(以“== Objects == * cebiesign <pre> <object id="cebiesign" name="cebiesign" classid="clsid:f3e92562-1b4d-4bfa-b2d4-e9bcabe3b5a8" codebase="js/cebiesign.ocx#version=2,0,0...”为内容创建页面)
 
第143行: 第143行:
 
* username = 11111111
 
* username = 11111111
 
* password = 22222222
 
* password = 22222222
 +
 +
<source lang="xml">
 +
<entry method="POST" url="https://www.cebbank.com/per/perlogin1.do">
 +
    <timestart>2014-06-19T06:00:43.594Z</timestart>
 +
    <timeend>2014-06-19T06:00:44.064Z</timeend>
 +
    <duration>0.470 s</duration>
 +
    <processname>C:\Program Files\Internet Explorer\iexplore.exe</processname>
 +
    <result>200 OK</result>
 +
    <size>0</size>
 +
    <stage>REQUEST_CLOSE</stage>
 +
    <mimetype>text/html</mimetype>
 +
    <redirecturl/>
 +
    <requestCamefromCache>False</requestCamefromCache>
 +
    <responseCamefromCache>False</responseCamefromCache>
 +
    <requestobjectname>/per/perlogin1.do</requestobjectname>
 +
    <winet_sr_result>True</winet_sr_result>
 +
    <winet_sr_errormessage/>
 +
    <bodySize>9333</bodySize>
 +
    <Web_PageID>0</Web_PageID>
 +
    <PageTitle/>
 +
    <Socket_SendSize>0</Socket_SendSize>
 +
    <Socket_RecvSize>0</Socket_RecvSize>
 +
    <Starred>False</Starred>
 +
    <Comment/>
 +
    <headers>
 +
      <requestheaders>
 +
        <header>POST /per/perlogin1.do HTTP/1.1</header>
 +
        <header>Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-shockwave-flash, */*</header>
 +
        <header>Referer: https://www.cebbank.com/per/prePerlogin.do?_locale=zh_CN</header>
 +
        <header>Accept-Language: en-us</header>
 +
        <header>User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0)</header>
 +
        <header>Content-Type: application/x-www-form-urlencoded</header>
 +
        <header>Accept-Encoding: gzip, deflate</header>
 +
        <header>Host: www.cebbank.com</header>
 +
        <header>Connection: Keep-Alive</header>
 +
        <header>Cache-Control: no-cache</header>
 +
        <header>Cookie: WT_FPC=id=2b3fd12fcdda9131eb91403212946597:lv=1403212951284:ss=1403212946597; cebmemberbranchcode=3550; cebmemberbranchname=%u5317%u4EAC%u5206%u884C; PERJSESSIONID=t6m9Tv0cW5s9jN7JhXFLBhvsbwnG9h4gLn0pyqKgDp97tnNPxdpC!-2124310495; BIGipServerpool_eb_8005=2366482624.17695.0000</header>
 +
        <header>Content-Length: 388</header>
 +
      </requestheaders>
 +
      <responseheaders>
 +
        <header>HTTP/1.1 200 OK</header>
 +
        <header>Server: Sun-Java-System-Web-Server/7.0</header>
 +
        <header>Date: Thu, 19 Jun 2014 10:01:06 GMT</header>
 +
        <header>Cache-Control: no-cache</header>
 +
        <header>Date: Thu, 19 Jun 2014 09:59:58 GMT</header>
 +
        <header>Pragma: No-cache</header>
 +
        <header>Content-type: text/html; charset=gbk</header>
 +
        <header>Expires: Thu, 01 Jan 1970 00:00:00 GMT</header>
 +
        <header>Content-Language: zh-CN</header>
 +
        <header>X-Powered-By: Servlet/2.5 JSP/2.1</header>
 +
        <header>Connection: Keep-alive</header>
 +
        <header>Via: 1.1 AN-0001544151441131</header>
 +
        <header>Content-Length: 9333</header>
 +
      </responseheaders>
 +
    </headers>
 +
    <content>
 +
      <contentLength>9333</contentLength>
 +
      <mimetype>text/html</mimetype>
 +
   
 +
    </content>
 +
    <cookies>
 +
      <sent>
 +
        <cookie name=" WT_FPC">id=2b3fd12fcdda9131eb91403212946597:lv=1403212951284:ss=1403212946597</cookie>
 +
        <cookie name=" cebmemberbranchcode">3550</cookie>
 +
        <cookie name=" cebmemberbranchname">&#177;&#177;&#190;&#169;&#183;&#214;&#208;&#208;</cookie>
 +
        <cookie name=" PERJSESSIONID">t6m9Tv0cW5s9jN7JhXFLBhvsbwnG9h4gLn0pyqKgDp97tnNPxdpC!-2124310495</cookie>
 +
        <cookie name=" BIGipServerpool_eb_8005">2366482624.17695.0000</cookie>
 +
      </sent>
 +
      <received/>
 +
    </cookies>
 +
    <cache>
 +
      <BeforeRequest>
 +
        <UrlInCache>False</UrlInCache>
 +
      </BeforeRequest>
 +
      <AfterRequest>
 +
        <UrlInCache>False</UrlInCache>
 +
      </AfterRequest>
 +
    </cache>
 +
    <QueryString/>
 +
    <PostData>
 +
      <mimetype>application/x-www-form-urlencoded</mimetype>
 +
      <size>388</size>
 +
      <params>
 +
        <param name="_viewReferer">login/login01</param>
 +
        <param name="_locale">zh_CN</param>
 +
        <param name="version">20140529</param>
 +
        <param name="Password">XQn0aqYKjJeFutYuXaooFuDF7cAU7jAYd4lpIff/qaZOd1gElxbw/ChRmY1mipjeUlpO0lO8FHO13VaeEyaQf54np25wFo6X2t0LlAKKpruupbDHEWas3pVuajAXsuUqsyqSeDqNlsXpckRWdFBopnzoKuggcgkaMLXsyJtGLU8=</param>
 +
        <param name="ran">55924190</param>
 +
        <param name="TransName"/>
 +
        <param name="Plain"/>
 +
        <param name="Signature"/>
 +
        <param name="MerName"/>
 +
        <param name="TransType"/>
 +
        <param name="OperationNo"/>
 +
        <param name="MerDCFlag"/>
 +
        <param name="checkloginflag"/>
 +
        <param name="_tokenName">z90qww5h</param>
 +
        <param name="LoginName">11111111</param>
 +
      </params>
 +
 +
  </entry>
 +
</source>

2014年6月19日 (四) 10:56的版本

Objects

  • cebiesign
<object id="cebiesign" name="cebiesign" classid="clsid:f3e92562-1b4d-4bfa-b2d4-e9bcabe3b5a8" codebase="js/cebiesign.ocx#version=2,0,0,4" border="0">
 </object>
  • powercommit
<object id="powercommit" codebase="js/PowerEnter.CAB#version=1,0,0,72" classid="clsid:BEEE2807-1709-4184-A05D-1B2DE01EE4CF" style="width:0px;height:0px" height="0" width="0">
<param name="width" value="0">
<param name="height" value="0">
<param name="frameName" value="mainFrame">
</object>
  • powerpassword
<object id="powerpassword" codebase="js/PowerEnter.CAB#version=1,0,0,72" classid="clsid:614E58F9-74D0-4D7B-90E3-64A0F2AA73B4" style="width:186pxpx;height:23pxpx" height="23px" width="186px">
<param name="width" value="186px">
<param name="height" value="23px">
<param name="maxLength" value="20">
<param name="minLength" value="0">
<param name="maskChar" value="*">
<param name="backColor" value="#FFFFFF">
<param name="textColor" value="#000000">
<param name="borderColor" value="#7f9db9">
<param name="accepts" value="*">
<param name="msgBox" value="false">
<param name="fieldName" value="Password">
</object>

Commit Code

var blob ="BgIAAACkAABSU0ExAAQAAAEAAQAfFsbhRXwKJMLpsGExRSNaUxLZhaHvMp9ZJEgO2sa30lj6jc2BkNrF/35TKQuLphYVYwDLADdbRj23ChSzVWVmQwAs9CXrqR3tcYavKGsRBEeHEFctULIt6QFn/1Gz6F11k61K8G9yMXy9AGgN+pHum2X3EODpRJBFH9/w1VC+1w==";

	function doLogin() {
		var ran = "<random value>";
		if(ran != null && ran !="") {
			var random = parseFloat(ran)+1;
			document.form1.ran.value = random;
		} else {
			document.form1.ran.value = 0;
		}
		var powercommit = document.getElementById("powercommit");
		var powerpassword = document.getElementById("powerpassword");
		powercommit.reset();
		powerpassword.publicKeyBlob(blob);
		powerpassword.commit("powercommit");
		powercommit.submit("form1");
	}

Form Params

<form name="form1" action="perlogin1.do" method="post">
<input type="hidden" name="_viewReferer" value="login/login01" />
<input type="hidden" name="_locale" value="zh_CN" />
<input type="hidden" name="version" value="20140529" />
<input type="hidden" name="Password" />
<input type="hidden" name="ran" value="063319703" />
<input type="hidden" name="TransName" value="" />
<input type="hidden" name="Plain" value="" />
<input type="hidden" name="Signature" value="" />
<input type="hidden" name="MerName" value="" />
<input type="hidden" name="TransType" value="" />
<input type="hidden" name="OperationNo" value="" />
<input type="hidden" name="MerDCFlag" value="" />
<input type="hidden" name="checkloginflag" value="" />

<input type="hidden" name="_tokenName" value="1jjihb5u" />
<div class="box">
<!--头部-->
<div class=" head"><table cellpadding="0" cellspacing="0" border="0"    style="margin:10px 0;"><tr><td  align="left" ><img src="images/public/login_2.gif"  /></td>
 </tr>
    </table>
</div>
<!--头部结束-->
<!--内容-->
<div class="content">
<table cellpadding="0" cellspacing="0" border="0">
<tr> 
  <td class="conback" valign="top" >
	
  </td>
  <td class="conback2" valign="top" align="center">
  <!--登录区-->
  <table cellpadding="0" cellspacing="0" border="0" class="login" width="433">
  	<tr><td valign="top" class="title line01" align="left"><img src="images/public/yhdl.gif" width="120" height="22" />
	<object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="1" height="1" id="flash" align="middle">
	    <param name="allowScriptAccess" value="sameDomain"/>
	    <param name="movie" value="/per/bharosa_web/flash/bharosa.swf"/>
	    <param name="quality" value="low"/>
	    <param name="bgcolor" value="#ffffff"/>
	    <param name=FlashVars value="dcUrl=/dc?s=true&"/>
	    <embed src="/per/bharosa_web/flash/bharosa.swf" quality="low" bgcolor="#ffffff" FlashVars="dcUrl=/dc?s=true&" width="1" height="1"name="flash" align="middle" allowScriptAccess="sameDomain" type="application/x-shockwave-flash"/>
	</object>
</td></tr>
    <tr><td height="35" align="center">
    	
    </td></tr>
    <tr><td align="left">
       <table cellpadding="0" cellspacing="3" border="0" width="100%">
         <tr>
           <td class="size01 txt02" align="right" width="120">登录名或账号:&nbsp;&nbsp;</td>
           <td align="left" height="32" width="190"><input name="LoginName" id="skey" value=""  class="input_out3" 
           		onfocus="this.className='input_on3';this.onmouseout=''" onblur="this.className='input_off3';this.onmouseout=function(){this.className='input_out3'};" type="text" size="16" /></td>
           <td width="100">&nbsp;</td>
         </tr> 
         <tr>
           <td class="size01 txt02" align="right"  width="120">登录密码:<img src="images/public/wen.gif" alt="请输入您设置的8~14位网银登录密码"/></td>
           <td align="left" height="32">
           		<script type="text/javascript">writePassObject("powerpassword",{"fieldName":"Password","maxLength":"20","minLength":"0","width":"186px","height":"23px","msgBox":"false","maskChar":"*","borderColor":"#7f9db9"});</script>
           </td>
           <td align="left">
           		<a href="####" class="txt_line txt07" onclick="MM_openBrWindow('pwdHelp.do','个人网上银行常见问题解答','width=640,height=420')">密码输入帮助</a>
           		
          		
          		
                  <img id="image1" src="tokenImage.xx?_timesShowToken=2&ran=063319703" style="display:none"/>
                
           </td>
         </tr>
         
         <tr><td colspan="3" height="10"></td></tr>
         <tr><td colspan="3" align="center">
         <img src="images/public/denglu_1.gif"  onclick="doLogin();"  style="cursor: hand"/>&nbsp;&nbsp;&nbsp;&nbsp;
         </td></tr>
       </table>
    </td></tr>
    <tr><td height="23"></td></tr>
    <tr><td class="txt08" align="center"><a href="FP320501.do" class="txt07 txt_line">找回登录名</a> | <a href="FP320301.do" class="txt07 txt_line">忘记登录密码</a> | <a href="FP990101.do?ident=gr&idper=ds" class="txt07 txt_line">我要开通网银</a> </td></tr>
  </table>
  <!--登录区结束-->
  </td>
</tr>
</table>


</form>

Sample Form

  • username = 11111111
  • password = 22222222
<entry method="POST" url="https://www.cebbank.com/per/perlogin1.do">
    <timestart>2014-06-19T06:00:43.594Z</timestart>
    <timeend>2014-06-19T06:00:44.064Z</timeend>
    <duration>0.470 s</duration>
    <processname>C:\Program Files\Internet Explorer\iexplore.exe</processname>
    <result>200 OK</result>
    <size>0</size>
    <stage>REQUEST_CLOSE</stage>
    <mimetype>text/html</mimetype>
    <redirecturl/>
    <requestCamefromCache>False</requestCamefromCache>
    <responseCamefromCache>False</responseCamefromCache>
    <requestobjectname>/per/perlogin1.do</requestobjectname>
    <winet_sr_result>True</winet_sr_result>
    <winet_sr_errormessage/>
    <bodySize>9333</bodySize>
    <Web_PageID>0</Web_PageID>
    <PageTitle/>
    <Socket_SendSize>0</Socket_SendSize>
    <Socket_RecvSize>0</Socket_RecvSize>
    <Starred>False</Starred>
    <Comment/>
    <headers>
      <requestheaders>
        <header>POST /per/perlogin1.do HTTP/1.1</header>
        <header>Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-shockwave-flash, */*</header>
        <header>Referer: https://www.cebbank.com/per/prePerlogin.do?_locale=zh_CN</header>
        <header>Accept-Language: en-us</header>
        <header>User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0)</header>
        <header>Content-Type: application/x-www-form-urlencoded</header>
        <header>Accept-Encoding: gzip, deflate</header>
        <header>Host: www.cebbank.com</header>
        <header>Connection: Keep-Alive</header>
        <header>Cache-Control: no-cache</header>
        <header>Cookie: WT_FPC=id=2b3fd12fcdda9131eb91403212946597:lv=1403212951284:ss=1403212946597; cebmemberbranchcode=3550; cebmemberbranchname=%u5317%u4EAC%u5206%u884C; PERJSESSIONID=t6m9Tv0cW5s9jN7JhXFLBhvsbwnG9h4gLn0pyqKgDp97tnNPxdpC!-2124310495; BIGipServerpool_eb_8005=2366482624.17695.0000</header>
        <header>Content-Length: 388</header>
      </requestheaders>
      <responseheaders>
        <header>HTTP/1.1 200 OK</header>
        <header>Server: Sun-Java-System-Web-Server/7.0</header>
        <header>Date: Thu, 19 Jun 2014 10:01:06 GMT</header>
        <header>Cache-Control: no-cache</header>
        <header>Date: Thu, 19 Jun 2014 09:59:58 GMT</header>
        <header>Pragma: No-cache</header>
        <header>Content-type: text/html; charset=gbk</header>
        <header>Expires: Thu, 01 Jan 1970 00:00:00 GMT</header>
        <header>Content-Language: zh-CN</header>
        <header>X-Powered-By: Servlet/2.5 JSP/2.1</header>
        <header>Connection: Keep-alive</header>
        <header>Via: 1.1 AN-0001544151441131</header>
        <header>Content-Length: 9333</header>
      </responseheaders>
    </headers>
    <content>
      <contentLength>9333</contentLength>
      <mimetype>text/html</mimetype>
    
    </content>
    <cookies>
      <sent>
        <cookie name=" WT_FPC">id=2b3fd12fcdda9131eb91403212946597:lv=1403212951284:ss=1403212946597</cookie>
        <cookie name=" cebmemberbranchcode">3550</cookie>
        <cookie name=" cebmemberbranchname">&#177;&#177;&#190;&#169;&#183;&#214;&#208;&#208;</cookie>
        <cookie name=" PERJSESSIONID">t6m9Tv0cW5s9jN7JhXFLBhvsbwnG9h4gLn0pyqKgDp97tnNPxdpC!-2124310495</cookie>
        <cookie name=" BIGipServerpool_eb_8005">2366482624.17695.0000</cookie>
      </sent>
      <received/>
    </cookies>
    <cache>
      <BeforeRequest>
        <UrlInCache>False</UrlInCache>
      </BeforeRequest>
      <AfterRequest>
        <UrlInCache>False</UrlInCache>
      </AfterRequest>
    </cache>
    <QueryString/>
    <PostData>
      <mimetype>application/x-www-form-urlencoded</mimetype>
      <size>388</size>
      <params>
        <param name="_viewReferer">login/login01</param>
        <param name="_locale">zh_CN</param>
        <param name="version">20140529</param>
        <param name="Password">XQn0aqYKjJeFutYuXaooFuDF7cAU7jAYd4lpIff/qaZOd1gElxbw/ChRmY1mipjeUlpO0lO8FHO13VaeEyaQf54np25wFo6X2t0LlAKKpruupbDHEWas3pVuajAXsuUqsyqSeDqNlsXpckRWdFBopnzoKuggcgkaMLXsyJtGLU8=</param>
        <param name="ran">55924190</param>
        <param name="TransName"/>
        <param name="Plain"/>
        <param name="Signature"/>
        <param name="MerName"/>
        <param name="TransType"/>
        <param name="OperationNo"/>
        <param name="MerDCFlag"/>
        <param name="checkloginflag"/>
        <param name="_tokenName">z90qww5h</param>
        <param name="LoginName">11111111</param>
      </params>

  </entry>