fix checkSSRF
This commit is contained in:
@@ -17,8 +17,6 @@
|
||||
security checkUrl = new security();
|
||||
String[] urlWList = {"joychou.com", "joychou.me"};
|
||||
Boolean ret = checkUrl.checkUrlWlist("http://test.joychou.me", urlWList);
|
||||
System.out.println(ret);
|
||||
|
||||
```
|
||||
|
||||
## SSRF
|
||||
@@ -36,11 +34,9 @@ JAVA默认dns请求会有30s的缓存,所以默认不存在dns rebind问题。
|
||||
### 验证代码
|
||||
|
||||
如果是内网IP,返回false,表示checkSSRF不通过,否则返回true,即合法返回true。
|
||||
|
||||
URL只支持HTTP协议。
|
||||
|
||||
```java
|
||||
security checkUrl = new security();
|
||||
ret = checkUrl.checkSSRF("http://127.0.0.1");
|
||||
System.out.println(ret);
|
||||
```
|
||||
|
||||
Reference in New Issue
Block a user