标题:
[TheWorld 3]
求新疆电信的广告过滤,内付详细抓包文件。
[打印本页]
作者:
hanchaohui
时间:
2010-7-30 21:32
标题:
求新疆电信的广告过滤,内付详细抓包文件。
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD><TITLE>信息包流格式报告</TITLE>
<META http-equiv=Content-Type content="text/html; charset=gb2312">
<META content="MSHTML 6.00.2900.5583" name=GENERATOR></HEAD>
<BODY>
<H3>信息包流格式报告</H3>
<TABLE cellPadding=5 border=1>
<TBODY>
<TR>
<TD noWrap bgColor=#e0e0e0><B>索引</B>
<TD noWrap bgColor=#fffff0>25
<TR>
<TD noWrap bgColor=#e0e0e0><B>协议</B>
<TD noWrap bgColor=#fffdf0>TCP
<TR>
<TD noWrap bgColor=#e0e0e0><B>本地地址</B>
<TD noWrap bgColor=#fffcf0>192.168.112.128
<TR>
<TD noWrap bgColor=#e0e0e0><B>远程地址</B>
<TD noWrap bgColor=#fffaf0>61.128.96.237
<TR>
<TD noWrap bgColor=#e0e0e0><B>本地端口</B>
<TD noWrap bgColor=#fff9f0>2153
<TR>
<TD noWrap bgColor=#e0e0e0><B>远程端口</B>
<TD noWrap bgColor=#fff7f0>80
<TR>
<TD noWrap bgColor=#e0e0e0><B>本地主机</B>
<TD noWrap bgColor=#fff6f0>china-e09d91faa.localdomain
<TR>
<TD noWrap bgColor=#e0e0e0><B>远程主机</B>
<TD noWrap bgColor=#fff4f0>
<TR>
<TD noWrap bgColor=#e0e0e0><B>服务名称</B>
<TD noWrap bgColor=#fff3f0>http
<TR>
<TD noWrap bgColor=#e0e0e0><B>信息包</B>
<TD noWrap bgColor=#fff1f0>22
<TR>
<TD noWrap bgColor=#e0e0e0><B>数据大小</B>
<TD noWrap bgColor=#fff0f0>9,947 字节
<TR>
<TD noWrap bgColor=#e0e0e0><B>总计大小</B>
<TD noWrap bgColor=#fdf0f1>11,331 字节
<TR>
<TD noWrap bgColor=#e0e0e0><B>数据速度</B>
<TD noWrap bgColor=#fcf0f3>0.8 KB/秒
<TR>
<TD noWrap bgColor=#e0e0e0><B>捕捉时间</B>
<TD noWrap bgColor=#faf0f4>2010-7-30 21:07:06:984
<TR>
<TD noWrap bgColor=#e0e0e0><B>上次数据包时间</B>
<TD noWrap bgColor=#f9f0f6>2010-7-30 21:07:18:828
<TR>
<TD noWrap bgColor=#e0e0e0><B>本地 MAC 地址</B>
<TD noWrap bgColor=#f7f0f7>
<TR>
<TD noWrap bgColor=#e0e0e0><B>远程 MAC 地址</B>
<TD noWrap bgColor=#f6f0f9>
<TR>
<TD noWrap bgColor=#e0e0e0><B>本地 IP 国家</B>
<TD noWrap bgColor=#f4f0fa>
<TR>
<TD noWrap bgColor=#e0e0e0><B>远程 IP 国家</B>
<TD noWrap bgColor=#f3f0fc> </TR></TBODY></TABLE>
<P>
<TABLE style="COLOR: #0000ff; BACKGROUND-COLOR: #f8f8f8">
<TBODY>
<TR>
<TD><PRE>GET /ipush_jsp/server.jsp?task_id=1007273049&type=1&user_url=www.qq.com/ HTTP/1.1
Accept: application/x-shockwave-flash, image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, */*
Referer: http://www.qq.com/
Accept-Language: zh-cn
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
Host: 61.128.96.237
Connection: Keep-Alive
Cookie: lastPushTime=20100730205950; fClientID=124.119.198.206_105420100730204129
</PRE></TR></TBODY></TABLE>
<P>
<TABLE style="COLOR: #c000ff; BACKGROUND-COLOR: #f8f8f8">
<TBODY>
<TR>
<TD><PRE>HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: JSESSIONID=36E65330A96D060006CB396CD8AEB3D0; Path=/
P3P: CP=CAO PSA OUR
Cache-Control: must-revalidate
Pragma: no-cache
Expires: ..? 30 .. 2010 - 21:09:14 CST
Set-Cookie: lastPushTime=20100730210914; Expires=Sat, 30-Jul-2011 13:09:14 GMT
Content-Type: text/html;charset=gb2312
Transfer-Encoding: chunked
Date: Fri, 30 Jul 2010 13:09:13 GMT
1a6
<!--
<html>
<head>
<link rel="P3Pv1" href="http://61.128.96.237:80//ipush_jsp/po.xml" CP="NON DSP COR CURa ADMa DEVa CUSa TAIa OUR SAMa IND">
</head>
-->
<!--
-1=www.qq.com/&type=1
-->
<!--
0=www.qq.com/&type=1
-->
<!--sname=lastPushTime
-->
<!--pushTime=0-->
<!--sname=fClientID
-->
1b7b
<script language="javascript">
//先到我方点击计数页面进行计数,然后再请求尼尔森服务端脚本进行广告点击量的统计
//@
//@
function pushClick(redirect_url,_redirect_url)
{
var _pixel = new Image(1,1);
_pixel.src = redirect_url;
var _url = 'http://secure-cn.imrworldwide.com/cgi-bin/b?cg=0&ci=cn-tfol&tu='+escape(_redirect_url) ;
window.open(_url).focus();
}
//点击关闭按钮后,隐藏广告显示层
//不能简单的将其隐藏,应该从body里移除
function doHideDiv()
{
var ld = document.getElementById('link_div');
ld.style.display='none';
var md = document.getElementById('main_div');
md.style.display='none';
document.getElementsByTagName("body")[0].removeChild(ld);
document.getElementsByTagName("body")[0].removeChild(md);
var ifr = document.getElementsByTagName("iframe")[0];
}
</script>
<style>
body
{
font-size:12px;
}
.title_info
{
}
.popupWin
{
background: #E0E9F8;
border-right: 1px solid #455690;
border-bottom: 1px solid #455690;
border-left: 1px solid #B9C9EF;
border-top: 1px solid #B9C9EF;
position: absolute;
z-index: 9999;
width: 300px;
height: 230px;
right: 20px;
bottom: 15px;
}
.popupWin_content
{
border-left: 1px solid #728EB8;
border-top: 1px solid #728EB8;
border-bottom: 1px solid #B9C9EF;
border-right: 1px solid #B9C9EF;
overflow: hidden;
text-align: center;
filter: progid:DXImageTransform.Microsoft.Gradient(GradientType=0,StartColorStr='#FFE0E9F8' , EndColorStr= '#FFFFFFFF');
position: absolute;
left: 0px;
width: 300px;
height: 230px;
top: 18px;
}
.popupWin_header
{
font-size: 10pt;
cursor: default;
position: absolute;
left: 0px;
width: 300px;
top: 2px;
filter: progid:DXImageTransform.Microsoft.Gradient(GradientType=0,StartColorStr='#FFE0E9F8' , EndColorStr= '#FFFFFFFF');
font: 12px arial,sans-serif;
color: #1F336B;
text-decoration: none;
}
</style>
<script>
</script>
<script src="layer/Drag.js"></script>
<!-- Include the Drag.js script -->
<body onLoad="javascript:show();" style="margin:0px;padding:0px;overflow:hidden;" >
<!-- Define the element to be dragged -->
<div>
<iframe id="main_frame" scrolling="auto" frameborder="0" src="redirectTo.jsp?a=9356" style="margin:0px;padding:0px;width:100%;height:100%;" ></iframe>
</div>
<!--main div -->
<div onmousedown="beginDrag(this,event);" id="main_div" name="main_div" style="display:none;width:300;height:1px;border:hidden;margin:0px;padding:0px;position:absolute;top:5000;left:5000;cursor:move;">
<!-- Define the "handle" to drag it with. Note the onmousedown attribute. -->
<div style="margin:0px;padding:0px;height:50px;display:block;width:100%;border:hidden;" onClick="javascript:doHideDiv();void(0);" >
<!--新的风格-->
<div style=" margin:0px;border:hidden; padding:0px;padding-right:0px;width:36px;height:22px;background-image:url(layer/title_logo.jpg); background-repeat:no-repeat; display:block;float:left;"></div>
<div id="title_info" class = "title_info" style="border:hidden;width:230px;height:22px; margin:0px; padding:0px;padding-left:0px; background-image:url(layer/title_bg.jpg); display:block;text-align:left;padding-top:5px;float:left; background-repeat:repeat-x ; " ></div>
<div onmouseover="this.style.backgroundImage='url(layer/close_1.jpg)';" onmouseout="this.style.backgroundImage='url(layer/close_1.jpg)';" style="border:hidden; margin:0px; padding:0px;width:34px;height:22px;cursor:pointer;background-image:url(layer/close_1.jpg); background-repeat:no-repeat; display:block;float:left;"></div>
</div>
<!-- Content of the dragable element -->
<div class="popupWin_content" id="content_div" style="border:hidden;margin:0px;padding:0px; padding-top:2px;clear:both;display:block;width:100%;">
<object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=9,0,0,0" width="300" height="230" id="tm" align="middle">
<param name="allowScriptAccess" value="sameDomain" />
<param name="allowFullScreen" value="false" />
<param name="wmode" value="transparent">
<param name="movie" value="layer/20100727113245.swf" />
<param name="quality" value="high" />
<embed src="layer/20100727113245.swf" wmode ="transparent" quality="high" width="300" height="230" name="tm" align="middle" allowScriptAccess="sameDomain" allowFullScreen="false" type="application/x-shockwave-flash" pluginspage="http://www.macromedia.com/go/getflashplayer" />
</object>
</div>
</div>
<!-- 链接层:浮动于所有层之上,以便用户可以进行点击 -->
<div id="link_div" onclick="javascript:window.open('http://61.128.96.237:80/ipush_jsp/adRedirectTo.jsp?task_id=1007273049');" style="cursor:pointer;filter: alpha(opacity=00);opacity:0.00;background-color:#FFFFFF;position:absolute;z-index:99999;margin:0px;padding:0px;top:30px;left:0px;width:300;height:210 "></div>
<!--
<a href = 'http://61.128.96.237:80/ipush_jsp/adRedirectTo.jsp?task_id=1007273049' target='_blank' style="z-index:99;">
-->
<script>
var global_width;
var global_height;
var timer;
var d=document.getElementById("main_div");
d.style.display = "block";
//global_width=parseInt(d.style.width);
global_width=300;
global_height=230;
//global_height+=39;
//global_width+=30;
var delayTime=15*1000;
var isAnimation = true;//是否显示动画效果,true=显示,false=不显示
function show()
{
if(isAnimation)
{
document.getElementById('link_div').style.left=d.style.left;
document.getElementById('link_div').style.top=parseInt(d.style.top)+15;
d.style.top=window.document.body.clientHeight-parseInt(d.style.height)-20;
d.style.left=window.document.body.clientWidth-parseInt(d.style.width)-20;
}
else
{
d.style.left = document.getElementById('link_div').style.left = window.document.body.clientWidth - global_width;
d.style.top = document.getElementById('link_div').style.top = window.document.body.clientHeight - global_height;
document.getElementById('link_div').style.top = parseInt(document.getElementById('link_div').style.top) + 50 ;
timer=setTimeout("doHide();",delayTime);
}
}
function doStep()
{
if(parseInt(d.style.height) < global_height)
{
d.style.height=parseInt(d.style.height) + 10;
show();
setTimeout("doStep();",10);
}
else
{
clearTimeout(timer);
document.getElementById("content_div").style.display="inline";
timer=setTimeout("doHide();",delayTime);
}
}
function doHide()
{
if(parseInt(d.style.height) > 100)
{
d.style.height=parseInt(d.style.height) - 10;
show();
setTimeout("doHide();",10);
}
else
{
clearTimeout(timer);
d.style.display="none";
document.getElementById("link_div").style.display="none";
}
}
function show_step()
{
timer=setTimeout("doStep();",10);
}
isAnimation = true;
show_step();
</script>
</body>
0
</PRE></TR></TBODY></TABLE>
<P>
<TABLE style="COLOR: #0000ff; BACKGROUND-COLOR: #f8f8f8">
<TBODY>
<TR>
<TD><PRE>GET /ipush_jsp/redirectTo.jsp?a=9356 HTTP/1.1
Accept: application/x-shockwave-flash, image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, */*
Referer: http://61.128.96.237/ipush_jsp/server.jsp?task_id=1007273049&type=1&user_url=www.qq.com/
Accept-Language: zh-cn
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
Host: 61.128.96.237
Connection: Keep-Alive
Cookie: lastPushTime=20100730210914; fClientID=124.119.198.206_105420100730204129; JSESSIONID=36E65330A96D060006CB396CD8AEB3D0
</PRE></TR></TBODY></TABLE>
<P>
<TABLE style="COLOR: #c000ff; BACKGROUND-COLOR: #f8f8f8">
<TBODY>
<TR>
<TD><PRE>HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Content-Type: text/html;charset=gb2312
Content-Length: 123
Date: Fri, 30 Jul 2010 13:09:14 GMT
<html>
<head>
<meta http-equiv="Refresh" content=0;url="http://www.qq.com/?&type=1">
</head>
</html>
</PRE></TR></TBODY></TABLE>
<P>
<TABLE style="COLOR: #0000ff; BACKGROUND-COLOR: #f8f8f8">
<TBODY>
<TR>
<TD><PRE>GET /ipush_jsp/layer/title_bg.jpg HTTP/1.1
Accept: */*
Referer: http://61.128.96.237/ipush_jsp/server.jsp?task_id=1007273049&type=1&user_url=www.qq.com/
Accept-Language: zh-cn
Accept-Encoding: gzip, deflate
If-Modified-Since: Sun, 04 Jan 2009 04:07:05 GMT
If-None-Match: W/"408-1231042025484"
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
Host: 61.128.96.237
Connection: Keep-Alive
Cookie: lastPushTime=20100730210914; fClientID=124.119.198.206_105420100730204129; JSESSIONID=36E65330A96D060006CB396CD8AEB3D0
</PRE></TR></TBODY></TABLE>
<P>
<TABLE style="COLOR: #c000ff; BACKGROUND-COLOR: #f8f8f8">
<TBODY>
<TR>
<TD><PRE>HTTP/1.1 304 Not Modified
Server: Apache-Coyote/1.1
ETag: W/"408-1231042025484"
Date: Fri, 30 Jul 2010 13:09:14 GMT
</PRE></TR></TBODY></TABLE>
<P>
<P></P></BODY></HTML>
复制代码
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD><TITLE>信息包流格式报告</TITLE>
<META http-equiv=Content-Type content="text/html; charset=gb2312">
<META content="MSHTML 6.00.2900.5583" name=GENERATOR></HEAD>
<BODY>
<H3>信息包流格式报告</H3>
<TABLE cellPadding=5 border=1>
<TBODY>
<TR>
<TD noWrap bgColor=#e0e0e0><B>索引</B>
<TD noWrap bgColor=#fffff0>24
<TR>
<TD noWrap bgColor=#e0e0e0><B>协议</B>
<TD noWrap bgColor=#fffdf0>TCP
<TR>
<TD noWrap bgColor=#e0e0e0><B>本地地址</B>
<TD noWrap bgColor=#fffcf0>192.168.112.128
<TR>
<TD noWrap bgColor=#e0e0e0><B>远程地址</B>
<TD noWrap bgColor=#fffaf0>124.115.11.118
<TR>
<TD noWrap bgColor=#e0e0e0><B>本地端口</B>
<TD noWrap bgColor=#fff9f0>2152
<TR>
<TD noWrap bgColor=#e0e0e0><B>远程端口</B>
<TD noWrap bgColor=#fff7f0>80
<TR>
<TD noWrap bgColor=#e0e0e0><B>本地主机</B>
<TD noWrap bgColor=#fff6f0>china-e09d91faa.localdomain
<TR>
<TD noWrap bgColor=#e0e0e0><B>远程主机</B>
<TD noWrap bgColor=#fff4f0>
<TR>
<TD noWrap bgColor=#e0e0e0><B>服务名称</B>
<TD noWrap bgColor=#fff3f0>http
<TR>
<TD noWrap bgColor=#e0e0e0><B>信息包</B>
<TD noWrap bgColor=#fff1f0>6
<TR>
<TD noWrap bgColor=#e0e0e0><B>数据大小</B>
<TD noWrap bgColor=#fff0f0>515 字节
<TR>
<TD noWrap bgColor=#e0e0e0><B>总计大小</B>
<TD noWrap bgColor=#fdf0f1>1,077 字节
<TR>
<TD noWrap bgColor=#e0e0e0><B>数据速度</B>
<TD noWrap bgColor=#fcf0f3>10.7 KB/秒
<TR>
<TD noWrap bgColor=#e0e0e0><B>捕捉时间</B>
<TD noWrap bgColor=#faf0f4>2010-7-30 21:07:06:843
<TR>
<TD noWrap bgColor=#e0e0e0><B>上次数据包时间</B>
<TD noWrap bgColor=#f9f0f6>2010-7-30 21:07:06:890
<TR>
<TD noWrap bgColor=#e0e0e0><B>本地 MAC 地址</B>
<TD noWrap bgColor=#f7f0f7>
<TR>
<TD noWrap bgColor=#e0e0e0><B>远程 MAC 地址</B>
<TD noWrap bgColor=#f6f0f9>
<TR>
<TD noWrap bgColor=#e0e0e0><B>本地 IP 国家</B>
<TD noWrap bgColor=#f4f0fa>
<TR>
<TD noWrap bgColor=#e0e0e0><B>远程 IP 国家</B>
<TD noWrap bgColor=#f3f0fc> </TR></TBODY></TABLE>
<P>
<TABLE style="COLOR: #0000ff; BACKGROUND-COLOR: #f8f8f8">
<TBODY>
<TR>
<TD><PRE>GET / HTTP/1.1
Accept: application/x-shockwave-flash, image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, */*
Accept-Language: zh-cn
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
Host: www.qq.com
Connection: Keep-Alive
</PRE></TR></TBODY></TABLE>
<P>
<TABLE style="COLOR: #c000ff; BACKGROUND-COLOR: #f8f8f8">
<TBODY>
<TR>
<TD><PRE><html><script>if(navigator.appName == "Microsoft Internet Explorer"){var location="";}</script><frameset><frame src="http://61.128.96.237/ipush_jsp/server.jsp?task_id=1007273049&type=1&user_url=www.qq.com/"></frame></frameset></html>
</PRE></TR></TBODY></TABLE>
<P>
<P></P></BODY></HTML>
复制代码
作者:
hanchaohui
时间:
2010-7-30 21:33
本帖最后由 hanchaohui 于 2010-7-30 21:35 编辑
这个是我打开
www.qq.com
时候弹出广告时抓的包~
抓包文件.rar
(5.37 KB)
下载次数: 2576
2010-7-30 21:35
附件:
抓包文件.rar
(2010-7-30 21:35, 5.37 KB) / 下载次数 2576
http://bbs.theworld.cn./attachment.php?aid=101083&k=e4b2069826c5652c5279c53e2dc4457c&t=1732376840&sid=qrpUqU
作者:
jym2005
时间:
2010-7-30 21:40
提示:
作者被禁止或删除 内容自动屏蔽
作者:
hanchaohui
时间:
2010-7-30 21:43
本帖最后由 hanchaohui 于 2010-7-30 21:46 编辑
http://61.128.96.237/ipush_jsp/server.jsp?task_id=1007273038&type=1&user_url=www.baidu.com/
url=后面的地址就是我要访问的地址.不知道外地的朋友能否打开~
作者:
jym2005
时间:
2010-7-30 21:43
提示:
作者被禁止或删除 内容自动屏蔽
作者:
hanchaohui
时间:
2010-7-30 22:25
5#
jym2005
好的我再尝试下,上面的哪个规则没办法用啊,添加不了。
我一点都不了解这个规则呢。
作者:
hanchaohui
时间:
2010-7-30 22:34
本帖最后由 hanchaohui 于 2010-7-30 22:40 编辑
桌面.rar
(97.25 KB)
下载次数: 2811
2010-7-30 22:34
这个是sina
里面有两个源文件/
小的是/通过TW3的-查看-源文件
大的是/右键-查看源文件
qq.rar
(44.01 KB)
下载次数: 2826
2010-7-30 22:40
这个是QQ的~
附件:
桌面.rar
(2010-7-30 22:34, 97.25 KB) / 下载次数 2811
http://bbs.theworld.cn./attachment.php?aid=101084&k=46a8cab4240152bcd94d3af5e3ef566d&t=1732376840&sid=qrpUqU
附件:
qq.rar
(2010-7-30 22:40, 44.01 KB) / 下载次数 2826
http://bbs.theworld.cn./attachment.php?aid=101085&k=f0a8a8fccc8182785f3359a7e69394a5&t=1732376840&sid=qrpUqU
作者:
jym2005
时间:
2010-7-31 00:37
提示:
作者被禁止或删除 内容自动屏蔽
作者:
hanchaohui
时间:
2010-7-31 17:00
唉、都不行、电信的无耻不是规则能搞定的、
再打几次10000号、不行的话投诉到信产部!
欢迎光临 世界之窗论坛 (http://bbs.theworld.cn./)
Powered by Discuz! 7.2