xlrtx吧 关注:6贴子:217

拆解掌上百度

只看楼主收藏回复

.rdata:0015D578 00000068 unicode http://%s/bbs-common/mobile.mo?src=%s&uid=%s&cnf=%s                                                                                                   
.rdata:0015D614 00000010 unicode &from=0                                                                                                                                               
.rdata:0015D624 0000000E unicode &from=                                                                                                                                                
.rdata:0015D638 00000042 unicode http://t.baidu.com/check?uid=bd_                                                                                                                      



1楼2011-03-26 16:06回复
    .rdata:0015D67C 00000010 unicode http://                                                                                                                                               
    .rdata:0015D68C 0000000A unicode &ua=                                                                                                                                                  
    .rdata:0015D6AC 0000003C unicode http://r1.mo.baidu.com/parse/                                                                                                                         
    .rdata:0015D6E8 00000050 unicode http://220.181.27.28:10000/tabinfo.gbza                                                                                                               
    .rdata:0015D738 00000046 unicode http://220.181.27.28:10000/active?                                                                                                                    
    


    2楼2011-03-26 16:06
    回复
      .rdata:0015D780 0000001A unicode r1.3gtan.net                                                                                                                                          
      .rdata:0015D79C 0000001A unicode r2.3gtan.net                         


      3楼2011-03-26 16:06
      回复
        .rdata:00160D64 0000002A unicode /space/blogcont.gbza                                                                                                                                  
        .rdata:00160D90 00000028 unicode /space/piclist.gbza                                                                                                                                   
        .rdata:00160DB8 00000022 unicode /space/info.gbza     


        4楼2011-03-26 16:06
        回复
          5楼2011-03-26 16:08
          回复
            <go href="baidu://t.baidu.com/tieba2/newsubject?" method="post">
            <postfield name="ti" not_null="1" err_msg="标题不允许为空" value="$(title)" />
            <postfield name="co" value="$(article)" />
            <postfield name="rs1" value="1" />
            <postfield name="value" value="" />
            <postfield name="ct" value="385875968" />
            <postfield name="tn" value="baiduWiseSubmit" />
            <postfield name="word" value="4king" />
            <postfield name="lm" value="1621225" />
            <postfield name="z" value="0" />
            <postfield name="sc" value="0" />
            <postfield name="cm" value="0" />
            <postfield name="bs" value="" />
            <postfield name="str1" value="" />
            <postfield name="code" value="" />
            <postfield name="rs4" value="" />
            <postfield name="str2" value="" />
            <postfield name="str3" value="7AA00225272AC764F6B2E4D8BAD4BC86" />
            <postfield name="str4" value="5f2cdaacf5d03098" />
            <postfield name="richba" value="1" />
            <postfield name="upimages" value="$(des_pic)"/>
            </go>
            我可真无聊= =


            6楼2011-03-26 16:37
            回复
              以上来自
              t.baidu.com/tieba2/getpostpage?type=Subject&word=
              有兴趣一起讨论~


              7楼2011-03-26 16:43
              回复
                关键在于弄清gbza,掌百目前已无价值,研究tieba2吧,我认为百度会有新产品放在tieba2


                8楼2011-03-26 23:06
                回复
                  回复:8楼
                  gbza加密要靠大牛去逆向分析了..
                  那些东西是从ppc版掌上百度里提取出来的
                  刚才也看了下tieba2,这个应该是老版本掌上百度用的
                  掌上百度第一个版本就再用,不过现在不知道是不是都已经换成了gbza
                  不过tieba2现在的确可以用,而且可以很容易的无验证码发帖,好欢乐啊
                  百度为了赚钱吧东西弄复杂了漏洞就是多


                  9楼2011-03-26 23:28
                  回复
                    回复:8楼
                    tieba2不可以在未登录的情况下回复帖子,ppc上运行老版本(tieba2)也会提示某些功能不可用
                    前阵子出现看帖自动回复的爆吧情况估计就是这弄的,不知道百度为什么只是吧未登录回复帖子功能限制,而不是彻底取消tieba2.


                    10楼2011-03-26 23:34
                    回复
                      <go href="baidu://t.baidu.com/tieba2/newsubject?" method="post">
                      <postfield name="ti" not_null="1" err_msg="标题不允许为空" value="$(title)" />
                      <postfield name="co" value="$(article)" />
                      <postfield name="rs1" value="1" />
                      <postfield name="value" value="" />
                      <postfield name="ct" value="385875968" />
                      <postfield name="tn" value="baiduWiseSubmit" />
                      <postfield name="word" value="4king" />
                      <postfield name="lm" value="1621225" />
                      <postfield name="z" value="0" />
                      <postfield name="sc" value="0" />
                      <postfield name="cm" value="0" />
                      <postfield name="bs" value="" />
                      <postfield name="str1" value="" />
                      <postfield name="code" value="" />
                      <postfield name="rs4" value="" />
                      <postfield name="str2" value="" />
                      <postfield name="str3" value="7AA00225272AC764F6B2E4D8BAD4BC86" />
                      <postfield name="str4" value="5f2cdaacf5d03098" />
                      <postfield name="richba" value="1" />
                      <postfield name="upimages" value="$(des_pic)"/>
                      </go>
                      


                      IP属地:四川11楼2011-03-26 23:38
                      回复
                        gbza已经研究出来了,就是个压缩算法适应手机的
                        不过我不明白为什么跟说吧联系到一块了,难道是搞手机围脖?


                        12楼2011-03-27 09:39
                        回复
                          tieba2的发帖器基本做好了\(^o^)/~
                          可能有个xss有空看下


                          14楼2011-03-27 22:18
                          回复
                            不知道是漏洞被封了还是ip被封了


                            15楼2011-03-28 15:51
                            回复
                              嘿嘿,被封啦
                              有百度工作人员在看这个贴子好荣幸=3=


                              16楼2011-03-28 16:56
                              回复