如何用Python检测URL跳转?实现Odoo域名有效性精准判定
解决Odoo钓鱼网站检测中的跳转判断问题
我用Python开发了一款钓鱼网站搜索器,代码如下:
output = [] for i in range (100): for subdomain_count in [1, 2, 3, 4]: webtypo = random.choice(typo) + '.odoo.com' http = random.choice(HTTP) data = random.sample(web, k=subdomain_count) + [webtypo] delims = (random.choices(delimiters, k=subdomain_count) address = ''.join([a+b for a, b in zip(data, delims)]) weburl = http + address output.append(weburl) exist=[] for c in output: try: request = requests.get(c) if request.status_code == 200: exist.append(c) print('Exist') elif request.status_code == 204: print('user does not exist') except: print('Not Exist')
现在遇到的问题是:访问构造的链接时,请求URL会跳转到https://www.odoo.com/typo?domain=minecraftnet.odoo.com&autodbname=edcandroidbni123&hosting=eu142a。我希望实现:若检测到网站链接发生跳转(跳转到这类typo错误页面),则输出“web does not exist”;若为真正使用odoo.com顶级域名的有效站点,则输出“exist”。
解决思路
核心是识别请求是否跳转到了Odoo官方的typo错误页面,或跳转后的域名与原请求域名是否不一致。这里采用允许跳转+检查最终URL特征的方案,能更精准区分有效站点与错误跳转页。
修改后的代码
import requests from urllib.parse import urlparse # 假设已定义typo、HTTP、web、delimiters变量 output = [] for i in range(100): for subdomain_count in [1, 2, 3, 4]: webtypo = random.choice(typo) + '.odoo.com' http = random.choice(HTTP) data = random.sample(web, k=subdomain_count) + [webtypo] delims = random.choices(delimiters, k=subdomain_count) # 修复原代码括号语法错误 address = ''.join([a+b for a, b in zip(data, delims)]) weburl = http + address output.append(weburl) exist = [] for c in output: try: # 允许自动跳转,记录完整跳转链路 response = requests.get(c, allow_redirects=True) # 优先检查是否跳转到官方typo错误页 if '/typo?' in response.url: print('web does not exist') elif response.status_code == 200: # 二次验证:确保最终域名属于odoo.com子域 original_domain = urlparse(c).netloc final_domain = urlparse(response.url).netloc if original_domain.endswith('.odoo.com') and final_domain.endswith('.odoo.com'): exist.append(c) print('exist') else: print('web does not exist') elif response.status_code == 204: print('user does not exist') else: print('web does not exist') except requests.exceptions.RequestException: # 捕获所有请求类异常(如连接超时、DNS解析失败) print('web does not exist')
关键修改说明
- 修复语法错误:原代码中
delims行多了一个左括号,已修正。 - 跳转特征识别:通过
/typo?关键字直接定位官方错误跳转页。 - 域名一致性校验:对比原请求与最终跳转后的域名,确保有效站点确实在odoo.com子域下,避免误判。
- 异常处理优化:将宽泛的
except:改为捕获requests.exceptions.RequestException,避免捕获非请求类异常。
内容的提问来源于stack exchange,提问作者TheBotHunter
相关产品推荐
相关产品推荐

