开发者社区> 问答> 正文

远程模拟登录,怎么通过token认证

想用PHP方式远程登录一台华为路由器,但是它使用了 token ,按照抓的HEADER和代码片段

从/asp/GetRandCount.asp取得一个Token,密码用base64encode编码后一并同用户名发送给/login.cgi

按照这种用 PHP 的 CURL 尝试远端登录路由器,结果返回提示用户名和密码,本人新手敬请老师们指点


----------------------------------------------------------
$.ajax({
type : "POST",
async : false,
cache : false,
url : '/asp/GetRandCount.asp',
success : function(data) {
cnt = data;
}
});

var Form = new webSubmitForm();
var cookie2 = "Cookie=body:" + "Language:" + Language + ":" + "id=-1;path=/";
Form.addParameter('UserName', Username.value);
Form.addParameter('PassWord', base64encode(Password.value));
    document.cookie = cookie2;

    Username.disabled = true;
    Password.disabled = true;

    Form.addParameter('x.X_HW_Token', cnt);
Form.setAction('/login.cgi');
Form.submit();
    return true;
}
----------------------------------------------------------


http/192.168.100.1/asp/GetRandCount.asp

POST /asp/GetRandCount.asp HTTP/1.1
Host: 192.168.100.1
User-Agent: Mozilla/5.0 (Windows NT 6.1; rv:49.0) Gecko/20100101 Firefox/49.0HTTcryPt/Add-on
Accept: */*
Accept-Language: zh-CN,zh;q=0.8,en-US;q=0.5,en;q=0.3
Accept-Encoding: gzip, deflate
X-Requested-With: XMLHttpRequest
Referer: http/192.168.100.1/
Connection: keep-alive
Content-Length: 0

----------------------------------------------------------
http/192.168.100.1/login.cgi

POST /login.cgi HTTP/1.1
Host: 192.168.100.1
User-Agent: Mozilla/5.0 (Windows NT 6.1; rv:49.0) Gecko/20100101 Firefox/49.0HTTcryPt/Add-on
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: zh-CN,zh;q=0.8,en-US;q=0.5,en;q=0.3
Accept-Encoding: gzip, deflate
Referer: http/192.168.100.1/
Cookie: Cookie=body:Language:chinese:id=-1
Connection: keep-alive
Upgrade-Insecure-Requests: 1
Content-Type: application/x-www-form-urlencoded
Content-Length: 83
UserName=root&PassWord=xxxxxxxxxxx&x.X_HW_Token=da2bd6366375c189b85e88f12ca72e14






展开
收起
东村 2016-09-21 19:33:06 7028 0
1 条回答
写回答
取消 提交回答
  • Re远程模拟登录,怎么通过token认证
    这个是登录页面相关文件
    2016-09-21 19:35:46
    赞同 展开评论 打赏
问答排行榜
最热
最新

相关电子书

更多
安全机制与User账户身份验证实战 立即下载
低代码开发师(初级)实战教程 立即下载
阿里巴巴DevOps 最佳实践手册 立即下载