{"id":65604,"date":"2026-01-25T13:04:47","date_gmt":"2026-01-25T05:04:47","guid":{"rendered":"https:\/\/www.wsisp.com\/helps\/65604.html"},"modified":"2026-01-25T13:04:47","modified_gmt":"2026-01-25T05:04:47","slug":"%e9%aa%8c%e8%af%81%e7%a0%81%e6%9c%ba%e5%88%b6%e7%9a%84%e5%ae%89%e5%85%a8%e6%80%a7%e6%b5%8b%e8%af%95%ef%bc%9a%e4%bb%8e%e9%80%bb%e8%be%91%e7%bc%ba%e9%99%b7%e5%88%b0ai%e5%af%b9%e6%8a%97%e7%9a%84%e5%85%a8","status":"publish","type":"post","link":"https:\/\/www.wsisp.com\/helps\/65604.html","title":{"rendered":"\u9a8c\u8bc1\u7801\u673a\u5236\u7684\u5b89\u5168\u6027\u6d4b\u8bd5\uff1a\u4ece\u903b\u8f91\u7f3a\u9677\u5230AI\u5bf9\u6297\u7684\u5168\u666f\u5256\u6790"},"content":{"rendered":"<p>\u7b2c\u4e00\u90e8\u5206&#xff1a;\u5f00\u7bc7\u660e\u4e49 \u2014\u2014 \u5b9a\u4e49\u3001\u4ef7\u503c\u4e0e\u76ee\u6807<\/p>\n<p>\u5728\u5f53\u4eca\u7684\u4e92\u8054\u7f51\u5b89\u5168\u4f53\u7cfb\u4e2d&#xff0c;\u9a8c\u8bc1\u7801 \u4f5c\u4e3a\u4e00\u79cd\u533a\u5206\u4eba\u7c7b\u7528\u6237\u4e0e\u81ea\u52a8\u5316\u7a0b\u5e8f\u7684\u56fe\u7075\u6d4b\u8bd5\u53d8\u4f53&#xff0c;\u5df2\u6210\u4e3a\u4fdd\u62a4Web\u5e94\u7528\u3001API\u63a5\u53e3\u548c\u5173\u952e\u4e1a\u52a1\u903b\u8f91\u7684\u7b2c\u4e00\u9053\u3001\u4e5f\u5f80\u5f80\u662f\u6700\u8106\u5f31\u7684\u4e00\u9053\u9632\u7ebf\u3002\u5b83\u6a2a\u8de8\u5728\u8eab\u4efd\u8ba4\u8bc1\u3001\u4ea4\u6613\u786e\u8ba4\u3001\u9632\u722c\u866b\u548c\u9632\u66b4\u529b\u7834\u89e3\u7b49\u591a\u4e2a\u5173\u952e\u5b89\u5168\u8282\u70b9\u4e0a\u3002\u56e0\u6b64&#xff0c;\u5bf9\u9a8c\u8bc1\u7801\u673a\u5236\u7684\u5b89\u5168\u6027\u8fdb\u884c\u8bc4\u4f30&#xff0c;\u4e0d\u518d\u662f\u6e17\u900f\u6d4b\u8bd5\u4e2d\u7684\u4e00\u4e2a\u53ef\u9009\u6b65\u9aa4&#xff0c;\u800c\u662f\u8bc4\u4f30\u76ee\u6807\u7cfb\u7edf\u6574\u4f53\u5b89\u5168\u6210\u719f\u5ea6\u7684\u6838\u5fc3\u8bd5\u91d1\u77f3\u3002\u4e00\u4e2a\u8bbe\u8ba1\u4e0d\u5f53\u6216\u5b9e\u73b0\u6709\u8bef\u7684\u9a8c\u8bc1\u7801&#xff0c;\u5176\u5371\u5bb3\u6027\u4e0d\u4e9a\u4e8e\u4e00\u4e2a\u9ad8\u5371\u7684SQL\u6ce8\u5165\u6f0f\u6d1e&#xff0c;\u56e0\u4e3a\u5b83\u53ef\u80fd\u76f4\u63a5\u5bfc\u81f4\u8d26\u6237\u88ab\u6279\u91cf\u7834\u89e3\u3001\u4e1a\u52a1\u8d44\u6e90\u88ab\u6076\u610f\u8017\u5c3d\u6216\u654f\u611f\u6570\u636e\u88ab\u81ea\u52a8\u5316\u722c\u53d6\u3002<\/p>\n<p>\u7ad9\u5728\u201c\u6559\u80b2\u8005\u201d\u548c\u201c\u5b9e\u6218\u8005\u201d\u7684\u89d2\u5ea6&#xff0c;\u672c\u6587\u65e8\u5728\u5c06\u9a8c\u8bc1\u7801\u5b89\u5168\u6d4b\u8bd5\u8fd9\u4e00\u770b\u4f3c\u7410\u788e\u3001\u5b9e\u5219\u6df1\u9083\u7684\u9886\u57df&#xff0c;\u8fdb\u884c\u7cfb\u7edf\u6027\u89e3\u6784\u3002\u6211\u4eec\u5c06\u4ece\u9a8c\u8bc1\u7801\u8bbe\u8ba1\u7684\u6839\u672c\u76ee\u6807\u51fa\u53d1&#xff0c;\u9010\u5c42\u5256\u6790\u5176\u53ef\u80fd\u5931\u6548\u7684\u6bcf\u4e00\u4e2a\u73af\u8282&#xff0c;\u5e76\u63d0\u4f9b\u4ece\u624b\u52a8\u5206\u6790\u5230\u81ea\u52a8\u5316\u5bf9\u6297\u7684\u5b8c\u6574\u65b9\u6cd5\u8bba\u3002\u65e0\u8bba\u60a8\u662f\u521d\u6d89\u5b89\u5168\u7684\u65b0\u4eba&#xff0c;\u8fd8\u662f\u7ecf\u9a8c\u4e30\u5bcc\u7684\u5de5\u7a0b\u5e08&#xff0c;\u672c\u6587\u90fd\u5c06\u4e3a\u60a8\u63d0\u4f9b\u4e00\u4e2a\u6e05\u6670\u3001\u53ef\u590d\u7528\u7684\u77e5\u8bc6\u6846\u67b6\u3002<\/p>\n<p>\u5b66\u4e60\u76ee\u6807<\/p>\n<p>\u8bfb\u5b8c\u672c\u6587&#xff0c;\u4f60\u5c06\u80fd\u591f&#xff1a;<\/p>\n<li>\u9610\u8ff0\u9a8c\u8bc1\u7801\u7684\u6838\u5fc3\u8bbe\u8ba1\u76ee\u6807\u3001\u5206\u7c7b\u53ca\u5176\u5728\u5b89\u5168\u67b6\u6784\u4e2d\u7684\u6218\u7565\u4ef7\u503c\u3002<\/li>\n<li>\u7cfb\u7edf\u5316\u5730\u5206\u6790\u4e0e\u6d4b\u8bd5\u5404\u7c7b\u9a8c\u8bc1\u7801&#xff08;\u56fe\u5f62\u3001\u6ed1\u52a8\u3001\u70b9\u9009\u3001\u77ed\u4fe1\/\u90ae\u4ef6\u3001\u884c\u4e3a&#xff09;\u7684\u903b\u8f91\u7f3a\u9677\u4e0e\u5b9e\u73b0\u6f0f\u6d1e\u3002<\/li>\n<li>\u8fd0\u7528\u4e0e\u7ec4\u5408\u591a\u79cd\u6280\u672f\u5de5\u5177&#xff08;\u4eceBurp Suite\u5230\u6df1\u5ea6\u5b66\u4e60\u6846\u67b6&#xff09;\u8fdb\u884c\u9a8c\u8bc1\u7801\u7684\u8bc6\u522b\u3001\u7ed5\u8fc7\u6216\u964d\u7ea7\u653b\u51fb\u3002<\/li>\n<li>\u8bbe\u8ba1\u5e76\u5b9e\u65bd\u517c\u987e\u5b89\u5168\u6027\u4e0e\u7528\u6237\u4f53\u9a8c\u7684\u9a8c\u8bc1\u7801\u9632\u5fa1\u65b9\u6848&#xff0c;\u5e76\u7406\u89e3\u5176\u80cc\u540e\u7684\u5b89\u5168\u539f\u7406\u3002<\/li>\n<li>\u5efa\u7acb\u9a8c\u8bc1\u7801\u5b89\u5168\u4e0e\u81ea\u52a8\u5316\u653b\u51fb\u3001\u4e1a\u52a1\u5b89\u5168\u3001AI\u5b89\u5168\u7b49\u66f4\u5e7f\u6cdb\u9886\u57df\u7684\u77e5\u8bc6\u8fde\u63a5\u3002<\/li>\n<p>\u524d\u7f6e\u77e5\u8bc6<\/p>\n<p>\u00b7 \u57fa\u7840\u7684Web\u6e17\u900f\u6d4b\u8bd5\u6982\u5ff5&#xff1a;\u4e86\u89e3HTTP\/HTTPS\u534f\u8bae\u3001Cookie\u3001Session\u3001\u5e38\u89c1Web\u6f0f\u6d1e&#xff08;\u5982\u903b\u8f91\u6f0f\u6d1e&#xff09;\u3002 \u00b7 Burp Suite\u7684\u4f7f\u7528&#xff1a;\u5177\u5907\u4f7f\u7528\u4ee3\u7406\u8fdb\u884c\u8bf7\u6c42\/\u54cd\u5e94\u62e6\u622a\u4e0e\u91cd\u653e\u7684\u57fa\u672c\u80fd\u529b\u3002 \u00b7 \u57fa\u7840\u7684\u7f16\u7a0b\u80fd\u529b&#xff08;Python&#xff09;&#xff1a;\u80fd\u591f\u7406\u89e3\u5e76\u8fd0\u884c\u63d0\u4f9b\u7684\u811a\u672c\u7247\u6bb5\u3002<\/p>\n<hr \/>\n<p>\u7b2c\u4e8c\u90e8\u5206&#xff1a;\u539f\u7406\u6df1\u6398 \u2014\u2014 \u4ece\u201c\u662f\u4ec0\u4e48\u201d\u5230\u201c\u4e3a\u4ec0\u4e48\u201d<\/p>\n<p>\u6838\u5fc3\u5b9a\u4e49\u4e0e\u7c7b\u6bd4<\/p>\n<p>\u9a8c\u8bc1\u7801 \u662f\u4e00\u79cd\u5168\u81ea\u52a8\u7684\u3001\u516c\u5f00\u7684\u56fe\u7075\u6d4b\u8bd5&#xff0c;\u7528\u4e8e\u533a\u5206\u8ba1\u7b97\u673a\u548c\u4eba\u7c7b\u3002\u5176\u6838\u5fc3\u76ee\u7684\u662f\u589e\u52a0\u81ea\u52a8\u5316\u653b\u51fb\u7684\u6210\u672c&#xff0c;\u65e0\u8bba\u662f\u6210\u672c&#xff08;\u65f6\u95f4\u3001\u8d44\u6e90&#xff09;\u8fd8\u662f\u6280\u672f\u590d\u6742\u5ea6&#xff0c;\u4f7f\u5176\u53d8\u5f97\u4e0d\u7ecf\u6d4e\u6216\u4e0d\u5207\u5b9e\u9645\u3002<\/p>\n<p>\u4e00\u4e2a\u8d34\u5207\u7684\u6bd4\u55bb\u662f&#xff1a;\u9a8c\u8bc1\u7801\u5982\u540c\u4e00\u4e2a\u5b88\u95e8\u4eba\u3002\u4e00\u4e2a\u7406\u60f3\u7684\u5b88\u95e8\u4eba\u5e94\u8be5\u80fd\u51c6\u786e\u3001\u8fc5\u901f\u5730\u5206\u8fa8\u51fa\u201c\u771f\u6b63\u60f3\u8fdb\u95e8\u7684\u5ba2\u4eba\u201d&#xff08;\u4eba\u7c7b\u7528\u6237&#xff09;\u548c\u201c\u4f01\u56fe\u4f2a\u88c5\u6f5c\u5165\u7684\u673a\u5668\u4eba\u201d&#xff08;\u81ea\u52a8\u5316\u811a\u672c&#xff09;\u3002\u7136\u800c&#xff0c;\u73b0\u5b9e\u4e2d\u5b88\u95e8\u4eba\u53ef\u80fd\u60a3\u6709\u201c\u8138\u76f2\u75c7\u201d&#xff08;\u8bc6\u522b\u7b97\u6cd5\u7f3a\u9677&#xff09;\u3001\u9075\u5faa\u201c\u6b7b\u677f\u89c4\u5219\u201d&#xff08;\u903b\u8f91\u7f3a\u9677&#xff09;\u3001\u6216\u8005\u53ef\u4ee5\u88ab\u201c\u4f2a\u9020\u7684\u901a\u884c\u8bc1\u201d&#xff08;\u81ea\u52a8\u5316\u8bc6\u522b&#xff09;\u6240\u6b3a\u9a97\u3002<\/p>\n<p>\u6839\u672c\u539f\u56e0\u5206\u6790&#xff1a;\u9a8c\u8bc1\u7801\u4e3a\u4f55\u4f1a\u88ab\u7ed5\u8fc7&#xff1f;<\/p>\n<p>\u9a8c\u8bc1\u7801\u5b89\u5168\u95ee\u9898\u5e76\u975e\u6e90\u4e8e\u5355\u4e00\u539f\u56e0&#xff0c;\u800c\u662f\u8bbe\u8ba1\u3001\u5b9e\u73b0\u4e0e\u8fd0\u7ef4\u591a\u4e2a\u5c42\u9762\u7f3a\u9677\u7684\u805a\u5408\u3002\u5176\u6839\u672c\u539f\u56e0\u53ef\u5f52\u7ed3\u4e3a\u4ee5\u4e0b\u51e0\u70b9&#xff1a;<\/p>\n<li>\u5b89\u5168\u6027\u4e0e\u53ef\u7528\u6027\u7684\u6c38\u6052\u77db\u76fe&#xff1a; \u00b7 \u8bbe\u8ba1\u521d\u8877&#xff1a;\u63d0\u9ad8\u81ea\u52a8\u5316\u653b\u51fb\u7684\u6210\u672c\u3002 \u00b7 \u73b0\u5b9e\u51b2\u7a81&#xff1a;\u8fc7\u4e8e\u590d\u6742&#xff08;\u5982\u626d\u66f2\u4e25\u91cd\u7684\u6587\u5b57\u3001\u591a\u6b65\u903b\u8f91&#xff09;\u4f1a\u4f24\u5bb3\u771f\u5b9e\u7528\u6237\u7684\u4f53\u9a8c&#xff0c;\u5bfc\u81f4\u6d41\u5931&#xff1b;\u8fc7\u4e8e\u7b80\u5355\u5219\u5bb9\u6613\u88ab\u81ea\u52a8\u5316\u7834\u89e3\u3002\u8fd9\u4e2a\u5e73\u8861\u70b9\u59cb\u7ec8\u5728\u52a8\u6001\u53d8\u5316\u3002<\/li>\n<li>\u903b\u8f91\u4e0e\u4e1a\u52a1\u6d41\u7684\u5206\u79bb&#xff1a; \u8bb8\u591a\u5f00\u53d1\u4eba\u5458\u9519\u8bef\u5730\u5c06\u201c\u5c55\u793a\u9a8c\u8bc1\u7801\u201d\u4e0e\u201c\u9a8c\u8bc1\u7ed3\u679c\u201d\u89c6\u4e3a\u4e24\u4e2a\u72ec\u7acb\u7684\u6b65\u9aa4&#xff0c;\u800c\u5ffd\u7565\u4e86\u5b83\u4eec\u5fc5\u987b\u5728\u4e00\u4e2a\u6709\u72b6\u6001\u7684\u3001\u53d7\u4fdd\u62a4\u7684\u4f1a\u8bdd\u4e2d\u5f3a\u7ed1\u5b9a\u3002\u8fd9\u5bfc\u81f4\u4e86\u5927\u91cf\u7684\u903b\u8f91\u6f0f\u6d1e&#xff0c;\u5982\u9a8c\u8bc1\u7801\u53ef\u91cd\u590d\u4f7f\u7528\u3001\u9a8c\u8bc1\u73af\u8282\u53ef\u7ed5\u8fc7\u3001\u9a8c\u8bc1\u7ed3\u679c\u524d\u7aef\u53ef\u7be1\u6539\u7b49\u3002<\/li>\n<li>\u6280\u672f\u5b9e\u73b0\u7684\u900f\u660e\u6027&#xff1a; \u5927\u90e8\u5206\u9a8c\u8bc1\u7801\u7684\u751f\u6210\u3001\u4f20\u9012\u548c\u9a8c\u8bc1\u903b\u8f91\u90fd\u8fd0\u884c\u5728\u5ba2\u6237\u7aef\u6216\u524d\u540e\u7aef\u4ea4\u4e92\u7684\u660e\u6587\u4e2d\u3002\u653b\u51fb\u8005\u53ef\u4ee5\u89c2\u5bdf\u8bf7\u6c42\/\u54cd\u5e94\u3001\u5206\u6790\u524d\u7aefJavaScript\u3001\u751a\u81f3\u76f4\u63a5\u8c03\u7528\u9a8c\u8bc1\u63a5\u53e3\u3002\u8fd9\u79cd\u900f\u660e\u6027\u4e3a\u9006\u5411\u5de5\u7a0b\u548c\u6f0f\u6d1e\u53d1\u73b0\u63d0\u4f9b\u4e86\u53ef\u80fd\u3002<\/li>\n<li>\u201cAI-\u5b89\u5168\u201d\u7684\u519b\u5907\u7ade\u8d5b&#xff1a; \u968f\u7740\u673a\u5668\u5b66\u4e60&#xff08;\u5c24\u5176\u662f\u6df1\u5ea6\u5b66\u4e60&#xff09;\u5728\u56fe\u50cf\u3001\u8bed\u97f3\u8bc6\u522b\u9886\u57df\u7684\u7a81\u7834&#xff0c;\u4f20\u7edf\u57fa\u4e8e\u201c\u4eba\u7c7b\u6613\u8bc6\u522b\u3001\u673a\u5668\u96be\u8bc6\u522b\u201d\u5047\u8bbe\u7684\u9a8c\u8bc1\u7801&#xff08;\u5982\u626d\u66f2\u6587\u5b57&#xff09;\u5df2\u57fa\u672c\u5931\u6548\u3002\u9632\u5fa1\u65b9\u5fc5\u987b\u4e0d\u65ad\u5347\u7ea7\u9a8c\u8bc1\u7801\u7684\u201c\u6297AI\u201d\u7279\u6027&#xff08;\u5982\u52a8\u6001\u6df7\u6dc6\u3001\u884c\u4e3a\u8f68\u8ff9&#xff09;&#xff0c;\u800c\u653b\u51fb\u65b9\u5219\u540c\u6b65\u8fdb\u5316\u5176\u81ea\u52a8\u5316\u8bc6\u522b\u80fd\u529b\u3002<\/li>\n<p>\u53ef\u89c6\u5316\u6838\u5fc3\u673a\u5236&#xff1a;\u9a8c\u8bc1\u7801\u7cfb\u7edf\u7684\u5bf9\u6297\u9762<\/p>\n<p>\u4e0b\u56fe\u63cf\u7ed8\u4e86\u4e00\u4e2a\u5178\u578b\u9a8c\u8bc1\u7801\u7cfb\u7edf\u7684\u5de5\u4f5c\u6d41\u7a0b&#xff0c;\u5e76\u9ad8\u4eae\u4e86\u6bcf\u4e2a\u73af\u8282\u53ef\u80fd\u5b58\u5728\u7684\u653b\u51fb\u9762&#xff08;\u7ea2\u8272\u6807\u6ce8&#xff09;\u3002\u8fd9\u5f20\u56fe\u662f\u7406\u89e3\u540e\u7eed\u6240\u6709\u6d4b\u8bd5\u6848\u4f8b\u7684\u201c\u5bfc\u822a\u56fe\u201d\u3002<\/p>\n<p>  #mermaid-svg-pFL5YMQTZ9VHZI5D{font-family:\\&#8221;trebuchet ms\\&#8221;,verdana,arial,sans-serif;font-size:16px;fill:#333;}@keyframes edge-animation-frame{from{stroke-dashoffset:0;}}@keyframes dash{to{stroke-dashoffset:0;}}#mermaid-svg-pFL5YMQTZ9VHZI5D .edge-animation-slow{stroke-dasharray:9,5!important;stroke-dashoffset:900;animation:dash 50s linear infinite;stroke-linecap:round;}#mermaid-svg-pFL5YMQTZ9VHZI5D .edge-animation-fast{stroke-dasharray:9,5!important;stroke-dashoffset:900;animation:dash 20s linear infinite;stroke-linecap:round;}#mermaid-svg-pFL5YMQTZ9VHZI5D .error-icon{fill:#552222;}#mermaid-svg-pFL5YMQTZ9VHZI5D .error-text{fill:#552222;stroke:#552222;}#mermaid-svg-pFL5YMQTZ9VHZI5D .edge-thickness-normal{stroke-width:1px;}#mermaid-svg-pFL5YMQTZ9VHZI5D .edge-thickness-thick{stroke-width:3.5px;}#mermaid-svg-pFL5YMQTZ9VHZI5D .edge-pattern-solid{stroke-dasharray:0;}#mermaid-svg-pFL5YMQTZ9VHZI5D .edge-thickness-invisible{stroke-width:0;fill:none;}#mermaid-svg-pFL5YMQTZ9VHZI5D .edge-pattern-dashed{stroke-dasharray:3;}#mermaid-svg-pFL5YMQTZ9VHZI5D .edge-pattern-dotted{stroke-dasharray:2;}#mermaid-svg-pFL5YMQTZ9VHZI5D .marker{fill:#333333;stroke:#333333;}#mermaid-svg-pFL5YMQTZ9VHZI5D .marker.cross{stroke:#333333;}#mermaid-svg-pFL5YMQTZ9VHZI5D svg{font-family:\\&#8221;trebuchet ms\\&#8221;,verdana,arial,sans-serif;font-size:16px;}#mermaid-svg-pFL5YMQTZ9VHZI5D p{margin:0;}#mermaid-svg-pFL5YMQTZ9VHZI5D .label{font-family:\\&#8221;trebuchet ms\\&#8221;,verdana,arial,sans-serif;color:#333;}#mermaid-svg-pFL5YMQTZ9VHZI5D .cluster-label text{fill:#333;}#mermaid-svg-pFL5YMQTZ9VHZI5D .cluster-label span{color:#333;}#mermaid-svg-pFL5YMQTZ9VHZI5D .cluster-label span p{background-color:transparent;}#mermaid-svg-pFL5YMQTZ9VHZI5D .label text,#mermaid-svg-pFL5YMQTZ9VHZI5D span{fill:#333;color:#333;}#mermaid-svg-pFL5YMQTZ9VHZI5D .node rect,#mermaid-svg-pFL5YMQTZ9VHZI5D .node circle,#mermaid-svg-pFL5YMQTZ9VHZI5D .node ellipse,#mermaid-svg-pFL5YMQTZ9VHZI5D .node polygon,#mermaid-svg-pFL5YMQTZ9VHZI5D .node path{fill:#ECECFF;stroke:#9370DB;stroke-width:1px;}#mermaid-svg-pFL5YMQTZ9VHZI5D .rough-node .label text,#mermaid-svg-pFL5YMQTZ9VHZI5D .node .label text,#mermaid-svg-pFL5YMQTZ9VHZI5D .image-shape .label,#mermaid-svg-pFL5YMQTZ9VHZI5D .icon-shape .label{text-anchor:middle;}#mermaid-svg-pFL5YMQTZ9VHZI5D .node .katex path{fill:#000;stroke:#000;stroke-width:1px;}#mermaid-svg-pFL5YMQTZ9VHZI5D .rough-node .label,#mermaid-svg-pFL5YMQTZ9VHZI5D .node .label,#mermaid-svg-pFL5YMQTZ9VHZI5D .image-shape .label,#mermaid-svg-pFL5YMQTZ9VHZI5D .icon-shape .label{text-align:center;}#mermaid-svg-pFL5YMQTZ9VHZI5D .node.clickable{cursor:pointer;}#mermaid-svg-pFL5YMQTZ9VHZI5D .root .anchor path{fill:#333333!important;stroke-width:0;stroke:#333333;}#mermaid-svg-pFL5YMQTZ9VHZI5D .arrowheadPath{fill:#333333;}#mermaid-svg-pFL5YMQTZ9VHZI5D .edgePath .path{stroke:#333333;stroke-width:2.0px;}#mermaid-svg-pFL5YMQTZ9VHZI5D .flowchart-link{stroke:#333333;fill:none;}#mermaid-svg-pFL5YMQTZ9VHZI5D .edgeLabel{background-color:rgba(232,232,232, 0.8);text-align:center;}#mermaid-svg-pFL5YMQTZ9VHZI5D .edgeLabel p{background-color:rgba(232,232,232, 0.8);}#mermaid-svg-pFL5YMQTZ9VHZI5D .edgeLabel rect{opacity:0.5;background-color:rgba(232,232,232, 0.8);fill:rgba(232,232,232, 0.8);}#mermaid-svg-pFL5YMQTZ9VHZI5D .labelBkg{background-color:rgba(232, 232, 232, 0.5);}#mermaid-svg-pFL5YMQTZ9VHZI5D .cluster rect{fill:#ffffde;stroke:#aaaa33;stroke-width:1px;}#mermaid-svg-pFL5YMQTZ9VHZI5D .cluster text{fill:#333;}#mermaid-svg-pFL5YMQTZ9VHZI5D .cluster span{color:#333;}#mermaid-svg-pFL5YMQTZ9VHZI5D div.mermaidTooltip{position:absolute;text-align:center;max-width:200px;padding:2px;font-family:\\&#8221;trebuchet ms\\&#8221;,verdana,arial,sans-serif;font-size:12px;background:hsl(80, 100%, 96.2745098039%);border:1px solid #aaaa33;border-radius:2px;pointer-events:none;z-index:100;}#mermaid-svg-pFL5YMQTZ9VHZI5D .flowchartTitleText{text-anchor:middle;font-size:18px;fill:#333;}#mermaid-svg-pFL5YMQTZ9VHZI5D rect.text{fill:none;stroke-width:0;}#mermaid-svg-pFL5YMQTZ9VHZI5D .icon-shape,#mermaid-svg-pFL5YMQTZ9VHZI5D .image-shape{background-color:rgba(232,232,232, 0.8);text-align:center;}#mermaid-svg-pFL5YMQTZ9VHZI5D .icon-shape p,#mermaid-svg-pFL5YMQTZ9VHZI5D .image-shape p{background-color:rgba(232,232,232, 0.8);padding:2px;}#mermaid-svg-pFL5YMQTZ9VHZI5D .icon-shape rect,#mermaid-svg-pFL5YMQTZ9VHZI5D .image-shape rect{opacity:0.5;background-color:rgba(232,232,232, 0.8);fill:rgba(232,232,232, 0.8);}#mermaid-svg-pFL5YMQTZ9VHZI5D .label-icon{display:inline-block;height:1em;overflow:visible;vertical-align:-0.125em;}#mermaid-svg-pFL5YMQTZ9VHZI5D .node .label-icon path{fill:currentColor;stroke:revert;stroke-width:revert;}#mermaid-svg-pFL5YMQTZ9VHZI5D :root{&#8211;mermaid-font-family:\\&#8221;trebuchet ms\\&#8221;,verdana,arial,sans-serif;}<\/p>\n<p>         <span class=\"nodeLabel\"><\/p>\n<p>\u81ea\u52a8\u5316\u653b\u51fb\u94fe\u8def<\/p>\n<p><\/span><\/p>\n<p>         <span class=\"nodeLabel\"><\/p>\n<p>\u670d\u52a1\u5668\u7aef<\/p>\n<p><\/span><\/p>\n<p>         <span class=\"nodeLabel\"><\/p>\n<p>\u5ba2\u6237\u7aef (\u653b\u51fb\u8005\u89c6\u89d2)<\/p>\n<p><\/span><\/p>\n<p>         <span class=\"edgeLabel\"><\/span><\/p>\n<p>         <span class=\"edgeLabel\"><\/p>\n<p>\u653b\u51fb\u9762\u2460: \u9884\u6d4b\/\u679a\u4e3e<\/p>\n<p><\/span><\/p>\n<p>         <span class=\"edgeLabel\"><\/span><\/p>\n<p>         <span class=\"edgeLabel\"><\/p>\n<p>\u653b\u51fb\u9762\u2461: \u4fe1\u606f\u6cc4\u6f0f\u3001\u91cd\u653e<\/p>\n<p><\/span><\/p>\n<p>         <span class=\"edgeLabel\"><\/p>\n<p>\u653b\u51fb\u9762\u2462: \u524d\u7aef\u6821\u9a8c\u7ed5\u8fc7<\/p>\n<p><\/span><\/p>\n<p>         <span class=\"edgeLabel\"><\/span><\/p>\n<p>         <span class=\"edgeLabel\"><\/p>\n<p>\u653b\u51fb\u9762\u2463: \u5b58\u50a8\u7f3a\u9677\u3001\u8fc7\u671f\u7b56\u7565<\/p>\n<p><\/span><\/p>\n<p>         <span class=\"edgeLabel\"><\/span><\/p>\n<p>         <span class=\"edgeLabel\"><\/p>\n<p>\u653b\u51fb\u9762\u2464: \u903b\u8f91\u7f3a\u9677\u3001\u66b4\u529b\u7834\u89e3<\/p>\n<p><\/span><\/p>\n<p>         <span class=\"edgeLabel\"><\/p>\n<p>\u662f<\/p>\n<p><\/span><\/p>\n<p>         <span class=\"edgeLabel\"><\/p>\n<p>\u5426<\/p>\n<p><\/span><\/p>\n<p>         <span class=\"edgeLabel\"><\/p>\n<p>\u653b\u51fb\u9762\u2465: \u72b6\u6001\u4e0d\u540c\u6b65<\/p>\n<p><\/span><\/p>\n<p>         <span class=\"edgeLabel\"><\/p>\n<p>\u65c1\u8def\u653b\u51fb: OCR\u8bc6\u522b\u3001\u6df1\u5ea6\u5b66\u4e60\u63a8\u7406<\/p>\n<p><\/span><\/p>\n<p>         <span class=\"edgeLabel\"><\/p>\n<p>\u5229\u7528\u653b\u51fb: \u91cd\u653e\u8bf7\u6c42\u3001\u7be1\u6539\u6570\u636e\u3001\u8c03\u7528API<\/p>\n<p><\/span><\/p>\n<p>         <span class=\"edgeLabel\"><\/p>\n<p>\u6d41\u7a0b\u5206\u6790: \u903b\u8f91\u3001\u89c4\u5f8b\u3001\u67b6\u6784<\/p>\n<p><\/span><\/p>\n<p>         <span class=\"nodeLabel\"><\/p>\n<p>\u7528\u6237\u8bbf\u95ee\u9700\u8981\u9a8c\u8bc1\u7801\u7684\u9875\u9762<\/p>\n<p><\/span><\/p>\n<p>         <span class=\"nodeLabel\"><\/p>\n<p>\u524d\u7aef\u8bf7\u6c42\u83b7\u53d6\u9a8c\u8bc1\u7801<\/p>\n<p><\/span><\/p>\n<p>         <span class=\"nodeLabel\"><\/p>\n<p>\u670d\u52a1\u5668\u751f\u6210\u9a8c\u8bc1\u7801<\/p>\n<p><\/span><\/p>\n<p>         <span class=\"nodeLabel\"><\/p>\n<p>\u8fd4\u56de\u9a8c\u8bc1\u7801\u56fe\u7247\/Token\/\u53c2\u6570<\/p>\n<p><\/span><\/p>\n<p>         <span class=\"nodeLabel\"><\/p>\n<p>\u7528\u6237\u8f93\u5165\u9a8c\u8bc1\u7801<\/p>\n<p><\/span><\/p>\n<p>         <span class=\"nodeLabel\"><\/p>\n<p>\u63d0\u4ea4\u8868\u5355\u542b\u9a8c\u8bc1\u7801\u7b54\u6848<\/p>\n<p><\/span><\/p>\n<p>         <span class=\"nodeLabel\"><\/p>\n<p>\u5c06\u6b63\u786e\u7b54\u6848\u4e0eSession\/Key\u7ed1\u5b9a\u5e76\u5b58\u50a8<\/p>\n<p><\/span><\/p>\n<p>         <span class=\"nodeLabel\"><\/p>\n<p>\u540e\u7aef\u9a8c\u8bc1\u63d0\u4ea4\u7684\u7b54\u6848<\/p>\n<p><\/span><\/p>\n<p>         <span class=\"nodeLabel\"><\/p>\n<p>\u9a8c\u8bc1\u6210\u529f?<\/p>\n<p><\/span><\/p>\n<p>         <span class=\"nodeLabel\"><\/p>\n<p>\u6267\u884c\u540e\u7eed\u4e1a\u52a1\u903b\u8f91<\/p>\n<p><\/span><\/p>\n<p>         <span class=\"nodeLabel\"><\/p>\n<p>\u8fd4\u56de\u9519\u8bef\u53ef\u80fd\u5237\u65b0\u9a8c\u8bc1\u7801<\/p>\n<p><\/span><\/p>\n<p>         <span class=\"nodeLabel\"><\/p>\n<p>\u81ea\u52a8\u5316\u811a\u672c\/\u5de5\u5177<\/p>\n<p><\/span><\/p>\n<p>         <span class=\"nodeLabel\"><\/p>\n<p>\u653b\u51fb\u8005\u5927\u8111<\/p>\n<p><\/span><\/p>\n<p>         <span class=\"nodeLabel\"><\/p>\n<p>\u6574\u4e2a\u6d41\u7a0b<\/p>\n<p><\/span><\/p>\n<p>\u653b\u51fb\u9762\u89e3\u8bfb&#xff1a;<\/p>\n<p>\u00b7 \u2460 \u9884\u6d4b\/\u679a\u4e3e&#xff1a;\u9a8c\u8bc1\u7801\u662f\u5426\u53ef\u9884\u6d4b&#xff08;\u5982\u57fa\u4e8e\u65f6\u95f4\u6233&#xff09;&#xff1f;\u7b54\u6848\u7a7a\u95f4\u662f\u5426\u8fc7\u5c0f&#xff08;\u59824\u4f4d\u7eaf\u6570\u5b57&#xff09;&#xff1f; \u00b7 \u2461 \u4fe1\u606f\u6cc4\u6f0f\u4e0e\u91cd\u653e&#xff1a;\u9a8c\u8bc1\u7801\u7b54\u6848\u662f\u5426\u76f4\u63a5\u8fd4\u56de\u5728\u54cd\u5e94\u4e2d&#xff1f;\u9a8c\u8bc1\u7801\u56fe\u7247\/Token\u662f\u5426\u53ef\u88ab\u540c\u4e00\u4f1a\u8bdd\u591a\u6b21\u4f7f\u7528&#xff1f; \u00b7 \u2462 \u524d\u7aef\u6821\u9a8c\u7ed5\u8fc7&#xff1a;\u9a8c\u8bc1\u662f\u5426\u4ec5\u5728\u524d\u7aefJavaScript\u8fdb\u884c&#xff1f;\u63d0\u4ea4\u7684\u53c2\u6570\u540d\u662f\u5426\u53ef\u731c\u6d4b&#xff08;\u5982code\u3001captcha&#xff09;&#xff1f; \u00b7 \u2463 \u5b58\u50a8\u4e0e\u72b6\u6001\u7f3a\u9677&#xff1a;\u670d\u52a1\u5668\u5982\u4f55\u5b58\u50a8\u9884\u671f\u7b54\u6848&#xff1f;Session\u7ba1\u7406\u662f\u5426\u5b89\u5168&#xff1f;\u9a8c\u8bc1\u7801\u662f\u5426\u6c38\u4e0d\u5931\u6548\u6216\u8fc7\u65e9\u5931\u6548&#xff1f; \u00b7 \u2464 \u6838\u5fc3\u903b\u8f91\u7f3a\u9677&#xff1a;\u9a8c\u8bc1\u4e0e\u4e1a\u52a1\u6267\u884c\u662f\u5426\u539f\u5b50\u64cd\u4f5c&#xff1f;\u9a8c\u8bc1\u5931\u8d25\u540e&#xff0c;\u5df2\u6263\u51cf\u7684\u8d44\u6e90&#xff08;\u5982\u77ed\u4fe1\u6b21\u6570&#xff09;\u662f\u5426\u56de\u6eda&#xff1f; \u00b7 \u2465 \u72b6\u6001\u540c\u6b65\u95ee\u9898&#xff1a;\u9a8c\u8bc1\u5931\u8d25\u540e&#xff0c;\u65e7\u7684\u9a8c\u8bc1\u7801\u662f\u5426\u4f9d\u7136\u6709\u6548&#xff1f;\u5237\u65b0\u673a\u5236\u662f\u5426\u5b58\u5728\u7ade\u4e89\u6761\u4ef6&#xff1f;<\/p>\n<hr \/>\n<p>\u7b2c\u4e09\u90e8\u5206&#xff1a;\u5b9e\u6218\u6f14\u7ec3 \u2014\u2014 \u4ece\u201c\u4e3a\u4ec0\u4e48\u201d\u5230\u201c\u600e\u4e48\u505a\u201d<\/p>\n<p>\u73af\u5883\u4e0e\u5de5\u5177\u51c6\u5907<\/p>\n<p>\u6211\u4eec\u5c06\u5728\u4e00\u4e2a\u53ef\u63a7\u7684\u6388\u6743\u6d4b\u8bd5\u73af\u5883\u4e2d\u8fdb\u884c\u6f14\u793a\u3002\u672c\u73af\u5883\u96c6\u6210\u4e86\u591a\u79cd\u6709\u7f3a\u9677\u7684\u9a8c\u8bc1\u7801\u5b9e\u73b0\u3002<\/p>\n<p>\u6f14\u793a\u73af\u5883&#xff1a;<\/p>\n<p>\u00b7 \u76ee\u6807\u5e94\u7528&#xff1a;\u4e00\u4e2a\u4e13\u4e3a\u5b89\u5168\u6d4b\u8bd5\u8bbe\u8ba1\u7684\u8106\u5f31Web\u5e94\u7528 (\u4f8b\u5982&#xff1a; http:\/\/vuln-captcha-lab:8080)\u3002 \u00b7 \u6280\u672f\u6808&#xff1a;Spring Boot &#043; Thymeleaf&#xff0c; \u5305\u542b\u591a\u4e2a\u72ec\u7acb\u7684\u3001\u5b58\u5728\u4e0d\u540c\u6f0f\u6d1e\u7684\u9a8c\u8bc1\u7801\u793a\u4f8b\u7aef\u70b9\u3002<\/p>\n<p>\u6838\u5fc3\u5de5\u5177\u6e05\u5355&#xff1a;<\/p>\n<li>\u62e6\u622a\u4e0e\u91cd\u653e&#xff1a;Burp Suite Professional (Community\u7248\u4ea6\u53ef&#xff0c; \u4f46\u7f3a\u5c11Intruder\u7684\u67d0\u4e9b\u9ad8\u7ea7\u529f\u80fd)\u3002<\/li>\n<li>\u6d4f\u89c8\u5668\u4e0e\u5f00\u53d1\u8005\u5de5\u5177&#xff1a;Chrome \/ Firefox\u3002<\/li>\n<li>\u81ea\u52a8\u5316\u811a\u672c\u6846\u67b6&#xff1a;Python 3.8&#043;&#xff0c; \u914d\u5907\u4ee5\u4e0b\u5e93&#xff1a; \u00b7 requests \/ httpx: HTTP\u5ba2\u6237\u7aef\u3002 \u00b7 Pillow (PIL): \u56fe\u50cf\u5904\u7406\u3002 \u00b7 opencv-python (cv2) \/ numpy: \u8ba1\u7b97\u673a\u89c6\u89c9\u9884\u5904\u7406\u3002 \u00b7 pytesseract: Tesseract OCR\u5f15\u64ce\u7684Python\u5c01\u88c5&#xff08;\u7528\u4e8e\u4f20\u7edfOCR&#xff09;\u3002 \u00b7 selenium: \u6d4f\u89c8\u5668\u81ea\u52a8\u5316&#xff08;\u7528\u4e8e\u884c\u4e3a\u9a8c\u8bc1\u7801\u6a21\u62df&#xff09;\u3002 \u00b7 tensorflow \/ pytorch: \u6df1\u5ea6\u5b66\u4e60\u6846\u67b6&#xff08;\u7528\u4e8e\u8bad\u7ec3\u5b9a\u5236\u8bc6\u522b\u6a21\u578b&#xff0c; \u8fdb\u9636\u4f7f\u7528&#xff09;\u3002<\/li>\n<li>OCR\u5f15\u64ce&#xff1a;Tesseract OCR (\u9700\u5355\u72ec\u5b89\u88c5)\u3002<\/li>\n<li>\u6df1\u5ea6\u5b66\u4e60\u8bad\u7ec3\u73af\u5883&#xff08;\u53ef\u9009&#xff09;&#xff1a;\u914d\u5907GPU\u7684\u673a\u5668&#xff0c;\u7528\u4e8e\u8bad\u7ec3\u5b9a\u5236\u8bc6\u522b\u6a21\u578b\u3002<\/li>\n<p>\u6700\u5c0f\u5316\u5b9e\u9a8c\u73af\u5883\u642d\u5efa&#xff08;\u4f7f\u7528Docker&#xff09;&#xff1a;<\/p>\n<p><span class=\"token comment\"># docker-compose.yml<\/span><br \/>\n<span class=\"token key atrule\">version<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token string\">&#039;3.8&#039;<\/span><br \/>\n<span class=\"token key atrule\">services<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">vuln-captcha-lab<\/span><span class=\"token punctuation\">:<\/span><br \/>\n    <span class=\"token key atrule\">image<\/span><span class=\"token punctuation\">:<\/span> registry.cn<span class=\"token punctuation\">&#8211;<\/span>hangzhou.aliyuncs.com\/sec<span class=\"token punctuation\">&#8211;<\/span>lab\/vuln<span class=\"token punctuation\">&#8211;<\/span>captcha<span class=\"token punctuation\">&#8211;<\/span>demo<span class=\"token punctuation\">:<\/span>latest <span class=\"token comment\"># \u5047\u8bbe\u5b58\u5728\u6b64\u955c\u50cf<\/span><br \/>\n    <span class=\"token key atrule\">ports<\/span><span class=\"token punctuation\">:<\/span><br \/>\n      <span class=\"token punctuation\">&#8211;<\/span> <span class=\"token string\">&#034;8080:8080&#034;<\/span><br \/>\n    <span class=\"token key atrule\">environment<\/span><span class=\"token punctuation\">:<\/span><br \/>\n      <span class=\"token punctuation\">&#8211;<\/span> SPRING_PROFILES_ACTIVE&#061;test<br \/>\n    <span class=\"token key atrule\">networks<\/span><span class=\"token punctuation\">:<\/span><br \/>\n      <span class=\"token punctuation\">&#8211;<\/span> test<span class=\"token punctuation\">&#8211;<\/span>net<\/p>\n<p>  <span class=\"token key atrule\">burp<\/span><span class=\"token punctuation\">:<\/span><br \/>\n    <span class=\"token key atrule\">image<\/span><span class=\"token punctuation\">:<\/span> linuxkonsult\/kali<span class=\"token punctuation\">&#8211;<\/span>burpsuite<span class=\"token punctuation\">:<\/span>latest<br \/>\n    <span class=\"token key atrule\">privileged<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token boolean important\">true<\/span><br \/>\n    <span class=\"token key atrule\">networks<\/span><span class=\"token punctuation\">:<\/span><br \/>\n      <span class=\"token punctuation\">&#8211;<\/span> test<span class=\"token punctuation\">&#8211;<\/span>net<br \/>\n    <span class=\"token comment\"># \u901a\u8fc7VNC\u6216X11\u8f6c\u53d1\u8bbf\u95eeBurp\u754c\u9762<\/span><\/p>\n<p><span class=\"token key atrule\">networks<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token key atrule\">test-net<\/span><span class=\"token punctuation\">:<\/span><br \/>\n    <span class=\"token key atrule\">driver<\/span><span class=\"token punctuation\">:<\/span> bridge<\/p>\n<p>\u4f7f\u7528\u547d\u4ee4 docker-compose up -d \u542f\u52a8\u73af\u5883\u3002<\/p>\n<p>\u6807\u51c6\u64cd\u4f5c\u6d41\u7a0b<\/p>\n<p>\u9636\u6bb5\u4e00&#xff1a;\u4fe1\u606f\u6536\u96c6\u4e0e\u4fa6\u5bdf<\/p>\n<p>\u8bbf\u95ee\u76ee\u6807\u5e94\u7528&#xff0c; \u679a\u4e3e\u6240\u6709\u6d89\u53ca\u9a8c\u8bc1\u7801\u7684\u529f\u80fd\u70b9&#xff1a;\u767b\u5f55\u3001\u6ce8\u518c\u3001\u5bc6\u7801\u627e\u56de\u3001\u77ed\u4fe1\u53d1\u9001\u3001\u6295\u7968\u3001\u8bc4\u8bba\u7b49\u3002<\/p>\n<p>\u4f7f\u7528Burp Suite\u6293\u53d6\u4e00\u4e2a\u5178\u578b\u7684\u9a8c\u8bc1\u7801\u8bf7\u6c42\u6d41\u7a0b&#xff1a;<\/p>\n<li>\u62e6\u622a\u201c\u83b7\u53d6\u9a8c\u8bc1\u7801\u201d\u7684\u8bf7\u6c42&#xff08;\u5982 GET \/api\/captcha\/image&#xff09;\u3002<\/li>\n<li>\u62e6\u622a\u63d0\u4ea4\u9a8c\u8bc1\u7801\u7684\u8bf7\u6c42&#xff08;\u5982 POST \/login&#xff09;\u3002<\/li>\n<li>\u5206\u6790\u8bf7\u6c42\/\u54cd\u5e94\u4e2d\u7684\u5173\u952e\u53c2\u6570&#xff1a; \u00b7 Cookie \/ Session ID&#xff1a;\u9a8c\u8bc1\u7801\u662f\u5426\u4e0e\u7279\u5b9a\u4f1a\u8bdd\u7ed1\u5b9a&#xff1f; \u00b7 \u9a8c\u8bc1\u7801\u6807\u8bc6&#xff1a;\u662f\u5426\u5b58\u5728\u4e00\u4e2acaptchaId\u3001token\u6216key&#xff0c;\u5c06\u83b7\u53d6\u7684\u9a8c\u8bc1\u7801\u4e0e\u540e\u7eed\u9a8c\u8bc1\u5173\u8054&#xff1f; \u00b7 \u54cd\u5e94\u4f53&#xff1a;\u9a8c\u8bc1\u7801\u56fe\u7247\u662f\u76f4\u63a5\u8fd4\u56de\u4e8c\u8fdb\u5236\u6d41&#xff0c;\u8fd8\u662fBase64\u7f16\u7801&#xff1f;\u662f\u5426\u6709\u7b54\u6848\u76f4\u63a5\u6cc4\u9732\u5728JSON\u6216HTML\u6ce8\u91ca\u4e2d&#xff1f;&#xff08;\u8fd9\u662f\u5e38\u89c1\u4f4e\u7ea7\u9519\u8bef&#xff09;\u3002 \u00b7 \u8bf7\u6c42\u4f53&#xff1a;\u63d0\u4ea4\u9a8c\u8bc1\u7801\u65f6&#xff0c;\u53c2\u6570\u540d\u662f\u4ec0\u4e48&#xff1f;\u662fcaptcha\u3001verificationCode\u8fd8\u662f\u5176\u4ed6&#xff1f;<\/li>\n<p>\u9636\u6bb5\u4e8c&#xff1a;\u903b\u8f91\u4e0e\u4e1a\u52a1\u6d41\u5206\u6790<\/p>\n<p>\u8fd9\u662f\u6700\u6709\u6548\u7684\u7ed5\u8fc7\u624b\u6bb5&#xff0c;\u901a\u5e38\u4e0d\u4f9d\u8d56\u4e8e\u590d\u6742\u7684\u6280\u672f\u8bc6\u522b\u3002<\/p>\n<p>\u6d4b\u8bd5\u6848\u4f8b1&#xff1a;\u9a8c\u8bc1\u7801\u53ef\u91cd\u7528<\/p>\n<li>\u83b7\u53d6\u4e00\u4e2a\u9a8c\u8bc1\u7801&#xff0c; \u5047\u8bbe\u7b54\u6848\u4e3a1234\u3002<\/li>\n<li>\u4f7f\u7528Burp Repeater&#xff0c; \u75281234\u63d0\u4ea4\u7b2c\u4e00\u6b21\u767b\u5f55\u8bf7\u6c42&#xff0c; \u6210\u529f\u3002<\/li>\n<li>\u4e0d\u5237\u65b0\u9a8c\u8bc1\u7801&#xff0c; \u5728Repeater\u4e2d\u518d\u6b21\u53d1\u9001\u76f8\u540c\u7684\u767b\u5f55\u8bf7\u6c42&#xff08;Cookie\u548ccaptcha\u53c2\u6570\u4e0d\u53d8&#xff09;\u3002<\/li>\n<li>\u9884\u671f\u5b89\u5168\u7ed3\u679c&#xff1a;\u670d\u52a1\u5668\u5e94\u4f7f\u8be5\u9a8c\u8bc1\u7801\u7acb\u5373\u5931\u6548&#xff0c;\u8fd4\u56de\u9519\u8bef\u3002<\/li>\n<li>\u6f0f\u6d1e\u73b0\u8c61&#xff1a;\u7b2c\u4e8c\u6b21\u8bf7\u6c42\u4f9d\u7136\u6210\u529f&#xff0c;\u8bf4\u660e\u9a8c\u8bc1\u7801\u9a8c\u8bc1\u540e\u72b6\u6001\u672a\u66f4\u65b0&#xff0c;\u53ef\u88ab\u66b4\u529b\u7834\u89e3\u91cd\u590d\u4f7f\u7528\u3002<\/li>\n<p>\u6d4b\u8bd5\u6848\u4f8b2&#xff1a;\u9a8c\u8bc1\u73af\u8282\u7f3a\u5931\u6216\u53ef\u7ed5\u8fc7<\/p>\n<li>\u5728\u4e1a\u52a1\u6d41\u7a0b\u4e2d&#xff08;\u5982\u201c\u91cd\u7f6e\u5bc6\u7801\u201d&#xff09;&#xff0c; \u6b63\u5e38\u6d41\u7a0b\u662f&#xff1a;\u8f93\u5165\u90ae\u7bb1 -&gt; \u83b7\u53d6\u90ae\u4ef6\u9a8c\u8bc1\u7801 -&gt; \u8f93\u5165\u9a8c\u8bc1\u7801 -&gt; \u91cd\u7f6e\u5bc6\u7801\u3002<\/li>\n<li>\u4f7f\u7528Burp\u62e6\u622a\u201c\u8f93\u5165\u9a8c\u8bc1\u7801\u201d\u540e\u7684\u201c\u91cd\u7f6e\u5bc6\u7801\u201d\u8bf7\u6c42\u3002<\/li>\n<li>\u5c1d\u8bd5\u76f4\u63a5\u8df3\u8fc7\u201c\u8f93\u5165\u9a8c\u8bc1\u7801\u201d\u7684\u6b65\u9aa4&#xff0c; \u5bfb\u627e\u662f\u5426\u6709\u4e00\u4e2a\u72ec\u7acb\u7684API\u7aef\u70b9&#xff08;\u5982 POST \/resetPassword&#xff09;\u53ef\u4ee5\u76f4\u63a5\u8c03\u7528&#xff0c;\u4ec5\u51ed\u90ae\u7bb1\u6216Token\u5c31\u80fd\u91cd\u7f6e\u3002<\/li>\n<li>\u6216\u8005&#xff0c; \u5c1d\u8bd5\u5728\u63d0\u4ea4\u201c\u91cd\u7f6e\u5bc6\u7801\u201d\u8bf7\u6c42\u65f6&#xff0c; \u5220\u9664\u6216\u7f6e\u7a7acaptcha\u53c2\u6570&#xff0c; \u89c2\u5bdf\u670d\u52a1\u5668\u662f\u5426\u4f9d\u7136\u5904\u7406\u3002<\/li>\n<p>\u6d4b\u8bd5\u6848\u4f8b3&#xff1a;\u9a8c\u8bc1\u7801\u4e0e\u4e1a\u52a1\u64cd\u4f5c\u975e\u539f\u5b50\u6027<\/p>\n<li>\u5728\u201c\u77ed\u4fe1\u9a8c\u8bc1\u7801\u767b\u5f55\u201d\u573a\u666f&#xff0c; \u6b63\u5e38\u6d41\u7a0b&#xff1a;\u8f93\u5165\u624b\u673a\u53f7 -&gt; \u70b9\u51fb\u201c\u53d1\u9001\u9a8c\u8bc1\u7801\u201d -&gt; \u6536\u5230\u77ed\u4fe1 -&gt; \u8f93\u5165\u9a8c\u8bc1\u7801\u767b\u5f55\u3002<\/li>\n<li>\u62e6\u622a\u201c\u53d1\u9001\u9a8c\u8bc1\u7801\u201d\u8bf7\u6c42&#xff0c; \u4f7f\u7528Burp Intruder\u8fdb\u884c\u624b\u673a\u53f7\u679a\u4e3e\u8f70\u70b8\u3002<\/li>\n<li>\u6f0f\u6d1e\u73b0\u8c61&#xff1a;\u5373\u4f7f\u77ed\u4fe1\u63a5\u53e3\u53ef\u80fd\u6709\u9891\u7387\u9650\u5236&#xff0c;\u4f46\u653b\u51fb\u8005\u53ef\u4ee5\u904d\u5386\u4e00\u4e2a\u624b\u673a\u53f7\u6bb5&#xff08;\u598213800138000\u523013800138999&#xff09;&#xff0c;\u5bfc\u81f4\u5927\u91cf\u5783\u573e\u77ed\u4fe1\u3002<\/li>\n<li>\u6df1\u5165\u6d4b\u8bd5&#xff1a;\u5728\u53d1\u9001\u9a8c\u8bc1\u7801\u540e&#xff0c; \u4e0d\u8fdb\u884c\u767b\u5f55&#xff0c; \u89c2\u5bdf\u662f\u5426\u6709\u63a5\u53e3\u53ef\u4ee5\u91cd\u590d\u89e6\u53d1\u53d1\u9001&#xff08;\u5982\u201c\u91cd\u53d1\u9a8c\u8bc1\u7801\u201d\u6309\u94ae\u672a\u505a\u9650\u5236&#xff09;\u3002<\/li>\n<p>\u9636\u6bb5\u4e09&#xff1a;\u6280\u672f\u5b9e\u73b0\u5206\u6790<\/p>\n<p>\u5f53\u903b\u8f91\u5c42\u9762\u6ca1\u6709\u660e\u663e\u6f0f\u6d1e\u65f6&#xff0c;\u6211\u4eec\u9700\u8981\u5206\u6790\u9a8c\u8bc1\u7801\u672c\u8eab\u7684\u6280\u672f\u5b9e\u73b0\u3002<\/p>\n<p>\u6d4b\u8bd5\u6848\u4f8b4&#xff1a;\u7b80\u5355\u7684\u56fe\u5f62\u9a8c\u8bc1\u7801&#xff08;\u6570\u5b57\u3001\u5b57\u6bcd&#xff09;<\/p>\n<p>\u00b7 \u5de5\u5177&#xff1a;pytesseract (Tesseract OCR) \u00b7 \u6b65\u9aa4&#xff1a;<\/p>\n<li>\u81ea\u52a8\u5316\u8bf7\u6c42\u9a8c\u8bc1\u7801\u56fe\u7247\u5e76\u4fdd\u5b58\u3002<\/li>\n<li>\u4f7f\u7528PIL\/Pillow\u8fdb\u884c\u9884\u5904\u7406&#xff1a;\u7070\u5ea6\u5316\u3001\u4e8c\u503c\u5316\u3001\u964d\u566a\u3002<\/li>\n<p><span class=\"token comment\"># \u793a\u4f8b\u4ee3\u7801&#xff1a;\u7b80\u5355OCR\u8bc6\u522b\u9a8c\u8bc1\u7801<\/span><br \/>\n<span class=\"token keyword\">import<\/span> requests<br \/>\n<span class=\"token keyword\">from<\/span> PIL <span class=\"token keyword\">import<\/span> Image<span class=\"token punctuation\">,<\/span> ImageFilter<br \/>\n<span class=\"token keyword\">import<\/span> pytesseract<br \/>\n<span class=\"token keyword\">import<\/span> io<\/p>\n<p>session <span class=\"token operator\">&#061;<\/span> requests<span class=\"token punctuation\">.<\/span>Session<span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><br \/>\n<span class=\"token comment\"># 1. \u83b7\u53d6\u9a8c\u8bc1\u7801\u56fe\u7247<\/span><br \/>\ncaptcha_url <span class=\"token operator\">&#061;<\/span> <span class=\"token string\">&#034;http:\/\/vuln-captcha-lab:8080\/captcha\/simple&#034;<\/span><br \/>\nheaders <span class=\"token operator\">&#061;<\/span> <span class=\"token punctuation\">{<\/span><span class=\"token string\">&#039;User-Agent&#039;<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token string\">&#039;Mozilla\/5.0&#039;<\/span><span class=\"token punctuation\">}<\/span><br \/>\nresp <span class=\"token operator\">&#061;<\/span> session<span class=\"token punctuation\">.<\/span>get<span class=\"token punctuation\">(<\/span>captcha_url<span class=\"token punctuation\">,<\/span> headers<span class=\"token operator\">&#061;<\/span>headers<span class=\"token punctuation\">)<\/span><\/p>\n<p><span class=\"token comment\"># 2. \u9884\u5904\u7406\u56fe\u50cf<\/span><br \/>\nimage <span class=\"token operator\">&#061;<\/span> Image<span class=\"token punctuation\">.<\/span><span class=\"token builtin\">open<\/span><span class=\"token punctuation\">(<\/span>io<span class=\"token punctuation\">.<\/span>BytesIO<span class=\"token punctuation\">(<\/span>resp<span class=\"token punctuation\">.<\/span>content<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">.<\/span>convert<span class=\"token punctuation\">(<\/span><span class=\"token string\">&#039;L&#039;<\/span><span class=\"token punctuation\">)<\/span>  <span class=\"token comment\"># \u8f6c\u4e3a\u7070\u5ea6<\/span><br \/>\n<span class=\"token comment\"># \u4e8c\u503c\u5316 (\u9608\u503c\u53ef\u6839\u636e\u5b9e\u9645\u60c5\u51b5\u8c03\u6574)<\/span><br \/>\nthreshold <span class=\"token operator\">&#061;<\/span> <span class=\"token number\">150<\/span><br \/>\nimage <span class=\"token operator\">&#061;<\/span> image<span class=\"token punctuation\">.<\/span>point<span class=\"token punctuation\">(<\/span><span class=\"token keyword\">lambda<\/span> p<span class=\"token punctuation\">:<\/span> p <span class=\"token operator\">&gt;<\/span> threshold <span class=\"token keyword\">and<\/span> <span class=\"token number\">255<\/span><span class=\"token punctuation\">)<\/span><br \/>\n<span class=\"token comment\"># \u53ef\u9009&#xff1a;\u964d\u566a<\/span><br \/>\nimage <span class=\"token operator\">&#061;<\/span> image<span class=\"token punctuation\">.<\/span><span class=\"token builtin\">filter<\/span><span class=\"token punctuation\">(<\/span>ImageFilter<span class=\"token punctuation\">.<\/span>MedianFilter<span class=\"token punctuation\">(<\/span>size<span class=\"token operator\">&#061;<\/span><span class=\"token number\">3<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">)<\/span><\/p>\n<p><span class=\"token comment\"># 3. \u4f7f\u7528Tesseract\u8bc6\u522b<\/span><br \/>\n<span class=\"token comment\"># \u6ce8\u610f&#xff1a;\u9700\u5148\u5728\u7cfb\u7edf\u5b89\u88c5Tesseract-OCR&#xff0c;\u5e76\u53ef\u80fd\u9700\u8981\u6307\u5b9a\u8bed\u8a00\u5305(eng)<\/span><br \/>\ncustom_config <span class=\"token operator\">&#061;<\/span> <span class=\"token string\">r&#039;&#8211;oem 3 &#8211;psm 7 -c tessedit_char_whitelist&#061;ABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789&#039;<\/span><br \/>\ncaptcha_text <span class=\"token operator\">&#061;<\/span> pytesseract<span class=\"token punctuation\">.<\/span>image_to_string<span class=\"token punctuation\">(<\/span>image<span class=\"token punctuation\">,<\/span> config<span class=\"token operator\">&#061;<\/span>custom_config<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">.<\/span>strip<span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><br \/>\n<span class=\"token keyword\">print<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string-interpolation\"><span class=\"token string\">f&#034;\u8bc6\u522b\u7ed3\u679c: <\/span><span class=\"token interpolation\"><span class=\"token punctuation\">{<\/span>captcha_text<span class=\"token punctuation\">}<\/span><\/span><span class=\"token string\">&#034;<\/span><\/span><span class=\"token punctuation\">)<\/span><\/p>\n<p><span class=\"token comment\"># 4. \u4f7f\u7528\u8bc6\u522b\u7ed3\u679c\u53d1\u8d77\u8bf7\u6c42 (\u4f8b\u5982\u767b\u5f55)<\/span><br \/>\nlogin_url <span class=\"token operator\">&#061;<\/span> <span class=\"token string\">&#034;http:\/\/vuln-captcha-lab:8080\/login&#034;<\/span><br \/>\ndata <span class=\"token operator\">&#061;<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n    <span class=\"token string\">&#039;username&#039;<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token string\">&#039;test&#039;<\/span><span class=\"token punctuation\">,<\/span><br \/>\n    <span class=\"token string\">&#039;password&#039;<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token string\">&#039;test&#039;<\/span><span class=\"token punctuation\">,<\/span><br \/>\n    <span class=\"token string\">&#039;captcha&#039;<\/span><span class=\"token punctuation\">:<\/span> captcha_text<br \/>\n<span class=\"token punctuation\">}<\/span><br \/>\n<span class=\"token comment\"># \u6ce8\u610f&#xff1a;\u901a\u5e38\u9700\u8981\u643a\u5e26\u83b7\u53d6\u9a8c\u8bc1\u7801\u65f6\u7684Cookie (session\u5df2\u81ea\u52a8\u5904\u7406)<\/span><br \/>\nlogin_resp <span class=\"token operator\">&#061;<\/span> session<span class=\"token punctuation\">.<\/span>post<span class=\"token punctuation\">(<\/span>login_url<span class=\"token punctuation\">,<\/span> data<span class=\"token operator\">&#061;<\/span>data<span class=\"token punctuation\">)<\/span><br \/>\n<span class=\"token keyword\">print<\/span><span class=\"token punctuation\">(<\/span>login_resp<span class=\"token punctuation\">.<\/span>status_code<span class=\"token punctuation\">,<\/span> login_resp<span class=\"token punctuation\">.<\/span>text<span class=\"token punctuation\">[<\/span><span class=\"token punctuation\">:<\/span><span class=\"token number\">200<\/span><span class=\"token punctuation\">]<\/span><span class=\"token punctuation\">)<\/span><\/p>\n<p>\u7ed5\u8fc7\u4e0e\u8fdb\u5316&#xff1a;\u5982\u679c\u9a8c\u8bc1\u7801\u52a0\u5165\u4e86\u7b80\u5355\u7684\u5e72\u6270\u7ebf\u3001\u626d\u66f2&#xff0c; Tesseract\u53ef\u80fd\u5931\u8d25\u3002\u6b64\u65f6\u9700\u8981\u66f4\u590d\u6742\u7684\u9884\u5904\u7406&#xff08;\u5982\u4f7f\u7528OpenCV\u8fdb\u884c\u5f62\u6001\u5b66\u64cd\u4f5c\u53bb\u9664\u5e72\u6270\u7ebf&#xff09;\u6216\u8bad\u7ec3\u4e13\u5c5e\u7684\u8bc6\u522b\u6a21\u578b\u3002<\/p>\n<p>\u6d4b\u8bd5\u6848\u4f8b5&#xff1a;\u6ed1\u52a8\u62fc\u56fe\u9a8c\u8bc1\u7801<\/p>\n<p>\u00b7 \u539f\u7406&#xff1a;\u7f3a\u53e3\u4f4d\u7f6e\u56fa\u5b9a\u6216\u53ef\u8ba1\u7b97\u3002 \u00b7 \u6b65\u9aa4&#xff1a;<\/p>\n<li>\u5206\u522b\u83b7\u53d6\u5e26\u7f3a\u53e3\u7684\u80cc\u666f\u56fe\u548c\u5b8c\u6574\u7684\u6ed1\u5757\u56fe\u3002<\/li>\n<li>\u4f7f\u7528OpenCV\u7684\u6a21\u677f\u5339\u914d(cv2.matchTemplate)\u6216\u56fe\u50cf\u5dee\u5206\u6280\u672f&#xff0c; \u8ba1\u7b97\u51fa\u7f3a\u53e3\u7684\u4f4d\u7f6e\u3002<\/li>\n<li>\u751f\u6210\u6ed1\u52a8\u8f68\u8ff9&#xff08;\u53ef\u80fd\u9700\u6a21\u62df\u4eba\u7c7b\u52a0\u901f\u5ea6\u66f2\u7ebf\u4ee5\u5bf9\u6297\u524d\u7aef\u884c\u4e3a\u76d1\u6d4b&#xff09;\u3002<\/li>\n<li>\u63d0\u4ea4\u6ed1\u52a8\u8ddd\u79bbdistance\u53c2\u6570&#xff08;\u901a\u5e38\u4ee5\u50cf\u7d20\u4e3a\u5355\u4f4d&#xff09;\u3002<\/li>\n<p><span class=\"token comment\"># \u793a\u4f8b\u4ee3\u7801&#xff1a;\u8ba1\u7b97\u6ed1\u52a8\u7f3a\u53e3\u8ddd\u79bb (\u7b80\u5316\u7248)<\/span><br \/>\n<span class=\"token keyword\">import<\/span> cv2<br \/>\n<span class=\"token keyword\">import<\/span> numpy <span class=\"token keyword\">as<\/span> np<\/p>\n<p><span class=\"token keyword\">def<\/span> <span class=\"token function\">get_slide_distance<\/span><span class=\"token punctuation\">(<\/span>bg_path<span class=\"token punctuation\">,<\/span> slide_path<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">:<\/span><br \/>\n    <span class=\"token triple-quoted-string string\">&#034;&#034;&#034;\u8ba1\u7b97\u6ed1\u5757\u9700\u8981\u79fb\u52a8\u7684\u8ddd\u79bb&#034;&#034;&#034;<\/span><br \/>\n    bg_img <span class=\"token operator\">&#061;<\/span> cv2<span class=\"token punctuation\">.<\/span>imread<span class=\"token punctuation\">(<\/span>bg_path<span class=\"token punctuation\">,<\/span> <span class=\"token number\">0<\/span><span class=\"token punctuation\">)<\/span>  <span class=\"token comment\"># \u7070\u5ea6\u8bfb\u53d6\u80cc\u666f\u56fe<\/span><br \/>\n    slide_img <span class=\"token operator\">&#061;<\/span> cv2<span class=\"token punctuation\">.<\/span>imread<span class=\"token punctuation\">(<\/span>slide_path<span class=\"token punctuation\">,<\/span> <span class=\"token number\">0<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token comment\"># \u7070\u5ea6\u8bfb\u53d6\u6ed1\u5757\u56fe<\/span><\/p>\n<p>    <span class=\"token comment\"># \u4f7f\u7528\u6a21\u677f\u5339\u914d<\/span><br \/>\n    result <span class=\"token operator\">&#061;<\/span> cv2<span class=\"token punctuation\">.<\/span>matchTemplate<span class=\"token punctuation\">(<\/span>bg_img<span class=\"token punctuation\">,<\/span> slide_img<span class=\"token punctuation\">,<\/span> cv2<span class=\"token punctuation\">.<\/span>TM_CCOEFF_NORMED<span class=\"token punctuation\">)<\/span><br \/>\n    min_val<span class=\"token punctuation\">,<\/span> max_val<span class=\"token punctuation\">,<\/span> min_loc<span class=\"token punctuation\">,<\/span> max_loc <span class=\"token operator\">&#061;<\/span> cv2<span class=\"token punctuation\">.<\/span>minMaxLoc<span class=\"token punctuation\">(<\/span>result<span class=\"token punctuation\">)<\/span><br \/>\n    <span class=\"token comment\"># max_loc \u662f\u5339\u914d\u4f4d\u7f6e\u7684\u5de6\u4e0a\u89d2\u5750\u6807 (x, y)<\/span><br \/>\n    <span class=\"token keyword\">return<\/span> max_loc<span class=\"token punctuation\">[<\/span><span class=\"token number\">0<\/span><span class=\"token punctuation\">]<\/span>  <span class=\"token comment\"># \u8fd4\u56dex\u5750\u6807&#xff0c;\u5373\u8ddd\u79bb<\/span><\/p>\n<p><span class=\"token comment\"># \u81ea\u52a8\u5316\u4e0b\u8f7d\u56fe\u7247\u5e76\u8ba1\u7b97&#8230;<\/span><br \/>\ndistance <span class=\"token operator\">&#061;<\/span> get_slide_distance<span class=\"token punctuation\">(<\/span><span class=\"token string\">&#039;background.png&#039;<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token string\">&#039;slider.png&#039;<\/span><span class=\"token punctuation\">)<\/span><br \/>\n<span class=\"token keyword\">print<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string-interpolation\"><span class=\"token string\">f&#034;\u9700\u6ed1\u52a8\u8ddd\u79bb: <\/span><span class=\"token interpolation\"><span class=\"token punctuation\">{<\/span>distance<span class=\"token punctuation\">}<\/span><\/span><span class=\"token string\">px&#034;<\/span><\/span><span class=\"token punctuation\">)<\/span><\/p>\n<p>\u5bf9\u6297\u6027\u601d\u8003&#xff1a;\u9ad8\u7ea7\u7684\u6ed1\u52a8\u9a8c\u8bc1\u7801\u4f1a\u4f7f\u7528\u52a8\u6001\u6df7\u6dc6&#xff08;\u968f\u673a\u5e72\u6270\u5757&#xff09;\u3001\u80cc\u666f\u56fe\u4e0e\u6ed1\u5757\u56fe\u975e\u4e00\u4e00\u5bf9\u5e94\u3001\u6216\u8981\u6c42\u591a\u6b65\u6ed1\u52a8\u3002\u6b64\u65f6\u53ef\u80fd\u9700\u8981\u66f4\u590d\u6742\u7684\u56fe\u50cf\u7b97\u6cd5&#xff0c;\u751a\u81f3\u5f15\u5165\u6df1\u5ea6\u5b66\u4e60\u6765\u8bc6\u522b\u7f3a\u53e3\u7279\u5f81\u3002<\/p>\n<p>\u6d4b\u8bd5\u6848\u4f8b6&#xff1a;\u70b9\u9009\u9a8c\u8bc1\u7801&#xff08;\u5982\u201c\u8bf7\u70b9\u51fb\u56fe\u4e2d\u6240\u6709\u7684xx\u201d&#xff09;<\/p>\n<p>\u00b7 \u5de5\u5177&#xff1a;\u6df1\u5ea6\u5b66\u4e60&#xff08;\u76ee\u6807\u68c0\u6d4b\u6a21\u578b&#xff0c; \u5982YOLO, Faster R-CNN&#xff09;\u3002 \u00b7 \u6b65\u9aa4&#xff1a;<\/p>\n<li>\u6536\u96c6\u5927\u91cf\u8be5\u7ad9\u70b9\u7684\u70b9\u9009\u9a8c\u8bc1\u7801\u56fe\u7247&#xff0c;\u5e76\u8fdb\u884c\u4eba\u5de5\u6807\u6ce8&#xff08;\u8fb9\u754c\u6846\u548c\u7c7b\u522b&#xff09;\u3002<\/li>\n<li>\u4f7f\u7528TensorFlow\/PyTorch\u8bad\u7ec3\u4e00\u4e2a\u5b9a\u5236\u5316\u7684\u76ee\u6807\u68c0\u6d4b\u6a21\u578b\u3002<\/li>\n<li>\u5728\u751f\u4ea7\u73af\u5883\u4e2d&#xff0c;\u4f7f\u7528\u8be5\u6a21\u578b\u5bf9\u83b7\u53d6\u7684\u9a8c\u8bc1\u7801\u56fe\u7247\u8fdb\u884c\u63a8\u7406&#xff0c;\u83b7\u53d6\u9700\u8981\u70b9\u51fb\u7684\u5750\u6807\u5e8f\u5217\u3002<\/li>\n<li>\u5c06\u5750\u6807\u5e8f\u5217&#xff08;\u901a\u5e38\u9700\u8981\u8f6c\u6362\u6210\u76f8\u5bf9\u4e8e\u56fe\u7247\u7684\u767e\u5206\u6bd4\u6216\u7279\u5b9a\u683c\u5f0f&#xff09;\u63d0\u4ea4\u7ed9\u540e\u7aef\u3002 \u00b7 \u4ee3\u7801\u6846\u67b6\u793a\u610f&#xff08;\u8bad\u7ec3\u90e8\u5206&#xff09;&#xff1a;<\/li>\n<p><span class=\"token comment\"># \u8fd9\u662f\u4e00\u4e2a\u9ad8\u5ea6\u7b80\u5316\u7684\u793a\u610f&#xff0c;\u5b9e\u9645\u8bad\u7ec3\u9700\u5927\u91cf\u6570\u636e\u548c\u8c03\u53c2<\/span><br \/>\n<span class=\"token keyword\">import<\/span> tensorflow <span class=\"token keyword\">as<\/span> tf<br \/>\n<span class=\"token comment\"># \u4f7f\u7528 TensorFlow Object Detection API \u662f\u66f4\u5b9e\u9645\u7684\u9009\u62e9<\/span><br \/>\n<span class=\"token comment\"># \u5047\u8bbe\u6211\u4eec\u5df2\u7ecf\u6709\u4e86\u6807\u6ce8\u597d\u7684\u6570\u636e\u96c6 &#096;tfrecord&#096; \u6587\u4ef6<\/span><br \/>\n<span class=\"token comment\"># 1. \u9009\u62e9\u9884\u8bad\u7ec3\u6a21\u578b (\u5982 SSD MobileNet V2)<\/span><br \/>\n<span class=\"token comment\"># 2. \u914d\u7f6e pipeline.config \u6587\u4ef6&#xff0c;\u6307\u5b9a\u7c7b\u522b\u3001\u8def\u5f84\u7b49<\/span><br \/>\n<span class=\"token comment\"># 3. \u6267\u884c\u8bad\u7ec3\u547d\u4ee4&#xff08;\u901a\u5e38\u5728\u547d\u4ee4\u884c&#xff09;<\/span><br \/>\n<span class=\"token comment\"># !python model_main_tf2.py &#8211;model_dir&#061;my_model &#8211;pipeline_config_path&#061;pipeline.config<\/span><\/p>\n<p>\u8b66\u544a&#xff1a;\u6b64\u65b9\u6cd5\u9700\u8981\u5927\u91cf\u7684\u524d\u671f\u6570\u636e\u6536\u96c6\u548c\u6a21\u578b\u8bad\u7ec3\u5de5\u4f5c&#xff0c;\u5c5e\u4e8e\u9ad8\u7ea7\u6301\u7eed\u6027\u653b\u51fb\u7684\u8303\u7574\u3002\u9632\u5fa1\u65b9\u5e94\u5b9a\u671f\u66f4\u65b0\u9a8c\u8bc1\u7801\u7684\u56fe\u7247\u5e93\u548c\u8bc6\u522b\u7269\u79cd\u7c7b\u522b\u3002<\/p>\n<p>\u6d4b\u8bd5\u6848\u4f8b7&#xff1a;\u77ed\u4fe1\/\u90ae\u4ef6\u9a8c\u8bc1\u7801<\/p>\n<p>\u00b7 \u653b\u51fb\u9762&#xff1a;\u66b4\u7834\u3001\u9884\u6d4b\u3001\u6ee5\u7528\u3002 \u00b7 \u66b4\u7834\u6d4b\u8bd5&#xff1a;<\/p>\n<p><span class=\"token comment\"># \u4f7f\u7528Burp Intruder\u6216Python\u811a\u672c\u8fdb\u884c\u66b4\u529b\u7834\u89e3<\/span><br \/>\n<span class=\"token keyword\">import<\/span> requests<br \/>\n<span class=\"token keyword\">import<\/span> concurrent<span class=\"token punctuation\">.<\/span>futures<\/p>\n<p>base_url <span class=\"token operator\">&#061;<\/span> <span class=\"token string\">&#034;http:\/\/vuln-captcha-lab:8080\/verify-sms&#034;<\/span><br \/>\nphone <span class=\"token operator\">&#061;<\/span> <span class=\"token string\">&#034;13800138000&#034;<\/span><br \/>\n<span class=\"token comment\"># \u5047\u8bbe\u6211\u4eec\u77e5\u9053\u9a8c\u8bc1\u7801\u662f6\u4f4d\u6570\u5b57<\/span><br \/>\n<span class=\"token keyword\">def<\/span> <span class=\"token function\">try_code<\/span><span class=\"token punctuation\">(<\/span>code<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">:<\/span><br \/>\n    data <span class=\"token operator\">&#061;<\/span> <span class=\"token punctuation\">{<\/span><span class=\"token string\">&#039;phone&#039;<\/span><span class=\"token punctuation\">:<\/span> phone<span class=\"token punctuation\">,<\/span> <span class=\"token string\">&#039;code&#039;<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token string-interpolation\"><span class=\"token string\">f&#034;<\/span><span class=\"token interpolation\"><span class=\"token punctuation\">{<\/span>code<span class=\"token punctuation\">:<\/span><span class=\"token format-spec\">06d<\/span><span class=\"token punctuation\">}<\/span><\/span><span class=\"token string\">&#034;<\/span><\/span><span class=\"token punctuation\">}<\/span><br \/>\n    resp <span class=\"token operator\">&#061;<\/span> requests<span class=\"token punctuation\">.<\/span>post<span class=\"token punctuation\">(<\/span>base_url<span class=\"token punctuation\">,<\/span> data<span class=\"token operator\">&#061;<\/span>data<span class=\"token punctuation\">)<\/span><br \/>\n    <span class=\"token keyword\">if<\/span> <span class=\"token string\">&#034;success&#034;<\/span> <span class=\"token keyword\">in<\/span> resp<span class=\"token punctuation\">.<\/span>text<span class=\"token punctuation\">.<\/span>lower<span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">:<\/span><br \/>\n        <span class=\"token keyword\">print<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string-interpolation\"><span class=\"token string\">f&#034;[&#043;] Found code: <\/span><span class=\"token interpolation\"><span class=\"token punctuation\">{<\/span>code<span class=\"token punctuation\">:<\/span><span class=\"token format-spec\">06d<\/span><span class=\"token punctuation\">}<\/span><\/span><span class=\"token string\">&#034;<\/span><\/span><span class=\"token punctuation\">)<\/span><br \/>\n        <span class=\"token keyword\">return<\/span> <span class=\"token boolean\">True<\/span><br \/>\n    <span class=\"token keyword\">return<\/span> <span class=\"token boolean\">False<\/span><\/p>\n<p><span class=\"token comment\"># \u8b66\u544a&#xff1a;\u6b64\u811a\u672c\u4ec5\u7528\u4e8e\u6388\u6743\u6d4b\u8bd5\u73af\u5883&#xff01;\u771f\u5b9e\u73af\u5883\u53ef\u80fd\u89e6\u53d1\u544a\u8b66\u548c\u5c01\u9501\u3002<\/span><br \/>\n<span class=\"token comment\"># \u4f7f\u7528\u7ebf\u7a0b\u6c60\u8c28\u614e\u6d4b\u8bd5&#xff0c;\u5e76\u8bbe\u7f6e\u5408\u7406\u7684\u5ef6\u8fdf\u548c\u5c1d\u8bd5\u6b21\u6570\u4e0a\u9650\u3002<\/span><br \/>\n<span class=\"token keyword\">with<\/span> concurrent<span class=\"token punctuation\">.<\/span>futures<span class=\"token punctuation\">.<\/span>ThreadPoolExecutor<span class=\"token punctuation\">(<\/span>max_workers<span class=\"token operator\">&#061;<\/span><span class=\"token number\">5<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token keyword\">as<\/span> executor<span class=\"token punctuation\">:<\/span><br \/>\n    futures <span class=\"token operator\">&#061;<\/span> <span class=\"token punctuation\">{<\/span>executor<span class=\"token punctuation\">.<\/span>submit<span class=\"token punctuation\">(<\/span>try_code<span class=\"token punctuation\">,<\/span> code<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">:<\/span> code <span class=\"token keyword\">for<\/span> code <span class=\"token keyword\">in<\/span> <span class=\"token builtin\">range<\/span><span class=\"token punctuation\">(<\/span><span class=\"token number\">1000000<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">}<\/span><br \/>\n    <span class=\"token comment\"># &#8230; \u5904\u7406\u7ed3\u679c (\u5b9e\u9645\u5e94\u66f4\u4f18\u96c5\u5730\u5904\u7406\u4e2d\u65ad\u548c\u7ed3\u679c\u6536\u96c6)<\/span><\/p>\n<p>\u00b7 \u9884\u6d4b\u4e0e\u6ee5\u7528&#xff1a;\u68c0\u67e5\u9a8c\u8bc1\u7801\u662f\u5426\u57fa\u4e8e\u65f6\u95f4\u3001\u624b\u673a\u53f7\u7b49\u53ef\u9884\u6d4b\u56e0\u5b50\u751f\u6210&#xff08;\u5982MD5(\u624b\u673a\u53f7&#043;\u5206\u949f\u65f6\u95f4\u6233).substr(0,6)&#xff09;\u3002\u68c0\u67e5\u201c\u91cd\u53d1\u201d\u63a5\u53e3\u662f\u5426\u65e0\u9650\u8c03\u7528\u3002<\/p>\n<p>\u6d4b\u8bd5\u6848\u4f8b8&#xff1a;\u884c\u4e3a\u9a8c\u8bc1\u7801&#xff08;\u65e0\u611f\u9a8c\u8bc1\/\u667a\u80fd\u9a8c\u8bc1&#xff09;<\/p>\n<p>\u00b7 \u539f\u7406&#xff1a;\u8fd9\u7c7b\u9a8c\u8bc1\u7801&#xff08;\u5982\u67d0\u76fe\u3001\u67d0\u9a8c&#xff09;\u4e0d\u76f4\u63a5\u7ed9\u51fa\u6311\u6218&#xff0c;\u800c\u662f\u901a\u8fc7\u91c7\u96c6\u7528\u6237\u5728\u9875\u9762\u7684\u9f20\u6807\u79fb\u52a8\u3001\u70b9\u51fb\u3001\u952e\u76d8\u4e8b\u4ef6\u7b49\u884c\u4e3a\u6570\u636e&#xff0c;\u7531\u540e\u7aefAI\u6a21\u578b\u5224\u65ad\u662f\u5426\u662f\u4eba\u7c7b\u3002 \u00b7 \u6d4b\u8bd5\u65b9\u6cd5&#xff1a;<\/p>\n<li>\u9006\u5411\u5206\u6790&#xff1a;\u4f7f\u7528\u6d4f\u89c8\u5668\u5f00\u53d1\u8005\u5de5\u5177&#xff0c;\u5206\u6790\u5176\u52a0\u8f7d\u7684JavaScript SDK\u3002\u67e5\u627e\u521d\u59cb\u5316\u914d\u7f6e\u3001\u6570\u636e\u6536\u96c6\u548c\u6700\u7ec8\u63d0\u4ea4\u7684token\u6216validate\u53c2\u6570\u3002<\/li>\n<li>\u91cd\u653e\u653b\u51fb&#xff1a;\u83b7\u53d6\u4e00\u4e2a\u6709\u6548\u7684token&#xff0c;\u5c1d\u8bd5\u5728\u53e6\u4e00\u4e2a\u4f1a\u8bdd\u6216\u4e0d\u540cIP\u4e2d\u91cd\u653e\u4f7f\u7528\u3002<\/li>\n<li>\u6a21\u62df\u884c\u4e3a&#xff1a;\u4f7f\u7528Selenium\u7b49\u5de5\u5177&#xff0c;\u5c3d\u53ef\u80fd\u903c\u771f\u5730\u6a21\u62df\u4eba\u7c7b\u64cd\u4f5c&#xff08;\u968f\u673a\u79fb\u52a8\u8f68\u8ff9\u3001\u52a0\u901f\u5ea6\u53d8\u5316\u3001\u5728\u6309\u94ae\u4e0a\u77ed\u6682\u505c\u7559\u7b49&#xff09;&#xff0c;\u7136\u540e\u63d0\u53d6\u751f\u6210\u7684token\u8fdb\u884c\u63d0\u4ea4\u3002<\/li>\n<li>\u53c2\u6570\u5206\u6790&#xff1a;\u63d0\u4ea4\u7684token\u662f\u5426\u5305\u542b\u4e86\u65f6\u95f4\u6233\u3001\u4f1a\u8bddID\u7b49\u4fe1\u606f&#xff1f;\u4fee\u6539\u8fd9\u4e9b\u4fe1\u606f\u662f\u5426\u4f1a\u5bfc\u81f4\u9a8c\u8bc1\u5931\u8d25&#xff1f;\u8fd9\u6709\u52a9\u4e8e\u7406\u89e3\u5176\u7ed1\u5b9a\u903b\u8f91\u3002<\/li>\n<p>\u81ea\u52a8\u5316\u4e0e\u811a\u672c&#xff1a;\u4e00\u4e2a\u96c6\u6210\u7684\u9a8c\u8bc1\u7801\u6d4b\u8bd5\u6846\u67b6\u601d\u8def<\/p>\n<p>\u4ee5\u4e0b\u662f\u4e00\u4e2a\u6982\u5ff5\u6027\u7684\u6846\u67b6\u7c7b\u8bbe\u8ba1&#xff0c;\u5c55\u793a\u4e86\u5982\u4f55\u5c06\u4e0d\u540c\u6d4b\u8bd5\u6a21\u5757\u7ec4\u7ec7\u8d77\u6765\u3002\u6ce8\u610f&#xff1a;\u6b64\u4e3a\u6559\u5b66\u793a\u4f8b&#xff0c;\u4e0d\u53ef\u76f4\u63a5\u7528\u4e8e\u975e\u6cd5\u6d4b\u8bd5\u3002<\/p>\n<p><span class=\"token comment\"># \u8b66\u544a&#xff1a;\u672c\u4ee3\u7801\u4ec5\u4f9b\u6388\u6743\u73af\u5883\u4e0b\u7684\u5b89\u5168\u7814\u7a76\u4e0e\u5b66\u4e60\u4f7f\u7528\u3002<\/span><br \/>\n<span class=\"token comment\"># captcha_tester_framework.py (\u6982\u5ff5\u6846\u67b6)<\/span><\/p>\n<p><span class=\"token keyword\">import<\/span> abc<br \/>\n<span class=\"token keyword\">from<\/span> enum <span class=\"token keyword\">import<\/span> Enum<br \/>\n<span class=\"token keyword\">import<\/span> requests<br \/>\n<span class=\"token keyword\">from<\/span> typing <span class=\"token keyword\">import<\/span> Optional<span class=\"token punctuation\">,<\/span> Dict<span class=\"token punctuation\">,<\/span> Any<\/p>\n<p><span class=\"token keyword\">class<\/span> <span class=\"token class-name\">CaptchaType<\/span><span class=\"token punctuation\">(<\/span>Enum<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">:<\/span><br \/>\n    IMAGE <span class=\"token operator\">&#061;<\/span> <span class=\"token string\">&#034;image&#034;<\/span><br \/>\n    SLIDE <span class=\"token operator\">&#061;<\/span> <span class=\"token string\">&#034;slide&#034;<\/span><br \/>\n    CLICK <span class=\"token operator\">&#061;<\/span> <span class=\"token string\">&#034;click&#034;<\/span><br \/>\n    SMS <span class=\"token operator\">&#061;<\/span> <span class=\"token string\">&#034;sms&#034;<\/span><br \/>\n    BEHAVIOR <span class=\"token operator\">&#061;<\/span> <span class=\"token string\">&#034;behavior&#034;<\/span><\/p>\n<p><span class=\"token keyword\">class<\/span> <span class=\"token class-name\">CaptchaTester<\/span><span class=\"token punctuation\">(<\/span>metaclass<span class=\"token operator\">&#061;<\/span>abc<span class=\"token punctuation\">.<\/span>ABCMeta<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">:<\/span><br \/>\n    <span class=\"token triple-quoted-string string\">&#034;&#034;&#034;\u9a8c\u8bc1\u7801\u6d4b\u8bd5\u5668\u62bd\u8c61\u57fa\u7c7b&#034;&#034;&#034;<\/span><br \/>\n    <span class=\"token keyword\">def<\/span> <span class=\"token function\">__init__<\/span><span class=\"token punctuation\">(<\/span>self<span class=\"token punctuation\">,<\/span> target_url<span class=\"token punctuation\">:<\/span> <span class=\"token builtin\">str<\/span><span class=\"token punctuation\">,<\/span> session<span class=\"token punctuation\">:<\/span> Optional<span class=\"token punctuation\">[<\/span>requests<span class=\"token punctuation\">.<\/span>Session<span class=\"token punctuation\">]<\/span> <span class=\"token operator\">&#061;<\/span> <span class=\"token boolean\">None<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">:<\/span><br \/>\n        self<span class=\"token punctuation\">.<\/span>target_url <span class=\"token operator\">&#061;<\/span> target_url<br \/>\n        self<span class=\"token punctuation\">.<\/span>session <span class=\"token operator\">&#061;<\/span> session <span class=\"token keyword\">or<\/span> requests<span class=\"token punctuation\">.<\/span>Session<span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><br \/>\n        self<span class=\"token punctuation\">.<\/span>session<span class=\"token punctuation\">.<\/span>headers<span class=\"token punctuation\">.<\/span>update<span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">{<\/span><span class=\"token string\">&#039;User-Agent&#039;<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token string\">&#039;Mozilla\/5.0 Sec-Test-Framework&#039;<\/span><span class=\"token punctuation\">}<\/span><span class=\"token punctuation\">)<\/span><\/p>\n<p>    <span class=\"token decorator annotation punctuation\">&#064;abc<span class=\"token punctuation\">.<\/span>abstractmethod<\/span><br \/>\n    <span class=\"token keyword\">def<\/span> <span class=\"token function\">fetch_challenge<\/span><span class=\"token punctuation\">(<\/span>self<span class=\"token punctuation\">,<\/span> <span class=\"token operator\">**<\/span>kwargs<span class=\"token punctuation\">)<\/span> <span class=\"token operator\">&#8211;<\/span><span class=\"token operator\">&gt;<\/span> Dict<span class=\"token punctuation\">[<\/span><span class=\"token builtin\">str<\/span><span class=\"token punctuation\">,<\/span> Any<span class=\"token punctuation\">]<\/span><span class=\"token punctuation\">:<\/span><br \/>\n        <span class=\"token triple-quoted-string string\">&#034;&#034;&#034;\u83b7\u53d6\u9a8c\u8bc1\u7801\u6311\u6218&#xff08;\u56fe\u7247\u3001\u53c2\u6570\u7b49&#xff09;&#034;&#034;&#034;<\/span><br \/>\n        <span class=\"token keyword\">pass<\/span><\/p>\n<p>    <span class=\"token decorator annotation punctuation\">&#064;abc<span class=\"token punctuation\">.<\/span>abstractmethod<\/span><br \/>\n    <span class=\"token keyword\">def<\/span> <span class=\"token function\">solve_challenge<\/span><span class=\"token punctuation\">(<\/span>self<span class=\"token punctuation\">,<\/span> challenge_data<span class=\"token punctuation\">:<\/span> Dict<span class=\"token punctuation\">[<\/span><span class=\"token builtin\">str<\/span><span class=\"token punctuation\">,<\/span> Any<span class=\"token punctuation\">]<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token operator\">&#8211;<\/span><span class=\"token operator\">&gt;<\/span> Optional<span class=\"token punctuation\">[<\/span><span class=\"token builtin\">str<\/span><span class=\"token punctuation\">]<\/span><span class=\"token punctuation\">:<\/span><br \/>\n        <span class=\"token triple-quoted-string string\">&#034;&#034;&#034;\u89e3\u51b3\u6311\u6218&#xff0c;\u8fd4\u56de\u7b54\u6848&#xff08;\u6587\u672c\u3001\u5750\u6807\u3001token\u7b49&#xff09;&#034;&#034;&#034;<\/span><br \/>\n        <span class=\"token keyword\">pass<\/span><\/p>\n<p>    <span class=\"token decorator annotation punctuation\">&#064;abc<span class=\"token punctuation\">.<\/span>abstractmethod<\/span><br \/>\n    <span class=\"token keyword\">def<\/span> <span class=\"token function\">submit_solution<\/span><span class=\"token punctuation\">(<\/span>self<span class=\"token punctuation\">,<\/span> solution<span class=\"token punctuation\">:<\/span> <span class=\"token builtin\">str<\/span><span class=\"token punctuation\">,<\/span> original_request<span class=\"token punctuation\">:<\/span> Optional<span class=\"token punctuation\">[<\/span>Dict<span class=\"token punctuation\">]<\/span> <span class=\"token operator\">&#061;<\/span> <span class=\"token boolean\">None<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token operator\">&#8211;<\/span><span class=\"token operator\">&gt;<\/span> <span class=\"token builtin\">bool<\/span><span class=\"token punctuation\">:<\/span><br \/>\n        <span class=\"token triple-quoted-string string\">&#034;&#034;&#034;\u63d0\u4ea4\u7b54\u6848&#xff0c;\u5e76\u8fd4\u56de\u9a8c\u8bc1\u662f\u5426\u6210\u529f&#034;&#034;&#034;<\/span><br \/>\n        <span class=\"token keyword\">pass<\/span><\/p>\n<p>    <span class=\"token keyword\">def<\/span> <span class=\"token function\">run_test<\/span><span class=\"token punctuation\">(<\/span>self<span class=\"token punctuation\">,<\/span> <span class=\"token operator\">**<\/span>kwargs<span class=\"token punctuation\">)<\/span> <span class=\"token operator\">&#8211;<\/span><span class=\"token operator\">&gt;<\/span> <span class=\"token builtin\">bool<\/span><span class=\"token punctuation\">:<\/span><br \/>\n        <span class=\"token triple-quoted-string string\">&#034;&#034;&#034;\u6267\u884c\u4e00\u6b21\u5b8c\u6574\u7684\u6d4b\u8bd5\u6d41\u7a0b&#034;&#034;&#034;<\/span><br \/>\n        <span class=\"token keyword\">try<\/span><span class=\"token punctuation\">:<\/span><br \/>\n            challenge <span class=\"token operator\">&#061;<\/span> self<span class=\"token punctuation\">.<\/span>fetch_challenge<span class=\"token punctuation\">(<\/span><span class=\"token operator\">**<\/span>kwargs<span class=\"token punctuation\">)<\/span><br \/>\n            solution <span class=\"token operator\">&#061;<\/span> self<span class=\"token punctuation\">.<\/span>solve_challenge<span class=\"token punctuation\">(<\/span>challenge<span class=\"token punctuation\">)<\/span><br \/>\n            <span class=\"token keyword\">if<\/span> solution<span class=\"token punctuation\">:<\/span><br \/>\n                <span class=\"token keyword\">return<\/span> self<span class=\"token punctuation\">.<\/span>submit_solution<span class=\"token punctuation\">(<\/span>solution<span class=\"token punctuation\">,<\/span> kwargs<span class=\"token punctuation\">.<\/span>get<span class=\"token punctuation\">(<\/span><span class=\"token string\">&#039;original_request&#039;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">)<\/span><br \/>\n        <span class=\"token keyword\">except<\/span> Exception <span class=\"token keyword\">as<\/span> e<span class=\"token punctuation\">:<\/span><br \/>\n            <span class=\"token keyword\">print<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string-interpolation\"><span class=\"token string\">f&#034;[-] \u6d4b\u8bd5\u8fc7\u7a0b\u51fa\u9519: <\/span><span class=\"token interpolation\"><span class=\"token punctuation\">{<\/span>e<span class=\"token punctuation\">}<\/span><\/span><span class=\"token string\">&#034;<\/span><\/span><span class=\"token punctuation\">)<\/span><br \/>\n        <span class=\"token keyword\">return<\/span> <span class=\"token boolean\">False<\/span><\/p>\n<p><span class=\"token keyword\">class<\/span> <span class=\"token class-name\">SimpleImageCaptchaTester<\/span><span class=\"token punctuation\">(<\/span>CaptchaTester<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">:<\/span><br \/>\n    <span class=\"token triple-quoted-string string\">&#034;&#034;&#034;\u7b80\u5355\u56fe\u5f62\u9a8c\u8bc1\u7801\u6d4b\u8bd5\u5668&#xff08;\u4f7f\u7528OCR&#xff09;&#034;&#034;&#034;<\/span><br \/>\n    <span class=\"token keyword\">def<\/span> <span class=\"token function\">__init__<\/span><span class=\"token punctuation\">(<\/span>self<span class=\"token punctuation\">,<\/span> target_url<span class=\"token punctuation\">,<\/span> ocr_engine<span class=\"token operator\">&#061;<\/span><span class=\"token string\">&#039;tesseract&#039;<\/span><span class=\"token punctuation\">,<\/span> preprocess_func<span class=\"token operator\">&#061;<\/span><span class=\"token boolean\">None<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">:<\/span><br \/>\n        <span class=\"token builtin\">super<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">.<\/span>__init__<span class=\"token punctuation\">(<\/span>target_url<span class=\"token punctuation\">)<\/span><br \/>\n        self<span class=\"token punctuation\">.<\/span>ocr_engine <span class=\"token operator\">&#061;<\/span> ocr_engine<br \/>\n        self<span class=\"token punctuation\">.<\/span>preprocess <span class=\"token operator\">&#061;<\/span> preprocess_func <span class=\"token keyword\">or<\/span> self<span class=\"token punctuation\">.<\/span>_default_preprocess<br \/>\n        <span class=\"token comment\"># \u521d\u59cb\u5316OCR\u5f15\u64ce&#8230;<\/span><\/p>\n<p>    <span class=\"token keyword\">def<\/span> <span class=\"token function\">fetch_challenge<\/span><span class=\"token punctuation\">(<\/span>self<span class=\"token punctuation\">,<\/span> get_url<span class=\"token punctuation\">:<\/span> <span class=\"token builtin\">str<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token operator\">**<\/span>kwargs<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">:<\/span><br \/>\n        resp <span class=\"token operator\">&#061;<\/span> self<span class=\"token punctuation\">.<\/span>session<span class=\"token punctuation\">.<\/span>get<span class=\"token punctuation\">(<\/span>get_url<span class=\"token punctuation\">)<\/span><br \/>\n        <span class=\"token comment\"># \u5047\u8bbe\u8fd4\u56de\u7684\u5c31\u662f\u56fe\u7247\u4e8c\u8fdb\u5236<\/span><br \/>\n        <span class=\"token keyword\">return<\/span> <span class=\"token punctuation\">{<\/span><span class=\"token string\">&#039;image_data&#039;<\/span><span class=\"token punctuation\">:<\/span> resp<span class=\"token punctuation\">.<\/span>content<span class=\"token punctuation\">,<\/span> <span class=\"token string\">&#039;cookies&#039;<\/span><span class=\"token punctuation\">:<\/span> self<span class=\"token punctuation\">.<\/span>session<span class=\"token punctuation\">.<\/span>cookies<span class=\"token punctuation\">}<\/span><\/p>\n<p>    <span class=\"token keyword\">def<\/span> <span class=\"token function\">solve_challenge<\/span><span class=\"token punctuation\">(<\/span>self<span class=\"token punctuation\">,<\/span> challenge_data<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">:<\/span><br \/>\n        image_data <span class=\"token operator\">&#061;<\/span> challenge_data<span class=\"token punctuation\">[<\/span><span class=\"token string\">&#039;image_data&#039;<\/span><span class=\"token punctuation\">]<\/span><br \/>\n        <span class=\"token comment\"># \u8c03\u7528\u9884\u5904\u7406\u548cOCR\u51fd\u6570<\/span><br \/>\n        processed_img <span class=\"token operator\">&#061;<\/span> self<span class=\"token punctuation\">.<\/span>preprocess<span class=\"token punctuation\">(<\/span>image_data<span class=\"token punctuation\">)<\/span><br \/>\n        answer <span class=\"token operator\">&#061;<\/span> self<span class=\"token punctuation\">.<\/span>_ocr<span class=\"token punctuation\">(<\/span>processed_img<span class=\"token punctuation\">)<\/span><br \/>\n        <span class=\"token keyword\">return<\/span> answer<\/p>\n<p>    <span class=\"token keyword\">def<\/span> <span class=\"token function\">submit_solution<\/span><span class=\"token punctuation\">(<\/span>self<span class=\"token punctuation\">,<\/span> solution<span class=\"token punctuation\">,<\/span> original_request<span class=\"token operator\">&#061;<\/span><span class=\"token boolean\">None<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">:<\/span><br \/>\n        <span class=\"token comment\"># \u5047\u8bbe\u6211\u4eec\u77e5\u9053\u63d0\u4ea4\u7684URL\u548c\u53c2\u6570\u683c\u5f0f<\/span><br \/>\n        post_url <span class=\"token operator\">&#061;<\/span> self<span class=\"token punctuation\">.<\/span>target_url <span class=\"token operator\">&#043;<\/span> <span class=\"token string\">&#034;\/submit&#034;<\/span><br \/>\n        data <span class=\"token operator\">&#061;<\/span> <span class=\"token punctuation\">{<\/span><span class=\"token string\">&#039;username&#039;<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token string\">&#039;test&#039;<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token string\">&#039;captcha&#039;<\/span><span class=\"token punctuation\">:<\/span> solution<span class=\"token punctuation\">}<\/span><br \/>\n        resp <span class=\"token operator\">&#061;<\/span> self<span class=\"token punctuation\">.<\/span>session<span class=\"token punctuation\">.<\/span>post<span class=\"token punctuation\">(<\/span>post_url<span class=\"token punctuation\">,<\/span> data<span class=\"token operator\">&#061;<\/span>data<span class=\"token punctuation\">)<\/span><br \/>\n        <span class=\"token keyword\">return<\/span> resp<span class=\"token punctuation\">.<\/span>status_code <span class=\"token operator\">&#061;&#061;<\/span> <span class=\"token number\">200<\/span> <span class=\"token keyword\">and<\/span> <span class=\"token string\">&#034;success&#034;<\/span> <span class=\"token keyword\">in<\/span> resp<span class=\"token punctuation\">.<\/span>text<span class=\"token punctuation\">.<\/span>lower<span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><\/p>\n<p>    <span class=\"token comment\"># &#8230; \u5177\u4f53\u5b9e\u73b0 _default_preprocess, _ocr \u7b49\u65b9\u6cd5<\/span><\/p>\n<p><span class=\"token comment\"># \u5de5\u5382\u6a21\u5f0f&#xff0c;\u6839\u636e\u9700\u8981\u521b\u5efa\u4e0d\u540c\u7684\u6d4b\u8bd5\u5668<\/span><br \/>\n<span class=\"token keyword\">class<\/span> <span class=\"token class-name\">TesterFactory<\/span><span class=\"token punctuation\">:<\/span><br \/>\n    <span class=\"token decorator annotation punctuation\">&#064;staticmethod<\/span><br \/>\n    <span class=\"token keyword\">def<\/span> <span class=\"token function\">create<\/span><span class=\"token punctuation\">(<\/span>ttype<span class=\"token punctuation\">:<\/span> CaptchaType<span class=\"token punctuation\">,<\/span> <span class=\"token operator\">**<\/span>kwargs<span class=\"token punctuation\">)<\/span> <span class=\"token operator\">&#8211;<\/span><span class=\"token operator\">&gt;<\/span> CaptchaTester<span class=\"token punctuation\">:<\/span><br \/>\n        <span class=\"token keyword\">if<\/span> ttype <span class=\"token operator\">&#061;&#061;<\/span> CaptchaType<span class=\"token punctuation\">.<\/span>IMAGE<span class=\"token punctuation\">:<\/span><br \/>\n            <span class=\"token keyword\">return<\/span> SimpleImageCaptchaTester<span class=\"token punctuation\">(<\/span><span class=\"token operator\">**<\/span>kwargs<span class=\"token punctuation\">)<\/span><br \/>\n        <span class=\"token comment\"># elif ttype &#061;&#061; CaptchaType.SLIDE: &#8230;<\/span><br \/>\n        <span class=\"token keyword\">else<\/span><span class=\"token punctuation\">:<\/span><br \/>\n            <span class=\"token keyword\">raise<\/span> ValueError<span class=\"token punctuation\">(<\/span><span class=\"token string-interpolation\"><span class=\"token string\">f&#034;Unsupported captcha type: <\/span><span class=\"token interpolation\"><span class=\"token punctuation\">{<\/span>ttype<span class=\"token punctuation\">}<\/span><\/span><span class=\"token string\">&#034;<\/span><\/span><span class=\"token punctuation\">)<\/span><\/p>\n<p><span class=\"token comment\"># \u4f7f\u7528\u793a\u4f8b<\/span><br \/>\n<span class=\"token keyword\">if<\/span> __name__ <span class=\"token operator\">&#061;&#061;<\/span> <span class=\"token string\">&#034;__main__&#034;<\/span><span class=\"token punctuation\">:<\/span><br \/>\n    <span class=\"token comment\"># \u4ec5\u5728\u6388\u6743\u7684\u6d4b\u8bd5\u73af\u5883\u4e2d\u8fd0\u884c&#xff01;<\/span><br \/>\n    target <span class=\"token operator\">&#061;<\/span> <span class=\"token string\">&#034;http:\/\/localhost:8080&#034;<\/span><br \/>\n    factory <span class=\"token operator\">&#061;<\/span> TesterFactory<span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><br \/>\n    tester <span class=\"token operator\">&#061;<\/span> factory<span class=\"token punctuation\">.<\/span>create<span class=\"token punctuation\">(<\/span>CaptchaType<span class=\"token punctuation\">.<\/span>IMAGE<span class=\"token punctuation\">,<\/span> target_url<span class=\"token operator\">&#061;<\/span>target <span class=\"token operator\">&#043;<\/span> <span class=\"token string\">&#034;\/captcha&#034;<\/span><span class=\"token punctuation\">)<\/span><br \/>\n    <span class=\"token comment\"># \u914d\u7f6e\u66f4\u591a\u53c2\u6570&#8230;<\/span><br \/>\n    success <span class=\"token operator\">&#061;<\/span> tester<span class=\"token punctuation\">.<\/span>run_test<span class=\"token punctuation\">(<\/span>get_url<span class=\"token operator\">&#061;<\/span>target <span class=\"token operator\">&#043;<\/span> <span class=\"token string\">&#034;\/api\/captcha&#034;<\/span><span class=\"token punctuation\">)<\/span><br \/>\n    <span class=\"token keyword\">print<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string-interpolation\"><span class=\"token string\">f&#034;\u6d4b\u8bd5\u7ed3\u679c: <\/span><span class=\"token interpolation\"><span class=\"token punctuation\">{<\/span><span class=\"token string\">&#039;\u6210\u529f&#039;<\/span> <span class=\"token keyword\">if<\/span> success <span class=\"token keyword\">else<\/span> <span class=\"token string\">&#039;\u5931\u8d25&#039;<\/span><span class=\"token punctuation\">}<\/span><\/span><span class=\"token string\">&#034;<\/span><\/span><span class=\"token punctuation\">)<\/span><\/p>\n<hr \/>\n<p>\u7b2c\u56db\u90e8\u5206&#xff1a;\u9632\u5fa1\u5efa\u8bbe \u2014\u2014 \u4ece\u201c\u600e\u4e48\u505a\u201d\u5230\u201c\u600e\u4e48\u9632\u201d<\/p>\n<p>\u5f00\u53d1\u4fa7\u4fee\u590d&#xff1a;\u5b89\u5168\u7f16\u7801\u8303\u5f0f<\/p>\n<p>\u5371\u9669\u6a21\u5f0f vs \u5b89\u5168\u6a21\u5f0f<\/p>\n<li>\u9a8c\u8bc1\u7801\u751f\u6210\u4e0e\u5b58\u50a8<\/li>\n<p>\u00b7 \u5371\u9669\u6a21\u5f0f&#xff1a;\u9a8c\u8bc1\u7801\u7b54\u6848\u5b58\u50a8\u5728\u5ba2\u6237\u7aefCookie\u6216\u524d\u7aef\u5168\u5c40\u53d8\u91cf\u4e2d\u3002<\/p>\n<p><span class=\"token comment\">\/\/ \u524d\u7aef\u751f\u6210&#xff08;\u7edd\u5bf9\u7981\u6b62&#xff01;&#xff09;<\/span><br \/>\n<span class=\"token keyword\">var<\/span> captcha <span class=\"token operator\">&#061;<\/span> Math<span class=\"token punctuation\">.<\/span><span class=\"token function\">floor<\/span><span class=\"token punctuation\">(<\/span>Math<span class=\"token punctuation\">.<\/span><span class=\"token function\">random<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><span class=\"token operator\">*<\/span><span class=\"token number\">9000<\/span><span class=\"token operator\">&#043;<\/span><span class=\"token number\">1000<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\ndocument<span class=\"token punctuation\">.<\/span><span class=\"token function\">getElementById<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#039;hiddenCaptcha&#039;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">.<\/span>value <span class=\"token operator\">&#061;<\/span> captcha<span class=\"token punctuation\">;<\/span><\/p>\n<p>\u00b7 \u5b89\u5168\u6a21\u5f0f&#xff1a;\u670d\u52a1\u5668\u7aef\u751f\u6210&#xff0c; \u4e0e\u4f1a\u8bdd\u6216\u552f\u4e00\u4ee4\u724c\u5f3a\u7ed1\u5b9a&#xff0c; \u4f7f\u7528\u5b89\u5168\u7684\u7f13\u5b58&#xff08;\u5982Redis&#xff09;\u5e76\u8bbe\u7f6e\u77ed\u6709\u6548\u671f&#xff08;\u59822-5\u5206\u949f&#xff09;\u3002<\/p>\n<p><span class=\"token comment\">\/\/ Spring Boot \u793a\u4f8b<\/span><br \/>\n<span class=\"token annotation punctuation\">&#064;GetMapping<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;\/captcha&#034;<\/span><span class=\"token punctuation\">)<\/span><br \/>\n<span class=\"token keyword\">public<\/span> <span class=\"token keyword\">void<\/span> <span class=\"token function\">generateCaptcha<\/span><span class=\"token punctuation\">(<\/span><span class=\"token class-name\">HttpServletRequest<\/span> request<span class=\"token punctuation\">,<\/span> <span class=\"token class-name\">HttpServletResponse<\/span> response<span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n    <span class=\"token class-name\">String<\/span> captchaText <span class=\"token operator\">&#061;<\/span> <span class=\"token function\">generateRandomText<\/span><span class=\"token punctuation\">(<\/span><span class=\"token number\">4<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span> <span class=\"token comment\">\/\/ \u751f\u6210\u968f\u673a\u6587\u672c<\/span><br \/>\n    <span class=\"token class-name\">String<\/span> captchaKey <span class=\"token operator\">&#061;<\/span> UUID<span class=\"token punctuation\">.<\/span><span class=\"token function\">randomUUID<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">.<\/span><span class=\"token function\">toString<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><\/p>\n<p>    <span class=\"token comment\">\/\/ \u5b58\u50a8&#xff1a; key -&gt; (text, timestamp)&#xff0c; \u6709\u6548\u671f5\u5206\u949f<\/span><br \/>\n    redisTemplate<span class=\"token punctuation\">.<\/span><span class=\"token function\">opsForValue<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">.<\/span><span class=\"token function\">set<\/span><span class=\"token punctuation\">(<\/span><br \/>\n        <span class=\"token string\">&#034;CAPTCHA:&#034;<\/span> <span class=\"token operator\">&#043;<\/span> captchaKey<span class=\"token punctuation\">,<\/span><br \/>\n        captchaText<span class=\"token punctuation\">,<\/span><br \/>\n        <span class=\"token class-name\">Duration<\/span><span class=\"token punctuation\">.<\/span><span class=\"token function\">ofMinutes<\/span><span class=\"token punctuation\">(<\/span><span class=\"token number\">5<\/span><span class=\"token punctuation\">)<\/span><br \/>\n    <span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><\/p>\n<p>    <span class=\"token comment\">\/\/ \u751f\u6210\u56fe\u7247&#xff0c;\u5c06captchaKey\u8fd4\u56de\u7ed9\u524d\u7aef&#xff08;\u5982\u653e\u5728\u56fe\u7247URL\u4e2d\u6216\u5355\u72ec\u63a5\u53e3\u8fd4\u56de&#xff09;<\/span><br \/>\n    <span class=\"token comment\">\/\/ ImageIO.write(image, &#034;png&#034;, response.getOutputStream());<\/span><br \/>\n    <span class=\"token comment\">\/\/ \u524d\u7aef\u63d0\u4ea4\u65f6&#xff0c;\u9700\u540c\u65f6\u63d0\u4ea4 captchaKey \u548c\u7528\u6237\u8f93\u5165\u7684\u7b54\u6848<\/span><br \/>\n<span class=\"token punctuation\">}<\/span><\/p>\n<li>\u9a8c\u8bc1\u7801\u9a8c\u8bc1\u903b\u8f91<\/li>\n<p>\u00b7 \u5371\u9669\u6a21\u5f0f&#xff1a;\u9a8c\u8bc1\u540e\u4e0d\u4f7f\u9a8c\u8bc1\u7801\u5931\u6548&#xff1b;\u9a8c\u8bc1\u903b\u8f91\u4e0e\u4e1a\u52a1\u903b\u8f91\u5206\u79bb&#xff0c;\u5b58\u5728\u7ed5\u8fc7\u53ef\u80fd\u3002<\/p>\n<p><span class=\"token comment\">\/\/ \u9519\u8bef&#xff1a;\u9a8c\u8bc1\u540e\u672a\u5220\u9664key<\/span><br \/>\n<span class=\"token class-name\">String<\/span> storedText <span class=\"token operator\">&#061;<\/span> redisTemplate<span class=\"token punctuation\">.<\/span><span class=\"token function\">opsForValue<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">.<\/span><span class=\"token function\">get<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;CAPTCHA:&#034;<\/span> <span class=\"token operator\">&#043;<\/span> key<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n<span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span>storedText <span class=\"token operator\">!&#061;<\/span> <span class=\"token keyword\">null<\/span> <span class=\"token operator\">&amp;&amp;<\/span> storedText<span class=\"token punctuation\">.<\/span><span class=\"token function\">equalsIgnoreCase<\/span><span class=\"token punctuation\">(<\/span>userInput<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n    <span class=\"token comment\">\/\/ \u6267\u884c\u767b\u5f55&#8230;<\/span><br \/>\n    <span class=\"token comment\">\/\/ \u5fd8\u8bb0\u5220\u9664 redis \u4e2d\u7684 key&#xff01;<\/span><br \/>\n<span class=\"token punctuation\">}<\/span><\/p>\n<p>\u00b7 \u5b89\u5168\u6a21\u5f0f&#xff1a;\u9a8c\u8bc1\u64cd\u4f5c\u5fc5\u987b\u662f\u539f\u5b50\u7684\u3001\u72b6\u6001\u5316\u7684\u3002\u9a8c\u8bc1\u6210\u529f\u540e\u7acb\u5373\u4f7f\u8be5\u9a8c\u8bc1\u7801\u5931\u6548\u3002\u4e1a\u52a1\u903b\u8f91\u5fc5\u987b\u5728\u9a8c\u8bc1\u901a\u8fc7\u4e4b\u540e\u624d\u80fd\u6267\u884c\u3002<\/p>\n<p><span class=\"token annotation punctuation\">&#064;PostMapping<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;\/login&#034;<\/span><span class=\"token punctuation\">)<\/span><br \/>\n<span class=\"token keyword\">public<\/span> <span class=\"token class-name\">ResponseEntity<\/span><span class=\"token generics\"><span class=\"token punctuation\">&lt;<\/span><span class=\"token operator\">?<\/span><span class=\"token punctuation\">&gt;<\/span><\/span> <span class=\"token function\">login<\/span><span class=\"token punctuation\">(<\/span><span class=\"token annotation punctuation\">&#064;RequestBody<\/span> <span class=\"token class-name\">LoginRequest<\/span> request<span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n    <span class=\"token comment\">\/\/ 1. \u5148\u9a8c\u8bc1\u9a8c\u8bc1\u7801<\/span><br \/>\n    <span class=\"token class-name\">String<\/span> redisKey <span class=\"token operator\">&#061;<\/span> <span class=\"token string\">&#034;CAPTCHA:&#034;<\/span> <span class=\"token operator\">&#043;<\/span> request<span class=\"token punctuation\">.<\/span><span class=\"token function\">getCaptchaKey<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token class-name\">String<\/span> storedText <span class=\"token operator\">&#061;<\/span> redisTemplate<span class=\"token punctuation\">.<\/span><span class=\"token function\">opsForValue<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">.<\/span><span class=\"token function\">get<\/span><span class=\"token punctuation\">(<\/span>redisKey<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><\/p>\n<p>    <span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span>storedText <span class=\"token operator\">&#061;&#061;<\/span> <span class=\"token keyword\">null<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n        <span class=\"token keyword\">return<\/span> <span class=\"token class-name\">ResponseEntity<\/span><span class=\"token punctuation\">.<\/span><span class=\"token function\">badRequest<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">.<\/span><span class=\"token function\">body<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;\u9a8c\u8bc1\u7801\u5df2\u8fc7\u671f&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><br \/>\n    <span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span><span class=\"token operator\">!<\/span>storedText<span class=\"token punctuation\">.<\/span><span class=\"token function\">equalsIgnoreCase<\/span><span class=\"token punctuation\">(<\/span>request<span class=\"token punctuation\">.<\/span><span class=\"token function\">getCaptcha<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n        <span class=\"token keyword\">return<\/span> <span class=\"token class-name\">ResponseEntity<\/span><span class=\"token punctuation\">.<\/span><span class=\"token function\">badRequest<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">.<\/span><span class=\"token function\">body<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;\u9a8c\u8bc1\u7801\u9519\u8bef&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><\/p>\n<p>    <span class=\"token comment\">\/\/ 2. \u9a8c\u8bc1\u7801\u6b63\u786e&#xff0c;\u7acb\u5373\u5220\u9664&#xff0c;\u9632\u6b62\u91cd\u7528<\/span><br \/>\n    redisTemplate<span class=\"token punctuation\">.<\/span><span class=\"token function\">delete<\/span><span class=\"token punctuation\">(<\/span>redisKey<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><\/p>\n<p>    <span class=\"token comment\">\/\/ 3. \u518d\u6267\u884c\u6838\u5fc3\u4e1a\u52a1\u903b\u8f91&#xff08;\u5982\u5bc6\u7801\u6821\u9a8c\u3001\u767b\u5f55\u6001\u751f\u6210&#xff09;<\/span><br \/>\n    <span class=\"token keyword\">boolean<\/span> loginSuccess <span class=\"token operator\">&#061;<\/span> userService<span class=\"token punctuation\">.<\/span><span class=\"token function\">authenticate<\/span><span class=\"token punctuation\">(<\/span>request<span class=\"token punctuation\">.<\/span><span class=\"token function\">getUsername<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">,<\/span> request<span class=\"token punctuation\">.<\/span><span class=\"token function\">getPassword<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span><span class=\"token operator\">!<\/span>loginSuccess<span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n        <span class=\"token keyword\">return<\/span> <span class=\"token class-name\">ResponseEntity<\/span><span class=\"token punctuation\">.<\/span><span class=\"token function\">status<\/span><span class=\"token punctuation\">(<\/span><span class=\"token number\">401<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">.<\/span><span class=\"token function\">body<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;\u7528\u6237\u540d\u6216\u5bc6\u7801\u9519\u8bef&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><br \/>\n    <span class=\"token comment\">\/\/ &#8230; \u751f\u6210session\/token<\/span><br \/>\n    <span class=\"token keyword\">return<\/span> <span class=\"token class-name\">ResponseEntity<\/span><span class=\"token punctuation\">.<\/span><span class=\"token function\">ok<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;\u767b\u5f55\u6210\u529f&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n<span class=\"token punctuation\">}<\/span><\/p>\n<li>\u77ed\u4fe1\/\u90ae\u4ef6\u9a8c\u8bc1\u7801<\/li>\n<p>\u00b7 \u5b89\u5168\u6a21\u5f0f&#xff1a; \u00b7 \u9891\u7387\u9650\u5236&#xff1a;\u540c\u4e00\u624b\u673a\u53f7\/\u90ae\u7bb1\u5728\u5355\u4f4d\u65f6\u95f4\u5185&#xff08;\u59821\u5206\u949f\/1\u5c0f\u65f6&#xff09;\u53d1\u9001\u6b21\u6570\u4e0a\u9650\u3002 \u00b7 \u603b\u91cf\u9650\u5236&#xff1a;\u540c\u4e00IP\u6216\u8d26\u53f7\u572824\u5c0f\u65f6\u5185\u53d1\u9001\u603b\u91cf\u4e0a\u9650\u3002 \u00b7 \u9632\u66b4\u7834&#xff1a;\u9a8c\u8bc1\u7801\u81f3\u5c116\u4f4d&#xff0c;\u5305\u542b\u5b57\u6bcd\u6570\u5b57&#xff0c;\u9519\u8bef\u5c1d\u8bd53-5\u6b21\u540e\u7acb\u5373\u4f5c\u5e9f\u5e76\u53ef\u80fd\u4e34\u65f6\u9501\u5b9a\u8be5\u53f7\u7801\u3002 \u00b7 \u5185\u5bb9\u65e0\u5173&#xff1a;\u9a8c\u8bc1\u7801\u4e0d\u5e94\u4e0e\u7528\u6237\u8eab\u4efd\u4fe1\u606f&#xff08;\u5982\u624b\u673a\u5c3e\u53f7&#xff09;\u6216\u65f6\u95f4\u6709\u7b80\u5355\u5173\u8054\u3002<\/p>\n<p>\u8fd0\u7ef4\u4fa7\u52a0\u56fa&#xff1a;\u67b6\u6784\u4e0e\u914d\u7f6e\u5efa\u8bae<\/p>\n<li>WAF\/\u7f51\u5173\u5c42\u9632\u62a4&#xff1a; \u00b7 \u914d\u7f6e\u89c4\u5219&#xff0c;\u8bc6\u522b\u5f02\u5e38\u7684\u9a8c\u8bc1\u7801\u63d0\u4ea4\u9891\u7387&#xff08;\u5982\u5355\u4e2aIP\u6bcf\u79d2\u63d0\u4ea4&gt;10\u6b21\u4e0d\u540c\u9a8c\u8bc1\u7801&#xff09;\u3002 \u00b7 \u8bc6\u522b\u81ea\u52a8\u5316\u5de5\u5177\u6307\u7eb9&#xff08;\u5982\u7279\u5b9a\u7684HTTP\u5934\u7f3a\u5931\u3001TLS\u6307\u7eb9&#xff09;\u3002<\/li>\n<li>\u5a01\u80c1\u60c5\u62a5\u96c6\u6210&#xff1a;\u63a5\u5165IP\u4fe1\u8a89\u5e93&#xff0c;\u5bf9\u6765\u81ea\u6570\u636e\u4e2d\u5fc3IP\u3001\u4ee3\u7406\u6c60IP\u7684\u9a8c\u8bc1\u7801\u8bf7\u6c42\u8fdb\u884c\u66f4\u4e25\u683c\u7684\u884c\u4e3a\u9a8c\u8bc1\u6216\u76f4\u63a5\u62e6\u622a\u3002<\/li>\n<li>\u670d\u52a1\u964d\u7ea7\u4e0e\u7528\u6237\u4f53\u9a8c&#xff1a;\u5f53\u68c0\u6d4b\u5230\u7591\u4f3c\u653b\u51fb\u65f6&#xff08;\u5982\u5927\u91cf\u9519\u8bef\u5c1d\u8bd5&#xff09;&#xff0c;\u53ef\u4ee5\u52a8\u6001\u5347\u7ea7\u9a8c\u8bc1\u7801\u96be\u5ea6&#xff08;\u4f8b\u5982\u4ece\u56fe\u5f62\u9a8c\u8bc1\u7801\u5347\u7ea7\u4e3a\u6ed1\u52a8\u6216\u667a\u80fd\u9a8c\u8bc1&#xff09;&#xff0c;\u800c\u4e0d\u662f\u76f4\u63a5\u5c01\u7981&#xff0c;\u907f\u514d\u5f71\u54cd\u6b63\u5e38\u7528\u6237\u3002<\/li>\n<li>\u4f7f\u7528\u6210\u719f\u7684\u7b2c\u4e09\u65b9\u9a8c\u8bc1\u7801\u670d\u52a1&#xff1a;\u5982 Google reCAPTCHA v3\/Enterprise&#xff0c; \u67d0\u76fe&#xff0c; \u67d0\u9a8c\u7b49\u3002\u8fd9\u4e9b\u670d\u52a1\u6295\u5165\u4e86\u5927\u91cf\u8d44\u6e90\u8fdb\u884cAI\u5bf9\u6297\u548c\u57fa\u7840\u8bbe\u65bd\u7ef4\u62a4\u3002\u6ce8\u610f&#xff1a;\u5373\u4f7f\u4f7f\u7528\u7b2c\u4e09\u65b9\u670d\u52a1&#xff0c;\u4e5f\u9700\u4e25\u683c\u6309\u7167\u5176\u6587\u6863\u96c6\u6210&#xff0c;\u5e76\u786e\u4fddtoken\u7684\u9a8c\u8bc1\u5728\u670d\u52a1\u5668\u7aef\u5b8c\u6210\u3002<\/li>\n<p>\u68c0\u6d4b\u4e0e\u54cd\u5e94\u7ebf\u7d22<\/p>\n<p>\u5728\u5e94\u7528\u65e5\u5fd7\u548cWAF\u65e5\u5fd7\u4e2d\u5173\u6ce8\u4ee5\u4e0b\u5f02\u5e38\u6a21\u5f0f&#xff1a;<\/p>\n<p>\u00b7 \u9ad8\u9891\u5931\u8d25&#xff1a;\u540c\u4e00\u4f1a\u8bdd\u6216IP\u5728\u77ed\u65f6\u95f4\u5185\u5bf9\u540c\u4e00\u9a8c\u8bc1\u7801\u8fdb\u884c\u591a\u6b21\u9519\u8bef\u5c1d\u8bd5\u3002 \u00b7 \u9a8c\u8bc1\u7801\u6d88\u8017\u5f02\u5e38&#xff1a;\u83b7\u53d6\u9a8c\u8bc1\u7801\u7684\u8bf7\u6c42\u9891\u7387\u8fdc\u9ad8\u4e8e\u6b63\u5e38\u4e1a\u52a1\u6210\u529f\u7387&#xff08;\u4f8b\u5982&#xff0c;\u83b7\u53d61000\u6b21\u9a8c\u8bc1\u7801&#xff0c;\u53ea\u67091\u6b21\u6210\u529f\u767b\u5f55&#xff09;\u3002 \u00b7 \u65e0\u5934\u6d4f\u89c8\u5668\u7279\u5f81&#xff1a;User-Agent\u5f02\u5e38\u3001JavaScript\u6267\u884c\u73af\u5883\u7f3a\u5931\u7279\u5b9a\u5c5e\u6027&#xff08;\u901a\u8fc7JavaScript\u63a2\u9488\u53ef\u68c0\u6d4b&#xff09;\u3002 \u00b7 OCR\u5de5\u5177\u7279\u5f81&#xff1a;\u8bf7\u6c42\u9a8c\u8bc1\u7801\u56fe\u7247\u540e&#xff0c;\u7d27\u968f\u7684\u63d0\u4ea4\u95f4\u9694\u6781\u77ed&#xff08;&lt; 1\u79d2&#xff09;&#xff0c;\u4e14\u6210\u529f\u7387\u5f02\u5e38\u9ad8\u3002 \u00b7 \u903b\u8f91\u6f0f\u6d1e\u5229\u7528&#xff1a;\u540c\u4e00\u9a8c\u8bc1\u7801key\u6216\u7b54\u6848\u88ab\u91cd\u590d\u63d0\u4ea4\u5e76\u6210\u529f\u3002<\/p>\n<hr \/>\n<p>\u7b2c\u4e94\u90e8\u5206&#xff1a;\u603b\u7ed3\u4e0e\u8109\u7edc \u2014\u2014 \u8fde\u63a5\u4e0e\u5c55\u671b<\/p>\n<p>\u6838\u5fc3\u8981\u70b9\u590d\u76d8<\/p>\n<li>\u9a8c\u8bc1\u7801\u662f\u6210\u672c\u63d0\u5347\u5668&#xff0c;\u800c\u975e\u7edd\u5bf9\u5c4f\u969c&#xff1a;\u5176\u5b89\u5168\u4ef7\u503c\u5728\u4e8e\u589e\u52a0\u653b\u51fb\u6210\u672c&#xff0c;\u8bbe\u8ba1\u65f6\u5fc5\u987b\u6743\u8861\u5b89\u5168\u4e0e\u4f53\u9a8c\u3002<\/li>\n<li>\u903b\u8f91\u6f0f\u6d1e\u662f\u4e3b\u8981\u7a81\u7834\u53e3&#xff1a;\u6d4b\u8bd5\u5e94\u4f18\u5148\u5173\u6ce8\u9a8c\u8bc1\u7801\u7684\u751f\u547d\u5468\u671f\u7ba1\u7406&#xff08;\u751f\u6210\u3001\u5b58\u50a8\u3001\u9a8c\u8bc1\u3001\u9500\u6bc1&#xff09;\u548c\u4e0e\u4e1a\u52a1\u6d41\u7684\u7ed1\u5b9a\u5173\u7cfb&#xff0c;\u8fd9\u4e9b\u5730\u65b9\u5f80\u5f80\u5b58\u5728\u53ef\u91cd\u653e\u3001\u53ef\u7ed5\u8fc7\u3001\u53ef\u9884\u6d4b\u7684\u81f4\u547d\u7f3a\u9677\u3002<\/li>\n<li>\u6280\u672f\u8bc6\u522b\u662f\u519b\u5907\u7ade\u8d5b&#xff1a;\u4ece\u4f20\u7edfOCR\u5230\u6df1\u5ea6\u5b66\u4e60&#xff0c;\u653b\u51fb\u6280\u672f\u4e0d\u65ad\u8fdb\u5316\u3002\u9632\u5fa1\u65b9\u9700\u91c7\u7528\u52a8\u6001\u5316\u3001\u884c\u4e3a\u5f0f\u3001\u591a\u6a21\u6001\u7684\u9a8c\u8bc1\u624b\u6bb5&#xff08;\u5982\u65e0\u611f\u9a8c\u8bc1&#xff09;\u3002<\/li>\n<li>\u9632\u5fa1\u9700\u8981\u5168\u6808\u89c6\u89d2&#xff1a;\u4ece\u540e\u7aef\u7684\u539f\u5b50\u5316\u9a8c\u8bc1\u903b\u8f91\u3001\u5b89\u5168\u7684\u5b58\u50a8&#xff0c;\u5230\u524d\u7aef\u7684\u4ea4\u4e92\u4fdd\u62a4&#xff0c;\u518d\u5230\u8fd0\u7ef4\u5c42\u7684\u9891\u7387\u9650\u5236\u548c\u5a01\u80c1\u60c5\u62a5&#xff0c;\u7f3a\u4e00\u4e0d\u53ef\u3002<\/li>\n<li>\u6d4b\u8bd5\u9700\u65b9\u6cd5\u8bba\u6307\u5f15&#xff1a;\u9075\u5faa\u201c\u4fe1\u606f\u6536\u96c6 -&gt; \u903b\u8f91\u5206\u6790 -&gt; \u6280\u672f\u5bf9\u6297\u201d\u7684\u6d41\u7a0b&#xff0c;\u7cfb\u7edf\u5316\u5730\u8bc4\u4f30\u9a8c\u8bc1\u7801\u7684\u6bcf\u4e00\u4e2a\u653b\u51fb\u9762\u3002<\/li>\n<p>\u77e5\u8bc6\u4f53\u7cfb\u8fde\u63a5<\/p>\n<p>\u672c\u6587\u662f\u201c\u4e1a\u52a1\u903b\u8f91\u5b89\u5168\u201d\u4e0e\u201c\u81ea\u52a8\u5316\u653b\u51fb\u5bf9\u6297\u201d\u77e5\u8bc6\u57df\u4e0b\u7684\u6838\u5fc3\u7bc7\u7ae0\u3002<\/p>\n<p>\u00b7 \u524d\u5e8f\u57fa\u7840&#xff1a; \u00b7 Web\u6e17\u900f\u6d4b\u8bd5\u57fa\u7840&#xff1a;HTTP\u534f\u8bae\u3001Burp Suite\u4f7f\u7528\u3001\u4f1a\u8bdd\u7ba1\u7406\u3002 \u00b7 \u5e38\u89c1\u903b\u8f91\u6f0f\u6d1e&#xff1a;\u8d8a\u6743\u3001\u6d41\u7a0b\u7ed5\u8fc7&#xff0c;\u8fd9\u4e9b\u662f\u5206\u6790\u9a8c\u8bc1\u7801\u903b\u8f91\u7f3a\u9677\u7684\u601d\u7ef4\u57fa\u7840\u3002 \u00b7 \u540e\u7ee7\u8fdb\u9636&#xff1a; \u00b7 \u81ea\u52a8\u5316\u653b\u51fb\u4e0eBot\u7ba1\u7406&#xff1a;\u5982\u4f55\u8bbe\u8ba1\u66f4\u5065\u58ee\u7684\u4f53\u7cfb\u6765\u533a\u5206\u6076\u610fBot\u548c\u5584\u610f\u722c\u866b\u3002 \u00b7 AI\u5728\u5b89\u5168\u4e2d\u7684\u5e94\u7528\u4e0e\u5bf9\u6297&#xff1a;\u6df1\u5165\u4e86\u89e3\u6df1\u5ea6\u5b66\u4e60\u5982\u4f55\u7528\u4e8e\u751f\u6210\u5bf9\u6297\u6837\u672c&#xff08;\u653b\u51fb&#xff09;\u548c\u68c0\u6d4b\u5f02\u5e38\u884c\u4e3a&#xff08;\u9632\u5fa1&#xff09;\u3002 \u00b7 \u79fb\u52a8\u7aef\/API\u5b89\u5168&#xff1a;\u9a8c\u8bc1\u7801\u5728APP\u548cAPI\u63a5\u53e3\u4e2d\u7684\u7279\u6b8a\u5b9e\u73b0\u4e0e\u5b89\u5168\u95ee\u9898\u3002<\/p>\n<p>\u8fdb\u9636\u65b9\u5411\u6307\u5f15<\/p>\n<li>\u65e0\u611f\u9a8c\u8bc1\u4e0e\u53cd\u65e0\u611f\u9a8c\u8bc1&#xff1a;\u6df1\u5165\u7814\u7a76\u4e3b\u6d41\u201c\u65e0\u611f\u9a8c\u8bc1\u201d\u670d\u52a1&#xff08;\u5982reCAPTCHA v3&#xff09;\u7684\u5de5\u4f5c\u539f\u7406\u3002\u653b\u51fb\u8005\u5982\u4f55\u901a\u8fc7\u6a21\u62df\u66f4\u7cbe\u7ec6\u7684\u6d4f\u89c8\u5668\u6307\u7eb9\u3001\u7f51\u7edc\u73af\u5883\u548c\u7528\u6237\u884c\u4e3a\u6765\u751f\u6210\u9ad8\u5206\u7684token&#xff1f;\u9632\u5fa1\u8005\u5982\u4f55\u66f4\u6709\u6548\u5730\u914d\u7f6e\u5206\u6570\u9608\u503c\u548c\u884c\u4e3a\u5206\u6790\u6a21\u578b&#xff1f;<\/li>\n<li>\u8054\u90a6\u5b66\u4e60\u4e0e\u9690\u79c1\u4fdd\u62a4\u9a8c\u8bc1\u7801&#xff1a;\u8fd9\u662f\u4e00\u4e2a\u524d\u6cbf\u8d8b\u52bf\u3002\u80fd\u5426\u5728\u4fdd\u62a4\u7528\u6237\u9690\u79c1&#xff08;\u4e0d\u4e0a\u4f20\u539f\u59cb\u884c\u4e3a\u6570\u636e&#xff09;\u7684\u524d\u63d0\u4e0b&#xff0c;\u901a\u8fc7\u8054\u90a6\u5b66\u4e60\u7684\u65b9\u5f0f&#xff0c;\u8ba9\u591a\u4e2a\u7ad9\u70b9\u5171\u540c\u8bad\u7ec3\u4e00\u4e2a\u66f4\u5f3a\u5927\u7684\u201c\u4eba\u7c7b\u884c\u4e3a\u6a21\u578b\u201d&#xff1f;\u8fd9\u5176\u4e2d\u7684\u5b89\u5168\u4e0e\u9690\u79c1\u6311\u6218\u662f\u4ec0\u4e48&#xff1f;<\/li>\n<hr \/>\n<p>\u81ea\u68c0\u6e05\u5355<\/p>\n<p>\u00b7 \u662f\u5426\u660e\u786e\u5b9a\u4e49\u4e86\u672c\u4e3b\u9898\u7684\u4ef7\u503c\u4e0e\u5b66\u4e60\u76ee\u6807&#xff1f; \u672c\u6587\u5f00\u7bc7\u5373\u9610\u660e\u9a8c\u8bc1\u7801\u4f5c\u4e3a\u5173\u952e\u9632\u7ebf\u7684\u6218\u7565\u4ef7\u503c&#xff0c;\u5e76\u5217\u51fa5\u4e2a\u5177\u4f53\u53ef\u8861\u91cf\u7684\u5b66\u4e60\u76ee\u6807\u3002 \u00b7 \u539f\u7406\u90e8\u5206\u662f\u5426\u5305\u542b\u4e00\u5f20\u81ea\u89e3\u91ca\u7684Mermaid\u6838\u5fc3\u673a\u5236\u56fe&#xff1f; \u7b2c\u4e8c\u90e8\u5206\u5305\u542b\u4e86\u4e00\u5f20\u5b8c\u6574\u7684\u9a8c\u8bc1\u7801\u7cfb\u7edf\u5de5\u4f5c\u6d41\u7a0b\u4e0e\u653b\u51fb\u9762\u5256\u6790\u56fe&#xff0c;\u662f\u5168\u6587\u7684\u89c6\u89c9\u951a\u70b9\u3002 \u00b7 \u5b9e\u6218\u90e8\u5206\u662f\u5426\u5305\u542b\u4e00\u4e2a\u53ef\u8fd0\u884c\u7684\u3001\u6ce8\u91ca\u8be6\u5c3d\u7684\u4ee3\u7801\u7247\u6bb5&#xff1f; \u7b2c\u4e09\u90e8\u5206\u63d0\u4f9b\u4e86\u4ece\u7b80\u5355OCR\u3001\u6ed1\u52a8\u8ddd\u79bb\u8ba1\u7b97\u5230\u6846\u67b6\u8bbe\u8ba1\u7684\u591a\u4e2a\u4ee3\u7801\u793a\u4f8b&#xff0c;\u5747\u5305\u542b\u8be6\u7ec6\u6ce8\u91ca\u548c\u5b89\u5168\u8b66\u544a\u3002 \u00b7 \u9632\u5fa1\u90e8\u5206\u662f\u5426\u63d0\u4f9b\u4e86\u81f3\u5c11\u4e00\u4e2a\u5177\u4f53\u7684\u5b89\u5168\u4ee3\u7801\u793a\u4f8b\u6216\u914d\u7f6e\u65b9\u6848&#xff1f; \u7b2c\u56db\u90e8\u5206\u901a\u8fc7\u201c\u5371\u9669\u6a21\u5f0f vs \u5b89\u5168\u6a21\u5f0f\u201d\u7684\u4ee3\u7801\u5bf9\u6bd4&#xff0c;\u8be6\u7ec6\u5c55\u793a\u4e86\u9a8c\u8bc1\u7801\u751f\u6210\u3001\u5b58\u50a8\u3001\u9a8c\u8bc1\u7684\u5b89\u5168\u7f16\u7801\u8303\u5f0f\u3002 \u00b7 \u662f\u5426\u5efa\u7acb\u4e86\u4e0e\u77e5\u8bc6\u5927\u7eb2\u4e2d\u5176\u4ed6\u6587\u7ae0\u7684\u8054\u7cfb&#xff1f; \u7b2c\u4e94\u90e8\u5206\u660e\u786e\u6307\u51fa\u4e86\u4e0e\u524d\u5e8f&#xff08;Web\u57fa\u7840\u3001\u903b\u8f91\u6f0f\u6d1e&#xff09;\u548c\u540e\u7ee7&#xff08;Bot\u7ba1\u7406\u3001AI\u5b89\u5168&#xff09;\u77e5\u8bc6\u7684\u8fde\u63a5\u3002 \u00b7 \u5168\u6587\u662f\u5426\u907f\u514d\u4e86\u672a\u5b9a\u4e49\u7684\u672f\u8bed\u548c\u6a21\u7cca\u8868\u8ff0&#xff1f; \u6587\u4e2d\u6240\u6709\u5173\u952e\u672f\u8bed&#xff08;\u5982\u9a8c\u8bc1\u7801\u3001\u539f\u5b50\u64cd\u4f5c\u3001OCR\u7b49&#xff09;\u5747\u5728\u9996\u6b21\u51fa\u73b0\u65f6\u8fdb\u884c\u4e86\u89e3\u91ca\u6216\u52a0\u7c97\u5f3a\u8c03&#xff0c;\u8bba\u8ff0\u529b\u6c42\u4e25\u8c28\u6e05\u6670\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u7b2c\u4e00\u90e8\u5206&#xff1a;\u5f00\u7bc7\u660e\u4e49 \u2014\u2014 \u5b9a\u4e49\u3001\u4ef7\u503c\u4e0e\u76ee\u6807<br \/>\n\u5728\u5f53\u4eca\u7684\u4e92\u8054\u7f51\u5b89\u5168\u4f53\u7cfb\u4e2d&#xff0c;\u9a8c\u8bc1\u7801 \u4f5c\u4e3a\u4e00\u79cd\u533a\u5206\u4eba\u7c7b\u7528\u6237\u4e0e\u81ea\u52a8\u5316\u7a0b\u5e8f\u7684\u56fe\u7075\u6d4b\u8bd5\u53d8\u4f53&#xff0c;\u5df2\u6210\u4e3a\u4fdd\u62a4Web\u5e94\u7528\u3001API\u63a5\u53e3\u548c\u5173\u952e\u4e1a\u52a1\u903b\u8f91\u7684\u7b2c\u4e00\u9053\u3001\u4e5f\u5f80\u5f80\u662f\u6700\u8106\u5f31\u7684\u4e00\u9053\u9632\u7ebf\u3002\u5b83\u6a2a\u8de8\u5728\u8eab\u4efd\u8ba4\u8bc1\u3001\u4ea4\u6613\u786e\u8ba4\u3001\u9632\u722c\u866b\u548c\u9632\u66b4\u529b\u7834\u89e3\u7b49\u591a\u4e2a\u5173\u952e\u5b89\u5168\u8282\u70b9\u4e0a\u3002\u56e0\u6b64&#xff0c;\u5bf9\u9a8c\u8bc1\u7801\u673a\u5236\u7684\u5b89\u5168\u6027\u8fdb\u884c\u8bc4\u4f30&#xff0c;\u4e0d\u518d\u662f\u6e17\u900f\u6d4b\u8bd5\u4e2d\u7684\u4e00\u4e2a\u53ef\u9009\u6b65\u9aa4&#xff0c;\u800c\u662f\u8bc4\u4f30\u76ee\u6807\u7cfb\u7edf\u6574\u4f53\u5b89\u5168\u6210\u719f\u5ea6\u7684\u6838\u5fc3\u8bd5\u91d1\u77f3\u3002\u4e00\u4e2a\u8bbe<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[50,2961,122],"topic":[],"class_list":["post-65604","post","type-post","status-publish","format-standard","hentry","category-server","tag-50","tag-2961","tag-122"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v20.3 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>\u9a8c\u8bc1\u7801\u673a\u5236\u7684\u5b89\u5168\u6027\u6d4b\u8bd5\uff1a\u4ece\u903b\u8f91\u7f3a\u9677\u5230AI\u5bf9\u6297\u7684\u5168\u666f\u5256\u6790 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.wsisp.com\/helps\/65604.html\" \/>\n<meta property=\"og:locale\" content=\"zh_CN\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\u9a8c\u8bc1\u7801\u673a\u5236\u7684\u5b89\u5168\u6027\u6d4b\u8bd5\uff1a\u4ece\u903b\u8f91\u7f3a\u9677\u5230AI\u5bf9\u6297\u7684\u5168\u666f\u5256\u6790 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3\" \/>\n<meta property=\"og:description\" content=\"\u7b2c\u4e00\u90e8\u5206&#xff1a;\u5f00\u7bc7\u660e\u4e49 \u2014\u2014 \u5b9a\u4e49\u3001\u4ef7\u503c\u4e0e\u76ee\u6807 \u5728\u5f53\u4eca\u7684\u4e92\u8054\u7f51\u5b89\u5168\u4f53\u7cfb\u4e2d&#xff0c;\u9a8c\u8bc1\u7801 \u4f5c\u4e3a\u4e00\u79cd\u533a\u5206\u4eba\u7c7b\u7528\u6237\u4e0e\u81ea\u52a8\u5316\u7a0b\u5e8f\u7684\u56fe\u7075\u6d4b\u8bd5\u53d8\u4f53&#xff0c;\u5df2\u6210\u4e3a\u4fdd\u62a4Web\u5e94\u7528\u3001API\u63a5\u53e3\u548c\u5173\u952e\u4e1a\u52a1\u903b\u8f91\u7684\u7b2c\u4e00\u9053\u3001\u4e5f\u5f80\u5f80\u662f\u6700\u8106\u5f31\u7684\u4e00\u9053\u9632\u7ebf\u3002\u5b83\u6a2a\u8de8\u5728\u8eab\u4efd\u8ba4\u8bc1\u3001\u4ea4\u6613\u786e\u8ba4\u3001\u9632\u722c\u866b\u548c\u9632\u66b4\u529b\u7834\u89e3\u7b49\u591a\u4e2a\u5173\u952e\u5b89\u5168\u8282\u70b9\u4e0a\u3002\u56e0\u6b64&#xff0c;\u5bf9\u9a8c\u8bc1\u7801\u673a\u5236\u7684\u5b89\u5168\u6027\u8fdb\u884c\u8bc4\u4f30&#xff0c;\u4e0d\u518d\u662f\u6e17\u900f\u6d4b\u8bd5\u4e2d\u7684\u4e00\u4e2a\u53ef\u9009\u6b65\u9aa4&#xff0c;\u800c\u662f\u8bc4\u4f30\u76ee\u6807\u7cfb\u7edf\u6574\u4f53\u5b89\u5168\u6210\u719f\u5ea6\u7684\u6838\u5fc3\u8bd5\u91d1\u77f3\u3002\u4e00\u4e2a\u8bbe\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.wsisp.com\/helps\/65604.html\" \/>\n<meta property=\"og:site_name\" content=\"\u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3\" \/>\n<meta property=\"article:published_time\" content=\"2026-01-25T05:04:47+00:00\" \/>\n<meta name=\"author\" content=\"admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u4f5c\u8005\" \/>\n\t<meta name=\"twitter:data1\" content=\"admin\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4\" \/>\n\t<meta name=\"twitter:data2\" content=\"11 \u5206\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/65604.html\",\"url\":\"https:\/\/www.wsisp.com\/helps\/65604.html\",\"name\":\"\u9a8c\u8bc1\u7801\u673a\u5236\u7684\u5b89\u5168\u6027\u6d4b\u8bd5\uff1a\u4ece\u903b\u8f91\u7f3a\u9677\u5230AI\u5bf9\u6297\u7684\u5168\u666f\u5256\u6790 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3\",\"isPartOf\":{\"@id\":\"https:\/\/www.wsisp.com\/helps\/#website\"},\"datePublished\":\"2026-01-25T05:04:47+00:00\",\"dateModified\":\"2026-01-25T05:04:47+00:00\",\"author\":{\"@id\":\"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/358e386c577a3ab51c4493330a20ad41\"},\"breadcrumb\":{\"@id\":\"https:\/\/www.wsisp.com\/helps\/65604.html#breadcrumb\"},\"inLanguage\":\"zh-Hans\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.wsisp.com\/helps\/65604.html\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/65604.html#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\u9996\u9875\",\"item\":\"https:\/\/www.wsisp.com\/helps\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"\u9a8c\u8bc1\u7801\u673a\u5236\u7684\u5b89\u5168\u6027\u6d4b\u8bd5\uff1a\u4ece\u903b\u8f91\u7f3a\u9677\u5230AI\u5bf9\u6297\u7684\u5168\u666f\u5256\u6790\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/#website\",\"url\":\"https:\/\/www.wsisp.com\/helps\/\",\"name\":\"\u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3\",\"description\":\"\u9999\u6e2f\u670d\u52a1\u5668_\u9999\u6e2f\u4e91\u670d\u52a1\u5668\u8d44\u8baf_\u670d\u52a1\u5668\u5e2e\u52a9\u6587\u6863_\u670d\u52a1\u5668\u6559\u7a0b\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.wsisp.com\/helps\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"zh-Hans\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/358e386c577a3ab51c4493330a20ad41\",\"name\":\"admin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/gravatar.wp-china-yes.net\/avatar\/?s=96&d=mystery\",\"contentUrl\":\"https:\/\/gravatar.wp-china-yes.net\/avatar\/?s=96&d=mystery\",\"caption\":\"admin\"},\"sameAs\":[\"http:\/\/wp.wsisp.com\"],\"url\":\"https:\/\/www.wsisp.com\/helps\/author\/admin\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"\u9a8c\u8bc1\u7801\u673a\u5236\u7684\u5b89\u5168\u6027\u6d4b\u8bd5\uff1a\u4ece\u903b\u8f91\u7f3a\u9677\u5230AI\u5bf9\u6297\u7684\u5168\u666f\u5256\u6790 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.wsisp.com\/helps\/65604.html","og_locale":"zh_CN","og_type":"article","og_title":"\u9a8c\u8bc1\u7801\u673a\u5236\u7684\u5b89\u5168\u6027\u6d4b\u8bd5\uff1a\u4ece\u903b\u8f91\u7f3a\u9677\u5230AI\u5bf9\u6297\u7684\u5168\u666f\u5256\u6790 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","og_description":"\u7b2c\u4e00\u90e8\u5206&#xff1a;\u5f00\u7bc7\u660e\u4e49 \u2014\u2014 \u5b9a\u4e49\u3001\u4ef7\u503c\u4e0e\u76ee\u6807 \u5728\u5f53\u4eca\u7684\u4e92\u8054\u7f51\u5b89\u5168\u4f53\u7cfb\u4e2d&#xff0c;\u9a8c\u8bc1\u7801 \u4f5c\u4e3a\u4e00\u79cd\u533a\u5206\u4eba\u7c7b\u7528\u6237\u4e0e\u81ea\u52a8\u5316\u7a0b\u5e8f\u7684\u56fe\u7075\u6d4b\u8bd5\u53d8\u4f53&#xff0c;\u5df2\u6210\u4e3a\u4fdd\u62a4Web\u5e94\u7528\u3001API\u63a5\u53e3\u548c\u5173\u952e\u4e1a\u52a1\u903b\u8f91\u7684\u7b2c\u4e00\u9053\u3001\u4e5f\u5f80\u5f80\u662f\u6700\u8106\u5f31\u7684\u4e00\u9053\u9632\u7ebf\u3002\u5b83\u6a2a\u8de8\u5728\u8eab\u4efd\u8ba4\u8bc1\u3001\u4ea4\u6613\u786e\u8ba4\u3001\u9632\u722c\u866b\u548c\u9632\u66b4\u529b\u7834\u89e3\u7b49\u591a\u4e2a\u5173\u952e\u5b89\u5168\u8282\u70b9\u4e0a\u3002\u56e0\u6b64&#xff0c;\u5bf9\u9a8c\u8bc1\u7801\u673a\u5236\u7684\u5b89\u5168\u6027\u8fdb\u884c\u8bc4\u4f30&#xff0c;\u4e0d\u518d\u662f\u6e17\u900f\u6d4b\u8bd5\u4e2d\u7684\u4e00\u4e2a\u53ef\u9009\u6b65\u9aa4&#xff0c;\u800c\u662f\u8bc4\u4f30\u76ee\u6807\u7cfb\u7edf\u6574\u4f53\u5b89\u5168\u6210\u719f\u5ea6\u7684\u6838\u5fc3\u8bd5\u91d1\u77f3\u3002\u4e00\u4e2a\u8bbe","og_url":"https:\/\/www.wsisp.com\/helps\/65604.html","og_site_name":"\u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","article_published_time":"2026-01-25T05:04:47+00:00","author":"admin","twitter_card":"summary_large_image","twitter_misc":{"\u4f5c\u8005":"admin","\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4":"11 \u5206"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.wsisp.com\/helps\/65604.html","url":"https:\/\/www.wsisp.com\/helps\/65604.html","name":"\u9a8c\u8bc1\u7801\u673a\u5236\u7684\u5b89\u5168\u6027\u6d4b\u8bd5\uff1a\u4ece\u903b\u8f91\u7f3a\u9677\u5230AI\u5bf9\u6297\u7684\u5168\u666f\u5256\u6790 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","isPartOf":{"@id":"https:\/\/www.wsisp.com\/helps\/#website"},"datePublished":"2026-01-25T05:04:47+00:00","dateModified":"2026-01-25T05:04:47+00:00","author":{"@id":"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/358e386c577a3ab51c4493330a20ad41"},"breadcrumb":{"@id":"https:\/\/www.wsisp.com\/helps\/65604.html#breadcrumb"},"inLanguage":"zh-Hans","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.wsisp.com\/helps\/65604.html"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.wsisp.com\/helps\/65604.html#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\u9996\u9875","item":"https:\/\/www.wsisp.com\/helps"},{"@type":"ListItem","position":2,"name":"\u9a8c\u8bc1\u7801\u673a\u5236\u7684\u5b89\u5168\u6027\u6d4b\u8bd5\uff1a\u4ece\u903b\u8f91\u7f3a\u9677\u5230AI\u5bf9\u6297\u7684\u5168\u666f\u5256\u6790"}]},{"@type":"WebSite","@id":"https:\/\/www.wsisp.com\/helps\/#website","url":"https:\/\/www.wsisp.com\/helps\/","name":"\u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","description":"\u9999\u6e2f\u670d\u52a1\u5668_\u9999\u6e2f\u4e91\u670d\u52a1\u5668\u8d44\u8baf_\u670d\u52a1\u5668\u5e2e\u52a9\u6587\u6863_\u670d\u52a1\u5668\u6559\u7a0b","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.wsisp.com\/helps\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"zh-Hans"},{"@type":"Person","@id":"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/358e386c577a3ab51c4493330a20ad41","name":"admin","image":{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/image\/","url":"https:\/\/gravatar.wp-china-yes.net\/avatar\/?s=96&d=mystery","contentUrl":"https:\/\/gravatar.wp-china-yes.net\/avatar\/?s=96&d=mystery","caption":"admin"},"sameAs":["http:\/\/wp.wsisp.com"],"url":"https:\/\/www.wsisp.com\/helps\/author\/admin"}]}},"_links":{"self":[{"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/posts\/65604","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/comments?post=65604"}],"version-history":[{"count":0,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/posts\/65604\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/media?parent=65604"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/categories?post=65604"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/tags?post=65604"},{"taxonomy":"topic","embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/topic?post=65604"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}