Ekultek / WhatWaf

Detect and bypass web application firewalls and protection systems
Other
2.55k stars 434 forks source link

Unknown Firewall (3a2c0b4c3) #1568

Closed WhatWaf-Firewalls closed 1 year ago

WhatWaf-Firewalls commented 1 year ago

WhatWaf version: 2.0.3 Running context: ./whatwaf -u **************************** Fingerprint:

<!--
GET http://www.pdidc.com HTTP/1.1
Status code: 461
Date: Sun, 31 Jul 2022 23:25:47 GMT
Content-Type: text/html;charset=utf-8
Transfer-Encoding: chunked
Connection: close
Set-Cookie: http_waf_cookie=18cae91e-ed6c-4c1fd611bdb1ad7f54f17a1e7afc9a008427; Expires=1659317147; Path=/; HttpOnly
cache-control: no-cache
Server: WAF
X-Request-Id: a26c425003b289be20b679d9c39785b5
-->
<!DOCTYPE doctype html>
 <head> <meta charset="utf-8">
<meta content="IE=9,Chrome=1" http-equiv="X-UA-Compatible"/>
<meta content="width=device-width, initial-scale=1.0" name="viewport">
<title>小伙伴出错了</title>
</meta></meta></head><body>
</body><body><div id="main" style="display:none"></div>
<style type="text/css">    /*css reset start*/    html, body, div, span, applet, object, iframe,    h1, h2, h3, h4, h5, h6, p, blockquote, pre,    a, abbr, acronym, address, big, cite, code,    del, dfn, em, img, ins, kbd, q, s, samp,    small, strike, strong, sub, sup, tt, var,    b, u, i, center,    dl, dt, dd, ol, ul, li,    fieldset, form, label, legend,    table, caption, tbody, tfoot, thead, tr, th, td,    article, aside, canvas, details, embed,    figure, figcaption, footer, header, hgroup,    menu, nav, output, ruby, section, summary,    time, mark, audio, video {        margin: 0;        padding: 0;        border: 0;        font-size: 100%;        font: inherit;        vertical-align: baseline;    }    article, aside, details, figcaption, figure,    footer, header, hgroup, menu, nav, section {        display: block;    }    body {        line-height: 1;    }    ol, ul {        list-style: none;    }    blockquote, q {        quotes: none;    }    blockquote:before, blockquote:after,    q:before, q:after {        content: &#039;&#039;;        content: none;    }    table {        border-collapse: collapse;        border-spacing: 0;    }    /*css reset end*/    html, body {        width: 100%;        height: 100%;        text-align: center;        overflow: hidden;    }    html {        font: 100%/1.6 &#039;Helvetica Neue&#039;, Helvetica, &#039;Hiragino Sans GB&#039;, STHeitiSC-Light, &#039;Microsoft YaHei&#039;, 微软雅黑, Arial, sans-serif;    }    img {        max-width: 100%;        height: 30%;    }    .container {        width: 100%;        height: 100%;        position: relative;    }    .main {        width: 100%;        height: 100%;    }    .err-tips-cn {        margin-top: 309px;    }    #err_code {        font-size: 136px;        font-style: italic;        font-weight: 300;        color: #00A2Ca;    }    #tpis_cn {        margin-left: 20px;        font-size: 40px;        color: #333;    }    .err-tips-en {        margin-top: 22px;        font-size: 55px;        color: #666;    }    .img-line {        margin-top: 10px;    }    .host-info {        margin-top: 10px;        color: #666;        font-size: 18px;        font-weight: 200;    }    .host-info-mar {        margin-left: 20px;    }    @media screen and (min-width: 992px) and (max-width: 1366px) {        .err-tips-cn {            margin-top: 200px;        }        #err_code {            font-size: 120px;        }        #tpis_cn {            font-size: 40px;        }        .err-tips-en {            font-size: 35px;        }    }    @media screen and  (min-width: 769px) and (max-width: 991px) {        .err-tips-cn {            margin-top: 200px;        }        #err_code {            font-size: 120px;        }        #tpis_cn {            font-size: 40px;        }        .err-tips-en {            font-size: 35px;        }        .host-info {            font-size: 20px;        }    }    @media screen and (min-width: 520px) and (max-width: 768px) {        .err-tips-cn {            margin-top: 350px;        }        #err_code {            font-size: 100px;        }        #tpis_cn {            font-size: 40px;        }        .err-tips-en {            font-size: 35px;        }        .host-info {            font-size: 20px;        }    }    @media screen and (min-width: 360px) and (max-width: 519px) {        .err-tips-cn {            margin-top: 250px;        }        #err_code {            font-size: 60px;        }        #tpis_cn {            font-size: 30px;        }        .err-tips-en {            font-size: 25px;        }        .host-info {            font-size: 15px;        }    }    @media screen and (max-width: 359px) {        .err-tips-cn {            margin-top: 200px;        }        #err_code {            font-size: 50px;        }        #tpis_cn {            font-size: 25px;        }        .err-tips-en {            font-size: 20px;        }        .host-info {            font-size: 10px;        }    }    /*ie9以下版本模拟媒体查询*/    .w992 .err-tips-cn {        margin-top: 200px;    }    .w992 #err_code {        font-size: 120px;    }    .w992 #tpis_cn {        font-size: 40px;    }    .w992 .err-tips-en {        font-size: 35px;    }    .w769 .err-tips-cn {        margin-top: 200px;    }    .w769 #err_code {        font-size: 120px;    }    .w769 #tpis_cn {        font-size: 40px;    }    .w769 .err-tips-en {        font-size: 35px;    }    .w769 .host-info {        font-size: 20px;    }    .w521 .err-tips-cn {        margin-top: 350px;    }    .w521 #err_code {        font-size: 100px;    }    .w521 #tpis_cn {        font-size: 40px;    }    .w521 .err-tips-en {        font-size: 35px;    }    .w521 .host-info {        font-size: 20px;    }    .w321 .err-tips-cn {        margin-top: 250px;    }    .w321 #err_code {        font-size: 60px;    }    .w321 #tpis_cn {        font-size: 30px;    }    .w321 .err-tips-en {        font-size: 25px;    }    .w321 .host-info {        font-size: 15px;    }    .lt-w320 .err-tips-cn {        margin-top: 200px;    }    .lt-w320 #err_code {        font-size: 50px;    }    .lt-w320 #tpis_cn {        font-size: 25px;    }    .lt-w320 .err-tips-en {        font-size: 20px;    }    .lt-w320 .host-info {        font-size: 10px;    }</style><div class="container"> <div class="main"> <div class="err-tips-cn"> <span id="err_code">461</span><span id="tpis_cn">请求被WEB防火墙拦截</span> </div> <div class="err-tips-en">Blocked by Cloud WAF</div> <div class="img-line"> <img alt="" src="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAABmkAAAABCAYAAAA1kEpOAAAAGXRFWHRTb2Z0d2FyZQBBZG9iZSBJbWFnZVJlYWR5ccllPAAAA3FpVFh0WE1MOmNvbS5hZG9iZS54bXAAAAAAADw/eHBhY2tldCBiZWdpbj0i77u/IiBpZD0iVzVNME1wQ2VoaUh6cmVTek5UY3prYzlkIj8+IDx4OnhtcG1ldGEgeG1sbnM6eD0iYWRvYmU6bnM6bWV0YS8iIHg6eG1wdGs9IkFkb2JlIFhNUCBDb3JlIDUuNS1jMDE0IDc5LjE1MTQ4MSwgMjAxMy8wMy8xMy0xMjowOToxNSAgICAgICAgIj4gPHJkZjpSREYgeG1sbnM6cmRmPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5LzAyLzIyLXJkZi1zeW50YXgtbnMjIj4gPHJkZjpEZXNjcmlwdGlvbiByZGY6YWJvdXQ9IiIgeG1sbnM6eG1wTU09Imh0dHA6Ly9ucy5hZG9iZS5jb20veGFwLzEuMC9tbS8iIHhtbG5zOnN0UmVmPSJodHRwOi8vbnMuYWRvYmUuY29tL3hhcC8xLjAvc1R5cGUvUmVzb3VyY2VSZWYjIiB4bWxuczp4bXA9Imh0dHA6Ly9ucy5hZG9iZS5jb20veGFwLzEuMC8iIHhtcE1NOk9yaWdpbmFsRG9jdW1lbnRJRD0ieG1wLmRpZDo1MzRkZTM1My01Y2EzLTM3NGMtOWYwMy00OWFjNjc2ZWQ0ZTQiIHhtcE1NOkRvY3VtZW50SUQ9InhtcC5kaWQ6MzhBN0E4QzI3NjUyMTFFNkJBMTdEQkJCNDc3MjBGMzYiIHhtcE1NOkluc3RhbmNlSUQ9InhtcC5paWQ6MzhBN0E4QzE3NjUyMTFFNkJBMTdEQkJCNDc3MjBGMzYiIHhtcDpDcmVhdG9yVG9vbD0iQWRvYmUgUGhvdG9zaG9wIENDIChXaW5kb3dzKSI+IDx4bXBNTTpEZXJpdmVkRnJvbSBzdFJlZjppbnN0YW5jZUlEPSJ4bXAuaWlkOmEyYzQ0Nzc2LTM1NWEtNGM0NS04MzYzLTQ3YTY5MjQ4ZTE5NyIgc3RSZWY6ZG9jdW1lbnRJRD0ieG1wLmRpZDo1MzRkZTM1My01Y2EzLTM3NGMtOWYwMy00OWFjNjc2ZWQ0ZTQiLz4gPC9yZGY6RGVzY3JpcHRpb24+IDwvcmRmOlJERj4gPC94OnhtcG1ldGE+IDw/eHBhY2tldCBlbmQ9InIiPz7J7FnQAAABuklEQVR42qxWSZLEMAiDecT8v/o58yn1qWtSNIuEnZsTwiKEjNvr79f+H7fvx4kzHu9d/D97r/h4xv+8j+ennT2+IfhTaqn+qb53cS3JdxPTmroZfFncneSDimtX/4SvH+Q9xe04VvXOCx4yOan4GumrqgcDFxVesjYbrk1z0vHMh1mdOKjq05QLgxOrtQyvXZw3u8AJFzTbiH5P+q5oyqlGdOcfUcdA8PpUn1jeqXZKnOwu7OpFwLK6s5l74GS/UO1sibst55nN9YMnDjFR9waGQzdqZfXWyN2t8r3JsbNBwf1pNwW5T6u92fqF6M+FnjA2SGxh3INQQzxntpl/NP6reD7kjiFvNn6Mw/hl8qveRZwQ+oeEOxNWHT7R77YvbB8mTEH4febM4MDWAqFGNDPAzEeX+ym+8XxSOxrsGaxwAc8MXxz0EZew6HoDceYhzhiaWL6sk+XZZmZAYsXgzM6e0hd2ftUcp3sBhI+O/5WmMDq74e5UV4aZ0idFG6tYJvZN7add0D917nFBq2yhnds7Vr0XFa3f4GwLjWXxd9P2jg2/XMwBw840aYAf5MfaTlqVfad2x7cAAwBq2FKRj67KIAAAAABJRU5ErkJggg=="> </img></div> <div class="host-info"> <span>您的IP:<span id="ip">182.16.101.164</span></span> <span class="host-info-mar">云节点:<span id="cloud_node">115.231.230.191</span></span>
<br><br> <span>RequestID: <span id="request_id">a26c425003b289be20b679d9c39785b5</span></span>
</br></br></div> </div></div>
<script src="/static/js/sys_infomation_count_9027952d6c0c3359ca5b8b1.js"></script>
<script language="javascript">
var fp = new Fingerprint2();
fp.get(function(result) {
    var src2= '/yd_http_error_upload/';
    var src3='info=c52f8e38722dd5a38f0b412ffd8f1e19181fd2f87c184737eabccd8e221eecb37f220bbb4a3d4c89f988ed272f6059cf87efe0b88a61fbaafc5ff63e833f4e4c835755adfac3344e360eebb7e71266bf681a782e1b512cbd7aa6bbb6804e57ece8fa0dea62078e9e879917b0664e23c5522c7b3b5374b68298c5c808c2145bbd&id=859294053c31ae7ef6d2e01344afe0f4&fingerprint=' + result;
    var xhr = null;
    if (window.XMLHttpRequest) xhr = new XMLHttpRequest();
    else xhr = new ActiveXObject('Microsoft.XMLHTTP');
    xhr.open('POST', src2, true);
    xhr.setRequestHeader("Content-type","application/x-www-form-urlencoded");
    xhr.send(src3);
});
</script>
</body>