## 点击时间后,Firefox Developer Tools 给出的 Post 内容:
https://fr.tlscontact.com/country/city/action.php?process=multiconfirm&what=take_appointment&fg_id= 66666666666&result=dateandtime&issuer_view=countrycity2fr&issuer_view=&target=ajax_form_status&time=now&_sid=bazhahei
## 同操作 Burp 给出的 Post 内容:
POST /country/city/ajax/confirm_action.php HTTP/1.1
Host:
fr.tlscontact.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.12; rv:58.0) Gecko/20100101 Firefox/58.0
Accept: text/javascript, text/html, application/xml, text/xml, */*
Accept-Language: en-US,en;q=0.5
Referer:
https://fr.tlscontact.com/country/city/myapp.php?fg_id=66666666666
X-Requested-With: XMLHttpRequest
X-Prototype-Version: 1.7
Content-type: application/x-www-form-urlencoded; charset=UTF-8
Content-Length: 281
Cookie: TLScontact=biu; uid=blah; _ga=mua; _gid=pia; TLScontact=duang
Connection: close
https://fr.tlscontact.com/country/city/action.php?process=multiconfirm&what=take_appointment&fg_id= 66666666666&result=dateandtime&issuer_view=countrycity2fr&issuer_view=&target=ajax_form_status&time=now&_sid=bazhahei
## 点击弹出框框中的确认按钮后,Burp 给出的内容:
POST /country/city/action.php HTTP/1.1
Host:
fr.tlscontact.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.12; rv:58.0) Gecko/20100101 Firefox/58.0
Accept: text/javascript, text/html, application/xml, text/xml, */*
Accept-Language: en-US,en;q=0.5
Referer:
https://fr.tlscontact.com/gb/LON/myapp.php?fg_id= 66666666666
X-Requested-With: XMLHttpRequest
X-Prototype-Version: 1.7
Content-type: application/x-www-form-urlencoded; charset=UTF-8
Content-Length: 170
Cookie: TLScontact= biu; uid= blah; _ga=mua; _gid= pia; TLScontact= duang; _dc_gtm_UA-28256030-1=1
Connection: close
f_id=&fg_id= 66666666666&what=take_appointment&result=dateandtime&as_u_id=&_sid= bazhahei&process=multiconfirm&reloader_timestamp=(now+1s)
以上值替换了 ID 之类的数据,所以我如果相约这个时间,道到底应该 post 什么呢?
这 [脏话] 网站,定了预约不能自行立即取消,最后一步不能盲目测试啊……