Nginx定义HEAD用到的是$http_head参数,head就是自定义的header名称HEAD
$cookie_[COOKIE_NAME]
$http_[HEADER_NAME]
# nginx记录cookie或者header里面的值
nginx日志
/usr/local/nginx/conf/nginx.conf
log_format main '{"timestamp":"$time_iso8601",'
'"remote_addr":"$remote_addr",'
'"remote_user":"$remote_user",'
'"time_local":"$time_local",'
'"request":"$request",'
'"response_time":$request_time,'
'"status":"$status",'
'"body_bytes_sent":"$body_bytes_sent",'
'"http_referer": "$http_referer",'
'"http_user_agent":"$http_user_agent",'
'"http_x_forwarded_for":"$http_x_forwarded_for",'
'"server_name":"$server_name",'
'"upstream_addr":"$upstream_addr",'
'"upstream_response_time":"$upstream_response_time",'
'"upstream_status":"$upstream_status",'
'"sn":"$http_sn",'
'"version":"$http_version",'
'"comment":"$http_comment"'
'}';
测试
test.py
import requests
headers = {"Accept": "text/html,application/xhtml+xml,application/xml;",
"User-Agent": "Chrome/42.0.2311.90",
"sn":"2019111111111",
"version":"android_v1",
"comment":"test1"
}
url = 'https://attacker.club'
response = requests.get(url,headers=headers)
# print(response.text)
效果图
转载于:https://my.oschina.net/attacker/blog/3048227