dongshushen4392 2011-05-18 17:03
浏览 29
已采纳

文档片段出现在PHP脚本中的请求URL中

While logging HTTP requests to a file I have found something I would not expect.

I just put in the log the $_SERVER['REQUEST_URI'].

Guess what I have found, an url with #fragment attached:

18/05: requested cat/page.html#fragment

Note out of 2477 line of logs I found only one line with fragment attached

Everyone know (should) that fragment is never known server-side but only javascript code can get it. So what is happening here?

I am running PHP 5.3 on Apache 2.X (Debian).

  • 写回答

1条回答 默认 最新

  • dphs48626 2011-05-18 17:18
    关注

    Your assertion that "fragment is never known server-side but only javascript code can get it" is a little short-sighted.

    Whilst it's true that, in general operation with a conventional browser, a fragment is not included in the request-to-server, there is nothing stopping me from writing whatever I want in an HTTP request.

    echo "GET /lol/werent/expecting/this#were_you HTTP/1.1" > /dev/tcp/yourwebsite.com/80
    

    Someone's testing, someone's playing, someone's playing a bizarre hack attempt, or someone's using a buggy browser.

    I wouldn't worry about it.

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论

报告相同问题?

悬赏问题

  • ¥15 c语言怎么用printf(“\b \b”)与getch()实现黑框里写入与删除?
  • ¥20 怎么用dlib库的算法识别小麦病虫害
  • ¥15 华为ensp模拟器中S5700交换机在配置过程中老是反复重启
  • ¥15 java写代码遇到问题,求帮助
  • ¥15 uniapp uview http 如何实现统一的请求异常信息提示?
  • ¥15 有了解d3和topogram.js库的吗?有偿请教
  • ¥100 任意维数的K均值聚类
  • ¥15 stamps做sbas-insar,时序沉降图怎么画
  • ¥15 买了个传感器,根据商家发的代码和步骤使用但是代码报错了不会改,有没有人可以看看
  • ¥15 关于#Java#的问题,如何解决?