php%253fac%253dprofile; path=/; domain=.verycd.com 33fc
Debug to see what you are sending.[PHP] View plain Copy this time we can analyze the error appearing in the first line print the object http object ( [errno:protected] => 0 [errstr:protected] => [response:protected] => [url:protected] => Array ( [scheme] => http [host] = > home.verycd.com [ path] => /cp.php [query] => ac=pm&op=send&touid=0&pmid=0 [port] => 80 ) [version:protected] => http/1.1 [fh:protected] => Resource id #3 [line:protected] => Array ( [0] => POST /cp.php HTTP/1.1 ) [header:protected] => Array ( [0] => Host:home.verycd.com [1] => Content-type:application/x-www-form-urlencoded [2] => Content-length:185 ) [body:protected] = > Array ( [0] => formhash=10fe754a&message=%e4%bd %a0%e5%a5%bd&pmsubmit=1&pmsubmit_btn=%e5%8f%91%e9%80%81&refer=http%3a%2f%2fhome.verycd.com% 2fspace.php%3fdo%3dpm%26filter%3dprivatepm&username=wuming1990 ) )
[PHP] View Plain copy modifies our HTTP class <pre name= "code" class= "PHP" > //http Request class interface interface proto{ //Connection url function conn ($url); //send get query function get (); //send post query Function post (); //close connection function close (); } class http implements proto{ const crlf= "\ r \ n"; protected $errno =-1; protected $errstr = '; protected $response = '; protected $url =null; protected $version = ' http/1.1 '; protected $fh =null; protected $line =array (); protected $header =array (); protected $body =array (); public function __construct ($url) { $this->conn ($url); $this-> SetHeader (' Host: '. $this->url[' host '); } //This method is responsible for writing request lines protected function setline ($method) { $this->line[0]= $method. ' $this->url[' path '. $this->url[' query ']. ' $this->version; } &NBSP;&NBSP;&NBsp; //This method is responsible for writing header information public function setheader ($headerline) { $this->header[]= $headerline; } //This method is responsible for writing the main information Protected function setbody ($body) { $this->body[]=http_build_query ($body); } //Connection url function conn ($url) { $this->url=parse _url ($url); //judgment Port if (!isset ($this->url[' Port ')) { $this->url[' Port ']=80; } $this->fh=fsockopen ($this->url[' host '), $this->url[' Port '], $this->errno, $this->errstr,3); } //constructs a GET request data function get () { $this->setline (' get '); $ This->request (); return $this->response; } //constructs POST request data function post ($body =array ()) { // Construction body Information $this->setline (' POST '); // Set up content-type $this->setheader (' Content-type: Application/x-www-form-urlencoded '); //set the body information, A different place than get $this->setbody ($body); //Computing content-length $this->setheader (' Content-length: strlen ($this->body[0)); $this->request (); return $this->response; } Real Request function request () { //putRequest line, header information, entity information put in an array for easy stitching $req =array_ Merge ($this->line, $this->header,array ("), $this->body,array (")); $req =implode (Self::crlf, $req); // print_ R ($this); // echo $req; // exit; fwrite ($this->fh, $req); while (!feof ($this->fh)) { $this->response.=fread ($this->fh,1024); } $this->close ();//close connection return $ this->response; } //Close Connection function close () { Fclose ($this->fh); } }
Generate the following post/cp.php?ac=pm&op=send&touid=0&pmid=0 http/1.1host:home.verycd.comcontent-type:application/ x-www-form-urlencodedcontent-length:185formhash=10fe754a&message=%e4%bd%a0%e5%a5%bd&pmsubmit=1& pmsubmit_btn=%e5%8f%91%e9%80%81&refer=http%3a%2f%2fhome.verycd.com%2fspace.php%3fdo%3dpm%26filter% 3dprivatepm&username=wuming1990[PHP] View plain copy http/1.1 200 ok server: nginx date: fri, 05 dec 2014 07:11:39 gmt content-type: text/html Transfer-Encoding: chunked connection: close Set-cookie: sid=deleted; expires=thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.verycd.com set-cookie: Member_id=deleted; expires=thu, 01-jan-1970 00:00:01 gmt; path=/; domain=. verycd.com set-cookie: member_name=deleted; expires=thu, 01-jan-1970 00:00:01 GMT; path=/; domain=.verycd.com set-cookie: pass_hash=deleted; expires= thu, 01-jan-1970 00:00:01 gmt; path=/; domain=.verycd.com Set-Cookie: rememberme=deleted; expires=thu, 01-jan-1970 00:00:01 gmt; path=/; domain= .verycd.com set-cookie: mgroupid=deleted; expires=thu, 01-jan-1970 00:00:01 gmt; path=/; domain=.verycd.com set-cookie: coppa=deleted; expires=thu, 01-jan-1970 00:00:01 gmt; path=/; domain=.verycd.com set-cookie: uchome_auth=deleted; expires=thu, 01-jan-1970 00:00:01 gmt; path=/; domain=.verycd.com set-cookie: uchome_loginuser=deleted; expires=thu, 01-jan-1970 00:00:01 gmt; path=/; domain=.verycd.com set-cookie: uchome__refer=cp.php%253fac%253dpm; path=/; domain=.verycd.com indicated success, but not complete, we went on to look at the contents of the res.html The Web page has the following contents: Indicates that you need to log in before you can operate
How did the server know we didn't log in?
HTTP is a very important feature: stateless, there is no relationship between requests two times.
How the server remembers a customer.
Create cookies.