Many people may think of the overflow that has been passed in for a long time before. In fact, the overflow is not so awesome, but the impact is not small. It is a logic vulnerability,
If you build a website and install WAF, you will definitely put the search engine crawler on the white list. Otherwise, SEO will hurt.
What does whitelist mean ???
That is to say, the users in the White List, WAF will not care about it, directly allow, then we can use this thing to bypass the safe dog.
Search engine crawlers are on the whitelist of secure dogs. We only need to pretend to be crawlers and then OK.
How does a Dongle determine crawlers ?? I tested it and found that he used a very common method, namely user-agent. Everyone knows that this is a good counterfeit.
The specific forgery method is not provided here. You can find related articles by yourself.