{"id":335,"date":"2025-11-29T19:30:04","date_gmt":"2025-11-29T11:30:04","guid":{"rendered":"https:\/\/index.cmiteam.cn\/?p=335"},"modified":"2025-11-29T19:30:16","modified_gmt":"2025-11-29T11:30:16","slug":"ctf%e5%9f%ba%e7%a1%80%e7%9f%a5%e8%af%86%e6%95%b4%e7%90%862","status":"publish","type":"post","link":"https:\/\/index.cmiteam.cn\/index.php\/2025\/11\/29\/ctf%e5%9f%ba%e7%a1%80%e7%9f%a5%e8%af%86%e6%95%b4%e7%90%862\/","title":{"rendered":"CTF\u57fa\u7840\u77e5\u8bc6\u6574\u74062"},"content":{"rendered":"\n<h1 class=\"wp-block-heading\">\u7f51\u7edc\u57fa\u7840\u5c0f\u77e5\u8bc6<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">\u4e92\u8054\u7f51\u662f\u600e\u4e48\u5de5\u4f5c\u7684<\/h2>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/usual1009.oss-cn-shanghai.aliyuncs.com\/img\/202511291926804.png\" alt=\"image-20251109181053190\"\/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/usual1009.oss-cn-shanghai.aliyuncs.com\/img\/202511291926869.png\" alt=\"image-20251109181105568\"\/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">URL\u662f\u4ec0\u4e48<\/h2>\n\n\n\n<p><strong>URL<\/strong> \u662f <strong>Uniform Resource Locator<\/strong> \u7684\u7f29\u5199\uff0c\u4e2d\u6587\u901a\u5e38\u7ffb\u8bd1\u4e3a\u201c\u7edf\u4e00\u8d44\u6e90\u5b9a\u4f4d\u7b26\u201d\u3002<\/p>\n\n\n\n<p>\u7b80\u5355\u6765\u8bf4\uff0cURL \u5c31\u662f\u4e92\u8054\u7f51\u4e0a<strong>\u8d44\u6e90\u7684\u5730\u5740<\/strong>\uff0c\u5c31\u50cf\u4f60\u5bb6\u5728\u5730\u7403\u4e0a\u7684\u8be6\u7ec6\u5730\u5740\u4e00\u6837\u3002\u8fd9\u4e2a\u201c\u8d44\u6e90\u201d\u53ef\u4ee5\u662f\u7f51\u9875\u3001\u56fe\u7247\u3001\u89c6\u9891\u3001\u6587\u4ef6\u3001\u5e94\u7528\u7a0b\u5e8f\u3001API\u63a5\u53e3\u7b49\u7b49\u4efb\u4f55\u53ef\u4ee5\u88ab\u8bbf\u95ee\u5230\u7684\u5185\u5bb9\u3002<\/p>\n\n\n\n<p>\u5b83\u63d0\u4f9b\u4e86\u4e00\u79cd\u6807\u51c6\u7684\u65b9\u5f0f\u6765<strong>\u5b9a\u4f4d<\/strong>\u548c<strong>\u8bbf\u95ee<\/strong>\u8fd9\u4e9b\u8d44\u6e90\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">URL \u7684\u4f5c\u7528<\/h3>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u5b9a\u4f4d\u8d44\u6e90\uff1a<\/strong> \u544a\u8bc9\u6d4f\u89c8\u5668\u6216\u5176\u4ed6\u5ba2\u6237\u7aef\u7a0b\u5e8f\uff0c\u8981\u627e\u7684\u8d44\u6e90\u5728\u54ea\u91cc\u3002<\/li>\n\n\n\n<li><strong>\u8bbf\u95ee\u65b9\u5f0f\uff1a<\/strong> \u544a\u8bc9\u5ba2\u6237\u7aef\u7a0b\u5e8f\uff0c\u5e94\u8be5\u4f7f\u7528\u4ec0\u4e48\u534f\u8bae\uff08\u5982 HTTP\u3001FTP\uff09\u53bb\u8bbf\u95ee\u8fd9\u4e2a\u8d44\u6e90\u3002<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">URL \u7684\u57fa\u672c\u7ed3\u6784<\/h3>\n\n\n\n<p>\u4e00\u4e2a\u5178\u578b\u7684 URL \u901a\u5e38\u7531\u4ee5\u4e0b\u51e0\u4e2a\u4e3b\u8981\u90e8\u5206\u7ec4\u6210\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">scheme:\/\/host:port\/path?query#fragment<\/pre>\n\n\n\n<p>\u6211\u4eec\u6765\u9010\u4e00\u5206\u89e3\u8fd9\u4e9b\u90e8\u5206\uff1a<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong><code>scheme<\/code> (\u534f\u8bae)<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u5b9a\u4e49\uff1a<\/strong> \u6307\u5b9a\u4e86\u5ba2\u6237\u7aef\uff08\u5982\u6d4f\u89c8\u5668\uff09\u548c\u670d\u52a1\u5668\u4e4b\u95f4\u8fdb\u884c\u6570\u636e\u4f20\u8f93\u6240\u4f7f\u7528\u7684\u534f\u8bae\u6216\u89c4\u5219\u3002<\/li>\n\n\n\n<li>\u5e38\u89c1\u4f8b\u5b50\uff1a\n<ul class=\"wp-block-list\">\n<li><code>http:\/\/<\/code> (Hypertext Transfer Protocol): \u8d85\u6587\u672c\u4f20\u8f93\u534f\u8bae\uff0c\u7528\u4e8e\u4f20\u8f93\u8d85\u6587\u672c\u6587\u6863\uff08\u5982\u7f51\u9875\uff09\u3002<\/li>\n\n\n\n<li><code>https:\/\/<\/code> (Hypertext Transfer Protocol Secure): \u5b89\u5168\u8d85\u6587\u672c\u4f20\u8f93\u534f\u8bae\uff0c\u662f HTTP \u7684\u5b89\u5168\u7248\u672c\uff0c\u901a\u8fc7 SSL\/TLS \u52a0\u5bc6\u901a\u4fe1\u3002\u5728CTF\u4e2d\uff0c<code>https<\/code>\u7684\u5b89\u5168\u6027\u662f\u9700\u8981\u8003\u8651\u7684\u3002<\/li>\n\n\n\n<li><code>ftp:\/\/<\/code> (File Transfer Protocol): \u6587\u4ef6\u4f20\u8f93\u534f\u8bae\uff0c\u7528\u4e8e\u6587\u4ef6\u4e0a\u4f20\u548c\u4e0b\u8f7d\u3002<\/li>\n\n\n\n<li><code>mailto:<\/code>: \u7528\u4e8e\u53d1\u9001\u7535\u5b50\u90ae\u4ef6\uff0c\u540e\u9762\u901a\u5e38\u63a5\u90ae\u4ef6\u5730\u5740\u3002<\/li>\n\n\n\n<li><code>file:\/\/<\/code>: \u7528\u4e8e\u8bbf\u95ee\u672c\u5730\u6587\u4ef6\u7cfb\u7edf\u4e2d\u7684\u6587\u4ef6\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>CTF\u76f8\u5173\uff1a<\/strong> \u4e86\u89e3\u4e0d\u540c\u7684\u534f\u8bae\u53ef\u4ee5\u5e2e\u52a9\u4f60\u8bc6\u522b\u6f5c\u5728\u7684\u670d\u52a1\u548c\u653b\u51fb\u9762\u3002\u4f8b\u5982\uff0c<code>https<\/code>\u53ef\u80fd\u6d89\u53ca\u5230\u8bc1\u4e66\u95ee\u9898\uff0c<code>ftp<\/code>\u53ef\u80fd\u5b58\u5728\u533f\u540d\u767b\u5f55\u6216\u5f31\u5bc6\u7801\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong><code>host<\/code> (\u4e3b\u673a\u540d \/ \u57df\u540d)<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u5b9a\u4e49\uff1a<\/strong> \u6307\u5b9a\u4e86\u5b58\u653e\u8d44\u6e90\u7684\u670d\u52a1\u5668\u7684\u540d\u79f0\u6216 IP \u5730\u5740\u3002<\/li>\n\n\n\n<li>\u4f8b\u5b50\uff1a\n<ul class=\"wp-block-list\">\n<li><code>www.example.com<\/code> (\u57df\u540d)<\/li>\n\n\n\n<li><code>192.168.1.100<\/code> (IP \u5730\u5740)<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u5de5\u4f5c\u539f\u7406\uff1a<\/strong> \u5f53\u4f60\u8f93\u5165\u4e00\u4e2a\u57df\u540d\u65f6\uff0c\u4f60\u7684\u8ba1\u7b97\u673a\u901a\u8fc7 <strong>DNS (Domain Name System)<\/strong> \u5c06\u5176\u89e3\u6790\u6210\u5bf9\u5e94\u7684 IP \u5730\u5740\uff0c\u7136\u540e\u624d\u80fd\u627e\u5230\u670d\u52a1\u5668\u3002<\/li>\n\n\n\n<li><strong>CTF\u76f8\u5173\uff1a<\/strong> \u57df\u540d\u548cIP\u5730\u5740\u662f\u7f51\u7edc\u4fa6\u5bdf\uff08Reconnaissance\uff09\u7684\u5173\u952e\u4fe1\u606f\u3002\u5b50\u57df\u540d\u679a\u4e3e\u3001DNS\u8bb0\u5f55\u67e5\u8be2\u7b49\u90fd\u662f\u5e38\u89c1\u624b\u6cd5\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong><code>port<\/code> (\u7aef\u53e3\u53f7) - \u53ef\u9009<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u5b9a\u4e49\uff1a<\/strong> \u6307\u5b9a\u4e86\u670d\u52a1\u5668\u4e0a\u7528\u4e8e\u63d0\u4f9b\u7279\u5b9a\u670d\u52a1\u7684\u7aef\u53e3\u53f7\u3002<\/li>\n\n\n\n<li><strong>\u4f8b\u5b50\uff1a<\/strong> <code>:8080<\/code><\/li>\n\n\n\n<li><strong>\u7279\u70b9\uff1a<\/strong> \u5982\u679c\u4f7f\u7528\u534f\u8bae\u7684\u9ed8\u8ba4\u7aef\u53e3\uff08\u4f8b\u5982 HTTP \u7684 80 \u7aef\u53e3\uff0cHTTPS \u7684 443 \u7aef\u53e3\uff09\uff0c\u5219\u901a\u5e38\u53ef\u4ee5\u7701\u7565\u4e0d\u5199\u3002<\/li>\n\n\n\n<li><strong>CTF\u76f8\u5173\uff1a<\/strong> \u626b\u63cf\u5f00\u653e\u7aef\u53e3\u662f\u6e17\u900f\u6d4b\u8bd5\u7684\u7b2c\u4e00\u6b65\u3002\u975e\u6807\u51c6\u7aef\u53e3\uff08\u5982 8080\u30018443\uff09\u5e38\u5e38\u8fd0\u884c\u7740\u7279\u6b8a\u7684Web\u670d\u52a1\u6216\u7ba1\u7406\u754c\u9762\uff0c\u662f\u6f5c\u5728\u7684\u653b\u51fb\u76ee\u6807\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong><code>path<\/code> (\u8def\u5f84)<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u5b9a\u4e49\uff1a<\/strong> \u6307\u5b9a\u4e86\u670d\u52a1\u5668\u4e0a\u8d44\u6e90\u7684\u5177\u4f53\u4f4d\u7f6e\uff0c\u7c7b\u4f3c\u4e8e\u6587\u4ef6\u7cfb\u7edf\u4e2d\u7684\u76ee\u5f55\u7ed3\u6784\u3002<\/li>\n\n\n\n<li><strong>\u4f8b\u5b50\uff1a<\/strong> <code>\/blog\/article\/latest.html<\/code><\/li>\n\n\n\n<li><strong>\u7279\u70b9\uff1a<\/strong> \u901a\u5e38\u4ee5 <code>\/<\/code> \u5f00\u5934\uff0c\u8868\u793a\u6839\u76ee\u5f55\u3002<\/li>\n\n\n\n<li><strong>CTF\u76f8\u5173\uff1a<\/strong> \u8def\u5f84\u904d\u5386\uff08Path Traversal\uff0c\u5982 <code>..\/<\/code> \u653b\u51fb\uff09\u3001\u76ee\u5f55\u7206\u7834\u3001\u6587\u4ef6\u5305\u542b\uff08Local File Inclusion\/Remote File Inclusion\uff09\u7b49\u6f0f\u6d1e\u90fd\u4e0e\u8def\u5f84\u5bc6\u5207\u76f8\u5173\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong><code>query<\/code> (\u67e5\u8be2\u5b57\u7b26\u4e32) - \u53ef\u9009<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u5b9a\u4e49\uff1a<\/strong> \u7528\u4e8e\u5411\u670d\u52a1\u5668\u4f20\u9012\u989d\u5916\u53c2\u6570\uff0c\u901a\u5e38\u4ee5 <code>?<\/code> \u5f00\u5934\uff0c\u540e\u9762\u8ddf\u7740\u4e00\u7cfb\u5217 <code>key=value<\/code> \u7684\u952e\u503c\u5bf9\uff0c\u591a\u4e2a\u952e\u503c\u5bf9\u4e4b\u95f4\u7528 <code>&amp;<\/code> \u8fde\u63a5\u3002<\/li>\n\n\n\n<li><strong>\u4f8b\u5b50\uff1a<\/strong> <code>?category=laptops&amp;id=12345<\/code><\/li>\n\n\n\n<li><strong>\u7279\u70b9\uff1a<\/strong> \u4e3b\u8981\u7528\u4e8e\u52a8\u6001\u7f51\u9875\uff0c\u5411\u670d\u52a1\u5668\u811a\u672c\u4f20\u9012\u6570\u636e\uff0c\u4f8b\u5982\u641c\u7d22\u5173\u952e\u8bcd\u3001\u5546\u54c1ID\u3001\u7528\u6237\u4f1a\u8bdd\u4fe1\u606f\u7b49\u3002<\/li>\n\n\n\n<li><strong>CTF\u76f8\u5173\uff1a<\/strong> \u8fd9\u662f\u6f0f\u6d1e\u5229\u7528\u7684\u91cd\u707e\u533a\uff01SQL\u6ce8\u5165\u3001XSS\u3001\u547d\u4ee4\u6ce8\u5165\u3001\u53c2\u6570\u7be1\u6539\u3001\u903b\u8f91\u6f0f\u6d1e\u7b49\u90fd\u7ecf\u5e38\u901a\u8fc7\u4fee\u6539\u67e5\u8be2\u5b57\u7b26\u4e32\u4e2d\u7684\u53c2\u6570\u6765\u89e6\u53d1\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong><code>fragment<\/code> (\u7247\u6bb5\u6807\u8bc6\u7b26 \/ \u951a\u70b9) - \u53ef\u9009<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u5b9a\u4e49\uff1a<\/strong> \u7528\u4e8e\u6307\u5b9a\u7f51\u9875\u5185\u90e8\u7684\u67d0\u4e2a\u7279\u5b9a\u4f4d\u7f6e\uff08\u901a\u5e38\u662f\u5e26\u6709 <code>id<\/code> \u5c5e\u6027\u7684 HTML \u5143\u7d20\uff09\u3002\u5b83\u4ee5 <code>#<\/code> \u5f00\u5934\u3002<\/li>\n\n\n\n<li><strong>\u4f8b\u5b50\uff1a<\/strong> <code>#section_description<\/code><\/li>\n\n\n\n<li><strong>\u7279\u70b9\uff1a<\/strong> \u8fd9\u90e8\u5206\u5185\u5bb9<strong>\u4e0d\u4f1a<\/strong>\u53d1\u9001\u5230\u670d\u52a1\u5668\uff0c\u800c\u662f\u7531\u6d4f\u89c8\u5668\u5728\u5ba2\u6237\u7aef\u8fdb\u884c\u5904\u7406\uff0c\u7528\u4e8e\u9875\u9762\u5185\u7684\u8df3\u8f6c\u3002<\/li>\n\n\n\n<li><strong>CTF\u76f8\u5173\uff1a<\/strong> \u867d\u7136\u7247\u6bb5\u672c\u8eab\u4e0d\u76f4\u63a5\u4e0e\u670d\u52a1\u5668\u4ea4\u4e92\uff0c\u4f46\u5728\u67d0\u4e9b\u524d\u7aef\u653b\u51fb\uff08\u5982DOM XSS\uff09\u4e2d\uff0c\u5b83\u53ef\u80fd\u88ab\u5229\u7528\u6765\u6ce8\u5165\u6076\u610f\u4ee3\u7801\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">\u5b8c\u6574\u793a\u4f8b<\/h3>\n\n\n\n<p>\u8ba9\u6211\u4eec\u770b\u4e00\u4e2a\u5b8c\u6574\u7684 URL \u4f8b\u5b50\uff0c\u5e76\u5206\u89e3\u5b83\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">https:\/\/www.google.com:443\/search?q=ctf+url+explanation&amp;sourceid=chrome&amp;ie=UTF-8#top<\/pre>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong><code>https<\/code><\/strong>: \u534f\u8bae (Scheme)<\/li>\n\n\n\n<li><strong><code>www.google.com<\/code><\/strong>: \u4e3b\u673a\u540d\/\u57df\u540d (Host)<\/li>\n\n\n\n<li><strong><code>:443<\/code><\/strong>: \u7aef\u53e3\u53f7 (Port) - HTTPS \u7684\u9ed8\u8ba4\u7aef\u53e3\uff0c\u901a\u5e38\u53ef\u4ee5\u7701\u7565<\/li>\n\n\n\n<li><strong><code>\/search<\/code><\/strong>: \u8def\u5f84 (Path)<\/li>\n\n\n\n<li><code>?q=ctf+url+explanation&amp;sourceid=chrome&amp;ie=UTF-8<\/code>: \u67e5\u8be2\u5b57\u7b26\u4e32 (Query String)\n<ul class=\"wp-block-list\">\n<li><code>q=ctf+url+explanation<\/code>: \u641c\u7d22\u5173\u952e\u8bcd<\/li>\n\n\n\n<li><code>sourceid=chrome<\/code>: \u6765\u6e90ID<\/li>\n\n\n\n<li><code>ie=UTF-8<\/code>: \u7f16\u7801\u65b9\u5f0f<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong><code>#top<\/code><\/strong>: \u7247\u6bb5\u6807\u8bc6\u7b26 (Fragment) - \u6307\u5411\u9875\u9762\u9876\u90e8<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">CTF \u4e2d\u7684\u610f\u4e49<\/h3>\n\n\n\n<p>\u5728 CTF \u4e2d\uff0c\u7406\u89e3 URL \u7684\u7ed3\u6784\u548c\u6bcf\u4e2a\u90e8\u5206\u7684\u542b\u4e49\u81f3\u5173\u91cd\u8981\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u4fa6\u5bdf (Reconnaissance)\uff1a<\/strong> \u901a\u8fc7\u5206\u6790 URL \u7ed3\u6784\uff0c\u53ef\u4ee5\u63a8\u65ad\u51fa\u7f51\u7ad9\u7684\u76ee\u5f55\u7ed3\u6784\u3001\u4f7f\u7528\u7684\u6280\u672f\uff08\u5982\u6587\u4ef6\u6269\u5c55\u540d\uff09\u3001\u53ef\u80fd\u5b58\u5728\u7684\u53c2\u6570\u3002<\/li>\n\n\n\n<li>\u6f0f\u6d1e\u5229\u7528\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u67e5\u8be2\u5b57\u7b26\u4e32\uff1a<\/strong> \u662f SQL \u6ce8\u5165\u3001XSS\u3001\u547d\u4ee4\u6ce8\u5165\u3001\u53c2\u6570\u7be1\u6539\u7b49\u6f0f\u6d1e\u7684\u5e38\u89c1\u5165\u53e3\u70b9\u3002<\/li>\n\n\n\n<li><strong>\u8def\u5f84\uff1a<\/strong> \u8def\u5f84\u904d\u5386\u3001\u6587\u4ef6\u5305\u542b\u3001\u76ee\u5f55\u904d\u5386\u7b49\u6f0f\u6d1e\u7684\u5229\u7528\u70b9\u3002<\/li>\n\n\n\n<li><strong>\u534f\u8bae\uff1a<\/strong> \u8bc6\u522b\u4e0d\u5b89\u5168\u7684\u534f\u8bae\uff08\u5982 HTTP \u800c\u975e HTTPS\uff09\u6216\u7279\u6b8a\u534f\u8bae\uff08\u5982 <code>file:\/\/<\/code>\u3001<code>ftp:\/\/<\/code>\uff09\u53ef\u80fd\u63ed\u793a\u5176\u4ed6\u653b\u51fb\u9762\u3002<\/li>\n\n\n\n<li><strong>\u4e3b\u673a\u540d\/\u57df\u540d\uff1a<\/strong> \u4e86\u89e3\u5b50\u57df\u540d\u3001Host Header \u653b\u51fb\u7b49\u3002<\/li>\n\n\n\n<li><strong>\u7aef\u53e3\uff1a<\/strong> \u8bc6\u522b\u975e\u6807\u51c6\u7aef\u53e3\u4e0a\u7684\u670d\u52a1\uff0c\u53ef\u80fd\u53d1\u73b0\u672a\u53d7\u4fdd\u62a4\u7684\u7ba1\u7406\u754c\u9762\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/usual1009.oss-cn-shanghai.aliyuncs.com\/img\/202511291926919.png\" alt=\"image-20251109181207706\"\/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/usual1009.oss-cn-shanghai.aliyuncs.com\/img\/202511291926836.png\" alt=\"image-20251109181132159\"\/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">URL\u4e0eURL\u7f16\u7801<\/h2>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/usual1009.oss-cn-shanghai.aliyuncs.com\/img\/202511291926996.png\" alt=\"image-20251109181149338\"\/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">URI\u662f\u4ec0\u4e48<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">URI \u662f\u4ec0\u4e48\uff1f<\/h3>\n\n\n\n<p><strong>URI<\/strong> \u662f <strong>Uniform Resource Identifier<\/strong> \u7684\u7f29\u5199\uff0c\u4e2d\u6587\u901a\u5e38\u7ffb\u8bd1\u4e3a\u201c\u7edf\u4e00\u8d44\u6e90\u6807\u8bc6\u7b26\u201d\u3002<\/p>\n\n\n\n<p>\u7b80\u5355\u6765\u8bf4\uff0cURI \u662f\u4e00\u4e2a\u66f4\u5e7f\u6cdb\u3001\u66f4\u62bd\u8c61\u7684\u6982\u5ff5\uff0c\u5b83\u662f\u4e00\u4e2a\u7528\u4e8e<strong>\u6807\u8bc6<\/strong>\u4e92\u8054\u7f51\u4e0a\u4efb\u4f55\u8d44\u6e90\u7684\u5b57\u7b26\u4e32\u3002\u8fd9\u4e2a\u201c\u6807\u8bc6\u201d\u53ef\u4ee5\u662f\u8d44\u6e90\u7684<strong>\u4f4d\u7f6e<\/strong>\uff0c\u4e5f\u53ef\u4ee5\u662f\u8d44\u6e90\u7684<strong>\u540d\u79f0<\/strong>\uff0c\u6216\u8005\u4e24\u8005\u517c\u6709\u3002<\/p>\n\n\n\n<p>\u4f60\u53ef\u4ee5\u628a URI \u7406\u89e3\u4e3a\u8d44\u6e90\u7684<strong>\u8eab\u4efd\u8bc1\u53f7<\/strong>\u3002\u5b83\u544a\u8bc9\u4f60\u201c\u8fd9\u662f\u4ec0\u4e48\u8d44\u6e90\u201d\uff0c\u4f46\u53ef\u80fd\u4e0d\u4e00\u5b9a\u544a\u8bc9\u4f60\u201c\u8fd9\u4e2a\u8d44\u6e90\u5728\u54ea\u91cc\u201d\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">URI \u4e0e URL\u3001URN \u7684\u5173\u7cfb<\/h3>\n\n\n\n<p><strong>URI \u662f\u4e00\u4e2a\u8d85\u96c6\uff08Superset\uff09\uff0c\u800c URL \u548c URN \u90fd\u662f URI \u7684\u5b50\u96c6\u3002<\/strong><\/p>\n\n\n\n<p>\u7528\u4e00\u4e2a\u7b80\u5355\u7684\u56fe\u6765\u8868\u793a\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\"> &nbsp; &nbsp;  URI (\u7edf\u4e00\u8d44\u6e90\u6807\u8bc6\u7b26)<br> &nbsp; &nbsp; &nbsp; \/ &nbsp;  \\<br> &nbsp; &nbsp;  \/ &nbsp; &nbsp;  \\<br> &nbsp;  URL &nbsp; &nbsp; &nbsp; URN<br>(\u7edf\u4e00\u8d44\u6e90\u5b9a\u4f4d\u7b26) (\u7edf\u4e00\u8d44\u6e90\u540d\u79f0)<\/pre>\n\n\n\n<p>\u8fd9\u610f\u5473\u7740\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u6240\u6709\u7684 URL \u90fd\u662f URI\u3002<\/strong><\/li>\n\n\n\n<li><strong>\u6240\u6709\u7684 URN \u90fd\u662f URI\u3002<\/strong><\/li>\n\n\n\n<li><strong>\u4f46\u4e0d\u662f\u6240\u6709\u7684 URI \u90fd\u662f URL<\/strong>\uff08\u56e0\u4e3a\u5b83\u53ef\u4ee5\u662f URN\uff09\u3002<\/li>\n\n\n\n<li><strong>\u4e5f\u4e0d\u662f\u6240\u6709\u7684 URI \u90fd\u662f URN<\/strong>\uff08\u56e0\u4e3a\u5b83\u53ef\u4ee5\u662f URL\uff09\u3002<\/li>\n<\/ul>\n\n\n\n<p>\u6211\u4eec\u5df2\u7ecf\u8be6\u7ec6\u8bb2\u4e86 URL\uff0c\u73b0\u5728\u6211\u4eec\u6765\u770b\u770b URN\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">1. URL (Uniform Resource Locator) - \u7edf\u4e00\u8d44\u6e90\u5b9a\u4f4d\u7b26<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u4f5c\u7528\uff1a<\/strong> <strong>\u5b9a\u4f4d<\/strong>\u8d44\u6e90\u3002\u5b83\u4e0d\u4ec5\u6807\u8bc6\u4e86\u8d44\u6e90\uff0c\u8fd8\u63d0\u4f9b\u4e86<strong>\u83b7\u53d6\u8be5\u8d44\u6e90\u7684\u65b9\u6cd5\uff08\u534f\u8bae\uff09\u548c\u4f4d\u7f6e<\/strong>\u3002<\/li>\n\n\n\n<li><strong>\u7279\u70b9\uff1a<\/strong> \u544a\u8bc9\u6211\u4eec<strong>\u5982\u4f55\u8bbf\u95ee<\/strong>\u4ee5\u53ca<strong>\u5728\u54ea\u91cc<\/strong>\u53ef\u4ee5\u627e\u5230\u8d44\u6e90\u3002<\/li>\n\n\n\n<li><strong>\u7c7b\u6bd4\uff1a<\/strong> \u5c31\u50cf\u4f60\u5bb6\u7684<strong>\u8be6\u7ec6\u5730\u5740<\/strong>\uff08\u5305\u62ec\u7701\u3001\u5e02\u3001\u533a\u3001\u8857\u9053\u3001\u95e8\u724c\u53f7\uff09\uff0c\u901a\u8fc7\u8fd9\u4e2a\u5730\u5740\uff0c\u5feb\u9012\u5458\u5c31\u80fd\u627e\u5230\u4f60\u5bb6\u3002<\/li>\n\n\n\n<li>\u4f8b\u5b50\uff1a\n<ul class=\"wp-block-list\">\n<li><code>https:\/\/www.example.com\/path\/to\/document.html<\/code><\/li>\n\n\n\n<li><code>ftp:\/\/ftp.example.com\/pub\/file.zip<\/code><\/li>\n\n\n\n<li><code>file:\/\/\/C:\/Users\/user\/Documents\/report.pdf<\/code><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">2. URN (Uniform Resource Name) - \u7edf\u4e00\u8d44\u6e90\u540d\u79f0<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u4f5c\u7528\uff1a<\/strong> <strong>\u547d\u540d<\/strong>\u8d44\u6e90\u3002\u5b83\u901a\u8fc7\u4e00\u4e2a<strong>\u6301\u4e45\u7684\u3001\u5168\u5c40\u552f\u4e00\u7684\u540d\u5b57<\/strong>\u6765\u6807\u8bc6\u8d44\u6e90\uff0c\u800c\u4e0e\u8d44\u6e90\u7684\u4f4d\u7f6e\u65e0\u5173\u3002<\/li>\n\n\n\n<li><strong>\u7279\u70b9\uff1a<\/strong> \u544a\u8bc9\u6211\u4eec<strong>\u8fd9\u4e2a\u8d44\u6e90\u662f\u4ec0\u4e48<\/strong>\uff0c\u4f46<strong>\u4e0d\u544a\u8bc9\u6211\u4eec\u5982\u4f55\u8bbf\u95ee\u5b83\u6216\u5728\u54ea\u91cc\u627e\u5230\u5b83<\/strong>\u3002\u5373\u4f7f\u8d44\u6e90\u7684\u4f4d\u7f6e\u6539\u53d8\u4e86\uff0c\u5b83\u7684 URN \u4ecd\u7136\u4fdd\u6301\u4e0d\u53d8\u3002<\/li>\n\n\n\n<li><strong>\u7c7b\u6bd4\uff1a<\/strong> \u5c31\u50cf\u4e00\u672c\u4e66\u7684 <strong>ISBN \u53f7\u7801<\/strong>\uff08\u56fd\u9645\u6807\u51c6\u4e66\u53f7\uff09\uff0c\u6216\u8005\u4e00\u4e2a\u4eba\u7684<strong>\u8eab\u4efd\u8bc1\u53f7\u7801<\/strong>\u3002\u901a\u8fc7 ISBN\uff0c\u4f60\u77e5\u9053\u662f\u54ea\u672c\u4e66\uff0c\u4f46\u4e0d\u77e5\u9053\u5728\u54ea\u91cc\u80fd\u4e70\u5230\u6216\u501f\u5230\u8fd9\u672c\u4e66\u3002<\/li>\n\n\n\n<li>\u4f8b\u5b50\uff1a\n<ul class=\"wp-block-list\">\n<li><code>urn:isbn:0451450523<\/code> (\u6807\u8bc6\u4e00\u672c\u540d\u4e3a \"The Last Unicorn\" \u7684\u4e66)<\/li>\n\n\n\n<li><code>urn:ietf:rfc:2141<\/code> (\u6807\u8bc6 IETF \u7684 RFC 2141 \u6587\u6863)<\/li>\n\n\n\n<li><code>urn:uuid:6e8bc430-9c3a-11d9-9669-0800200c9a66<\/code> (\u6807\u8bc6\u4e00\u4e2a\u901a\u7528\u552f\u4e00\u6807\u8bc6\u7b26)<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u5e94\u7528\uff1a<\/strong> URN \u5728\u5b9e\u9645\u7684 Web \u6d4f\u89c8\u4e2d\u4e0d\u5982 URL \u5e38\u89c1\uff0c\u4f46\u5b83\u4eec\u5728\u56fe\u4e66\u9986\u7cfb\u7edf\u3001\u6570\u5b57\u7248\u6743\u7ba1\u7406\u548c\u5206\u5e03\u5f0f\u4fe1\u606f\u7cfb\u7edf\u4e2d\u975e\u5e38\u6709\u7528\uff0c\u56e0\u4e3a\u5b83\u4eec\u63d0\u4f9b\u4e86\u8d44\u6e90\u7684\u6301\u4e45\u6807\u8bc6\u3002<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">\u603b\u7ed3<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>URI (Uniform Resource Identifier)<\/strong>\uff1a<strong>\u6807\u8bc6<\/strong>\u8d44\u6e90\u3002\u4e00\u4e2a\u5e7f\u4e49\u7684\u6982\u5ff5\uff0c\u5305\u62ec\u5b9a\u4f4d\u548c\u547d\u540d\u3002<\/li>\n\n\n\n<li><strong>URL (Uniform Resource Locator)<\/strong>\uff1a<strong>\u5b9a\u4f4d<\/strong>\u8d44\u6e90\u3002\u544a\u8bc9\u4f60\u5728\u54ea\u91cc\u4ee5\u53ca\u5982\u4f55\u627e\u5230\u8d44\u6e90\u3002<\/li>\n\n\n\n<li><strong>URN (Uniform Resource Name)<\/strong>\uff1a<strong>\u547d\u540d<\/strong>\u8d44\u6e90\u3002\u901a\u8fc7\u4e00\u4e2a\u6301\u4e45\u7684\u540d\u79f0\u6765\u6807\u8bc6\u8d44\u6e90\uff0c\u4e0d\u5173\u5fc3\u5176\u4f4d\u7f6e\u3002<\/li>\n<\/ul>\n\n\n\n<p><strong>\u6700\u7b80\u5355\u7684\u8bb0\u5fc6\u65b9\u5f0f\uff1a<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>URI = URL + URN<\/strong><\/li>\n\n\n\n<li><strong>URL \u544a\u8bc9\u4f60\u201c\u5728\u54ea\u91cc\u201d<\/strong> (Location)<\/li>\n\n\n\n<li><strong>URN \u544a\u8bc9\u4f60\u201c\u662f\u4ec0\u4e48\u201d<\/strong> (Name)<\/li>\n<\/ul>\n\n\n\n<p>\u5728\u65e5\u5e38\u7684 Web \u4ea4\u4e92\u548c CTF \u4e2d\uff0c\u4f60\u51e0\u4e4e\u603b\u662f\u4f1a\u9047\u5230 <strong>URL<\/strong>\u3002\u5f53\u4eba\u4eec\u8bf4\u201cURI\u201d\u65f6\uff0c\u4ed6\u4eec\u901a\u5e38\u6307\u7684\u4e5f\u662f URL\uff0c\u56e0\u4e3a URL \u662f\u6700\u5e38\u89c1\u7684 URI \u7c7b\u578b\u3002\u4f46\u4ece\u6280\u672f\u4e0a\u8bb2\uff0c\u7406\u89e3\u5b83\u4eec\u4e4b\u95f4\u7684\u533a\u522b\u662f\u5f88\u91cd\u8981\u7684\u3002<\/p>\n\n\n\n<p>\u90a3\u6211\u4eec\u65e0\u6240\u4e0d\u77e5\u7684<a href=\"https:\/\/zhida.zhihu.com\/search?content_id=100694358&amp;content_type=Article&amp;match_order=1&amp;q=%E7%BB%B4%E5%9F%BA%E7%99%BE%E7%A7%91&amp;zd_token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJ6aGlkYV9zZXJ2ZXIiLCJleHAiOjE3NjI4NTczMzUsInEiOiLnu7Tln7rnmb7np5EiLCJ6aGlkYV9zb3VyY2UiOiJlbnRpdHkiLCJjb250ZW50X2lkIjoxMDA2OTQzNTgsImNvbnRlbnRfdHlwZSI6IkFydGljbGUiLCJtYXRjaF9vcmRlciI6MSwiemRfdG9rZW4iOm51bGx9.CIscPwK_MhzOEo-LQlgwU5V1kXaDOxHO3ka3t67LH8k&amp;zhida_source=entity\" target=\"_blank\"  rel=\"nofollow\" >\u7ef4\u57fa\u767e\u79d1<\/a>\u628a\u8fd9\u6bb5\u6d88\u5316\u7684\u5f88\u597d\uff0c\u5e76\u63cf\u8ff0\u7684\u66f4\u52a0\u5f62\u8c61\u4e86\uff1a<\/p>\n\n\n\n<p><strong>\u201cURI\u53ef\u4ee5\u5206\u4e3aURL,URN\u6216\u540c\u65f6\u5177\u5907locators \u548cnames\u7279\u6027\u7684\u4e00\u4e2a\u4e1c\u897f\u3002URN\u4f5c\u7528\u5c31\u597d\u50cf\u4e00\u4e2a\u4eba\u7684\u540d\u5b57\uff0cURL\u5c31\u50cf\u4e00\u4e2a\u4eba\u7684\u5730\u5740\u3002\u6362\u53e5\u8bdd\u8bf4\uff1aURN\u786e\u5b9a\u4e86\u4e1c\u897f\u7684\u8eab\u4efd\uff0cURL\u63d0\u4f9b\u4e86\u627e\u5230\u5b83\u7684\u65b9\u5f0f\u3002\u201d<\/strong><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u65b9\u4fbf\u7406\u89e3\uff1a<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u9996\u5148\uff0cURL\u662fURI\u7684\u4e00\u79cd\uff08\u901a\u8fc7\u90a3\u4e2a\u56fe\u5c31\u770b\u7684\u51fa\u6765\u5427\uff09\u3002\u6240\u4ee5\u6709\u4eba\u8ddf\u4f60\u8bf4URL\u4e0d\u662fURI\uff0c\u4ed6\u5c31\u9519\u4e86\u5457\u3002\u4f46\u4e5f\u4e0d\u662f\u6240\u6709\u7684URI\u90fd\u662fURL\u54e6\uff0c\u5c31\u597d\u50cf\u8774\u8776\u90fd\u4f1a\u98de\uff0c\u4f46\u4f1a\u98de\u7684\u53ef\u4e0d\u90fd\u662f\u8774\u8776\u554a\uff0c\u4f60\u8ba9\u82cd\u8747\u600e\u4e48\u60f3\uff01<\/li>\n\n\n\n<li>\u8ba9URI\u80fd\u6210\u4e3aURL\u7684\u5f53\u7136\u5c31\u662f\u90a3\u4e2a\u201c\u8bbf\u95ee\u673a\u5236\u201d\uff0c\u201c\u7f51\u7edc\u4f4d\u7f6e\u201d\u3002e.g. <code>http:\/\/<\/code> or <code>ftp:\/\/<\/code>.\u3002<\/li>\n\n\n\n<li>URN\u662f\u552f\u4e00\u6807\u8bc6\u7684\u4e00\u90e8\u5206\uff0c\u5c31\u662f\u4e00\u4e2a\u7279\u6b8a\u7684\u540d\u5b57\u3002<\/li>\n<\/ul>\n\n\n\n<p>\u3000\u3000\u4e0b\u9762\u5c31\u6765\u770b\u770b\u4f8b\u5b50\u5427\uff0c\u5f53\u6765\u4e5f\u662f\u6765\u81ea\u6743\u5a01\u7684RFC\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><code>ftp:\/\/ftp.is.co.za\/rfc\/rfc1808.txt<\/code> (also a URL because of the protocol)<\/li>\n\n\n\n<li><code>http:\/\/www.ietf.org\/rfc\/rfc2396.txt<\/code> (also a URL because of the protocol)<\/li>\n\n\n\n<li><code>ldap:\/\/[2001:db8::7]\/c=GB?objectClass?one<\/code> (also a URL because of the protocol)<\/li>\n\n\n\n<li><code>mailto:John.Doe@example.com<\/code> (also a URL because of the protocol)<\/li>\n\n\n\n<li><code>news:comp.infosystems.www.servers.unix<\/code> (also a URL because of the protocol)<\/li>\n\n\n\n<li><code>tel:+1-816-555-1212<\/code><\/li>\n\n\n\n<li><code>telnet:\/\/192.0.2.16:80\/<\/code> (also a URL because of the protocol)<\/li>\n\n\n\n<li><code>urn:oasis:names:specification:docbook:dtd:xml:4.1.2<\/code><\/li>\n<\/ul>\n\n\n\n<p>\u3000\u3000\u8fd9\u4e9b\u5168\u90fd\u662fURI, \u5176\u4e2d\u6709\u4e9b\u662fURL\u3002\u54ea\u4e9b? \u5c31\u662f\u90a3\u4e9b\u63d0\u4f9b\u4e86\u8bbf\u95ee\u673a\u5236\u7684\u3002<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\u5565\u662f\u8d85\u94fe\u63a5\uff1f<\/h2>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/usual1009.oss-cn-shanghai.aliyuncs.com\/img\/202511291926974.png\" alt=\"image-20251109183943403\"\/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">TCP\/IP \u662f\u4ec0\u4e48 \u4e09\u6b21\u63e1\u624b\u548c\u56db\u6b21\u6325\u624b\u7684\u8be6\u7ec6\u8fc7\u7a0b\u89e3\u6790<\/h2>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/usual1009.oss-cn-shanghai.aliyuncs.com\/img\/202511291926412.png\" alt=\"image-20251109174325612\"\/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/usual1009.oss-cn-shanghai.aliyuncs.com\/img\/202511291926587.png\" alt=\"image-20251109171128461\"\/><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/usual1009.oss-cn-shanghai.aliyuncs.com\/img\/202511291926086.jpeg\" alt=\"img\"\/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>\u4e09\u6b21\u63e1\u624b \u5efa\u7acb\u53ef\u9760\u8fde\u63a5<\/strong><\/h3>\n\n\n\n<p><strong>\u76ee\u7684\uff1a<\/strong> \u786e\u4fdd\u5ba2\u6237\u7aef\u548c\u670d\u52a1\u5668\u90fd\u80fd\u53d1\u9001\u548c\u63a5\u6536\u6570\u636e\uff0c\u5e76\u540c\u6b65\u5f7c\u6b64\u7684\u521d\u59cb\u5e8f\u5217\u53f7 (ISN)\uff0c\u4ece\u800c\u5efa\u7acb\u4e00\u4e2a\u53ef\u9760\u7684\u3001\u5168\u53cc\u5de5\u7684\u8fde\u63a5\u3002<\/p>\n\n\n\n<p><strong>\u8fc7\u7a0b\u8be6\u89e3\uff1a<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/usual1009.oss-cn-shanghai.aliyuncs.com\/img\/202511291926610.webp\" alt=\"img\"\/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/usual1009.oss-cn-shanghai.aliyuncs.com\/img\/202511291926735.webp\" alt=\"\u5728\u8fd9\u91cc\u63d2\u5165\u56fe\u7247\u63cf\u8ff0\"\/><\/figure>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u7b2c\u4e00\u6b21\u63e1\u624b (SYN)\uff1a\u5ba2\u6237\u7aef -> \u670d\u52a1\u5668<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u5ba2\u6237\u7aef\u72b6\u6001\uff1a<\/strong> <code>CLOSED<\/code> -> <code>SYN-SENT<\/code><\/li>\n\n\n\n<li><strong>\u5ba2\u6237\u7aef\u52a8\u4f5c\uff1a<\/strong> \u5ba2\u6237\u7aef\u5411\u670d\u52a1\u5668\u53d1\u9001\u4e00\u4e2a <strong>SYN (Synchronize)<\/strong> \u62a5\u6587\u6bb5\u3002\n<ul class=\"wp-block-list\">\n<li><code>SYN<\/code> \u6807\u5fd7\u4f4d\u8bbe\u7f6e\u4e3a1\u3002<\/li>\n\n\n\n<li>\u643a\u5e26\u4e00\u4e2a\u968f\u673a\u751f\u6210\u7684<strong>\u521d\u59cb\u5e8f\u5217\u53f7 (ISN_C)<\/strong>\uff0c\u4f8b\u5982 <code>seq=X<\/code>\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u901a\u4fd7\u7406\u89e3\uff1a<\/strong> \u5ba2\u6237\u7aef\u8bf4\uff1a\u201c\u5582\uff0c\u670d\u52a1\u5668\uff01\u6211\u60f3\u548c\u4f60\u5efa\u7acb\u8fde\u63a5\uff0c\u6211\u7684\u8d77\u59cb\u7f16\u53f7\u662fX\u3002\u4f60\u6536\u5230\u6211\u4e86\u5417\uff1f\u201d<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u7b2c\u4e8c\u6b21\u63e1\u624b (SYN-ACK)\uff1a\u670d\u52a1\u5668 -> \u5ba2\u6237\u7aef<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u670d\u52a1\u5668\u72b6\u6001\uff1a<\/strong> <code>LISTEN<\/code> -> <code>SYN-RECEIVED<\/code><\/li>\n\n\n\n<li><strong>\u670d\u52a1\u5668\u52a8\u4f5c\uff1a<\/strong> \u670d\u52a1\u5668\u6536\u5230\u5ba2\u6237\u7aef\u7684 <code>SYN<\/code> \u540e\uff0c\u5982\u679c\u540c\u610f\u5efa\u7acb\u8fde\u63a5\uff0c\u4f1a\u53d1\u9001\u4e00\u4e2a <strong>SYN-ACK<\/strong> \u62a5\u6587\u6bb5\u3002\n<ul class=\"wp-block-list\">\n<li><code>SYN<\/code> \u6807\u5fd7\u4f4d\u8bbe\u7f6e\u4e3a1\u3002<\/li>\n\n\n\n<li><code>ACK<\/code> (Acknowledgment) \u6807\u5fd7\u4f4d\u8bbe\u7f6e\u4e3a1\u3002<\/li>\n\n\n\n<li><strong>\u786e\u8ba4\u53f7 (ack)<\/strong> \u8bbe\u7f6e\u4e3a <code>X + 1<\/code>\uff0c\u8868\u793a\u5df2\u6210\u529f\u6536\u5230\u5ba2\u6237\u7aef\u7684 <code>SYN<\/code>\u3002<\/li>\n\n\n\n<li>\u643a\u5e26\u4e00\u4e2a\u670d\u52a1\u5668\u81ea\u5df1\u968f\u673a\u751f\u6210\u7684<strong>\u521d\u59cb\u5e8f\u5217\u53f7 (ISN_S)<\/strong>\uff0c\u4f8b\u5982 <code>seq=Y<\/code>\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u901a\u4fd7\u7406\u89e3\uff1a<\/strong> \u670d\u52a1\u5668\u8bf4\uff1a\u201c\u6211\u6536\u5230\u4e86\u4f60\u7684\u8bf7\u6c42\uff08\u786e\u8ba4\u53f7X+1\uff09\uff0c\u6211\u4e5f\u540c\u610f\u5efa\u7acb\u8fde\u63a5\uff0c\u6211\u7684\u8d77\u59cb\u7f16\u53f7\u662fY\u3002\u4f60\u6536\u5230\u6211\u4e86\u5417\uff1f\u201d<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u7b2c\u4e09\u6b21\u63e1\u624b (ACK)\uff1a\u5ba2\u6237\u7aef -> \u670d\u52a1\u5668<\/strong><ul><li><strong>\u5ba2\u6237\u7aef\u72b6\u6001\uff1a<\/strong> <code>SYN-SENT<\/code> -> <code>ESTABLISHED<\/code><\/li><li><strong>\u5ba2\u6237\u7aef\u52a8\u4f5c\uff1a<\/strong> \u5ba2\u6237\u7aef\u6536\u5230\u670d\u52a1\u5668\u7684 <code>SYN-ACK<\/code> \u540e\uff0c\u4f1a\u53d1\u9001\u4e00\u4e2a <strong>ACK<\/strong> \u62a5\u6587\u6bb5\u3002<ul><li><code>ACK<\/code> \u6807\u5fd7\u4f4d\u8bbe\u7f6e\u4e3a1\u3002<\/li><li><strong>\u786e\u8ba4\u53f7 (ack)<\/strong> \u8bbe\u7f6e\u4e3a <code>Y + 1<\/code>\uff0c\u8868\u793a\u5df2\u6210\u529f\u6536\u5230\u670d\u52a1\u5668\u7684 <code>SYN<\/code>\u3002<\/li><li><strong>\u6ce8\u610f\uff1a<\/strong> \u8fd9\u4e2a\u62a5\u6587\u6bb5\u53ef\u4ee5\u643a\u5e26\u6570\u636e\uff08\u4f46\u901a\u5e38\u4e0d\u643a\u5e26\uff0c\u56e0\u4e3a\u8fde\u63a5\u521a\u5efa\u7acb\uff09\u3002<\/li><\/ul><\/li><li><strong>\u901a\u4fd7\u7406\u89e3\uff1a<\/strong> \u5ba2\u6237\u7aef\u8bf4\uff1a\u201c\u6211\u6536\u5230\u4e86\u4f60\u7684\u786e\u8ba4\u548c\u8d77\u59cb\u7f16\u53f7\uff08\u786e\u8ba4\u53f7Y+1\uff09\u3002\u597d\u7684\uff0c\u6211\u4eec\u73b0\u5728\u53ef\u4ee5\u6b63\u5f0f\u5f00\u59cb\u901a\u4fe1\u4e86\uff01\u201d<\/li><li><strong>\u670d\u52a1\u5668\u72b6\u6001\uff1a<\/strong> <code>SYN-RECEIVED<\/code> -> <code>ESTABLISHED<\/code><\/li><\/ul><img decoding=\"async\" src=\"https:\/\/usual1009.oss-cn-shanghai.aliyuncs.com\/img\/202511291926566.png\" alt=\"image-20251109172139189\"><\/li>\n<\/ol>\n\n\n\n<p><strong>\u4e3a\u4ec0\u4e48\u662f\u4e09\u6b21\u63e1\u624b\uff1f<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u9632\u6b62\u5df2\u5931\u6548\u7684\u8fde\u63a5\u8bf7\u6c42\u62a5\u6587\u6bb5\u7a81\u7136\u53c8\u4f20\u5230\u670d\u52a1\u5668\uff0c\u5bfc\u81f4\u9519\u8bef\u8fde\u63a5\u3002<\/strong> \u60f3\u8c61\u5ba2\u6237\u7aef\u53d1\u4e86\u4e2aSYN\uff0c\u4f46\u7f51\u7edc\u5ef6\u8fdf\u5f88\u4e45\u624d\u5230\u670d\u52a1\u5668\u3002\u5ba2\u6237\u7aef\u4ee5\u4e3a\u8d85\u65f6\u4e86\u5c31\u91cd\u53d1\u4e86\u4e00\u4e2a\uff0c\u5e76\u5efa\u7acb\u4e86\u65b0\u8fde\u63a5\u3002\u5982\u679c\u65e7\u7684SYN\u7a81\u7136\u53c8\u5230\u4e86\u670d\u52a1\u5668\uff0c\u670d\u52a1\u5668\u4f1a\u56de\u590dSYN-ACK\u3002\u5982\u679c\u53ea\u6709\u4e24\u6b21\u63e1\u624b\uff0c\u5ba2\u6237\u7aef\u6536\u5230\u8fd9\u4e2a\u65e7\u7684SYN-ACK\u540e\u4f1a\u8bef\u4ee5\u4e3a\u662f\u65b0\u8fde\u63a5\uff0c\u5bfc\u81f4\u9519\u8bef\u3002\u4e09\u6b21\u63e1\u624b\u786e\u4fdd\u5ba2\u6237\u7aef\u4f1a\u5ffd\u7565\u8fd9\u4e2a\u65e7\u7684SYN-ACK\uff0c\u56e0\u4e3a\u5b83\u4e0d\u662f\u5b83\u671f\u671b\u7684\u3002<\/li>\n\n\n\n<li><strong>\u786e\u4fdd\u53cc\u65b9\u90fd\u5177\u5907\u53d1\u9001\u548c\u63a5\u6536\u80fd\u529b\u3002<\/strong>\n<ul class=\"wp-block-list\">\n<li>\u7b2c\u4e00\u6b21\u63e1\u624b\uff1a\u5ba2\u6237\u7aef\u80fd\u53d1\uff0c\u670d\u52a1\u5668\u80fd\u6536\u3002<\/li>\n\n\n\n<li>\u7b2c\u4e8c\u6b21\u63e1\u624b\uff1a\u670d\u52a1\u5668\u80fd\u53d1\uff0c\u5ba2\u6237\u7aef\u80fd\u6536\u3002<\/li>\n\n\n\n<li>\u7b2c\u4e09\u6b21\u63e1\u624b\uff1a\u5ba2\u6237\u7aef\u80fd\u53d1\uff08\u786e\u8ba4\u670d\u52a1\u5668\u7684SYN\uff09\uff0c\u670d\u52a1\u5668\u80fd\u6536\uff08\u5ba2\u6237\u7aef\u7684ACK\uff09\u3002<\/li>\n\n\n\n<li>\u901a\u8fc7\u4e09\u6b21\u786e\u8ba4\uff0c\u53cc\u65b9\u90fd\u660e\u786e\u5bf9\u65b9\u5df2\u51c6\u5907\u597d\u8fdb\u884c\u53cc\u5411\u6570\u636e\u4f20\u8f93\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>\u4e09\u6b21\u63e1\u624b\u8fc7\u7a0b\u4e2d\u5bb9\u6613\u906d\u53d7\u7684\u653b\u51fb\u53ca\u89e3\u51b3\u65b9\u6848\uff1a<\/strong><\/h3>\n\n\n\n<p><strong>\u653b\u51fb\u7c7b\u578b\uff1aSYN \u6d2a\u6cdb\u653b\u51fb (SYN Flood)<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u653b\u51fb\u8fc7\u7a0b\uff1a<\/strong> \u653b\u51fb\u8005\u5411\u76ee\u6807\u670d\u52a1\u5668\u53d1\u9001\u5927\u91cf\u7684 <code>SYN<\/code> \u8bf7\u6c42\u62a5\u6587\u6bb5\uff0c\u4f46\u6536\u5230\u670d\u52a1\u5668\u7684 <code>SYN-ACK<\/code> \u54cd\u5e94\u540e\uff0c\u5374\u6545\u610f\u4e0d\u53d1\u9001\u7b2c\u4e09\u6b21\u63e1\u624b\u7684 <code>ACK<\/code> \u62a5\u6587\u6bb5\u6765\u5b8c\u6210\u8fde\u63a5\u3002\u653b\u51fb\u8005\u901a\u5e38\u4f1a\u4f2a\u9020\u6e90IP\u5730\u5740\uff0c\u4f7f\u5f97\u670d\u52a1\u5668\u7684 <code>SYN-ACK<\/code> \u65e0\u6cd5\u5230\u8fbe\u771f\u6b63\u7684\u5ba2\u6237\u7aef\uff0c\u6216\u8005\u5230\u8fbe\u4e00\u4e2a\u4e0d\u5b58\u5728\u7684\u5730\u5740\u3002<\/li>\n\n\n\n<li><strong>\u653b\u51fb\u539f\u7406\uff1a<\/strong> \u670d\u52a1\u5668\u5728\u6536\u5230 <code>SYN<\/code> \u5e76\u53d1\u9001 <code>SYN-ACK<\/code> \u540e\uff0c\u4f1a\u4e3a\u8fd9\u4e2a\u201c\u534a\u5f00\u8fde\u63a5\u201d\u5728\u5185\u5b58\u4e2d\u5206\u914d\u5e76\u7ef4\u62a4\u4e00\u4e2a<strong>\u8fde\u63a5\u72b6\u6001\u5757 (TCB - Transmission Control Block)<\/strong>\uff0c\u5e76\u5c06\u5176\u653e\u5165\u534a\u5f00\u8fde\u63a5\u961f\u5217\u3002\u5927\u91cf\u7684\u534a\u5f00\u8fde\u63a5\u4f1a\u8fc5\u901f\u8017\u5c3d\u670d\u52a1\u5668\u7684\u5185\u5b58\u548cCPU\u8d44\u6e90\uff0c\u5e76\u586b\u6ee1\u534a\u5f00\u8fde\u63a5\u961f\u5217\u3002<\/li>\n\n\n\n<li><strong>\u653b\u51fb\u5f71\u54cd\uff1a<\/strong> \u5f53\u534a\u5f00\u8fde\u63a5\u961f\u5217\u6ee1\u8f7d\u65f6\uff0c\u670d\u52a1\u5668\u65e0\u6cd5\u5904\u7406\u65b0\u7684\u5408\u6cd5 <code>SYN<\/code> \u8bf7\u6c42\uff0c\u5bfc\u81f4\u771f\u6b63\u7684\u7528\u6237\u65e0\u6cd5\u5efa\u7acb\u8fde\u63a5\uff0c\u4ece\u800c\u9020\u6210<strong>\u62d2\u7edd\u670d\u52a1 (DoS\/DDoS)<\/strong>\u3002<\/li>\n<\/ul>\n\n\n\n<p><strong>\u89e3\u51b3\u65b9\u6848\u53ca\u8be6\u7ec6\u89e3\u91ca\uff1a<\/strong><\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>SYN Cookies (\u540c\u6b65\u5e8f\u5217\u53f7cookies)<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u539f\u7406\uff1a<\/strong> \u8fd9\u662f\u6700\u6709\u6548\u7684\u9632\u5fa1\u624b\u6bb5\u4e4b\u4e00\u3002\u5f53\u670d\u52a1\u5668\u6536\u5230\u5ba2\u6237\u7aef\u7684 <code>SYN<\/code> \u8bf7\u6c42\u65f6\uff0c\u5b83<strong>\u4e0d\u7acb\u5373\u5206\u914d\u8d44\u6e90<\/strong>\u3002\u76f8\u53cd\uff0c\u5b83\u4f1a\u6839\u636e\u5ba2\u6237\u7aef\u7684IP\u5730\u5740\u3001\u7aef\u53e3\u3001\u5ba2\u6237\u7aef\u7684\u521d\u59cb\u5e8f\u5217\u53f7 (<code>seq=X<\/code>)\u3001\u670d\u52a1\u5668\u7684IP\u5730\u5740\u3001\u7aef\u53e3\u4ee5\u53ca\u4e00\u4e2a\u79d8\u5bc6\u503c\uff0c\u901a\u8fc7\u52a0\u5bc6\u7b97\u6cd5\u8ba1\u7b97\u51fa\u4e00\u4e2a\u7279\u6b8a\u7684\u201c\u997c\u5e72\u201d\u503c\u3002\u8fd9\u4e2a\u201c\u997c\u5e72\u201d\u503c\u88ab\u7528\u4f5c\u670d\u52a1\u5668\u7684\u521d\u59cb\u5e8f\u5217\u53f7 (<code>seq=Y<\/code>)\uff0c\u5305\u542b\u5728 <code>SYN-ACK<\/code> \u62a5\u6587\u6bb5\u4e2d\u53d1\u9001\u7ed9\u5ba2\u6237\u7aef\u3002\u53ea\u6709\u5f53\u5ba2\u6237\u7aef\u56de\u590d\u4e86\u6b63\u786e\u7684 <code>ACK<\/code> \u62a5\u6587\u6bb5\uff08\u5176\u4e2d\u5305\u542b\u6b63\u786e\u7684\u786e\u8ba4\u53f7 <code>Y+1<\/code>\uff09\uff0c\u670d\u52a1\u5668\u624d\u4f1a\u6839\u636e\u8fd9\u4e2a\u786e\u8ba4\u53f7\u4e2d\u7684\u4fe1\u606f\uff0c<strong>\u91cd\u65b0\u8ba1\u7b97\u5e76\u9a8c\u8bc1\u201c\u997c\u5e72\u201d\uff08Cookies\uff09\u503c<\/strong>\u3002\u5982\u679c\u9a8c\u8bc1\u901a\u8fc7\uff0c\u670d\u52a1\u5668\u624d\u771f\u6b63\u4e3a\u8fd9\u4e2a\u8fde\u63a5\u5206\u914d\u8d44\u6e90\u5e76\u5efa\u7acb\u8fde\u63a5\u3002<\/li>\n\n\n\n<li><strong>\u539f\u56e0\u89e3\u91ca\uff1a<\/strong> \u901a\u8fc7\u5c06\u8fde\u63a5\u72b6\u6001\u4fe1\u606f\u7f16\u7801\u5230\u5e8f\u5217\u53f7\u4e2d\uff0c\u670d\u52a1\u5668\u5728\u6536\u5230 <code>SYN<\/code> \u65f6\u4fdd\u6301\u201c\u65e0\u72b6\u6001\u201d\uff0c\u4e0d\u5360\u7528\u4efb\u4f55\u5185\u5b58\u8d44\u6e90\u3002\u53ea\u6709\u5f53\u5ba2\u6237\u7aef\u5b8c\u6210\u7b2c\u4e09\u6b21\u63e1\u624b\u65f6\uff0c\u624d\u5206\u914d\u8d44\u6e90\u3002\u8fd9\u4f7f\u5f97\u653b\u51fb\u8005\u53d1\u9001\u518d\u591a\u7684 <code>SYN<\/code> \u5305\u4e5f\u65e0\u6cd5\u8017\u5c3d\u670d\u52a1\u5668\u7684\u8fde\u63a5\u961f\u5217\u548c\u5185\u5b58\uff0c\u56e0\u4e3a\u670d\u52a1\u5668\u5728\u6536\u5230 <code>ACK<\/code> \u4e4b\u524d\u6ca1\u6709\u4e3a\u8fd9\u4e9b\u8fde\u63a5\u5206\u914d\u8d44\u6e90\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>SYN Proxy (SYN \u4ee3\u7406)<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u539f\u7406\uff1a<\/strong> \u5728\u670d\u52a1\u5668\u524d\u7aef\u90e8\u7f72\u4e00\u4e2a\u4e13\u95e8\u7684\u4ee3\u7406\u8bbe\u5907\uff08\u5982\u9632\u706b\u5899\u3001\u8d1f\u8f7d\u5747\u8861\u5668\u6216DDoS\u9632\u62a4\u8bbe\u5907\uff09\u3002\u8fd9\u4e2a\u4ee3\u7406\u8bbe\u5907\u4f1a\u62e6\u622a\u6240\u6709\u7684 <code>SYN<\/code> \u8bf7\u6c42\u3002\u5b83\u4f1a\u4ee3\u66ff\u540e\u7aef\u670d\u52a1\u5668\u4e0e\u5ba2\u6237\u7aef\u5b8c\u6210\u4e09\u6b21\u63e1\u624b\u3002\u53ea\u6709\u5f53\u4ee3\u7406\u8bbe\u5907\u6210\u529f\u4e0e\u5ba2\u6237\u7aef\u5efa\u7acb\u4e86\u5b8c\u6574\u7684TCP\u8fde\u63a5\u540e\uff0c\u5b83\u624d\u4f1a\u5411\u540e\u7aef\u670d\u52a1\u5668\u53d1\u9001\u4e00\u4e2a\u65b0\u7684 <code>SYN<\/code> \u8bf7\u6c42\uff0c\u5efa\u7acb\u7b2c\u4e8c\u4e2aTCP\u8fde\u63a5\uff0c\u5e76\u5c06\u5ba2\u6237\u7aef\u7684\u6d41\u91cf\u8f6c\u53d1\u7ed9\u540e\u7aef\u670d\u52a1\u5668\u3002<\/li>\n\n\n\n<li><strong>\u539f\u56e0\u89e3\u91ca\uff1a<\/strong> \u540e\u7aef\u670d\u52a1\u5668\u6c38\u8fdc\u4e0d\u4f1a\u76f4\u63a5\u66b4\u9732\u5728 <code>SYN<\/code> \u6d2a\u6cdb\u7684\u98ce\u9669\u4e2d\u3002\u4ee3\u7406\u8bbe\u5907\u627f\u62c5\u4e86\u5efa\u7acb\u8fde\u63a5\u7684\u5f00\u9500\u548c\u98ce\u9669\uff0c\u4fdd\u62a4\u4e86\u540e\u7aef\u670d\u52a1\u5668\u7684\u8d44\u6e90\u3002\u5373\u4f7f\u4ee3\u7406\u8bbe\u5907\u88ab\u653b\u51fb\uff0c\u540e\u7aef\u670d\u52a1\u4e5f\u80fd\u4fdd\u6301\u53ef\u7528\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u589e\u52a0\u534a\u5f00\u8fde\u63a5\u961f\u5217\u5927\u5c0f (Backlog Queue Size)<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u539f\u7406\uff1a<\/strong> \u8c03\u6574\u64cd\u4f5c\u7cfb\u7edf\u53c2\u6570\uff0c\u589e\u52a0\u670d\u52a1\u5668\u53ef\u4ee5\u540c\u65f6\u7ef4\u62a4\u7684\u534a\u5f00\u8fde\u63a5\uff08<code>SYN-RECEIVED<\/code> \u72b6\u6001\uff09\u7684\u6570\u91cf\u3002<\/li>\n\n\n\n<li><strong>\u539f\u56e0\u89e3\u91ca\uff1a<\/strong> \u8fd9\u662f\u4e00\u79cd\u4e34\u65f6\u7f13\u89e3\u63aa\u65bd\uff0c\u53ef\u4ee5\u5ef6\u7f13\u961f\u5217\u88ab\u586b\u6ee1\u7684\u65f6\u95f4\uff0c\u4e3a\u5176\u4ed6\u9632\u5fa1\u63aa\u65bd\u4e89\u53d6\u65f6\u95f4\u3002\u4f46\u5b83\u4e0d\u80fd\u4ece\u6839\u672c\u4e0a\u89e3\u51b3\u95ee\u9898\uff0c\u5982\u679c\u653b\u51fb\u6d41\u91cf\u8db3\u591f\u5927\uff0c\u961f\u5217\u6700\u7ec8\u8fd8\u662f\u4f1a\u88ab\u586b\u6ee1\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u8fde\u63a5\u901f\u7387\u9650\u5236 (Rate Limiting)<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u539f\u7406\uff1a<\/strong> \u5728\u9632\u706b\u5899\u3001\u8def\u7531\u5668\u6216\u670d\u52a1\u5668\u4e0a\u914d\u7f6e\uff0c\u9650\u5236\u4ece\u5355\u4e2aIP\u5730\u5740\u6216\u7279\u5b9aIP\u6bb5\u5728\u5355\u4f4d\u65f6\u95f4\u5185\u53d1\u8d77\u7684 <code>SYN<\/code> \u8bf7\u6c42\u6570\u91cf\u3002<\/li>\n\n\n\n<li><strong>\u539f\u56e0\u89e3\u91ca\uff1a<\/strong> \u53ef\u4ee5\u6709\u6548\u51cf\u7f13\u6765\u81ea\u975e\u4f2a\u9020IP\u5730\u5740\u7684 <code>SYN<\/code> \u6d2a\u6cdb\u653b\u51fb\u3002\u4f46\u5bf9\u4e8e\u4f2a\u9020\u6e90IP\u7684\u653b\u51fb\u6548\u679c\u6709\u9650\uff0c\u56e0\u4e3a\u6bcf\u4e2a\u4f2a\u9020IP\u53ef\u80fd\u53ea\u53d1\u9001\u5c11\u91cf\u8bf7\u6c42\uff0c\u4f46\u603b\u6570\u5de8\u5927\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>\u56db\u6b21\u6325\u624b \u65ad\u5f00\u53ef\u9760\u8fde\u63a5<\/strong><\/h3>\n\n\n\n<p><strong>\u76ee\u7684\uff1a<\/strong> \u4f18\u96c5\u5730\u7ec8\u6b62\u4e00\u4e2a\u5168\u53cc\u5de5\u7684TCP\u8fde\u63a5\uff0c\u786e\u4fdd\u53cc\u65b9\u6240\u6709\u5f85\u53d1\u9001\u7684\u6570\u636e\u90fd\u5df2\u4f20\u8f93\u5b8c\u6bd5\u5e76\u5f97\u5230\u786e\u8ba4\uff0c\u7136\u540e\u5b89\u5168\u5730\u91ca\u653e\u8fde\u63a5\u8d44\u6e90\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/usual1009.oss-cn-shanghai.aliyuncs.com\/img\/202511291926181.webp\" alt=\"img\"\/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/usual1009.oss-cn-shanghai.aliyuncs.com\/img\/202511291926490.webp\" alt=\"\u5728\u8fd9\u91cc\u63d2\u5165\u56fe\u7247\u63cf\u8ff0\"\/><\/figure>\n\n\n\n<p><strong>\u8fc7\u7a0b\u8be6\u89e3\uff1a<\/strong><\/p>\n\n\n\n<p>TCP\u8fde\u63a5\u662f\u5168\u53cc\u5de5\u7684\uff0c\u610f\u5473\u7740\u6570\u636e\u53ef\u4ee5\u5728\u4e24\u4e2a\u65b9\u5411\u4e0a\u72ec\u7acb\u4f20\u8f93\u3002\u56e0\u6b64\uff0c\u5173\u95ed\u8fde\u63a5\u4e5f\u9700\u8981\u53cc\u65b9\u5404\u81ea\u72ec\u7acb\u5730\u5173\u95ed\u81ea\u5df1\u7684\u53d1\u9001\u901a\u9053\u3002<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u7b2c\u4e00\u6b21\u6325\u624b (FIN)\uff1a\u53d1\u8d77\u65b9 -> \u63a5\u6536\u65b9<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u53d1\u8d77\u65b9\u72b6\u6001\uff1a<\/strong> <code>ESTABLISHED<\/code> -> <code>FIN-WAIT-1<\/code><\/li>\n\n\n\n<li><strong>\u53d1\u8d77\u65b9\u52a8\u4f5c\uff1a<\/strong> \u5f53\u4e00\u65b9\uff08\u4f8b\u5982\u5ba2\u6237\u7aef\uff09\u5b8c\u6210\u6240\u6709\u6570\u636e\u53d1\u9001\u540e\uff0c\u5b83\u4f1a\u53d1\u9001\u4e00\u4e2a <strong>FIN (Finish)<\/strong> \u62a5\u6587\u6bb5\u3002\n<ul class=\"wp-block-list\">\n<li><code>FIN<\/code> \u6807\u5fd7\u4f4d\u8bbe\u7f6e\u4e3a1\u3002<\/li>\n\n\n\n<li>\u643a\u5e26\u4e00\u4e2a\u5e8f\u5217\u53f7\uff0c\u4f8b\u5982 <code>seq=U<\/code> (U\u662f\u4e4b\u524d\u53d1\u9001\u7684\u6700\u540e\u4e00\u4e2a\u5b57\u8282\u7684\u5e8f\u5217\u53f7+1)\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u901a\u4fd7\u7406\u89e3\uff1a<\/strong> \u5ba2\u6237\u7aef\u8bf4\uff1a\u201c\u6211\u8fd9\u8fb9\u7684\u6570\u636e\u90fd\u53d1\u5b8c\u4e86\uff0c\u6211\u51c6\u5907\u5173\u95ed\u6211\u7684\u53d1\u9001\u901a\u9053\u4e86\u3002\u6211\u7684\u6700\u540e\u4e00\u4e2a\u5b57\u8282\u662fU\u3002\u201d<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u7b2c\u4e8c\u6b21\u6325\u624b (ACK)\uff1a\u63a5\u6536\u65b9 -> \u53d1\u8d77\u65b9<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u63a5\u6536\u65b9\u72b6\u6001\uff1a<\/strong> <code>ESTABLISHED<\/code> -> <code>CLOSE-WAIT<\/code><\/li>\n\n\n\n<li><strong>\u63a5\u6536\u65b9\u52a8\u4f5c\uff1a<\/strong> \u63a5\u6536\u65b9\u6536\u5230\u53d1\u8d77\u65b9\u7684 <code>FIN<\/code> \u540e\uff0c\u4f1a\u53d1\u9001\u4e00\u4e2a <strong>ACK<\/strong> \u62a5\u6587\u6bb5\u3002\n<ul class=\"wp-block-list\">\n<li><code>ACK<\/code> \u6807\u5fd7\u4f4d\u8bbe\u7f6e\u4e3a1\u3002<\/li>\n\n\n\n<li><strong>\u786e\u8ba4\u53f7 (ack)<\/strong> \u8bbe\u7f6e\u4e3a <code>U + 1<\/code>\uff0c\u8868\u793a\u5df2\u6210\u529f\u6536\u5230\u53d1\u8d77\u65b9\u7684 <code>FIN<\/code>\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u901a\u4fd7\u7406\u89e3\uff1a<\/strong> \u670d\u52a1\u5668\u8bf4\uff1a\u201c\u6211\u6536\u5230\u4e86\u4f60\u7684\u5173\u95ed\u8bf7\u6c42\uff08\u786e\u8ba4\u53f7U+1\uff09\u3002\u597d\u7684\uff0c\u6211\u77e5\u9053\u4f60\u4e0d\u518d\u53d1\u9001\u6570\u636e\u4e86\u3002\u201d<\/li>\n\n\n\n<li><strong>\u6ce8\u610f\uff1a<\/strong> \u6b64\u65f6\uff0c\u63a5\u6536\u65b9\u53ef\u80fd\u8fd8\u6709\u6570\u636e\u8981\u53d1\u9001\u7ed9\u53d1\u8d77\u65b9\uff0c\u6240\u4ee5\u8fde\u63a5\u4ecd\u5904\u4e8e\u534a\u5173\u95ed\u72b6\u6001\uff08\u63a5\u6536\u65b9\u4ecd\u53ef\u53d1\u9001\u6570\u636e\uff0c\u53d1\u8d77\u65b9\u4ecd\u53ef\u63a5\u6536\u6570\u636e\uff09\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u7b2c\u4e09\u6b21\u6325\u624b (FIN-ACK)\uff1a\u63a5\u6536\u65b9 -> \u53d1\u8d77\u65b9<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u63a5\u6536\u65b9\u72b6\u6001\uff1a<\/strong> <code>CLOSE-WAIT<\/code> -> <code>LAST-ACK<\/code><\/li>\n\n\n\n<li><strong>\u63a5\u6536\u65b9\u52a8\u4f5c\uff1a<\/strong> \u5f53\u63a5\u6536\u65b9\u4e5f\u5b8c\u6210\u6240\u6709\u6570\u636e\u53d1\u9001\u540e\uff0c\u5b83\u4e5f\u4f1a\u53d1\u9001\u4e00\u4e2a <strong>FIN-ACK<\/strong> \u62a5\u6587\u6bb5\u3002\n<ul class=\"wp-block-list\">\n<li><code>FIN<\/code> \u6807\u5fd7\u4f4d\u8bbe\u7f6e\u4e3a1\u3002<\/li>\n\n\n\n<li><code>ACK<\/code> \u6807\u5fd7\u4f4d\u8bbe\u7f6e\u4e3a1\u3002<\/li>\n\n\n\n<li>\u643a\u5e26\u4e00\u4e2a\u5e8f\u5217\u53f7\uff0c\u4f8b\u5982 <code>seq=V<\/code> (V\u662f\u670d\u52a1\u5668\u4e4b\u524d\u53d1\u9001\u7684\u6700\u540e\u4e00\u4e2a\u5b57\u8282\u7684\u5e8f\u5217\u53f7+1)\u3002<\/li>\n\n\n\n<li><strong>\u786e\u8ba4\u53f7 (ack)<\/strong> \u4ecd\u4e3a <code>U + 1<\/code> (\u6216\u66f4\u65b0\u4e3a <code>U+1<\/code>\uff0c\u5982\u679c\u4e4b\u524d\u6709\u6570\u636e\u53d1\u9001)\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u901a\u4fd7\u7406\u89e3\uff1a<\/strong> \u670d\u52a1\u5668\u8bf4\uff1a\u201c\u6211\u8fd9\u8fb9\u7684\u6570\u636e\u4e5f\u53d1\u5b8c\u4e86\uff0c\u6211\u4e5f\u51c6\u5907\u5173\u95ed\u6211\u7684\u53d1\u9001\u901a\u9053\u4e86\u3002\u6211\u7684\u6700\u540e\u4e00\u4e2a\u5b57\u8282\u662fV\u3002\u201d<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u7b2c\u56db\u6b21\u6325\u624b (ACK)\uff1a\u53d1\u8d77\u65b9 -> \u63a5\u6536\u65b9<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u53d1\u8d77\u65b9\u72b6\u6001\uff1a<\/strong> <code>FIN-WAIT-2<\/code> -> <code>TIME-WAIT<\/code><\/li>\n\n\n\n<li><strong>\u53d1\u8d77\u65b9\u52a8\u4f5c\uff1a<\/strong> \u53d1\u8d77\u65b9\u6536\u5230\u63a5\u6536\u65b9\u7684 <code>FIN<\/code> \u540e\uff0c\u4f1a\u53d1\u9001\u4e00\u4e2a <strong>ACK<\/strong> \u62a5\u6587\u6bb5\u3002\n<ul class=\"wp-block-list\">\n<li><code>ACK<\/code> \u6807\u5fd7\u4f4d\u8bbe\u7f6e\u4e3a1\u3002<\/li>\n\n\n\n<li><strong>\u786e\u8ba4\u53f7 (ack)<\/strong> \u8bbe\u7f6e\u4e3a <code>V + 1<\/code>\uff0c\u8868\u793a\u5df2\u6210\u529f\u6536\u5230\u63a5\u6536\u65b9\u7684 <code>FIN<\/code>\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u901a\u4fd7\u7406\u89e3\uff1a<\/strong> \u5ba2\u6237\u7aef\u8bf4\uff1a\u201c\u6211\u6536\u5230\u4e86\u4f60\u7684\u5173\u95ed\u8bf7\u6c42\uff08\u786e\u8ba4\u53f7V+1\uff09\u3002\u597d\u7684\uff0c\u6211\u4eec\u73b0\u5728\u53ef\u4ee5\u5f7b\u5e95\u65ad\u5f00\u8fde\u63a5\u4e86\uff01\u201d<\/li>\n\n\n\n<li><strong>\u63a5\u6536\u65b9\u72b6\u6001\uff1a<\/strong> <code>LAST-ACK<\/code> -> <code>CLOSED<\/code> (\u6536\u5230\u6700\u540e\u4e00\u4e2aACK\u540e)<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/usual1009.oss-cn-shanghai.aliyuncs.com\/img\/202511291926442.png\" alt=\"image-20251109172207660\"\/><\/figure>\n\n\n\n<p><strong>\u4e3a\u4ec0\u4e48\u662f\u56db\u6b21\u6325\u624b\uff1f<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u5168\u53cc\u5de5\u7279\u6027\uff1a<\/strong> TCP\u8fde\u63a5\u662f\u5168\u53cc\u5de5\u7684\uff0c\u610f\u5473\u7740\u6bcf\u4e2a\u65b9\u5411\u7684\u6570\u636e\u6d41\u90fd\u662f\u72ec\u7acb\u7684\u3002\u5f53\u4e00\u65b9\u5b8c\u6210\u53d1\u9001\u540e\uff0c\u5b83\u53ea\u80fd\u5173\u95ed\u81ea\u5df1\u7684\u53d1\u9001\u901a\u9053\uff0c\u800c\u4e0d\u80fd\u5f3a\u5236\u5173\u95ed\u5bf9\u65b9\u7684\u53d1\u9001\u901a\u9053\u3002\u5bf9\u65b9\u53ef\u80fd\u8fd8\u6709\u6570\u636e\u8981\u53d1\u9001\u3002<\/li>\n\n\n\n<li><strong>\u72ec\u7acb\u5173\u95ed\uff1a<\/strong> \u7b2c\u4e00\u6b21 <code>FIN<\/code> + <code>ACK<\/code> \u5173\u95ed\u4e86\u4ece\u53d1\u8d77\u65b9\u5230\u63a5\u6536\u65b9\u7684\u6570\u636e\u6d41\u3002\u7b2c\u4e8c\u6b21 <code>FIN<\/code> + <code>ACK<\/code> \u5173\u95ed\u4e86\u4ece\u63a5\u6536\u65b9\u5230\u53d1\u8d77\u65b9\u7684\u6570\u636e\u6d41\u3002\u53ea\u6709\u53cc\u65b9\u90fd\u660e\u786e\u8868\u793a\u4e0d\u518d\u53d1\u9001\u6570\u636e\u5e76\u6536\u5230\u5bf9\u65b9\u7684\u786e\u8ba4\uff0c\u8fde\u63a5\u624d\u80fd\u5b8c\u5168\u5173\u95ed\u3002<\/li>\n\n\n\n<li><strong>TIME_WAIT \u72b6\u6001\uff1a<\/strong> \u53d1\u8d77\u65b9\u5728\u53d1\u9001\u5b8c\u6700\u540e\u4e00\u4e2a <code>ACK<\/code> \u540e\uff0c\u4f1a\u8fdb\u5165\u4e00\u4e2a <code>TIME-WAIT<\/code> \u72b6\u6001\uff0c\u5e76\u6301\u7eed\u4e00\u6bb5\u65f6\u95f4\uff08\u901a\u5e38\u662f2MSL\uff0c\u5373\u6700\u957f\u62a5\u6587\u6bb5\u5bff\u547d\u7684\u4e24\u500d\uff09\u3002\n<ul class=\"wp-block-list\">\n<li><strong>\u4f5c\u75281\uff1a<\/strong> \u786e\u4fdd\u6700\u540e\u4e00\u4e2a <code>ACK<\/code> \u62a5\u6587\u6bb5\u80fd\u591f\u5230\u8fbe\u63a5\u6536\u65b9\u3002\u5982\u679c <code>ACK<\/code> \u4e22\u5931\uff0c\u63a5\u6536\u65b9\u4f1a\u91cd\u4f20 <code>FIN<\/code>\uff0c\u53d1\u8d77\u65b9\u53ef\u4ee5\u5728 <code>TIME-WAIT<\/code> \u72b6\u6001\u4e0b\u91cd\u65b0\u53d1\u9001 <code>ACK<\/code>\u3002<\/li>\n\n\n\n<li><strong>\u4f5c\u75282\uff1a<\/strong> \u786e\u4fdd\u5f53\u524d\u8fde\u63a5\u7684\u6240\u6709\u62a5\u6587\u6bb5\u90fd\u5df2\u5728\u7f51\u7edc\u4e2d\u6d88\u5931\u3002\u8fd9\u53ef\u4ee5\u9632\u6b62\u65e7\u8fde\u63a5\u4e2d\u5ef6\u8fdf\u5230\u8fbe\u7684\u62a5\u6587\u6bb5\u88ab\u8bef\u8ba4\u4e3a\u662f\u65b0\u8fde\u63a5\u7684\u62a5\u6587\u6bb5\uff0c\u4ece\u800c\u907f\u514d\u6570\u636e\u6df7\u4e71\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>\u56db\u6b21\u6325\u624b\u8fc7\u7a0b\u4e2d\u5bb9\u6613\u906d\u53d7\u7684\u653b\u51fb\u53ca\u89e3\u51b3\u65b9\u6848\uff1a<\/strong><\/h3>\n\n\n\n<p><strong>\u653b\u51fb\u7c7b\u578b1\uff1aTCP \u91cd\u7f6e\u653b\u51fb (TCP Reset Attack \/ RST Attack)<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u653b\u51fb\u8fc7\u7a0b\uff1a<\/strong> \u653b\u51fb\u8005\u55c5\u63a2\u6b63\u5728\u8fdb\u884c\u7684TCP\u8fde\u63a5\uff0c\u83b7\u53d6\u5230\u8fde\u63a5\u53cc\u65b9\u7684IP\u5730\u5740\u3001\u7aef\u53e3\u53f7\u4ee5\u53ca\u5f53\u524d\u7684\u5e8f\u5217\u53f7\u548c\u786e\u8ba4\u53f7\u3002\u7136\u540e\uff0c\u653b\u51fb\u8005\u4f2a\u9020\u4e00\u4e2a <code>RST<\/code> (Reset) \u62a5\u6587\u6bb5\uff0c\u5176\u4e2d\u5305\u542b\u6b63\u786e\u7684\u6e90IP\u3001\u76ee\u7684IP\u3001\u6e90\u7aef\u53e3\u3001\u76ee\u7684\u7aef\u53e3\uff0c\u4ee5\u53ca\u6700\u91cd\u8981\u7684\u2014\u2014<strong>\u6b63\u786e\u7684\u5e8f\u5217\u53f7\u548c\u786e\u8ba4\u53f7<\/strong>\u3002\u5c06\u8fd9\u4e2a\u4f2a\u9020\u7684 <code>RST<\/code> \u5305\u53d1\u9001\u7ed9\u8fde\u63a5\u7684\u4efb\u610f\u4e00\u65b9\uff08\u901a\u5e38\u662f\u5ba2\u6237\u7aef\u6216\u670d\u52a1\u5668\uff09\u3002<\/li>\n\n\n\n<li><strong>\u653b\u51fb\u539f\u7406\uff1a<\/strong> TCP\u534f\u8bae\u89c4\u5b9a\uff0c\u6536\u5230\u4e00\u4e2a\u5e26\u6709\u6b63\u786e\u5e8f\u5217\u53f7\u548c\u786e\u8ba4\u53f7\u7684 <code>RST<\/code> \u62a5\u6587\u6bb5\u65f6\uff0c\u63a5\u6536\u65b9\u4f1a\u7acb\u5373\u7ec8\u6b62\u5f53\u524d\u7684TCP\u8fde\u63a5\uff0c\u4e0d\u8fdb\u884c\u4efb\u4f55\u786e\u8ba4\u3002<\/li>\n\n\n\n<li><strong>\u653b\u51fb\u5f71\u54cd\uff1a<\/strong> \u5f3a\u5236\u4e2d\u65ad\u6b63\u5728\u8fdb\u884c\u7684\u5408\u6cd5TCP\u8fde\u63a5\uff0c\u5bfc\u81f4\u7528\u6237\u4e0b\u8f7d\u4e2d\u65ad\u3001\u7f51\u9875\u52a0\u8f7d\u5931\u8d25\u3001\u5728\u7ebf\u6e38\u620f\u6389\u7ebf\u7b49\uff0c\u8fd9\u662f\u4e00\u79cd\u6709\u6548\u7684<strong>\u62d2\u7edd\u670d\u52a1\u653b\u51fb<\/strong>\u624b\u6bb5\u3002<\/li>\n<\/ul>\n\n\n\n<p><strong>\u89e3\u51b3\u65b9\u6848\u53ca\u8be6\u7ec6\u89e3\u91ca\uff1a<\/strong><\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u4f7f\u7528\u52a0\u5bc6\u901a\u4fe1 (TLS\/SSL\/VPN)<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u539f\u7406\uff1a<\/strong> \u5f53\u4f7f\u7528TLS\/SSL\uff08\u5982HTTPS\uff09\u6216VPN\u65f6\uff0c\u6240\u6709\u6570\u636e\uff08\u5305\u62ecTCP\u7684\u5e8f\u5217\u53f7\u548c\u786e\u8ba4\u53f7\uff09\u90fd\u4f1a\u88ab\u52a0\u5bc6\u3002\u653b\u51fb\u8005\u5373\u4f7f\u55c5\u63a2\u5230\u6d41\u91cf\uff0c\u4e5f\u65e0\u6cd5\u83b7\u53d6\u5230\u771f\u5b9e\u7684\u3001\u672a\u52a0\u5bc6\u7684\u5e8f\u5217\u53f7\u548c\u786e\u8ba4\u53f7\u3002\u56e0\u6b64\uff0c\u653b\u51fb\u8005\u65e0\u6cd5\u6784\u9020\u51fa\u5e26\u6709\u6b63\u786e\u5e8f\u5217\u53f7\u548c\u786e\u8ba4\u53f7\u7684\u4f2a\u9020 <code>RST<\/code> \u62a5\u6587\u6bb5\u3002<\/li>\n\n\n\n<li><strong>\u539f\u56e0\u89e3\u91ca\uff1a<\/strong> <code>RST<\/code> \u653b\u51fb\u4f9d\u8d56\u4e8e\u5bf9TCP\u5e8f\u5217\u53f7\u7684\u9884\u6d4b\u6216\u55c5\u63a2\u3002\u52a0\u5bc6\u4f7f\u5f97\u8fd9\u4e9b\u5173\u952e\u4fe1\u606f\u5bf9\u653b\u51fb\u8005\u4e0d\u53ef\u89c1\uff0c\u4ece\u800c\u4f7f\u5176\u65e0\u6cd5\u6210\u529f\u4f2a\u9020\u6709\u6548\u7684 <code>RST<\/code> \u5305\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u9632\u706b\u5899\/\u5165\u4fb5\u68c0\u6d4b\u7cfb\u7edf (IDS\/IPS) \u6df1\u5ea6\u5305\u68c0\u6d4b<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u539f\u7406\uff1a<\/strong> \u914d\u7f6e\u9632\u706b\u5899\u6216IDS\/IPS\uff0c\u5bf9\u7ecf\u8fc7\u7684\u6d41\u91cf\u8fdb\u884c\u6df1\u5ea6\u5305\u68c0\u6d4b\u3002\u5b83\u4eec\u53ef\u4ee5\u8ddf\u8e2aTCP\u8fde\u63a5\u7684\u72b6\u6001\u3002\u5982\u679c\u6536\u5230\u4e00\u4e2a <code>RST<\/code> \u62a5\u6587\u6bb5\uff0c\u4f46\u5176\u5e8f\u5217\u53f7\u6216\u786e\u8ba4\u53f7\u4e0d\u7b26\u5408\u5f53\u524d\u8fde\u63a5\u7684\u9884\u671f\u72b6\u6001\uff0c\u6216\u8005\u5176\u6e90IP\/\u7aef\u53e3\u4e0e\u5df2\u5efa\u7acb\u8fde\u63a5\u7684\u5bf9\u7aef\u4e0d\u5339\u914d\uff0c\u5219\u5c06\u5176\u89c6\u4e3a\u5f02\u5e38\u5e76\u4e22\u5f03\u3002<\/li>\n\n\n\n<li><strong>\u539f\u56e0\u89e3\u91ca\uff1a<\/strong> \u5408\u6cd5\u7684 <code>RST<\/code> \u901a\u5e38\u53ea\u5728\u8fde\u63a5\u51fa\u73b0\u4e25\u91cd\u9519\u8bef\u65f6\u7531\u8fde\u63a5\u7684\u5bf9\u7aef\u53d1\u9001\u3002IDS\/IPS\u53ef\u4ee5\u901a\u8fc7\u5206\u6790 <code>RST<\/code> \u5305\u7684\u4e0a\u4e0b\u6587\u548c\u5185\u5bb9\uff0c\u8bc6\u522b\u51fa\u4f2a\u9020\u7684\u3001\u4e0d\u7b26\u5408\u534f\u8bae\u89c4\u8303\u7684 <code>RST<\/code> \u653b\u51fb\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n\n\n\n<p><strong>\u653b\u51fb\u7c7b\u578b2\uff1aFIN \u6d2a\u6cdb\u653b\u51fb (FIN Flood)<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u653b\u51fb\u8fc7\u7a0b\uff1a<\/strong> \u653b\u51fb\u8005\u5411\u76ee\u6807\u670d\u52a1\u5668\u53d1\u9001\u5927\u91cf\u7684 <code>FIN<\/code> \u62a5\u6587\u6bb5\uff0c\u8bf7\u6c42\u5173\u95ed\u8fde\u63a5\u3002\u8fd9\u7c7b\u4f3c\u4e8e <code>SYN<\/code> \u6d2a\u6cdb\uff0c\u4f46\u9488\u5bf9\u7684\u662f\u8fde\u63a5\u7ec8\u6b62\u9636\u6bb5\u3002<\/li>\n\n\n\n<li><strong>\u653b\u51fb\u539f\u7406\uff1a<\/strong> \u670d\u52a1\u5668\u6536\u5230 <code>FIN<\/code> \u540e\uff0c\u9700\u8981\u67e5\u627e\u5bf9\u5e94\u7684\u8fde\u63a5\uff0c\u5e76\u5c06\u5176\u72b6\u6001\u4ece <code>ESTABLISHED<\/code> \u8f6c\u79fb\u5230 <code>CLOSE-WAIT<\/code>\uff0c\u7136\u540e\u6700\u7ec8\u5230 <code>CLOSED<\/code>\u3002\u5982\u679c\u653b\u51fb\u8005\u53d1\u9001\u5927\u91cf <code>FIN<\/code> \u5305\uff0c\u670d\u52a1\u5668\u53ef\u80fd\u9700\u8981\u6d88\u8017\u5927\u91cfCPU\u548c\u5185\u5b58\u8d44\u6e90\u6765\u5904\u7406\u8fd9\u4e9b\u5173\u95ed\u8bf7\u6c42\uff0c\u5c24\u5176\u662f\u5728\u7ef4\u62a4\u5927\u91cf <code>TIME-WAIT<\/code> \u72b6\u6001\u7684\u8fde\u63a5\u65f6\u3002<\/li>\n\n\n\n<li><strong>\u653b\u51fb\u5f71\u54cd\uff1a<\/strong> \u53ef\u80fd\u5bfc\u81f4\u670d\u52a1\u5668\u8d44\u6e90\u8017\u5c3d\uff0c\u5f71\u54cd\u670d\u52a1\u5668\u6027\u80fd\uff0c\u751a\u81f3\u5bfc\u81f4\u62d2\u7edd\u670d\u52a1\u3002<\/li>\n<\/ul>\n\n\n\n<p><strong>\u89e3\u51b3\u65b9\u6848\u53ca\u8be6\u7ec6\u89e3\u91ca\uff1a<\/strong><\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u901f\u7387\u9650\u5236 (Rate Limiting)<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u539f\u7406\uff1a<\/strong> \u5728\u9632\u706b\u5899\u6216\u8d1f\u8f7d\u5747\u8861\u5668\u4e0a\u914d\u7f6e\uff0c\u9650\u5236\u5355\u4e2aIP\u5730\u5740\u6216\u7279\u5b9aIP\u6bb5\u5728\u5355\u4f4d\u65f6\u95f4\u5185\u53d1\u9001\u7684 <code>FIN<\/code> \u62a5\u6587\u6bb5\u6570\u91cf\u3002<\/li>\n\n\n\n<li><strong>\u539f\u56e0\u89e3\u91ca\uff1a<\/strong> \u51cf\u5c11\u6076\u610f <code>FIN<\/code> \u62a5\u6587\u6bb5\u5bf9\u670d\u52a1\u5668\u7684\u51b2\u51fb\uff0c\u4f7f\u5176\u65e0\u6cd5\u5728\u77ed\u65f6\u95f4\u5185\u5904\u7406\u8fc7\u591a\u7684\u5173\u95ed\u8bf7\u6c42\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u8fde\u63a5\u72b6\u6001\u8ddf\u8e2a (Connection State Tracking)<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u539f\u7406\uff1a<\/strong> \u9632\u706b\u5899\u6216IPS\u53ef\u4ee5\u7ef4\u62a4\u6240\u6709TCP\u8fde\u63a5\u7684\u72b6\u6001\u8868\u3002\u53ea\u5141\u8bb8\u9488\u5bf9\u5df2\u5efa\u7acb\u7684\u3001\u6d3b\u8dc3\u7684TCP\u8fde\u63a5\u53d1\u9001 <code>FIN<\/code> \u62a5\u6587\u6bb5\u3002\u5bf9\u4e8e\u90a3\u4e9b\u6ca1\u6709\u5bf9\u5e94\u6d3b\u8dc3\u8fde\u63a5\u7684 <code>FIN<\/code> \u62a5\u6587\u6bb5\uff0c\u76f4\u63a5\u4e22\u5f03\u3002<\/li>\n\n\n\n<li><strong>\u539f\u56e0\u89e3\u91ca\uff1a<\/strong> \u5927\u90e8\u5206 <code>FIN<\/code> \u6d2a\u6cdb\u653b\u51fb\u4f1a\u53d1\u9001\u9488\u5bf9\u4e0d\u5b58\u5728\u6216\u5df2\u5173\u95ed\u8fde\u63a5\u7684 <code>FIN<\/code> \u5305\u3002\u901a\u8fc7\u72b6\u6001\u8ddf\u8e2a\uff0c\u53ef\u4ee5\u6709\u6548\u8fc7\u6ee4\u6389\u8fd9\u4e9b\u65e0\u6548\u7684\u653b\u51fb\u6d41\u91cf\uff0c\u51cf\u8f7b\u670d\u52a1\u5668\u7684\u8d1f\u62c5\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u8c03\u6574 <code>TIME_WAIT<\/code> \u72b6\u6001\u65f6\u95f4 (\u8c28\u614e\u4f7f\u7528)<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u539f\u7406\uff1a<\/strong> \u5728\u67d0\u4e9b\u64cd\u4f5c\u7cfb\u7edf\uff08\u5982Linux\uff09\u4e2d\uff0c\u53ef\u4ee5\u8c03\u6574 <code>TIME_WAIT<\/code> \u72b6\u6001\u7684\u6301\u7eed\u65f6\u95f4\uff08\u4f8b\u5982\u901a\u8fc7 <code>net.ipv4.tcp_fin_timeout<\/code> \u53c2\u6570\uff09\u3002\u5c06\u5176\u7f29\u77ed\u53ef\u4ee5\u66f4\u5feb\u5730\u91ca\u653e\u7aef\u53e3\u8d44\u6e90\u3002<\/li>\n\n\n\n<li><strong>\u539f\u56e0\u89e3\u91ca\uff1a<\/strong> \u7f29\u77ed <code>TIME_WAIT<\/code> \u65f6\u95f4\u53ef\u4ee5\u66f4\u5feb\u5730\u56de\u6536\u8d44\u6e90\uff0c\u4ece\u800c\u5728\u4e00\u5b9a\u7a0b\u5ea6\u4e0a\u7f13\u89e3\u56e0\u5927\u91cf <code>FIN<\/code> \u5bfc\u81f4 <code>TIME_WAIT<\/code> \u72b6\u6001\u8fde\u63a5\u8fc7\u591a\u800c\u8017\u5c3d\u8d44\u6e90\u7684\u95ee\u9898\u3002<strong>\u4f46\u8bf7\u6ce8\u610f\uff0c\u8fd9\u662f\u4e00\u79cd\u6743\u8861\uff0c\u7f29\u77ed <code>TIME_WAIT<\/code> \u53ef\u80fd\u4f1a\u589e\u52a0\u65e7\u6570\u636e\u5305\u5e72\u6270\u65b0\u8fde\u63a5\u7684\u98ce\u9669\uff0c\u56e0\u6b64\u9700\u8c28\u614e\u8bc4\u4f30\u548c\u6d4b\u8bd5\u3002<\/strong><\/li>\n\n\n\n<li><\/li>\n<\/ul>\n<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">\u5907\u6ce8<\/h3>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>SYN<\/strong>\uff1a\u7b80\u5199\u4e3a<code>S<\/code>\uff0c\u540c\u6b65\u6807\u5fd7\u4f4d\uff0c\u7528\u4e8e\u5efa\u7acb\u4f1a\u8bdd\u8fde\u63a5\uff0c\u540c\u6b65\u5e8f\u5217\u53f7\uff1b<\/li>\n\n\n\n<li><strong>ACK<\/strong>\uff1a \u7b80\u5199\u4e3a<code>.<\/code>\uff0c\u786e\u8ba4\u6807\u5fd7\u4f4d\uff0c\u5bf9\u5df2\u63a5\u6536\u7684\u6570\u636e\u5305\u8fdb\u884c\u786e\u8ba4\uff1b<\/li>\n\n\n\n<li><strong>FIN<\/strong>\uff1a \u7b80\u5199\u4e3a<code>F<\/code>\uff0c\u5b8c\u6210\u6807\u5fd7\u4f4d\uff0c\u8868\u793a\u6211\u5df2\u7ecf\u6ca1\u6709\u6570\u636e\u8981\u53d1\u9001\u4e86\uff0c\u5373\u5c06\u5173\u95ed\u8fde\u63a5\uff1b<\/li>\n\n\n\n<li><em>PSH<\/em>\uff1a\u7b80\u5199\u4e3a<code>P<\/code>\uff0c\u63a8\u9001\u6807\u5fd7\u4f4d\uff0c\u8868\u793a\u8be5\u6570\u636e\u5305\u88ab\u5bf9\u65b9\u63a5\u6536\u540e\u5e94\u7acb\u5373\u4ea4\u7ed9\u4e0a\u5c42\u5e94\u7528\uff0c\u800c\u4e0d\u5728\u7f13\u51b2\u533a\u6392\u961f\uff1b<\/li>\n\n\n\n<li><em>RST<\/em>\uff1a\u7b80\u5199\u4e3a<code>R<\/code>\uff0c\u91cd\u7f6e\u6807\u5fd7\u4f4d\uff0c\u7528\u4e8e\u8fde\u63a5\u590d\u4f4d\u3001\u62d2\u7edd\u9519\u8bef\u548c\u975e\u6cd5\u7684\u6570\u636e\u5305\uff1b<\/li>\n\n\n\n<li><em>URG<\/em>\uff1a\u7b80\u5199\u4e3a<code>U<\/code>\uff0c\u7d27\u6025\u6807\u5fd7\u4f4d\uff0c\u8868\u793a\u6570\u636e\u5305\u7684\u7d27\u6025\u6307\u9488\u57df\u6709\u6548\uff0c\u7528\u6765\u4fdd\u8bc1\u8fde\u63a5\u4e0d\u88ab\u963b\u65ad\uff0c\u5e76\u7763\u4fc3\u4e2d\u95f4\u8bbe\u5907\u5c3d\u5feb\u5904\u7406\uff1b<\/li>\n\n\n\n<li><img decoding=\"async\" src=\"https:\/\/usual1009.oss-cn-shanghai.aliyuncs.com\/img\/202511291926538.png\" alt=\"image-20251109180954866\"><\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\">OSI\u4e03\u5c42\u53c2\u8003\u6a21\u578b\u53ca\u5176\u6bcf\u4e00\u5c42\u5e38\u89c1\u7aef\u53e3<\/h2>\n\n\n\n<h2 class=\"wp-block-heading\">TCP UDP\uff08\u4f20\u8f93\u5c42\uff09 \u5206\u522b\u662f\u4ec0\u4e48\uff1f\u533a\u522b\uff1f\u54ea\u4e2a\u66f4\u5b89\u5168<\/h2>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/usual1009.oss-cn-shanghai.aliyuncs.com\/img\/202511291926781.png\" alt=\"image-20251109173718682\"\/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>TCP<\/strong><\/h3>\n\n\n\n<p><strong>(Transmission Control Protocol) - \u4f20\u8f93\u63a7\u5236\u534f\u8bae<\/strong><\/p>\n\n\n\n<p><strong>\u901a\u4fd7\u6bd4\u55bb\uff1a<\/strong> \u60f3\u8c61\u4f60\u7ed9\u670b\u53cb\u5bc4\u4e00\u5c01\u975e\u5e38\u91cd\u8981\u7684\u4fe1\u4ef6\u3002\u4f60\u4e0d\u4ec5\u8981\u786e\u4fdd\u4fe1\u4ef6\u80fd\u5bc4\u5230\uff0c\u8fd8\u8981\u786e\u8ba4\u670b\u53cb\u6536\u5230\u4e86\uff0c\u5e76\u4e14\u4fe1\u4ef6\u5185\u5bb9\u5b8c\u6574\u65e0\u7f3a\uff0c\u987a\u5e8f\u6b63\u786e\u3002\u5982\u679c\u670b\u53cb\u6ca1\u6536\u5230\u6216\u4fe1\u4ef6\u7834\u635f\uff0c\u4f60\u4f1a\u91cd\u65b0\u5bc4\u9001\u3002<\/p>\n\n\n\n<p><strong>\u6838\u5fc3\u7279\u70b9\uff1a<\/strong><\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u9762\u5411\u8fde\u63a5 (Connection-Oriented)\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li>\u5728\u6570\u636e\u4f20\u8f93\u4e4b\u524d\uff0cTCP\u9700\u8981\u901a\u8fc7<strong>\u4e09\u6b21\u63e1\u624b<\/strong>\u5efa\u7acb\u4e00\u4e2a\u903b\u8f91\u8fde\u63a5\u3002<\/li>\n\n\n\n<li>\u5728\u6570\u636e\u4f20\u8f93\u7ed3\u675f\u540e\uff0c\u9700\u8981\u901a\u8fc7<strong>\u56db\u6b21\u6325\u624b<\/strong>\u65ad\u5f00\u8fde\u63a5\u3002<\/li>\n\n\n\n<li><strong>\u539f\u56e0\uff1a<\/strong> \u5efa\u7acb\u8fde\u63a5\u662f\u4e3a\u4e86\u521d\u59cb\u5316\u8fde\u63a5\u53c2\u6570\uff08\u5982\u5e8f\u5217\u53f7\uff09\uff0c\u5e76\u786e\u4fdd\u53cc\u65b9\u90fd\u51c6\u5907\u597d\u8fdb\u884c\u901a\u4fe1\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u53ef\u9760\u4f20\u8f93 (Reliable)\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li>TCP\u4fdd\u8bc1\u6570\u636e\u80fd\u591f<strong>\u51c6\u786e\u65e0\u8bef\u3001\u4e0d\u4e22\u5931\u3001\u4e0d\u91cd\u590d\u3001\u6309\u987a\u5e8f<\/strong>\u5730\u5230\u8fbe\u76ee\u7684\u5730\u3002<\/li>\n\n\n\n<li>\u5b9e\u73b0\u673a\u5236\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u5e8f\u5217\u53f7 (Sequence Numbers)\uff1a<\/strong> \u6bcf\u4e2aTCP\u62a5\u6587\u6bb5\u90fd\u6709\u4e00\u4e2a\u5e8f\u5217\u53f7\uff0c\u7528\u4e8e\u6807\u8bc6\u62a5\u6587\u6bb5\u4e2d\u7684\u6570\u636e\u5b57\u8282\u6d41\uff0c\u786e\u4fdd\u6570\u636e\u6309\u5e8f\u5230\u8fbe\u548c\u91cd\u7ec4\u3002<\/li>\n\n\n\n<li><strong>\u786e\u8ba4\u5e94\u7b54 (Acknowledgments - ACK)\uff1a<\/strong> \u63a5\u6536\u65b9\u6536\u5230\u6570\u636e\u540e\u4f1a\u53d1\u9001\u786e\u8ba4\u5e94\u7b54\uff0c\u544a\u77e5\u53d1\u9001\u65b9\u5df2\u6536\u5230\u54ea\u4e9b\u6570\u636e\u3002<\/li>\n\n\n\n<li><strong>\u8d85\u65f6\u91cd\u4f20 (Retransmission)\uff1a<\/strong> \u5982\u679c\u53d1\u9001\u65b9\u5728\u4e00\u5b9a\u65f6\u95f4\u5185\u6ca1\u6709\u6536\u5230\u786e\u8ba4\u5e94\u7b54\uff0c\u5c31\u4f1a\u8ba4\u4e3a\u6570\u636e\u4e22\u5931\uff0c\u5e76\u91cd\u65b0\u53d1\u9001\u3002<\/li>\n\n\n\n<li><strong>\u6821\u9a8c\u548c (Checksum)\uff1a<\/strong> \u68c0\u67e5\u6570\u636e\u5728\u4f20\u8f93\u8fc7\u7a0b\u4e2d\u662f\u5426\u635f\u574f\u3002<\/li>\n\n\n\n<li><strong>\u6d41\u91cf\u63a7\u5236 (Flow Control)\uff1a<\/strong> \u4f7f\u7528\u201c\u6ed1\u52a8\u7a97\u53e3\u201d\u673a\u5236\uff0c\u9632\u6b62\u53d1\u9001\u65b9\u53d1\u9001\u6570\u636e\u8fc7\u5feb\uff0c\u5bfc\u81f4\u63a5\u6536\u65b9\u6765\u4e0d\u53ca\u5904\u7406\u800c\u6ea2\u51fa\u3002<\/li>\n\n\n\n<li><strong>\u62e5\u585e\u63a7\u5236 (Congestion Control)\uff1a<\/strong> \u907f\u514d\u5411\u7f51\u7edc\u4e2d\u6ce8\u5165\u8fc7\u591a\u6570\u636e\uff0c\u5bfc\u81f4\u7f51\u7edc\u62e5\u5835\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u5168\u53cc\u5de5\u901a\u4fe1 (Full-Duplex)\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li>\u6570\u636e\u53ef\u4ee5\u5728\u4e24\u4e2a\u65b9\u5411\u4e0a\u540c\u65f6\u4f20\u8f93\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u57fa\u4e8e\u5b57\u8282\u6d41 (Byte Stream)\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li>TCP\u4e0d\u5173\u5fc3\u5e94\u7528\u7a0b\u5e8f\u53d1\u9001\u7684\u6570\u636e\u5757\u5927\u5c0f\uff0c\u5b83\u5c06\u5e94\u7528\u7a0b\u5e8f\u6570\u636e\u89c6\u4e3a\u4e00\u4e32\u65e0\u7ed3\u6784\u7684\u5b57\u8282\u6d41\uff0c\u7136\u540e\u6839\u636e\u9700\u8981\u8fdb\u884c\u5206\u6bb5\u53d1\u9001\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n\n\n\n<p><strong>\u9002\u7528\u573a\u666f\uff1a<\/strong> \u5bf9\u6570\u636e\u5b8c\u6574\u6027\u3001\u987a\u5e8f\u548c\u53ef\u9760\u6027\u8981\u6c42\u9ad8\u7684\u5e94\u7528\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Web \u6d4f\u89c8 (HTTP\/HTTPS)\uff1a<\/strong> \u786e\u4fdd\u7f51\u9875\u5185\u5bb9\u5b8c\u6574\u52a0\u8f7d\u3002<\/li>\n\n\n\n<li><strong>\u6587\u4ef6\u4f20\u8f93 (FTP)\uff1a<\/strong> \u786e\u4fdd\u6587\u4ef6\u4f20\u8f93\u65e0\u8bef\u3002<\/li>\n\n\n\n<li><strong>\u7535\u5b50\u90ae\u4ef6 (SMTP\/POP3\/IMAP)\uff1a<\/strong> \u786e\u4fdd\u90ae\u4ef6\u5185\u5bb9\u5b8c\u6574\u3002<\/li>\n\n\n\n<li><strong>\u5b89\u5168\u5916\u58f3 (SSH)\uff1a<\/strong> \u786e\u4fdd\u8fdc\u7a0b\u63a7\u5236\u547d\u4ee4\u51c6\u786e\u65e0\u8bef\u3002<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>UDP<\/strong><\/h3>\n\n\n\n<p><strong>(User Datagram Protocol) - \u7528\u6237\u6570\u636e\u62a5\u534f\u8bae<\/strong><\/p>\n\n\n\n<p><strong>\u901a\u4fd7\u6bd4\u55bb\uff1a<\/strong> \u60f3\u8c61\u4f60\u7ed9\u670b\u53cb\u5bc4\u4e00\u5f20\u660e\u4fe1\u7247\u3002\u4f60\u5199\u597d\u5c31\u5bc4\u51fa\u53bb\uff0c\u4e0d\u5173\u5fc3\u670b\u53cb\u662f\u5426\u6536\u5230\uff0c\u4e5f\u4e0d\u7ba1\u660e\u4fe1\u7247\u662f\u5426\u4f1a\u4e22\u5931\u6216\u987a\u5e8f\u98a0\u5012\u3002\u4f60\u53ea\u56fe\u4e00\u4e2a\u201c\u5feb\u201d\u3002<\/p>\n\n\n\n<p><strong>\u6838\u5fc3\u7279\u70b9\uff1a<\/strong><\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u65e0\u8fde\u63a5 (Connectionless)\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li>UDP\u5728\u6570\u636e\u4f20\u8f93\u4e4b\u524d<strong>\u4e0d\u9700\u8981\u5efa\u7acb\u8fde\u63a5<\/strong>\u3002<\/li>\n\n\n\n<li>\u53d1\u9001\u65b9\u76f4\u63a5\u5c06\u6570\u636e\u62a5\u53d1\u9001\u51fa\u53bb\uff0c\u4e0d\u5173\u5fc3\u63a5\u6536\u65b9\u662f\u5426\u5728\u7ebf\u6216\u662f\u5426\u51c6\u5907\u597d\u63a5\u6536\u3002<\/li>\n\n\n\n<li><strong>\u539f\u56e0\uff1a<\/strong> \u7701\u53bb\u4e86\u5efa\u7acb\u548c\u65ad\u5f00\u8fde\u63a5\u7684\u5f00\u9500\uff0c\u4f20\u8f93\u901f\u5ea6\u66f4\u5feb\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u4e0d\u53ef\u9760\u4f20\u8f93 (Unreliable)\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li>UDP<strong>\u4e0d\u4fdd\u8bc1<\/strong>\u6570\u636e\u80fd\u591f\u51c6\u786e\u65e0\u8bef\u3001\u4e0d\u4e22\u5931\u3001\u4e0d\u91cd\u590d\u3001\u6309\u987a\u5e8f\u5730\u5230\u8fbe\u76ee\u7684\u5730\u3002<\/li>\n\n\n\n<li><strong>\u6ca1\u6709\u5b9e\u73b0\u673a\u5236\uff1a<\/strong> \u6ca1\u6709\u5e8f\u5217\u53f7\u3001\u6ca1\u6709\u786e\u8ba4\u5e94\u7b54\u3001\u6ca1\u6709\u8d85\u65f6\u91cd\u4f20\u3001\u6ca1\u6709\u6d41\u91cf\u63a7\u5236\u3001\u6ca1\u6709\u62e5\u585e\u63a7\u5236\u3002<\/li>\n\n\n\n<li><strong>\u539f\u56e0\uff1a<\/strong> \u8fd9\u4e9b\u673a\u5236\u4f1a\u589e\u52a0\u5f00\u9500\uff0c\u964d\u4f4e\u4f20\u8f93\u901f\u5ea6\u3002UDP\u5c06\u8fd9\u4e9b\u53ef\u9760\u6027\u4fdd\u8bc1\u7684\u4efb\u52a1\u7559\u7ed9\u4e86\u5e94\u7528\u5c42\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u62a5\u6587\u6bb5\u5bfc\u5411 (Datagram-Oriented)\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li>UDP\u4fdd\u7559\u4e86\u5e94\u7528\u7a0b\u5e8f\u53d1\u9001\u7684\u62a5\u6587\u8fb9\u754c\u3002\u53d1\u9001\u65b9\u53d1\u9001\u4e00\u4e2aUDP\u6570\u636e\u62a5\uff0c\u63a5\u6536\u65b9\u5c31\u6536\u5230\u4e00\u4e2aUDP\u6570\u636e\u62a5\uff0c\u4e0d\u4f1a\u8fdb\u884c\u62c6\u5206\u6216\u5408\u5e76\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u5934\u90e8\u5f00\u9500\u5c0f (Low Overhead)\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li>UDP\u5934\u90e8\u53ea\u67098\u4e2a\u5b57\u8282\uff08\u6e90\u7aef\u53e3\u3001\u76ee\u7684\u7aef\u53e3\u3001\u957f\u5ea6\u3001\u6821\u9a8c\u548c\uff09\uff0c\u800cTCP\u5934\u90e8\u81f3\u5c11\u670920\u4e2a\u5b57\u8282\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n\n\n\n<p><strong>\u9002\u7528\u573a\u666f\uff1a<\/strong> \u5bf9\u5b9e\u65f6\u6027\u8981\u6c42\u9ad8\uff0c\u5141\u8bb8\u5c11\u91cf\u6570\u636e\u4e22\u5931\uff0c\u6216\u8005\u5e94\u7528\u5c42\u81ea\u5df1\u5b9e\u73b0\u53ef\u9760\u6027\u673a\u5236\u7684\u5e94\u7528\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u5b9e\u65f6\u97f3\u89c6\u9891\u4f20\u8f93 (VoIP, Video Streaming)\uff1a<\/strong> \u4e22\u5931\u51e0\u4e2a\u6570\u636e\u5305\u53ef\u80fd\u53ea\u662f\u753b\u9762\u5361\u987f\u6216\u58f0\u97f3\u5931\u771f\uff0c\u4f46\u7b49\u5f85\u91cd\u4f20\u4f1a\u5bfc\u81f4\u4e25\u91cd\u5ef6\u8fdf\uff0c\u5f71\u54cd\u7528\u6237\u4f53\u9a8c\u3002<\/li>\n\n\n\n<li><strong>\u5728\u7ebf\u6e38\u620f\uff1a<\/strong> \u5b9e\u65f6\u6027\u81f3\u5173\u91cd\u8981\uff0c\u77ed\u6682\u7684\u5ef6\u8fdf\u6bd4\u4e22\u5931\u51e0\u4e2a\u753b\u9762\u66f4\u65b0\u66f4\u7cdf\u7cd5\u3002<\/li>\n\n\n\n<li><strong>\u57df\u540d\u7cfb\u7edf (DNS)\uff1a<\/strong> \u5feb\u901f\u67e5\u8be2\u548c\u54cd\u5e94\uff0c\u901a\u5e38\u662f\u5c0f\u6570\u636e\u5305\uff0c\u4e22\u5931\u53ef\u4ee5\u91cd\u8bd5\u3002<\/li>\n\n\n\n<li><strong>\u7f51\u7edc\u7ba1\u7406\u534f\u8bae (SNMP)\uff1a<\/strong> \u76d1\u63a7\u7f51\u7edc\u8bbe\u5907\uff0c\u5feb\u901f\u53d1\u9001\u72b6\u6001\u4fe1\u606f\u3002<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>\u4e3b\u8981\u533a\u522b\u603b\u7ed3<\/strong><\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u7279\u5f81<\/th><th>TCP (\u4f20\u8f93\u63a7\u5236\u534f\u8bae)<\/th><th>UDP (\u7528\u6237\u6570\u636e\u62a5\u534f\u8bae)<\/th><\/tr><\/thead><tbody><tr><td><strong>\u8fde\u63a5\u6027<\/strong><\/td><td>\u9762\u5411\u8fde\u63a5 (\u4e09\u6b21\u63e1\u624b\u5efa\u7acb\uff0c\u56db\u6b21\u6325\u624b\u65ad\u5f00)<\/td><td>\u65e0\u8fde\u63a5<\/td><\/tr><tr><td><strong>\u53ef\u9760\u6027<\/strong><\/td><td>\u53ef\u9760\u4f20\u8f93 (\u4fdd\u8bc1\u6570\u636e\u4e0d\u4e22\u5931\u3001\u4e0d\u91cd\u590d\u3001\u6309\u5e8f\u5230\u8fbe)<\/td><td>\u4e0d\u53ef\u9760\u4f20\u8f93 (\u4e0d\u4fdd\u8bc1\u6570\u636e\u5230\u8fbe)<\/td><\/tr><tr><td><strong>\u4f20\u8f93\u65b9\u5f0f<\/strong><\/td><td>\u5b57\u8282\u6d41 (\u5e94\u7528\u7a0b\u5e8f\u6570\u636e\u88ab\u89c6\u4e3a\u5b57\u8282\u6d41\uff0cTCP\u8fdb\u884c\u5206\u6bb5)<\/td><td>\u6570\u636e\u62a5 (\u4fdd\u7559\u5e94\u7528\u7a0b\u5e8f\u53d1\u9001\u7684\u62a5\u6587\u8fb9\u754c)<\/td><\/tr><tr><td><strong>\u4f20\u8f93\u901f\u5ea6<\/strong><\/td><td>\u76f8\u5bf9\u8f83\u6162 (\u56e0\u53ef\u9760\u6027\u673a\u5236\u548c\u8fde\u63a5\u7ba1\u7406\u5f00\u9500)<\/td><td>\u76f8\u5bf9\u8f83\u5feb (\u5f00\u9500\u5c0f\uff0c\u76f4\u63a5\u53d1\u9001)<\/td><\/tr><tr><td><strong>\u5934\u90e8\u5927\u5c0f<\/strong><\/td><td>20-60 \u5b57\u8282<\/td><td>8 \u5b57\u8282<\/td><\/tr><tr><td><strong>\u6d41\u91cf\u63a7\u5236<\/strong><\/td><td>\u6709 (\u6ed1\u52a8\u7a97\u53e3\u673a\u5236)<\/td><td>\u65e0<\/td><\/tr><tr><td><strong>\u62e5\u585e\u63a7\u5236<\/strong><\/td><td>\u6709 (\u6162\u542f\u52a8\u3001\u62e5\u585e\u907f\u514d\u7b49\u7b97\u6cd5)<\/td><td>\u65e0<\/td><\/tr><tr><td><strong>\u9002\u7528\u573a\u666f<\/strong><\/td><td>\u6587\u4ef6\u4f20\u8f93\u3001Web\u6d4f\u89c8\u3001\u90ae\u4ef6\u3001SSH\u7b49<\/td><td>\u5b9e\u65f6\u97f3\u89c6\u9891\u3001\u5728\u7ebf\u6e38\u620f\u3001DNS\u3001SNMP\u7b49<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>TCP\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u662f\u4ec0\u4e48\uff1a<\/strong> \u9762\u5411\u8fde\u63a5\u3001\u53ef\u9760\u7684\u4f20\u8f93\u534f\u8bae\u3002<\/li>\n\n\n\n<li>\u7279\u70b9\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u4e09\u6b21\u63e1\u624b<\/strong>\u5efa\u7acb\u8fde\u63a5\uff0c<strong>\u56db\u6b21\u6325\u624b<\/strong>\u65ad\u5f00\u8fde\u63a5\u3002<\/li>\n\n\n\n<li><strong>\u6570\u636e\u6309\u5e8f\u5230\u8fbe<\/strong>\uff0c<strong>\u65e0\u5dee\u9519<\/strong>\uff0c<strong>\u65e0\u4e22\u5931<\/strong>\u3002<\/li>\n\n\n\n<li>\u6709\u6d41\u91cf\u63a7\u5236\u3001\u62e5\u585e\u63a7\u5236\u673a\u5236\u3002<\/li>\n\n\n\n<li>\u5f00\u9500\u8f83\u5927\uff0c\u4f20\u8f93\u6548\u7387\u76f8\u5bf9\u4f4e\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u7c7b\u6bd4\uff1a<\/strong> \u6253\u7535\u8bdd\uff0c\u9700\u8981\u5148\u63a5\u901a\uff0c\u901a\u8bdd\u8fc7\u7a0b\u7a33\u5b9a\u53ef\u9760\u3002<\/li>\n\n\n\n<li><strong>\u5e94\u7528\uff1a<\/strong> HTTP, HTTPS, FTP, SSH, SMTP, POP3, IMAP \u7b49\u3002<\/li>\n\n\n\n<li><strong>CTF \u610f\u4e49\uff1a<\/strong> SYN Flood \u653b\u51fb\u3001TCP \u4f1a\u8bdd\u52ab\u6301\u3001\u7aef\u53e3\u626b\u63cf\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>UDP\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u662f\u4ec0\u4e48\uff1a<\/strong> \u65e0\u8fde\u63a5\u3001\u4e0d\u53ef\u9760\u7684\u4f20\u8f93\u534f\u8bae\u3002<\/li>\n\n\n\n<li>\u7279\u70b9\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u65e0\u9700\u5efa\u7acb\u8fde\u63a5<\/strong>\uff0c\u76f4\u63a5\u53d1\u9001\u6570\u636e\u3002<\/li>\n\n\n\n<li><strong>\u4e0d\u4fdd\u8bc1\u6570\u636e\u5230\u8fbe<\/strong>\uff0c\u4e0d\u4fdd\u8bc1\u987a\u5e8f\uff0c\u53ef\u80fd\u4e22\u5931\u3001\u91cd\u590d\u6216\u4e71\u5e8f\u3002<\/li>\n\n\n\n<li>\u65e0\u6d41\u91cf\u63a7\u5236\u3001\u62e5\u585e\u63a7\u5236\u3002<\/li>\n\n\n\n<li>\u5f00\u9500\u5c0f\uff0c\u4f20\u8f93\u6548\u7387\u9ad8\uff0c\u5ef6\u8fdf\u4f4e\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u7c7b\u6bd4\uff1a<\/strong> \u5bc4\u660e\u4fe1\u7247\uff0c\u53d1\u51fa\u53bb\u5c31\u4e0d\u7ba1\u4e86\uff0c\u4e0d\u4fdd\u8bc1\u5bf9\u65b9\u4e00\u5b9a\u6536\u5230\u3002<\/li>\n\n\n\n<li><strong>\u5e94\u7528\uff1a<\/strong> DNS, NTP, SNMP, VoIP, \u5728\u7ebf\u6e38\u620f\u7b49\u3002<\/li>\n\n\n\n<li><strong>CTF \u610f\u4e49\uff1a<\/strong> UDP Flood \u653b\u51fb\u3001DNS \u653e\u5927\u653b\u51fb\u3001NTP \u653e\u5927\u653b\u51fb\u3001\u7aef\u53e3\u626b\u63cf\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u4e3b\u8981\u533a\u522b\uff1a<\/strong> TCP \u53ef\u9760\u3001\u9762\u5411\u8fde\u63a5\uff1bUDP \u4e0d\u53ef\u9760\u3001\u65e0\u8fde\u63a5\u3002<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>\u54ea\u4e2a\u66f4\u201c\u5b89\u5168\u201d\uff1f<\/strong><\/h3>\n\n\n\n<p>\u5f53\u6211\u4eec\u8c08\u8bbaTCP\u548cUDP\u54ea\u4e2a\u66f4\u201c\u5b89\u5168\u201d\u65f6\uff0c\u9700\u8981\u6f84\u6e05\u201c\u5b89\u5168\u201d\u7684\u542b\u4e49\u3002<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u6570\u636e\u5b8c\u6574\u6027\u4e0e\u53ef\u9760\u6027\u65b9\u9762\u7684\u201c\u5b89\u5168\u201d\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>TCP \u66f4\u201c\u5b89\u5168\u201d<\/strong>\u3002TCP\u901a\u8fc7\u5176\u53ef\u9760\u6027\u673a\u5236\uff08\u5e8f\u5217\u53f7\u3001\u786e\u8ba4\u5e94\u7b54\u3001\u91cd\u4f20\u3001\u6821\u9a8c\u548c\u7b49\uff09\u786e\u4fdd\u6570\u636e\u5728\u4f20\u8f93\u8fc7\u7a0b\u4e2d\u4e0d\u4f1a\u4e22\u5931\u3001\u635f\u574f\u6216\u4e71\u5e8f\u3002\u5b83\u4fdd\u8bc1\u4e86<strong>\u6570\u636e\u4f20\u8f93\u7684\u5b8c\u6574\u6027\u548c\u51c6\u786e\u6027<\/strong>\u3002\u4ece\u8fd9\u4e2a\u89d2\u5ea6\u770b\uff0cTCP\u63d0\u4f9b\u4e86\u66f4\u9ad8\u7684\u201c\u5b89\u5168\u6027\u201d\uff0c\u56e0\u4e3a\u5b83\u786e\u4fdd\u4e86\u4f60\u53d1\u9001\u7684\u6570\u636e\u5c31\u662f\u63a5\u6536\u65b9\u6536\u5230\u7684\u6570\u636e\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u52a0\u5bc6\u4e0e\u9690\u79c1\u65b9\u9762\u7684\u201c\u5b89\u5168\u201d\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>TCP \u548c UDP \u672c\u8eab\u90fd\u4e0d\u63d0\u4f9b\u52a0\u5bc6\u6216\u9690\u79c1\u4fdd\u62a4\u3002<\/strong> \u5b83\u4eec\u53ea\u662f\u4f20\u8f93\u534f\u8bae\uff0c\u4e0d\u8d1f\u8d23\u6570\u636e\u7684\u52a0\u5bc6\u3002<\/li>\n\n\n\n<li>\u771f\u6b63\u7684\u52a0\u5bc6\u5b89\u5168\u6027\u662f\u7531\u66f4\u9ad8\u5c42\u7684\u534f\u8bae\u63d0\u4f9b\u7684\uff0c\u4f8b\u5982\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>TLS\/SSL\uff1a<\/strong> \u901a\u5e38\u8fd0\u884c\u5728TCP\u4e4b\u4e0a\uff08\u5982HTTPS\uff09\uff0c\u63d0\u4f9b\u6570\u636e\u52a0\u5bc6\u3001\u8eab\u4efd\u9a8c\u8bc1\u548c\u5b8c\u6574\u6027\u4fdd\u62a4\u3002<\/li>\n\n\n\n<li><strong>IPsec\uff1a<\/strong> \u8fd0\u884c\u5728\u7f51\u7edc\u5c42\uff0c\u53ef\u4ee5\u4e3aTCP\u548cUDP\u6d41\u91cf\u63d0\u4f9b\u52a0\u5bc6\u548c\u8eab\u4efd\u9a8c\u8bc1\u3002<\/li>\n\n\n\n<li><strong>VPN\uff1a<\/strong> \u53ef\u4ee5\u5728IP\u5c42\u6216\u66f4\u9ad8\u5c42\u521b\u5efa\u52a0\u5bc6\u96a7\u9053\uff0c\u4fdd\u62a4TCP\u548cUDP\u6d41\u91cf\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\">TCP\u7ed3\u6784\u4e0eOSI\u7ed3\u6784\u7684\u5bf9\u6bd4\u5173\u7cfb<\/h2>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/usual1009.oss-cn-shanghai.aliyuncs.com\/img\/202511291926940.png\" alt=\"image-20251109173520756\"\/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">\u6570\u636e\u7684\u5c01\u88c5\u4e0e\u89e3\u5c01\u56fe\uff08TCP\/IP\u4f53\u7cfb\uff09<\/h2>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/usual1009.oss-cn-shanghai.aliyuncs.com\/img\/202511291927186.png\" alt=\"image-20251109175114899\"\/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/usual1009.oss-cn-shanghai.aliyuncs.com\/img\/202511291927382.png\" alt=\"image-20251109175714422\"\/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">OSI\u4e03\u5c42\u6a21\u578b<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">\u603b\u6982<\/h3>\n\n\n\n<p><strong>\u80cc\u666f\uff1a<\/strong> OSI\u6a21\u578b\u662f\u7531\u56fd\u9645\u6807\u51c6\u5316\u7ec4\u7ec7 (ISO) \u57281980\u5e74\u4ee3\u63d0\u51fa\u7684\u4e00\u4e2a\u6982\u5ff5\u6027\u6846\u67b6\uff0c\u65e8\u5728\u5b9a\u4e49\u7f51\u7edc\u901a\u4fe1\u7684\u5404\u4e2a\u9636\u6bb5\uff0c\u4f7f\u4e0d\u540c\u5382\u5546\u7684\u786c\u4ef6\u548c\u8f6f\u4ef6\u80fd\u591f\u76f8\u4e92\u517c\u5bb9\u3002\u5b83\u5c06\u590d\u6742\u7684\u7f51\u7edc\u901a\u4fe1\u8fc7\u7a0b\u5212\u5206\u4e3a\u4e03\u4e2a\u903b\u8f91\u4e0a\u72ec\u7acb\u7684\u5c42\u6b21\u3002<\/p>\n\n\n\n<p><strong>\u6838\u5fc3\u601d\u60f3\uff1a<\/strong> \u6bcf\u4e00\u5c42\u90fd\u4e3a\u4e0a\u4e00\u5c42\u63d0\u4f9b\u670d\u52a1\uff0c\u5e76\u4f7f\u7528\u4e0b\u4e00\u5c42\u63d0\u4f9b\u7684\u670d\u52a1\u3002\u5c42\u4e0e\u5c42\u4e4b\u95f4\u901a\u8fc7\u63a5\u53e3\u8fdb\u884c\u901a\u4fe1\uff0c\u6bcf\u5c42\u53ea\u5173\u5fc3\u81ea\u5df1\u7684\u529f\u80fd\uff0c\u4e0d\u5173\u5fc3\u5176\u4ed6\u5c42\u7684\u5177\u4f53\u5b9e\u73b0\u3002\u8fd9\u79cd\u5206\u5c42\u8bbe\u8ba1\u4f7f\u5f97\u7f51\u7edc\u534f\u8bae\u7684\u5f00\u53d1\u548c\u7ef4\u62a4\u66f4\u52a0\u6a21\u5757\u5316\u548c\u9ad8\u6548\u3002<\/p>\n\n\n\n<p><strong>\u6570\u636e\u5c01\u88c5\u4e0e\u89e3\u5c01\u88c5\uff1a<\/strong> \u6570\u636e\u4ece\u5e94\u7528\u5c42\u5411\u4e0b\u4f20\u9012\u65f6\uff0c\u6bcf\u4e00\u5c42\u90fd\u4f1a\u7ed9\u6570\u636e\u6dfb\u52a0\u81ea\u5df1\u7684<strong>\u5934\u90e8 (Header)<\/strong> \u4fe1\u606f\uff08\u6709\u65f6\u8fd8\u6709\u5c3e\u90e8\uff09\uff0c\u8fd9\u4e2a\u8fc7\u7a0b\u79f0\u4e3a<strong>\u5c01\u88c5 (Encapsulation)<\/strong>\u3002\u6570\u636e\u5230\u8fbe\u76ee\u7684\u4e3b\u673a\u540e\uff0c\u4ece\u7269\u7406\u5c42\u5411\u4e0a\u9012\u4ea4\u65f6\uff0c\u6bcf\u4e00\u5c42\u90fd\u4f1a\u5265\u79bb\u6389\u5bf9\u5e94\u7684\u5934\u90e8\u4fe1\u606f\uff0c\u8fd9\u4e2a\u8fc7\u7a0b\u79f0\u4e3a<strong>\u89e3\u5c01\u88c5 (Decapsulation)<\/strong>\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/usual1009.oss-cn-shanghai.aliyuncs.com\/img\/202511291927425.png\" alt=\"image-20251109175659204\"\/><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>OSI \u4e03\u5c42\u6a21\u578b\u8be6\u89e3\u53ca\u7aef\u53e3\u5173\u8054<\/strong><\/h3>\n\n\n\n<p><strong>\u91cd\u8981\u63d0\u793a\uff1a<\/strong> <strong>\u7aef\u53e3 (Port)<\/strong> \u662f\u4e00\u4e2a<strong>\u4f20\u8f93\u5c42 (Transport Layer, \u7b2c\u56db\u5c42)<\/strong> \u7684\u6982\u5ff5\uff0c\u7528\u4e8e\u6807\u8bc6\u4e00\u53f0\u4e3b\u673a\u4e0a\u4e0d\u540c\u7684\u5e94\u7528\u7a0b\u5e8f\u6216\u670d\u52a1\u8fdb\u7a0b\u3002\u56e0\u6b64\uff0c\u4e25\u683c\u6765\u8bf4\uff0c\u53ea\u6709\u4f20\u8f93\u5c42\u548c\u5e94\u7528\u5c42\uff08\u901a\u8fc7\u4f20\u8f93\u5c42\uff09\u624d\u4e0e\u7aef\u53e3\u76f4\u63a5\u76f8\u5173\u3002\u5176\u4ed6\u5c42\u6ca1\u6709\u201c\u7aef\u53e3\u201d\u7684\u6982\u5ff5\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>\u7b2c\u4e00\u5c42\uff1a\u7269\u7406\u5c42 (Physical Layer)<\/strong><\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u529f\u80fd\uff1a<\/strong> \u8d1f\u8d23\u6570\u636e\u5728\u7269\u7406\u4f20\u8f93\u4ecb\u8d28\u4e0a\u7684\u539f\u59cb\u6bd4\u7279\u6d41\u4f20\u8f93\u3002\u5b83\u5b9a\u4e49\u4e86\u7269\u7406\u63a5\u53e3\u7684\u7535\u6c14\u3001\u673a\u68b0\u3001\u8fc7\u7a0b\u548c\u529f\u80fd\u7279\u6027\u3002<\/li>\n\n\n\n<li><strong>\u4f20\u8f93\u5355\u4f4d\uff1a<\/strong> <strong>\u6bd4\u7279 (Bit)<\/strong>\u3002<\/li>\n\n\n\n<li>\u5173\u952e\u6982\u5ff5\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u4ecb\u8d28\uff1a<\/strong> \u7f51\u7ebf\uff08\u53cc\u7ede\u7ebf\u3001\u5149\u7ea4\uff09\u3001\u65e0\u7ebf\u7535\u6ce2\u7b49\u3002<\/li>\n\n\n\n<li><strong>\u4fe1\u53f7\uff1a<\/strong> \u7535\u538b\u3001\u5149\u8109\u51b2\u3001\u65e0\u7ebf\u9891\u7387\u7b49\u3002<\/li>\n\n\n\n<li><strong>\u62d3\u6251\uff1a<\/strong> \u661f\u578b\u3001\u603b\u7ebf\u578b\u3001\u73af\u578b\u7b49\u3002<\/li>\n\n\n\n<li><strong>\u7f16\u7801\uff1a<\/strong> \u5982\u4f55\u5c06\u6bd4\u7279\u8f6c\u6362\u4e3a\u7269\u7406\u4fe1\u53f7\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u5e38\u89c1\u8bbe\u5907\uff1a<\/strong> \u7f51\u7ebf\u3001\u7f51\u5361\u3001\u96c6\u7ebf\u5668 (Hub)\u3001\u4e2d\u7ee7\u5668 (Repeater)\u3002<\/li>\n\n\n\n<li><strong>\u901a\u4fd7\u6bd4\u55bb\uff1a<\/strong> \u5c31\u50cf\u4fee\u5efa\u9053\u8def\u548c\u94fa\u8bbe\u7535\u7ebf\uff0c\u786e\u4fdd\u4fe1\u606f\u80fd\u4ee5\u7269\u7406\u5f62\u5f0f\u4f20\u8f93\u3002<\/li>\n\n\n\n<li><strong>\u4e0e\u7aef\u53e3\u7684\u5173\u8054\uff1a<\/strong> <strong>\u65e0\u3002<\/strong> \u7269\u7406\u5c42\u53ea\u5173\u5fc3\u6bd4\u7279\u6d41\u7684\u4f20\u8f93\uff0c\u4e0d\u6d89\u53ca\u4efb\u4f55\u903b\u8f91\u4e0a\u7684\u5e94\u7528\u7a0b\u5e8f\u6807\u8bc6\u3002<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>\u7b2c\u4e8c\u5c42\uff1a\u6570\u636e\u94fe\u8def\u5c42 (Data Link Layer)<\/strong><\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u529f\u80fd\uff1a<\/strong> \u5728\u7269\u7406\u5c42\u63d0\u4f9b\u7684\u4e0d\u53ef\u9760\u6bd4\u7279\u6d41\u4f20\u8f93\u57fa\u7840\u4e0a\uff0c\u5efa\u7acb\u3001\u7ef4\u62a4\u548c\u91ca\u653e\u6570\u636e\u94fe\u8def\uff0c\u8fdb\u884c<strong>\u5e27 (Frame)<\/strong> \u7684\u4f20\u8f93\uff0c\u5e76\u63d0\u4f9b<strong>\u9519\u8bef\u68c0\u6d4b\u548c\u7ea0\u6b63<\/strong>\uff08\u5728\u67d0\u4e9b\u5b50\u5c42\uff09\u3002\u5b83\u8d1f\u8d23\u5728<strong>\u5c40\u57df\u7f51 (LAN)<\/strong> \u5185\u7684\u76f8\u90bb\u8282\u70b9\u4e4b\u95f4\u53ef\u9760\u5730\u4f20\u8f93\u6570\u636e\u3002<\/li>\n\n\n\n<li><strong>\u4f20\u8f93\u5355\u4f4d\uff1a<\/strong> <strong>\u5e27 (Frame)<\/strong>\u3002<\/li>\n\n\n\n<li>\u5173\u952e\u6982\u5ff5\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>MAC \u5730\u5740 (Media Access Control Address)\uff1a<\/strong> \u7269\u7406\u5730\u5740\uff0c\u5168\u7403\u552f\u4e00\uff0c\u7528\u4e8e\u5728\u5c40\u57df\u7f51\u5185\u6807\u8bc6\u7f51\u7edc\u8bbe\u5907\u3002<\/li>\n\n\n\n<li><strong>ARP (Address Resolution Protocol)\uff1a<\/strong> \u5730\u5740\u89e3\u6790\u534f\u8bae\uff0c\u5c06IP\u5730\u5740\u89e3\u6790\u4e3aMAC\u5730\u5740\u3002<\/li>\n\n\n\n<li><strong>\u4ea4\u6362\u673a (Switch)\uff1a<\/strong> \u6839\u636eMAC\u5730\u5740\u8f6c\u53d1\u5e27\u3002<\/li>\n\n\n\n<li><strong>LLC (Logical Link Control) \u5b50\u5c42\uff1a<\/strong> \u63d0\u4f9b\u6570\u636e\u94fe\u8def\u670d\u52a1\u8bbf\u95ee\u70b9 (DSAP\/SSAP)\uff0c\u4e0e\u7f51\u7edc\u5c42\u63a5\u53e3\u3002<\/li>\n\n\n\n<li><strong>MAC (Media Access Control) \u5b50\u5c42\uff1a<\/strong> \u8d1f\u8d23\u4ecb\u8d28\u8bbf\u95ee\u63a7\u5236\u3001\u5e27\u7684\u5c01\u88c5\u548c\u89e3\u5c01\u88c5\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u5e38\u89c1\u534f\u8bae\uff1a<\/strong> \u4ee5\u592a\u7f51 (Ethernet)\u3001Wi-Fi (802.11)\u3001PPP (Point-to-Point Protocol)\u3002<\/li>\n\n\n\n<li><strong>\u5e38\u89c1\u8bbe\u5907\uff1a<\/strong> \u7f51\u5361\u3001\u4ea4\u6362\u673a (Switch)\u3002<\/li>\n\n\n\n<li><strong>\u901a\u4fd7\u6bd4\u55bb\uff1a<\/strong> \u5c31\u50cf\u5728\u4e00\u6761\u7279\u5b9a\u7684\u9053\u8def\u4e0a\uff0c\u8f66\u8f86\uff08\u5e27\uff09\u5982\u4f55\u884c\u9a76\uff0c\u5982\u4f55\u907f\u514d\u78b0\u649e\uff0c\u4ee5\u53ca\u6bcf\u8f86\u8f66\u90fd\u6709\u4e00\u4e2a\u72ec\u7279\u7684\u8f66\u724c\u53f7\uff08MAC\u5730\u5740\uff09\u3002<\/li>\n\n\n\n<li><strong>\u4e0e\u7aef\u53e3\u7684\u5173\u8054\uff1a<\/strong> <strong>\u65e0\u3002<\/strong> \u6570\u636e\u94fe\u8def\u5c42\u4f7f\u7528MAC\u5730\u5740\u8fdb\u884c\u5c40\u57df\u7f51\u5185\u7684\u5bfb\u5740\uff0c\u4e0d\u6d89\u53ca\u7aef\u53e3\u53f7\u3002<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>\u7b2c\u4e09\u5c42\uff1a\u7f51\u7edc\u5c42 (Network Layer)<\/strong><\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u529f\u80fd\uff1a<\/strong> \u8d1f\u8d23\u5728<strong>\u4e0d\u540c\u7f51\u7edc\u4e4b\u95f4<\/strong>\u8fdb\u884c\u6570\u636e\u5305\u7684\u8def\u7531\u548c\u8f6c\u53d1\uff0c\u5b9e\u73b0<strong>\u7aef\u5230\u7aef (End-to-End)<\/strong> \u7684\u903b\u8f91\u5bfb\u5740\u3002\u5b83\u5b9a\u4e49\u4e86\u6570\u636e\u5305\u5982\u4f55\u4ece\u6e90\u4e3b\u673a\u4f20\u8f93\u5230\u76ee\u7684\u4e3b\u673a\uff0c\u5373\u4f7f\u5b83\u4eec\u4e0d\u5728\u540c\u4e00\u4e2a\u5c40\u57df\u7f51\u4e2d\u3002<\/li>\n\n\n\n<li><strong>\u4f20\u8f93\u5355\u4f4d\uff1a<\/strong> <strong>\u6570\u636e\u5305 (Packet)<\/strong>\u3002<\/li>\n\n\n\n<li>\u5173\u952e\u6982\u5ff5\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>IP \u5730\u5740 (Internet Protocol Address)\uff1a<\/strong> \u903b\u8f91\u5730\u5740\uff0c\u7528\u4e8e\u5728\u4e92\u8054\u7f51\u4e0a\u552f\u4e00\u6807\u8bc6\u4e00\u53f0\u4e3b\u673a\u3002<\/li>\n\n\n\n<li><strong>\u8def\u7531 (Routing)\uff1a<\/strong> \u51b3\u5b9a\u6570\u636e\u5305\u4ece\u6e90\u5230\u76ee\u7684\u7684\u6700\u4f73\u8def\u5f84\u3002<\/li>\n\n\n\n<li><strong>\u8def\u7531\u5668 (Router)\uff1a<\/strong> \u8fde\u63a5\u4e0d\u540c\u7f51\u7edc\uff0c\u6839\u636eIP\u5730\u5740\u8f6c\u53d1\u6570\u636e\u5305\u3002<\/li>\n\n\n\n<li><strong>ICMP (Internet Control Message Protocol)\uff1a<\/strong> \u4e92\u8054\u7f51\u63a7\u5236\u62a5\u6587\u534f\u8bae\uff0c\u7528\u4e8e\u53d1\u9001\u9519\u8bef\u62a5\u544a\u548c\u7f51\u7edc\u8bca\u65ad\u4fe1\u606f\uff08\u5982Ping\uff09\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u5e38\u89c1\u534f\u8bae\uff1a<\/strong> IP (IPv4, IPv6)\u3001ICMP\u3001IGMP (Internet Group Management Protocol)\u3002<\/li>\n\n\n\n<li><strong>\u5e38\u89c1\u8bbe\u5907\uff1a<\/strong> \u8def\u7531\u5668 (Router)\u3002<\/li>\n\n\n\n<li><strong>\u901a\u4fd7\u6bd4\u55bb\uff1a<\/strong> \u5c31\u50cf\u5168\u7403\u90ae\u653f\u7cfb\u7edf\uff0c\u8d1f\u8d23\u5c06\u4fe1\u4ef6\uff08\u6570\u636e\u5305\uff09\u4ece\u4e00\u4e2a\u57ce\u5e02\u7684\u5730\u5740\uff08\u6e90IP\uff09\u53d1\u9001\u5230\u53e6\u4e00\u4e2a\u57ce\u5e02\u7684\u5730\u5740\uff08\u76ee\u7684IP\uff09\uff0c\u4e2d\u95f4\u53ef\u80fd\u7ecf\u8fc7\u5f88\u591a\u4e2d\u8f6c\u7ad9\uff08\u8def\u7531\u5668\uff09\u3002<\/li>\n\n\n\n<li><strong>\u4e0e\u7aef\u53e3\u7684\u5173\u8054\uff1a<\/strong> <strong>\u65e0\u3002<\/strong> \u7f51\u7edc\u5c42\u4f7f\u7528IP\u5730\u5740\u8fdb\u884c\u4e3b\u673a\u95f4\u7684\u5bfb\u5740\uff0c\u4e0d\u6d89\u53ca\u7aef\u53e3\u53f7\u3002<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>\u7b2c\u56db\u5c42\uff1a\u4f20\u8f93\u5c42 (Transport Layer)<\/strong><\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u529f\u80fd\uff1a<\/strong> \u63d0\u4f9b<strong>\u7aef\u5230\u7aef (End-to-End)<\/strong> \u7684<strong>\u8fdb\u7a0b\u95f4\u901a\u4fe1<\/strong>\u3002\u5b83\u8d1f\u8d23\u5c06\u6570\u636e\u4ece\u6e90\u4e3b\u673a\u4e0a\u7684<strong>\u67d0\u4e2a\u5e94\u7528\u7a0b\u5e8f\u8fdb\u7a0b<\/strong>\u4f20\u8f93\u5230\u76ee\u7684\u4e3b\u673a\u4e0a\u7684<strong>\u67d0\u4e2a\u5e94\u7528\u7a0b\u5e8f\u8fdb\u7a0b<\/strong>\u3002\u5b83\u63d0\u4f9b\u4e24\u79cd\u4e3b\u8981\u670d\u52a1\uff1a\u53ef\u9760\u7684\u9762\u5411\u8fde\u63a5\u670d\u52a1 (TCP) \u548c\u4e0d\u53ef\u9760\u7684\u65e0\u8fde\u63a5\u670d\u52a1 (UDP)\u3002<\/li>\n\n\n\n<li><strong>\u4f20\u8f93\u5355\u4f4d\uff1a<\/strong> <strong>TCP \u6bb5 (Segment)<\/strong> \u6216 <strong>UDP \u6570\u636e\u62a5 (Datagram)<\/strong>\u3002<\/li>\n\n\n\n<li><strong>\u5173\u952e\u6982\u5ff5\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u7aef\u53e3\u53f7 (Port Number)\uff1a<\/strong> 16\u4f4d\u6570\u5b57\uff0c\u7528\u4e8e\u6807\u8bc6\u4e00\u53f0\u4e3b\u673a\u4e0a\u4e0d\u540c\u7684\u5e94\u7528\u7a0b\u5e8f\u8fdb\u7a0b\u3002\u8fd9\u662f\u672c\u5c42\u6700\u91cd\u8981\u7684\u6982\u5ff5\u3002<\/li>\n\n\n\n<li><strong>TCP (Transmission Control Protocol)\uff1a<\/strong> \u63d0\u4f9b\u53ef\u9760\u7684\u3001\u9762\u5411\u8fde\u63a5\u7684\u3001\u5168\u53cc\u5de5\u7684\u4f20\u8f93\u670d\u52a1\uff0c\u5177\u6709\u6d41\u91cf\u63a7\u5236\u3001\u62e5\u585e\u63a7\u5236\u3001\u91cd\u4f20\u673a\u5236\u7b49\u3002<\/li>\n\n\n\n<li><strong>UDP (User Datagram Protocol)\uff1a<\/strong> \u63d0\u4f9b\u4e0d\u53ef\u9760\u7684\u3001\u65e0\u8fde\u63a5\u7684\u3001\u5c3d\u529b\u800c\u4e3a\u7684\u4f20\u8f93\u670d\u52a1\uff0c\u5f00\u9500\u5c0f\uff0c\u901f\u5ea6\u5feb\u3002<\/li>\n\n\n\n<li><strong>\u5e8f\u5217\u53f7 (Sequence Number)\uff1a<\/strong> TCP\u7528\u4e8e\u4fdd\u8bc1\u6570\u636e\u6309\u5e8f\u5230\u8fbe\u3002<\/li>\n\n\n\n<li><strong>\u786e\u8ba4\u5e94\u7b54 (Acknowledgment - ACK)\uff1a<\/strong> TCP\u7528\u4e8e\u786e\u8ba4\u6570\u636e\u6536\u5230\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u5e38\u89c1\u534f\u8bae\uff1a<\/strong> TCP\u3001UDP\u3002<\/li>\n\n\n\n<li><strong>\u5e38\u89c1\u8bbe\u5907\uff1a<\/strong> \u65e0\u72ec\u7acb\u8bbe\u5907\uff0c\u529f\u80fd\u7531\u64cd\u4f5c\u7cfb\u7edf\u5b9e\u73b0\u3002<\/li>\n\n\n\n<li><strong>\u901a\u4fd7\u6bd4\u55bb\uff1a<\/strong> \u5c31\u50cf\u5728\u6536\u5230\u4e86\u4fe1\u4ef6\u7684\u5927\u697c\u91cc\uff0c\u5c06\u4fe1\u4ef6\u51c6\u786e\u5730\u6295\u9012\u5230\u6536\u4ef6\u4eba\u6240\u5728\u7684<strong>\u5177\u4f53\u623f\u95f4\u53f7<\/strong>\uff08\u7aef\u53e3\u53f7\uff09\u3002<\/li>\n\n\n\n<li><strong>\u4e0e\u7aef\u53e3\u7684\u5173\u8054\uff1a<\/strong><strong>\u6709\uff01\u8fd9\u662f\u7aef\u53e3\u6982\u5ff5\u7684\u8bde\u751f\u5730\u3002<\/strong> \u7aef\u53e3\u53f7\u662f\u4f20\u8f93\u5c42\u7528\u6765\u533a\u5206\u4e0d\u540c\u5e94\u7528\u7a0b\u5e8f\u8fdb\u7a0b\u7684\u6807\u8bc6\u7b26\u3002\n<ul class=\"wp-block-list\">\n<li><strong>\u7aef\u53e3\u8303\u56f4\uff1a<\/strong> 0 - 65535<\/li>\n\n\n\n<li><strong>\u5468\u77e5\u7aef\u53e3 (Well-known Ports)\uff1a0 - 1023<\/strong>\uff0c\u7531IANA\uff08\u4e92\u8054\u7f51\u53f7\u7801\u5206\u914d\u673a\u6784\uff09\u5206\u914d\u7ed9\u5e38\u7528\u7684\u7f51\u7edc\u670d\u52a1\u3002<\/li>\n\n\n\n<li><strong>\u6ce8\u518c\u7aef\u53e3 (Registered Ports)\uff1a1024 - 49151<\/strong>\uff0c\u53ef\u7531\u7528\u6237\u8fdb\u7a0b\u6216\u5e94\u7528\u7a0b\u5e8f\u6ce8\u518c\u4f7f\u7528\u3002<\/li>\n\n\n\n<li><strong>\u52a8\u6001\/\u79c1\u6709\u7aef\u53e3 (Dynamic\/Private Ports)\uff1a49152 - 65535<\/strong>\uff0c\u901a\u5e38\u7531\u5ba2\u6237\u7aef\u7a0b\u5e8f\u4e34\u65f6\u4f7f\u7528\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>\u7b2c\u4e94\u5c42\uff1a\u4f1a\u8bdd\u5c42 (Session Layer)<\/strong><\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u529f\u80fd\uff1a<\/strong> \u8d1f\u8d23\u5efa\u7acb\u3001\u7ba1\u7406\u548c\u7ec8\u6b62\u5e94\u7528\u7a0b\u5e8f\u4e4b\u95f4\u7684\u4f1a\u8bdd\uff08\u5bf9\u8bdd\uff09\u3002\u5b83\u63d0\u4f9b\u540c\u6b65\u670d\u52a1\uff0c\u5305\u62ec\u5728\u6570\u636e\u6d41\u4e2d\u8bbe\u7f6e\u68c0\u67e5\u70b9\uff0c\u4ee5\u4fbf\u5728\u7f51\u7edc\u6545\u969c\u65f6\u4ece\u4e0a\u6b21\u68c0\u67e5\u70b9\u6062\u590d\u4f1a\u8bdd\u3002<\/li>\n\n\n\n<li><strong>\u4f20\u8f93\u5355\u4f4d\uff1a<\/strong> \u6570\u636e (Data)\u3002<\/li>\n\n\n\n<li>\u5173\u952e\u6982\u5ff5\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u5bf9\u8bdd\u63a7\u5236\uff1a<\/strong> \u51b3\u5b9a\u7531\u54ea\u4e00\u65b9\u53d1\u9001\u6570\u636e\uff0c\u54ea\u4e00\u65b9\u63a5\u6536\u6570\u636e\uff08\u5168\u53cc\u5de5\u3001\u534a\u53cc\u5de5\u3001\u5355\u5de5\uff09\u3002<\/li>\n\n\n\n<li><strong>\u540c\u6b65\uff1a<\/strong> \u5728\u6570\u636e\u6d41\u4e2d\u63d2\u5165\u540c\u6b65\u70b9\uff0c\u65b9\u4fbf\u6062\u590d\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u5e38\u89c1\u534f\u8bae\uff1a<\/strong> NetBIOS\u3001RPC (Remote Procedure Call)\u3001PPTP (Point-to-Point Tunneling Protocol\uff0c\u6709\u65f6\u4e5f\u5f52\u4e3a\u6b64\u5c42)\u3002<\/li>\n\n\n\n<li><strong>\u901a\u4fd7\u6bd4\u55bb\uff1a<\/strong> \u5c31\u50cf\u4f60\u548c\u670b\u53cb\u6253\u7535\u8bdd\uff0c\u4f1a\u8bdd\u5c42\u8d1f\u8d23\u7ba1\u7406\u4f60\u4eec\u7684\u5bf9\u8bdd\uff08\u8c01\u5148\u8bf4\uff0c\u8c01\u540e\u8bf4\uff0c\u4ec0\u4e48\u65f6\u5019\u6302\u65ad\uff09\u3002<\/li>\n\n\n\n<li><strong>\u4e0e\u7aef\u53e3\u7684\u5173\u8054\uff1a<\/strong> <strong>\u65e0\u3002<\/strong> \u4f1a\u8bdd\u5c42\u672c\u8eab\u4e0d\u4f7f\u7528\u7aef\u53e3\u53f7\uff0c\u5b83\u4f9d\u8d56\u4e8e\u4f20\u8f93\u5c42\u63d0\u4f9b\u7684\u7aef\u53e3\u670d\u52a1\u6765\u5efa\u7acb\u548c\u7ba1\u7406\u4f1a\u8bdd\u3002<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>\u7b2c\u516d\u5c42\uff1a\u8868\u793a\u5c42 (Presentation Layer)<\/strong><\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u529f\u80fd\uff1a<\/strong> \u8d1f\u8d23\u6570\u636e\u683c\u5f0f\u7684\u8f6c\u6362\u3001\u7f16\u7801\u3001\u89e3\u7801\u3001\u52a0\u5bc6\u548c\u89e3\u5bc6\uff0c\u4ee5\u53ca\u6570\u636e\u538b\u7f29\u548c\u89e3\u538b\u7f29\u3002\u5b83\u786e\u4fdd\u4ece\u5e94\u7528\u5c42\u63a5\u6536\u5230\u7684\u6570\u636e\u80fd\u591f\u88ab\u76ee\u7684\u4e3b\u673a\u7684\u5e94\u7528\u5c42\u7406\u89e3\u548c\u5904\u7406\u3002<\/li>\n\n\n\n<li><strong>\u4f20\u8f93\u5355\u4f4d\uff1a<\/strong> \u6570\u636e (Data)\u3002<\/li>\n\n\n\n<li>\u5173\u952e\u6982\u5ff5\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u6570\u636e\u683c\u5f0f\u5316\uff1a<\/strong> \u5c06\u5e94\u7528\u7a0b\u5e8f\u6570\u636e\u8f6c\u6362\u4e3a\u7f51\u7edc\u6807\u51c6\u683c\u5f0f\uff0c\u6216\u5c06\u7f51\u7edc\u6807\u51c6\u683c\u5f0f\u8f6c\u6362\u56de\u5e94\u7528\u7a0b\u5e8f\u683c\u5f0f\uff08\u5982ASCII\u3001EBCDIC\uff09\u3002<\/li>\n\n\n\n<li><strong>\u6570\u636e\u52a0\u5bc6\/\u89e3\u5bc6\uff1a<\/strong> \u63d0\u4f9b\u6570\u636e\u5b89\u5168\u670d\u52a1\u3002<\/li>\n\n\n\n<li><strong>\u6570\u636e\u538b\u7f29\/\u89e3\u538b\u7f29\uff1a<\/strong> \u63d0\u9ad8\u4f20\u8f93\u6548\u7387\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u5e38\u89c1\u534f\u8bae\uff1a<\/strong> JPEG\u3001MPEG\u3001ASCII\u3001EBCDIC\u3002SSL\/TLS\uff08\u5b89\u5168\u5957\u63a5\u5c42\/\u4f20\u8f93\u5c42\u5b89\u5168\uff09\u901a\u5e38\u88ab\u8ba4\u4e3a\u5de5\u4f5c\u5728\u8868\u793a\u5c42\u548c\u4f1a\u8bdd\u5c42\u4e4b\u95f4\uff0c\u751a\u81f3\u8de8\u8d8a\u66f4\u591a\u5c42\u3002<\/li>\n\n\n\n<li><strong>\u901a\u4fd7\u6bd4\u55bb\uff1a<\/strong> \u5c31\u50cf\u4e00\u4e2a\u7ffb\u8bd1\u5b98\u6216\u6570\u636e\u683c\u5f0f\u8f6c\u6362\u5668\uff0c\u786e\u4fdd\u4f60\u53d1\u51fa\u7684\u4e2d\u6587\u4fe1\u606f\u80fd\u88ab\u5916\u56fd\u4eba\u7406\u89e3\uff0c\u6216\u8005\u5bf9\u4fe1\u606f\u8fdb\u884c\u52a0\u5bc6\u548c\u538b\u7f29\u3002<\/li>\n\n\n\n<li><strong>\u4e0e\u7aef\u53e3\u7684\u5173\u8054\uff1a<\/strong> <strong>\u65e0\u3002<\/strong> \u8868\u793a\u5c42\u5904\u7406\u7684\u662f\u6570\u636e\u7684\u8868\u73b0\u5f62\u5f0f\uff0c\u4e0d\u6d89\u53ca\u7aef\u53e3\u53f7\u3002<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>\u7b2c\u4e03\u5c42\uff1a\u5e94\u7528\u5c42 (Application Layer)<\/strong><\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u529f\u80fd\uff1a<\/strong> \u63d0\u4f9b\u7528\u6237\u4e0e\u7f51\u7edc\u4e4b\u95f4\u7684\u63a5\u53e3\uff0c\u76f4\u63a5\u4e3a\u6700\u7ec8\u7528\u6237\u5e94\u7528\u7a0b\u5e8f\u63d0\u4f9b\u7f51\u7edc\u670d\u52a1\u3002\u5b83\u5305\u542b\u4e86\u5404\u79cd\u5e94\u7528\u7a0b\u5e8f\u6240\u9700\u7684\u534f\u8bae\uff0c\u7528\u4e8e\u6587\u4ef6\u4f20\u8f93\u3001\u7535\u5b50\u90ae\u4ef6\u3001\u7f51\u9875\u6d4f\u89c8\u7b49\u3002<\/li>\n\n\n\n<li><strong>\u4f20\u8f93\u5355\u4f4d\uff1a<\/strong> \u6570\u636e (Data)\u3002<\/li>\n\n\n\n<li><strong>\u5173\u952e\u6982\u5ff5\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u7528\u6237\u754c\u9762\uff1a<\/strong> \u5e94\u7528\u7a0b\u5e8f\u4e0e\u7528\u6237\u4ea4\u4e92\u7684\u754c\u9762\u3002<\/li>\n\n\n\n<li><strong>\u7279\u5b9a\u670d\u52a1\uff1a<\/strong> \u5404\u79cd\u5177\u4f53\u7684\u7f51\u7edc\u670d\u52a1\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u5e38\u89c1\u534f\u8bae\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>HTTP (Hypertext Transfer Protocol)\uff1a<\/strong> \u7f51\u9875\u6d4f\u89c8\u3002<\/li>\n\n\n\n<li><strong>HTTPS (Hypertext Transfer Protocol Secure)\uff1a<\/strong> \u5b89\u5168\u7f51\u9875\u6d4f\u89c8\u3002<\/li>\n\n\n\n<li><strong>FTP (File Transfer Protocol)\uff1a<\/strong> \u6587\u4ef6\u4f20\u8f93\u3002<\/li>\n\n\n\n<li><strong>SMTP (Simple Mail Transfer Protocol)\uff1a<\/strong> \u7535\u5b50\u90ae\u4ef6\u53d1\u9001\u3002<\/li>\n\n\n\n<li><strong>POP3 (Post Office Protocol version 3)\uff1a<\/strong> \u7535\u5b50\u90ae\u4ef6\u63a5\u6536\u3002<\/li>\n\n\n\n<li><strong>IMAP (Internet Message Access Protocol)\uff1a<\/strong> \u7535\u5b50\u90ae\u4ef6\u63a5\u6536\u548c\u7ba1\u7406\u3002<\/li>\n\n\n\n<li><strong>DNS (Domain Name System)\uff1a<\/strong> \u57df\u540d\u89e3\u6790\u3002<\/li>\n\n\n\n<li><strong>DHCP (Dynamic Host Configuration Protocol)\uff1a<\/strong> \u52a8\u6001\u4e3b\u673a\u914d\u7f6e\u3002<\/li>\n\n\n\n<li><strong>Telnet\uff1a<\/strong> \u8fdc\u7a0b\u7ec8\u7aef\u8bbf\u95ee\uff08\u4e0d\u5b89\u5168\uff09\u3002<\/li>\n\n\n\n<li><strong>SSH (Secure Shell)\uff1a<\/strong> \u5b89\u5168\u8fdc\u7a0b\u7ec8\u7aef\u8bbf\u95ee\u3002<\/li>\n\n\n\n<li><strong>SNMP (Simple Network Management Protocol)\uff1a<\/strong> \u7f51\u7edc\u8bbe\u5907\u7ba1\u7406\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u901a\u4fd7\u6bd4\u55bb\uff1a<\/strong> \u5c31\u50cf\u4f60\u4f7f\u7528\u7684\u5404\u79cd\u5e94\u7528\u7a0b\u5e8f\u672c\u8eab\uff08\u6d4f\u89c8\u5668\u3001\u90ae\u4ef6\u5ba2\u6237\u7aef\u3001\u6587\u4ef6\u7ba1\u7406\u5668\uff09\uff0c\u5b83\u4eec\u901a\u8fc7\u7f51\u7edc\u6765\u5b9e\u73b0\u7279\u5b9a\u529f\u80fd\u3002<\/li>\n\n\n\n<li><strong>\u4e0e\u7aef\u53e3\u7684\u5173\u8054\uff1a<\/strong><strong>\u6709\uff01\u5e94\u7528\u5c42\u534f\u8bae\u4f1a\u4f7f\u7528\u4f20\u8f93\u5c42\u7684\u7aef\u53e3\u53f7\u3002<\/strong>\n<ul class=\"wp-block-list\">\n<li>\u5e38\u89c1\u5e94\u7528\u5c42\u534f\u8bae\u53ca\u5176\u9ed8\u8ba4\u7aef\u53e3\u53f7 (TCP\/UDP)\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>HTTP\uff1a<\/strong> TCP 80<\/li>\n\n\n\n<li><strong>HTTPS\uff1a<\/strong> TCP 443<\/li>\n\n\n\n<li><strong>FTP\uff1a<\/strong> TCP 20 (\u6570\u636e), TCP 21 (\u63a7\u5236)<\/li>\n\n\n\n<li><strong>SSH\uff1a<\/strong> TCP 22<\/li>\n\n\n\n<li><strong>Telnet\uff1a<\/strong> TCP 23<\/li>\n\n\n\n<li><strong>SMTP\uff1a<\/strong> TCP 25<\/li>\n\n\n\n<li><strong>DNS\uff1a<\/strong> UDP 53 (\u67e5\u8be2), TCP 53 (\u533a\u57df\u4f20\u8f93)<\/li>\n\n\n\n<li><strong>DHCP\uff1a<\/strong> UDP 67 (\u670d\u52a1\u5668), UDP 68 (\u5ba2\u6237\u7aef)<\/li>\n\n\n\n<li><strong>TFTP (Trivial File Transfer Protocol)\uff1a<\/strong> UDP 69<\/li>\n\n\n\n<li><strong>POP3\uff1a<\/strong> TCP 110<\/li>\n\n\n\n<li><strong>IMAP\uff1a<\/strong> TCP 143<\/li>\n\n\n\n<li><strong>SNMP\uff1a<\/strong> UDP 161 (\u4ee3\u7406), UDP 162 (\u7ba1\u7406\u5668)<\/li>\n\n\n\n<li><strong>LDAP (Lightweight Directory Access Protocol)\uff1a<\/strong> TCP 389<\/li>\n\n\n\n<li><strong>RDP (Remote Desktop Protocol)\uff1a<\/strong> TCP 3389<\/li>\n\n\n\n<li><strong>MySQL\uff1a<\/strong> TCP 3306<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>\u9762\u8bd5\u603b\u7ed3\u8981\u70b9\uff1a<\/strong><\/h3>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>OSI\u6a21\u578b\u662f\u6982\u5ff5\u6027\u6846\u67b6<\/strong>\uff0cTCP\/IP\u6a21\u578b\u662f\u5b9e\u9645\u5e94\u7528\u3002<\/li>\n\n\n\n<li><strong>\u8bb0\u4f4f\u6bcf\u4e00\u5c42\u7684\u540d\u79f0\u3001\u7f16\u53f7\u548c\u6838\u5fc3\u529f\u80fd\u3002<\/strong><\/li>\n\n\n\n<li><strong>\u8bb0\u4f4f\u6bcf\u4e00\u5c42\u7684\u4f20\u8f93\u5355\u4f4d\u3002<\/strong> (\u6bd4\u7279\u3001\u5e27\u3001\u6570\u636e\u5305\u3001\u6bb5\/\u6570\u636e\u62a5\u3001\u6570\u636e)<\/li>\n\n\n\n<li><strong>\u660e\u786e\u7aef\u53e3\u662f\u4f20\u8f93\u5c42 (L4) \u7684\u6982\u5ff5\u3002<\/strong> \u5f3a\u8c03\u5176\u4ed6\u5c42\u6ca1\u6709\u7aef\u53e3\u3002<\/li>\n\n\n\n<li><strong>\u80fd\u591f\u5217\u4e3e\u5e38\u89c1\u5e94\u7528\u5c42\u534f\u8bae\u53ca\u5176\u5bf9\u5e94\u7684\u7aef\u53e3\u53f7\u3002<\/strong> \u8fd9\u662fL7\u534f\u8bae\u201c\u4f7f\u7528\u201dL4\u7aef\u53e3\u7684\u4f53\u73b0\u3002<\/li>\n\n\n\n<li><strong>\u7406\u89e3\u6570\u636e\u5c01\u88c5\u548c\u89e3\u5c01\u88c5\u7684\u8fc7\u7a0b\u3002<\/strong><\/li>\n\n\n\n<li><strong>\u7406\u89e3\u5206\u5c42\u5e26\u6765\u7684\u597d\u5904<\/strong>\uff08\u6a21\u5757\u5316\u3001\u6807\u51c6\u5316\u3001\u6613\u4e8e\u7ef4\u62a4\u548c\u5347\u7ea7\uff09\u3002<\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\">\u4ea4\u6362\u673a\u662f\u4ec0\u4e48\uff1f\u4ea4\u6362\u673a\u7684\u79cd\u7c7b<\/h2>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/usual1009.oss-cn-shanghai.aliyuncs.com\/img\/202511291927566.png\" alt=\"image-20251109180713097\"\/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">\u4ea4\u6362\u673a\u662f\u4ec0\u4e48\uff1f<\/h3>\n\n\n\n<p><strong>\u4ea4\u6362\u673a (Switch)<\/strong> \u662f\u4e00\u79cd\u7f51\u7edc\u8bbe\u5907\uff0c\u7528\u4e8e\u5728\u5c40\u57df\u7f51 (LAN) \u4e2d\u8fde\u63a5\u591a\u4e2a\u8ba1\u7b97\u673a\u3001\u670d\u52a1\u5668\u3001\u6253\u5370\u673a\u7b49\u8bbe\u5907\uff0c\u5e76\u5141\u8bb8\u5b83\u4eec\u4e4b\u95f4\u8fdb\u884c\u901a\u4fe1\u3002\u5b83\u5de5\u4f5c\u5728OSI\u6a21\u578b\u7684<strong>\u6570\u636e\u94fe\u8def\u5c42\uff08\u7b2c\u4e8c\u5c42\uff09<\/strong>\uff0c\u4f46\u4e5f\u6709\u4e00\u4e9b\u9ad8\u7ea7\u4ea4\u6362\u673a\u53ef\u4ee5\u5de5\u4f5c\u5728<strong>\u7f51\u7edc\u5c42\uff08\u7b2c\u4e09\u5c42\uff09<\/strong>\u3002<\/p>\n\n\n\n<p>\u4f60\u53ef\u4ee5\u5c06\u4ea4\u6362\u673a\u60f3\u8c61\u6210\u4e00\u4e2a\u667a\u80fd\u7684\u4ea4\u901a\u6307\u6325\u4e2d\u5fc3\uff1a<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u667a\u80fd\u8f6c\u53d1\uff1a<\/strong> \u5f53\u6570\u636e\u5e27\uff08\u6570\u636e\u94fe\u8def\u5c42\u7684\u6570\u636e\u5355\u5143\uff09\u5230\u8fbe\u4ea4\u6362\u673a\u65f6\uff0c\u4ea4\u6362\u673a\u4f1a\u8bfb\u53d6\u5e27\u5934\u4e2d\u7684<strong>\u76ee\u6807MAC\u5730\u5740<\/strong>\u3002<\/li>\n\n\n\n<li><strong>MAC\u5730\u5740\u5b66\u4e60\uff1a<\/strong> \u4ea4\u6362\u673a\u4f1a\u7ef4\u62a4\u4e00\u4e2a<strong>MAC\u5730\u5740\u8868\uff08CAM\u8868\uff09<\/strong>\u3002\u5b83\u901a\u8fc7\u76d1\u542c\u8fde\u63a5\u5230\u5176\u7aef\u53e3\u7684\u8bbe\u5907\u53d1\u9001\u7684\u6570\u636e\u5e27\uff0c\u5b66\u4e60\u8fd9\u4e9b\u8bbe\u5907\u7684MAC\u5730\u5740\u4ee5\u53ca\u5b83\u4eec\u8fde\u63a5\u5728\u54ea\u4e2a\u7aef\u53e3\u4e0a\u3002<\/li>\n\n\n\n<li><strong>\u7cbe\u786e\u4f20\u8f93\uff1a<\/strong> \u4e00\u65e6\u4ea4\u6362\u673a\u77e5\u9053\u76ee\u6807MAC\u5730\u5740\u8fde\u63a5\u5728\u54ea\u4e2a\u7aef\u53e3\uff0c\u5b83\u5c31\u4f1a\u5c06\u6570\u636e\u5e27<strong>\u7cbe\u786e\u5730\u8f6c\u53d1\u5230\u8be5\u7aef\u53e3<\/strong>\uff0c\u800c\u4e0d\u662f\u50cf\u96c6\u7ebf\u5668\uff08Hub\uff09\u90a3\u6837\u5c06\u6570\u636e\u5e7f\u64ad\u7ed9\u6240\u6709\u7aef\u53e3\u3002\u8fd9\u5927\u5927\u63d0\u9ad8\u4e86\u7f51\u7edc\u7684\u6548\u7387\u548c\u5b89\u5168\u6027\u3002<\/li>\n\n\n\n<li><strong>\u72ec\u4eab\u5e26\u5bbd\uff1a<\/strong> \u7531\u4e8e\u4ea4\u6362\u673a\u662f\u70b9\u5bf9\u70b9\u8f6c\u53d1\uff0c\u6bcf\u4e2a\u8fde\u63a5\u5230\u4ea4\u6362\u673a\u7684\u8bbe\u5907\u90fd\u53ef\u4ee5\u83b7\u5f97<strong>\u72ec\u7acb\u7684\u5e26\u5bbd<\/strong>\uff0c\u907f\u514d\u4e86\u51b2\u7a81\u57df\u7684\u6269\u5927\uff0c\u63d0\u9ad8\u4e86\u7f51\u7edc\u6027\u80fd\u3002<\/li>\n<\/ol>\n\n\n\n<p><strong>\u6838\u5fc3\u529f\u80fd\u603b\u7ed3\uff1a<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u8fde\u63a5\u8bbe\u5907\uff1a<\/strong> \u5c06\u5c40\u57df\u7f51\u5185\u7684\u5404\u79cd\u8bbe\u5907\u8fde\u63a5\u8d77\u6765\u3002<\/li>\n\n\n\n<li><strong>MAC\u5730\u5740\u5b66\u4e60\uff1a<\/strong> \u81ea\u52a8\u5b66\u4e60\u8fde\u63a5\u8bbe\u5907\u7684MAC\u5730\u5740\u53ca\u5176\u5bf9\u5e94\u7684\u7aef\u53e3\u3002<\/li>\n\n\n\n<li><strong>\u5e27\u8f6c\u53d1\uff1a<\/strong> \u6839\u636eMAC\u5730\u5740\u8868\uff0c\u5c06\u6570\u636e\u5e27\u7cbe\u786e\u5730\u8f6c\u53d1\u5230\u76ee\u6807\u8bbe\u5907\u6240\u5728\u7684\u7aef\u53e3\u3002<\/li>\n\n\n\n<li><strong>\u6d88\u9664\u51b2\u7a81\u57df\uff1a<\/strong> \u6bcf\u4e2a\u4ea4\u6362\u673a\u7aef\u53e3\u90fd\u6784\u6210\u4e00\u4e2a\u72ec\u7acb\u7684\u51b2\u7a81\u57df\uff0c\u63d0\u9ad8\u4e86\u7f51\u7edc\u6548\u7387\u3002<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">\u4ea4\u6362\u673a\u7684\u79cd\u7c7b<\/h3>\n\n\n\n<p>\u4ea4\u6362\u673a\u53ef\u4ee5\u6839\u636e\u4e0d\u540c\u7684\u6807\u51c6\u8fdb\u884c\u5206\u7c7b\u3002\u4ee5\u4e0b\u662f\u4e00\u4e9b\u4e3b\u8981\u7684\u5206\u7c7b\u65b9\u5f0f\uff1a<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">1. \u6309\u7ba1\u7406\u80fd\u529b\u5206\u7c7b<\/h4>\n\n\n\n<p>\u8fd9\u662f\u6700\u5e38\u89c1\u7684\u5206\u7c7b\u65b9\u5f0f\uff0c\u4e5f\u662f\u5728CTF\u4e2d\u9700\u8981\u7279\u522b\u5173\u6ce8\u7684\u4e00\u70b9\uff0c\u56e0\u4e3a\u7ba1\u7406\u578b\u4ea4\u6362\u673a\u63d0\u4f9b\u4e86\u66f4\u591a\u7684\u914d\u7f6e\u548c\u5b89\u5168\u9009\u9879\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u975e\u7ba1\u7406\u578b\u4ea4\u6362\u673a (Unmanaged Switches)<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u7279\u70b9\uff1a<\/strong> \u5373\u63d2\u5373\u7528\uff0c\u65e0\u9700\u4efb\u4f55\u914d\u7f6e\u3002\u5b83\u4eec\u6ca1\u6709\u7ba1\u7406\u754c\u9762\uff08\u5982Web\u754c\u9762\u6216\u547d\u4ee4\u884c\u63a5\u53e3\uff09\uff0c\u4e5f\u4e0d\u80fd\u8fdb\u884c\u4efb\u4f55\u9ad8\u7ea7\u8bbe\u7f6e\u3002<\/li>\n\n\n\n<li><strong>\u4f18\u70b9\uff1a<\/strong> \u4ef7\u683c\u4fbf\u5b9c\uff0c\u5b89\u88c5\u7b80\u5355\uff0c\u9002\u5408\u5bb6\u5ead\u7f51\u7edc\u6216\u5c0f\u578b\u529e\u516c\u5ba4\u3002<\/li>\n\n\n\n<li><strong>\u7f3a\u70b9\uff1a<\/strong> \u65e0\u6cd5\u914d\u7f6eVLAN\u3001QoS\u3001\u7aef\u53e3\u5b89\u5168\u7b49\u529f\u80fd\uff0c\u7f3a\u4e4f\u5bf9\u7f51\u7edc\u7684\u63a7\u5236\u548c\u53ef\u89c1\u6027\u3002<\/li>\n\n\n\n<li><strong>CTF\u76f8\u5173\uff1a<\/strong> \u8fd9\u79cd\u4ea4\u6362\u673a\u901a\u5e38\u5b89\u5168\u98ce\u9669\u8f83\u4f4e\uff0c\u56e0\u4e3a\u6ca1\u6709\u914d\u7f6e\u6f0f\u6d1e\u53ef\u5229\u7528\uff0c\u4f46\u5176\u7f3a\u4e4f\u7ba1\u7406\u80fd\u529b\u4e5f\u4f7f\u5f97\u7f51\u7edc\u96be\u4ee5\u8fdb\u884c\u7ec6\u7c92\u5ea6\u9694\u79bb\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u7ba1\u7406\u578b\u4ea4\u6362\u673a (Managed Switches)<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u7279\u70b9\uff1a<\/strong> \u63d0\u4f9b\u4e86\u4e30\u5bcc\u7684\u7ba1\u7406\u529f\u80fd\uff0c\u53ef\u4ee5\u901a\u8fc7Web\u754c\u9762\u3001\u547d\u4ee4\u884c\u63a5\u53e3 (CLI)\u3001SNMP\u7b49\u65b9\u5f0f\u8fdb\u884c\u914d\u7f6e\u548c\u76d1\u63a7\u3002<\/li>\n\n\n\n<li><strong>\u4f18\u70b9\uff1a<\/strong> \u63d0\u4f9b\u4e86\u5bf9\u7f51\u7edc\u7684\u5168\u9762\u63a7\u5236\uff0c\u53ef\u4ee5\u914d\u7f6eVLAN\u3001QoS\u3001\u7aef\u53e3\u955c\u50cf\u3001\u751f\u6210\u6811\u534f\u8bae (STP)\u3001\u94fe\u8def\u805a\u5408 (LACP)\u3001\u7aef\u53e3\u5b89\u5168\u3001ACLs\u7b49\u9ad8\u7ea7\u529f\u80fd\u3002<\/li>\n\n\n\n<li><strong>\u7f3a\u70b9\uff1a<\/strong> \u4ef7\u683c\u8f83\u9ad8\uff0c\u914d\u7f6e\u590d\u6742\uff0c\u9700\u8981\u4e13\u4e1a\u7684\u7f51\u7edc\u77e5\u8bc6\u3002<\/li>\n\n\n\n<li><strong>CTF\u76f8\u5173\uff1a<\/strong> \u8fd9\u662fCTF\u4e2d\u5e38\u89c1\u7684\u653b\u51fb\u76ee\u6807\uff0c\u56e0\u4e3a\u5176\u590d\u6742\u7684\u914d\u7f6e\u53ef\u80fd\u5bfc\u81f4\u6f0f\u6d1e\uff08\u5982\u5f31\u5bc6\u7801\u3001\u672a\u6388\u6743\u8bbf\u95ee\u7ba1\u7406\u754c\u9762\u3001\u914d\u7f6e\u9519\u8bef\u5bfc\u81f4\u7684\u5b89\u5168\u7b56\u7565\u7ed5\u8fc7\u3001SNMP\u793e\u533a\u5b57\u7b26\u4e32\u6cc4\u9732\u7b49\uff09\u3002\u4e86\u89e3\u5176\u7ba1\u7406\u529f\u80fd\u5bf9\u4e8e\u7f51\u7edc\u4fa6\u5bdf\u548c\u6f0f\u6d1e\u5229\u7528\u81f3\u5173\u91cd\u8981\u3002<\/li>\n\n\n\n<li>\u5b50\u5206\u7c7b\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u667a\u80fd\u4ea4\u6362\u673a \/ Web\u7ba1\u7406\u578b\u4ea4\u6362\u673a (Smart\/Web-Managed Switches)\uff1a<\/strong> \u63d0\u4f9b\u57fa\u672c\u7684Web\u7ba1\u7406\u754c\u9762\uff0c\u529f\u80fd\u4ecb\u4e8e\u975e\u7ba1\u7406\u578b\u548c\u5168\u7ba1\u7406\u578b\u4e4b\u95f4\uff0c\u901a\u5e38\u9002\u5408\u4e2d\u5c0f\u578b\u4f01\u4e1a\u3002<\/li>\n\n\n\n<li><strong>\u4f01\u4e1a\u7ea7\u7ba1\u7406\u578b\u4ea4\u6362\u673a (Enterprise-grade Managed Switches)\uff1a<\/strong> \u529f\u80fd\u6700\u5168\u9762\uff0c\u901a\u5e38\u901a\u8fc7CLI\u8fdb\u884c\u9ad8\u7ea7\u914d\u7f6e\uff0c\u652f\u6301\u590d\u6742\u7684\u7f51\u7edc\u62d3\u6251\u548c\u5b89\u5168\u7b56\u7565\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">2. \u6309\u5de5\u4f5c\u5c42\u6b21\u5206\u7c7b<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u4e8c\u5c42\u4ea4\u6362\u673a (Layer 2 Switches)<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u7279\u70b9\uff1a<\/strong> \u57fa\u4e8eMAC\u5730\u5740\u8fdb\u884c\u6570\u636e\u5e27\u8f6c\u53d1\uff0c\u5de5\u4f5c\u5728OSI\u6a21\u578b\u7684\u6570\u636e\u94fe\u8def\u5c42\u3002<\/li>\n\n\n\n<li><strong>\u529f\u80fd\uff1a<\/strong> \u4e3b\u8981\u7528\u4e8e\u8fde\u63a5\u540c\u4e00\u5c40\u57df\u7f51\u5185\u7684\u8bbe\u5907\uff0c\u5b9e\u73b0\u8bbe\u5907\u95f4\u7684\u901a\u4fe1\u3002<\/li>\n\n\n\n<li><strong>\u5e94\u7528\uff1a<\/strong> \u5927\u591a\u6570\u5e38\u89c1\u7684\u4ea4\u6362\u673a\u90fd\u662f\u4e8c\u5c42\u4ea4\u6362\u673a\u3002<\/li>\n\n\n\n<li><strong>CTF\u76f8\u5173\uff1a<\/strong> ARP\u6b3a\u9a97\u3001MAC\u6cdb\u6d2a\u7b49\u653b\u51fb\u901a\u5e38\u9488\u5bf9\u4e8c\u5c42\u4ea4\u6362\u673a\u3002\u7406\u89e3VLAN\uff08\u865a\u62df\u5c40\u57df\u7f51\uff09\u5728\u4e8c\u5c42\u4ea4\u6362\u673a\u4e0a\u7684\u5b9e\u73b0\u5bf9\u4e8e\u7406\u89e3\u7f51\u7edc\u9694\u79bb\u548c\u7a81\u7834\u9694\u79bb\u975e\u5e38\u91cd\u8981\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u4e09\u5c42\u4ea4\u6362\u673a (Layer 3 Switches)<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u7279\u70b9\uff1a<\/strong> \u9664\u4e86\u5177\u5907\u4e8c\u5c42\u4ea4\u6362\u673a\u7684\u8f6c\u53d1\u529f\u80fd\u5916\uff0c\u8fd8\u5177\u5907\u90e8\u5206\u8def\u7531\u5668\u7684\u529f\u80fd\uff0c\u53ef\u4ee5\u57fa\u4e8eIP\u5730\u5740\u8fdb\u884c\u6570\u636e\u5305\u8f6c\u53d1\uff08\u8def\u7531\uff09\u3002\u5b83\u5de5\u4f5c\u5728OSI\u6a21\u578b\u7684\u7f51\u7edc\u5c42\u3002<\/li>\n\n\n\n<li><strong>\u529f\u80fd\uff1a<\/strong> \u53ef\u4ee5\u5b9e\u73b0\u4e0d\u540cVLAN\u4e4b\u95f4\u7684\u8def\u7531\uff08VLAN\u95f4\u8def\u7531\uff09\uff0c\u4ee5\u53ca\u8fde\u63a5\u4e0d\u540c\u7684\u5b50\u7f51\u3002<\/li>\n\n\n\n<li><strong>\u4f18\u70b9\uff1a<\/strong> \u8def\u7531\u901f\u5ea6\u6bd4\u4f20\u7edf\u8def\u7531\u5668\u5feb\uff08\u56e0\u4e3a\u662f\u786c\u4ef6\u8f6c\u53d1\uff09\uff0c\u9002\u7528\u4e8e\u5927\u578b\u7f51\u7edc\u7684\u6838\u5fc3\u5c42\u6216\u6c47\u805a\u5c42\uff0c\u9700\u8981\u9ad8\u6027\u80fd\u8def\u7531\u7684\u573a\u666f\u3002<\/li>\n\n\n\n<li><strong>CTF\u76f8\u5173\uff1a<\/strong> \u4e86\u89e3\u4e09\u5c42\u4ea4\u6362\u673a\u7684\u8def\u7531\u529f\u80fd\u5bf9\u4e8e\u7406\u89e3\u7f51\u7edc\u5206\u6bb5\u3001\u8def\u7531\u7b56\u7565\u548c\u6f5c\u5728\u7684\u8def\u7531\u6f0f\u6d1e\uff08\u5982BGP\u52ab\u6301\u3001OSPF\/EIGRP\u8def\u7531\u534f\u8bae\u6f0f\u6d1e\uff09\u975e\u5e38\u91cd\u8981\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">3. \u6309\u7aef\u53e3\u914d\u7f6e\u5206\u7c7b<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u56fa\u5b9a\u914d\u7f6e\u4ea4\u6362\u673a (Fixed Configuration Switches)<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u7279\u70b9\uff1a<\/strong> \u7aef\u53e3\u6570\u91cf\u548c\u7c7b\u578b\u662f\u56fa\u5b9a\u7684\uff0c\u4e0d\u80fd\u6269\u5c55\u6216\u66f4\u6539\u3002<\/li>\n\n\n\n<li><strong>\u4f18\u70b9\uff1a<\/strong> \u6210\u672c\u8f83\u4f4e\uff0c\u7ed3\u6784\u7d27\u51d1\u3002<\/li>\n\n\n\n<li><strong>\u5e94\u7528\uff1a<\/strong> \u9002\u7528\u4e8e\u7aef\u53e3\u9700\u6c42\u76f8\u5bf9\u7a33\u5b9a\u7684\u5c0f\u578b\u5230\u4e2d\u578b\u7f51\u7edc\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u6a21\u5757\u5316\u4ea4\u6362\u673a (Modular Switches)<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u7279\u70b9\uff1a<\/strong> \u5141\u8bb8\u7528\u6237\u6839\u636e\u9700\u6c42\u63d2\u5165\u6216\u66f4\u6362\u4e0d\u540c\u7684\u6a21\u5757\uff0c\u4f8b\u5982\u4e0d\u540c\u6570\u91cf\u548c\u7c7b\u578b\u7684\u7aef\u53e3\u6a21\u5757\u3001\u7535\u6e90\u6a21\u5757\u3001\u7ba1\u7406\u6a21\u5757\u7b49\u3002<\/li>\n\n\n\n<li><strong>\u4f18\u70b9\uff1a<\/strong> \u7075\u6d3b\u6027\u9ad8\uff0c\u53ef\u6269\u5c55\u6027\u5f3a\uff0c\u652f\u6301\u5197\u4f59\u914d\u7f6e\u3002<\/li>\n\n\n\n<li><strong>\u5e94\u7528\uff1a<\/strong> \u9002\u7528\u4e8e\u5927\u578b\u4f01\u4e1a\u7f51\u7edc\u3001\u6570\u636e\u4e2d\u5fc3\u7684\u6838\u5fc3\u5c42\uff0c\u9700\u8981\u9ad8\u53ef\u7528\u6027\u548c\u672a\u6765\u6269\u5c55\u6027\u7684\u573a\u666f\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">4. \u6309\u662f\u5426\u652f\u6301PoE\u5206\u7c7b<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>PoE \u4ea4\u6362\u673a (Power over Ethernet Switches)<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u7279\u70b9\uff1a<\/strong> \u80fd\u591f\u901a\u8fc7\u4ee5\u592a\u7f51\u7ebf\u7f06\u540c\u65f6\u4e3a\u8fde\u63a5\u7684\u8bbe\u5907\u63d0\u4f9b\u6570\u636e\u4f20\u8f93\u548c\u7535\u529b\u3002<\/li>\n\n\n\n<li><strong>\u4f18\u70b9\uff1a<\/strong> \u7b80\u5316\u5e03\u7ebf\uff0c\u65b9\u4fbf\u90e8\u7f72IP\u7535\u8bdd\u3001\u65e0\u7ebf\u63a5\u5165\u70b9 (AP)\u3001\u7f51\u7edc\u6444\u50cf\u5934\u7b49\u8bbe\u5907\u3002<\/li>\n\n\n\n<li><strong>CTF\u76f8\u5173\uff1a<\/strong> \u4e86\u89e3PoE\u4f9b\u7535\u673a\u5236\u53ef\u4ee5\u5e2e\u52a9\u8bc6\u522b\u7f51\u7edc\u4e2d\u7684\u7279\u5b9a\u8bbe\u5907\uff0c\u6216\u8005\u5728\u7269\u7406\u8bbf\u95ee\u53d7\u9650\u7684\u60c5\u51b5\u4e0b\uff0c\u5229\u7528PoE\u4f9b\u7535\u7684\u7279\u6027\u8fdb\u884c\u4e00\u4e9b\u64cd\u4f5c\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u975ePoE \u4ea4\u6362\u673a (Non-PoE Switches)<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u7279\u70b9\uff1a<\/strong> \u53ea\u63d0\u4f9b\u6570\u636e\u4f20\u8f93\u529f\u80fd\uff0c\u4e0d\u63d0\u4f9b\u7535\u529b\u3002<\/li>\n\n\n\n<li><strong>\u5e94\u7528\uff1a<\/strong> \u5927\u591a\u6570\u4f20\u7edf\u4ea4\u6362\u673a\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">\u8282\u70b9<\/h2>\n\n\n\n<p>\u201c\u8282\u70b9\u201d\uff08Node\uff09\u662f\u4e00\u4e2a\u975e\u5e38\u901a\u7528\u4e14\u57fa\u7840\u7684\u8ba1\u7b97\u673a\u79d1\u5b66\u548c\u7f51\u7edc\u9886\u57df\u7684\u672f\u8bed\u3002\u5b83\u7684\u5177\u4f53\u542b\u4e49\u4f1a\u6839\u636e\u4f60\u6240\u8ba8\u8bba\u7684<strong>\u4e0a\u4e0b\u6587<\/strong>\u800c\u6709\u6240\u4e0d\u540c\uff0c\u4f46\u6838\u5fc3\u601d\u60f3\u662f\u76f8\u4f3c\u7684\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/usual1009.oss-cn-shanghai.aliyuncs.com\/img\/202511291927632.png\" alt=\"image-20251109180915875\"\/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">\u6838\u5fc3\u601d\u60f3<\/h3>\n\n\n\n<p>\u4e00\u4e2a\u201c\u8282\u70b9\u201d\u901a\u5e38\u6307\u7684\u662f\uff1a<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u7cfb\u7edf\u4e2d\u7684\u4e00\u4e2a\u70b9\u6216\u5b9e\u4f53\uff1a<\/strong> \u5b83\u662f\u67d0\u4e2a\u66f4\u5927\u7cfb\u7edf\u3001\u7ed3\u6784\u6216\u7f51\u7edc\u4e2d\u7684\u4e00\u4e2a<strong>\u57fa\u672c\u7ec4\u6210\u5355\u5143<\/strong>\u3002<\/li>\n\n\n\n<li><strong>\u5177\u6709\u7279\u5b9a\u529f\u80fd\uff1a<\/strong> \u8fd9\u4e2a\u70b9\u6216\u5b9e\u4f53\u901a\u5e38\u5177\u6709\u67d0\u79cd\u5904\u7406\u3001\u5b58\u50a8\u3001\u8f6c\u53d1\u6216\u53c2\u4e0e\u7279\u5b9a\u4efb\u52a1\u7684\u80fd\u529b\u3002<\/li>\n\n\n\n<li><strong>\u4e0e\u5176\u4ed6\u70b9\u4ea4\u4e92\uff1a<\/strong> \u5b83\u901a\u5e38\u4e0e\u5176\u4ed6\u8282\u70b9\u76f8\u4e92\u8fde\u63a5\u3001\u901a\u4fe1\u6216\u534f\u4f5c\u3002<\/li>\n<\/ol>\n\n\n\n<p>\u4f60\u53ef\u4ee5\u628a\u201c\u8282\u70b9\u201d\u60f3\u8c61\u6210\u4e00\u4e2a<strong>\u7f51\u7edc\u4e2d\u7684\u201c\u505c\u9760\u7ad9\u201d<\/strong>\uff0c\u6216\u8005\u4e00\u4e2a<strong>\u7ed3\u6784\u4e2d\u7684\u201c\u7816\u5757\u201d<\/strong>\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u4e0d\u540c\u9886\u57df\u7684\u201c\u8282\u70b9\u201d<\/h3>\n\n\n\n<p>\u4e3a\u4e86\u8ba9\u4f60\u66f4\u6e05\u695a\u5730\u7406\u89e3\uff0c\u6211\u4eec\u6765\u770b\u770b\u5728\u4e0d\u540c\u4e0a\u4e0b\u6587\u4e2d\uff0c\u201c\u8282\u70b9\u201d\u5177\u4f53\u6307\u4ec0\u4e48\uff1a<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">1. \u8ba1\u7b97\u673a\u7f51\u7edc\u4e2d\u7684\u201c\u8282\u70b9\u201d (CTF\u4e2d\u6700\u5e38\u89c1\u542b\u4e49)<\/h4>\n\n\n\n<p>\u5728\u8ba1\u7b97\u673a\u7f51\u7edc\u4e2d\uff0c\u201c\u8282\u70b9\u201d\u662f\u6700\u5e38\u89c1\u7684\u7528\u6cd5\uff0c\u5b83\u6307\u7684\u662f<strong>\u4efb\u4f55\u8fde\u63a5\u5230\u7f51\u7edc\u7684\u8bbe\u5907\u6216\u8ba1\u7b97\u673a<\/strong>\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u4f8b\u5b50\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li>\u4f60\u7684<strong>\u7535\u8111<\/strong> (PC)<\/li>\n\n\n\n<li><strong>\u670d\u52a1\u5668<\/strong> (Server)<\/li>\n\n\n\n<li><strong>\u8def\u7531\u5668<\/strong> (Router)<\/li>\n\n\n\n<li><strong>\u4ea4\u6362\u673a<\/strong> (Switch)<\/li>\n\n\n\n<li><strong>\u6253\u5370\u673a<\/strong> (Printer)<\/li>\n\n\n\n<li><strong>\u667a\u80fd\u624b\u673a<\/strong> (Smartphone)<\/li>\n\n\n\n<li><strong>\u7269\u8054\u7f51\u8bbe\u5907<\/strong> (IoT Device\uff0c\u5982\u667a\u80fd\u6444\u50cf\u5934\u3001\u667a\u80fd\u97f3\u7bb1)<\/li>\n\n\n\n<li>\u4efb\u4f55\u5177\u6709<strong>\u7f51\u7edc\u63a5\u53e3<\/strong>\u5e76\u80fd\u591f\u53d1\u9001\u6216\u63a5\u6536\u6570\u636e\u7684\u8bbe\u5907\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u7279\u70b9\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li>\u6bcf\u4e2a\u8282\u70b9\u901a\u5e38\u90fd\u6709\u4e00\u4e2a<strong>\u552f\u4e00\u7684\u7f51\u7edc\u5730\u5740<\/strong>\uff08\u5982MAC\u5730\u5740\u548cIP\u5730\u5740\uff09\u3002<\/li>\n\n\n\n<li>\u5b83\u4eec\u901a\u8fc7\u7f51\u7edc\u4ecb\u8d28\uff08\u5982\u7f51\u7ebf\u3001Wi-Fi\uff09\u76f8\u4e92\u8fde\u63a5\u3002<\/li>\n\n\n\n<li>\u5b83\u4eec\u80fd\u591f\u4e0e\u5176\u4ed6\u8282\u70b9\u8fdb\u884c\u6570\u636e\u901a\u4fe1\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>CTF\u4e2d\u7684\u610f\u4e49\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li>\u5728CTF\u4e2d\u8fdb\u884c\u7f51\u7edc\u6e17\u900f\u6d4b\u8bd5\u65f6\uff0c\u4f60\u9996\u5148\u8981\u505a\u7684\u5c31\u662f<strong>\u8bc6\u522b\u7f51\u7edc\u4e2d\u6709\u54ea\u4e9b\u8282\u70b9<\/strong>\uff08\u8bbe\u5907\uff09\uff0c\u5b83\u4eec\u662f\u4ec0\u4e48\u7c7b\u578b\uff0c\u8fd0\u884c\u4ec0\u4e48\u670d\u52a1\uff0c\u4ee5\u53ca\u5b83\u4eec\u4e4b\u95f4\u7684\u8fde\u63a5\u5173\u7cfb\u3002<\/li>\n\n\n\n<li>\u653b\u51fb\u76ee\u6807\u5f80\u5f80\u662f\u7f51\u7edc\u4e2d\u7684\u67d0\u4e2a\u6216\u67d0\u7ec4\u8282\u70b9\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">2. \u6570\u636e\u7ed3\u6784\u4e0e\u7b97\u6cd5\u4e2d\u7684\u201c\u8282\u70b9\u201d<\/h4>\n\n\n\n<p>\u5728\u8ba1\u7b97\u673a\u79d1\u5b66\u7684\u6570\u636e\u7ed3\u6784\u4e2d\uff0c\u201c\u8282\u70b9\u201d\u662f\u6784\u5efa\u590d\u6742\u6570\u636e\u7ed3\u6784\uff08\u5982\u94fe\u8868\u3001\u6811\u3001\u56fe\uff09\u7684\u57fa\u672c\u5355\u5143\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u4f8b\u5b50\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u94fe\u8868 (Linked List) \u4e2d\u7684\u8282\u70b9\uff1a<\/strong> \u901a\u5e38\u5305\u542b\u4e24\u90e8\u5206\u2014\u2014\u6570\u636e\u672c\u8eab\uff0c\u4ee5\u53ca\u4e00\u4e2a\u6307\u5411\u4e0b\u4e00\u4e2a\u8282\u70b9\u7684\u6307\u9488\uff08\u6216\u5f15\u7528\uff09\u3002 <code>[\u6570\u636e | \u6307\u5411\u4e0b\u4e00\u4e2a\u8282\u70b9\u7684\u6307\u9488]<\/code><\/li>\n\n\n\n<li><strong>\u6811 (Tree) \u4e2d\u7684\u8282\u70b9\uff1a<\/strong> \u5305\u542b\u6570\u636e\uff0c\u4ee5\u53ca\u6307\u5411\u5176\u5b50\u8282\u70b9\u7684\u6307\u9488\u3002\u6811\u6709\u6839\u8282\u70b9 (Root Node)\u3001\u7236\u8282\u70b9 (Parent Node)\u3001\u5b50\u8282\u70b9 (Child Node) \u548c\u53f6\u8282\u70b9 (Leaf Node) \u7b49\u6982\u5ff5\u3002 <code>[\u6570\u636e | \u6307\u5411\u5b50\u8282\u70b9\u7684\u6307\u9488]<\/code><\/li>\n\n\n\n<li><strong>\u56fe (Graph) \u4e2d\u7684\u8282\u70b9\uff1a<\/strong> \u4e5f\u79f0\u4e3a\u201c\u9876\u70b9\u201d\uff08Vertex\uff09\uff0c\u4ee3\u8868\u56fe\u4e2d\u7684\u4e00\u4e2a\u5b9e\u4f53\uff0c\u53ef\u4ee5\u6709\u6570\u636e\uff0c\u5e76\u901a\u8fc7\u201c\u8fb9\u201d\uff08Edge\uff09\u4e0e\u5176\u4ed6\u8282\u70b9\u8fde\u63a5\u3002 <code>[\u6570\u636e]<\/code><\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u7279\u70b9\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li>\u5b58\u50a8\u6570\u636e\u3002<\/li>\n\n\n\n<li>\u5305\u542b\u6307\u5411\u5176\u4ed6\u8282\u70b9\u7684\u94fe\u63a5\uff0c\u4ece\u800c\u5f62\u6210\u7279\u5b9a\u7684\u7ed3\u6784\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">3. \u5206\u5e03\u5f0f\u7cfb\u7edf\u548c\u533a\u5757\u94fe\u4e2d\u7684\u201c\u8282\u70b9\u201d<\/h4>\n\n\n\n<p>\u5728\u5206\u5e03\u5f0f\u7cfb\u7edf\u548c\u533a\u5757\u94fe\u6280\u672f\u4e2d\uff0c\u201c\u8282\u70b9\u201d\u6307\u7684\u662f\u53c2\u4e0e\u5230\u8fd9\u4e2a\u5206\u5e03\u5f0f\u7f51\u7edc\u4e2d\u7684<strong>\u6bcf\u4e00\u53f0\u72ec\u7acb\u7684\u8ba1\u7b97\u673a\u6216\u670d\u52a1\u5668<\/strong>\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u4f8b\u5b50\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u533a\u5757\u94fe\u7f51\u7edc\u4e2d\u7684\u8282\u70b9\uff1a<\/strong> \u6bcf\u53f0\u8fd0\u884c\u533a\u5757\u94fe\u8f6f\u4ef6\u3001\u5b58\u50a8\u8d26\u672c\u526f\u672c\u3001\u9a8c\u8bc1\u4ea4\u6613\u5e76\u53c2\u4e0e\u5171\u8bc6\u673a\u5236\u7684\u8ba1\u7b97\u673a\u3002\u5b83\u4eec\u5171\u540c\u7ef4\u62a4\u6574\u4e2a\u533a\u5757\u94fe\u7684\u5b8c\u6574\u6027\u3002<\/li>\n\n\n\n<li><strong>\u5206\u5e03\u5f0f\u6570\u636e\u5e93\u4e2d\u7684\u8282\u70b9\uff1a<\/strong> \u6bcf\u53f0\u5b58\u50a8\u90e8\u5206\u6570\u636e\u6216\u63d0\u4f9b\u6570\u636e\u5e93\u670d\u52a1\u7684\u670d\u52a1\u5668\u3002<\/li>\n\n\n\n<li><strong>\u4e91\u8ba1\u7b97\u96c6\u7fa4\u4e2d\u7684\u8ba1\u7b97\u8282\u70b9\uff1a<\/strong> \u63d0\u4f9b\u8ba1\u7b97\u8d44\u6e90\u7684\u670d\u52a1\u5668\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u7279\u70b9\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li>\u901a\u5e38\u662f\u72ec\u7acb\u7684\u7269\u7406\u6216\u865a\u62df\u673a\u5668\u3002<\/li>\n\n\n\n<li>\u5b83\u4eec\u534f\u540c\u5de5\u4f5c\uff0c\u5171\u540c\u5b8c\u6210\u4e00\u4e2a\u4efb\u52a1\u6216\u7ef4\u62a4\u4e00\u4e2a\u5171\u4eab\u7684\u72b6\u6001\u3002<\/li>\n\n\n\n<li>\u8282\u70b9\u4e4b\u95f4\u901a\u8fc7\u7f51\u7edc\u8fdb\u884c\u901a\u4fe1\u548c\u540c\u6b65\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">4. \u7269\u7406\u7f51\u7edc\u62d3\u6251\u4e2d\u7684\u201c\u8282\u70b9\u201d<\/h4>\n\n\n\n<p>\u5728\u63cf\u8ff0\u7269\u7406\u7f51\u7edc\u5e03\u7ebf\u65f6\uff0c\u201c\u8282\u70b9\u201d\u4e5f\u53ef\u4ee5\u6307<strong>\u7269\u7406\u8fde\u63a5\u70b9<\/strong>\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u4f8b\u5b50\uff1a\n<ul class=\"wp-block-list\">\n<li>\u5899\u4e0a\u7684<strong>\u7f51\u7ebf\u63d2\u5ea7<\/strong>\u3002<\/li>\n\n\n\n<li>\u914d\u7ebf\u67b6\u4e0a\u7684<strong>\u7aef\u53e3<\/strong>\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">\u603b\u7ed3<\/h3>\n\n\n\n<p>\u6240\u4ee5\uff0c\u5f53\u4f60\u542c\u5230\u201c\u8282\u70b9\u201d\u8fd9\u4e2a\u8bcd\u65f6\uff0c\u9996\u5148\u8981\u8003\u8651\u5b83\u6240\u5728\u7684<strong>\u4e0a\u4e0b\u6587<\/strong>\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u5728CTF\u548c\u65e5\u5e38\u7f51\u7edc\u8bed\u5883\u4e2d\uff0c\u5b83\u51e0\u4e4e\u603b\u662f\u6307\u8fde\u63a5\u5230\u7f51\u7edc\u7684<\/strong>\u8bbe\u5907\u6216\u8ba1\u7b97\u673a<strong>\u3002<\/strong><\/li>\n\n\n\n<li>\u5728\u5176\u4ed6\u8ba1\u7b97\u673a\u79d1\u5b66\u9886\u57df\uff0c\u5b83\u53ef\u80fd\u6307\u6570\u636e\u7ed3\u6784\u4e2d\u7684\u5143\u7d20\u6216\u5206\u5e03\u5f0f\u7cfb\u7edf\u4e2d\u7684\u53c2\u4e0e\u8005\u3002<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><strong><a href=\"https:\/\/zhida.zhihu.com\/search?content_id=170268177&amp;content_type=Article&amp;match_order=1&amp;q=ICMP%E5%8D%8F%E8%AE%AE&amp;zd_token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJ6aGlkYV9zZXJ2ZXIiLCJleHAiOjE3NjI4NTg2MzQsInEiOiJJQ01Q5Y2P6K6uIiwiemhpZGFfc291cmNlIjoiZW50aXR5IiwiY29udGVudF9pZCI6MTcwMjY4MTc3LCJjb250ZW50X3R5cGUiOiJBcnRpY2xlIiwibWF0Y2hfb3JkZXIiOjEsInpkX3Rva2VuIjpudWxsfQ.tFuJMd6CBiba2tdBzMdbYpRQbuhPMiy9z-w-zzGfIMA&amp;zhida_source=entity\" target=\"_blank\"  rel=\"nofollow\" >ICMP\u534f\u8bae<\/a><\/strong>\uff08\u672a\u7ec6\u770b\uff0c\u4ec5\u8bb0\u5f55\uff09<\/h2>\n\n\n\n<p>ICMP\u662f Internet Control Message Protocol \u7684\u7f29\u5199\uff0c\u5373\u4e92\u8054\u7f51\u63a7\u5236\u6d88\u606f\u534f\u8bae\u3002\u5b83\u662f\u4e92\u8054\u7f51\u534f\u8bae\u65cf\u7684\u6838\u5fc3\u534f\u8bae\u4e4b\u4e00\u3002\u5b83\u7528\u4e8e <a href=\"https:\/\/zhida.zhihu.com\/search?content_id=170268177&amp;content_type=Article&amp;match_order=1&amp;q=TCP%2FIP&amp;zd_token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJ6aGlkYV9zZXJ2ZXIiLCJleHAiOjE3NjI4NTg2MzQsInEiOiJUQ1AvSVAiLCJ6aGlkYV9zb3VyY2UiOiJlbnRpdHkiLCJjb250ZW50X2lkIjoxNzAyNjgxNzcsImNvbnRlbnRfdHlwZSI6IkFydGljbGUiLCJtYXRjaF9vcmRlciI6MSwiemRfdG9rZW4iOm51bGx9.Dx_Lp1Qi9K1h4IuUIjoHlHW5P2pYRtipDbdx27zSHBA&amp;zhida_source=entity\" target=\"_blank\"  rel=\"nofollow\" >TCP\/IP<\/a> \u7f51\u7edc\u4e2d\u53d1\u9001\u63a7\u5236\u6d88\u606f\uff0c\u63d0\u4f9b\u53ef\u80fd\u53d1\u751f\u5728\u901a\u4fe1\u73af\u5883\u4e2d\u7684\u5404\u79cd\u95ee\u9898\u53cd\u9988\uff0c\u901a\u8fc7\u8fd9\u4e9b\u4fe1\u606f\uff0c\u4f7f\u7f51\u7edc\u7ba1\u7406\u8005\u53ef\u4ee5\u5bf9\u6240\u53d1\u751f\u7684\u95ee\u9898\u4f5c\u51fa\u8bca\u65ad\uff0c\u7136\u540e\u91c7\u53d6\u9002\u5f53\u7684\u63aa\u65bd\u89e3\u51b3\u95ee\u9898\u3002<\/p>\n\n\n\n<p>\u867d\u7136 ICMP \u662f\u7f51\u7edc\u5c42\u534f\u8bae\uff0c\u4f46\u662f\u5b83\u4e0d\u50cf IP \u534f\u8bae\u548c ARP \u534f\u8bae\u4e00\u6837\u76f4\u63a5\u4f20\u9012\u7ed9\u6570\u636e\u94fe\u8def\u5c42\uff0c\u800c\u662f\u5148\u5c01\u88c5\u6210 IP \u6570\u636e\u5305\u7136\u540e\u518d\u4f20\u9012\u7ed9\u6570\u636e\u94fe\u8def\u5c42\u3002\u6240\u4ee5\u5728 IP \u6570\u636e\u5305\u4e2d\u5982\u679c\u534f\u8bae\u7c7b\u578b\u5b57\u6bb5\u7684\u503c\u662f 1 \u7684\u8bdd\uff0c\u5c31\u8868\u793a IP \u6570\u636e\u662f ICMP \u62a5\u6587\u3002IP \u6570\u636e\u5305\u5c31\u662f\u9760\u8fd9\u4e2a\u534f\u8bae\u7c7b\u578b\u5b57\u6bb5\u6765\u533a\u5206\u4e0d\u540c\u7684\u6570\u636e\u5305\u7684\u3002\u5982\u4e0b\u56fe <a href=\"https:\/\/zhida.zhihu.com\/search?content_id=170268177&amp;content_type=Article&amp;match_order=1&amp;q=WireShark&amp;zd_token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJ6aGlkYV9zZXJ2ZXIiLCJleHAiOjE3NjI4NTg2MzQsInEiOiJXaXJlU2hhcmsiLCJ6aGlkYV9zb3VyY2UiOiJlbnRpdHkiLCJjb250ZW50X2lkIjoxNzAyNjgxNzcsImNvbnRlbnRfdHlwZSI6IkFydGljbGUiLCJtYXRjaF9vcmRlciI6MSwiemRfdG9rZW4iOm51bGx9.hN23_aHMdbhpjEOEL4r1x5bvy8J2eWbXlam3Z80Pw4Y&amp;zhida_source=entity\" target=\"_blank\"  rel=\"nofollow\" >WireShark<\/a> \u6293\u5305\u6240\u793a\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/usual1009.oss-cn-shanghai.aliyuncs.com\/img\/202511291927736.jpeg\" alt=\"img\"\/><\/figure>\n\n\n\n<p>\u5728 IP \u901a\u4fe1\u4e2d\u5982\u679c\u67d0\u4e2a\u5305\u56e0\u4e3a\u672a\u77e5\u539f\u56e0\u6ca1\u6709\u5230\u8fbe\u76ee\u7684\u5730\u5740\uff0c\u90a3\u4e48\u8fd9\u4e2a\u5177\u4f53\u7684\u539f\u56e0\u5c31\u662f\u7531 ICMP \u8d1f\u8d23\u544a\u77e5\u3002\u800c ICMP \u534f\u8bae\u7684\u7c7b\u578b\u5b9a\u4e49\u4e2d\u5c31\u6e05\u695a\u7684\u63cf\u8ff0\u4e86\u5404\u79cd\u62a5\u6587\u7684\u542b\u4e49\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>ICMP\u534f\u8bae\u7c7b\u578b<\/strong><\/h3>\n\n\n\n<p>ICMP\u534f\u8bae\u7684\u7c7b\u578b\u5206\u4e3a\u4e24\u5927\u7c7b\uff0c<strong>\u67e5\u8be2\u62a5\u6587<\/strong>\u548c<strong>\u5dee\u9519\u62a5\u6587<\/strong>\u3002\u5982\u4e0b\u8868\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/usual1009.oss-cn-shanghai.aliyuncs.com\/img\/202511291927463.jpeg\" alt=\"img\"\/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/usual1009.oss-cn-shanghai.aliyuncs.com\/img\/202511291927974.jpeg\" alt=\"img\"\/><\/figure>\n\n\n\n<p><em>\u662f\u4e0d\u662f\u770b\u8d77\u6765\u6709\u70b9\u591a\u554a\uff1f\u8ba1\u7b97\u673a\u7f51\u7edc\u771f\u7684\u662f\u535a\u5927\u7cbe\u6df1\u554a\u3002\u800c\u5e73\u65f6\u6211\u4eec\u7ecf\u5e38\u4f7f\u7528\u7684\u5c11\u4e4b\u53c8\u5c11\u3002<\/em><\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>ICMP\u62a5\u6587\u683c\u5f0f<\/strong><\/h3>\n\n\n\n<p>\u4ece ICMP \u7684\u62a5\u6587\u683c\u5f0f\u6765\u8bf4\uff0cICMP \u662f IP \u7684\u4e0a\u5c42\u534f\u8bae\u3002\u4f46\u662f ICMP \u662f\u5206\u62c5\u4e86 IP \u7684\u4e00\u90e8\u5206\u529f\u80fd\u3002\u6240\u4ee5\uff0c\u4ed6\u4e5f\u88ab\u8ba4\u4e3a\u662f\u4e0e IP \u540c\u5c42\u7684\u534f\u8bae\u3002\u4e0b\u9762\u4e00\u8d77\u6765\u770b\u4e00\u4e0b ICMP \u6570\u636e\u5305\u683c\u5f0f\u548c\u62a5\u6587\u5185\u5bb9\u5427\u3002\u5177\u4f53\u53c2\u8003\u4e0b\u56fe\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/usual1009.oss-cn-shanghai.aliyuncs.com\/img\/202511291927594.jpeg\" alt=\"img\"\/><\/figure>\n\n\n\n<p>\u53ef\u4ee5\u770b\u5230\uff0c\u6211\u4eec\u4e00\u5c42\u5c42\u5265\u5f00 ICMP \u7684\u5916\u58f3\uff0c\u67e5\u770b\u5176\u672c\u8d28\u3002\u65b9\u4fbf\u6211\u4eec\u66f4\u597d\u7684\u7406\u89e3 ICMP \u534f\u8bae\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>ICMP\u534f\u8bae\u5b9e\u73b0--Ping\u547d\u4ee4<\/strong><\/h3>\n\n\n\n<p>\u901a\u8fc7\u4e0a\u9762\u7684\u53d9\u8ff0\uff0c\u6211\u4eec\u521d\u6b65\u4e86\u89e3\u4e86 ICMP \u534f\u8bae\u7684\u5185\u5bb9\uff0c\u90a3\u4e48\u4e0b\u9762\u6211\u4eec\u6765\u770b\u4e00\u4e0bICMP \u7684\u5177\u4f53\u5b9e\u73b0\u4e0e\u5e94\u7528\u5427\uff0c\u9996\u5148\u6211\u4eec\u6765\u4e86\u89e3<strong>\u67e5\u8be2\u62a5\u6587<\/strong>\u7684\u5e94\u7528--ping\uff0c\u4e0b\u9762\u6211\u4eec\u901a\u8fc7 ping \u540c\u4e00\u4e2a\u5b50\u7f51\u7684\u4e3b\u673a\uff0c\u6765\u770b\u4e00\u4e0b\u6574\u4e2a\u8fc7\u7a0b\u662f\u600e\u4e48\u6837\u7684\u3002<\/p>\n\n\n\n<p>\u90a3\u4e48\u6bd4\u8f83\u5b8c\u6574\u7684\u6d41\u7a0b\u662f\uff1a<\/p>\n\n\n\n<p><strong>1. \u5411\u76ee\u7684\u670d\u52a1\u5668\u53d1\u9001\u56de\u663e\u8bf7\u6c42<\/strong> \u9996\u5148\uff0c\u5411\u76ee\u7684\u670d\u52a1\u5668\u4e0a\u6267\u884cping\u547d\u4ee4\uff0c\u4e3b\u673a\u4f1a\u6784\u5efa\u4e00\u4e2a ICMP \u56de\u663e\u8bf7\u6c42\u6d88\u606f\u6570\u636e\u5305\uff08\u7c7b\u578b\u662f8\uff0c\u4ee3\u7801\u662f0\uff09\uff0c\u5728\u8fd9\u4e2a\u56de\u663e\u8bf7\u6c42\u6570\u636e\u5305\u4e2d\uff0c\u9664\u4e86\u7c7b\u578b\u548c\u4ee3\u7801\u5b57\u6bb5\uff0c\u8fd8\u88ab\u8ffd\u52a0\u4e86\u6807\u8bc6\u7b26\u548c\u5e8f\u53f7\u5b57\u6bb5\u3002\u6807\u8bc6\u7b26\u548c\u5e8f\u53f7\u5b57\u6bb5\u5206\u522b\u662f 16 \u4f4d\u7684\u5b57\u6bb5\u3002ping \u547d\u4ee4\u5728\u53d1\u9001\u56de\u663e\u8bf7\u6c42\u6570\u636e\u5305\u65f6\uff0c\u4f1a\u5c06\u8fdb\u7a0b\u53f7\u586b\u5199\u5728\u6807\u8bc6\u7b26\u91cc\u3002\u5bf9\u4e8e\u5e8f\u53f7\uff0c\u6bcf\u9001\u51fa\u4e00\u4e2a\u6570\u636e\u5305\u6570\u503c\u5c31\u589e\u52a01\u3002\u800c\u4e14\uff0c\u56de\u663e\u8bf7\u6c42\u7684\u9009\u9879\u6570\u636e\u90e8\u5206\u7528\u6765\u88c5\u4efb\u610f\u6570\u636e\u3002\u8fd9\u4e2a\u4efb\u610f\u6570\u636e\u7528\u6765\u8c03\u6574 ping \u7684\u4ea4\u4e92\u6570\u636e\u5305\u7684\u5927\u5c0f\u3002\u5982\u4e0b\u56fe\u5728 192.168.1.10\u4e0a\u6267\u884c ping 192.168.1.1\u7684\u547d\u4ee4\uff1a<\/p>\n\n\n\n<p>ping \u547d\u4ee4\u6267\u884c\u7684\u65f6\u5019\uff0c\u4ed6\u7684\u8fdb\u7a0b\u53f7\u662f 43991\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/usual1009.oss-cn-shanghai.aliyuncs.com\/img\/202511291927723.jpeg\" alt=\"img\"\/><\/figure>\n\n\n\n<p>\u901a\u8fc7 WireShark \u6293\u5305\u53ef\u4ee5\u770b\u51fa\uff0c\u4e0a\u56fe\u4e2d\u7684 192.168.1.10 \u4e3b\u673a\u4f1a\u6784\u5efa\u4e00\u4e2a ICMP \u56de\u663e\u8bf7\u6c42\u6d88\u606f\u6570\u636e\u5305\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/usual1009.oss-cn-shanghai.aliyuncs.com\/img\/202511291927124.jpeg\" alt=\"img\"\/><\/figure>\n\n\n\n<p>\u4e0a\u56fe\u4e2d\u6211\u4eec\u53ef\u4ee5\u770b\u5230 ICMP \u7684 Type\uff08\u534f\u8bae\u7c7b\u578b\uff09\u662f 8\uff0cCode\uff08\u4ee3\u7801\uff09\u662f 0\uff0cIdentifier(ping\u8fdb\u7a0b\u53f7) \u662f 43991\uff0c\u540c\u65f6\u8fd8\u6709 Sequence Number \u53d1\u9001\u5e8f\u53f711\uff0c\u4ee5\u53ca\u53d1\u9001\u65f6\u95f4 \u3002<\/p>\n\n\n\n<p><strong>2. \u76ee\u7684\u670d\u52a1\u5668\u53d1\u9001\u56de\u663e\u5e94\u7b54<\/strong><\/p>\n\n\n\n<p>\u5f53192.168.1.10\u9001\u5230 \u56de\u663e\u8bf7\u6c42\u6570\u636e\u5305\u540e\uff0c192.168.1.1\u5c31\u4f1a\u5411\u53d1\u9001\u65b9192.168.1.10\u53d1\u9001\u56de\u663e\u5e94\u7b54\uff08\u7c7b\u578b\u662f0\uff0c\u4ee3\u7801\u662f0\uff09\uff0c\u8fd9\u4e2a ICMP \u56de\u663e\u5e94\u7b54\u6570\u636e\u5305\u5728 IP \u5c42\u6765\u770b\uff0c\u4e0e\u88ab\u9001\u6765\u7684\u56de\u663e\u8bf7\u6c42\u6570\u636e\u5305\u57fa\u672c\u4e0a\u4e00\u6837\u3002\u4e0d\u540c\u7684\u53ea\u6709\u6e90\u3001\u76ee\u6807 IP \u5730\u5740\u5b57\u6bb5\u88ab\u4ea4\u6362\u4e86\uff0cType\u7c7b\u578b\u5b57\u6bb5\u91cc\u586b\u5165\u4e86\u8868\u793a\u56de\u663e\u5e94\u7b54\u76840\u3002\u901a\u8fc7 WireShark \u6293\u5305\u53ef\u4ee5\u770b\u51fa\uff0c\u5982\u4e0b\u56fe\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/usual1009.oss-cn-shanghai.aliyuncs.com\/img\/202511291927214.jpeg\" alt=\"img\"\/><\/figure>\n\n\n\n<p><strong>3. \u6e90\u670d\u52a1\u5668\u663e\u793a\u76f8\u5173\u6570\u636e<\/strong><\/p>\n\n\n\n<p>\u5982\u679c\u6e90\u670d\u52a1\u5668\u53ef\u4ee5\u63a5\u6536\u5230\u56de\u663e\u5e94\u7b54\u6570\u636e\u5305\uff0c\u90a3\u6211\u4eec\u5c31\u8ba4\u4e3a192.168.1.1\u662f\u6b63\u5e38\u5de5\u4f5c\u7740\u7684\u3002\u8fdb\u4e00\u6b65\uff0c\u8bb0\u4f4f\u53d1\u9001\u56de\u663e\u8bf7\u6c42\u6570\u636e\u5305\u7684\u65f6\u95f4\uff0c\u4e0e\u63a5\u6536\u5230\u56de\u663e\u5e94\u7b54\u6570\u636e\u5305\u7684\u65f6\u95f4\u5dee\uff0c\u5c31\u80fd\u8ba1\u7b97\u51fa\u6570\u636e\u5305\u4e00\u53bb\u4e00\u56de\u6240\u9700\u8981\u7684\u65f6\u95f4\u3002\u8fd9\u4e2a\u65f6\u5019ping\u547d\u4ee4\u5c31\u4f1a\u5c06\u76ee\u7684\u670d\u52a1\u5668\u7684 IP \u5730\u5740\uff0c\u6570\u636e\u5927\u5c0f\uff0c\u5f80\u8fd4\u82b1\u8d39\u7684\u65f6\u95f4\u6253\u5370\u5230\u5c4f\u5e55\u4e0a\u3002\u5982\u4e0b\u56fe\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/usual1009.oss-cn-shanghai.aliyuncs.com\/img\/202511291927316.jpeg\" alt=\"img\"\/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>ICMP\u534f\u8bae\u5b9e\u73b0--traceroute\u547d\u4ee4<\/strong><\/h3>\n\n\n\n<p>traceroute\u547d\u4ee4\u662f\u4e00\u6b3e\u5145\u5206\u5229\u7528 ICMP <strong>\u5dee\u9519\u62a5\u6587<\/strong>\u7c7b\u578b\u7684\u5e94\u7528\uff0c\u5176\u4e3b\u8981\u7528\u4f5c\u8ffd\u8e2a\u8def\u7531\u4fe1\u606f\uff0c\u4e0b\u9762\u6211\u4eec\u6765\u9010\u4e2a\u67e5\u770b\u4e00\u4e0b\u5176\u5de5\u4f5c\u539f\u7406\u3002<\/p>\n\n\n\n<p>\u6211\u4eec\u901a\u8fc7\u6267\u884c traceroute 192.168.1.1\uff0c\u6765\u5206\u6790\u4e00\u4e0b\u4ed6\u7684\u539f\u7406\uff0c\u5b83\u7684\u539f\u7406\u5c31\u662f\u5229\u7528 IP \u5305\u7684 TTL \u4ece 1 \u5f00\u59cb\u6309\u7167\u987a\u5e8f\u9012\u589e\u7684\u540c\u65f6\u53d1\u9001 UDP \u5305\uff0c\u5f3a\u5236\u63a5\u6536 ICMP \u8d85\u65f6\u6d88\u606f\u7684\u65b9\u6cd5\u3002<\/p>\n\n\n\n<p>\u9996\u5148 traceroute \u4f1a\u5c06 IP \u5305\u7684 TTL \u8bbe\u7f6e \u4e3a 1\uff0c\u7136\u540e\u53d1\u9001 UDP \u5305\uff0c\u4ed6\u4f1a\u586b\u5165\u4e00\u4e2a\u7aef\u53e3\u53f7\u4f5c\u4e3a UDP \u76ee\u6807\u7aef\u53e3\u53f7\uff08\u9ed8\u8ba4\u662f\uff1a33434-33534\uff09\u3002\u5982\u4e0b\u56fe\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/usual1009.oss-cn-shanghai.aliyuncs.com\/img\/202511291927136.jpeg\" alt=\"img\"\/><\/figure>\n\n\n\n<p>\u5f53\u76ee\u7684\u4e3b\u673a\u6536\u5230 UDP \u5305\u540e\uff0c\u4f1a\u8fd4\u56de ICMP \u5dee\u9519\u62a5\u6587\u6d88\u606f\uff08\u7c7b\u578b 3\uff0c\u4ee3\u7801 3\uff09\u3002\u53c2\u7167\u4e0a\u9762\u7684\u8868\uff0c\u8be5\u9519\u62a5\u6587\u7c7b\u578b\u662f\u7aef\u53e3\u4e0d\u53ef\u8fbe\uff0c\u8bf4\u660e\u53d1\u9001\u65b9\u53d1\u51fa\u7684 UDP \u5305\u5230\u8fbe\u4e86\u76ee\u7684\u4e3b\u673a\u3002\u5982\u4e0b\u56fe\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/usual1009.oss-cn-shanghai.aliyuncs.com\/img\/202511291927199.jpeg\" alt=\"img\"\/><\/figure>\n\n\n\n<p>\u8fd9\u6837\u7684\u8fc7\u7a0b\uff0ctraceroute \u5c31\u53ef\u4ee5\u62ff\u5230\u4e86\u6240\u6709\u7684\u8def\u7531\u5668 IP\uff0c\u8fd9\u6837\u5b50\u5c31\u53ef\u4ee5\u770b\u5230\u4ece\u6e90\u4e3b\u673a\u5230\u76ee\u7684\u4e3b\u673a\u8fc7\u7a0b\u4e2d\u7684\u6240\u6709\u8def\u7531\u4fe1\u606f\u3002<\/p>\n\n\n\n<p>\u5f53\u7136\u5b9e\u9645\u60c5\u51b5\u6709\u7684\u8def\u7531\u5668\u7981\u7528 ICMP \uff0c\u90a3\u4e48\u4ed6\u5c31\u6839\u672c\u4e0d\u4f1a\u8fd4\u56de\u8fd9\u4e2a ICMP \u5dee\u9519\u62a5\u6587\uff0c\u6240\u4ee5\u662f\u770b\u4e0d\u5230\u4e2d\u95f4\u7ecf\u8fc7\u7684\u8def\u7531IP\u7684\u3002<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>Tips\uff1atraceroute \u5728\u7c7b Unix\/Linux \u7cfb\u7edf\u4e2d\u9ed8\u8ba4\u4f7f\u7528\u7684\u662f<a href=\"https:\/\/zhida.zhihu.com\/search?content_id=170268177&amp;content_type=Article&amp;match_order=1&amp;q=+UDP+%E5%8D%8F%E8%AE%AE&amp;zd_token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJ6aGlkYV9zZXJ2ZXIiLCJleHAiOjE3NjI4NTg2MzQsInEiOiIgVURQIOWNj-iuriIsInpoaWRhX3NvdXJjZSI6ImVudGl0eSIsImNvbnRlbnRfaWQiOjE3MDI2ODE3NywiY29udGVudF90eXBlIjoiQXJ0aWNsZSIsIm1hdGNoX29yZGVyIjoxLCJ6ZF90b2tlbiI6bnVsbH0.LSfqsfiQBFSeRjdqbJS3v-hKxBESkIjmCbJy29YRyBc&amp;zhida_source=entity\" target=\"_blank\"  rel=\"nofollow\" > UDP \u534f\u8bae<\/a>\uff0c\u4e5f\u53ef\u4ee5\u901a\u8fc7\u53c2\u6570\u4fee\u6539\u4e3a\u4f7f\u7528 ICMP \u534f\u8bae\uff1bWindows \u64cd\u4f5c\u7cfb\u7edf\u4e2d\u53ea\u4f7f\u7528 ICMP \u534f\u8bae\u3002<\/p>\n<\/blockquote>\n\n\n\n<p>\u8bf4\u4e86\u8fd9\u4e48\u591a\uff0c\u6211\u4eec\u8fd8\u662f\u76f4\u63a5\u6765\u770b\u4e00\u5f20\u56fe\u5427\uff0c\u57fa\u672c\u53ef\u4ee5\u63cf\u8ff0\u6e05\u695a traceroute \u7684\u6574\u4e2a\u8fc7\u7a0b\u3002\u5982\u4e0b\u56fe\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/usual1009.oss-cn-shanghai.aliyuncs.com\/img\/202511291927171.jpeg\" alt=\"img\"\/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">DDOS\u4e0b\u6709\u5e38\u89c1\u7684\u51e0\u79cd\u653b\u51fb<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">\u7f51\u7edc\u5c42\u653b\u51fb (Layer 3 Attacks)<\/h3>\n\n\n\n<p>\u8fd9\u7c7b\u653b\u51fb\u4e3b\u8981\u9488\u5bf9 OSI \u6a21\u578b\u4e2d\u7684<strong>\u7f51\u7edc\u5c42<\/strong>\uff0c\u65e8\u5728\u6d88\u8017\u76ee\u6807\u7f51\u7edc\u7684\u5e26\u5bbd\u8d44\u6e90\uff0c\u6216\u8017\u5c3d\u7f51\u7edc\u8bbe\u5907\uff08\u5982\u8def\u7531\u5668\u3001\u9632\u706b\u5899\uff09\u7684\u5904\u7406\u80fd\u529b\u3002\u653b\u51fb\u8005\u901a\u5e38\u53d1\u9001\u5927\u91cf\u7684\u5783\u573e\u6570\u636e\u5305\uff0c\u4f7f\u5f97\u5408\u6cd5\u6d41\u91cf\u65e0\u6cd5\u901a\u8fc7\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">1. ICMP Flood \u653b\u51fb (ICMP \u6d2a\u6c34\u653b\u51fb)<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u662f\u4ec0\u4e48\uff1a<\/strong> ICMP (Internet Control Message Protocol) \u662f\u4e00\u79cd\u7528\u4e8e\u5728 IP \u7f51\u7edc\u4e2d\u53d1\u9001\u63a7\u5236\u6d88\u606f\u7684\u534f\u8bae\uff0c\u6700\u5e38\u89c1\u7684\u5e94\u7528\u662f <code>ping<\/code> \u547d\u4ee4\u3002ICMP Flood \u653b\u51fb\u5c31\u662f\u5229\u7528\u5927\u91cf\u7684 ICMP \u6570\u636e\u5305\uff08\u901a\u5e38\u662f Echo Request\uff0c\u5373 ping \u8bf7\u6c42\uff09\u6765\u6df9\u6ca1\u76ee\u6807\u3002<\/li>\n\n\n\n<li>\u5982\u4f55\u5de5\u4f5c\uff1a\n<ol class=\"wp-block-list\">\n<li>\u653b\u51fb\u8005\u4f7f\u7528\u591a\u4e2a\u6e90\uff08\u50f5\u5c38\u4e3b\u673a\uff09\u5411\u76ee\u6807\u670d\u52a1\u5668\u53d1\u9001\u6d77\u91cf\u7684 ICMP Echo Request \u6570\u636e\u5305\u3002\uff08\u591a\u4e2a\u5080\u5121\u673a\u5411\u670d\u52a1\u5668\u53d1\u8d77ping\u6307\u4ee4\uff09<\/li>\n\n\n\n<li>\u76ee\u6807\u670d\u52a1\u5668\u5728\u6536\u5230\u6bcf\u4e2a Echo Request \u540e\uff0c\u90fd\u9700\u8981\u751f\u6210\u5e76\u53d1\u9001\u4e00\u4e2a ICMP Echo Reply \u6570\u636e\u5305\u4f5c\u4e3a\u54cd\u5e94\u3002<\/li>\n\n\n\n<li>\u8fd9\u4e2a\u8fc7\u7a0b\u4f1a\u6d88\u8017\u76ee\u6807\u670d\u52a1\u5668\u7684 <strong>CPU \u8d44\u6e90<\/strong>\uff08\u7528\u4e8e\u5904\u7406\u4f20\u5165\u7684 ICMP \u8bf7\u6c42\u548c\u751f\u6210\u4f20\u51fa\u7684\u54cd\u5e94\uff09\u548c<strong>\u7f51\u7edc\u5e26\u5bbd<\/strong>\uff08\u7528\u4e8e\u53d1\u9001\u548c\u63a5\u6536\u5927\u91cf\u7684 ICMP \u5305\uff09\u3002<\/li>\n<\/ol>\n<\/li>\n\n\n\n<li>\u76ee\u6807\/\u5f71\u54cd\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u8017\u5c3d\u76ee\u6807\u4e3b\u673a\u7684 CPU \u8d44\u6e90\uff1a<\/strong> \u670d\u52a1\u5668\u9700\u8981\u4e0d\u65ad\u5904\u7406\u8fd9\u4e9b\u8bf7\u6c42\u548c\u54cd\u5e94\u3002<\/li>\n\n\n\n<li><strong>\u8017\u5c3d\u76ee\u6807\u7f51\u7edc\u7684\u5e26\u5bbd\uff1a<\/strong> \u5927\u91cf\u7684 ICMP \u5305\u4f1a\u5360\u636e\u7f51\u7edc\u94fe\u8def\uff0c\u5bfc\u81f4\u5408\u6cd5\u6d41\u91cf\u65e0\u6cd5\u901a\u8fc7\u3002<\/li>\n\n\n\n<li><strong>\u5bfc\u81f4\u7cfb\u7edf\u54cd\u5e94\u7f13\u6162\u6216\u5b8c\u5168\u65e0\u54cd\u5e94\u3002<\/strong><\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>CTF \u76f8\u5173\uff1a<\/strong> \u8bc6\u522b\u5927\u91cf\u7684 ICMP \u6d41\u91cf\u53ef\u80fd\u8868\u660e\u6b63\u5728\u906d\u53d7\u6b64\u7c7b\u653b\u51fb\u3002\u9632\u5fa1\u901a\u5e38\u6d89\u53ca\u5728\u9632\u706b\u5899\u4e0a\u9650\u5236 ICMP \u6d41\u91cf\u6216\u901f\u7387\u3002<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">2. ARP Flood \u653b\u51fb (ARP \u6d2a\u6c34\u653b\u51fb)<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u662f\u4ec0\u4e48\uff1a<\/strong> ARP (Address Resolution Protocol) \u662f\u4e00\u79cd\u7528\u4e8e\u5c06<strong>IP \u5730\u5740\u89e3\u6790\u4e3a MAC \u5730\u5740<\/strong>\u7684\u534f\u8bae\uff0c\u5de5\u4f5c\u5728\u6570\u636e\u94fe\u8def\u5c42\uff08L2\uff09\uff0c\u4f46\u5176\u5f71\u54cd\u4f1a\u6ce2\u53ca\u5230\u7f51\u7edc\u5c42\u8bbe\u5907\u7684\u6027\u80fd\u3002ARP Flood \u653b\u51fb\u901a\u8fc7\u53d1\u9001\u5927\u91cf\u7684 ARP \u8bf7\u6c42\u6216\u54cd\u5e94\u6765\u5e72\u6270\u5c40\u57df\u7f51\u5185\u7684\u6b63\u5e38\u901a\u4fe1\u3002<\/li>\n\n\n\n<li>\u5982\u4f55\u5de5\u4f5c\uff1a\n<ol class=\"wp-block-list\">\n<li><strong>\u9488\u5bf9\u4ea4\u6362\u673a\uff1a<\/strong> \u653b\u51fb\u8005\u5411\u5c40\u57df\u7f51\u5185\u7684\u4ea4\u6362\u673a\u53d1\u9001\u5927\u91cf\u4f2a\u9020\u7684 ARP \u8bf7\u6c42\u6216\u54cd\u5e94\uff0c\u8fd9\u4e9b\u8bf7\u6c42\u6216\u54cd\u5e94\u5305\u542b\u5927\u91cf\u7684\u968f\u673a MAC \u5730\u5740\u548c IP \u5730\u5740\u5bf9\u3002<\/li>\n\n\n\n<li>\u4ea4\u6362\u673a\u9700\u8981\u7ef4\u62a4\u4e00\u4e2a <strong>MAC \u5730\u5740\u8868 (CAM \u8868)<\/strong>\uff0c\u7528\u4e8e\u8bb0\u5f55\u54ea\u4e2a MAC \u5730\u5740\u5bf9\u5e94\u54ea\u4e2a\u7aef\u53e3\u3002\u5f53 CAM \u8868\u88ab\u5927\u91cf\u7684\u4f2a\u9020 ARP \u6761\u76ee\u586b\u6ee1\u65f6\uff0c\u5c31\u4f1a\u53d1\u751f <strong>CAM \u8868\u6ea2\u51fa<\/strong>\u3002<\/li>\n\n\n\n<li>\u4e00\u65e6 CAM \u8868\u6ea2\u51fa\uff0c\u4ea4\u6362\u673a\u53ef\u80fd\u65e0\u6cd5\u518d\u5b66\u4e60\u65b0\u7684 MAC \u5730\u5740\uff0c\u6216\u8005\u4e3a\u4e86\u5904\u7406\u65b0\u7684 ARP \u6761\u76ee\u800c\u4e0d\u65ad\u5237\u65b0\u65e7\u6761\u76ee\u3002\u5728\u67d0\u4e9b\u60c5\u51b5\u4e0b\uff0c\u4ea4\u6362\u673a\u53ef\u80fd\u4f1a\u9000\u5316\u5230\u50cf\u96c6\u7ebf\u5668 (Hub) \u4e00\u6837\uff0c\u5c06\u6240\u6709\u6d41\u91cf\u5e7f\u64ad\u5230\u6240\u6709\u7aef\u53e3\u3002<\/li>\n<\/ol>\n<\/li>\n\n\n\n<li>\u76ee\u6807\/\u5f71\u54cd\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u5360\u7528\u7f51\u7edc\u8d44\u6e90\uff0c\u5bfc\u81f4\u7f51\u7edc\u62e5\u5835\uff1a<\/strong> \u65e0\u8bba\u662f CAM \u8868\u6ea2\u51fa\u5bfc\u81f4\u7684\u5e7f\u64ad\uff0c\u8fd8\u662f\u5904\u7406\u5927\u91cf ARP \u5305\u672c\u8eab\uff0c\u90fd\u4f1a\u663e\u8457\u589e\u52a0\u5c40\u57df\u7f51\u7684\u6d41\u91cf\u8d1f\u62c5\u3002<\/li>\n\n\n\n<li><strong>\u5bfc\u81f4\u5408\u6cd5 ARP \u6761\u76ee\u88ab\u8986\u76d6\u6216\u5237\u65b0\uff1a<\/strong> \u4f7f\u5f97\u5408\u6cd5\u8bbe\u5907\u65e0\u6cd5\u6b63\u786e\u89e3\u6790 IP-MAC \u6620\u5c04\uff0c\u4ece\u800c\u65e0\u6cd5\u901a\u4fe1\u3002<\/li>\n\n\n\n<li><strong>\u4e3a\u5176\u4ed6\u653b\u51fb\uff08\u5982 ARP \u6b3a\u9a97\u3001\u4e2d\u95f4\u4eba\u653b\u51fb\uff09\u94fa\u5e73\u9053\u8def\u3002<\/strong><\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>CTF \u76f8\u5173\uff1a<\/strong> ARP Flood \u653b\u51fb\u901a\u5e38\u53d1\u751f\u5728\u5c40\u57df\u7f51\u5185\u90e8\uff0c\u662f\u5185\u7f51\u6e17\u900f\u4e2d\u5e38\u89c1\u7684\u4fa6\u5bdf\u548c\u5e72\u6270\u624b\u6bb5\u3002\u9632\u5fa1\u63aa\u65bd\u5305\u62ec\u7aef\u53e3\u5b89\u5168 (Port Security) \u548c ARP \u7ed1\u5b9a\u3002<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">3. IP \u5206\u7247\u653b\u51fb (IP Fragmentation Attack)<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u662f\u4ec0\u4e48\uff1a<\/strong> IP \u5206\u7247\u662f IP \u534f\u8bae\u7684\u4e00\u9879\u6b63\u5e38\u529f\u80fd\uff0c\u5f53\u4e00\u4e2a IP \u6570\u636e\u5305\u7684\u5927\u5c0f\u8d85\u8fc7\u4e86\u7f51\u7edc\u94fe\u8def\u7684 MTU (Maximum Transmission Unit) \u65f6\uff0c\u5b83\u4f1a\u88ab\u5206\u6210\u591a\u4e2a\u66f4\u5c0f\u7684\u7247\u6bb5\u8fdb\u884c\u4f20\u8f93\uff0c\u7136\u540e\u5728\u76ee\u6807\u7aef\u91cd\u65b0\u7ec4\u88c5\u3002IP \u5206\u7247\u653b\u51fb\u5c31\u662f\u5229\u7528\u8fd9\u4e2a\u673a\u5236\uff0c\u53d1\u9001\u6076\u610f\u7684\u3001\u7578\u5f62\u7684\u6216\u5927\u91cf\u7684 IP \u5206\u7247\u6570\u636e\u5305\u3002<\/li>\n\n\n\n<li>\u5982\u4f55\u5de5\u4f5c\uff1a\n<ol class=\"wp-block-list\">\n<li>\u653b\u51fb\u8005\u53d1\u9001\u5927\u91cf\u7684 IP \u5206\u7247\u6570\u636e\u5305\u5230\u76ee\u6807\u3002\u8fd9\u4e9b\u5206\u7247\u53ef\u80fd\u88ab\u8bbe\u8ba1\u6210\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u91cd\u53e0\u5206\u7247\uff1a<\/strong> \u67d0\u4e9b\u5206\u7247\u7684\u504f\u79fb\u91cf\u548c\u957f\u5ea6\u5bfc\u81f4\u5b83\u4eec\u7684\u6570\u636e\u533a\u57df\u4e0e\u5176\u4ed6\u5206\u7247\u91cd\u53e0\u3002<\/li>\n\n\n\n<li><strong>\u5fae\u5c0f\u5206\u7247\uff1a<\/strong> \u5206\u7247\u975e\u5e38\u5c0f\uff0c\u5bfc\u81f4\u9700\u8981\u5927\u91cf\u5206\u7247\u624d\u80fd\u7ec4\u6210\u4e00\u4e2a\u5b8c\u6574\u7684\u6570\u636e\u5305\u3002<\/li>\n\n\n\n<li><strong>\u4e0d\u5b8c\u6574\u5206\u7247\uff1a<\/strong> \u6545\u610f\u4e0d\u53d1\u9001\u67d0\u4e2a\u5173\u952e\u5206\u7247\uff0c\u5bfc\u81f4\u76ee\u6807\u6c38\u8fdc\u65e0\u6cd5\u5b8c\u6210\u91cd\u7ec4\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>\u76ee\u6807\u670d\u52a1\u5668\u7684 IP \u534f\u8bae\u6808\u9700\u8981\u4e3a\u6bcf\u4e2a\u4f20\u5165\u7684\u5206\u7247\u5206\u914d\u5185\u5b58\u7f13\u51b2\u533a\uff0c\u5e76\u5c1d\u8bd5\u5c06\u5b83\u4eec\u91cd\u65b0\u7ec4\u88c5\u6210\u539f\u59cb\u6570\u636e\u5305\u3002<\/li>\n<\/ol>\n<\/li>\n\n\n\n<li>\u76ee\u6807\/\u5f71\u54cd\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u8017\u5c3d\u76ee\u6807\u4e3b\u673a\u7684 CPU \u8d44\u6e90\uff1a<\/strong> \u91cd\u65b0\u7ec4\u88c5 IP \u5206\u7247\u662f\u4e00\u4e2a\u8ba1\u7b97\u5bc6\u96c6\u578b\u64cd\u4f5c\uff0c\u7279\u522b\u662f\u5f53\u5206\u7247\u6570\u91cf\u5de8\u5927\u6216\u683c\u5f0f\u7578\u5f62\u65f6\u3002<\/li>\n\n\n\n<li><strong>\u8017\u5c3d\u76ee\u6807\u4e3b\u673a\u7684\u5185\u5b58\u8d44\u6e90\uff1a<\/strong> \u670d\u52a1\u5668\u9700\u8981\u4e3a\u6bcf\u4e2a\u5206\u7247\u5206\u914d\u7f13\u51b2\u533a\uff0c\u6076\u610f\u5206\u7247\u53ef\u4ee5\u5feb\u901f\u586b\u6ee1\u8fd9\u4e9b\u7f13\u51b2\u533a\u3002<\/li>\n\n\n\n<li><strong>\u5bfc\u81f4\u7cfb\u7edf\u4e0d\u7a33\u5b9a\u3001\u5d29\u6e83\u6216\u65e0\u6cd5\u5904\u7406\u5408\u6cd5\u6d41\u91cf\u3002<\/strong><\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>CTF \u76f8\u5173\uff1a<\/strong> \u8fd9\u79cd\u653b\u51fb\u5728\u73b0\u4ee3\u7cfb\u7edf\u4e2d\u9632\u5fa1\u8f83\u597d\uff0c\u4f46\u5728\u4e00\u4e9b\u8001\u65e7\u6216\u914d\u7f6e\u4e0d\u5f53\u7684\u7cfb\u7edf\u4e0a\u4ecd\u53ef\u80fd\u6709\u6548\u3002\u5b83\u4e3b\u8981\u901a\u8fc7\u6d88\u8017\u7cfb\u7edf\u8d44\u6e90\u6765\u8fbe\u5230\u62d2\u7edd\u670d\u52a1\u7684\u76ee\u7684\u3002<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">\u4f20\u8f93\u5c42\u653b\u51fb (Layer 4 Attacks)<\/h3>\n\n\n\n<p>\u8fd9\u7c7b\u653b\u51fb\u9488\u5bf9 OSI \u6a21\u578b\u4e2d\u7684<strong>\u4f20\u8f93\u5c42<\/strong>\uff0c\u65e8\u5728\u4f7f\u76ee\u6807\u670d\u52a1\u5668\u6216\u7f51\u7edc\u8bbe\u5907\uff08\u5982\u9632\u706b\u5899\u3001\u8d1f\u8f7d\u5747\u8861\u5668\uff09\u7684\u8fde\u63a5\u72b6\u6001\u8868\u8fc7\u8f7d\uff0c\u4ece\u800c\u963b\u6b62\u5408\u6cd5\u7528\u6237\u5efa\u7acb\u65b0\u7684\u8fde\u63a5\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">1. SYN Flood \u653b\u51fb<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u662f\u4ec0\u4e48\uff1a<\/strong> SYN Flood \u662f\u4e00\u79cd\u7ecf\u5178\u7684 DDoS \u653b\u51fb\uff0c\u5b83\u5229\u7528 TCP \u4e09\u6b21\u63e1\u624b\uff08SYN-SYN\/ACK-ACK\uff09\u7684\u673a\u5236\u6765\u8017\u5c3d\u670d\u52a1\u5668\u7684\u8fde\u63a5\u8d44\u6e90\u3002<\/li>\n\n\n\n<li>\u5982\u4f55\u5de5\u4f5c\uff1a\n<ol class=\"wp-block-list\">\n<li>\u653b\u51fb\u8005\uff08\u901a\u5e38\u662f\u50f5\u5c38\u4e3b\u673a\uff09\u5411\u76ee\u6807\u670d\u52a1\u5668\u53d1\u9001\u5927\u91cf\u7684 TCP SYN (\u540c\u6b65) \u8bf7\u6c42\u5305\uff0c\u8bf7\u6c42\u5efa\u7acb\u8fde\u63a5\u3002<\/li>\n\n\n\n<li>\u76ee\u6807\u670d\u52a1\u5668\u6536\u5230 SYN \u5305\u540e\uff0c\u4f1a\u56de\u590d\u4e00\u4e2a SYN\/ACK (\u540c\u6b65\/\u786e\u8ba4) \u5305\uff0c\u5e76\u4e3a\u8fd9\u4e2a\u534a\u5f00\u8fde\u63a5\u5728\u5185\u5b58\u4e2d\u5206\u914d\u8d44\u6e90\uff08\u5982\u8fde\u63a5\u72b6\u6001\u3001\u5b9a\u65f6\u5668\u7b49\uff09\uff0c\u7b49\u5f85\u5ba2\u6237\u7aef\u53d1\u9001\u6700\u7ec8\u7684 ACK \u5305\u3002<\/li>\n\n\n\n<li>\u653b\u51fb\u8005<strong>\u6545\u610f\u4e0d\u53d1\u9001\u6700\u7ec8\u7684 ACK \u5305<\/strong>\uff0c\u6216\u8005\u53d1\u9001\u7684\u6e90 IP \u5730\u5740\u662f\u4f2a\u9020\u7684\uff0c\u5bfc\u81f4\u670d\u52a1\u5668\u65e0\u6cd5\u5c06 SYN\/ACK \u53d1\u9001\u7ed9\u5b9e\u9645\u7684\u653b\u51fb\u8005\u3002<\/li>\n\n\n\n<li>\u670d\u52a1\u5668\u4f1a\u6301\u7eed\u7b49\u5f85\u8fd9\u4e9b\u534a\u5f00\u8fde\u63a5\u7684 ACK \u5305\uff0c\u76f4\u5230\u8d85\u65f6\u3002\u5728\u6b64\u671f\u95f4\uff0c\u5927\u91cf\u7684\u534a\u5f00\u8fde\u63a5\u4f1a\u8fc5\u901f\u586b\u6ee1\u670d\u52a1\u5668\u7684\u8fde\u63a5\u961f\u5217\u3002<\/li>\n<\/ol>\n<\/li>\n\n\n\n<li>\u76ee\u6807\/\u5f71\u54cd\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u8017\u5c3d\u670d\u52a1\u5668\u7684\u8fde\u63a5\u8d44\u6e90\uff1a<\/strong> \u5f53\u8fde\u63a5\u961f\u5217\u88ab\u586b\u6ee1\u540e\uff0c\u670d\u52a1\u5668\u65e0\u6cd5\u518d\u63a5\u53d7\u65b0\u7684\u5408\u6cd5 TCP \u8fde\u63a5\u8bf7\u6c42\u3002<\/li>\n\n\n\n<li><strong>\u5bfc\u81f4\u5408\u6cd5\u7528\u6237\u65e0\u6cd5\u8bbf\u95ee\u670d\u52a1\uff1a<\/strong> \u5373\u4f7f\u670d\u52a1\u5668\u672c\u8eab\u8d44\u6e90\u5145\u8db3\uff0c\u4f46\u7531\u4e8e\u65e0\u6cd5\u5efa\u7acb\u65b0\u7684\u8fde\u63a5\uff0c\u670d\u52a1\u4ecd\u7136\u4e0d\u53ef\u7528\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>CTF \u76f8\u5173\uff1a<\/strong> SYN Flood \u662f\u975e\u5e38\u5e38\u89c1\u7684 DDoS \u653b\u51fb\u7c7b\u578b\uff0c\u7406\u89e3 TCP \u4e09\u6b21\u63e1\u624b\u662f\u7406\u89e3\u6b64\u653b\u51fb\u7684\u57fa\u7840\u3002\u9632\u5fa1\u901a\u5e38\u6d89\u53ca SYN Cookie\u3001\u964d\u4f4e\u534a\u5f00\u8fde\u63a5\u8d85\u65f6\u65f6\u95f4\u3001\u589e\u52a0\u8fde\u63a5\u961f\u5217\u5927\u5c0f\u7b49\u3002<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">2. ACK Flood \u653b\u51fb<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u662f\u4ec0\u4e48\uff1a<\/strong> ACK Flood \u653b\u51fb\u662f\u6307\u653b\u51fb\u8005\u5411\u76ee\u6807\u53d1\u9001\u5927\u91cf\u7684 TCP ACK (\u786e\u8ba4) \u6570\u636e\u5305\u3002<\/li>\n\n\n\n<li>\u5982\u4f55\u5de5\u4f5c\uff1a\n<ol class=\"wp-block-list\">\n<li>\u653b\u51fb\u8005\u53d1\u9001\u6d77\u91cf\u7684 ACK \u5305\u5230\u76ee\u6807\u670d\u52a1\u5668\uff0c\u8fd9\u4e9b ACK \u5305\u901a\u5e38\u5177\u6709\u968f\u673a\u7684\u6e90 IP \u5730\u5740\u3001\u7aef\u53e3\u53f7\u548c\u5e8f\u5217\u53f7\u3002<\/li>\n\n\n\n<li>\u76ee\u6807\u670d\u52a1\u5668\u6536\u5230 ACK \u5305\u540e\uff0c\u4f1a\u5c1d\u8bd5\u5c06\u5176\u4e0e\u73b0\u6709\u7684 TCP \u8fde\u63a5\u8fdb\u884c\u5339\u914d\u3002\u7531\u4e8e\u8fd9\u4e9b ACK \u5305\u901a\u5e38\u4e0d\u5bf9\u5e94\u4efb\u4f55\u6d3b\u52a8\u7684\u8fde\u63a5\uff0c\u670d\u52a1\u5668\u4f1a\u82b1\u8d39\u5927\u91cf\u7684 CPU \u8d44\u6e90\u53bb\u67e5\u627e\u5339\u914d\u9879\uff0c\u4f46\u6700\u7ec8\u4f1a\u53d1\u73b0\u6ca1\u6709\u5339\u914d\u9879\u5e76\u4e22\u5f03\u5b83\u4eec\u3002<\/li>\n\n\n\n<li>\u5982\u679c ACK \u5305\u7684\u8f7d\u8377\uff08payload\uff09\u975e\u5e38\u5927\uff0c\u5b83\u8fd8\u4f1a\u6d88\u8017\u5927\u91cf\u7684\u7f51\u7edc\u5e26\u5bbd\u3002<\/li>\n<\/ol>\n<\/li>\n\n\n\n<li>\u76ee\u6807\/\u5f71\u54cd\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u8017\u5c3d\u76ee\u6807\u4e3b\u673a\u7684 CPU \u8d44\u6e90\uff1a<\/strong> \u670d\u52a1\u5668\u5904\u7406\u6bcf\u4e2a ACK \u5305\u90fd\u9700\u8981\u8fdb\u884c\u67e5\u627e\u548c\u9a8c\u8bc1\u64cd\u4f5c\u3002<\/li>\n\n\n\n<li><strong>\u8017\u5c3d\u7f51\u7edc\u5e26\u5bbd\uff1a<\/strong> \u5982\u679c ACK \u5305\u5e26\u6709\u8d85\u5927\u8f7d\u8377\uff0c\u4f1a\u663e\u8457\u589e\u52a0\u7f51\u7edc\u6d41\u91cf\uff0c\u5bfc\u81f4\u94fe\u8def\u62e5\u585e\u3002<\/li>\n\n\n\n<li><strong>\u53ef\u80fd\u7ed5\u8fc7\u67d0\u4e9b\u72b6\u6001\u9632\u706b\u5899\uff1a<\/strong> \u6709\u4e9b\u9632\u706b\u5899\u53ef\u80fd\u53ea\u68c0\u67e5 SYN \u5305\u6765\u5efa\u7acb\u8fde\u63a5\u72b6\u6001\uff0c\u800c\u5bf9 ACK \u5305\u7684\u68c0\u67e5\u76f8\u5bf9\u5bbd\u677e\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>CTF \u76f8\u5173\uff1a<\/strong> \u8fd9\u79cd\u653b\u51fb\u4e3b\u8981\u901a\u8fc7\u6d88\u8017 CPU \u548c\u5e26\u5bbd\u6765\u8fbe\u5230\u62d2\u7edd\u670d\u52a1\u7684\u76ee\u7684\u3002\u5728\u5206\u6790\u6d41\u91cf\u65f6\uff0c\u5982\u679c\u53d1\u73b0\u5927\u91cf\u4e0d\u5e26 SYN \u6807\u5fd7\u7684 ACK \u5305\uff0c\u53ef\u80fd\u5c31\u662f ACK Flood\u3002<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">3. UDP Flood \u653b\u51fb (UDP \u6d2a\u6c34\u653b\u51fb)<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u662f\u4ec0\u4e48\uff1a<\/strong> UDP (User Datagram Protocol) \u662f\u4e00\u79cd\u65e0\u8fde\u63a5\u7684\u4f20\u8f93\u5c42\u534f\u8bae\u3002UDP Flood \u653b\u51fb\u5c31\u662f\u5411\u76ee\u6807\u53d1\u9001\u5927\u91cf\u7684 UDP \u6570\u636e\u5305\u3002<\/li>\n\n\n\n<li>\u5982\u4f55\u5de5\u4f5c\uff1a\n<ol class=\"wp-block-list\">\n<li>\u653b\u51fb\u8005\uff08\u901a\u5e38\u662f\u50f5\u5c38\u4e3b\u673a\uff09\u5411\u76ee\u6807\u670d\u52a1\u5668\u53d1\u9001\u5927\u91cf\u7684 UDP \u6570\u636e\u5305\uff0c\u8fd9\u4e9b\u6570\u636e\u5305\u53ef\u4ee5\u53d1\u9001\u5230\u968f\u673a\u7aef\u53e3\uff0c\u4e5f\u53ef\u4ee5\u53d1\u9001\u5230\u7279\u5b9a\u7684\u5f00\u653e\u7aef\u53e3\uff08\u5982 DNS\u3001NTP\u3001SNMP \u670d\u52a1\u7aef\u53e3\uff09\u3002<\/li>\n\n\n\n<li>\u5982\u679c UDP \u5305\u53d1\u9001\u5230\u76ee\u6807\u670d\u52a1\u5668\u4e0a\u4e00\u4e2a<strong>\u6ca1\u6709\u5e94\u7528\u7a0b\u5e8f\u76d1\u542c\u7684\u7aef\u53e3<\/strong>\uff0c\u76ee\u6807\u670d\u52a1\u5668\u4f1a\u751f\u6210\u4e00\u4e2a ICMP Destination Unreachable (Port Unreachable) \u6d88\u606f\u4f5c\u4e3a\u54cd\u5e94\uff0c\u5e76\u5c06\u5176\u53d1\u9001\u56de\u6e90 IP \u5730\u5740\u3002<\/li>\n\n\n\n<li>\u5982\u679c UDP \u5305\u53d1\u9001\u5230<strong>\u6709\u5e94\u7528\u7a0b\u5e8f\u76d1\u542c\u7684\u7aef\u53e3<\/strong>\uff0c\u8be5\u5e94\u7528\u7a0b\u5e8f\u9700\u8981\u5904\u7406\u8fd9\u4e9b\u65e0\u6548\u7684\u8bf7\u6c42\uff0c\u6d88\u8017\u5176\u8d44\u6e90\u3002<\/li>\n<\/ol>\n<\/li>\n\n\n\n<li>\u76ee\u6807\/\u5f71\u54cd\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u8017\u5c3d\u76ee\u6807\u7f51\u7edc\u7684\u5e26\u5bbd\uff1a<\/strong> \u5927\u91cf\u7684 UDP \u5305\u672c\u8eab\u5c31\u4f1a\u5360\u7528\u7f51\u7edc\u94fe\u8def\u3002<\/li>\n\n\n\n<li><strong>\u8017\u5c3d\u76ee\u6807\u4e3b\u673a\u7684 CPU \u8d44\u6e90\uff1a<\/strong> \u5904\u7406\u4f20\u5165\u7684 UDP \u5305\u548c\u751f\u6210 ICMP \u54cd\u5e94\u90fd\u9700\u8981 CPU\u3002<\/li>\n\n\n\n<li><strong>\u5145\u585e\u76ee\u6807\u4e3b\u673a\u7684\u7aef\u53e3\uff0c\u5bfc\u81f4\u7cfb\u7edf\u5931\u53bb\u54cd\u5e94\uff1a<\/strong> \u65e0\u8bba\u662f\u7aef\u53e3\u54cd\u5e94\u8fd8\u662f ICMP \u54cd\u5e94\uff0c\u90fd\u4f1a\u6d88\u8017\u7cfb\u7edf\u8d44\u6e90\uff0c\u6700\u7ec8\u5bfc\u81f4\u5408\u6cd5\u670d\u52a1\u65e0\u6cd5\u6b63\u5e38\u5de5\u4f5c\u3002<\/li>\n\n\n\n<li><strong>\u5e38\u7528\u4e8e\u653e\u5927\u653b\u51fb\uff1a<\/strong> UDP \u534f\u8bae\u7684\u65e0\u8fde\u63a5\u7279\u6027\u4f7f\u5176\u6210\u4e3a DNS\u3001NTP\u3001Memcached \u7b49\u653e\u5927\u653b\u51fb\u7684\u7406\u60f3\u8f7d\u4f53\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>CTF \u76f8\u5173\uff1a<\/strong> UDP Flood \u653b\u51fb\u7684\u6d41\u91cf\u7279\u5f81\u660e\u663e\uff0c\u6613\u4e8e\u68c0\u6d4b\u3002\u9632\u5fa1\u901a\u5e38\u6d89\u53ca\u5728\u9632\u706b\u5899\u4e0a\u9650\u5236 UDP \u6d41\u91cf\u6216\u8fdb\u884c\u6d41\u91cf\u6e05\u6d17\u3002<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">\u5e94\u7528\u5c42\u653b\u51fb (Layer 7 Attacks)<\/h3>\n\n\n\n<p>\u8fd9\u7c7b\u653b\u51fb\u9488\u5bf9 OSI \u6a21\u578b\u4e2d\u7684<strong>\u5e94\u7528\u5c42<\/strong>\uff0c\u65e8\u5728\u901a\u8fc7\u6a21\u62df\u5408\u6cd5\u7528\u6237\u8bf7\u6c42\u6765\u6d88\u8017\u5e94\u7528\u7a0b\u5e8f\u7684\u8d44\u6e90\uff08\u5982 CPU\u3001\u5185\u5b58\u3001\u6570\u636e\u5e93\u8fde\u63a5\u3001Web \u670d\u52a1\u5668\u8fdb\u7a0b\uff09\uff0c\u4ece\u800c\u8ba9\u771f\u5b9e\u7528\u6237\u65e0\u6cd5\u6b63\u5e38\u4f7f\u7528\u5e94\u7528\u7a0b\u5e8f\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">1. DNS Flood \u653b\u51fb (DNS \u6d2a\u6c34\u653b\u51fb)<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u662f\u4ec0\u4e48\uff1a<\/strong> DNS Flood \u653b\u51fb\u662f\u6307\u653b\u51fb\u8005\u5411\u76ee\u6807 DNS \u670d\u52a1\u5668\u53d1\u9001\u5927\u91cf\u7684 DNS \u67e5\u8be2\u8bf7\u6c42\uff0c\u76ee\u7684\u662f\u4f7f\u5176\u8fc7\u8f7d\uff0c\u65e0\u6cd5\u54cd\u5e94\u5408\u6cd5\u7684 DNS \u89e3\u6790\u8bf7\u6c42\u3002<\/li>\n\n\n\n<li>\u5982\u4f55\u5de5\u4f5c\uff1a\n<ol class=\"wp-block-list\">\n<li>\u653b\u51fb\u8005\uff08\u901a\u5e38\u662f\u50f5\u5c38\u4e3b\u673a\uff09\u5411\u76ee\u6807 DNS \u670d\u52a1\u5668\u53d1\u9001\u5927\u91cf\u7684 DNS \u67e5\u8be2\u8bf7\u6c42\u3002\u8fd9\u4e9b\u8bf7\u6c42\u53ef\u4ee5\u662f\u9488\u5bf9\u4e0d\u5b58\u5728\u7684\u57df\u540d\u3001\u968f\u673a\u5b50\u57df\u540d\uff0c\u6216\u8005\u9488\u5bf9\u76ee\u6807 DNS \u670d\u52a1\u5668\u672c\u8eab\u8d1f\u8d23\u89e3\u6790\u7684\u57df\u540d\u3002<\/li>\n\n\n\n<li>\u76ee\u6807 DNS \u670d\u52a1\u5668\u9700\u8981\u5904\u7406\u6bcf\u4e00\u4e2a\u67e5\u8be2\u8bf7\u6c42\uff0c\u8fdb\u884c\u67e5\u627e\u3001\u9012\u5f52\u67e5\u8be2\u6216\u54cd\u5e94\u3002<\/li>\n<\/ol>\n<\/li>\n\n\n\n<li>\u76ee\u6807\/\u5f71\u54cd\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u7834\u574f DNS \u89e3\u6790\uff0c\u5bfc\u81f4\u4e1a\u52a1\u4e2d\u65ad\uff1a<\/strong> \u5f53 DNS \u670d\u52a1\u5668\u8fc7\u8f7d\u65f6\uff0c\u5b83\u5c06\u65e0\u6cd5\u4e3a\u5408\u6cd5\u7528\u6237\u89e3\u6790\u57df\u540d\u3002\u8fd9\u610f\u5473\u7740\u7528\u6237\u65e0\u6cd5\u901a\u8fc7\u57df\u540d\u8bbf\u95ee\u7f51\u7ad9\u3001\u90ae\u4ef6\u670d\u52a1\u6216\u5176\u4ed6\u4f9d\u8d56 DNS \u7684\u5e94\u7528\u7a0b\u5e8f\u3002<\/li>\n\n\n\n<li><strong>\u8017\u5c3d DNS \u670d\u52a1\u5668\u7684 CPU \u548c\u5185\u5b58\u8d44\u6e90\u3002<\/strong><\/li>\n\n\n\n<li><strong>\u589e\u52a0 DNS \u670d\u52a1\u5668\u7684\u4e0a\u6e38\u5e26\u5bbd\u6d88\u8017\u3002<\/strong><\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>CTF \u76f8\u5173\uff1a<\/strong> DNS \u662f\u4e92\u8054\u7f51\u7684\u57fa\u7840\u8bbe\u65bd\uff0c\u653b\u51fb DNS \u670d\u52a1\u5668\u7684\u5371\u5bb3\u5de8\u5927\u3002\u5728 CTF \u4e2d\uff0c\u5982\u679c\u76ee\u6807\u670d\u52a1\u65e0\u6cd5\u8bbf\u95ee\uff0c\u68c0\u67e5 DNS \u89e3\u6790\u662f\u5426\u6b63\u5e38\u662f\u91cd\u8981\u4e00\u6b65\u3002\u8fd9\u4e0e DNS <em>\u653e\u5927<\/em>\u653b\u51fb\u4e0d\u540c\uff0cDNS Flood \u662f\u76f4\u63a5\u653b\u51fb DNS \u670d\u52a1\u5668\u672c\u8eab\u3002<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">2. HTTP Flood \u653b\u51fb (HTTP \u6d2a\u6c34\u653b\u51fb)<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u662f\u4ec0\u4e48\uff1a<\/strong> HTTP Flood \u653b\u51fb\u662f\u6307\u653b\u51fb\u8005\u5411\u76ee\u6807 Web \u670d\u52a1\u5668\u53d1\u9001\u5927\u91cf\u7684 HTTP GET \u6216 POST \u8bf7\u6c42\uff0c\u76ee\u7684\u662f\u8017\u5c3d Web \u670d\u52a1\u5668\u7684\u5e94\u7528\u7a0b\u5e8f\u8d44\u6e90\u3002<\/li>\n\n\n\n<li>\u5982\u4f55\u5de5\u4f5c\uff1a\n<ol class=\"wp-block-list\">\n<li>\u653b\u51fb\u8005\uff08\u901a\u5e38\u662f\u50f5\u5c38\u4e3b\u673a\uff09\u5411\u76ee\u6807 Web \u670d\u52a1\u5668\u53d1\u9001\u5927\u91cf\u7684 HTTP \u8bf7\u6c42\u3002\u8fd9\u4e9b\u8bf7\u6c42\u53ef\u4ee5\u662f\u9488\u5bf9\u4e3b\u9875\u3001\u56fe\u7247\u3001CSS\/JS \u6587\u4ef6\uff0c\u4e5f\u53ef\u4ee5\u662f\u9488\u5bf9\u7279\u5b9a\u7684\u3001\u9700\u8981\u5927\u91cf\u670d\u52a1\u5668\u8d44\u6e90\u624d\u80fd\u54cd\u5e94\u7684\u52a8\u6001\u9875\u9762\u6216 API \u63a5\u53e3\u3002<\/li>\n\n\n\n<li>Web \u670d\u52a1\u5668\u9700\u8981\u5904\u7406\u6bcf\u4e2a HTTP \u8bf7\u6c42\uff1a\u89e3\u6790\u8bf7\u6c42\u3001\u6267\u884c\u811a\u672c\uff08\u5982 PHP, Python, Java\uff09\u3001\u67e5\u8be2\u6570\u636e\u5e93\u3001\u751f\u6210\u54cd\u5e94\u5185\u5bb9\u7b49\u3002<\/li>\n<\/ol>\n<\/li>\n\n\n\n<li>\u76ee\u6807\/\u5f71\u54cd\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u8017\u5c3d\u670d\u52a1\u5668\u7684 CPU\u3001\u5185\u5b58\u3001\u6570\u636e\u5e93\u8fde\u63a5\u3001\u5e94\u7528\u7a0b\u5e8f\u7ebf\u7a0b\u7b49\u8d44\u6e90\u3002<\/strong><\/li>\n\n\n\n<li><strong>\u4f7f\u670d\u52a1\u5668\u65e0\u6cd5\u54cd\u5e94\u5408\u6cd5\u6d41\u91cf\uff1a<\/strong> \u7531\u4e8e\u8d44\u6e90\u88ab\u6076\u610f\u8bf7\u6c42\u5360\u7528\uff0c\u5408\u6cd5\u7528\u6237\u7684\u8bf7\u6c42\u5904\u7406\u901f\u5ea6\u53d8\u6162\uff0c\u751a\u81f3\u65e0\u6cd5\u83b7\u5f97\u54cd\u5e94\u3002<\/li>\n\n\n\n<li><strong>\u5bfc\u81f4\u7f51\u7ad9\u54cd\u5e94\u7f13\u6162\u3001\u9875\u9762\u52a0\u8f7d\u5931\u8d25\u6216\u670d\u52a1\u5668\u5d29\u6e83\u3002<\/strong><\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>CTF \u76f8\u5173\uff1a<\/strong> \u8fd9\u662f Web \u6e17\u900f\u6d4b\u8bd5\u4e2d\u5e38\u89c1\u7684\u62d2\u7edd\u670d\u52a1\u624b\u6bb5\u3002\u9632\u5fa1\u901a\u5e38\u6d89\u53ca Web \u5e94\u7528\u9632\u706b\u5899 (WAF)\u3001\u901f\u7387\u9650\u5236\u3001\u9a8c\u8bc1\u7801\u3001CDN \u7b49\u3002<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">3. CC \u653b\u51fb (Challenge Collapsar)<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u662f\u4ec0\u4e48\uff1a<\/strong> CC \u653b\u51fb\u662f HTTP Flood \u7684\u4e00\u4e2a\u7279\u4f8b\u548c\u9ad8\u7ea7\u53d8\u79cd\uff0c\u5b83\u662f\u4e00\u79cd<strong>\u6a21\u62df\u771f\u5b9e\u7528\u6237\u884c\u4e3a<\/strong>\u7684\u3001<strong>\u9488\u5bf9\u9ad8\u6d88\u8017\u8d44\u6e90<\/strong>\u7684 HTTP\/HTTPS \u5e94\u7528\u5c42\u653b\u51fb\u3002<\/li>\n\n\n\n<li>\u5982\u4f55\u5de5\u4f5c\uff1a\n<ol class=\"wp-block-list\">\n<li>\u653b\u51fb\u8005\u4f7f\u7528\u50f5\u5c38\u7f51\u7edc\u4e2d\u7684\u8ba1\u7b97\u673a\uff0c\u5411\u76ee\u6807\u7f51\u7ad9\u7684<strong>\u7279\u5b9a\u3001\u8ba1\u7b97\u5bc6\u96c6\u578b\u6216\u6570\u636e\u5e93\u5bc6\u96c6\u578b\u9875\u9762\/API \u63a5\u53e3<\/strong>\u53d1\u9001\u5927\u91cf HTTP\/HTTPS \u8bf7\u6c42\u3002<\/li>\n\n\n\n<li>\u8fd9\u4e9b\u8bf7\u6c42\u901a\u5e38\u4f1a<strong>\u4f2a\u9020\u6216\u6a21\u62df\u5408\u6cd5\u7528\u6237\u7684\u8bf7\u6c42\u5934<\/strong>\uff08\u5982 User-Agent\u3001Referer\u3001Cookie\uff09\uff0c\u751a\u81f3\u4f1a\u6a21\u62df\u7528\u6237\u7684\u6d4f\u89c8\u8def\u5f84\uff0c\u4f7f\u5176\u770b\u8d77\u6765\u975e\u5e38\u50cf\u771f\u5b9e\u7528\u6237\u7684\u8bbf\u95ee\u3002<\/li>\n\n\n\n<li>\u653b\u51fb\u8005\u4f1a\u9009\u62e9\u90a3\u4e9b\u9700\u8981\u670d\u52a1\u5668\u8fdb\u884c\u590d\u6742\u8ba1\u7b97\u3001\u5927\u91cf\u6570\u636e\u5e93\u67e5\u8be2\u3001\u6587\u4ef6\u8bfb\u5199\u6216\u52a8\u6001\u5185\u5bb9\u751f\u6210\u7684\u9875\u9762\u4f5c\u4e3a\u76ee\u6807\uff0c\u800c\u4e0d\u662f\u7b80\u5355\u7684\u9759\u6001\u9875\u9762\u3002<\/li>\n\n\n\n<li>\u653b\u51fb\u6a21\u5f0f\u53ef\u4ee5\u662f\u9ad8\u901f\uff08\u77ed\u65f6\u95f4\u5185\u5927\u91cf\u8bf7\u6c42\uff09\u6216\u4f4e\u901f\uff08\u957f\u65f6\u95f4\u5185\u6301\u7eed\u53d1\u9001\u5c11\u91cf\u8bf7\u6c42\uff0c\u4f46\u603b\u91cf\u5de8\u5927\uff09\uff0c\u751a\u81f3\u6df7\u5408\u6a21\u5f0f\uff0c\u4ee5\u589e\u52a0\u68c0\u6d4b\u548c\u9632\u5fa1\u7684\u96be\u5ea6\u3002<\/li>\n<\/ol>\n<\/li>\n\n\n\n<li>\u76ee\u6807\/\u5f71\u54cd\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u8017\u5c3d\u670d\u52a1\u5668\u7684 CPU\u3001\u5185\u5b58\u3001\u6570\u636e\u5e93\u8fde\u63a5\u3001\u5e94\u7528\u7a0b\u5e8f\u7ebf\u7a0b\u3001Web \u670d\u52a1\u5668\u8fdb\u7a0b\u7b49\u5e94\u7528\u7a0b\u5e8f\u5c42\u8d44\u6e90\u3002<\/strong><\/li>\n\n\n\n<li><strong>\u4f7f\u670d\u52a1\u5668\u5b95\u673a\u6216\u54cd\u5e94\u6781\u6162\uff1a<\/strong> \u7531\u4e8e\u5927\u91cf\u8d44\u6e90\u88ab\u7528\u4e8e\u5904\u7406\u8fd9\u4e9b\u770b\u4f3c\u5408\u6cd5\u7684\u201c\u91cd\u201d\u8bf7\u6c42\uff0c\u670d\u52a1\u5668\u65e0\u6cd5\u4e3a\u771f\u5b9e\u7528\u6237\u63d0\u4f9b\u670d\u52a1\u3002<\/li>\n\n\n\n<li><strong>\u96be\u4ee5\u9632\u5fa1\uff1a<\/strong> \u56e0\u4e3a\u8bf7\u6c42\u770b\u8d77\u6765\u5408\u6cd5\uff0c\u4f20\u7edf\u7684\u57fa\u4e8e\u6d41\u91cf\u6216\u534f\u8bae\u5f02\u5e38\u7684 DDoS \u9632\u5fa1\u624b\u6bb5\u6548\u679c\u4e0d\u4f73\uff0c\u9700\u8981\u66f4\u667a\u80fd\u7684\u884c\u4e3a\u5206\u6790\u548c\u5e94\u7528\u5c42\u9632\u62a4\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">DDOS\u653b\u51fb\u76f8\u5e94\u7684\u9632\u5fa1\u63aa\u65bd<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">\u7f51\u7edc\u5c42\u653b\u51fb (Layer 3 Attacks) \u9632\u5fa1<\/h3>\n\n\n\n<p>\u8fd9\u7c7b\u653b\u51fb\u4e3b\u8981\u901a\u8fc7\u6d88\u8017\u7f51\u7edc\u5e26\u5bbd\u548c\u8bbe\u5907\u5904\u7406\u80fd\u529b\u6765\u8fbe\u5230\u62d2\u7edd\u670d\u52a1\u7684\u76ee\u7684\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">1. ICMP Flood \u653b\u51fb \u9632\u5fa1<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u653b\u51fb\u7279\u70b9\uff1a<\/strong> \u5927\u91cf ICMP Echo Request\/Reply \u5305\uff0c\u6d88\u8017 CPU \u548c\u5e26\u5bbd\u3002<\/li>\n\n\n\n<li>\u9632\u5fa1\u63aa\u65bd\uff1a\n<ul class=\"wp-block-list\">\n<li>\u9632\u706b\u5899\u89c4\u5219 (Firewall Rules)\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u9650\u5236 ICMP \u6d41\u91cf\uff1a<\/strong> \u914d\u7f6e\u9632\u706b\u5899\u6216\u8def\u7531\u5668\uff0c\u9650\u5236\u6bcf\u79d2\u5141\u8bb8\u901a\u8fc7\u7684 ICMP \u5305\u6570\u91cf\uff08\u901f\u7387\u9650\u5236\uff09\u3002\u4f8b\u5982\uff0c\u9650\u5236\u6bcf\u79d2\u53ea\u5141\u8bb8 100 \u4e2a ICMP Echo Request \u5305\u3002<\/li>\n\n\n\n<li><strong>\u7981\u7528 ICMP \u54cd\u5e94\uff1a<\/strong> \u5982\u679c\u4e1a\u52a1\u4e0d\u9700\u8981\uff0c\u53ef\u4ee5\u76f4\u63a5\u7981\u7528\u670d\u52a1\u5668\u5bf9 ICMP Echo Request \u7684\u54cd\u5e94\u3002\u8fd9\u4f1a\u4f7f\u670d\u52a1\u5668\u5bf9\u5916\u90e8\u201c\u9690\u8eab\u201d\uff0c\u4f46\u4e5f\u4f1a\u5f71\u54cd\u7f51\u7edc\u8bca\u65ad\u5de5\u5177\uff08\u5982 <code>ping<\/code>\uff09\u7684\u4f7f\u7528\u3002<\/li>\n\n\n\n<li><strong>\u4e22\u5f03\u7578\u5f62 ICMP \u5305\uff1a<\/strong> \u914d\u7f6e\u9632\u706b\u5899\u6216\u5165\u4fb5\u9632\u5fa1\u7cfb\u7edf (IPS) \u4e22\u5f03\u4e0d\u7b26\u5408\u6807\u51c6 ICMP \u534f\u8bae\u89c4\u8303\u7684\u7578\u5f62\u5305\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>\u5165\u4fb5\u9632\u5fa1\u7cfb\u7edf (IPS) \/ \u5165\u4fb5\u68c0\u6d4b\u7cfb\u7edf (IDS)\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u8bc6\u522b\u5f02\u5e38\u6a21\u5f0f\uff1a<\/strong> IPS\/IDS \u53ef\u4ee5\u68c0\u6d4b\u5230\u5f02\u5e38\u9ad8\u9891\u7387\u7684 ICMP \u6d41\u91cf\uff0c\u5e76\u81ea\u52a8\u963b\u6b62\u6765\u81ea\u653b\u51fb\u6e90\u7684\u6d41\u91cf\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>DDoS \u6e05\u6d17\u670d\u52a1 (DDoS Scrubbing Services)\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u6d41\u91cf\u8fc7\u6ee4\uff1a<\/strong> \u5c06\u6240\u6709\u5165\u7ad9\u6d41\u91cf\u91cd\u5b9a\u5411\u5230\u4e13\u4e1a\u7684 DDoS \u6e05\u6d17\u4e2d\u5fc3\uff0c\u5728\u90a3\u91cc\u5bf9\u6d41\u91cf\u8fdb\u884c\u5206\u6790\u548c\u8fc7\u6ee4\uff0c\u53bb\u9664\u6076\u610f ICMP \u5305\uff0c\u53ea\u5c06\u5e72\u51c0\u7684\u6d41\u91cf\u8f6c\u53d1\u7ed9\u76ee\u6807\u670d\u52a1\u5668\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">2. ARP Flood \u653b\u51fb \u9632\u5fa1<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u653b\u51fb\u7279\u70b9\uff1a<\/strong> \u5927\u91cf\u4f2a\u9020 ARP \u8bf7\u6c42\/\u54cd\u5e94\uff0c\u5bfc\u81f4\u4ea4\u6362\u673a CAM \u8868\u6ea2\u51fa\uff0c\u7f51\u7edc\u62e5\u5835\u3002<\/li>\n\n\n\n<li>\u9632\u5fa1\u63aa\u65bd\uff1a\n<ul class=\"wp-block-list\">\n<li>\u7aef\u53e3\u5b89\u5168 (Port Security) on Switches\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>MAC \u5730\u5740\u9650\u5236\uff1a<\/strong> \u5728\u4ea4\u6362\u673a\u7aef\u53e3\u4e0a\u914d\u7f6e\u5141\u8bb8\u5b66\u4e60\u7684\u6700\u5927 MAC \u5730\u5740\u6570\u91cf\u3002\u4e00\u65e6\u8fbe\u5230\u9650\u5236\uff0c\u65b0\u5b66\u4e60\u7684 MAC \u5730\u5740\u5c06\u88ab\u62d2\u7edd\uff0c\u751a\u81f3\u53ef\u4ee5\u5173\u95ed\u7aef\u53e3\u3002<\/li>\n\n\n\n<li><strong>Sticky MAC (\u7c98\u6027 MAC)\uff1a<\/strong> \u5141\u8bb8\u7aef\u53e3\u5b66\u4e60\u8fde\u63a5\u8bbe\u5907\u7684 MAC \u5730\u5740\uff0c\u5e76\u5c06\u5176\u4fdd\u5b58\u5230\u914d\u7f6e\u4e2d\u3002\u4e0b\u6b21\u8bbe\u5907\u8fde\u63a5\u65f6\uff0c\u53ea\u5141\u8bb8\u8be5 MAC \u5730\u5740\u901a\u8fc7\uff0c\u9632\u6b62\u5176\u4ed6 MAC \u5730\u5740\u5192\u5145\u3002<\/li>\n\n\n\n<li><strong>\u8fdd\u89c4\u884c\u4e3a\u5904\u7406\uff1a<\/strong> \u914d\u7f6e\u7aef\u53e3\u5728\u68c0\u6d4b\u5230\u8fdd\u89c4\u884c\u4e3a\uff08\u5982 MAC \u5730\u5740\u6570\u91cf\u8d85\u9650\uff09\u65f6\u91c7\u53d6\u7684\u52a8\u4f5c\uff0c\u4f8b\u5982\u5173\u95ed\u7aef\u53e3 (shutdown)\u3001\u9650\u5236\u6d41\u91cf (restrict) \u6216\u4fdd\u62a4\u7aef\u53e3 (protect)\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>DHCP Snooping (DHCP \u4fa6\u542c)\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u9632\u6b62 rogue DHCP \u670d\u52a1\u5668\uff1a<\/strong> \u5728\u4ea4\u6362\u673a\u4e0a\u542f\u7528 DHCP Snooping\uff0c\u53ef\u4ee5\u9632\u6b62\u653b\u51fb\u8005\u90e8\u7f72\u6076\u610f\u7684 DHCP \u670d\u52a1\u5668\uff0c\u4ece\u800c\u963b\u6b62\u5176\u5206\u53d1\u9519\u8bef\u7684 IP \u5730\u5740\u6216\u8fdb\u884c ARP \u6b3a\u9a97\u3002<\/li>\n\n\n\n<li><strong>\u6784\u5efa\u4fe1\u4efb\u6570\u636e\u5e93\uff1a<\/strong> DHCP Snooping \u53ef\u4ee5\u5efa\u7acb\u4e00\u4e2a\u7ed1\u5b9a\u8868\uff0c\u8bb0\u5f55 IP-MAC-\u7aef\u53e3\u7684\u5bf9\u5e94\u5173\u7cfb\uff0c\u4e3a\u540e\u7eed\u7684 DAI \u63d0\u4f9b\u6570\u636e\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>\u52a8\u6001 ARP \u68c0\u6d4b (Dynamic ARP Inspection, DAI)\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u9a8c\u8bc1 ARP \u5305\uff1a<\/strong> DAI \u68c0\u67e5\u6240\u6709\u901a\u8fc7\u4ea4\u6362\u673a\u7684 ARP \u8bf7\u6c42\u548c\u54cd\u5e94\uff0c\u5e76\u6839\u636e DHCP Snooping \u5efa\u7acb\u7684\u7ed1\u5b9a\u8868\u6765\u9a8c\u8bc1\u5176\u5408\u6cd5\u6027\u3002\u5982\u679c ARP \u5305\u4e2d\u7684 IP-MAC \u6620\u5c04\u4e0d\u5339\u914d\uff0c\u6216\u8005\u6e90 IP\/MAC \u5730\u5740\u662f\u4f2a\u9020\u7684\uff0cDAI \u4f1a\u4e22\u5f03\u8be5\u5305\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>\u9759\u6001 ARP \u7ed1\u5b9a (Static ARP Entries)\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u624b\u52a8\u6620\u5c04\uff1a<\/strong> \u5bf9\u4e8e\u5173\u952e\u670d\u52a1\u5668\u6216\u8bbe\u5907\uff0c\u53ef\u4ee5\u5728\u4ea4\u6362\u673a\u6216\u8def\u7531\u5668\u4e0a\u624b\u52a8\u914d\u7f6e\u9759\u6001 ARP \u6761\u76ee\uff0c\u5c06 IP \u5730\u5740\u6c38\u4e45\u7ed1\u5b9a\u5230\u5176 MAC \u5730\u5740\u3002\u8fd9\u53ef\u4ee5\u9632\u6b62\u8fd9\u4e9b\u5173\u952e\u8bbe\u5907\u7684 ARP \u8868\u88ab\u6076\u610f\u66f4\u65b0\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>\u7f51\u7edc\u5206\u6bb5 (Network Segmentation)\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u9650\u5236\u653b\u51fb\u8303\u56f4\uff1a<\/strong> \u5c06\u7f51\u7edc\u5212\u5206\u4e3a\u591a\u4e2a VLAN \u6216\u5b50\u7f51\uff0c\u53ef\u4ee5\u9650\u5236 ARP Flood \u653b\u51fb\u7684\u5f71\u54cd\u8303\u56f4\uff0c\u4f7f\u5176\u53ea\u5728\u4e00\u4e2a\u5c0f\u7684\u5e7f\u64ad\u57df\u5185\u4f20\u64ad\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">3. IP \u5206\u7247\u653b\u51fb \u9632\u5fa1<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u653b\u51fb\u7279\u70b9\uff1a<\/strong> \u7578\u5f62\u3001\u91cd\u53e0\u6216\u4e0d\u5b8c\u6574\u7684 IP \u5206\u7247\uff0c\u6d88\u8017\u76ee\u6807\u4e3b\u673a\u7684\u91cd\u7ec4\u8d44\u6e90\u3002<\/li>\n\n\n\n<li>\u9632\u5fa1\u63aa\u65bd\uff1a\n<ul class=\"wp-block-list\">\n<li>\u9632\u706b\u5899 \/ \u5165\u4fb5\u9632\u5fa1\u7cfb\u7edf (IPS)\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u5206\u7247\u91cd\u7ec4\uff1a<\/strong> \u8bb8\u591a\u73b0\u4ee3\u9632\u706b\u5899\u548c IPS \u80fd\u591f\u5728\u6d41\u91cf\u8fdb\u5165\u5185\u90e8\u7f51\u7edc\u4e4b\u524d\u5bf9 IP \u5206\u7247\u8fdb\u884c\u91cd\u7ec4\u3002\u5982\u679c\u91cd\u7ec4\u5931\u8d25\uff08\u4f8b\u5982\u5206\u7247\u4e0d\u5b8c\u6574\u6216\u7578\u5f62\uff09\uff0c\u5219\u4e22\u5f03\u6574\u4e2a\u6570\u636e\u5305\u3002<\/li>\n\n\n\n<li><strong>\u68c0\u6d4b\u548c\u4e22\u5f03\u5f02\u5e38\u5206\u7247\uff1a<\/strong> \u914d\u7f6e\u9632\u706b\u5899\/IPS \u8bc6\u522b\u5e76\u4e22\u5f03\u5177\u6709\u5f02\u5e38\u6807\u5fd7\u3001\u91cd\u53e0\u504f\u79fb\u3001\u8fc7\u5c0f\u6216\u8fc7\u5927\u8f7d\u8377\u7684 IP \u5206\u7247\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>\u64cd\u4f5c\u7cfb\u7edf\/\u7f51\u7edc\u8bbe\u5907\u914d\u7f6e\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u9650\u5236\u5206\u7247\u91cd\u7ec4\u8d44\u6e90\uff1a<\/strong> \u8c03\u6574\u64cd\u4f5c\u7cfb\u7edf\u6216\u7f51\u7edc\u8bbe\u5907\u7684\u53c2\u6570\uff0c\u9650\u5236\u7528\u4e8e IP \u5206\u7247\u91cd\u7ec4\u7684\u5185\u5b58\u548c CPU \u8d44\u6e90\u3002\u4f8b\u5982\uff0c\u9650\u5236\u53ef\u4ee5\u540c\u65f6\u5904\u7406\u7684\u5206\u7247\u6570\u91cf\u6216\u91cd\u7ec4\u8d85\u65f6\u65f6\u95f4\u3002<\/li>\n\n\n\n<li><strong>\u7981\u7528 IP \u5206\u7247 (\u5982\u679c\u53ef\u80fd)\uff1a<\/strong> \u5728\u67d0\u4e9b\u7279\u5b9a\u7684\u7f51\u7edc\u6216\u670d\u52a1\u4e2d\uff0c\u5982\u679c\u4e0d\u9700\u8981 IP \u5206\u7247\uff0c\u53ef\u4ee5\u8003\u8651\u5728\u8bbe\u5907\u4e0a\u7981\u7528\u5b83\uff0c\u4ece\u800c\u6d88\u9664\u8fd9\u79cd\u653b\u51fb\u9762\u3002\u4f46\u8fd9\u9700\u8981\u4ed4\u7ec6\u8bc4\u4f30\uff0c\u56e0\u4e3a\u5b83\u53ef\u80fd\u5f71\u54cd\u67d0\u4e9b\u5927\u5305\u4f20\u8f93\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>DDoS \u6e05\u6d17\u670d\u52a1\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u9ad8\u7ea7\u8fc7\u6ee4\uff1a<\/strong> \u4e13\u4e1a\u7684 DDoS \u6e05\u6d17\u670d\u52a1\u80fd\u591f\u66f4\u6709\u6548\u5730\u8bc6\u522b\u548c\u8fc7\u6ee4\u6389\u5404\u79cd\u7578\u5f62\u7684 IP \u5206\u7247\u653b\u51fb\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">\u4f20\u8f93\u5c42\u653b\u51fb (Layer 4 Attacks) \u9632\u5fa1<\/h3>\n\n\n\n<p>\u8fd9\u7c7b\u653b\u51fb\u4e3b\u8981\u901a\u8fc7\u8017\u5c3d\u670d\u52a1\u5668\u7684\u8fde\u63a5\u72b6\u6001\u8868\u6216\u7f51\u7edc\u8bbe\u5907\u7684\u8d44\u6e90\uff0c\u963b\u6b62\u5408\u6cd5\u7528\u6237\u5efa\u7acb\u65b0\u7684\u8fde\u63a5\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">1. SYN Flood \u653b\u51fb \u9632\u5fa1<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u653b\u51fb\u7279\u70b9\uff1a<\/strong> \u5927\u91cf\u534a\u5f00\u8fde\u63a5\uff0c\u8017\u5c3d\u670d\u52a1\u5668\u8fde\u63a5\u961f\u5217\u3002<\/li>\n\n\n\n<li>\u9632\u5fa1\u63aa\u65bd\uff1a\n<ul class=\"wp-block-list\">\n<li>SYN Cookies (SYN Cookie \u6280\u672f)\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u65e0\u72b6\u6001\u8fde\u63a5\uff1a<\/strong> \u670d\u52a1\u5668\u5728\u6536\u5230 SYN \u8bf7\u6c42\u65f6\uff0c\u4e0d\u7acb\u5373\u4e3a\u8be5\u8fde\u63a5\u5206\u914d\u8d44\u6e90\uff0c\u800c\u662f\u751f\u6210\u4e00\u4e2a\u7279\u6b8a\u7684\u201ccookie\u201d\uff08\u4e00\u4e2a\u52a0\u5bc6\u7684\u5e8f\u5217\u53f7\uff09\uff0c\u5e76\u5c06\u5176\u4f5c\u4e3a SYN\/ACK \u5305\u7684\u5e8f\u5217\u53f7\u53d1\u9001\u7ed9\u5ba2\u6237\u7aef\u3002<\/li>\n\n\n\n<li><strong>\u9a8c\u8bc1\uff1a<\/strong> \u53ea\u6709\u5f53\u5ba2\u6237\u7aef\u56de\u590d\u5e26\u6709\u6b63\u786e cookie \u7684 ACK \u5305\u65f6\uff0c\u670d\u52a1\u5668\u624d\u8ba4\u4e3a\u8fd9\u662f\u4e00\u4e2a\u5408\u6cd5\u8fde\u63a5\uff0c\u5e76\u5206\u914d\u8d44\u6e90\u3002\u8fd9\u4f7f\u5f97\u670d\u52a1\u5668\u5728\u653b\u51fb\u671f\u95f4\u65e0\u9700\u4e3a\u5927\u91cf\u534a\u5f00\u8fde\u63a5\u7ef4\u62a4\u72b6\u6001\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>\u589e\u52a0\u8fde\u63a5\u961f\u5217\u5927\u5c0f (Increase Backlog Queue)\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u4e34\u65f6\u7f13\u89e3\uff1a<\/strong> \u8c03\u6574\u64cd\u4f5c\u7cfb\u7edf\u53c2\u6570\uff0c\u589e\u52a0 TCP \u8fde\u63a5\u7684\u534a\u5f00\u548c\u5168\u5f00\u961f\u5217\u5927\u5c0f\u3002\u8fd9\u53ef\u4ee5\u6682\u65f6\u5bb9\u7eb3\u66f4\u591a\u7684\u8fde\u63a5\uff0c\u4f46\u4e0d\u80fd\u4ece\u6839\u672c\u4e0a\u89e3\u51b3\u95ee\u9898\uff0c\u4e14\u4f1a\u6d88\u8017\u66f4\u591a\u5185\u5b58\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>\u7f29\u77ed SYN-ACK \u91cd\u4f20\u8d85\u65f6\u65f6\u95f4 (Reduce SYN-ACK Retransmission Timeout)\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u5feb\u901f\u91ca\u653e\u8d44\u6e90\uff1a<\/strong> \u51cf\u5c11\u670d\u52a1\u5668\u7b49\u5f85\u5ba2\u6237\u7aef ACK \u5305\u7684\u8d85\u65f6\u65f6\u95f4\u3002\u8fd9\u6837\u53ef\u4ee5\u66f4\u5feb\u5730\u91ca\u653e\u56e0\u534a\u5f00\u8fde\u63a5\u800c\u5360\u7528\u7684\u8d44\u6e90\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>SYN Proxy \/ \u9632\u706b\u5899\u4ee3\u7406\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u4e2d\u95f4\u4eba\u6a21\u5f0f\uff1a<\/strong> \u4e13\u4e1a\u7684\u9632\u706b\u5899\u6216\u4ee3\u7406\u8bbe\u5907\uff08\u5982\u8d1f\u8f7d\u5747\u8861\u5668\uff09\u53ef\u4ee5\u5145\u5f53 SYN \u4ee3\u7406\u3002\u5b83\u9996\u5148\u4e0e\u5ba2\u6237\u7aef\u5b8c\u6210\u4e09\u6b21\u63e1\u624b\uff0c\u786e\u8ba4\u5ba2\u6237\u7aef\u662f\u5408\u6cd5\u7684\uff0c\u7136\u540e\u624d\u4ee3\u8868\u5ba2\u6237\u7aef\u4e0e\u540e\u7aef\u670d\u52a1\u5668\u5efa\u7acb\u8fde\u63a5\u3002\u8fd9\u4fdd\u62a4\u4e86\u540e\u7aef\u670d\u52a1\u5668\u514d\u53d7 SYN Flood \u653b\u51fb\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>DDoS \u6e05\u6d17\u670d\u52a1\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u6d41\u91cf\u8fc7\u6ee4\uff1a<\/strong> \u4e13\u4e1a\u7684 DDoS \u6e05\u6d17\u4e2d\u5fc3\u80fd\u591f\u8bc6\u522b\u548c\u8fc7\u6ee4\u5927\u91cf\u7684 SYN \u8bf7\u6c42\uff0c\u53ea\u5c06\u5408\u6cd5\u7684\u8fde\u63a5\u8bf7\u6c42\u8f6c\u53d1\u7ed9\u76ee\u6807\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">2. ACK Flood \u653b\u51fb \u9632\u5fa1<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u653b\u51fb\u7279\u70b9\uff1a<\/strong> \u5927\u91cf\u4f2a\u9020 ACK \u5305\uff0c\u6d88\u8017 CPU \u548c\u5e26\u5bbd\u3002<\/li>\n\n\n\n<li>\u9632\u5fa1\u63aa\u65bd\uff1a\n<ul class=\"wp-block-list\">\n<li>\u72b6\u6001\u9632\u706b\u5899 \/ \u5165\u4fb5\u9632\u5fa1\u7cfb\u7edf (IPS)\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u8fde\u63a5\u72b6\u6001\u8ddf\u8e2a\uff1a<\/strong> \u72b6\u6001\u9632\u706b\u5899\u4f1a\u8ddf\u8e2a\u6240\u6709\u5df2\u5efa\u7acb\u7684 TCP \u8fde\u63a5\u7684\u72b6\u6001\u3002\u4efb\u4f55\u4e0d\u5c5e\u4e8e\u5df2\u77e5\u8fde\u63a5\u7684 ACK \u5305\uff08\u5373\u6ca1\u6709\u5bf9\u5e94\u7684 SYN \u5305\u6216\u5df2\u5efa\u7acb\u7684\u8fde\u63a5\uff09\u90fd\u4f1a\u88ab\u76f4\u63a5\u4e22\u5f03\uff0c\u800c\u4e0d\u4f1a\u53d1\u9001\u5230\u76ee\u6807\u670d\u52a1\u5668\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>\u901f\u7387\u9650\u5236 (Rate Limiting)\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u9650\u5236 ACK \u5305\u6570\u91cf\uff1a<\/strong> \u5728\u9632\u706b\u5899\u6216\u8def\u7531\u5668\u4e0a\u914d\u7f6e\u7b56\u7565\uff0c\u9650\u5236\u6bcf\u79d2\u5141\u8bb8\u901a\u8fc7\u7684 ACK \u5305\u6570\u91cf\uff0c\u9632\u6b62 CPU \u8fc7\u8f7d\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>\u6d41\u91cf\u6e05\u6d17\u670d\u52a1\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u6df1\u5ea6\u5305\u68c0\u6d4b\uff1a<\/strong> \u4e13\u4e1a\u7684 DDoS \u6e05\u6d17\u670d\u52a1\u53ef\u4ee5\u8fdb\u884c\u6df1\u5ea6\u5305\u68c0\u6d4b\uff0c\u8bc6\u522b\u5e76\u8fc7\u6ee4\u6389\u5927\u91cf\u7684\u4f2a\u9020 ACK \u6d41\u91cf\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">3. UDP Flood \u653b\u51fb \u9632\u5fa1<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u653b\u51fb\u7279\u70b9\uff1a<\/strong> \u5927\u91cf UDP \u5305\uff0c\u6d88\u8017\u5e26\u5bbd\uff0c\u6216\u5bfc\u81f4\u76ee\u6807\u4e3b\u673a\u53d1\u9001\u5927\u91cf ICMP \u54cd\u5e94\u3002<\/li>\n\n\n\n<li>\u9632\u5fa1\u63aa\u65bd\uff1a\n<ul class=\"wp-block-list\">\n<li>\u9632\u706b\u5899\u89c4\u5219\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u9650\u5236 UDP \u6d41\u91cf\uff1a<\/strong> \u9650\u5236\u6bcf\u79d2\u5141\u8bb8\u901a\u8fc7\u7684 UDP \u5305\u6570\u91cf\u3002<\/li>\n\n\n\n<li><strong>\u5173\u95ed\u4e0d\u5fc5\u8981\u7684 UDP \u7aef\u53e3\uff1a<\/strong> \u5728\u9632\u706b\u5899\u4e0a\u963b\u6b62\u6240\u6709\u4e0d\u5fc5\u8981\u7684 UDP \u7aef\u53e3\uff0c\u53ea\u5f00\u653e\u4e1a\u52a1\u6240\u9700\u7684\u7aef\u53e3\u3002\u8fd9\u53ef\u4ee5\u51cf\u5c11\u653b\u51fb\u9762\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>\u7981\u7528 ICMP Unreachable \u54cd\u5e94\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u51cf\u5c11\u670d\u52a1\u5668\u8d1f\u8f7d\uff1a<\/strong> \u914d\u7f6e\u670d\u52a1\u5668\u6216\u9632\u706b\u5899\uff0c\u7981\u7528\u6216\u9650\u5236\u53d1\u9001 ICMP Destination Unreachable (Port Unreachable) \u54cd\u5e94\u3002\u8fd9\u53ef\u4ee5\u9632\u6b62\u670d\u52a1\u5668\u5728\u6536\u5230\u5927\u91cf\u53d1\u5f80\u5173\u95ed\u7aef\u53e3\u7684 UDP \u5305\u65f6\uff0c\u56e0\u751f\u6210\u5927\u91cf ICMP \u54cd\u5e94\u800c\u8017\u5c3d\u8d44\u6e90\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>DDoS \u6e05\u6d17\u670d\u52a1\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u5e26\u5bbd\u5438\u6536\u4e0e\u8fc7\u6ee4\uff1a<\/strong> UDP Flood \u5f80\u5f80\u662f\u6d41\u91cf\u578b\u653b\u51fb\u7684\u4e3b\u529b\uff0c\u4e13\u4e1a\u7684 DDoS \u6e05\u6d17\u670d\u52a1\u80fd\u591f\u5438\u6536\u5de8\u5927\u7684 UDP \u6d41\u91cf\uff0c\u5e76\u901a\u8fc7\u534f\u8bae\u5206\u6790\u3001\u5f02\u5e38\u68c0\u6d4b\u7b49\u624b\u6bb5\u8fc7\u6ee4\u6389\u6076\u610f\u6d41\u91cf\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>Anycast \u7f51\u7edc\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u5206\u6563\u6d41\u91cf\uff1a<\/strong> \u5bf9\u4e8e\u63d0\u4f9b UDP \u670d\u52a1\u7684\u573a\u666f\uff08\u5982 DNS\uff09\uff0c\u4f7f\u7528 Anycast \u53ef\u4ee5\u5c06\u6d41\u91cf\u5206\u6563\u5230\u591a\u4e2a\u5730\u7406\u4f4d\u7f6e\u7684\u670d\u52a1\u5668\uff0c\u4ece\u800c\u5206\u62c5\u653b\u51fb\u538b\u529b\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">\u5e94\u7528\u5c42\u653b\u51fb (Layer 7 Attacks) \u9632\u5fa1<\/h3>\n\n\n\n<p>\u8fd9\u7c7b\u653b\u51fb\u65e8\u5728\u901a\u8fc7\u6a21\u62df\u5408\u6cd5\u7528\u6237\u8bf7\u6c42\u6765\u6d88\u8017\u5e94\u7528\u7a0b\u5e8f\u7684\u8d44\u6e90\uff0c\u4ece\u800c\u8ba9\u771f\u5b9e\u7528\u6237\u65e0\u6cd5\u6b63\u5e38\u4f7f\u7528\u5e94\u7528\u7a0b\u5e8f\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">1. DNS Flood \u653b\u51fb \u9632\u5fa1<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u653b\u51fb\u7279\u70b9\uff1a<\/strong> \u5927\u91cf DNS \u67e5\u8be2\u8bf7\u6c42\uff0c\u4f7f DNS \u670d\u52a1\u5668\u8fc7\u8f7d\u3002<\/li>\n\n\n\n<li>\u9632\u5fa1\u63aa\u65bd\uff1a\n<ul class=\"wp-block-list\">\n<li>DNS \u6d41\u91cf\u901f\u7387\u9650\u5236 (Rate Limiting DNS Queries)\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u9650\u5236\u6bcf\u6e90 IP \u67e5\u8be2\u6570\uff1a<\/strong> \u914d\u7f6e DNS \u670d\u52a1\u5668\u6216\u524d\u7aef\u9632\u706b\u5899\uff0c\u9650\u5236\u6bcf\u4e2a\u6e90 IP \u5730\u5740\u5728\u7279\u5b9a\u65f6\u95f4\u6bb5\u5185\u5141\u8bb8\u53d1\u8d77\u7684 DNS \u67e5\u8be2\u6570\u91cf\u3002<\/li>\n\n\n\n<li><strong>\u9650\u5236\u6bcf\u79d2\u603b\u67e5\u8be2\u6570\uff1a<\/strong> \u5bf9 DNS \u670d\u52a1\u5668\u7684\u603b\u67e5\u8be2\u91cf\u8fdb\u884c\u9650\u5236\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>Anycast DNS \u67b6\u6784\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u5168\u7403\u5206\u5e03\u5f0f\uff1a<\/strong> \u5c06 DNS \u670d\u52a1\u90e8\u7f72\u5728\u591a\u4e2a\u5730\u7406\u4f4d\u7f6e\u7684 Anycast IP \u5730\u5740\u4e0a\u3002\u5f53\u653b\u51fb\u53d1\u751f\u65f6\uff0c\u6d41\u91cf\u4f1a\u88ab\u8def\u7531\u5230\u6700\u8fd1\u7684\u3001\u672a\u53d7\u653b\u51fb\u7684\u8282\u70b9\uff0c\u6216\u5206\u6563\u5230\u6240\u6709\u8282\u70b9\uff0c\u4ece\u800c\u5206\u62c5\u653b\u51fb\u538b\u529b\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>DNS \u7f13\u5b58\u670d\u52a1\u5668 \/ \u9012\u5f52\u89e3\u6790\u5668\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u51cf\u8f7b\u6743\u5a01\u670d\u52a1\u5668\u538b\u529b\uff1a<\/strong> \u5728\u524d\u7aef\u90e8\u7f72\u9ad8\u6027\u80fd\u7684 DNS \u7f13\u5b58\u670d\u52a1\u5668\u6216\u9012\u5f52\u89e3\u6790\u5668\uff0c\u5b83\u4eec\u53ef\u4ee5\u5904\u7406\u5927\u90e8\u5206\u67e5\u8be2\uff0c\u51cf\u8f7b\u540e\u7aef\u6743\u5a01 DNS \u670d\u52a1\u5668\u7684\u538b\u529b\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>DDoS \u6e05\u6d17\u670d\u52a1 (\u4e13\u95e8\u9488\u5bf9 DNS)\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u9ad8\u7ea7 DNS \u6d41\u91cf\u8fc7\u6ee4\uff1a<\/strong> \u4e13\u4e1a\u7684 DDoS \u670d\u52a1\u63d0\u4f9b\u5546\u6709\u4e13\u95e8\u9488\u5bf9 DNS \u653b\u51fb\u7684\u9632\u62a4\u63aa\u65bd\uff0c\u80fd\u591f\u8bc6\u522b\u5e76\u8fc7\u6ee4\u6389\u6076\u610f DNS \u67e5\u8be2\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>DNSSEC (DNS Security Extensions)\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u6570\u636e\u5b8c\u6574\u6027\uff1a<\/strong> \u867d\u7136\u4e0d\u76f4\u63a5\u9632\u5fa1 Flood\uff0c\u4f46 DNSSEC \u63d0\u4f9b\u4e86 DNS \u6570\u636e\u7684\u52a0\u5bc6\u7b7e\u540d\u548c\u9a8c\u8bc1\uff0c\u589e\u5f3a\u4e86 DNS \u7684\u5b89\u5168\u6027\uff0c\u4f7f\u5176\u66f4\u96be\u4ee5\u88ab\u7be1\u6539\uff0c\u4ece\u800c\u63d0\u5347\u4e86\u6574\u4f53 DNS \u57fa\u7840\u8bbe\u65bd\u7684\u5065\u58ee\u6027\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">2. HTTP Flood \u653b\u51fb \u9632\u5fa1<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u653b\u51fb\u7279\u70b9\uff1a<\/strong> \u5927\u91cf HTTP GET\/POST \u8bf7\u6c42\uff0c\u8017\u5c3d Web \u670d\u52a1\u5668\u8d44\u6e90\u3002<\/li>\n\n\n\n<li>\u9632\u5fa1\u63aa\u65bd\uff1a\n<ul class=\"wp-block-list\">\n<li>Web \u5e94\u7528\u9632\u706b\u5899 (WAF)\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u8bf7\u6c42\u8fc7\u6ee4\uff1a<\/strong> WAF \u90e8\u7f72\u5728 Web \u670d\u52a1\u5668\u524d\u7aef\uff0c\u53ef\u4ee5\u5206\u6790 HTTP \u8bf7\u6c42\u7684\u5185\u5bb9\uff08\u5982\u8bf7\u6c42\u5934\u3001URL\u3001\u53c2\u6570\uff09\uff0c\u8bc6\u522b\u5e76\u963b\u6b62\u6076\u610f\u8bf7\u6c42\u3002\u5b83\u80fd\u68c0\u6d4b\u5230\u5f02\u5e38\u7684\u8bf7\u6c42\u6a21\u5f0f\u3001\u9891\u7387\u3001User-Agent \u7b49\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>\u5185\u5bb9\u5206\u53d1\u7f51\u7edc (CDN)\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u6d41\u91cf\u5438\u6536\u4e0e\u7f13\u5b58\uff1a<\/strong> CDN \u5c06\u7f51\u7ad9\u5185\u5bb9\u5206\u53d1\u5230\u5168\u7403\u5404\u5730\u7684\u8fb9\u7f18\u8282\u70b9\u3002\u5f53\u653b\u51fb\u53d1\u751f\u65f6\uff0cCDN \u80fd\u591f\u5438\u6536\u5927\u91cf\u7684\u653b\u51fb\u6d41\u91cf\uff0c\u5e76\u5c06\u5408\u6cd5\u7528\u6237\u7684\u8bf7\u6c42\u8def\u7531\u5230\u6700\u8fd1\u7684\u3001\u5065\u5eb7\u7684\u8282\u70b9\u3002\u540c\u65f6\uff0cCDN \u7f13\u5b58\u9759\u6001\u5185\u5bb9\uff0c\u51cf\u5c11\u5bf9\u6e90\u670d\u52a1\u5668\u7684\u8bf7\u6c42\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>\u901f\u7387\u9650\u5236 (Rate Limiting)\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u9650\u5236\u8bf7\u6c42\u9891\u7387\uff1a<\/strong> \u5728 WAF\u3001\u8d1f\u8f7d\u5747\u8861\u5668\u6216 Web \u670d\u52a1\u5668\uff08\u5982 Nginx, Apache\uff09\u4e0a\u914d\u7f6e\uff0c\u9650\u5236\u6bcf\u4e2a\u6e90 IP \u5730\u5740\u3001\u6bcf\u4e2a\u7528\u6237\u4f1a\u8bdd\u6216\u6bcf\u4e2a URL \u5728\u7279\u5b9a\u65f6\u95f4\u6bb5\u5185\u7684\u8bf7\u6c42\u6570\u91cf\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>\u8d1f\u8f7d\u5747\u8861\u5668 (Load Balancers)\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u5206\u53d1\u6d41\u91cf\uff1a<\/strong> \u5c06\u5408\u6cd5\u6d41\u91cf\u5206\u53d1\u5230\u591a\u4e2a\u540e\u7aef\u670d\u52a1\u5668\uff0c\u9632\u6b62\u5355\u70b9\u8fc7\u8f7d\u3002\u867d\u7136\u4e0d\u80fd\u76f4\u63a5\u9632\u5fa1 DDoS\uff0c\u4f46\u53ef\u4ee5\u63d0\u9ad8\u7cfb\u7edf\u7684\u5bb9\u9519\u80fd\u529b\u548c\u5904\u7406\u80fd\u529b\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>CAPTCHA \/ JavaScript \u6311\u6218\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u4eba\u673a\u9a8c\u8bc1\uff1a<\/strong> \u5728\u68c0\u6d4b\u5230\u53ef\u7591\u6d41\u91cf\u65f6\uff0c\u5411\u5ba2\u6237\u7aef\u53d1\u9001 CAPTCHA \u9a8c\u8bc1\u7801\u6216 JavaScript \u6311\u6218\u3002\u673a\u5668\u4eba\u901a\u5e38\u65e0\u6cd5\u901a\u8fc7\u8fd9\u4e9b\u9a8c\u8bc1\uff0c\u800c\u5408\u6cd5\u7528\u6237\u53ef\u4ee5\u7ee7\u7eed\u8bbf\u95ee\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>\u8fde\u63a5\/\u8bf7\u6c42\u8d85\u65f6\u914d\u7f6e\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u5feb\u901f\u91ca\u653e\u8d44\u6e90\uff1a<\/strong> \u8c03\u6574 Web \u670d\u52a1\u5668\u7684\u8fde\u63a5\u548c\u8bf7\u6c42\u8d85\u65f6\u65f6\u95f4\uff0c\u786e\u4fdd\u4e0d\u6d3b\u8dc3\u7684\u8fde\u63a5\u6216\u8bf7\u6c42\u80fd\u5feb\u901f\u91ca\u653e\u8d44\u6e90\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>IP \u4fe1\u8a89\u5e93 (IP Reputation Databases)\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u963b\u6b62\u5df2\u77e5\u6076\u610f IP\uff1a<\/strong> \u5229\u7528\u7b2c\u4e09\u65b9 IP \u4fe1\u8a89\u670d\u52a1\uff0c\u81ea\u52a8\u963b\u6b62\u6765\u81ea\u5df2\u77e5\u6076\u610f IP \u5730\u5740\u7684\u8bf7\u6c42\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">3. CC \u653b\u51fb \u9632\u5fa1<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u653b\u51fb\u7279\u70b9\uff1a<\/strong> \u6a21\u62df\u771f\u5b9e\u7528\u6237\u884c\u4e3a\uff0c\u9488\u5bf9\u9ad8\u6d88\u8017\u9875\u9762\uff0c\u9ad8\u901f\/\u4f4e\u901f\u6df7\u5408\u6a21\u5f0f\uff0c\u96be\u4ee5\u533a\u5206\u5408\u6cd5\u4e0e\u6076\u610f\u3002<\/li>\n\n\n\n<li>\u9632\u5fa1\u63aa\u65bd (\u901a\u5e38\u662f HTTP Flood \u9632\u5fa1\u7684\u66f4\u9ad8\u7ea7\u548c\u667a\u80fd\u7248\u672c)\uff1a\n<ul class=\"wp-block-list\">\n<li>\u9ad8\u7ea7 Web \u5e94\u7528\u9632\u706b\u5899 (WAF) \/ \u884c\u4e3a\u5206\u6790\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u6df1\u5ea6\u884c\u4e3a\u5206\u6790\uff1a<\/strong> \u4e0d\u4ec5\u68c0\u67e5\u8bf7\u6c42\u5185\u5bb9\uff0c\u8fd8\u5206\u6790\u7528\u6237\u884c\u4e3a\u6a21\u5f0f\uff0c\u4f8b\u5982\u8bbf\u95ee\u9891\u7387\u3001\u9875\u9762\u505c\u7559\u65f6\u95f4\u3001\u8bbf\u95ee\u8def\u5f84\u3001User-Agent \u4e00\u81f4\u6027\u3001\u5730\u7406\u4f4d\u7f6e\u5f02\u5e38\u7b49\u3002\u8bc6\u522b\u51fa\u975e\u4eba\u7c7b\u6216\u5f02\u5e38\u884c\u4e3a\u3002<\/li>\n\n\n\n<li><strong>\u4f1a\u8bdd\u8ddf\u8e2a\uff1a<\/strong> \u8ddf\u8e2a\u7528\u6237\u4f1a\u8bdd\uff0c\u8bc6\u522b\u5f02\u5e38\u7684\u4f1a\u8bdd\u884c\u4e3a\uff08\u5982\u77ed\u65f6\u95f4\u5185\u521b\u5efa\u5927\u91cf\u4f1a\u8bdd\uff0c\u6216\u5355\u4e2a\u4f1a\u8bdd\u53d1\u51fa\u5927\u91cf\u8bf7\u6c42\uff09\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>\u5ba2\u6237\u7aef\u6307\u7eb9\u8bc6\u522b (Client Fingerprinting)\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u8bc6\u522b\u552f\u4e00\u5ba2\u6237\u7aef\uff1a<\/strong> \u901a\u8fc7\u5206\u6790\u6d4f\u89c8\u5668\u7279\u6027\u3001\u63d2\u4ef6\u3001\u5b57\u4f53\u7b49\u4fe1\u606f\uff0c\u751f\u6210\u5ba2\u6237\u7aef\u6307\u7eb9\uff0c\u5373\u4f7f IP \u5730\u5740\u53d8\u5316\u4e5f\u80fd\u8bc6\u522b\u51fa\u653b\u51fb\u8005\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>\u667a\u80fd\u901f\u7387\u9650\u5236\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u591a\u7ef4\u5ea6\u9650\u5236\uff1a<\/strong> \u4e0d\u4ec5\u4ec5\u57fa\u4e8e IP\uff0c\u8fd8\u53ef\u4ee5\u57fa\u4e8e User-Agent\u3001Cookie\u3001Referer\u3001URL \u8def\u5f84\u3001\u4f1a\u8bdd ID \u7b49\u591a\u4e2a\u7ef4\u5ea6\u8fdb\u884c\u66f4\u7cbe\u7ec6\u7684\u901f\u7387\u9650\u5236\u3002<\/li>\n\n\n\n<li><strong>\u81ea\u9002\u5e94\u9650\u901f\uff1a<\/strong> \u6839\u636e\u670d\u52a1\u5668\u8d1f\u8f7d\u52a8\u6001\u8c03\u6574\u9650\u901f\u7b56\u7565\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>JavaScript \u6311\u6218 \/ \u9a8c\u8bc1\u7801\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u5f3a\u5236\u5ba2\u6237\u7aef\u6267\u884c\uff1a<\/strong> \u5728\u68c0\u6d4b\u5230\u53ef\u7591\u6d41\u91cf\u65f6\uff0c\u5f3a\u5236\u5ba2\u6237\u7aef\u6267\u884c JavaScript \u4ee3\u7801\u6216\u663e\u793a\u9a8c\u8bc1\u7801\u3002\u8fd9\u53ef\u4ee5\u6709\u6548\u963b\u6b62\u6ca1\u6709\u5b8c\u6574\u6d4f\u89c8\u5668\u73af\u5883\u7684\u50f5\u5c38\u7a0b\u5e8f\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>IP \u4fe1\u8a89\u548c\u9ed1\u767d\u540d\u5355\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u52a8\u6001\u66f4\u65b0\uff1a<\/strong> \u7ed3\u5408\u5b9e\u65f6\u5a01\u80c1\u60c5\u62a5\uff0c\u52a8\u6001\u66f4\u65b0\u6076\u610f IP \u9ed1\u540d\u5355\u548c\u53d7\u4fe1\u4efb IP \u767d\u540d\u5355\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>\u5e94\u7528\u5c42\u4f18\u5316\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u4ee3\u7801\u4f18\u5316\uff1a<\/strong> \u4f18\u5316\u7f51\u7ad9\u4ee3\u7801\uff0c\u51cf\u5c11\u6570\u636e\u5e93\u67e5\u8be2\u6b21\u6570\uff0c\u4f7f\u7528\u7f13\u5b58\uff0c\u63d0\u9ad8\u9875\u9762\u54cd\u5e94\u901f\u5ea6\uff0c\u964d\u4f4e\u5355\u4e2a\u8bf7\u6c42\u7684\u8d44\u6e90\u6d88\u8017\u3002<\/li>\n\n\n\n<li><strong>\u9759\u6001\u5316\u5904\u7406\uff1a<\/strong> \u5c06\u52a8\u6001\u9875\u9762\u5c3d\u53ef\u80fd\u9759\u6001\u5316\uff0c\u51cf\u5c11\u670d\u52a1\u5668\u7684\u8ba1\u7b97\u8d1f\u62c5\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>\u5f39\u6027\u4f38\u7f29 (Auto-scaling)\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u4e91\u670d\u52a1\u4f18\u52bf\uff1a<\/strong> \u5728\u4e91\u73af\u5883\u4e2d\uff0c\u53ef\u4ee5\u914d\u7f6e\u670d\u52a1\u6839\u636e\u8d1f\u8f7d\u81ea\u52a8\u589e\u52a0\u6216\u51cf\u5c11\u670d\u52a1\u5668\u5b9e\u4f8b\uff0c\u4ece\u800c\u5728\u4e00\u5b9a\u7a0b\u5ea6\u4e0a\u5e94\u5bf9\u6d41\u91cf\u9ad8\u5cf0\uff0c\u5305\u62ec\u653b\u51fb\u6d41\u91cf\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>\u871c\u7f50 (Honeypots) \/ \u6b3a\u9a97\u6280\u672f\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u8bf1\u6355\u653b\u51fb\u8005\uff1a<\/strong> \u90e8\u7f72\u4e00\u4e9b\u865a\u5047\u7684\u3001\u8d44\u6e90\u6d88\u8017\u5927\u7684\u9875\u9762\u6216 API \u63a5\u53e3\u4f5c\u4e3a\u871c\u7f50\uff0c\u5438\u5f15\u653b\u51fb\u8005\uff0c\u4ece\u800c\u4fdd\u62a4\u771f\u5b9e\u670d\u52a1\uff0c\u5e76\u6536\u96c6\u653b\u51fb\u60c5\u62a5\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">DDOS\u653b\u51fb\u548cCC\u653b\u51fb\u7684\u533a\u522b<\/h2>\n\n\n\n<p>\u867d\u7136DDoS\u653b\u51fb\u548cCC\u653b\u51fb\u7684\u8bde\u751f\u90fd\u662f\u5229\u7528\u4e86<a href=\"https:\/\/zhida.zhihu.com\/search?content_id=104334939&amp;content_type=Article&amp;match_order=1&amp;q=TCP%2FIP+\u534f\u8bae&amp;zd_token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJ6aGlkYV9zZXJ2ZXIiLCJleHAiOjE3NjI4NTc3NTYsInEiOiJUQ1AvSVAg5Y2P6K6uIiwiemhpZGFfc291cmNlIjoiZW50aXR5IiwiY29udGVudF9pZCI6MTA0MzM0OTM5LCJjb250ZW50X3R5cGUiOiJBcnRpY2xlIiwibWF0Y2hfb3JkZXIiOjEsInpkX3Rva2VuIjpudWxsfQ.9lxOh9TD9MnuczIPTCuaQGYVrqY3NHMtAyD1r0omItw&amp;zhida_source=entity\" target=\"_blank\"  rel=\"nofollow\" >TCP\/IP \u534f\u8bae<\/a>\u7684\u7f3a\u9677\uff0c\u4f46\u4ed6\u4eec\u8fd8\u662f\u6709\u4e00\u5b9a\u533a\u522b\u7684\u3002<\/p>\n\n\n\n<p><strong>\u2605\u653b\u51fb\u5bf9\u8c61\u4e0d\u540c\uff1a<\/strong><\/p>\n\n\n\n<p>DDoS\u662f\u9488\u5bf9IP\u7684\u653b\u51fb\u3002<\/p>\n\n\n\n<p>CC\u653b\u51fb\u9488\u5bf9\u7684\u662f\u7f51\u9875\u3002<\/p>\n\n\n\n<p><strong>\u2605\u5371\u5bb3\u4e0d\u540c\uff1a<\/strong><\/p>\n\n\n\n<p>DDoS\u653b\u51fb\u5371\u5bb3\u6027\u8f83\u5927\uff0c\u66f4\u96be\u9632\u5fa1\u3002<\/p>\n\n\n\n<p>CC\u653b\u51fb\u7684\u5371\u5bb3\u4e0d\u662f\u6bc1\u706d\u6027\u7684\uff0c\u4f46\u662f\u6301\u7eed\u65f6\u95f4\u957f\u3002<\/p>\n\n\n\n<p><strong>\u2605\u95e8\u69db\u4e0d\u540c\uff1a<\/strong><\/p>\n\n\n\n<p>DDoS\u653b\u51fb\u95e8\u69db\u9ad8\uff0c\u653b\u51fb\u8005\u4e00\u822c\u9700\u8981\u5728\u653b\u51fb\u524d\u641c\u96c6\u88ab\u653b\u51fb\u76ee\u6807\u4e3b\u673a\u6570\u76ee\u3001\u5730\u5740\u60c5\u51b5\u3001\u76ee\u6807\u4e3b\u673a\u7684\u914d\u7f6e\u6027\u80fd\u7b49\u8d44\u6599\uff0c\u76f2\u76ee\u653b\u51fb\u53ef\u80fd\u5bfc\u81f4\u6548\u679c\u4e0d\u4f73\u3002<\/p>\n\n\n\n<p>CC\u653b\u51fb\u95e8\u69db\u4f4e\uff0c\u5229\u7528\u66f4\u6362IP\u4ee3\u7406\u5de5\u5177\u5373\u53ef\u5b9e\u65bd\u653b\u51fb\uff0c\u4e14\u76ee\u6807\u6bd4\u8f83\u660e\u786e\uff0c\u9ed1\u5ba2\u6c34\u5e73\u6bd4\u8f83\u4f4e\u7684\u7528\u6237\u4e5f\u80fd\u8fdb\u884c\u3002<\/p>\n\n\n\n<p><strong>\u2605\u6d41\u91cf\u5927\u5c0f\u4e0d\u540c\uff1a<\/strong><\/p>\n\n\n\n<p>DDoS\u653b\u51fb\u6bd4CC\u653b\u51fb\u6240\u9700\u8981\u6d41\u91cf\u66f4\u5927\uff0c\u4e14CC\u653b\u51fb\u6709\u65f6\u4e0d\u9700\u8981\u5f88\u5927\u7684\u6d41\u91cf\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">DDoS \u548c CC \u7684\u533a\u522b\uff08\u8868\u683c\uff09<\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u7279\u6027<\/th><th>DDoS (\u5206\u5e03\u5f0f\u62d2\u7edd\u670d\u52a1)<\/th><th>CC (Challenge Collapsar)<\/th><\/tr><\/thead><tbody><tr><td><strong>\u653b\u51fb\u8303\u56f4<\/strong><\/td><td>\u4e00\u4e2a\u5e7f\u4e49\u7684\u6982\u5ff5\uff0c\u5305\u542b\u591a\u79cd\u653b\u51fb\u7c7b\u578b\u3002<\/td><td>DDoS \u653b\u51fb\u4e2d\u7684\u4e00\u79cd\uff0c\u7279\u6307\u5e94\u7528\u5c42\u653b\u51fb\u3002<\/td><\/tr><tr><td><strong>\u653b\u51fb\u5c42\u7ea7<\/strong><\/td><td>\u53ef\u653b\u51fb\u7f51\u7edc\u5c42 (L3)\u3001\u4f20\u8f93\u5c42 (L4)\u3001\u5e94\u7528\u5c42 (L7)\u3002<\/td><td>\u4e13\u95e8\u9488\u5bf9\u5e94\u7528\u5c42 (L7)\u3002<\/td><\/tr><tr><td><strong>\u653b\u51fb\u76ee\u6807<\/strong><\/td><td>\u8017\u5c3d\u76ee\u6807\u5e26\u5bbd\u3001\u7f51\u7edc\u8bbe\u5907\u5904\u7406\u80fd\u529b\u3001\u670d\u52a1\u5668\u8fde\u63a5\u6570\u7b49\u3002<\/td><td>\u8017\u5c3d\u670d\u52a1\u5668\u7684 CPU\u3001\u5185\u5b58\u3001\u6570\u636e\u5e93\u8fde\u63a5\u3001\u5e94\u7528\u7a0b\u5e8f\u5904\u7406\u80fd\u529b\u7b49\u3002<\/td><\/tr><tr><td><strong>\u6d41\u91cf\u7279\u5f81<\/strong><\/td><td>\u6d41\u91cf\u5de8\u5927\uff0c\u53ef\u80fd\u5305\u542b\u5927\u91cf\u65e0\u6548\u3001\u7578\u5f62\u6216\u975e HTTP \u534f\u8bae\u7684\u8bf7\u6c42\u3002<\/td><td>\u5355\u4e2a\u8bf7\u6c42\u6d41\u91cf\u5c0f\uff0c\u4f46\u8bf7\u6c42\u6570\u91cf\u5de8\u5927\uff0c\u8bf7\u6c42\u5185\u5bb9\u901a\u5e38\u662f\u5408\u6cd5\u7684 HTTP\/HTTPS \u8bf7\u6c42\u3002<\/td><\/tr><tr><td><strong>\u8d44\u6e90\u6d88\u8017<\/strong><\/td><td>\u4e3b\u8981\u6d88\u8017\u7f51\u7edc\u5e26\u5bbd\u3001\u7f51\u7edc\u8bbe\u5907\u8d44\u6e90\u3001\u670d\u52a1\u5668\u8fde\u63a5\u8868\u3002<\/td><td>\u4e3b\u8981\u6d88\u8017\u670d\u52a1\u5668\u7684 CPU\u3001\u5185\u5b58\u3001\u6570\u636e\u5e93\u8d44\u6e90\u3001Web \u670d\u52a1\u5668\u8fdb\u7a0b\u3002<\/td><\/tr><tr><td><strong>\u68c0\u6d4b\u96be\u5ea6<\/strong><\/td><td>\u76f8\u5bf9\u5bb9\u6613\u68c0\u6d4b\uff0c\u56e0\u4e3a\u6d41\u91cf\u5f02\u5e38\u5de8\u5927\u6216\u534f\u8bae\u5f02\u5e38\u3002<\/td><td>\u76f8\u5bf9\u96be\u4ee5\u68c0\u6d4b\uff0c\u56e0\u4e3a\u8bf7\u6c42\u770b\u8d77\u6765\u50cf\u5408\u6cd5\u7528\u6237\u884c\u4e3a\u3002<\/td><\/tr><tr><td><strong>\u9632\u5fa1\u96be\u5ea6<\/strong><\/td><td>\u4f20\u7edf\u9632\u5fa1\u624b\u6bb5\uff08\u5982\u6d41\u91cf\u6e05\u6d17\u3001\u9ed1\u6d1e\u8def\u7531\uff09\u76f8\u5bf9\u6709\u6548\u3002<\/td><td>\u96be\u4ee5\u9632\u5fa1\uff0c\u9700\u8981\u66f4\u7cbe\u7ec6\u7684\u7b56\u7565\uff0c\u5982 Web \u5e94\u7528\u9632\u706b\u5899 (WAF)\u3001\u9a8c\u8bc1\u7801\u3001\u667a\u80fd\u6d41\u91cf\u5206\u6790\u3001\u884c\u4e3a\u8bc6\u522b\u3001\u9650\u6d41\u7b49\u3002<\/td><\/tr><tr><td><strong>\u653b\u51fb\u5de5\u5177<\/strong><\/td><td>LOIC, HOIC, hping3, scapy, DDoS Botnets \u7b49\u3002<\/td><td>CC \u653b\u51fb\u5de5\u5177\u3001Web \u5e94\u7528\u722c\u866b\u3001\u811a\u672c\u7b49\u3002<\/td><\/tr><tr><td><strong>\u653b\u51fb\u6548\u679c<\/strong><\/td><td>\u5bfc\u81f4\u7f51\u7edc\u62e5\u585e\u3001\u670d\u52a1\u4e2d\u65ad\u3001\u65e0\u6cd5\u5efa\u7acb\u8fde\u63a5\u3002<\/td><td>\u5bfc\u81f4\u7f51\u7ad9\u54cd\u5e94\u7f13\u6162\u3001\u6570\u636e\u5e93\u5d29\u6e83\u3001\u9875\u9762\u9519\u8bef\u3001\u670d\u52a1\u4e0d\u53ef\u7528\u3002<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">\u603b\u7ed3<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>DDoS<\/strong> \u662f\u4e00\u4e2a<strong>\u5927\u7c7b<\/strong>\uff0c\u6307\u7684\u662f\u901a\u8fc7\u5206\u5e03\u5f0f\u65b9\u5f0f\u53d1\u8d77\uff0c\u65e8\u5728\u62d2\u7edd\u670d\u52a1\u7684\u6240\u6709\u653b\u51fb\u3002\u5b83\u53ef\u4ee5\u5728\u7f51\u7edc\u7684\u4e0d\u540c\u5c42\u7ea7\u8fdb\u884c\u3002<\/li>\n\n\n\n<li><strong>CC<\/strong> \u662f DDoS \u653b\u51fb\u4e2d\u7684\u4e00\u4e2a<strong>\u5b50\u7c7b<\/strong>\uff0c\u7279\u6307<strong>\u5e94\u7528\u5c42<\/strong>\u7684 DDoS \u653b\u51fb\uff0c\u5b83\u901a\u8fc7\u6a21\u62df\u5408\u6cd5\u7528\u6237\u8bf7\u6c42\u6765\u8017\u5c3d\u670d\u52a1\u5668\u7684\u5e94\u7528\u8d44\u6e90\u3002<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Linux \u7684 SYN Cookie \u673a\u5236\u603b\u7ed3<\/h2>\n\n\n\n<p><strong>1. \u5b9a\u4e49\u4e0e\u76ee\u7684<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>SYN Cookie \u662f Linux\u3001FreeBSD \u7b49\u64cd\u4f5c\u7cfb\u7edf\u7528\u4e8e\u9632\u5fa1 <strong>SYN Flood \u653b\u51fb<\/strong>\u7684\u4e00\u79cd\u673a\u5236\u3002<\/li>\n\n\n\n<li>\u5176\u6838\u5fc3\u76ee\u7684\u662f\u5728\u670d\u52a1\u5668\u7684<strong>\u534a\u8fde\u63a5\u961f\u5217 (backlog \u961f\u5217) \u6ea2\u6ee1<\/strong>\u65f6\uff0c\u4e0d\u4e3a\u6bcf\u4e2a\u4f20\u5165\u7684 SYN \u8bf7\u6c42\u5206\u914d\u5185\u5b58\u8d44\u6e90\uff0c\u800c\u662f\u901a\u8fc7\u4e00\u79cd<strong>\u65e0\u72b6\u6001\u7684\u52a0\u5bc6\u6280\u672f<\/strong>\u6765\u9a8c\u8bc1 TCP \u8fde\u63a5\u7684\u5408\u6cd5\u6027\u3002<\/li>\n<\/ul>\n\n\n\n<p><strong>2. \u6b63\u5e38 TCP \u4e09\u6b21\u63e1\u624b\u56de\u987e<\/strong><\/p>\n\n\n\n<p>\u5728\u6b63\u5e38\u60c5\u51b5\u4e0b\uff0cTCP \u8fde\u63a5\u7684\u5efa\u7acb\u9700\u8981\u4e09\u6b21\u63e1\u624b\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u5ba2\u6237\u7aef -> \u670d\u52a1\u5668\uff1aSYN (seq=x)<\/strong><\/li>\n\n\n\n<li>\u670d\u52a1\u5668 -> \u5ba2\u6237\u7aef\uff1aSYN+ACK (seq=y, ack=x+1)\n<ul class=\"wp-block-list\">\n<li><strong>\u6b64\u65f6\uff0c\u670d\u52a1\u5668\u4f1a\u5728\u5185\u5b58\u4e2d\u8bb0\u5f55\u4e00\u6761\u534a\u5f00\u8fde\u63a5\u7684\u4fe1\u606f\uff0c\u7b49\u5f85\u5ba2\u6237\u7aef\u7684\u6700\u7ec8 ACK\u3002<\/strong><\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u5ba2\u6237\u7aef -> \u670d\u52a1\u5668\uff1aACK (seq=x+1, ack=y+1)<\/strong><\/li>\n<\/ul>\n\n\n\n<p><strong>3. SYN Cookie \u7684\u5de5\u4f5c\u539f\u7406 (\u5f53\u534a\u8fde\u63a5\u961f\u5217\u6ee1\u65f6)<\/strong><\/p>\n\n\n\n<p>\u5f53\u670d\u52a1\u5668\u7684\u5185\u5b58\u8868\uff08\u534a\u8fde\u63a5\u961f\u5217\uff09\u56e0 SYN Flood \u653b\u51fb\u800c\u5373\u5c06\u6ea2\u51fa\u65f6\uff0cSYN Cookie \u673a\u5236\u4f1a\u88ab\u6fc0\u6d3b\u3002\u5176\u5de5\u4f5c\u6d41\u7a0b\u5982\u4e0b\uff1a<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u670d\u52a1\u5668\u6536\u5230 SYN \u8bf7\u6c42\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li>\u5f53\u670d\u52a1\u5668\u7684\u534a\u8fde\u63a5\u961f\u5217\u5df2\u6ee1\uff0c\u65e0\u6cd5\u518d\u4e3a\u65b0\u7684 SYN \u8bf7\u6c42\u5206\u914d\u5185\u5b58\u8d44\u6e90\u65f6\uff0c\u5b83\u4e0d\u4f1a\u76f4\u63a5\u4e22\u5f03\u8bf7\u6c42\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u8ba1\u7b97 \"Cookie\"\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li>\u670d\u52a1\u5668\u4f1a\u6839\u636e\u4f20\u5165 SYN \u5305\u4e2d\u7684\u5173\u952e\u4fe1\u606f\uff08\u4f8b\u5982\uff1a<strong>\u5ba2\u6237\u7aef IP\u3001\u5ba2\u6237\u7aef\u7aef\u53e3\u3001\u670d\u52a1\u5668 IP\u3001\u670d\u52a1\u5668\u7aef\u53e3<\/strong>\uff09\uff0c\u4ee5\u53ca\u4e00\u4e2a<strong>\u79d8\u5bc6\u7684\u968f\u673a\u6570\/\u65f6\u95f4\u7247 (timer)<\/strong> \u7b49\u5b89\u5168\u6570\u503c\uff0c\u8fdb\u884c\u54c8\u5e0c (hash) \u8fd0\u7b97\u3002<\/li>\n\n\n\n<li>\u8fd9\u4e2a\u54c8\u5e0c\u8fd0\u7b97\u7684\u7ed3\u679c\uff0c\u5c31\u662f\u201cCookie\u201d\u3002<\/li>\n\n\n\n<li><strong>\u793a\u4f8b\u54c8\u5e0c\u7b97\u6cd5\uff1a<\/strong> <code>cookie = hash(srcIP, srcPort, dstIP, dstPort, secret, timer)<\/code><\/li>\n\n\n\n<li><strong>\u793a\u4f8b\u8ba1\u7b97\u7ed3\u679c\uff1a<\/strong> <code>cookie = 0xA1B2C3D4<\/code><\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u53d1\u9001 SYN+ACK (\u4ee5 Cookie \u4e3a ISN)\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li>\u670d\u52a1\u5668\u5c06\u8fd9\u4e2a\u8ba1\u7b97\u51fa\u6765\u7684 <strong>Cookie \u4f5c\u4e3a SYN+ACK \u5305\u7684\u521d\u59cb\u5e8f\u5217\u53f7 (ISN)<\/strong> \u53d1\u9001\u7ed9\u5ba2\u6237\u7aef\u3002<\/li>\n\n\n\n<li><strong>\u5173\u952e\u70b9\uff1a<\/strong> \u5728\u6b64\u6b65\u9aa4\u4e2d\uff0c\u670d\u52a1\u5668<strong>\u5e76\u4e0d\u5728\u5185\u5b58\u91cc\u4fdd\u5b58\u4efb\u4f55\u5173\u4e8e\u8fd9\u4e2a\u534a\u5f00\u8fde\u63a5\u7684\u72b6\u6001<\/strong>\u3002<\/li>\n\n\n\n<li><strong>\u793a\u4f8b\u670d\u52a1\u5668\u53d1\u51fa\uff1a<\/strong> <code>SYN+ACK (seq = 0xA1B2C3D4, ack = x+1)<\/code><\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u5ba2\u6237\u7aef\u56de\u590d ACK\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li>\u5408\u6cd5\u7684\u5ba2\u6237\u7aef\u6536\u5230 SYN+ACK \u5305\u540e\uff0c\u4f1a\u6309\u7167 TCP \u534f\u8bae\u7684\u89c4\u5b9a\uff0c\u56de\u590d\u4e00\u4e2a ACK \u5305\u3002<\/li>\n\n\n\n<li>\u8fd9\u4e2a ACK \u5305\u7684\u786e\u8ba4\u53f7 (ACK Number) \u5c06\u662f\u670d\u52a1\u5668\u5728 SYN+ACK \u4e2d\u53d1\u9001\u7684 ISN (\u5373 Cookie) <strong>\u52a0 1<\/strong>\u3002<\/li>\n\n\n\n<li><strong>\u793a\u4f8b\u5408\u6cd5\u5ba2\u6237\u7aef\u8fd4\u56de\uff1a<\/strong> <code>ACK (ack = 0xA1B2C3D4 + 1)<\/code><\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u670d\u52a1\u5668\u63a5\u6536 ACK \u5e76\u9a8c\u8bc1 Cookie\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li>\u670d\u52a1\u5668\u6536\u5230\u5ba2\u6237\u7aef\u7684 ACK \u5305\u540e\uff0c\u4f1a\u6267\u884c\u4ee5\u4e0b\u6b65\u9aa4\uff1a\n<ol class=\"wp-block-list\">\n<li><strong>\u91cd\u65b0\u8ba1\u7b97 Cookie\uff1a<\/strong> \u670d\u52a1\u5668\u4f1a\u7528<strong>\u76f8\u540c\u7684\u54c8\u5e0c\u516c\u5f0f\u548c\u53c2\u6570<\/strong>\uff08\u4ece\u6536\u5230\u7684 ACK \u5305\u4e2d\u63d0\u53d6\u7684\u5ba2\u6237\u7aef IP\/\u7aef\u53e3\u3001\u670d\u52a1\u5668 IP\/\u7aef\u53e3\uff0c\u4ee5\u53ca\u5f53\u524d\u65f6\u95f4\u7247\u548c\u79d8\u94a5\uff09<strong>\u91cd\u65b0\u8ba1\u7b97<\/strong>\u4e00\u4e2a\u9884\u671f\u7684 Cookie (<code>expected_cookie<\/code>)\u3002<\/li>\n\n\n\n<li><strong>\u8fdb\u884c\u6bd4\u8f83\uff1a<\/strong> \u670d\u52a1\u5668\u5c06\u5ba2\u6237\u7aef ACK \u5305\u4e2d\u7684\u786e\u8ba4\u53f7<strong>\u51cf 1<\/strong> (<code>ack - 1<\/code>)\uff0c\u4e0e\u91cd\u65b0\u8ba1\u7b97\u51fa\u7684 <code>expected_cookie<\/code> \u8fdb\u884c\u6bd4\u8f83\u3002<\/li>\n\n\n\n<li>\u5224\u65ad\u5408\u6cd5\u6027\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u5982\u679c\u4e24\u8005\u76f8\u7b49\uff1a<\/strong> \u8868\u793a\u8fd9\u662f\u4e00\u4e2a\u771f\u5b9e\u7684\u5ba2\u6237\u7aef\u8fd4\u56de\u7684\u6709\u6548 ACK\u3002<\/li>\n\n\n\n<li><strong>\u4e8e\u662f\uff0c\u670d\u52a1\u5668\u6b64\u65f6\u624d\u5206\u914d\u5185\u5b58\u8d44\u6e90\u5e76\u5efa\u7acb\u8fde\u63a5\u3002<\/strong><\/li>\n\n\n\n<li><strong>\u5982\u679c\u4e24\u8005\u4e0d\u76f8\u7b49\uff1a<\/strong> \u8868\u793a\u8fd9\u662f\u4e00\u4e2a\u4f2a\u9020\u7684 ACK \u5305\uff0c\u670d\u52a1\u5668\u4f1a\u76f4\u63a5\u4e22\u5f03\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n\n\n\n<p><strong>4. \u9632\u5fa1 SYN Flood \u7684\u539f\u7406<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u5bf9\u653b\u51fb\u8005\u65e0\u6548\uff1a<\/strong> \u4f2a\u9020\u6e90 IP \u7684\u653b\u51fb\u8005\u65e0\u6cd5\u63a5\u6536\u5230\u670d\u52a1\u5668\u8fd4\u56de\u7684\u5e26\u6709\u6b63\u786e Cookie (\u4f5c\u4e3a ISN) \u7684 SYN+ACK \u5305\u3002\u56e0\u6b64\uff0c\u653b\u51fb\u8005\u65e0\u6cd5\u6784\u9020\u51fa\u6b63\u786e\u7684 ACK \u5305\uff08\u5373 <code>Cookie + 1<\/code>\uff09\u6765\u5b8c\u6210\u4e09\u6b21\u63e1\u624b\u3002<\/li>\n\n\n\n<li><strong>\u8d44\u6e90\u4fdd\u62a4\uff1a<\/strong> \u670d\u52a1\u5668\u5728\u9a8c\u8bc1 ACK \u4e4b\u524d\u4e0d\u5206\u914d\u4efb\u4f55\u5185\u5b58\u8d44\u6e90\uff0c\u4ece\u800c\u6709\u6548\u9632\u6b62\u4e86 SYN Flood \u653b\u51fb\u8017\u5c3d\u670d\u52a1\u5668\u7684\u8fde\u63a5\u961f\u5217\u548c\u5185\u5b58\u8d44\u6e90\uff0c\u786e\u4fdd\u4e86\u5408\u6cd5\u7528\u6237\u4ecd\u80fd\u5efa\u7acb\u8fde\u63a5\u3002<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Windows Server \u7684 SYN Flood \u9632\u5fa1\u673a\u5236<\/h2>\n\n\n\n<p>Windows Server \u7684 TCP\/IP \u5806\u6808\u7ecf\u8fc7\u4f18\u5316\uff0c\u65e8\u5728\u62b5\u5fa1 SYN Flood \u653b\u51fb\uff0c\u5176\u4e3b\u8981\u901a\u8fc7\u4ee5\u4e0b\u51e0\u79cd\u65b9\u5f0f\u534f\u540c\u5de5\u4f5c\uff1a<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>TCP\/IP \u5806\u6808\u5f3a\u5316\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li>Windows \u7684\u7f51\u7edc\u5806\u6808\u8bbe\u8ba1\u5f97\u66f4\u52a0\u5065\u58ee\uff0c\u80fd\u591f\u66f4\u597d\u5730\u5904\u7406\u9ad8\u5e76\u53d1\u8fde\u63a5\u548c\u5f02\u5e38\u6d41\u91cf\uff0c\u800c\u4e0d\u4f1a\u8f7b\u6613\u5d29\u6e83\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u52a8\u6001\u8c03\u6574\u534a\u5f00\u8fde\u63a5\u961f\u5217\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li>Windows Server \u4f1a\u6839\u636e\u5f53\u524d\u7684\u7cfb\u7edf\u8d44\u6e90\uff08\u5982\u5185\u5b58\u3001CPU\uff09\u548c\u68c0\u6d4b\u5230\u7684\u7f51\u7edc\u72b6\u51b5\uff0c<strong>\u52a8\u6001\u8c03\u6574\u5176\u534a\u5f00\u8fde\u63a5\u961f\u5217\uff08backlog queue\uff09\u7684\u5927\u5c0f<\/strong>\u3002\u8fd9\u610f\u5473\u7740\u5728\u68c0\u6d4b\u5230\u653b\u51fb\u65f6\uff0c\u5b83\u53ef\u80fd\u4f1a\u4e34\u65f6\u589e\u52a0\u961f\u5217\u5bb9\u91cf\uff0c\u4ee5\u5bb9\u7eb3\u66f4\u591a\u5408\u6cd5\u8fde\u63a5\uff0c\u540c\u65f6\u4e5f\u4f1a\u6709\u7b56\u7565\u5730\u7ba1\u7406\u8fd9\u4e9b\u8fde\u63a5\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u66f4\u5feb\u7684\u8d85\u65f6\u548c\u91cd\u8bd5\u673a\u5236\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li>\u5bf9\u4e8e\u90a3\u4e9b\u957f\u65f6\u95f4\u672a\u5b8c\u6210\u4e09\u6b21\u63e1\u624b\u7684\u534a\u5f00\u8fde\u63a5\uff0cWindows \u4f1a\u6bd4\u6b63\u5e38\u60c5\u51b5\u4e0b<strong>\u66f4\u5feb\u5730\u5c06\u5176\u8d85\u65f6\u5e76\u91ca\u653e\u6240\u5360\u7528\u7684\u8d44\u6e90<\/strong>\u3002\u8fd9\u53ef\u4ee5\u9632\u6b62\u653b\u51fb\u8005\u957f\u65f6\u95f4\u5360\u7528\u670d\u52a1\u5668\u8d44\u6e90\u3002<\/li>\n\n\n\n<li>\u5b83\u8fd8\u4f1a\u9650\u5236\u5bf9\u534a\u5f00\u8fde\u63a5\u8fdb\u884c SYN\/ACK \u91cd\u8bd5\u7684\u6b21\u6570\uff0c\u4e00\u65e6\u8fbe\u5230\u91cd\u8bd5\u4e0a\u9650\uff0c\u5c31\u4f1a\u4e22\u5f03\u8be5\u534a\u5f00\u8fde\u63a5\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u8fde\u63a5\u9650\u5236\u548c\u4e22\u5f03\u7b56\u7565\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li>\u5f53\u68c0\u6d4b\u5230\u6765\u81ea\u540c\u4e00\u6e90 IP \u5730\u5740\u6216\u5177\u6709\u76f8\u4f3c\u7279\u5f81\u7684\u5f02\u5e38\u9ad8\u9891\u7387 SYN \u8bf7\u6c42\u65f6\uff0cWindows \u53ef\u80fd\u4f1a\u91c7\u53d6\u7b56\u7565\uff0c\u4f8b\u5982\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u9650\u5236\u6765\u81ea\u540c\u4e00\u6e90 IP \u7684\u8fde\u63a5\u6570\u3002<\/strong><\/li>\n\n\n\n<li><strong>\u76f4\u63a5\u4e22\u5f03\u88ab\u8ba4\u4e3a\u662f\u6076\u610f\u7684 SYN \u8bf7\u6c42\u3002<\/strong><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u6ce8\u518c\u8868\u914d\u7f6e\uff08\u7528\u4e8e\u5fae\u8c03\uff09\uff1a<\/strong> \u867d\u7136\u9ed8\u8ba4\u914d\u7f6e\u5df2\u7ecf\u5f88\u5f3a\u5927\uff0c\u4f46 Windows \u63d0\u4f9b\u4e86\u591a\u4e2a\u6ce8\u518c\u8868\u952e\u503c\uff0c\u5141\u8bb8\u7ba1\u7406\u5458\u5bf9 SYN Flood \u9632\u5fa1\u884c\u4e3a\u8fdb\u884c\u66f4\u7cbe\u7ec6\u7684\u63a7\u5236\u548c\u5fae\u8c03\u3002\u8fd9\u4e9b\u952e\u503c\u901a\u5e38\u4f4d\u4e8e <code>HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Tcpip\\Parameters<\/code> \u4e0b\uff0c\u5e38\u89c1\u7684\u5305\u62ec\uff1a\n<ul class=\"wp-block-list\">\n<li><code>TcpMaxHalfOpen<\/code>\uff1a\u63a7\u5236\u5141\u8bb8\u7684\u6700\u5927\u534a\u5f00\u8fde\u63a5\u6570\u3002<\/li>\n\n\n\n<li><code>TcpMaxHalfOpenRetried<\/code>\uff1a\u63a7\u5236\u5141\u8bb8\u7684\u6700\u5927\u5df2\u91cd\u8bd5\u534a\u5f00\u8fde\u63a5\u6570\uff08\u5373\u670d\u52a1\u5668\u5df2\u53d1\u9001\u8fc7 SYN\/ACK \u4f46\u672a\u6536\u5230 ACK \u7684\u8fde\u63a5\uff09\u3002<\/li>\n\n\n\n<li><code>SynAttackProtect<\/code> (\u5728\u8f83\u65e7\u7684 Windows \u7248\u672c\u4e2d\u66f4\u4e3a\u5e38\u89c1\uff0c\u65b0\u7248\u672c\u53ef\u80fd\u7531\u9ed8\u8ba4\u884c\u4e3a\u548c\u66f4\u667a\u80fd\u7684\u7b97\u6cd5\u53d6\u4ee3)\uff1a\u4e00\u4e2a\u5f00\u5173\uff0c\u7528\u4e8e\u542f\u7528\u6216\u7981\u7528\u4e00\u4e9b SYN \u653b\u51fb\u4fdd\u62a4\u529f\u80fd\u3002<\/li>\n\n\n\n<li><code>TcpMaxConnectRetransmissions<\/code>\uff1a\u63a7\u5236 TCP \u8fde\u63a5\u91cd\u4f20 SYN\/ACK \u7684\u6700\u5927\u6b21\u6570\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>Windows Defender Firewall \/ \u7b2c\u4e09\u65b9\u9632\u706b\u5899\/IPS\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li>Windows Server \u81ea\u5e26\u7684\u9632\u706b\u5899\u53ef\u4ee5\u914d\u7f6e\u89c4\u5219\u6765\u9650\u5236\u5165\u7ad9 SYN \u6d41\u91cf\u7684\u901f\u7387\u3002<\/li>\n\n\n\n<li>\u7ed3\u5408\u7b2c\u4e09\u65b9\u5165\u4fb5\u9632\u5fa1\u7cfb\u7edf (IPS) \u6216\u4e13\u4e1a\u7684 DDoS \u9632\u5fa1\u8bbe\u5907\uff0c\u53ef\u4ee5\u63d0\u4f9b\u66f4\u9ad8\u7ea7\u7684\u6d41\u91cf\u5206\u6790\u548c\u8fc7\u6ee4\u529f\u80fd\uff0c\u8bc6\u522b\u5e76\u963b\u6b62 SYN Flood \u653b\u51fb\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">\u603b\u7ed3\u533a\u522b<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Linux SYN Cookie\uff1a<\/strong> \u662f\u4e00\u79cd<strong>\u65e0\u72b6\u6001<\/strong>\u7684\u9632\u5fa1\u673a\u5236\u3002\u5728\u653b\u51fb\u671f\u95f4\uff0c\u670d\u52a1\u5668\u5728\u6536\u5230 SYN \u540e\uff0c\u4e0d\u4e3a\u8fde\u63a5\u5206\u914d\u8d44\u6e90\uff0c\u800c\u662f\u5c06\u8fde\u63a5\u4fe1\u606f\u7f16\u7801\u5230 SYN\/ACK \u7684 ISN \u4e2d\u3002\u53ea\u6709\u5f53\u5ba2\u6237\u7aef\u8fd4\u56de\u6b63\u786e\u7684 ACK \u540e\uff0c\u670d\u52a1\u5668\u624d\u5206\u914d\u8d44\u6e90\u3002<\/li>\n\n\n\n<li><strong>Windows Server \u9632\u5fa1\uff1a<\/strong> \u662f\u4e00\u79cd<strong>\u6709\u72b6\u6001\u4f46\u9ad8\u5ea6\u4f18\u5316<\/strong>\u7684\u9632\u5fa1\u673a\u5236\u3002\u5b83\u4ecd\u7136\u4f1a\u4e3a\u534a\u5f00\u8fde\u63a5\u5206\u914d\u4e00\u4e9b\u8d44\u6e90\uff0c\u4f46\u4f1a\u901a\u8fc7\u52a8\u6001\u8c03\u6574\u961f\u5217\u5927\u5c0f\u3001\u66f4\u5feb\u7684\u8d85\u65f6\u3001\u9650\u5236\u91cd\u8bd5\u6b21\u6570\u4ee5\u53ca\u667a\u80fd\u4e22\u5f03\u7b56\u7565\u6765\u79ef\u6781\u7ba1\u7406\u8fd9\u4e9b\u8d44\u6e90\uff0c\u4ee5\u9632\u6b62\u8d44\u6e90\u8017\u5c3d\u3002<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Socket (\u5957\u63a5\u5b57) \u662f\u4ec0\u4e48\uff1f<\/h2>\n\n\n\n<p>\u4f60\u53ef\u4ee5\u628a Socket \u7406\u89e3\u4e3a<strong>\u5e94\u7528\u7a0b\u5e8f\u4e0e\u7f51\u7edc\u4e4b\u95f4\u8fdb\u884c\u901a\u4fe1\u7684\u201c\u63a5\u53e3\u201d\u6216\u201c\u7aef\u53e3\u201d<\/strong>\u3002\u5b83\u662f\u4e00\u4e2a\u62bd\u8c61\u5c42\uff0c\u7531\u64cd\u4f5c\u7cfb\u7edf\u63d0\u4f9b\uff0c\u5141\u8bb8\u5e94\u7528\u7a0b\u5e8f\u901a\u8fc7\u5b83\u6765\u53d1\u9001\u548c\u63a5\u6536\u6570\u636e\uff0c\u4ece\u800c\u5b9e\u73b0\u7f51\u7edc\u4e0a\u7684\u8fdb\u7a0b\u95f4\u901a\u4fe1\uff08IPC\uff09\u3002<\/p>\n\n\n\n<p>\u66f4\u5f62\u8c61\u5730\u8bf4\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u5982\u679c\u628a\u7f51\u7edc\u901a\u4fe1\u6bd4\u4f5c\u6253\u7535\u8bdd\uff0c\u90a3\u4e48 <strong>Socket \u5c31\u662f\u4f60\u7684\u201c\u7535\u8bdd\u673a\u201d<\/strong>\u3002<\/li>\n\n\n\n<li>\u4f60\u7684\u7535\u8bdd\u673a\u9700\u8981\u4e00\u4e2a<strong>\u7535\u8bdd\u53f7\u7801\uff08IP \u5730\u5740 + \u7aef\u53e3\u53f7\uff09<\/strong>\u624d\u80fd\u4e0e\u522b\u4eba\u901a\u8bdd\u3002<\/li>\n\n\n\n<li>Socket \u5c31\u662f\u4f60\u7684\u5e94\u7528\u7a0b\u5e8f\u7528\u6765\u201c\u62e8\u53f7\u201d\u548c\u201c\u63a5\u542c\u201d\u7684\u5de5\u5177\u3002<\/li>\n<\/ul>\n\n\n\n<p><strong>\u6838\u5fc3\u601d\u60f3\uff1a<\/strong><\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u901a\u4fe1\u7aef\u70b9\uff1a<\/strong> Socket \u662f\u7f51\u7edc\u901a\u4fe1\u4e2d\u7684\u4e00\u4e2a\u7aef\u70b9\uff0c\u5b83\u6807\u8bc6\u4e86\u7f51\u7edc\u4e0a\u4e00\u4e2a\u7279\u5b9a\u7684\u8fdb\u7a0b\u3002<\/li>\n\n\n\n<li><strong>\u64cd\u4f5c\u7cfb\u7edf\u63d0\u4f9b\uff1a<\/strong> \u5b83\u662f\u7531\u64cd\u4f5c\u7cfb\u7edf\u5185\u6838\u63d0\u4f9b\u7684\u7f16\u7a0b\u63a5\u53e3\uff0c\u9690\u85cf\u4e86\u5e95\u5c42\u590d\u6742\u7684\u7f51\u7edc\u534f\u8bae\u7ec6\u8282\uff08\u5982 TCP\/IP \u534f\u8bae\u6808\uff09\u3002<\/li>\n\n\n\n<li>IP + \u7aef\u53e3\uff1a \u5bf9\u4e8e\u7f51\u7edc Socket \u800c\u8a00\uff0c\u5b83\u901a\u5e38\u4e0e\u4e00\u4e2a IP \u5730\u5740\u548c\u4e00\u4e2a \u7aef\u53e3\u53f7 \u7ed1\u5b9a\u3002\n<ul class=\"wp-block-list\">\n<li><strong>IP \u5730\u5740\uff1a<\/strong> \u6807\u8bc6\u7f51\u7edc\u4e2d\u7684\u4e00\u53f0\u4e3b\u673a\u3002<\/li>\n\n\n\n<li><strong>\u7aef\u53e3\u53f7\uff1a<\/strong> \u6807\u8bc6\u4e3b\u673a\u4e0a\u8fd0\u884c\u7684\u4e00\u4e2a\u7279\u5b9a\u5e94\u7528\u7a0b\u5e8f\u6216\u670d\u52a1\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">Socket \u7684\u7c7b\u578b<\/h3>\n\n\n\n<p>Socket \u4e3b\u8981\u6709\u4ee5\u4e0b\u51e0\u79cd\u7c7b\u578b\uff0c\u5b83\u4eec\u5bf9\u5e94\u7740\u4e0d\u540c\u7684\u901a\u4fe1\u534f\u8bae\u548c\u7279\u6027\uff1a<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u6d41\u5f0f\u5957\u63a5\u5b57 (Stream Sockets) - \u57fa\u4e8e TCP \u534f\u8bae<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u7c7b\u578b\uff1a<\/strong> <code>SOCK_STREAM<\/code><\/li>\n\n\n\n<li>\u7279\u70b9\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u9762\u5411\u8fde\u63a5\uff1a<\/strong> \u5728\u6570\u636e\u4f20\u8f93\u524d\u5fc5\u987b\u5efa\u7acb\u8fde\u63a5\uff08TCP \u4e09\u6b21\u63e1\u624b\uff09\u3002<\/li>\n\n\n\n<li><strong>\u53ef\u9760\u4f20\u8f93\uff1a<\/strong> \u4fdd\u8bc1\u6570\u636e\u6309\u987a\u5e8f\u3001\u65e0\u5dee\u9519\u5730\u5230\u8fbe\u3002\u5982\u679c\u6570\u636e\u4e22\u5931\u6216\u635f\u574f\uff0c\u4f1a\u81ea\u52a8\u91cd\u4f20\u3002<\/li>\n\n\n\n<li><strong>\u5b57\u8282\u6d41\u4f20\u8f93\uff1a<\/strong> \u6570\u636e\u4ee5\u5b57\u8282\u6d41\u7684\u5f62\u5f0f\u53d1\u9001\uff0c\u6ca1\u6709\u6d88\u606f\u8fb9\u754c\u3002<\/li>\n\n\n\n<li><strong>\u5168\u53cc\u5de5\uff1a<\/strong> \u6570\u636e\u53ef\u4ee5\u540c\u65f6\u53cc\u5411\u4f20\u8f93\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u7c7b\u6bd4\uff1a<\/strong> \u5c31\u50cf\u6253\u7535\u8bdd\uff0c\u5148\u5efa\u7acb\u8fde\u63a5\uff0c\u7136\u540e\u7a33\u5b9a\u5730\u5bf9\u8bdd\u3002<\/li>\n\n\n\n<li><strong>\u5e94\u7528\uff1a<\/strong> \u7edd\u5927\u591a\u6570\u9700\u8981\u53ef\u9760\u4f20\u8f93\u7684\u5e94\u7528\uff0c\u5982 HTTP (\u7f51\u9875\u6d4f\u89c8)\u3001FTP (\u6587\u4ef6\u4f20\u8f93)\u3001SSH (\u8fdc\u7a0b\u767b\u5f55)\u3001SMTP (\u90ae\u4ef6\u53d1\u9001) \u7b49\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u6570\u636e\u62a5\u5957\u63a5\u5b57 (Datagram Sockets) - \u57fa\u4e8e UDP \u534f\u8bae<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u7c7b\u578b\uff1a<\/strong> <code>SOCK_DGRAM<\/code><\/li>\n\n\n\n<li>\u7279\u70b9\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u65e0\u8fde\u63a5\uff1a<\/strong> \u6570\u636e\u53d1\u9001\u524d\u65e0\u9700\u5efa\u7acb\u8fde\u63a5\uff0c\u76f4\u63a5\u53d1\u9001\u3002<\/li>\n\n\n\n<li><strong>\u4e0d\u53ef\u9760\u4f20\u8f93\uff1a<\/strong> \u4e0d\u4fdd\u8bc1\u6570\u636e\u4e00\u5b9a\u5230\u8fbe\uff0c\u4e5f\u4e0d\u4fdd\u8bc1\u987a\u5e8f\u3002\u6570\u636e\u5305\u53ef\u80fd\u4e22\u5931\u3001\u91cd\u590d\u6216\u4e71\u5e8f\u3002<\/li>\n\n\n\n<li><strong>\u6709\u6d88\u606f\u8fb9\u754c\uff1a<\/strong> \u6570\u636e\u4ee5\u72ec\u7acb\u7684\u6570\u636e\u62a5\u5f62\u5f0f\u53d1\u9001\uff0c\u6bcf\u4e2a\u6570\u636e\u62a5\u90fd\u662f\u4e00\u4e2a\u72ec\u7acb\u7684\u6d88\u606f\u3002<\/li>\n\n\n\n<li><strong>\u5f00\u9500\u5c0f\uff1a<\/strong> \u7531\u4e8e\u6ca1\u6709\u8fde\u63a5\u7ba1\u7406\u548c\u53ef\u9760\u6027\u4fdd\u8bc1\uff0c\u4f20\u8f93\u6548\u7387\u9ad8\uff0c\u5ef6\u8fdf\u4f4e\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u7c7b\u6bd4\uff1a<\/strong> \u5c31\u50cf\u5bc4\u660e\u4fe1\u7247\uff0c\u53d1\u51fa\u53bb\u5c31\u4e0d\u7ba1\u4e86\uff0c\u4e0d\u4fdd\u8bc1\u5bf9\u65b9\u4e00\u5b9a\u6536\u5230\uff0c\u4e5f\u4e0d\u4fdd\u8bc1\u6309\u987a\u5e8f\u6536\u5230\u3002<\/li>\n\n\n\n<li><strong>\u5e94\u7528\uff1a<\/strong> \u5bf9\u5b9e\u65f6\u6027\u8981\u6c42\u9ad8\u3001\u5bf9\u5c11\u91cf\u6570\u636e\u4e22\u5931\u4e0d\u654f\u611f\u7684\u5e94\u7528\uff0c\u5982 DNS (\u57df\u540d\u89e3\u6790)\u3001NTP (\u7f51\u7edc\u65f6\u95f4\u534f\u8bae)\u3001SNMP (\u7f51\u7edc\u7ba1\u7406\u534f\u8bae)\u3001\u5728\u7ebf\u6e38\u620f\u3001VoIP (\u7f51\u7edc\u7535\u8bdd) \u7b49\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u539f\u59cb\u5957\u63a5\u5b57 (Raw Sockets)<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u7c7b\u578b\uff1a<\/strong> <code>SOCK_RAW<\/code><\/li>\n\n\n\n<li>\u7279\u70b9\uff1a\n<ul class=\"wp-block-list\">\n<li>\u5141\u8bb8\u5e94\u7528\u7a0b\u5e8f\u76f4\u63a5\u8bbf\u95ee IP \u5c42\u6216\u66f4\u4f4e\u5c42\u7684\u6570\u636e\u5305\uff0c\u7ed5\u8fc7\u4f20\u8f93\u5c42\u534f\u8bae\uff08TCP\/UDP\uff09\u3002<\/li>\n\n\n\n<li>\u53ef\u4ee5\u7528\u4e8e\u53d1\u9001\u6216\u63a5\u6536\u81ea\u5b9a\u4e49\u534f\u8bae\u7684\u6570\u636e\u5305\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u5e94\u7528\uff1a<\/strong> \u7f51\u7edc\u8bca\u65ad\u5de5\u5177\uff08\u5982 <code>ping<\/code>\u3001<code>traceroute<\/code>\uff09\u3001\u81ea\u5b9a\u4e49\u7f51\u7edc\u534f\u8bae\u7684\u5b9e\u73b0\u3001\u7f51\u7edc\u55c5\u63a2\u3001\u7f51\u7edc\u653b\u51fb\u5de5\u5177\u7b49\u3002\u901a\u5e38\u9700\u8981\u7ba1\u7406\u5458\u6743\u9650\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">Socket \u7684\u751f\u547d\u5468\u671f (\u4ee5 TCP \u4e3a\u4f8b)<\/h3>\n\n\n\n<p><strong>\u670d\u52a1\u5668\u7aef\uff1a<\/strong><\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong><code>socket()<\/code>\uff1a<\/strong> \u521b\u5efa\u4e00\u4e2a\u5957\u63a5\u5b57\u3002<\/li>\n\n\n\n<li><strong><code>bind()<\/code>\uff1a<\/strong> \u5c06\u5957\u63a5\u5b57\u7ed1\u5b9a\u5230\u670d\u52a1\u5668\u7684 IP \u5730\u5740\u548c\u7aef\u53e3\u53f7\u3002<\/li>\n\n\n\n<li><strong><code>listen()<\/code>\uff1a<\/strong> \u4f7f\u5957\u63a5\u5b57\u8fdb\u5165\u76d1\u542c\u72b6\u6001\uff0c\u7b49\u5f85\u5ba2\u6237\u7aef\u8fde\u63a5\u8bf7\u6c42\u3002<\/li>\n\n\n\n<li><strong><code>accept()<\/code>\uff1a<\/strong> \u963b\u585e\u7b49\u5f85\uff0c\u5f53\u6709\u5ba2\u6237\u7aef\u8fde\u63a5\u8bf7\u6c42\u5230\u8fbe\u65f6\uff0c\u63a5\u53d7\u8fde\u63a5\u5e76\u8fd4\u56de\u4e00\u4e2a\u65b0\u7684\u5957\u63a5\u5b57\uff0c\u7528\u4e8e\u4e0e\u8be5\u5ba2\u6237\u7aef\u8fdb\u884c\u901a\u4fe1\u3002<\/li>\n\n\n\n<li><strong><code>send()<\/code> \/ <code>recv()<\/code>\uff1a<\/strong> \u4f7f\u7528\u65b0\u7684\u5957\u63a5\u5b57\u4e0e\u5ba2\u6237\u7aef\u4ea4\u6362\u6570\u636e\u3002<\/li>\n\n\n\n<li><strong><code>close()<\/code>\uff1a<\/strong> \u5173\u95ed\u4e0e\u5ba2\u6237\u7aef\u901a\u4fe1\u7684\u5957\u63a5\u5b57\u3002<\/li>\n<\/ol>\n\n\n\n<p><strong>\u5ba2\u6237\u7aef\uff1a<\/strong><\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong><code>socket()<\/code>\uff1a<\/strong> \u521b\u5efa\u4e00\u4e2a\u5957\u63a5\u5b57\u3002<\/li>\n\n\n\n<li><strong><code>connect()<\/code>\uff1a<\/strong> \u5411\u670d\u52a1\u5668\u7684 IP \u5730\u5740\u548c\u7aef\u53e3\u53f7\u53d1\u8d77\u8fde\u63a5\u8bf7\u6c42\u3002<\/li>\n\n\n\n<li><strong><code>send()<\/code> \/ <code>recv()<\/code>\uff1a<\/strong> \u4e0e\u670d\u52a1\u5668\u4ea4\u6362\u6570\u636e\u3002<\/li>\n\n\n\n<li><strong><code>close()<\/code>\uff1a<\/strong> \u5173\u95ed\u5957\u63a5\u5b57\u3002<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">Socket \u7528\u5728\u4ec0\u4e48\u4e0a\u9762\uff1f<\/h3>\n\n\n\n<p>Socket \u662f\u6240\u6709\u7f51\u7edc\u901a\u4fe1\u7684\u57fa\u77f3\uff0c\u51e0\u4e4e\u6240\u6709\u9700\u8981\u901a\u8fc7\u7f51\u7edc\u8fdb\u884c\u6570\u636e\u4ea4\u6362\u7684\u5e94\u7528\u7a0b\u5e8f\u90fd\u4f1a\u7528\u5230\u5b83\u3002\u5177\u4f53\u5305\u62ec\uff1a<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Web \u5e94\u7528\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>Web \u6d4f\u89c8\u5668 (\u5ba2\u6237\u7aef)\uff1a<\/strong> \u4f7f\u7528 Socket \u8fde\u63a5\u5230 Web \u670d\u52a1\u5668\uff08\u901a\u5e38\u662f 80 \u7aef\u53e3\u7528\u4e8e HTTP\uff0c443 \u7aef\u53e3\u7528\u4e8e HTTPS\uff09\uff0c\u53d1\u9001 HTTP \u8bf7\u6c42\uff0c\u63a5\u6536\u5e76\u663e\u793a\u7f51\u9875\u5185\u5bb9\u3002<\/li>\n\n\n\n<li><strong>Web \u670d\u52a1\u5668 (\u670d\u52a1\u7aef)\uff1a<\/strong> \u76d1\u542c 80\/443 \u7aef\u53e3\uff0c\u63a5\u53d7\u5ba2\u6237\u7aef\u8fde\u63a5\uff0c\u5904\u7406 HTTP \u8bf7\u6c42\uff0c\u8fd4\u56de\u7f51\u9875\u3001\u56fe\u7247\u3001API \u6570\u636e\u7b49\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>\u6587\u4ef6\u4f20\u8f93\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>FTP \u5ba2\u6237\u7aef\/\u670d\u52a1\u5668\uff1a<\/strong> \u7528\u4e8e\u4e0a\u4f20\u548c\u4e0b\u8f7d\u6587\u4ef6\u3002<\/li>\n\n\n\n<li><strong>P2P \u6587\u4ef6\u5171\u4eab\uff1a<\/strong> \u5982 BitTorrent\uff0c\u5ba2\u6237\u7aef\u4e4b\u95f4\u76f4\u63a5\u901a\u8fc7 Socket \u4ea4\u6362\u6587\u4ef6\u5757\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>\u7535\u5b50\u90ae\u4ef6\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u90ae\u4ef6\u5ba2\u6237\u7aef\/\u670d\u52a1\u5668\uff1a<\/strong> \u4f7f\u7528 Socket \u8fdb\u884c\u90ae\u4ef6\u7684\u53d1\u9001 (SMTP) \u548c\u63a5\u6536 (POP3\/IMAP)\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>\u8fdc\u7a0b\u8bbf\u95ee\u548c\u63a7\u5236\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>SSH (Secure Shell)\uff1a<\/strong> \u5ba2\u6237\u7aef\u901a\u8fc7 Socket \u8fde\u63a5\u5230\u8fdc\u7a0b\u670d\u52a1\u5668\uff0c\u5efa\u7acb\u52a0\u5bc6\u901a\u9053\u8fdb\u884c\u547d\u4ee4\u884c\u64cd\u4f5c\u3002<\/li>\n\n\n\n<li><strong>RDP (Remote Desktop Protocol)\uff1a<\/strong> \u8fdc\u7a0b\u684c\u9762\u8fde\u63a5\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>\u6570\u636e\u5e93\u8fde\u63a5\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u6570\u636e\u5e93\u5ba2\u6237\u7aef\uff1a<\/strong> \u901a\u8fc7 Socket \u8fde\u63a5\u5230\u6570\u636e\u5e93\u670d\u52a1\u5668\uff0c\u53d1\u9001 SQL \u67e5\u8be2\uff0c\u63a5\u6536\u67e5\u8be2\u7ed3\u679c\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>\u5b9e\u65f6\u901a\u4fe1\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u5373\u65f6\u901a\u8baf\u8f6f\u4ef6 (\u5982\u5fae\u4fe1\u3001QQ)\uff1a<\/strong> \u6d88\u606f\u53d1\u9001\u548c\u63a5\u6536\u3002<\/li>\n\n\n\n<li><strong>VoIP (\u7f51\u7edc\u7535\u8bdd)\uff1a<\/strong> \u8bed\u97f3\u548c\u89c6\u9891\u6570\u636e\u4f20\u8f93\u3002<\/li>\n\n\n\n<li><strong>\u5728\u7ebf\u6e38\u620f\uff1a<\/strong> \u5ba2\u6237\u7aef\u4e0e\u6e38\u620f\u670d\u52a1\u5668\u4e4b\u95f4\u5b9e\u65f6\u540c\u6b65\u6e38\u620f\u72b6\u6001\u548c\u73a9\u5bb6\u64cd\u4f5c\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>\u7269\u8054\u7f51 (IoT) \u8bbe\u5907\uff1a\n<ul class=\"wp-block-list\">\n<li>\u667a\u80fd\u5bb6\u5c45\u8bbe\u5907\u3001\u4f20\u611f\u5668\u7b49\u901a\u8fc7 Socket \u5c06\u6570\u636e\u53d1\u9001\u5230\u4e91\u5e73\u53f0\u6216\u63a7\u5236\u4e2d\u5fc3\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>\u81ea\u5b9a\u4e49\u7f51\u7edc\u670d\u52a1\uff1a\n<ul class=\"wp-block-list\">\n<li>\u4efb\u4f55\u9700\u8981\u5b9e\u73b0\u7279\u5b9a\u7f51\u7edc\u534f\u8bae\u6216\u670d\u52a1\u7684\u5e94\u7528\u7a0b\u5e8f\uff0c\u90fd\u53ef\u4ee5\u4f7f\u7528 Socket \u8fdb\u884c\u7f16\u7a0b\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\">\u5957\u63a5\u5b57\u4e0d\u662f\u7aef\u53e3\uff0c\u4e24\u8005\u533a\u522b<\/h2>\n\n\n\n<p><strong>Socket (\u5957\u63a5\u5b57) \u4e0d\u662f\u7aef\u53e3<\/strong>\u3002<\/p>\n\n\n\n<p>\u8fd9\u662f\u4e00\u4e2a\u975e\u5e38\u5e38\u89c1\u7684\u6df7\u6dc6\u70b9\uff0c\u6211\u4eec\u6765\u5f7b\u5e95\u7406\u6e05\u5b83\u4eec\u4e4b\u95f4\u7684\u5173\u7cfb\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u6838\u5fc3\u533a\u522b<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u7aef\u53e3 (Port)\uff1a<\/strong> \u4ec5\u4ec5\u662f\u4e00\u4e2a<strong>\u6570\u5b57\u6807\u8bc6\u7b26<\/strong>\u3002\u5b83\u7684\u4f5c\u7528\u662f\u533a\u5206\u4e00\u53f0\u4e3b\u673a\u4e0a\u4e0d\u540c\u7684\u5e94\u7528\u7a0b\u5e8f\u6216\u670d\u52a1\u3002\n<ul class=\"wp-block-list\">\n<li>\u4f8b\u5982\uff0cWeb \u670d\u52a1\u5668\u901a\u5e38\u4f7f\u7528 80 \u7aef\u53e3 (HTTP) \u6216 443 \u7aef\u53e3 (HTTPS)\u3002<\/li>\n\n\n\n<li>\u90ae\u4ef6\u670d\u52a1\u5668\u53ef\u80fd\u4f7f\u7528 25 \u7aef\u53e3 (SMTP) \u6216 110 \u7aef\u53e3 (POP3)\u3002<\/li>\n\n\n\n<li>\u7aef\u53e3\u53f7\u8303\u56f4\u662f 0 \u5230 65535\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u5957\u63a5\u5b57 (Socket)\uff1a<\/strong> \u662f\u4e00\u4e2a<strong>\u901a\u4fe1\u7aef\u70b9<\/strong>\uff0c\u5b83\u7531<strong>IP \u5730\u5740<\/strong>\u548c<strong>\u7aef\u53e3\u53f7<\/strong>\u5171\u540c\u552f\u4e00\u6807\u8bc6\u3002\u5b83\u662f\u5e94\u7528\u7a0b\u5e8f\u7528\u6765\u8fdb\u884c\u7f51\u7edc\u901a\u4fe1\u7684<strong>\u7f16\u7a0b\u63a5\u53e3<\/strong>\u3002<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">\u5f62\u8c61\u7c7b\u6bd4<\/h3>\n\n\n\n<p>\u6211\u4eec\u53ef\u4ee5\u7528\u201c\u6253\u7535\u8bdd\u201d\u7684\u4f8b\u5b50\u6765\u8fdb\u4e00\u6b65\u8bf4\u660e\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>IP \u5730\u5740\uff1a<\/strong> \u5c31\u50cf\u4f60\u5bb6\u7684<strong>\u533a\u53f7<\/strong>\uff08\u4f8b\u5982\uff0c\u5317\u4eac\u7684 010\uff09\u3002\u5b83\u6807\u8bc6\u4e86\u7f51\u7edc\u4e2d\u7684\u4e00\u53f0\u4e3b\u673a\u3002<\/li>\n\n\n\n<li><strong>\u7aef\u53e3\u53f7\uff1a<\/strong> \u5c31\u50cf\u4f60\u5bb6\u91cc\u7684<strong>\u5206\u673a\u53f7<\/strong>\uff08\u4f8b\u5982\uff0c\u4f60\u7238\u7238\u7684\u5206\u673a\u53f7\u662f 101\uff0c\u4f60\u5988\u5988\u7684\u5206\u673a\u53f7\u662f 102\uff09\u3002\u5b83\u6807\u8bc6\u4e86\u4e3b\u673a\u4e0a\u8fd0\u884c\u7684\u7279\u5b9a\u5e94\u7528\u7a0b\u5e8f\u6216\u670d\u52a1\u3002<\/li>\n\n\n\n<li><strong>Socket (\u5957\u63a5\u5b57)\uff1a<\/strong> \u5c31\u50cf\u4f60\u5bb6\u91cc\u7684<strong>\u7535\u8bdd\u673a<\/strong>\u3002\u5b83\u662f\u4e00\u4e2a\u5b9e\u9645\u7684\u8bbe\u5907\uff08\u6216\u8005\u8bf4\u662f\u4e00\u4e2a\u8f6f\u4ef6\u63a5\u53e3\uff09\uff0c\u4f60\u901a\u8fc7\u5b83\u6765\u62e8\u53f7\uff08\u8fde\u63a5\uff09\u6216\u63a5\u542c\uff08\u76d1\u542c\uff09\uff0c\u5e76\u8fdb\u884c\u5b9e\u9645\u7684\u901a\u8bdd\uff08\u6570\u636e\u4f20\u8f93\uff09\u3002<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">\u5b83\u4eec\u7684\u5173\u7cfb<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u4e00\u4e2a Socket \u5fc5\u987b\u7ed1\u5b9a\u5230\u4e00\u4e2a IP \u5730\u5740\u548c\u4e00\u4e2a\u7aef\u53e3\u53f7\u624d\u80fd\u5728\u7f51\u7edc\u4e0a\u8fdb\u884c\u901a\u4fe1\u3002<\/strong>\n<ul class=\"wp-block-list\">\n<li>\u4f8b\u5982\uff0c\u4e00\u4e2a Web \u670d\u52a1\u5668\u5e94\u7528\u7a0b\u5e8f\u4f1a\u521b\u5efa\u4e00\u4e2a Socket\uff0c\u5e76\u5c06\u5176\u7ed1\u5b9a\u5230\u670d\u52a1\u5668\u7684 IP \u5730\u5740\u548c 80 \u7aef\u53e3\u4e0a\uff0c\u7136\u540e\u76d1\u542c\u6765\u81ea\u5ba2\u6237\u7aef\u7684\u8fde\u63a5\u3002<\/li>\n\n\n\n<li>\u5ba2\u6237\u7aef\u5e94\u7528\u7a0b\u5e8f\u4e5f\u4f1a\u521b\u5efa\u4e00\u4e2a Socket\uff0c\u5e76\u4f7f\u7528\u5b83\u8fde\u63a5\u5230\u670d\u52a1\u5668\u7684 IP \u5730\u5740\u548c 80 \u7aef\u53e3\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u7aef\u53e3\u53f7\u662f Socket \u6807\u8bc6\u7684\u4e00\u90e8\u5206\uff0c\u4f46 Socket \u5305\u542b\u4e86\u66f4\u591a\u7684\u4fe1\u606f\u548c\u529f\u80fd\u3002<\/strong>\n<ul class=\"wp-block-list\">\n<li>Socket \u4e0d\u4ec5\u4ec5\u662f\u4e00\u4e2a\u6570\u5b57\uff0c\u5b83\u662f\u4e00\u4e2a\u64cd\u4f5c\u7cfb\u7edf\u63d0\u4f9b\u7684\u62bd\u8c61\u5c42\uff0c\u5305\u542b\u4e86\u534f\u8bae\u7c7b\u578b\uff08TCP\/UDP\uff09\u3001\u8fde\u63a5\u72b6\u6001\u3001\u6570\u636e\u7f13\u51b2\u533a\u7b49\u4fe1\u606f\uff0c\u5e76\u63d0\u4f9b\u4e86\u4e00\u7cfb\u5217\u7528\u4e8e\u7f51\u7edc\u901a\u4fe1\u7684\u51fd\u6570\uff08\u5982 <code>bind<\/code>, <code>listen<\/code>, <code>accept<\/code>, <code>connect<\/code>, <code>send<\/code>, <code>recv<\/code>\uff09\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u4e00\u4e2a\u7aef\u53e3\u53f7\u53ef\u4ee5\u88ab\u4e00\u4e2a Socket \u5360\u7528\u3002<\/strong>\n<ul class=\"wp-block-list\">\n<li>\u5f53\u4e00\u4e2a\u5e94\u7528\u7a0b\u5e8f\u5728\u4e00\u4e2a\u7279\u5b9a\u7684\u7aef\u53e3\u4e0a\u76d1\u542c\u65f6\uff0c\u8fd9\u4e2a\u7aef\u53e3\u5c31\u88ab\u8be5\u5e94\u7528\u7a0b\u5e8f\u7684 Socket \u5360\u7528\u4e86\u3002\u5176\u4ed6\u5e94\u7528\u7a0b\u5e8f\u5c31\u4e0d\u80fd\u518d\u4f7f\u7528\u540c\u4e00\u4e2a IP \u5730\u5740\u548c\u7aef\u53e3\u53f7\u8fdb\u884c\u76d1\u542c\u4e86\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">\u533a\u5206IP\u548cMAC\uff1a<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>IP \u5730\u5740 (Internet Protocol Address)\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u662f\u4ec0\u4e48\uff1a<\/strong> \u903b\u8f91\u5730\u5740\uff0c\u7528\u4e8e\u5728<strong>\u7f51\u7edc\u5c42 (Layer 3)<\/strong> \u6807\u8bc6\u7f51\u7edc\u4e2d\u7684\u4e00\u53f0\u4e3b\u673a\u3002\u5b83\u5141\u8bb8\u6570\u636e\u5305\u5728\u4e0d\u540c\u7f51\u7edc\u4e4b\u95f4\u8def\u7531\u3002<\/li>\n\n\n\n<li><strong>\u7279\u70b9\uff1a<\/strong> \u53ef\u914d\u7f6e\uff08\u9759\u6001\u6216\u52a8\u6001\u83b7\u53d6\uff09\uff0c\u53ef\u53d8\uff0c\u5206\u516c\u7f51 IP \u548c\u79c1\u7f51 IP\u3002<\/li>\n\n\n\n<li><strong>\u7c7b\u6bd4\uff1a<\/strong> \u4f60\u7684<strong>\u5bb6\u5ead\u4f4f\u5740<\/strong>\uff0c\u7528\u4e8e\u90ae\u9012\u5458\u8de8\u57ce\u5e02\uff08\u7f51\u7edc\uff09\u627e\u5230\u4f60\u7684\u5bb6\u3002<\/li>\n\n\n\n<li><strong>CTF \u610f\u4e49\uff1a<\/strong> \u7f51\u7edc\u4fa6\u5bdf\u3001\u76ee\u6807\u5b9a\u4f4d\u3001\u8def\u7531\u5206\u6790\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>MAC \u5730\u5740 (Media Access Control Address)\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u662f\u4ec0\u4e48\uff1a<\/strong> \u7269\u7406\u5730\u5740\uff0c\u7528\u4e8e\u5728<strong>\u6570\u636e\u94fe\u8def\u5c42 (Layer 2)<\/strong> \u6807\u8bc6\u7f51\u7edc\u63a5\u53e3\u5361 (NIC)\u3002\u5b83\u5141\u8bb8\u6570\u636e\u5e27\u5728\u540c\u4e00\u5c40\u57df\u7f51\u5185\u4f20\u8f93\u3002<\/li>\n\n\n\n<li><strong>\u7279\u70b9\uff1a<\/strong> \u56fa\u5316\u5728\u7f51\u5361\u786c\u4ef6\u4e2d\uff0c\u5168\u7403\u552f\u4e00\uff08\u7406\u8bba\u4e0a\uff09\uff0c\u4e0d\u53ef\u53d8\uff08\u901a\u5e38\uff09\uff0c\u4f46\u53ef\u4ee5\u901a\u8fc7\u8f6f\u4ef6\u4f2a\u9020 (MAC Spoofing)\u3002<\/li>\n\n\n\n<li><strong>\u7c7b\u6bd4\uff1a<\/strong> \u4f60\u5bb6<strong>\u95e8\u724c\u53f7<\/strong>\uff0c\u7528\u4e8e\u5feb\u9012\u5458\u5728\u4f60\u7684\u5c0f\u533a\uff08\u5c40\u57df\u7f51\uff09\u5185\u627e\u5230\u4f60\u7684\u5177\u4f53\u95e8\u3002<\/li>\n\n\n\n<li><strong>CTF \u610f\u4e49\uff1a<\/strong> ARP \u6b3a\u9a97\u3001MAC \u6cdb\u6d2a\u3001\u7aef\u53e3\u5b89\u5168\u7ed5\u8fc7\u3001\u8bbe\u5907\u6307\u7eb9\u8bc6\u522b\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u4e3b\u8981\u533a\u522b\uff1a<\/strong> IP \u5730\u5740\u7528\u4e8e<strong>\u8de8\u7f51\u7edc\u8def\u7531<\/strong>\uff0cMAC \u5730\u5740\u7528\u4e8e<strong>\u5c40\u57df\u7f51\u5185\u5bfb\u5740<\/strong>\u3002<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">\u533a\u5206\u8def\u7531\u5668 (Router) vs. \u4ea4\u6362\u673a (Switch) vs. \u96c6\u7ebf\u5668 (Hub)<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u96c6\u7ebf\u5668 (Hub)\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u662f\u4ec0\u4e48\uff1a<\/strong> \u6700\u7b80\u5355\u7684\u7f51\u7edc\u8bbe\u5907\uff0c\u5de5\u4f5c\u5728 <strong>\u7269\u7406\u5c42 (Layer 1)<\/strong>\u3002<\/li>\n\n\n\n<li><strong>\u7279\u70b9\uff1a<\/strong> \u6536\u5230\u6570\u636e\u540e\uff0c\u4f1a\u5c06\u6570\u636e<strong>\u5e7f\u64ad<\/strong>\u7ed9\u6240\u6709\u8fde\u63a5\u7684\u7aef\u53e3\u3002\u4e0d\u533a\u5206\u76ee\u6807\u5730\u5740\uff0c\u4e0d\u667a\u80fd\u3002<\/li>\n\n\n\n<li><strong>\u5f71\u54cd\uff1a<\/strong> \u6269\u5927\u4e86\u51b2\u7a81\u57df\uff0c\u964d\u4f4e\u7f51\u7edc\u6548\u7387\uff0c\u5b89\u5168\u6027\u5dee\uff08\u6240\u6709\u8bbe\u5907\u90fd\u80fd\u6536\u5230\u6240\u6709\u6d41\u91cf\uff09\u3002<\/li>\n\n\n\n<li><strong>CTF \u610f\u4e49\uff1a<\/strong> \u5728 Hub \u73af\u5883\u4e0b\uff0c\u7f51\u7edc\u55c5\u63a2\u975e\u5e38\u5bb9\u6613\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u4ea4\u6362\u673a (Switch)\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u662f\u4ec0\u4e48\uff1a<\/strong> \u667a\u80fd\u7f51\u7edc\u8bbe\u5907\uff0c\u5de5\u4f5c\u5728 <strong>\u6570\u636e\u94fe\u8def\u5c42 (Layer 2)<\/strong>\u3002<\/li>\n\n\n\n<li><strong>\u7279\u70b9\uff1a<\/strong> \u5b66\u4e60\u8fde\u63a5\u8bbe\u5907\u7684 MAC \u5730\u5740\uff0c\u5e76\u7ef4\u62a4\u4e00\u4e2a MAC \u5730\u5740\u8868\u3002\u6536\u5230\u6570\u636e\u5e27\u540e\uff0c\u6839\u636e\u76ee\u6807 MAC \u5730\u5740<strong>\u7cbe\u786e\u8f6c\u53d1<\/strong>\u5230\u5bf9\u5e94\u7684\u7aef\u53e3\u3002<\/li>\n\n\n\n<li><strong>\u5f71\u54cd\uff1a<\/strong> \u6bcf\u4e2a\u7aef\u53e3\u90fd\u662f\u4e00\u4e2a\u72ec\u7acb\u7684\u51b2\u7a81\u57df\uff0c\u63d0\u9ad8\u4e86\u7f51\u7edc\u6548\u7387\u548c\u5b89\u5168\u6027\u3002<\/li>\n\n\n\n<li><strong>CTF \u610f\u4e49\uff1a<\/strong> \u5927\u591a\u6570\u73b0\u4ee3\u7f51\u7edc\u90fd\u4f7f\u7528\u4ea4\u6362\u673a\uff0c\u9700\u8981 ARP \u6b3a\u9a97\u3001MAC \u6cdb\u6d2a\u7b49 L2 \u653b\u51fb\u624d\u80fd\u8fdb\u884c\u55c5\u63a2\u3002VLAN \u9694\u79bb\u4e5f\u662f\u4ea4\u6362\u673a\u7684\u529f\u80fd\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u8def\u7531\u5668 (Router)\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u662f\u4ec0\u4e48\uff1a<\/strong> \u667a\u80fd\u7f51\u7edc\u8bbe\u5907\uff0c\u5de5\u4f5c\u5728 <strong>\u7f51\u7edc\u5c42 (Layer 3)<\/strong>\u3002<\/li>\n\n\n\n<li><strong>\u7279\u70b9\uff1a<\/strong> \u6839\u636e IP \u5730\u5740\u8fdb\u884c\u6570\u636e\u5305\u8f6c\u53d1\uff0c\u8fde\u63a5\u4e0d\u540c\u7684\u7f51\u7edc\uff08\u5b50\u7f51\uff09\uff0c\u5b9e\u73b0\u8def\u7531\u529f\u80fd\u3002<\/li>\n\n\n\n<li><strong>\u5f71\u54cd\uff1a<\/strong> \u9694\u79bb\u4e86\u5e7f\u64ad\u57df\uff0c\u662f\u8fde\u63a5\u5e7f\u57df\u7f51 (WAN) \u548c\u4e92\u8054\u7f51\u7684\u5173\u952e\u8bbe\u5907\u3002<\/li>\n\n\n\n<li><strong>CTF \u610f\u4e49\uff1a<\/strong> \u8def\u7531\u534f\u8bae\u6f0f\u6d1e\u3001\u8def\u7531\u8868\u7be1\u6539\u3001NAT \u7a7f\u8d8a\u3001\u9632\u706b\u5899\u7ed5\u8fc7\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u4e3b\u8981\u533a\u522b\uff1a<\/strong> Hub \u5e7f\u64ad (L1)\uff0cSwitch \u7cbe\u786e\u8f6c\u53d1 (L2)\uff0cRouter \u8def\u7531 (L3)\u3002<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">\u533a\u5206\u6570\u636e\u5305 (Packet) vs. \u6570\u636e\u5e27 (Frame) vs. \u6570\u636e\u6bb5 (Segment) vs. \u6570\u636e\u62a5 (Datagram) \uff08\u672a\u7ec6\u770b\uff09<\/h2>\n\n\n\n<p>\u8fd9\u4e9b\u90fd\u662f\u6570\u636e\u5728 OSI \u6a21\u578b\u4e0d\u540c\u5c42\u7ea7\u4e2d\u7684\u540d\u79f0\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u6570\u636e\u6bb5 (Segment)\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u5c42\u7ea7\uff1a<\/strong> <strong>\u4f20\u8f93\u5c42 (Layer 4)<\/strong>\u3002<\/li>\n\n\n\n<li><strong>\u534f\u8bae\uff1a<\/strong> TCP (\u5e26\u6709\u5e8f\u5217\u53f7\u3001\u786e\u8ba4\u53f7\u7b49)\u3002<\/li>\n\n\n\n<li><strong>CTF \u610f\u4e49\uff1a<\/strong> TCP \u52ab\u6301\u3001\u7aef\u53e3\u626b\u63cf\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u6570\u636e\u62a5 (Datagram)\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u5c42\u7ea7\uff1a<\/strong> <strong>\u4f20\u8f93\u5c42 (Layer 4)<\/strong>\u3002<\/li>\n\n\n\n<li><strong>\u534f\u8bae\uff1a<\/strong> UDP (\u7b80\u5355\u7684\u6570\u636e\u5355\u5143)\u3002<\/li>\n\n\n\n<li><strong>CTF \u610f\u4e49\uff1a<\/strong> UDP Flood\u3001DNS \u653e\u5927\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u6570\u636e\u5305 (Packet)\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u5c42\u7ea7\uff1a<\/strong> <strong>\u7f51\u7edc\u5c42 (Layer 3)<\/strong>\u3002<\/li>\n\n\n\n<li><strong>\u534f\u8bae\uff1a<\/strong> IP (\u5e26\u6709\u6e90\/\u76ee\u7684 IP \u5730\u5740)\u3002<\/li>\n\n\n\n<li><strong>\u7279\u70b9\uff1a<\/strong> \u662f Segment \u6216 Datagram \u52a0\u4e0a IP \u5934\u3002<\/li>\n\n\n\n<li><strong>CTF \u610f\u4e49\uff1a<\/strong> IP \u6b3a\u9a97\u3001IP \u5206\u7247\u653b\u51fb\u3001\u8def\u7531\u5206\u6790\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u6570\u636e\u5e27 (Frame)\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u5c42\u7ea7\uff1a<\/strong> <strong>\u6570\u636e\u94fe\u8def\u5c42 (Layer 2)<\/strong>\u3002<\/li>\n\n\n\n<li><strong>\u534f\u8bae\uff1a<\/strong> \u4ee5\u592a\u7f51 (\u5e26\u6709\u6e90\/\u76ee\u7684 MAC \u5730\u5740)\u3002<\/li>\n\n\n\n<li><strong>\u7279\u70b9\uff1a<\/strong> \u662f Packet \u52a0\u4e0a MAC \u5934\u548c\u5e27\u5c3e\u3002<\/li>\n\n\n\n<li><strong>CTF \u610f\u4e49\uff1a<\/strong> ARP \u6b3a\u9a97\u3001MAC \u6cdb\u6d2a\u3001VLAN \u653b\u51fb\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u4e3b\u8981\u533a\u522b\uff1a<\/strong> \u5b83\u4eec\u662f\u540c\u4e00\u4efd\u6570\u636e\u5728\u4e0d\u540c OSI \u5c42\u7ea7\u88ab\u5c01\u88c5\uff08\u6dfb\u52a0\u5934\u90e8\u548c\u5c3e\u90e8\uff09\u540e\u7684\u4e0d\u540c\u79f0\u8c13\u3002<\/li>\n\n\n\n<li><\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">VPN \u662f\u4ec0\u4e48\uff1f<\/h2>\n\n\n\n<h4 class=\"wp-block-heading\">1. \u4ec0\u4e48\u662f VPN\uff1f<\/h4>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/usual1009.oss-cn-shanghai.aliyuncs.com\/img\/202511291927211.png\" alt=\"image-20251109193539191\"\/><\/figure>\n\n\n\n<p><strong>VPN<\/strong> \u662f <strong>Virtual Private Network<\/strong> \u7684\u7f29\u5199\uff0c\u4e2d\u6587\u610f\u601d\u662f\u201c\u865a\u62df\u79c1\u4eba\u7f51\u7edc\u201d\u3002<\/p>\n\n\n\n<p>\u5b83\u662f\u4e00\u79cd\u6280\u672f\uff0c\u5141\u8bb8\u7528\u6237\u901a\u8fc7\u516c\u5171\u7f51\u7edc\uff08\u5982\u4e92\u8054\u7f51\uff09\u5efa\u7acb\u4e00\u4e2a<strong>\u52a0\u5bc6\u7684\u3001\u5b89\u5168\u7684\u8fde\u63a5<\/strong>\uff0c\u5c31\u50cf\u76f4\u63a5\u8fde\u63a5\u5230\u79c1\u4eba\u7f51\u7edc\u4e00\u6837\u3002\u5b83\u521b\u5efa\u4e86\u4e00\u4e2a\u201c\u96a7\u9053\u201d\uff0c\u6240\u6709\u901a\u8fc7\u8fd9\u4e2a\u96a7\u9053\u4f20\u8f93\u7684\u6570\u636e\u90fd\u4f1a\u88ab\u52a0\u5bc6\uff0c\u4ece\u800c\u4fdd\u62a4\u7528\u6237\u7684\u9690\u79c1\u548c\u6570\u636e\u5b89\u5168\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">2. VPN \u7684\u6838\u5fc3\u7279\u70b9\u548c\u5de5\u4f5c\u539f\u7406<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u865a\u62df (Virtual)\uff1a<\/strong> VPN \u8fde\u63a5\u5e76\u4e0d\u662f\u7269\u7406\u4e0a\u72ec\u7acb\u7684\u7f51\u7edc\u8fde\u63a5\uff0c\u800c\u662f\u901a\u8fc7\u5728\u73b0\u6709\u516c\u5171\u7f51\u7edc\uff08\u5982\u4e92\u8054\u7f51\uff09\u4e0a\u5efa\u7acb\u903b\u8f91\u8fde\u63a5\u6765\u5b9e\u73b0\u7684\u3002\u5b83\u6a21\u62df\u4e86\u4e00\u4e2a\u70b9\u5bf9\u70b9\u7684\u4e13\u7528\u8fde\u63a5\u3002<\/li>\n\n\n\n<li><strong>\u79c1\u4eba (Private)\uff1a<\/strong> VPN \u901a\u8fc7<strong>\u52a0\u5bc6<\/strong>\u6280\u672f\uff08\u5982 IPsec, OpenVPN, L2TP\/IPsec, PPTP \u7b49\uff09\u786e\u4fdd\u6570\u636e\u5728\u516c\u5171\u7f51\u7edc\u4e0a\u4f20\u8f93\u65f6\u7684\u673a\u5bc6\u6027\u548c\u5b8c\u6574\u6027\u3002\u53ea\u6709 VPN \u96a7\u9053\u4e24\u7aef\u7684\u8bbe\u5907\u624d\u80fd\u89e3\u5bc6\u548c\u8bfb\u53d6\u6570\u636e\u3002<\/li>\n\n\n\n<li><strong>\u7f51\u7edc (Network)\uff1a<\/strong> VPN \u5141\u8bb8\u7528\u6237\u8fdc\u7a0b\u8bbf\u95ee\u53e6\u4e00\u4e2a\u7f51\u7edc\uff08\u4f8b\u5982\u516c\u53f8\u5185\u7f51\uff09\uff0c\u5c31\u597d\u50cf\u4ed6\u4eec\u7269\u7406\u4e0a\u5c31\u5728\u90a3\u4e2a\u7f51\u7edc\u4e2d\u4e00\u6837\u3002<\/li>\n<\/ul>\n\n\n\n<p><strong>\u5de5\u4f5c\u6d41\u7a0b\uff1a<\/strong><\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u8eab\u4efd\u9a8c\u8bc1\uff1a<\/strong> \u7528\u6237\uff08\u5ba2\u6237\u7aef\uff09\u9996\u5148\u5411 VPN \u670d\u52a1\u5668\u8fdb\u884c\u8eab\u4efd\u9a8c\u8bc1\uff0c\u4ee5\u8bc1\u660e\u5176\u5408\u6cd5\u6027\u3002<\/li>\n\n\n\n<li><strong>\u5efa\u7acb\u96a7\u9053\uff1a<\/strong> \u8eab\u4efd\u9a8c\u8bc1\u6210\u529f\u540e\uff0cVPN \u5ba2\u6237\u7aef\u548c VPN \u670d\u52a1\u5668\u4e4b\u95f4\u4f1a\u5efa\u7acb\u4e00\u4e2a\u52a0\u5bc6\u7684\u201c\u96a7\u9053\u201d\u3002\u8fd9\u4e2a\u96a7\u9053\u901a\u5e38\u662f\u57fa\u4e8e\u67d0\u79cd VPN \u534f\u8bae\uff08\u5982 OpenVPN\u3001IPsec\uff09\u5b9e\u73b0\u7684\u3002<\/li>\n\n\n\n<li><strong>\u6570\u636e\u52a0\u5bc6\u548c\u5c01\u88c5\uff1a<\/strong> \u5ba2\u6237\u7aef\u53d1\u9001\u7684\u6240\u6709\u6570\u636e\u90fd\u4f1a\u5728\u8fdb\u5165\u96a7\u9053\u524d\u88ab\u52a0\u5bc6\uff0c\u5e76\u5c01\u88c5\u5728 VPN \u534f\u8bae\u7684\u6570\u636e\u5305\u4e2d\u3002<\/li>\n\n\n\n<li><strong>\u6570\u636e\u4f20\u8f93\uff1a<\/strong> \u52a0\u5bc6\u540e\u7684\u6570\u636e\u5305\u901a\u8fc7\u516c\u5171\u7f51\u7edc\u4f20\u8f93\u5230 VPN \u670d\u52a1\u5668\u3002<\/li>\n\n\n\n<li><strong>\u6570\u636e\u89e3\u5bc6\u548c\u8f6c\u53d1\uff1a<\/strong> VPN \u670d\u52a1\u5668\u6536\u5230\u6570\u636e\u5305\u540e\uff0c\u4f1a\u5bf9\u5176\u8fdb\u884c\u89e3\u5bc6\uff0c\u7136\u540e\u5c06\u539f\u59cb\u6570\u636e\u5305\u8f6c\u53d1\u5230\u76ee\u6807\u7f51\u7edc\uff08\u4f8b\u5982\u516c\u53f8\u5185\u7f51\u6216\u4e92\u8054\u7f51\uff09\u3002<\/li>\n\n\n\n<li><strong>\u54cd\u5e94\u8fd4\u56de\uff1a<\/strong> \u76ee\u6807\u7f51\u7edc\u7684\u54cd\u5e94\u6570\u636e\u4f1a\u7ecf\u8fc7 VPN \u670d\u52a1\u5668\uff0c\u518d\u6b21\u52a0\u5bc6\u5e76\u901a\u8fc7\u96a7\u9053\u8fd4\u56de\u7ed9 VPN \u5ba2\u6237\u7aef\uff0c\u5ba2\u6237\u7aef\u89e3\u5bc6\u540e\u63a5\u6536\u3002<\/li>\n<\/ol>\n\n\n\n<h4 class=\"wp-block-heading\">3. VPN \u7684\u4e3b\u8981\u7528\u9014<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u8fdc\u7a0b\u8bbf\u95ee\u516c\u53f8\u5185\u7f51\uff1a<\/strong> \u5458\u5de5\u53ef\u4ee5\u5728\u5bb6\u6216\u51fa\u5dee\u65f6\uff0c\u901a\u8fc7 VPN \u5b89\u5168\u5730\u8fde\u63a5\u5230\u516c\u53f8\u7684\u5185\u90e8\u7f51\u7edc\uff0c\u8bbf\u95ee\u5185\u90e8\u8d44\u6e90\uff08\u5982\u6587\u4ef6\u670d\u52a1\u5668\u3001\u5185\u90e8\u5e94\u7528\uff09\u3002<\/li>\n\n\n\n<li><strong>\u4fdd\u62a4\u6570\u636e\u9690\u79c1\u548c\u5b89\u5168\uff1a<\/strong> \u5728\u4f7f\u7528\u516c\u5171 Wi-Fi \u65f6\uff0cVPN \u53ef\u4ee5\u52a0\u5bc6\u6240\u6709\u6d41\u91cf\uff0c\u9632\u6b62\u6570\u636e\u88ab\u7a83\u542c\u6216\u7be1\u6539\u3002<\/li>\n\n\n\n<li><strong>\u7ed5\u8fc7\u5730\u7406\u9650\u5236\uff1a<\/strong> \u7528\u6237\u53ef\u4ee5\u901a\u8fc7\u8fde\u63a5\u5230\u4f4d\u4e8e\u5176\u4ed6\u56fd\u5bb6\u7684 VPN \u670d\u52a1\u5668\uff0c\u83b7\u53d6\u8be5\u56fd\u5bb6\u7684 IP \u5730\u5740\uff0c\u4ece\u800c\u8bbf\u95ee\u5f53\u5730\u53d7\u5730\u7406\u9650\u5236\u7684\u5185\u5bb9\u6216\u670d\u52a1\uff08\u4f8b\u5982\u6d41\u5a92\u4f53\u3001\u7f51\u7ad9\uff09\u3002<\/li>\n\n\n\n<li><strong>\u9690\u85cf\u771f\u5b9e IP \u5730\u5740\uff1a<\/strong> \u589e\u5f3a\u7528\u6237\u7684\u5728\u7ebf\u533f\u540d\u6027\uff0c\u9632\u6b62\u7f51\u7ad9\u6216\u670d\u52a1\u8ffd\u8e2a\u7528\u6237\u7684\u771f\u5b9e\u4f4d\u7f6e\u3002<\/li>\n\n\n\n<li><strong>\u5b89\u5168\u5730\u8fdb\u884c P2P \u4e0b\u8f7d\uff1a<\/strong> \u4fdd\u62a4\u7528\u6237\u5728\u4e0b\u8f7d\u6587\u4ef6\u65f6\u7684\u9690\u79c1\u3002<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">4. \u5e38\u89c1\u7684 VPN \u534f\u8bae<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>OpenVPN\uff1a<\/strong> \u5f00\u6e90\u3001\u7075\u6d3b\u3001\u5b89\u5168\uff0c\u5e7f\u6cdb\u4f7f\u7528\u3002<\/li>\n\n\n\n<li><strong>IPsec (Internet Protocol Security)\uff1a<\/strong> \u4e00\u5957\u534f\u8bae\u65cf\uff0c\u63d0\u4f9b\u7f51\u7edc\u5c42\u5b89\u5168\uff0c\u5e38\u7528\u4e8e\u7ad9\u70b9\u5230\u7ad9\u70b9\u7684 VPN\u3002<\/li>\n\n\n\n<li><strong>L2TP\/IPsec (Layer 2 Tunneling Protocol over IPsec)\uff1a<\/strong> L2TP \u63d0\u4f9b\u96a7\u9053\uff0cIPsec \u63d0\u4f9b\u52a0\u5bc6\u548c\u8ba4\u8bc1\u3002<\/li>\n\n\n\n<li><strong>PPTP (Point-to-Point Tunneling Protocol)\uff1a<\/strong> \u8f83\u8001\uff0c\u5b89\u5168\u6027\u8f83\u4f4e\uff0c\u4e0d\u63a8\u8350\u4f7f\u7528\u3002<\/li>\n\n\n\n<li><strong>WireGuard\uff1a<\/strong> \u8f83\u65b0\uff0c\u8bbe\u8ba1\u66f4\u7b80\u6d01\uff0c\u6027\u80fd\u66f4\u9ad8\uff0c\u5b89\u5168\u6027\u5f3a\u3002<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">CDN (Content Delivery Network) - \u5185\u5bb9\u5206\u53d1\u7f51\u7edc<\/h2>\n\n\n\n<h4 class=\"wp-block-heading\">1. \u4ec0\u4e48\u662f CDN\uff1f<\/h4>\n\n\n\n<p><strong>CDN<\/strong> \u662f <strong>Content Delivery Network<\/strong> \u7684\u7f29\u5199\uff0c\u4e2d\u6587\u610f\u601d\u662f\u201c\u5185\u5bb9\u5206\u53d1\u7f51\u7edc\u201d\u3002<\/p>\n\n\n\n<p>\u5b83\u662f\u4e00\u4e2a\u7531<strong>\u5206\u5e03\u5728\u5168\u7403\u5404\u5730\u7684\u670d\u52a1\u5668\u8282\u70b9<\/strong>\u7ec4\u6210\u7684\u7f51\u7edc\u3002CDN \u7684\u6838\u5fc3\u76ee\u6807\u662f<strong>\u66f4\u5feb\u3001\u66f4\u53ef\u9760\u5730\u5c06\u5185\u5bb9\uff08\u5982\u7f51\u9875\u3001\u56fe\u7247\u3001\u89c6\u9891\u3001\u6587\u4ef6\u7b49\uff09\u4ea4\u4ed8\u7ed9\u7528\u6237<\/strong>\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">2. CDN \u7684\u5de5\u4f5c\u539f\u7406<\/h4>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u5185\u5bb9\u7f13\u5b58\uff1a<\/strong> \u7f51\u7ad9\u7684\u9759\u6001\u5185\u5bb9\uff08\u5982\u56fe\u7247\u3001CSS\u3001JavaScript \u6587\u4ef6\u3001\u89c6\u9891\u3001\u4e0b\u8f7d\u6587\u4ef6\uff09\u4f1a\u88ab\u7f13\u5b58\u5230 CDN \u7f51\u7edc\u4e2d\u7684\u5404\u4e2a<strong>\u8fb9\u7f18\u8282\u70b9\uff08Edge Servers\uff09<\/strong>\u4e0a\u3002\u8fd9\u4e9b\u8fb9\u7f18\u8282\u70b9\u901a\u5e38\u90e8\u7f72\u5728\u79bb\u7528\u6237\u5730\u7406\u4f4d\u7f6e\u8f83\u8fd1\u7684\u6570\u636e\u4e2d\u5fc3\u3002<\/li>\n\n\n\n<li><strong>DNS \u89e3\u6790\u4f18\u5316\uff1a<\/strong> \u5f53\u7528\u6237\u8bf7\u6c42\u8bbf\u95ee\u4e00\u4e2a\u4f7f\u7528\u4e86 CDN \u7684\u7f51\u7ad9\u65f6\uff0cDNS \u89e3\u6790\u7cfb\u7edf\u4f1a\u5c06\u7528\u6237\u7684\u8bf7\u6c42\u5bfc\u5411\u79bb\u7528\u6237\u6700\u8fd1\u7684\u3001\u6027\u80fd\u6700\u4f73\u7684 CDN \u8fb9\u7f18\u8282\u70b9\u3002<\/li>\n\n\n\n<li><strong>\u5c31\u8fd1\u8bbf\u95ee\uff1a<\/strong> \u7528\u6237\u4e0d\u518d\u76f4\u63a5\u8bbf\u95ee\u7f51\u7ad9\u7684\u6e90\u670d\u52a1\u5668\uff08Origin Server\uff09\uff0c\u800c\u662f\u4ece\u6700\u8fd1\u7684 CDN \u8fb9\u7f18\u8282\u70b9\u83b7\u53d6\u5185\u5bb9\u3002<\/li>\n\n\n\n<li><strong>\u56de\u6e90\u673a\u5236\uff1a<\/strong> \u5982\u679c\u8fb9\u7f18\u8282\u70b9\u6ca1\u6709\u7528\u6237\u8bf7\u6c42\u7684\u5185\u5bb9\uff0c\u6216\u8005\u5185\u5bb9\u5df2\u8fc7\u671f\uff0c\u5b83\u4f1a\u5411\u6e90\u670d\u52a1\u5668\u8bf7\u6c42\u6700\u65b0\u7684\u5185\u5bb9\uff0c\u5e76\u5c06\u5176\u7f13\u5b58\u8d77\u6765\uff0c\u7136\u540e\u518d\u8fd4\u56de\u7ed9\u7528\u6237\u3002<\/li>\n<\/ol>\n\n\n\n<h4 class=\"wp-block-heading\">3. CDN \u7684\u4e3b\u8981\u4f18\u52bf<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u52a0\u901f\u5185\u5bb9\u4ea4\u4ed8\uff1a<\/strong> \u7528\u6237\u4ece\u5730\u7406\u4f4d\u7f6e\u66f4\u8fd1\u7684\u670d\u52a1\u5668\u83b7\u53d6\u5185\u5bb9\uff0c\u5927\u5927\u51cf\u5c11\u4e86\u7f51\u7edc\u5ef6\u8fdf\u548c\u52a0\u8f7d\u65f6\u95f4\u3002<\/li>\n\n\n\n<li><strong>\u51cf\u8f7b\u6e90\u670d\u52a1\u5668\u8d1f\u8f7d\uff1a<\/strong> \u5927\u90e8\u5206\u8bf7\u6c42\u7531 CDN \u8fb9\u7f18\u8282\u70b9\u5904\u7406\uff0c\u51cf\u5c11\u4e86\u6e90\u670d\u52a1\u5668\u7684\u538b\u529b\uff0c\u4f7f\u5176\u53ef\u4ee5\u4e13\u6ce8\u4e8e\u5904\u7406\u52a8\u6001\u5185\u5bb9\u3002<\/li>\n\n\n\n<li><strong>\u63d0\u9ad8\u53ef\u7528\u6027\u548c\u5197\u4f59\uff1a<\/strong> \u5373\u4f7f\u6e90\u670d\u52a1\u5668\u51fa\u73b0\u6545\u969c\uff0cCDN \u4ecd\u7136\u53ef\u4ee5\u63d0\u4f9b\u7f13\u5b58\u7684\u5185\u5bb9\u3002\u591a\u4e2a\u8fb9\u7f18\u8282\u70b9\u4e5f\u63d0\u4f9b\u4e86\u5197\u4f59\uff0c\u63d0\u9ad8\u4e86\u670d\u52a1\u7684\u53ef\u7528\u6027\u3002<\/li>\n\n\n\n<li><strong>\u589e\u5f3a\u5b89\u5168\u6027\uff1a<\/strong> CDN \u53ef\u4ee5\u4f5c\u4e3a DDoS \u653b\u51fb\u7684\u7b2c\u4e00\u9053\u9632\u7ebf\uff0c\u5438\u6536\u5927\u91cf\u7684\u653b\u51fb\u6d41\u91cf\uff0c\u4fdd\u62a4\u6e90\u670d\u52a1\u5668\u3002<\/li>\n\n\n\n<li><strong>\u8282\u7701\u5e26\u5bbd\u6210\u672c\uff1a<\/strong> \u51cf\u5c11\u6e90\u670d\u52a1\u5668\u7684\u51fa\u7ad9\u5e26\u5bbd\u6d88\u8017\u3002<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">4. CDN \u9002\u7528\u7684\u5185\u5bb9\u7c7b\u578b<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u9759\u6001\u7f51\u9875\u5143\u7d20\uff1a<\/strong> \u56fe\u7247\u3001CSS \u6587\u4ef6\u3001JavaScript \u6587\u4ef6\u3001\u5b57\u4f53\u6587\u4ef6\u3002<\/li>\n\n\n\n<li><strong>\u89c6\u9891\u548c\u97f3\u9891\u6d41\uff1a<\/strong> \u5728\u7ebf\u89c6\u9891\u64ad\u653e\u3001\u97f3\u4e50\u6d41\u5a92\u4f53\u3002<\/li>\n\n\n\n<li><strong>\u8f6f\u4ef6\u4e0b\u8f7d\uff1a<\/strong> \u6e38\u620f\u5ba2\u6237\u7aef\u3001\u5e94\u7528\u7a0b\u5e8f\u5b89\u88c5\u5305\u3002<\/li>\n\n\n\n<li><strong>\u52a8\u6001\u5185\u5bb9\u52a0\u901f\uff1a<\/strong> \u67d0\u4e9b CDN \u4e5f\u63d0\u4f9b\u52a8\u6001\u5185\u5bb9\u52a0\u901f\u670d\u52a1\uff0c\u901a\u8fc7\u4f18\u5316\u8def\u7531\u3001\u534f\u8bae\u7b49\u65b9\u5f0f\u6765\u52a0\u901f\u52a8\u6001\u8bf7\u6c42\u3002<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">VPN\u4e0eCDN\u7684\u533a\u522b<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>\u4e00\u3001 VPN\u7684\u672c\u8d28\uff1a\u4e00\u6761\u201c\u52a0\u5bc6\u7684\u6539\u9053\u516c\u8def\u201d<\/strong><\/h3>\n\n\n\n<p>\u60f3\u8c61\u4e00\u4e0b\uff0c\u4f60\u7684\u7f51\u7edc\u6570\u636e\u672c\u6765\u8d70\u7684\u662f\u4f60\u5bb6\u95e8\u53e3\u90a3\u6761\u8c01\u90fd\u770b\u5f97\u89c1\u7684\u56fd\u9053\uff08\u4f60\u7684\u672c\u5730\u7f51\u7edc\uff09\u3002\u800cVPN\uff0c\u5c31\u662f\u5728\u4f60\u548c\u76ee\u7684\u5730\u4e4b\u95f4\uff0c\u4fee\u4e86\u4e00\u6761<strong>\u79c1\u5bc6\u7684\u3001\u53ea\u6709\u4f60\u80fd\u8d70\u7684\u9ad8\u901f\u516c\u8def\uff08\u52a0\u5bc6\u96a7\u9053\uff09<\/strong>\uff0c\u5e76\u4e14\u4f60\u7684\u8f66\uff08\u6570\u636e\uff09\u4f1a\u5728\u8fd9\u6761\u8def\u7684\u5165\u53e3\uff08VPN\u670d\u52a1\u5668\uff09\u6362\u4e00\u526f\u724c\u7167\uff08\u670d\u52a1\u5668\u7684IP\u5730\u5740\uff09\u3002<\/p>\n\n\n\n<p><strong>\u6240\u4ee5\uff0cVPN\u7684\u6838\u5fc3\u4f5c\u7528\u662f\uff1a<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u6539\u9053\u4e0e\u4f2a\u88c5<\/strong>\uff1a\u8ba9\u4f60\u201c\u51fa\u73b0\u201d\u5728\u53e6\u4e00\u4e2a\u5730\u65b9\uff0c\u8bbf\u95ee\u5f53\u5730\u8d44\u6e90\uff08\u6bd4\u5982\u770b\u56fd\u5916\u7684\u5267\uff09\u3002<\/li>\n\n\n\n<li><strong>\u52a0\u5bc6\u4e0e\u9632\u7aa5<\/strong>\uff1a\u5728\u201c\u56fd\u9053\u201d\u90a3\u6bb5\uff0c\u9632\u6b62\u8def\u8fb9\u6709\u4eba\uff08\u6bd4\u5982\u9ed1\u5ba2\u3001\u4e0d\u6000\u597d\u610f\u7684Wi-Fi\u63d0\u4f9b\u8005\uff09\u770b\u5230\u4f60\u7684\u8f66\u91cc\u9762\u88c5\u4e86\u5565\u3002<\/li>\n<\/ul>\n\n\n\n<p><strong>\u4f46\u5b83\u7edd\u4e0d\u662f\u201c\u52a0\u901f\u5668\u201d<\/strong>\u3002\u4e8b\u5b9e\u4e0a\uff0c\u56e0\u4e3a\u7ed5\u4e86\u8fdc\u8def\uff0c\u4f60\u7684\u6570\u636e\u5ef6\u8fdf\uff08ping\u503c\uff09\u53ef\u80fd\u4f1a\u589e\u52a0\uff0c\u7f51\u901f\u751a\u81f3\u4f1a\u53d8\u6162\u3002\u6307\u671b\u7528\u5b83\u6765\u7ed9\u6e38\u620f\u201c\u52a0\u901f\u201d\uff0c\u5f80\u5f80\u662f\u5357\u8f95\u5317\u8f99\u3002<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><strong>\u4e2a\u4eba\u8e29\u5751\u7ecf\u9a8c<\/strong>\uff1a\u65e9\u5e74\u4e3a\u4e86\u73a9\u7f8e\u670d\u6e38\u620f\uff0c\u7528\u4e86\u4e00\u6b3e\u77e5\u540dVPN\uff0c\u7ed3\u679c\u5ef6\u8fdf\u4ece200ms\u98d9\u5347\u5230400ms\uff0c\u5361\u6210\u5e7b\u706f\u7247\u3002\u8fd9\u624d\u660e\u767d\uff0cVPN\u662f\u201c\u7ed5\u8def\u5de5\u5177\u201d\uff0c\u4e0d\u662f\u201c\u4fee\u8def\u5de5\u5177\u201d\u3002<\/p>\n<\/blockquote>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>\u4e8c\u3001 \u771f\u6b63\u7684\u201c\u7f51\u7edc\u52a0\u901f\u201d\u662f\u4ec0\u4e48\uff1f\u7b54\u6848\u662f<a href=\"https:\/\/zhida.zhihu.com\/search?content_id=266017977&amp;content_type=Article&amp;match_order=1&amp;q=CDN&amp;zd_token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJ6aGlkYV9zZXJ2ZXIiLCJleHAiOjE3NjI4NjA5MDMsInEiOiJDRE4iLCJ6aGlkYV9zb3VyY2UiOiJlbnRpdHkiLCJjb250ZW50X2lkIjoyNjYwMTc5NzcsImNvbnRlbnRfdHlwZSI6IkFydGljbGUiLCJtYXRjaF9vcmRlciI6MSwiemRfdG9rZW4iOm51bGx9.oClK_lT2VHY_CCSjBCqpWTNWN05DgIrPfPJErPp3dLk&amp;zhida_source=entity\" target=\"_blank\"  rel=\"nofollow\" >CDN<\/a><\/strong><\/h3>\n\n\n\n<p>\u90a3\u4e48\uff0c\u4e3a\u4ec0\u4e48\u6211\u4eec\u770b\u5948\u98de\u3001\u6cb9\u7ba1\uff0c\u6709\u65f6\u5019\u53c8\u80fd\u90a3\u4e48\u6d41\u7545\u5462\uff1f\u8fd9\u5c31\u8981\u5f15\u51fa\u4eca\u5929\u7684\u4e3b\u89d2\uff0c\u4e5f\u662f\u771f\u6b63\u51b3\u5b9a\u4f60\u7f51\u7edc\u4f53\u9a8c\u7684\u5e55\u540e\u82f1\u96c4\u2014\u2014<strong>CDN<\/strong>\u3002<\/p>\n\n\n\n<p>CDN\u7684\u539f\u7406\uff0c\u548cVPN\u5b8c\u5168\u4e0d\u540c\u3002\u5b83\u4e0d\u7ed9\u4f60\u201c\u6539\u9053\u201d\uff0c\u800c\u662f<strong>\u76f4\u63a5\u628a\u6c34\u4e95\u6316\u5230\u4f60\u5bb6\u95e8\u53e3<\/strong>\u3002<\/p>\n\n\n\n<p>CDN\u670d\u52a1\u5546\u5728\u5168\u7403\u5efa\u8bbe\u4e86\u6210\u5343\u4e0a\u4e07\u4e2a\u201c<a href=\"https:\/\/zhida.zhihu.com\/search?content_id=266017977&amp;content_type=Article&amp;match_order=1&amp;q=%E8%BE%B9%E7%BC%98%E8%8A%82%E7%82%B9&amp;zd_token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJ6aGlkYV9zZXJ2ZXIiLCJleHAiOjE3NjI4NjA5MDMsInEiOiLovrnnvJjoioLngrkiLCJ6aGlkYV9zb3VyY2UiOiJlbnRpdHkiLCJjb250ZW50X2lkIjoyNjYwMTc5NzcsImNvbnRlbnRfdHlwZSI6IkFydGljbGUiLCJtYXRjaF9vcmRlciI6MSwiemRfdG9rZW4iOm51bGx9.PJdJfq5eZM0DjPRCMjYsmzcigjRIPsnSLEVoPc8q8GQ&amp;zhida_source=entity\" target=\"_blank\"  rel=\"nofollow\" >\u8fb9\u7f18\u8282\u70b9<\/a>\u201d\uff08\u4f60\u53ef\u4ee5\u7406\u89e3\u4e3a\u5c0f\u578b\u6c34\u5e93\uff09\u3002\u5f53\u4e00\u4e2a\u70ed\u95e8\u8d44\u6e90\uff08\u6bd4\u5982\u4e00\u90e8\u65b0\u7535\u5f71\u3001\u4e00\u4e2a\u6e38\u620f\u66f4\u65b0\u5305\uff09\u53d1\u5e03\u65f6\uff0cCDN\u4f1a\u628a\u5b83\u63d0\u524d\u7f13\u5b58\u5230\u5168\u7403\u5404\u4e2a\u201c\u6c34\u5e93\u201d\u91cc\u3002<\/p>\n\n\n\n<p>\u4f60\u70b9\u51fb\u64ad\u653e\u65f6\uff0c\u7cfb\u7edf\u4f1a\u81ea\u52a8\u5f15\u5bfc\u4f60\u5230<strong>\u79bb\u4f60\u5730\u7406\u8ddd\u79bb\u6700\u8fd1\u3001\u7f51\u7edc\u94fe\u8def\u6700\u4f18<\/strong>\u7684\u90a3\u4e2a\u201c\u6c34\u5e93\u201d\u53bb\u53d6\u6c34\u3002\u8def\u5f84\u6700\u77ed\uff0c\u81ea\u7136\u5c31\u5feb\u4e86\u3002<\/p>\n\n\n\n<p><strong>\u6240\u4ee5\uff0cVPN\u548cCDN\u7684\u5173\u7cfb\u662f\uff1a<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>VPN\u8d1f\u8d23\u8ba9\u4f60\u201c\u5b89\u5168\u5730\u7ed5\u5230\u7f8e\u56fd\u53bb\u6253\u5f00\u6c34\u5e93\u9600\u95e8\u201d\u3002<\/strong><\/li>\n\n\n\n<li><strong>CDN\u8d1f\u8d23\u201c\u628a\u7f8e\u56fd\u6c34\u5e93\u7684\u6c34\u5f15\u5230\u4f60\u5bb6\u540e\u9662\uff0c\u8ba9\u4f60\u76f4\u63a5\u5f00\u95f8\u201d\u3002<\/strong><\/li>\n<\/ul>\n\n\n\n<p>\u540e\u8005\u5bf9\u901f\u5ea6\u7684\u63d0\u5347\uff0c\u662f\u6570\u91cf\u7ea7\u7684\u3002<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Nginx\u662f\u4ec0\u4e48\uff1f<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Nginx (Engine-X)<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">1. \u4ec0\u4e48\u662f Nginx\uff1f<\/h4>\n\n\n\n<p><strong>Nginx<\/strong> (\u53d1\u97f3\u4e3a \"engine-x\") \u662f\u4e00\u6b3e\u9ad8\u6027\u80fd\u7684\u5f00\u6e90 <strong>Web \u670d\u52a1\u5668<\/strong>\u3001<strong>\u53cd\u5411\u4ee3\u7406\u670d\u52a1\u5668<\/strong>\u3001<strong>\u8d1f\u8f7d\u5747\u8861\u5668<\/strong>\u548c <strong>HTTP \u7f13\u5b58<\/strong>\u3002\u5b83\u7531 Igor Sysoev \u5f00\u53d1\uff0c\u4ee5\u5176\u5353\u8d8a\u7684\u6027\u80fd\u3001\u7a33\u5b9a\u6027\u3001\u4e30\u5bcc\u7684\u529f\u80fd\u96c6\u548c\u4f4e\u8d44\u6e90\u6d88\u8017\u800c\u95fb\u540d\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">2. Nginx \u7684\u6838\u5fc3\u7279\u70b9<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u9ad8\u6027\u80fd\u548c\u4f4e\u8d44\u6e90\u6d88\u8017\uff1a<\/strong> Nginx \u91c7\u7528<strong>\u4e8b\u4ef6\u9a71\u52a8 (Event-driven)<\/strong>\u3001<strong>\u5f02\u6b65\u975e\u963b\u585e (Asynchronous Non-blocking)<\/strong> \u7684\u67b6\u6784\uff0c\u4f7f\u5176\u80fd\u591f\u5904\u7406\u5927\u91cf\u5e76\u53d1\u8fde\u63a5\u800c\u5360\u7528\u6781\u5c11\u7684\u5185\u5b58\u548c CPU \u8d44\u6e90\u3002\u8fd9\u4e0e Apache \u7b49\u4f20\u7edf\u7684\u591a\u8fdb\u7a0b\/\u591a\u7ebf\u7a0b\u6a21\u578b\u5f62\u6210\u5bf9\u6bd4\u3002<\/li>\n\n\n\n<li><strong>\u9ad8\u5e76\u53d1\u652f\u6301\uff1a<\/strong> \u80fd\u591f\u8f7b\u677e\u5904\u7406\u6570\u4e07\u751a\u81f3\u6570\u5341\u4e07\u7684\u5e76\u53d1\u8fde\u63a5\u3002<\/li>\n\n\n\n<li><strong>\u6a21\u5757\u5316\u8bbe\u8ba1\uff1a<\/strong> \u6613\u4e8e\u6269\u5c55\u548c\u5b9a\u5236\u3002<\/li>\n\n\n\n<li><strong>\u7a33\u5b9a\u6027\uff1a<\/strong> \u7ecf\u8fc7\u5927\u89c4\u6a21\u751f\u4ea7\u73af\u5883\u9a8c\u8bc1\u3002<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">3. Nginx \u7684\u4e3b\u8981\u529f\u80fd\u548c\u7528\u9014<\/h4>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Web \u670d\u52a1\u5668 (Web Server)\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u9ad8\u6548\u670d\u52a1\u9759\u6001\u6587\u4ef6\uff1a<\/strong> Nginx \u5728\u63d0\u4f9b\u9759\u6001\u6587\u4ef6\uff08HTML\u3001CSS\u3001JS\u3001\u56fe\u7247\u3001\u89c6\u9891\u7b49\uff09\u65b9\u9762\u8868\u73b0\u51fa\u8272\uff0c\u901f\u5ea6\u6781\u5feb\u3002<\/li>\n\n\n\n<li><strong>\u5904\u7406 HTTP \u8bf7\u6c42\uff1a<\/strong> \u4f5c\u4e3a\u4f20\u7edf\u7684 Web \u670d\u52a1\u5668\uff0c\u63a5\u6536\u5ba2\u6237\u7aef\u7684 HTTP \u8bf7\u6c42\u5e76\u8fd4\u56de\u54cd\u5e94\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u53cd\u5411\u4ee3\u7406\u670d\u52a1\u5668 (Reverse Proxy Server)\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u6838\u5fc3\u529f\u80fd\u4e4b\u4e00\uff1a<\/strong> Nginx \u7ecf\u5e38\u88ab\u90e8\u7f72\u5728\u524d\u7aef\u4f5c\u4e3a\u53cd\u5411\u4ee3\u7406\uff0c\u63a5\u6536\u6765\u81ea\u5ba2\u6237\u7aef\u7684\u8bf7\u6c42\uff0c\u7136\u540e\u5c06\u8fd9\u4e9b\u8bf7\u6c42\u8f6c\u53d1\u7ed9\u540e\u7aef\u7684\u4e00\u53f0\u6216\u591a\u53f0\u5e94\u7528\u670d\u52a1\u5668\uff08\u5982 Node.js\u3001Python Django\/Flask\u3001Java Tomcat \u7b49\uff09\u3002<\/li>\n\n\n\n<li><strong>\u9690\u85cf\u540e\u7aef\uff1a<\/strong> \u4fdd\u62a4\u540e\u7aef\u670d\u52a1\u5668\u7684\u771f\u5b9e IP \u548c\u62d3\u6251\u3002<\/li>\n\n\n\n<li><strong>SSL\/TLS \u5378\u8f7d\uff1a<\/strong> Nginx \u53ef\u4ee5\u5728\u524d\u7aef\u5904\u7406 SSL\/TLS \u52a0\u5bc6\u548c\u89e3\u5bc6\uff0c\u5c06\u672a\u52a0\u5bc6\u7684\u8bf7\u6c42\u8f6c\u53d1\u7ed9\u540e\u7aef\u670d\u52a1\u5668\uff0c\u51cf\u8f7b\u540e\u7aef\u670d\u52a1\u5668\u7684\u8d1f\u62c5\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u8d1f\u8f7d\u5747\u8861\u5668 (Load Balancer)\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u5206\u53d1\u6d41\u91cf\uff1a<\/strong> \u5f53\u6709\u591a\u4e2a\u540e\u7aef\u670d\u52a1\u5668\u65f6\uff0cNginx \u53ef\u4ee5\u6839\u636e\u4e0d\u540c\u7684\u8d1f\u8f7d\u5747\u8861\u7b97\u6cd5\uff08\u5982\u8f6e\u8be2\u3001IP Hash\u3001\u6700\u5c11\u8fde\u63a5\u7b49\uff09\u5c06\u5ba2\u6237\u7aef\u8bf7\u6c42\u5206\u53d1\u5230\u8fd9\u4e9b\u670d\u52a1\u5668\u4e0a\uff0c\u4ece\u800c\u5e73\u8861\u670d\u52a1\u5668\u8d1f\u8f7d\uff0c\u63d0\u9ad8\u7cfb\u7edf\u7684\u53ef\u7528\u6027\u548c\u53ef\u4f38\u5410\u6027\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>HTTP \u7f13\u5b58 (HTTP Cache)\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u52a0\u901f\u54cd\u5e94\uff1a<\/strong> Nginx \u53ef\u4ee5\u7f13\u5b58\u540e\u7aef\u670d\u52a1\u5668\u7684\u54cd\u5e94\u5185\u5bb9\u3002\u5f53\u518d\u6b21\u6536\u5230\u76f8\u540c\u8bf7\u6c42\u65f6\uff0c\u76f4\u63a5\u4ece\u7f13\u5b58\u4e2d\u8fd4\u56de\uff0c\u65e0\u9700\u518d\u6b21\u8bbf\u95ee\u540e\u7aef\u670d\u52a1\u5668\uff0c\u5927\u5927\u52a0\u5feb\u4e86\u54cd\u5e94\u901f\u5ea6\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>API \u7f51\u5173 (API Gateway)\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li>\u53ef\u4ee5\u4f5c\u4e3a\u5fae\u670d\u52a1\u67b6\u6784\u4e2d\u7684 API \u7f51\u5173\uff0c\u63d0\u4f9b\u8def\u7531\u3001\u8ba4\u8bc1\u3001\u9650\u6d41\u7b49\u529f\u80fd\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u52a8\u9759\u5206\u79bb\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li>\u914d\u7f6e Nginx \u76f4\u63a5\u5904\u7406\u9759\u6001\u6587\u4ef6\u8bf7\u6c42\uff0c\u800c\u5c06\u52a8\u6001\u8bf7\u6c42\u8f6c\u53d1\u7ed9\u540e\u7aef\u5e94\u7528\u670d\u52a1\u5668\uff0c\u4f18\u5316\u6027\u80fd\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\">\u6b63\u5411\u4ee3\u7406\u548c\u53cd\u5411\u4ee3\u7406<\/h2>\n\n\n\n<h4 class=\"wp-block-heading\">1. \u6b63\u5411\u4ee3\u7406 (Forward Proxy)<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u5b9a\u4e49\uff1a<\/strong> \u6b63\u5411\u4ee3\u7406\u662f<strong>\u5ba2\u6237\u7aef\u7684\u4ee3\u7406<\/strong>\u3002\u5b83\u4f4d\u4e8e\u5ba2\u6237\u7aef\u548c\u4e92\u8054\u7f51\u4e4b\u95f4\u3002\u5ba2\u6237\u7aef\u660e\u786e\u77e5\u9053\u8981\u8bbf\u95ee\u7684\u76ee\u6807\u670d\u52a1\u5668\uff0c\u4f46\u5b83\u4e0d\u76f4\u63a5\u8fde\u63a5\u76ee\u6807\u670d\u52a1\u5668\uff0c\u800c\u662f\u5c06\u8bf7\u6c42\u53d1\u9001\u7ed9\u6b63\u5411\u4ee3\u7406\u670d\u52a1\u5668\uff0c\u7531\u4ee3\u7406\u670d\u52a1\u5668\u53bb\u8bbf\u95ee\u76ee\u6807\u670d\u52a1\u5668\uff0c\u7136\u540e\u5c06\u54cd\u5e94\u8fd4\u56de\u7ed9\u5ba2\u6237\u7aef\u3002<\/li>\n\n\n\n<li><strong>\u8c01\u77e5\u9053\u4ee3\u7406\u7684\u5b58\u5728\uff1a<\/strong> \u5ba2\u6237\u7aef\u77e5\u9053\u4ee3\u7406\u7684\u5b58\u5728\uff0c\u5e76\u4e14\u9700\u8981\u914d\u7f6e\u4f7f\u7528\u4ee3\u7406\u3002\u76ee\u6807\u670d\u52a1\u5668\u4e0d\u77e5\u9053\u5ba2\u6237\u7aef\u7684\u771f\u5b9e IP \u5730\u5740\uff0c\u5b83\u53ea\u770b\u5230\u4ee3\u7406\u670d\u52a1\u5668\u7684 IP \u5730\u5740\u3002<\/li>\n\n\n\n<li>\u4f5c\u7528\/\u76ee\u7684\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u7a81\u7834\u7f51\u7edc\u9650\u5236\uff1a<\/strong> \u8bbf\u95ee\u88ab\u9632\u706b\u5899\u6216\u5ba1\u67e5\u7cfb\u7edf\u963b\u6b62\u7684\u7f51\u7ad9\uff08\u4f8b\u5982\uff0c\u7ffb\u5899\uff09\u3002<\/li>\n\n\n\n<li><strong>\u9690\u85cf\u5ba2\u6237\u7aef\u771f\u5b9e IP\uff1a<\/strong> \u4fdd\u62a4\u5ba2\u6237\u7aef\u9690\u79c1\uff0c\u589e\u52a0\u533f\u540d\u6027\u3002<\/li>\n\n\n\n<li><strong>\u8bbf\u95ee\u5185\u90e8\u8d44\u6e90\uff1a<\/strong> \u67d0\u4e9b\u4f01\u4e1a\u5185\u90e8\u7f51\u7edc\u53ef\u80fd\u9700\u8981\u901a\u8fc7\u6b63\u5411\u4ee3\u7406\u624d\u80fd\u8bbf\u95ee\u5916\u90e8\u4e92\u8054\u7f51\u3002<\/li>\n\n\n\n<li><strong>\u7f13\u5b58\uff1a<\/strong> \u7f13\u5b58\u7ecf\u5e38\u8bbf\u95ee\u7684\u5916\u90e8\u8d44\u6e90\uff0c\u52a0\u5feb\u8bbf\u95ee\u901f\u5ea6\uff0c\u8282\u7701\u5e26\u5bbd\u3002<\/li>\n\n\n\n<li><strong>\u5185\u5bb9\u8fc7\u6ee4\uff1a<\/strong> \u8fc7\u6ee4\u6076\u610f\u7f51\u7ad9\u6216\u4e0d\u5f53\u5185\u5bb9\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>\u7c7b\u6bd4\uff1a\n<ul class=\"wp-block-list\">\n<li>\u4f60\uff08\u5ba2\u6237\u7aef\uff09\u60f3\u7ed9\u4e00\u4e2a\u5916\u56fd\u670b\u53cb\uff08\u76ee\u6807\u670d\u52a1\u5668\uff09\u5bc4\u4fe1\uff0c\u4f46\u4f60\u4e0d\u77e5\u9053\u600e\u4e48\u5bc4\uff0c\u6216\u8005\u76f4\u63a5\u5bc4\u53ef\u80fd\u4f1a\u88ab\u68c0\u67e5\u3002\u4e8e\u662f\u4f60\u628a\u4fe1\u4ea4\u7ed9\u4e00\u4e2a<strong>\u56fd\u9645\u5feb\u9012\u516c\u53f8<\/strong>\uff08\u6b63\u5411\u4ee3\u7406\uff09\uff0c\u7531\u5feb\u9012\u516c\u53f8\u5e2e\u4f60\u5904\u7406\u5e76\u5bc4\u7ed9\u4f60\u7684\u670b\u53cb\u3002\u4f60\u7684\u670b\u53cb\u53ea\u77e5\u9053\u662f\u5feb\u9012\u516c\u53f8\u5bc4\u6765\u7684\uff0c\u4e0d\u77e5\u9053\u662f\u4f60\u3002<\/li>\n\n\n\n<li>\u6216\u8005\uff0c\u4f60\uff08\u5ba2\u6237\u7aef\uff09\u60f3\u53bb\u4e00\u5bb6\u88ab\u7981\u6b62\u8fdb\u5165\u7684\u9910\u5385\uff08\u76ee\u6807\u670d\u52a1\u5668\uff09\uff0c\u4f60\u8ba9\u4f60\u7684\u670b\u53cb\uff08\u6b63\u5411\u4ee3\u7406\uff09\u66ff\u4f60\u53bb\uff0c\u7136\u540e\u670b\u53cb\u628a\u83dc\u5e26\u56de\u6765\u7ed9\u4f60\u3002\u9910\u5385\u53ea\u770b\u5230\u4f60\u670b\u53cb\uff0c\u4e0d\u77e5\u9053\u662f\u4f60\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">2. \u53cd\u5411\u4ee3\u7406 (Reverse Proxy)<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u5b9a\u4e49\uff1a<\/strong> \u53cd\u5411\u4ee3\u7406\u662f<strong>\u670d\u52a1\u5668\u7684\u4ee3\u7406<\/strong>\u3002\u5b83\u4f4d\u4e8e\u670d\u52a1\u5668\u548c\u4e92\u8054\u7f51\u4e4b\u95f4\u3002\u5ba2\u6237\u7aef\u53d1\u9001\u8bf7\u6c42\u65f6\uff0c\u5b83\u4ee5\u4e3a\u76f4\u63a5\u8bbf\u95ee\u7684\u662f\u76ee\u6807\u670d\u52a1\u5668\uff0c\u4f46\u5b9e\u9645\u4e0a\u8bf7\u6c42\u9996\u5148\u5230\u8fbe\u53cd\u5411\u4ee3\u7406\u670d\u52a1\u5668\uff0c\u7531\u53cd\u5411\u4ee3\u7406\u670d\u52a1\u5668\u5c06\u8bf7\u6c42\u8f6c\u53d1\u7ed9\u5185\u90e8\u7684\u771f\u5b9e\u670d\u52a1\u5668\uff08\u540e\u7aef\u670d\u52a1\u5668\uff09\uff0c\u7136\u540e\u5c06\u540e\u7aef\u670d\u52a1\u5668\u7684\u54cd\u5e94\u8fd4\u56de\u7ed9\u5ba2\u6237\u7aef\u3002<\/li>\n\n\n\n<li><strong>\u8c01\u77e5\u9053\u4ee3\u7406\u7684\u5b58\u5728\uff1a<\/strong> \u5ba2\u6237\u7aef\u4e0d\u77e5\u9053\u4ee3\u7406\u7684\u5b58\u5728\uff0c\u5b83\u4ee5\u4e3a\u76f4\u63a5\u4e0e\u76ee\u6807\u670d\u52a1\u5668\u901a\u4fe1\u3002\u53cd\u5411\u4ee3\u7406\u77e5\u9053\u540e\u7aef\u670d\u52a1\u5668\u7684\u771f\u5b9e IP \u5730\u5740\u548c\u7ed3\u6784\u3002<\/li>\n\n\n\n<li>\u4f5c\u7528\/\u76ee\u7684\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u8d1f\u8f7d\u5747\u8861 (Load Balancing)\uff1a<\/strong> \u5c06\u5ba2\u6237\u7aef\u8bf7\u6c42\u5206\u53d1\u5230\u591a\u53f0\u540e\u7aef\u670d\u52a1\u5668\u4e0a\uff0c\u5e73\u8861\u670d\u52a1\u5668\u8d1f\u8f7d\uff0c\u63d0\u9ad8\u7cfb\u7edf\u7684\u541e\u5410\u91cf\u548c\u53ef\u7528\u6027\u3002<\/li>\n\n\n\n<li><strong>\u63d0\u9ad8\u5b89\u5168\u6027\uff1a<\/strong> \u9690\u85cf\u540e\u7aef\u670d\u52a1\u5668\u7684\u771f\u5b9e IP \u5730\u5740\u548c\u62d3\u6251\u7ed3\u6784\uff0c\u4fdd\u62a4\u540e\u7aef\u670d\u52a1\u5668\u514d\u53d7\u76f4\u63a5\u653b\u51fb\u3002\u53cd\u5411\u4ee3\u7406\u53ef\u4ee5\u4f5c\u4e3a\u7b2c\u4e00\u9053\u9632\u7ebf\uff0c\u8fc7\u6ee4\u6076\u610f\u8bf7\u6c42\u3002<\/li>\n\n\n\n<li><strong>SSL\/TLS \u5378\u8f7d (SSL\/TLS Termination)\uff1a<\/strong> \u5728\u53cd\u5411\u4ee3\u7406\u4e0a\u5904\u7406 SSL\/TLS \u52a0\u5bc6\u548c\u89e3\u5bc6\uff0c\u51cf\u8f7b\u540e\u7aef\u670d\u52a1\u5668\u7684\u8ba1\u7b97\u8d1f\u62c5\u3002<\/li>\n\n\n\n<li><strong>\u7f13\u5b58\uff1a<\/strong> \u7f13\u5b58\u540e\u7aef\u670d\u52a1\u5668\u7684\u54cd\u5e94\uff0c\u52a0\u5feb\u5ba2\u6237\u7aef\u8bbf\u95ee\u901f\u5ea6\uff0c\u51cf\u8f7b\u540e\u7aef\u670d\u52a1\u5668\u538b\u529b\u3002<\/li>\n\n\n\n<li><strong>Web \u5e94\u7528\u9632\u706b\u5899 (WAF)\uff1a<\/strong> \u4f5c\u4e3a\u5e94\u7528\u5c42\u9632\u706b\u5899\uff0c\u8fc7\u6ee4\u6076\u610f Web \u8bf7\u6c42\u3002<\/li>\n\n\n\n<li><strong>\u52a8\u9759\u5206\u79bb\uff1a<\/strong> \u9759\u6001\u8d44\u6e90\u7531\u53cd\u5411\u4ee3\u7406\u76f4\u63a5\u8fd4\u56de\uff0c\u52a8\u6001\u8bf7\u6c42\u8f6c\u53d1\u7ed9\u540e\u7aef\u670d\u52a1\u5668\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>\u7c7b\u6bd4\uff1a\n<ul class=\"wp-block-list\">\n<li>\u4f60\uff08\u5ba2\u6237\u7aef\uff09\u6253\u7535\u8bdd\u7ed9\u4e00\u5bb6\u5927\u516c\u53f8\u7684\u5ba2\u670d\uff08\u53cd\u5411\u4ee3\u7406\uff09\uff0c\u4f60\u4e0d\u77e5\u9053\u80cc\u540e\u6709\u591a\u5c11\u4e2a\u5ba2\u670d\u4eba\u5458\uff08\u540e\u7aef\u670d\u52a1\u5668\uff09\uff0c\u4f60\u7684\u7535\u8bdd\u4f1a\u88ab\u8f6c\u63a5\u5230\u4e00\u4e2a\u7a7a\u95f2\u7684\u5ba2\u670d\u4eba\u5458\u90a3\u91cc\u3002\u4f60\u53ea\u77e5\u9053\u4f60\u5728\u548c\u201c\u516c\u53f8\u201d\u8bf4\u8bdd\uff0c\u4e0d\u77e5\u9053\u5177\u4f53\u662f\u54ea\u4e2a\u5ba2\u670d\u3002<\/li>\n\n\n\n<li>\u6216\u8005\uff0c\u4f60\uff08\u5ba2\u6237\u7aef\uff09\u53bb\u4e00\u5bb6\u9910\u5385\u70b9\u9910\uff0c\u4f60\u628a\u83dc\u5355\u4ea4\u7ed9\u524d\u53f0\uff08\u53cd\u5411\u4ee3\u7406\uff09\uff0c\u524d\u53f0\u518d\u628a\u4f60\u7684\u8ba2\u5355\u5206\u53d1\u7ed9\u4e0d\u540c\u7684\u53a8\u5e08\uff08\u540e\u7aef\u670d\u52a1\u5668\uff09\u6765\u5236\u4f5c\u3002\u4f60\u53ea\u77e5\u9053\u4f60\u5728\u9910\u5385\u70b9\u9910\uff0c\u4e0d\u77e5\u9053\u5177\u4f53\u662f\u54ea\u4e2a\u53a8\u5e08\u505a\u7684\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">3. \u6838\u5fc3\u533a\u522b\u603b\u7ed3<\/h4>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u7279\u6027<\/th><th>\u6b63\u5411\u4ee3\u7406 (Forward Proxy)<\/th><th>\u53cd\u5411\u4ee3\u7406 (Reverse Proxy)<\/th><\/tr><\/thead><tbody><tr><td><strong>\u670d\u52a1\u5bf9\u8c61<\/strong><\/td><td>\u5ba2\u6237\u7aef (Client)<\/td><td>\u670d\u52a1\u5668 (Server)<\/td><\/tr><tr><td><strong>\u4f4d\u7f6e<\/strong><\/td><td>\u5ba2\u6237\u7aef\u4e0e\u4e92\u8054\u7f51\u4e4b\u95f4<\/td><td>\u4e92\u8054\u7f51\u4e0e\u540e\u7aef\u670d\u52a1\u5668\u4e4b\u95f4<\/td><\/tr><tr><td><strong>\u5ba2\u6237\u7aef\u611f\u77e5<\/strong><\/td><td>\u5ba2\u6237\u7aef\u77e5\u9053\u4ee3\u7406\u7684\u5b58\u5728\u5e76\u9700\u8981\u914d\u7f6e<\/td><td>\u5ba2\u6237\u7aef\u4e0d\u77e5\u9053\u4ee3\u7406\u7684\u5b58\u5728\uff0c\u4ee5\u4e3a\u76f4\u63a5\u8bbf\u95ee\u76ee\u6807\u670d\u52a1\u5668<\/td><\/tr><tr><td><strong>\u76ee\u6807\u670d\u52a1\u5668\u611f\u77e5<\/strong><\/td><td>\u76ee\u6807\u670d\u52a1\u5668\u53ea\u77e5\u9053\u4ee3\u7406\u7684 IP\uff0c\u4e0d\u77e5\u9053\u5ba2\u6237\u7aef\u771f\u5b9e IP<\/td><td>\u76ee\u6807\u670d\u52a1\u5668\u77e5\u9053\u4ee3\u7406\u7684 IP (\u901a\u5e38)\uff0c\u4f46\u5ba2\u6237\u7aef\u4e0d\u77e5\u9053\u540e\u7aef\u670d\u52a1\u5668 IP<\/td><\/tr><tr><td><strong>\u4e3b\u8981\u76ee\u7684<\/strong><\/td><td>\u7a81\u7834\u9650\u5236\u3001\u9690\u85cf\u5ba2\u6237\u7aef IP\u3001\u8bbf\u95ee\u63a7\u5236<\/td><td>\u8d1f\u8f7d\u5747\u8861\u3001\u5b89\u5168\u9632\u62a4\u3001SSL \u5378\u8f7d\u3001\u7f13\u5b58\u3001\u63d0\u9ad8\u6027\u80fd<\/td><\/tr><tr><td><strong>\u9690\u85cf\u5bf9\u8c61<\/strong><\/td><td>\u9690\u85cf\u5ba2\u6237\u7aef<\/td><td>\u9690\u85cf\u540e\u7aef\u670d\u52a1\u5668<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">\u6b63\u5411\u4ee3\u7406\u3001\u53cd\u5411\u4ee3\u7406\u3001VPN\u4e0d\u662f\u4e00\u4e2a\u4e1c\u897f<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">\u6b63\u5411\u4ee3\u7406 (Forward Proxy)<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u672c\u8d28\uff1a<\/strong> \u5ba2\u6237\u7aef\u7684<strong>\u4e2d\u95f4\u4eba<\/strong>\u3002<\/li>\n\n\n\n<li><strong>\u6838\u5fc3\u76ee\u7684\uff1a<\/strong> \u4ee3\u8868\u5ba2\u6237\u7aef\u5411\u5916\u90e8\u4e92\u8054\u7f51\u53d1\u8d77\u8bf7\u6c42\uff0c\u4e3b\u8981\u7528\u4e8e<strong>\u5ba2\u6237\u7aef\u8bbf\u95ee\u63a7\u5236\u3001\u9690\u79c1\u4fdd\u62a4\uff08\u9690\u85cf\u5ba2\u6237\u7aef\u771f\u5b9eIP\uff09\u3001\u7a81\u7834\u8bbf\u95ee\u9650\u5236<\/strong>\u3002<\/li>\n\n\n\n<li><strong>\u5de5\u4f5c\u5c42\u7ea7\uff1a<\/strong> \u4e3b\u8981\u5728<strong>\u5e94\u7528\u5c42 (Layer 7)<\/strong>\uff0c\u5904\u7406 HTTP\/HTTPS \u8bf7\u6c42\u3002<\/li>\n\n\n\n<li><strong>\u52a0\u5bc6\uff1a<\/strong> \u6b63\u5411\u4ee3\u7406\u672c\u8eab<strong>\u4e0d\u4e00\u5b9a\u63d0\u4f9b\u7aef\u5230\u7aef\u52a0\u5bc6<\/strong>\u3002\u5982\u679c\u5ba2\u6237\u7aef\u901a\u8fc7 HTTP \u8bbf\u95ee\uff0c\u4ee3\u7406\u901a\u5e38\u4e0d\u52a0\u5bc6\uff1b\u5982\u679c\u5ba2\u6237\u7aef\u901a\u8fc7 HTTPS \u8bbf\u95ee\uff0c\u4ee3\u7406\u4f1a\u8fdb\u884c SSL \u96a7\u9053\u8f6c\u53d1 (CONNECT \u65b9\u6cd5)\uff0c\u6570\u636e\u5728\u5ba2\u6237\u7aef\u548c\u76ee\u6807\u670d\u52a1\u5668\u4e4b\u95f4\u52a0\u5bc6\uff0c\u4ee3\u7406\u53ea\u8f6c\u53d1\u52a0\u5bc6\u6570\u636e\u3002<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">\u53cd\u5411\u4ee3\u7406 (Reverse Proxy)<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u672c\u8d28\uff1a<\/strong> \u670d\u52a1\u5668\u7684<strong>\u95e8\u536b\/\u8c03\u5ea6\u5458<\/strong>\u3002<\/li>\n\n\n\n<li><strong>\u6838\u5fc3\u76ee\u7684\uff1a<\/strong> \u4ee3\u8868\u540e\u7aef\u670d\u52a1\u5668\u63a5\u6536\u5ba2\u6237\u7aef\u8bf7\u6c42\uff0c\u4e3b\u8981\u7528\u4e8e<strong>\u8d1f\u8f7d\u5747\u8861\u3001\u5b89\u5168\u9632\u62a4\uff08\u9690\u85cf\u540e\u7aef\u670d\u52a1\u5668\uff09\u3001SSL \u5378\u8f7d\u3001\u7f13\u5b58<\/strong>\u3002<\/li>\n\n\n\n<li><strong>\u5de5\u4f5c\u5c42\u7ea7\uff1a<\/strong> \u4e3b\u8981\u5728<strong>\u5e94\u7528\u5c42 (Layer 7)<\/strong>\uff0c\u5904\u7406 HTTP\/HTTPS \u8bf7\u6c42\u3002<\/li>\n\n\n\n<li><strong>\u52a0\u5bc6\uff1a<\/strong> \u53cd\u5411\u4ee3\u7406\u53ef\u4ee5\u8fdb\u884c <strong>SSL\/TLS \u5378\u8f7d<\/strong>\uff0c\u5373\u5728\u4ee3\u7406\u7aef\u5b8c\u6210\u52a0\u5bc6\u548c\u89e3\u5bc6\uff0c\u540e\u7aef\u670d\u52a1\u5668\u63a5\u6536\u672a\u52a0\u5bc6\u6570\u636e\uff0c\u6216\u8005\u4ee3\u7406\u4e0e\u540e\u7aef\u4e4b\u95f4\u518d\u6b21\u52a0\u5bc6\u3002\u5ba2\u6237\u7aef\u4e0e\u53cd\u5411\u4ee3\u7406\u4e4b\u95f4\u7684\u6570\u636e\u662f\u52a0\u5bc6\u7684\u3002<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">VPN (Virtual Private Network)<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u672c\u8d28\uff1a<\/strong> \u5728\u516c\u5171\u7f51\u7edc\u4e0a\u5efa\u7acb\u7684<strong>\u52a0\u5bc6\u5b89\u5168\u901a\u9053<\/strong>\u3002<\/li>\n\n\n\n<li><strong>\u6838\u5fc3\u76ee\u7684\uff1a<\/strong> <strong>\u6269\u5c55\u79c1\u4eba\u7f51\u7edc\u5230\u516c\u5171\u7f51\u7edc\uff0c\u63d0\u4f9b\u5b89\u5168\u3001\u79c1\u5bc6\u7684\u8fdc\u7a0b\u8bbf\u95ee\u548c\u6570\u636e\u4f20\u8f93<\/strong>\u3002<\/li>\n\n\n\n<li><strong>\u5de5\u4f5c\u5c42\u7ea7\uff1a<\/strong> \u4e3b\u8981\u5728<strong>\u7f51\u7edc\u5c42 (Layer 3)<\/strong> \u6216<strong>\u6570\u636e\u94fe\u8def\u5c42 (Layer 2)<\/strong>\uff0c\u5bf9\u6574\u4e2a\u7f51\u7edc\u6d41\u91cf\u8fdb\u884c\u52a0\u5bc6\u548c\u5c01\u88c5\u3002\u5b83\u521b\u5efa\u4e00\u4e2a\u865a\u62df\u7684\u7f51\u7edc\u63a5\u53e3\uff0c\u5c06\u6240\u6709\u6d41\u91cf\u901a\u8fc7\u52a0\u5bc6\u96a7\u9053\u4f20\u8f93\u3002<\/li>\n\n\n\n<li><strong>\u52a0\u5bc6\uff1a<\/strong> VPN \u7684<strong>\u6838\u5fc3\u529f\u80fd\u5c31\u662f\u7aef\u5230\u7aef\u52a0\u5bc6<\/strong>\u3002\u6240\u6709\u901a\u8fc7 VPN \u96a7\u9053\u7684\u6570\u636e\u90fd\u4f1a\u88ab\u52a0\u5bc6\uff0c\u786e\u4fdd\u6570\u636e\u5728\u516c\u5171\u7f51\u7edc\u4f20\u8f93\u65f6\u7684\u673a\u5bc6\u6027\u548c\u5b8c\u6574\u6027\u3002<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">\u5173\u952e\u533a\u522b\u70b9<\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u7279\u6027<\/th><th>\u6b63\u5411\u4ee3\u7406<\/th><th>\u53cd\u5411\u4ee3\u7406<\/th><th>VPN<\/th><\/tr><\/thead><tbody><tr><td><strong>\u6838\u5fc3\u529f\u80fd<\/strong><\/td><td>\u5ba2\u6237\u7aef\u8bbf\u95ee\u63a7\u5236\u3001\u9690\u79c1\u3001\u7a81\u7834\u9650\u5236<\/td><td>\u8d1f\u8f7d\u5747\u8861\u3001\u5b89\u5168\u3001\u52a0\u901f<\/td><td>\u5b89\u5168\u52a0\u5bc6\u901a\u4fe1\u3001\u8fdc\u7a0b\u8bbf\u95ee\u79c1\u7f51<\/td><\/tr><tr><td><strong>\u52a0\u5bc6<\/strong><\/td><td><strong>\u4e0d\u5f3a\u5236\u63d0\u4f9b<\/strong>\uff0c\u53d6\u51b3\u4e8e\u534f\u8bae\u548c\u914d\u7f6e<\/td><td><strong>\u53ef\u63d0\u4f9b SSL\/TLS \u5378\u8f7d<\/strong>\uff0c\u4f46\u975e\u6838\u5fc3\u529f\u80fd<\/td><td><strong>\u6838\u5fc3\u529f\u80fd<\/strong>\uff0c\u5bf9\u6574\u4e2a\u96a7\u9053\u6d41\u91cf\u52a0\u5bc6<\/td><\/tr><tr><td><strong>\u7f51\u7edc\u5c42\u7ea7<\/strong><\/td><td>\u5e94\u7528\u5c42 (L7)<\/td><td>\u5e94\u7528\u5c42 (L7)<\/td><td>\u7f51\u7edc\u5c42 (L3) \u6216\u6570\u636e\u94fe\u8def\u5c42 (L2)<\/td><\/tr><tr><td><strong>\u6570\u636e\u6d41\u5411<\/strong><\/td><td>\u5ba2\u6237\u7aef -&gt; \u4ee3\u7406 -&gt; \u76ee\u6807\u670d\u52a1\u5668<\/td><td>\u5ba2\u6237\u7aef -&gt; \u4ee3\u7406 -&gt; \u540e\u7aef\u670d\u52a1\u5668<\/td><td>\u5ba2\u6237\u7aef -&gt; VPN \u670d\u52a1\u5668 -&gt; \u76ee\u6807\u7f51\u7edc<\/td><\/tr><tr><td><strong>\u8c01\u7684\u4ee3\u7406<\/strong><\/td><td>\u5ba2\u6237\u7aef<\/td><td>\u670d\u52a1\u5668<\/td><td>\u6574\u4e2a\u7f51\u7edc\u6d41\u91cf\u7684\u52a0\u5bc6\u901a\u9053<\/td><\/tr><tr><td><strong>\u662f\u5426\u521b\u5efa\u865a\u62df\u7f51\u7edc\u63a5\u53e3<\/strong><\/td><td>\u5426<\/td><td>\u5426<\/td><td><strong>\u662f<\/strong>\uff0c\u5728\u5ba2\u6237\u7aef\u521b\u5efa\u865a\u62df\u7f51\u5361<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">\u6838\u5fc3\u533a\u522b\u603b\u7ed3\u8868\u683c<\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u7279\u6027<\/th><th>\u6b63\u5411\u4ee3\u7406 (Forward Proxy)<\/th><th>\u53cd\u5411\u4ee3\u7406 (Reverse Proxy)<\/th><\/tr><\/thead><tbody><tr><td><strong>\u670d\u52a1\u5bf9\u8c61<\/strong><\/td><td>\u5ba2\u6237\u7aef (Client)<\/td><td>\u670d\u52a1\u5668 (Server)<\/td><\/tr><tr><td><strong>\u4f4d\u7f6e<\/strong><\/td><td>\u5ba2\u6237\u7aef\u4e0e\u4e92\u8054\u7f51\u4e4b\u95f4<\/td><td>\u4e92\u8054\u7f51\u4e0e\u540e\u7aef\u670d\u52a1\u5668\u4e4b\u95f4<\/td><\/tr><tr><td><strong>\u5ba2\u6237\u7aef\u611f\u77e5<\/strong><\/td><td>\u5ba2\u6237\u7aef\u77e5\u9053\u4ee3\u7406\u7684\u5b58\u5728\u5e76\u9700\u8981\u914d\u7f6e<\/td><td>\u5ba2\u6237\u7aef<strong>\u4e0d\u77e5\u9053<\/strong>\u4ee3\u7406\u7684\u5b58\u5728\uff0c\u4ee5\u4e3a\u76f4\u63a5\u8bbf\u95ee\u76ee\u6807\u670d\u52a1\u5668<\/td><\/tr><tr><td><strong>\u76ee\u6807\u670d\u52a1\u5668\u611f\u77e5<\/strong><\/td><td>\u76ee\u6807\u670d\u52a1\u5668\u53ea\u77e5\u9053\u4ee3\u7406\u7684 IP\uff0c<strong>\u4e0d\u77e5\u9053\u5ba2\u6237\u7aef\u771f\u5b9e IP<\/strong><\/td><td>\u540e\u7aef\u670d\u52a1\u5668\u77e5\u9053\u4ee3\u7406\u7684 IP (\u901a\u5e38)\uff0c\u4f46\u5ba2\u6237\u7aef<strong>\u4e0d\u77e5\u9053\u540e\u7aef\u670d\u52a1\u5668 IP<\/strong><\/td><\/tr><tr><td><strong>\u4e3b\u8981\u76ee\u7684<\/strong><\/td><td>\u7a81\u7834\u9650\u5236\u3001\u9690\u85cf\u5ba2\u6237\u7aef IP\u3001\u8bbf\u95ee\u63a7\u5236<\/td><td>\u8d1f\u8f7d\u5747\u8861\u3001\u5b89\u5168\u9632\u62a4\u3001SSL \u5378\u8f7d\u3001\u7f13\u5b58\u3001\u63d0\u9ad8\u6027\u80fd<\/td><\/tr><tr><td><strong>\u9690\u85cf\u5bf9\u8c61<\/strong><\/td><td>\u9690\u85cf<strong>\u5ba2\u6237\u7aef<\/strong><\/td><td>\u9690\u85cf<strong>\u540e\u7aef\u670d\u52a1\u5668<\/strong><\/td><\/tr><tr><td><strong>\u8c01\u6765\u914d\u7f6e<\/strong><\/td><td>\u5ba2\u6237\u7aef\u6216\u5ba2\u6237\u7aef\u6240\u5728\u7f51\u7edc\u7684\u7ba1\u7406\u5458<\/td><td>\u670d\u52a1\u5668\u6216\u670d\u52a1\u5668\u6240\u5728\u7f51\u7edc\u7684\u7ba1\u7406\u5458<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">\u9ad8\u6821\u7684VPN\u5e76\u975e\u771f\u6b63\u7684VPN<\/h2>\n\n\n\n<p><strong>\u9ad8\u6821\u7684 WebVPN\uff08\u5982\u6c5f\u82cf\u5927\u5b66\u7684 WebVPN\uff09\u5728\u529f\u80fd\u4e0a\u66f4\u63a5\u8fd1\u4e8e\u4e00\u79cd\u7279\u6b8a\u7684\u53cd\u5411\u4ee3\u7406\uff0c\u800c\u4e0d\u662f\u4f20\u7edf\u7684\u3001\u7f51\u7edc\u5c42\u7ea7\u7684 VPN\u3002<\/strong><\/p>\n\n\n\n<p>\u867d\u7136\u5b83\u540d\u5b57\u91cc\u5e26\u6709\u201cVPN\u201d\uff0c\u4f46\u5b83\u548c\u6211\u4eec\u901a\u5e38\u7406\u89e3\u7684\u3001\u901a\u8fc7\u5b89\u88c5\u5ba2\u6237\u7aef\u5efa\u7acb\u7f51\u7edc\u5c42\u96a7\u9053\uff08\u5982 OpenVPN, IPsec VPN\uff09\u7684 VPN \u6709\u663e\u8457\u533a\u522b\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">WebVPN \u7684\u5de5\u4f5c\u539f\u7406\u548c\u4ee3\u7406\u7684\u76f8\u4f3c\u6027<\/h3>\n\n\n\n<p>\u9ad8\u6821\u7684 WebVPN \u901a\u5e38\u88ab\u79f0\u4e3a <strong>SSL VPN Portal<\/strong> \u6216 <strong>Clientless SSL VPN<\/strong>\u3002\u5b83\u7684\u5de5\u4f5c\u65b9\u5f0f\u5982\u4e0b\uff1a<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u7528\u6237\u901a\u8fc7\u6d4f\u89c8\u5668\u8bbf\u95ee WebVPN \u95e8\u6237\uff1a<\/strong> \u4f60\u6253\u5f00\u6d4f\u89c8\u5668\uff0c\u8f93\u5165 WebVPN \u7684\u7f51\u5740\uff08\u4f8b\u5982 <code>webvpn.ujs.edu.cn<\/code>\uff09\uff0c\u7136\u540e\u8f93\u5165\u4f60\u7684\u5b66\u53f7\/\u5de5\u53f7\u548c\u5bc6\u7801\u8fdb\u884c\u767b\u5f55\u3002<\/li>\n\n\n\n<li><strong>WebVPN \u670d\u52a1\u5668\u4f5c\u4e3a\u4e2d\u95f4\u4eba\uff1a<\/strong> \u767b\u5f55\u6210\u529f\u540e\uff0c\u4f60\u4f1a\u770b\u5230\u4e00\u4e2a\u9875\u9762\uff0c\u4e0a\u9762\u5217\u51fa\u4e86\u4f60\u53ef\u4ee5\u8bbf\u95ee\u7684\u6821\u5185\u8d44\u6e90\uff08\u5982\u56fe\u4e66\u9986\u6570\u636e\u5e93\u3001\u6559\u52a1\u7cfb\u7edf\u3001\u79d1\u7814\u7cfb\u7edf\u7b49\uff09\u3002<\/li>\n\n\n\n<li><strong>\u4ee3\u7406\u8bf7\u6c42\uff1a<\/strong> \u5f53\u4f60\u70b9\u51fb\u8fd9\u4e9b\u8d44\u6e90\u94fe\u63a5\u65f6\uff0c\u4f60\u7684\u6d4f\u89c8\u5668\u4f1a\u5411 <strong>WebVPN \u670d\u52a1\u5668<\/strong>\u53d1\u9001\u8bf7\u6c42\u3002WebVPN \u670d\u52a1\u5668\u6536\u5230\u4f60\u7684\u8bf7\u6c42\u540e\uff0c\u4f1a<strong>\u4ee3\u8868\u4f60<\/strong>\u53bb\u8bbf\u95ee\u771f\u6b63\u7684\u6821\u5185\u76ee\u6807\u670d\u52a1\u5668\u3002<\/li>\n\n\n\n<li><strong>\u5185\u5bb9\u91cd\u5199\u548c\u8f6c\u53d1\uff1a<\/strong> \u76ee\u6807\u670d\u52a1\u5668\u5c06\u54cd\u5e94\u53d1\u9001\u7ed9 WebVPN \u670d\u52a1\u5668\uff0cWebVPN \u670d\u52a1\u5668\u53ef\u80fd\u4f1a\u5bf9\u54cd\u5e94\u5185\u5bb9\uff08\u5982 URL\u3001\u811a\u672c\u7b49\uff09\u8fdb\u884c\u91cd\u5199\uff0c\u4ee5\u786e\u4fdd\u5b83\u4eec\u5728\u4f60\u7684\u6d4f\u89c8\u5668\u4e2d\u80fd\u6b63\u786e\u663e\u793a\uff0c\u7136\u540e\u5c06\u5185\u5bb9\u8f6c\u53d1\u7ed9\u4f60\u3002<\/li>\n\n\n\n<li><strong>\u9690\u85cf\u771f\u5b9e IP\uff1a<\/strong> \u5bf9\u4e8e\u6821\u5185\u76ee\u6807\u670d\u52a1\u5668\u800c\u8a00\uff0c\u5b83\u770b\u5230\u7684\u662f WebVPN \u670d\u52a1\u5668\u7684 IP \u5730\u5740\uff0c\u800c\u4e0d\u662f\u4f60\u8bbe\u5907\u7684\u771f\u5b9e\u516c\u7f51 IP \u5730\u5740\u3002<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">\u4e3a\u4ec0\u4e48\u8bf4\u5b83\u66f4\u50cf\u53cd\u5411\u4ee3\u7406\uff1f<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u670d\u52a1\u5bf9\u8c61\uff1a<\/strong> \u5b83\u670d\u52a1\u4e8e\u540e\u7aef\uff08\u6821\u5185\uff09\u670d\u52a1\u5668\uff0c\u5c06\u6821\u5185\u8d44\u6e90\u5b89\u5168\u5730\u66b4\u9732\u7ed9\u6821\u5916\u7528\u6237\u3002\u8fd9\u7b26\u5408\u53cd\u5411\u4ee3\u7406\u201c\u670d\u52a1\u5668\u7684\u4ee3\u7406\u201d\u7684\u5b9a\u4e49\u3002<\/li>\n\n\n\n<li><strong>\u9690\u85cf\u540e\u7aef\uff1a<\/strong> \u5b83\u9690\u85cf\u4e86\u6821\u5185\u8d44\u6e90\u670d\u52a1\u5668\u7684\u771f\u5b9e IP \u5730\u5740\u548c\u5185\u90e8\u7f51\u7edc\u7ed3\u6784\uff0c\u5ba2\u6237\u7aef\uff08\u4f60\u7684\u6d4f\u89c8\u5668\uff09\u53ea\u77e5\u9053\u4e0e WebVPN \u670d\u52a1\u5668\u4ea4\u4e92\u3002<\/li>\n\n\n\n<li><strong>Web \u6d41\u91cf\u5904\u7406\uff1a<\/strong> \u5b83\u4e3b\u8981\u5904\u7406 HTTP\/HTTPS \u534f\u8bae\u7684 Web \u6d41\u91cf\uff0c\u800c\u4e0d\u662f\u50cf\u4f20\u7edf VPN \u90a3\u6837\u5904\u7406\u6240\u6709\u7f51\u7edc\u5c42\u6d41\u91cf\uff08\u5982 ICMP, FTP, SSH \u7b49\uff09\u3002<\/li>\n\n\n\n<li><strong>\u65e0\u9700\u5ba2\u6237\u7aef\uff1a<\/strong> \u6700\u5927\u7684\u7279\u70b9\u662f\u901a\u5e38\u4e0d\u9700\u8981\u5b89\u88c5\u4e13\u95e8\u7684\u5ba2\u6237\u7aef\u8f6f\u4ef6\uff0c\u53ea\u9700\u901a\u8fc7\u6d4f\u89c8\u5668\u5373\u53ef\u8bbf\u95ee\u3002\u8fd9\u662f\u201cClientless\u201d\u7684\u7531\u6765\u3002<\/li>\n\n\n\n<li><strong>SSL\/TLS \u52a0\u5bc6\uff1a<\/strong> \u7528\u6237\u6d4f\u89c8\u5668\u4e0e WebVPN \u670d\u52a1\u5668\u4e4b\u95f4\u7684\u8fde\u63a5\u662f\u52a0\u5bc6\u7684\uff08\u901a\u5e38\u662f HTTPS\uff09\uff0c\u786e\u4fdd\u4e86\u4f20\u8f93\u5b89\u5168\u3002WebVPN \u670d\u52a1\u5668\u4e0e\u540e\u7aef\u6821\u5185\u8d44\u6e90\u4e4b\u95f4\u4e5f\u53ef\u80fd\u662f\u52a0\u5bc6\u6216\u5185\u7f51\u76f4\u8fde\u3002<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">\u4e0e\u4f20\u7edf VPN \u7684\u533a\u522b<\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u7279\u6027<\/th><th>\u9ad8\u6821 WebVPN (SSL VPN Portal)<\/th><th>\u4f20\u7edf VPN (\u5982 OpenVPN, IPsec VPN)<\/th><\/tr><\/thead><tbody><tr><td><strong>\u5de5\u4f5c\u5c42\u7ea7<\/strong><\/td><td>\u4e3b\u8981\u5728<strong>\u5e94\u7528\u5c42 (L7)<\/strong><\/td><td>\u4e3b\u8981\u5728<strong>\u7f51\u7edc\u5c42 (L3)<\/strong> \u6216\u6570\u636e\u94fe\u8def\u5c42 (L2)<\/td><\/tr><tr><td><strong>\u8bbf\u95ee\u65b9\u5f0f<\/strong><\/td><td>\u901a\u8fc7<strong>\u6d4f\u89c8\u5668<\/strong>\u8bbf\u95ee\u95e8\u6237<\/td><td>\u901a\u5e38\u9700\u8981\u5b89\u88c5<strong>\u5ba2\u6237\u7aef\u8f6f\u4ef6<\/strong><\/td><\/tr><tr><td><strong>\u7f51\u7edc\u63a5\u53e3<\/strong><\/td><td><strong>\u4e0d\u521b\u5efa<\/strong>\u865a\u62df\u7f51\u7edc\u63a5\u53e3<\/td><td><strong>\u521b\u5efa<\/strong>\u865a\u62df\u7f51\u7edc\u63a5\u53e3<\/td><\/tr><tr><td><strong>\u6d41\u91cf\u8303\u56f4<\/strong><\/td><td>\u4e3b\u8981\u4ee3\u7406<strong>Web (HTTP\/HTTPS) \u6d41\u91cf<\/strong><\/td><td>\u96a7\u9053\u5316<strong>\u6240\u6709<\/strong>\u6216\u6307\u5b9a\u7f51\u7edc\u6d41\u91cf<\/td><\/tr><tr><td><strong>IP \u5730\u5740<\/strong><\/td><td>\u4f60\u7684\u8bbe\u5907\u4ecd\u4f7f\u7528\u539f IP\uff0cWebVPN \u670d\u52a1\u5668\u4ee3\u8868\u4f60\u8bbf\u95ee<\/td><td>\u4f60\u7684\u8bbe\u5907\u83b7\u5f97\u4e00\u4e2a<strong>\u865a\u62df IP<\/strong>\uff0c\u6210\u4e3a\u76ee\u6807\u7f51\u7edc\u7684\u4e00\u90e8\u5206<\/td><\/tr><tr><td><strong>\u6838\u5fc3\u76ee\u7684<\/strong><\/td><td>\u5b89\u5168\u5730\u8fdc\u7a0b\u8bbf\u95ee<strong>Web \u5e94\u7528<\/strong><\/td><td>\u5b89\u5168\u5730\u8fdc\u7a0b\u8bbf\u95ee<strong>\u6574\u4e2a\u76ee\u6807\u7f51\u7edc<\/strong><\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">\u54c8\u5e0c\u52a0\u5bc6 (Hashing) \u662f\u4ec0\u4e48\uff1f<\/h2>\n\n\n\n<p>\u54c8\u5e0c\u52a0\u5bc6\uff0c\u66f4\u51c6\u786e\u5730\u8bf4\u662f<strong>\u54c8\u5e0c\u51fd\u6570 (Hash Function)<\/strong>\uff0c\u662f\u5bc6\u7801\u5b66\u4e2d\u7684\u4e00\u4e2a\u57fa\u672c\u5de5\u5177\u3002\u5b83\u662f\u4e00\u79cd<strong>\u5355\u5411\u7684\u6570\u5b66\u51fd\u6570<\/strong>\uff0c\u80fd\u591f\u5c06\u4efb\u610f\u957f\u5ea6\u7684\u8f93\u5165\u6570\u636e\uff08\u79f0\u4e3a\u201c\u6d88\u606f\u201d\u6216\u201c\u660e\u6587\u201d\uff09\u8f6c\u6362\u6210\u4e00\u4e2a\u56fa\u5b9a\u957f\u5ea6\u7684\u3001\u770b\u4f3c\u968f\u673a\u7684\u5b57\u7b26\u4e32\uff0c\u8fd9\u4e2a\u5b57\u7b26\u4e32\u88ab\u79f0\u4e3a<strong>\u54c8\u5e0c\u503c (Hash Value)<\/strong>\u3001<strong>\u6563\u5217\u503c<\/strong>\u3001<strong>\u6d88\u606f\u6458\u8981 (Message Digest)<\/strong> \u6216<strong>\u6307\u7eb9 (Fingerprint)<\/strong>\u3002<\/p>\n\n\n\n<p>\u4f60\u53ef\u4ee5\u628a\u5b83\u60f3\u8c61\u6210\u4e00\u4e2a<strong>\u6570\u636e\u7684\u201c\u538b\u7f29\u5668\u201d\u6216\u201c\u6307\u7eb9\u751f\u6210\u5668\u201d<\/strong>\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u6838\u5fc3\u7279\u6027<\/h3>\n\n\n\n<p>\u4e00\u4e2a\u597d\u7684\u5bc6\u7801\u5b66\u54c8\u5e0c\u51fd\u6570\u5fc5\u987b\u5177\u5907\u4ee5\u4e0b\u51e0\u4e2a\u5173\u952e\u7279\u6027\uff1a<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u5355\u5411\u6027 (One-way \/ Preimage Resistance)\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u542b\u4e49\uff1a<\/strong> \u4ece\u54c8\u5e0c\u503c\uff08\u8f93\u51fa\uff09<strong>\u4e0d\u53ef\u80fd<\/strong>\uff08\u5728\u8ba1\u7b97\u4e0a\u4e0d\u53ef\u884c\uff09\u9006\u5411\u63a8\u5bfc\u51fa\u539f\u59cb\u8f93\u5165\u6570\u636e\u3002<\/li>\n\n\n\n<li><strong>\u91cd\u8981\u6027\uff1a<\/strong> \u8fd9\u662f\u54c8\u5e0c\u51fd\u6570\u201c\u52a0\u5bc6\u201d\u6027\u8d28\u7684\u4f53\u73b0\u3002\u4f8b\u5982\uff0c\u5b58\u50a8\u5bc6\u7801\u65f6\uff0c\u6211\u4eec\u53ea\u5b58\u50a8\u54c8\u5e0c\u503c\uff0c\u5373\u4f7f\u6570\u636e\u5e93\u6cc4\u9732\uff0c\u653b\u51fb\u8005\u4e5f\u65e0\u6cd5\u76f4\u63a5\u4ece\u54c8\u5e0c\u503c\u8fd8\u539f\u51fa\u539f\u59cb\u5bc6\u7801\u3002<\/li>\n\n\n\n<li><strong>\u7c7b\u6bd4\uff1a<\/strong> \u5c31\u50cf\u628a\u4e00\u5934\u725b\u6254\u8fdb\u7ede\u8089\u673a\uff0c\u5f97\u5230\u8089\u9985\uff0c\u4f46\u4f60\u65e0\u6cd5\u4ece\u8089\u9985\u8fd8\u539f\u51fa\u539f\u6765\u7684\u90a3\u5934\u725b\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u6297\u78b0\u649e\u6027 (Collision Resistance)\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li>\u542b\u4e49\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u5f31\u6297\u78b0\u649e\u6027 (Second Preimage Resistance)\uff1a<\/strong> \u7ed9\u5b9a\u4e00\u4e2a\u8f93\u5165 <code>M1<\/code>\uff0c\u627e\u5230\u53e6\u4e00\u4e2a\u4e0d\u540c\u7684\u8f93\u5165 <code>M2<\/code>\uff0c\u4f7f\u5f97 <code>hash(M1) = hash(M2)<\/code> \u662f\u8ba1\u7b97\u4e0d\u53ef\u884c\u7684\u3002<\/li>\n\n\n\n<li><strong>\u5f3a\u6297\u78b0\u649e\u6027 (Collision Resistance)\uff1a<\/strong> \u627e\u5230<strong>\u4efb\u610f\u4e24\u4e2a\u4e0d\u540c<\/strong>\u7684\u8f93\u5165 <code>M1<\/code> \u548c <code>M2<\/code>\uff0c\u4f7f\u5f97 <code>hash(M1) = hash(M2)<\/code> \u662f\u8ba1\u7b97\u4e0d\u53ef\u884c\u7684\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u91cd\u8981\u6027\uff1a<\/strong> \u786e\u4fdd\u6bcf\u4e2a\u8f93\u5165\u90fd\u6709\u4e00\u4e2a\u72ec\u7279\u7684\u201c\u6307\u7eb9\u201d\u3002\u5982\u679c\u80fd\u8f7b\u6613\u627e\u5230\u78b0\u649e\uff0c\u653b\u51fb\u8005\u5c31\u53ef\u4ee5\u7528\u4e00\u4e2a\u6076\u610f\u6587\u4ef6\u66ff\u6362\u4e00\u4e2a\u5408\u6cd5\u6587\u4ef6\uff0c\u800c\u5b83\u4eec\u7684\u54c8\u5e0c\u503c\u76f8\u540c\uff0c\u4ece\u800c\u7ed5\u8fc7\u5b8c\u6574\u6027\u6821\u9a8c\u3002<\/li>\n\n\n\n<li><strong>\u7c7b\u6bd4\uff1a<\/strong> \u5c31\u50cf\u5730\u7403\u4e0a\u6bcf\u4e2a\u4eba\u7684\u6307\u7eb9\u90fd\u662f\u72ec\u4e00\u65e0\u4e8c\u7684\uff08\u7406\u8bba\u4e0a\uff09\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u96ea\u5d29\u6548\u5e94 (Avalanche Effect)\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u542b\u4e49\uff1a<\/strong> \u5373\u4f7f\u8f93\u5165\u6570\u636e\u53ea\u53d1\u751f<strong>\u5fae\u5c0f\u7684\u53d8\u5316<\/strong>\uff08\u4f8b\u5982\uff0c\u6539\u53d8\u4e00\u4e2a\u6bd4\u7279\uff09\uff0c\u5176\u751f\u6210\u7684\u54c8\u5e0c\u503c\u4e5f\u4f1a\u53d1\u751f<strong>\u5de8\u5927\u4e14\u4e0d\u53ef\u9884\u6d4b\u7684\u53d8\u5316<\/strong>\u3002<\/li>\n\n\n\n<li><strong>\u91cd\u8981\u6027\uff1a<\/strong> \u4f7f\u5f97\u653b\u51fb\u8005\u65e0\u6cd5\u901a\u8fc7\u5fae\u8c03\u8f93\u5165\u6765\u9884\u6d4b\u54c8\u5e0c\u503c\u7684\u53d8\u5316\uff0c\u4ece\u800c\u96be\u4ee5\u8fdb\u884c\u6709\u76ee\u7684\u7684\u653b\u51fb\u3002<\/li>\n\n\n\n<li><strong>\u7c7b\u6bd4\uff1a<\/strong> \u8774\u8776\u6548\u5e94\uff0c\u6247\u52a8\u4e00\u4e0b\u7fc5\u8180\u53ef\u80fd\u5f15\u53d1\u4e00\u573a\u98ce\u66b4\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u786e\u5b9a\u6027 (Determinism)\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u542b\u4e49\uff1a<\/strong> \u5bf9\u4e8e<strong>\u76f8\u540c\u7684\u8f93\u5165<\/strong>\uff0c\u54c8\u5e0c\u51fd\u6570\u603b\u662f\u4f1a\u4ea7\u751f<strong>\u76f8\u540c\u7684\u54c8\u5e0c\u503c<\/strong>\u3002<\/li>\n\n\n\n<li><strong>\u91cd\u8981\u6027\uff1a<\/strong> \u8fd9\u662f\u54c8\u5e0c\u51fd\u6570\u80fd\u591f\u8fdb\u884c\u9a8c\u8bc1\u7684\u57fa\u7840\u3002\u5982\u679c\u6bcf\u6b21\u54c8\u5e0c\u7ed3\u679c\u90fd\u4e0d\u540c\uff0c\u5c31\u65e0\u6cd5\u8fdb\u884c\u5b8c\u6574\u6027\u6821\u9a8c\u6216\u5bc6\u7801\u9a8c\u8bc1\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u8f93\u51fa\u56fa\u5b9a\u957f\u5ea6\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u542b\u4e49\uff1a<\/strong> \u65e0\u8bba\u8f93\u5165\u6570\u636e\u6709\u591a\u957f\uff0c\u54c8\u5e0c\u51fd\u6570\u751f\u6210\u7684\u54c8\u5e0c\u503c\u957f\u5ea6\u603b\u662f\u56fa\u5b9a\u7684\u3002<\/li>\n\n\n\n<li><strong>\u91cd\u8981\u6027\uff1a<\/strong> \u65b9\u4fbf\u5b58\u50a8\u548c\u6bd4\u8f83\u3002\u4f8b\u5982\uff0cMD5 \u603b\u662f\u751f\u6210 128 \u4f4d\u54c8\u5e0c\u503c\uff0cSHA256 \u603b\u662f\u751f\u6210 256 \u4f4d\u54c8\u5e0c\u503c\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">\u54c8\u5e0c\u52a0\u5bc6\u7684\u7528\u9014<\/h3>\n\n\n\n<p>\u54c8\u5e0c\u52a0\u5bc6\u5728\u4fe1\u606f\u5b89\u5168\u548c\u8ba1\u7b97\u673a\u79d1\u5b66\u4e2d\u6709\u5e7f\u6cdb\u7684\u5e94\u7528\uff0c\u4e3b\u8981\u5305\u62ec\uff1a<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u5bc6\u7801\u5b58\u50a8 (Password Storage)\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li>\u8fd9\u662f\u6700\u5e38\u89c1\u7684\u7528\u9014\u4e4b\u4e00\u3002\u7f51\u7ad9\u548c\u5e94\u7528\u7a0b\u5e8f\u4e0d\u4f1a\u76f4\u63a5\u5b58\u50a8\u7528\u6237\u7684\u660e\u6587\u5bc6\u7801\uff0c\u800c\u662f\u5b58\u50a8\u5bc6\u7801\u7684\u54c8\u5e0c\u503c\uff08\u901a\u5e38\u4f1a\u52a0\u76d0\u5e76\u4f7f\u7528\u6162\u901f\u54c8\u5e0c\u7b97\u6cd5\uff09\u3002<\/li>\n\n\n\n<li>\u5f53\u7528\u6237\u767b\u5f55\u65f6\uff0c\u7cfb\u7edf\u4f1a\u5bf9\u5176\u8f93\u5165\u7684\u5bc6\u7801\u8fdb\u884c\u54c8\u5e0c\u8fd0\u7b97\uff0c\u7136\u540e\u4e0e\u5b58\u50a8\u7684\u54c8\u5e0c\u503c\u8fdb\u884c\u6bd4\u8f83\u3002<\/li>\n\n\n\n<li>\u76ee\u7684\uff1a\u5373\u4f7f\u6570\u636e\u5e93\u88ab\u6cc4\u9732\uff0c\u653b\u51fb\u8005\u4e5f\u65e0\u6cd5\u76f4\u63a5\u83b7\u53d6\u5230\u7528\u6237\u7684\u660e\u6587\u5bc6\u7801\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u6570\u636e\u5b8c\u6574\u6027\u6821\u9a8c (Data Integrity Verification)\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li>\u5728\u6587\u4ef6\u4e0b\u8f7d\u3001\u6570\u636e\u4f20\u8f93\u6216\u5b58\u50a8\u65f6\uff0c\u53ef\u4ee5\u8ba1\u7b97\u6570\u636e\u7684\u54c8\u5e0c\u503c\u3002\u63a5\u6536\u65b9\u6216\u9a8c\u8bc1\u65b9\u91cd\u65b0\u8ba1\u7b97\u6570\u636e\u7684\u54c8\u5e0c\u503c\uff0c\u5e76\u4e0e\u539f\u59cb\u54c8\u5e0c\u503c\u8fdb\u884c\u6bd4\u8f83\u3002<\/li>\n\n\n\n<li>\u5982\u679c\u54c8\u5e0c\u503c\u5339\u914d\uff0c\u5219\u8868\u660e\u6570\u636e\u5728\u4f20\u8f93\u6216\u5b58\u50a8\u8fc7\u7a0b\u4e2d\u6ca1\u6709\u88ab\u7be1\u6539\u3002<\/li>\n\n\n\n<li>\u4f8b\u5982\uff0c\u8f6f\u4ef6\u4e0b\u8f7d\u7f51\u7ad9\u901a\u5e38\u4f1a\u63d0\u4f9b\u6587\u4ef6\u7684 MD5 \u6216 SHA256 \u503c\uff0c\u4f9b\u7528\u6237\u6821\u9a8c\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u6570\u5b57\u7b7e\u540d (Digital Signatures)\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li>\u6570\u5b57\u7b7e\u540d\u662f\u5bf9\u6570\u636e\u7684\u54c8\u5e0c\u503c\u8fdb\u884c\u52a0\u5bc6\uff0c\u800c\u4e0d\u662f\u5bf9\u6574\u4e2a\u6570\u636e\u8fdb\u884c\u52a0\u5bc6\u3002<\/li>\n\n\n\n<li>\u5b83\u7528\u4e8e\u9a8c\u8bc1\u6570\u636e\u7684\u6765\u6e90\uff08\u8c01\u53d1\u9001\u7684\uff09\u548c\u6570\u636e\u7684\u5b8c\u6574\u6027\uff08\u6570\u636e\u662f\u5426\u88ab\u7be1\u6539\uff09\u3002<\/li>\n\n\n\n<li>\u76ee\u7684\uff1a\u786e\u4fdd\u4fe1\u606f\u7684\u771f\u5b9e\u6027\u548c\u4e0d\u53ef\u5426\u8ba4\u6027\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u533a\u5757\u94fe (Blockchain)\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li>\u533a\u5757\u94fe\u6280\u672f\u7684\u6838\u5fc3\u5c31\u662f\u54c8\u5e0c\u94fe\u3002\u6bcf\u4e2a\u533a\u5757\u90fd\u5305\u542b\u524d\u4e00\u4e2a\u533a\u5757\u7684\u54c8\u5e0c\u503c\uff0c\u5f62\u6210\u4e00\u4e2a\u4e0d\u53ef\u7be1\u6539\u7684\u94fe\u6761\u3002<\/li>\n\n\n\n<li>\u4ea4\u6613\u6570\u636e\u548c\u533a\u5757\u5934\u4e5f\u901a\u8fc7\u54c8\u5e0c\u8fdb\u884c\u9a8c\u8bc1\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u6587\u4ef6\u67e5\u627e\u548c\u53bb\u91cd (File Lookup and Deduplication)\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li>\u901a\u8fc7\u8ba1\u7b97\u6587\u4ef6\u7684\u54c8\u5e0c\u503c\uff0c\u53ef\u4ee5\u5feb\u901f\u5224\u65ad\u4e24\u4e2a\u6587\u4ef6\u662f\u5426\u76f8\u540c\uff0c\u6216\u8005\u5728\u5927\u91cf\u6587\u4ef6\u4e2d\u67e5\u627e\u91cd\u590d\u9879\u3002<\/li>\n\n\n\n<li>\u4f8b\u5982\uff0c\u7f51\u76d8\u670d\u52a1\u53ef\u4ee5\u901a\u8fc7\u54c8\u5e0c\u503c\u6765\u8bc6\u522b\u7528\u6237\u4e0a\u4f20\u7684\u91cd\u590d\u6587\u4ef6\uff0c\u4ece\u800c\u8282\u7701\u5b58\u50a8\u7a7a\u95f4\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u6d88\u606f\u8ba4\u8bc1\u7801 (Message Authentication Code, MAC)\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li>\u7ed3\u5408\u5bc6\u94a5\u548c\u54c8\u5e0c\u51fd\u6570\uff0c\u7528\u4e8e\u9a8c\u8bc1\u6d88\u606f\u7684\u5b8c\u6574\u6027\u548c\u771f\u5b9e\u6027\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">\u54c8\u5e0c\u52a0\u5bc6\u4e0d\u662f\u201c\u52a0\u5bc6\u201d<\/h3>\n\n\n\n<p>\u9700\u8981\u7279\u522b\u5f3a\u8c03\u7684\u662f\uff0c\u5c3d\u7ba1\u6211\u4eec\u5e38\u8bf4\u201c\u54c8\u5e0c\u52a0\u5bc6\u201d\uff0c\u4f46\u4ece\u4e25\u683c\u7684\u5bc6\u7801\u5b66\u5b9a\u4e49\u6765\u770b\uff0c<strong>\u54c8\u5e0c\u51fd\u6570\u4e0d\u662f\u52a0\u5bc6\u7b97\u6cd5<\/strong>\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u52a0\u5bc6\u7b97\u6cd5 (Encryption Algorithm)\uff1a<\/strong> \u662f<strong>\u53cc\u5411\u7684<\/strong>\uff0c\u6709\u52a0\u5bc6\u548c\u89e3\u5bc6\u8fc7\u7a0b\uff0c\u9700\u8981\u5bc6\u94a5\u3002\u76ee\u7684\u662f\u4fdd\u62a4\u6570\u636e\u7684\u673a\u5bc6\u6027\uff0c\u4f7f\u5176\u5728\u4f20\u8f93\u6216\u5b58\u50a8\u65f6\u53ea\u6709\u6388\u6743\u65b9\u624d\u80fd\u8bfb\u53d6\u3002<\/li>\n\n\n\n<li><strong>\u54c8\u5e0c\u51fd\u6570 (Hash Function)\uff1a<\/strong> \u662f<strong>\u5355\u5411\u7684<\/strong>\uff0c\u6ca1\u6709\u89e3\u5bc6\u8fc7\u7a0b\uff0c\u4e5f\u4e0d\u9700\u8981\u5bc6\u94a5\uff08\u9664\u975e\u662f\u5e26\u5bc6\u94a5\u7684\u54c8\u5e0c\uff0c\u5982 HMAC\uff09\u3002\u76ee\u7684\u662f\u9a8c\u8bc1\u6570\u636e\u7684\u5b8c\u6574\u6027\u3001\u552f\u4e00\u6027\uff0c\u4ee5\u53ca\u5b89\u5168\u5b58\u50a8\u5bc6\u7801\u3002<\/li>\n<\/ul>\n\n\n\n<p>\u6240\u4ee5\uff0c\u201c\u54c8\u5e0c\u52a0\u5bc6\u201d\u8fd9\u4e2a\u8bcd\u66f4\u591a\u662f\u53e3\u8bed\u5316\u7684\u8bf4\u6cd5\uff0c\u51c6\u786e\u7684\u672f\u8bed\u662f\u201c\u54c8\u5e0c\u51fd\u6570\u201d\u6216\u201c\u5bc6\u7801\u5b66\u54c8\u5e0c\u51fd\u6570\u201d\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u5e38\u89c1\u7684\u54c8\u5e0c\u51fd\u6570<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>MD5\uff1a<\/strong> \u5df2\u88ab\u8bc1\u660e\u4e0d\u5b89\u5168\uff0c\u4e0d\u63a8\u8350\u7528\u4e8e\u5b89\u5168\u7528\u9014\u3002<\/li>\n\n\n\n<li><strong>SHA-1\uff1a<\/strong> \u5df2\u88ab\u8bc1\u660e\u4e0d\u5b89\u5168\uff0c\u4e0d\u63a8\u8350\u7528\u4e8e\u5b89\u5168\u7528\u9014\u3002<\/li>\n\n\n\n<li><strong>SHA-2 \u7cfb\u5217\uff1a<\/strong> \u5305\u62ec SHA-256\u3001SHA-512 \u7b49\uff0c\u76ee\u524d\u4ecd\u88ab\u8ba4\u4e3a\u662f\u5b89\u5168\u7684\u901a\u7528\u54c8\u5e0c\u51fd\u6570\u3002<\/li>\n\n\n\n<li><strong>SHA-3 \u7cfb\u5217\uff1a<\/strong> Keccak \u7b97\u6cd5\uff0cNIST \u9009\u5b9a\u7684\u65b0\u4e00\u4ee3\u54c8\u5e0c\u6807\u51c6\u3002<\/li>\n\n\n\n<li><strong>\u4e13\u95e8\u7528\u4e8e\u5bc6\u7801\u5b58\u50a8\u7684 KDFs (Key Derivation Functions)\uff1a<\/strong> \u5982 Bcrypt\u3001Scrypt\u3001PBKDF2\u3001Argon2\u3002\u5b83\u4eec\u88ab\u8bbe\u8ba1\u6210\u8ba1\u7b97\u7f13\u6162\uff0c\u4ee5\u62b5\u6297\u66b4\u529b\u7834\u89e3\u3002<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">\u52a0\u76d0\u662f\u4ec0\u4e48\uff08\u54c8\u5e0c\uff09<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">\u54c8\u5e0c\u52a0\u5bc6 (Hashing) \u7684\u57fa\u672c\u6982\u5ff5<\/h3>\n\n\n\n<p>\u9996\u5148\uff0c\u56de\u987e\u4e00\u4e0b\u54c8\u5e0c\u52a0\u5bc6\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u5355\u5411\u6027\uff1a<\/strong> \u54c8\u5e0c\u51fd\u6570\u5c06\u4efb\u610f\u957f\u5ea6\u7684\u8f93\u5165\uff08\u5982\u5bc6\u7801\uff09\u8f6c\u6362\u4e3a\u56fa\u5b9a\u957f\u5ea6\u7684\u8f93\u51fa\uff08\u54c8\u5e0c\u503c\/\u6458\u8981\uff09\u3002\u8fd9\u4e2a\u8fc7\u7a0b\u662f\u5355\u5411\u7684\uff0c\u65e0\u6cd5\u4ece\u54c8\u5e0c\u503c\u9006\u5411\u63a8\u5bfc\u51fa\u539f\u59cb\u8f93\u5165\u3002<\/li>\n\n\n\n<li><strong>\u786e\u5b9a\u6027\uff1a<\/strong> \u76f8\u540c\u7684\u8f93\u5165\u603b\u662f\u4ea7\u751f\u76f8\u540c\u7684\u54c8\u5e0c\u503c\u3002<\/li>\n\n\n\n<li><strong>\u96ea\u5d29\u6548\u5e94\uff1a<\/strong> \u8f93\u5165\u7684\u5fae\u5c0f\u53d8\u5316\u4f1a\u5bfc\u81f4\u54c8\u5e0c\u503c\u53d1\u751f\u5de8\u5927\u53d8\u5316\u3002<\/li>\n\n\n\n<li><strong>\u9632\u7be1\u6539\uff1a<\/strong> \u5982\u679c\u6570\u636e\u88ab\u7be1\u6539\uff0c\u5176\u54c8\u5e0c\u503c\u4f1a\u6539\u53d8\uff0c\u4ece\u800c\u53ef\u4ee5\u68c0\u6d4b\u5230\u7be1\u6539\u3002<\/li>\n<\/ul>\n\n\n\n<p>\u7136\u800c\uff0c\u7eaf\u7cb9\u7684\u54c8\u5e0c\u52a0\u5bc6\u5b58\u5728\u4e00\u4e2a\u5f31\u70b9\uff1a<strong>\u5f69\u8679\u8868\u653b\u51fb (Rainbow Table Attack)<\/strong>\u3002\u653b\u51fb\u8005\u53ef\u4ee5\u9884\u5148\u8ba1\u7b97\u5927\u91cf\u5e38\u7528\u5bc6\u7801\u7684\u54c8\u5e0c\u503c\uff0c\u5e76\u5b58\u50a8\u5728\u4e00\u4e2a\u8868\u4e2d\u3002\u5f53\u4ed6\u4eec\u83b7\u53d6\u5230\u6570\u636e\u5e93\u4e2d\u7684\u54c8\u5e0c\u503c\u65f6\uff0c\u53ef\u4ee5\u76f4\u63a5\u67e5\u8868\u627e\u5230\u5bf9\u5e94\u7684\u539f\u59cb\u5bc6\u7801\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u52a0\u76d0 (Salting) \u7684\u76ee\u7684<\/h3>\n\n\n\n<p><strong>\u52a0\u76d0<\/strong>\u5c31\u662f\u4e3a\u4e86\u9632\u5fa1\u5f69\u8679\u8868\u653b\u51fb\u548c\u5b57\u5178\u653b\u51fb\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u539f\u7406\uff1a<\/strong> \u5728\u5bf9\u5bc6\u7801\u8fdb\u884c\u54c8\u5e0c\u8fd0\u7b97\u4e4b\u524d\uff0c\u5148\u5c06\u4e00\u4e2a<strong>\u968f\u673a\u751f\u6210\u7684\u5b57\u7b26\u4e32\uff08\u76d0\uff09<\/strong>\u4e0e\u539f\u59cb\u5bc6\u7801\u7ec4\u5408\u5728\u4e00\u8d77\uff0c\u7136\u540e\u518d\u8fdb\u884c\u54c8\u5e0c\u3002<\/li>\n\n\n\n<li>\u6548\u679c\uff1a\n<ol class=\"wp-block-list\">\n<li>\u5373\u4f7f\u4e24\u4e2a\u7528\u6237\u8bbe\u7f6e\u4e86\u76f8\u540c\u7684\u5bc6\u7801\uff0c\u7531\u4e8e\u4ed6\u4eec\u7684\u76d0\u4e0d\u540c\uff0c\u6700\u7ec8\u751f\u6210\u7684\u54c8\u5e0c\u503c\u4e5f\u4f1a\u4e0d\u540c\u3002<\/li>\n\n\n\n<li>\u653b\u51fb\u8005\u65e0\u6cd5\u4f7f\u7528\u9884\u5148\u8ba1\u7b97\u597d\u7684\u5f69\u8679\u8868\uff0c\u56e0\u4e3a\u6bcf\u4e2a\u54c8\u5e0c\u503c\u90fd\u5305\u542b\u4e86\u72ec\u7279\u7684\u76d0\u3002\u653b\u51fb\u8005\u5fc5\u987b\u4e3a\u6bcf\u4e2a\u54c8\u5e0c\u503c\u91cd\u65b0\u8fdb\u884c\u8ba1\u7b97\uff0c\u5927\u5927\u589e\u52a0\u4e86\u653b\u51fb\u6210\u672c\u3002<\/li>\n\n\n\n<li>\u5373\u4f7f\u653b\u51fb\u8005\u77e5\u9053\u67d0\u4e2a\u5bc6\u7801\u7684\u54c8\u5e0c\u503c\uff0c\u4e5f\u65e0\u6cd5\u76f4\u63a5\u7528\u5f69\u8679\u8868\u67e5\u627e\uff0c\u56e0\u4e3a\u4ed6\u4e0d\u77e5\u9053\u8fd9\u4e2a\u54c8\u5e0c\u503c\u662f\u54ea\u4e2a\u76d0\u751f\u6210\u7684\u3002<\/li>\n<\/ol>\n<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">\u76d0 (Salt) \u4ee5\u4ec0\u4e48\u5f62\u5f0f\u4fdd\u5b58\uff1f<\/h3>\n\n\n\n<p>\u76d0\u7684\u4fdd\u5b58\u5f62\u5f0f\u975e\u5e38\u5173\u952e\uff0c\u56e0\u4e3a\u5b83\u76f4\u63a5\u5f71\u54cd\u5230\u52a0\u76d0\u673a\u5236\u7684\u6709\u6548\u6027\u3002<\/p>\n\n\n\n<p><strong>\u76d0\u901a\u5e38\u4ee5\u201c\u660e\u6587\u201d\u5f62\u5f0f\uff0c\u4e0e\u54c8\u5e0c\u540e\u7684\u5bc6\u7801\u4e00\u8d77\u5b58\u50a8\u5728\u6570\u636e\u5e93\u4e2d\u3002<\/strong><\/p>\n\n\n\n<p>\u8fd9\u542c\u8d77\u6765\u53ef\u80fd\u6709\u70b9\u53cd\u76f4\u89c9\uff0c\u4f46\u8fd9\u662f\u6b63\u786e\u7684\u505a\u6cd5\uff0c\u5e76\u4e14\u4e0d\u4f1a\u964d\u4f4e\u5b89\u5168\u6027\u3002<\/p>\n\n\n\n<p><strong>\u5177\u4f53\u4fdd\u5b58\u5f62\u5f0f\uff1a<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u4f5c\u4e3a\u54c8\u5e0c\u503c\u7684\u4e00\u90e8\u5206\uff1a \u6700\u5e38\u89c1\u7684\u65b9\u5f0f\u662f\u5c06\u76d0\u76f4\u63a5\u9644\u52a0\u6216\u524d\u7f6e\u5230\u54c8\u5e0c\u503c\u4e2d\uff0c\u7136\u540e\u5c06\u6574\u4e2a\u5b57\u7b26\u4e32\u5b58\u50a8\u4e3a\u4e00\u4e2a\u5b57\u6bb5\u3002\n<ul class=\"wp-block-list\">\n<li>\u4f8b\u5982\uff1a<code>hashed_password = hash(password + salt)<\/code>\uff0c\u7136\u540e\u5b58\u50a8 <code>salt + hashed_password<\/code>\u3002<\/li>\n\n\n\n<li>\u6570\u636e\u5e93\u5b57\u6bb5\u53ef\u80fd\u770b\u8d77\u6765\u50cf\u8fd9\u6837\uff1a<code>$salt_value$hashed_value<\/code><\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u4f5c\u4e3a\u5355\u72ec\u7684\u5b57\u6bb5\uff1a<\/strong> \u5728\u6570\u636e\u5e93\u7684\u7528\u6237\u8868\u4e2d\uff0c\u4e3a\u6bcf\u4e2a\u7528\u6237\u521b\u5efa\u4e00\u4e2a\u5355\u72ec\u7684 <code>salt<\/code> \u5b57\u6bb5\uff0c\u4e0e <code>password_hash<\/code> \u5b57\u6bb5\u5e76\u884c\u5b58\u50a8\u3002<\/li>\n<\/ul>\n\n\n\n<p><strong>\u4e3a\u4ec0\u4e48\u76d0\u53ef\u4ee5\u660e\u6587\u4fdd\u5b58\uff1f<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u76d0\u4e0d\u662f\u79d8\u5bc6\uff1a<\/strong> \u76d0\u7684\u76ee\u7684\u662f\u8ba9\u6bcf\u4e2a\u54c8\u5e0c\u503c\u90fd\u72ec\u4e00\u65e0\u4e8c\uff0c\u800c\u4e0d\u662f\u4f5c\u4e3a\u4e00\u4e2a\u79d8\u5bc6\u6765\u4fdd\u62a4\u3002\u5b83\u7684\u968f\u673a\u6027\u548c\u552f\u4e00\u6027\u624d\u662f\u5173\u952e\u3002<\/li>\n\n\n\n<li><strong>\u54c8\u5e0c\u51fd\u6570\u7684\u5355\u5411\u6027\uff1a<\/strong> \u5373\u4f7f\u653b\u51fb\u8005\u77e5\u9053\u76d0\u548c\u54c8\u5e0c\u503c\uff0c\u4e5f\u65e0\u6cd5\u901a\u8fc7\u5b83\u4eec\u9006\u5411\u63a8\u5bfc\u51fa\u539f\u59cb\u5bc6\u7801\uff0c\u56e0\u4e3a\u54c8\u5e0c\u51fd\u6570\u662f\u5355\u5411\u7684\u3002<\/li>\n\n\n\n<li><strong>\u9a8c\u8bc1\u9700\u8981\uff1a<\/strong> \u5728\u9a8c\u8bc1\u5bc6\u7801\u65f6\uff0c\u670d\u52a1\u5668\u9700\u8981\u77e5\u9053\u7528\u6237\u5bf9\u5e94\u7684\u76d0\uff0c\u624d\u80fd\u7528\u76f8\u540c\u7684\u76d0\u548c\u7528\u6237\u8f93\u5165\u7684\u5bc6\u7801\u91cd\u65b0\u8ba1\u7b97\u54c8\u5e0c\u503c\u8fdb\u884c\u6bd4\u8f83\u3002\u5982\u679c\u76d0\u662f\u79d8\u5bc6\u7684\uff0c\u670d\u52a1\u5668\u5c31\u65e0\u6cd5\u9a8c\u8bc1\u3002<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">\u540e\u7eed\u5982\u4f55\u9a8c\u8bc1\u5bc6\u7801\u662f\u6b63\u786e\u7684\uff1f<\/h3>\n\n\n\n<p>\u5f53\u7528\u6237\u5c1d\u8bd5\u767b\u5f55\u5e76\u8f93\u5165\u5bc6\u7801\u65f6\uff0c\u7cfb\u7edf\u4f1a\u6267\u884c\u4ee5\u4e0b\u9a8c\u8bc1\u6b65\u9aa4\uff1a<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u7528\u6237\u8f93\u5165\u5bc6\u7801\uff1a<\/strong> \u7528\u6237\u5728\u767b\u5f55\u754c\u9762\u8f93\u5165\u4ed6\u4eec\u7684\u539f\u59cb\u5bc6\u7801\uff08<code>user_input_password<\/code>\uff09\u3002<\/li>\n\n\n\n<li>\u4ece\u6570\u636e\u5e93\u83b7\u53d6\u76d0\u548c\u54c8\u5e0c\u503c\uff1a \u7cfb\u7edf\u6839\u636e\u7528\u6237\u7684\u7528\u6237\u540d\uff08\u6216\u5176\u4ed6\u552f\u4e00\u6807\u8bc6\u7b26\uff09\uff0c\u4ece\u6570\u636e\u5e93\u4e2d\u68c0\u7d22\u51fa\u8be5\u7528\u6237\u5bf9\u5e94\u7684\u5b58\u50a8\u7684\u76d0 (<code>stored_salt<\/code>) <strong>\u548c<\/strong>\u5b58\u50a8\u7684\u54c8\u5e0c\u503c (<code>stored_hash<\/code>)\u3002\n<ul class=\"wp-block-list\">\n<li>\u5982\u679c\u76d0\u662f\u5b58\u50a8\u5728\u54c8\u5e0c\u503c\u5b57\u7b26\u4e32\u4e2d\u7684\uff0c\u7cfb\u7edf\u4f1a\u89e3\u6790\u51fa\u76d0\u548c\u54c8\u5e0c\u503c\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>\u8ba1\u7b97\u7528\u6237\u8f93\u5165\u5bc6\u7801\u7684\u54c8\u5e0c\u503c\uff1a \u7cfb\u7edf\u4f7f\u7528\u76f8\u540c\u7684\u54c8\u5e0c\u7b97\u6cd5\u548c\u4ece\u6570\u636e\u5e93\u4e2d\u83b7\u53d6\u7684 <code>stored_salt<\/code>\uff0c\u5bf9\u7528\u6237\u8f93\u5165\u7684\u5bc6\u7801 (user_input_password) \u8fdb\u884c\u54c8\u5e0c\u8fd0\u7b97\u3002\n<ul class=\"wp-block-list\">\n<li><code>computed_hash = hash(user_input_password + stored_salt)<\/code><\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>\u6bd4\u8f83\u54c8\u5e0c\u503c\uff1a \u7cfb\u7edf\u5c06computed_hash\u4e0e\u4ece\u6570\u636e\u5e93\u4e2d\u68c0\u7d22\u5230\u7684stored_hash\u8fdb\u884c\u6bd4\u8f83\u3002\n<ul class=\"wp-block-list\">\n<li><strong>\u5982\u679c <code>computed_hash<\/code> == <code>stored_hash<\/code>\uff1a<\/strong> \u5bc6\u7801\u662f\u6b63\u786e\u7684\uff0c\u7528\u6237\u901a\u8fc7\u8eab\u4efd\u9a8c\u8bc1\u3002<\/li>\n\n\n\n<li><strong>\u5982\u679c <code>computed_hash<\/code> != <code>stored_hash<\/code>\uff1a<\/strong> \u5bc6\u7801\u662f\u9519\u8bef\u7684\uff0c\u8eab\u4efd\u9a8c\u8bc1\u5931\u8d25\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">\u793a\u4f8b\u6d41\u7a0b<\/h3>\n\n\n\n<p>\u5047\u8bbe\u7528\u6237\u540d\u4e3a <code>alice<\/code>\uff0c\u5bc6\u7801\u4e3a <code>password123<\/code>\u3002<\/p>\n\n\n\n<p><strong>\u6ce8\u518c\u65f6\uff1a<\/strong><\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Alice \u8f93\u5165 <code>password123<\/code>\u3002<\/li>\n\n\n\n<li>\u7cfb\u7edf\u751f\u6210\u4e00\u4e2a\u968f\u673a\u76d0\uff0c\u4f8b\u5982 <code>xyzABC123<\/code>\u3002<\/li>\n\n\n\n<li>\u7cfb\u7edf\u8ba1\u7b97 <code>hash(\"password123\" + \"xyzABC123\")<\/code>\uff0c\u5f97\u5230\u54c8\u5e0c\u503c <code>H1<\/code>\u3002<\/li>\n\n\n\n<li>\u7cfb\u7edf\u5728\u6570\u636e\u5e93\u4e2d\u4fdd\u5b58\uff1a\n<ul class=\"wp-block-list\">\n<li><code>username: alice<\/code><\/li>\n\n\n\n<li><code>salt: xyzABC123<\/code><\/li>\n\n\n\n<li><code>password_hash: H1<\/code><\/li>\n<\/ul>\n<\/li>\n<\/ol>\n\n\n\n<p><strong>\u767b\u5f55\u65f6\uff1a<\/strong><\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Alice \u8f93\u5165\u7528\u6237\u540d <code>alice<\/code> \u548c\u5bc6\u7801 <code>password123<\/code>\u3002<\/li>\n\n\n\n<li>\u7cfb\u7edf\u6839\u636e <code>alice<\/code> \u4ece\u6570\u636e\u5e93\u4e2d\u67e5\u8be2\uff0c\u83b7\u53d6\u5230 <code>salt: xyzABC123<\/code> \u548c <code>password_hash: H1<\/code>\u3002<\/li>\n\n\n\n<li>\u7cfb\u7edf\u8ba1\u7b97 <code>hash(\"password123\" + \"xyzABC123\")<\/code>\uff0c\u5f97\u5230\u54c8\u5e0c\u503c <code>H2<\/code>\u3002<\/li>\n\n\n\n<li>\u7cfb\u7edf\u6bd4\u8f83H1\u548cH2\u3002\n<ul class=\"wp-block-list\">\n<li>\u56e0\u4e3a <code>password123<\/code> \u662f\u6b63\u786e\u7684\uff0c\u6240\u4ee5 <code>H1<\/code> == <code>H2<\/code>\u3002\u767b\u5f55\u6210\u529f\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n\n\n\n<p>\u5982\u679c Alice \u8f93\u5165\u4e86\u9519\u8bef\u7684\u5bc6\u7801 <code>wrongpass<\/code>\uff1a<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>\u7cfb\u7edf\u8ba1\u7b97 <code>hash(\"wrongpass\" + \"xyzABC123\")<\/code>\uff0c\u5f97\u5230\u54c8\u5e0c\u503c <code>H3<\/code>\u3002<\/li>\n\n\n\n<li>\u7cfb\u7edf\u6bd4\u8f83H1\u548cH3\u3002\n<ul class=\"wp-block-list\">\n<li>\u56e0\u4e3a <code>wrongpass<\/code> \u662f\u9519\u8bef\u7684\uff0c\u6240\u4ee5 <code>H1<\/code> != <code>H3<\/code>\u3002\u767b\u5f55\u5931\u8d25\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\">\u4e0d\u5b89\u5168\u7684\u52a0\u89e3\u5bc6\u662f\u4ec0\u4e48\uff1f<\/h2>\n\n\n\n<p>\u201c\u4e0d\u5b89\u5168\u7684\u52a0\u89e3\u5bc6\u201d\u901a\u5e38\u6307\u7684\u662f\u5728\u5bc6\u7801\u5b66\u5b9e\u8df5\u4e2d\uff0c\u7531\u4e8e\u8bbe\u8ba1\u7f3a\u9677\u3001\u5b9e\u73b0\u9519\u8bef\u3001\u7b97\u6cd5\u8fc7\u65f6\u6216\u4f7f\u7528\u4e0d\u5f53\uff0c\u5bfc\u81f4\u65e0\u6cd5\u6709\u6548\u4fdd\u62a4\u6570\u636e\u673a\u5bc6\u6027\u3001\u5b8c\u6574\u6027\u6216\u8eab\u4efd\u9a8c\u8bc1\u7684\u52a0\u5bc6\u65b9\u6848\u3002<\/p>\n\n\n\n<p>\u5177\u4f53\u6765\u8bf4\uff0c\u53ef\u80fd\u5305\u62ec\uff1a<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u4f7f\u7528\u5f31\u52a0\u5bc6\u7b97\u6cd5\uff1a<\/strong> \u4f8b\u5982\uff0c\u4f7f\u7528 DES\u3001RC4 \u7b49\u5df2\u88ab\u8bc1\u660e\u5b58\u5728\u4e25\u91cd\u6f0f\u6d1e\u6216\u8ba1\u7b97\u80fd\u529b\u4e0d\u8db3\u4ee5\u62b5\u6297\u73b0\u4ee3\u653b\u51fb\u7684\u7b97\u6cd5\u3002<\/li>\n\n\n\n<li><strong>\u4f7f\u7528\u5f31\u54c8\u5e0c\u51fd\u6570\u8fdb\u884c\u5bc6\u7801\u5b58\u50a8\uff1a<\/strong> \u4f8b\u5982\uff0c\u4f7f\u7528 MD5 \u6216 SHA1 \u76f4\u63a5\u5b58\u50a8\u5bc6\u7801\uff08\u5373\u4f7f\u52a0\u76d0\uff0c\u4e5f\u56e0\u5176\u901f\u5ea6\u5feb\u800c\u6613\u53d7\u66b4\u529b\u7834\u89e3\uff09\u3002<\/li>\n\n\n\n<li><strong>\u4e0d\u52a0\u76d0\u7684\u54c8\u5e0c\uff1a<\/strong> \u76f4\u63a5\u5bf9\u5bc6\u7801\u8fdb\u884c\u54c8\u5e0c\uff0c\u5bb9\u6613\u53d7\u5230\u5f69\u8679\u8868\u653b\u51fb\u3002<\/li>\n\n\n\n<li><strong>\u4f7f\u7528\u53ef\u9006\u52a0\u5bc6\u5b58\u50a8\u5bc6\u7801\uff1a<\/strong> \u5c06\u5bc6\u7801\u7528\u53ef\u9006\u52a0\u5bc6\u7b97\u6cd5\u52a0\u5bc6\u540e\u5b58\u50a8\uff0c\u800c\u4e0d\u662f\u54c8\u5e0c\u3002\u8fd9\u610f\u5473\u7740\u653b\u51fb\u8005\u4e00\u65e6\u83b7\u53d6\u5230\u5bc6\u94a5\uff0c\u5c31\u80fd\u76f4\u63a5\u89e3\u5bc6\u6240\u6709\u5bc6\u7801\u3002\u8fd9\u662f<strong>\u975e\u5e38\u5371\u9669<\/strong>\u7684\u505a\u6cd5\u3002<\/li>\n\n\n\n<li>\u5bc6\u94a5\u7ba1\u7406\u4e0d\u5f53\uff1a\n<ul class=\"wp-block-list\">\n<li>\u786c\u7f16\u7801\u5bc6\u94a5\u5230\u4ee3\u7801\u4e2d\u3002<\/li>\n\n\n\n<li>\u4f7f\u7528\u5f31\u5bc6\u94a5\u6216\u53ef\u9884\u6d4b\u7684\u5bc6\u94a5\u3002<\/li>\n\n\n\n<li>\u5bc6\u94a5\u6ca1\u6709\u53d7\u5230\u9002\u5f53\u7684\u4fdd\u62a4\uff0c\u5bb9\u6613\u88ab\u6cc4\u9732\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>\u5b9e\u73b0\u9519\u8bef\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u968f\u673a\u6570\u751f\u6210\u5668\u4e0d\u5b89\u5168\uff1a<\/strong> \u4f7f\u7528\u53ef\u9884\u6d4b\u7684\u4f2a\u968f\u673a\u6570\u751f\u6210\u5668\u6765\u751f\u6210\u5bc6\u94a5\u6216 IV (\u521d\u59cb\u5316\u5411\u91cf)\u3002<\/li>\n\n\n\n<li><strong>\u4e0d\u4f7f\u7528 IV\uff1a<\/strong> \u5728\u5757\u5bc6\u7801\u6a21\u5f0f\u4e2d\u4e0d\u4f7f\u7528\u6216\u91cd\u590d\u4f7f\u7528 IV\uff0c\u53ef\u80fd\u5bfc\u81f4\u6a21\u5f0f\u6cc4\u9732\u6216\u91cd\u653e\u653b\u51fb\u3002<\/li>\n\n\n\n<li><strong>\u586b\u5145\u653b\u51fb\uff1a<\/strong> \u5757\u5bc6\u7801\u6a21\u5f0f\u7684\u586b\u5145\u65b9\u5f0f\u5b58\u5728\u6f0f\u6d1e\uff0c\u53ef\u80fd\u5bfc\u81f4\u653b\u51fb\u8005\u901a\u8fc7\u9519\u8bef\u6d88\u606f\u63a8\u65ad\u660e\u6587\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u534f\u8bae\u8bbe\u8ba1\u7f3a\u9677\uff1a<\/strong> \u5373\u4f7f\u5e95\u5c42\u7b97\u6cd5\u5b89\u5168\uff0c\u534f\u8bae\u672c\u8eab\u4e5f\u53ef\u80fd\u5b58\u5728\u903b\u8f91\u6f0f\u6d1e\uff0c\u5bfc\u81f4\u4fe1\u606f\u6cc4\u9732\u6216\u8ba4\u8bc1\u7ed5\u8fc7\u3002<\/li>\n\n\n\n<li><strong>\u4f7f\u7528\u8fc7\u77ed\u7684\u5bc6\u94a5\u957f\u5ea6\uff1a<\/strong> \u5bc6\u94a5\u957f\u5ea6\u4e0d\u8db3\u4ee5\u62b5\u6297\u66b4\u529b\u7834\u89e3\u653b\u51fb\u3002<\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\">MD5 \u548c SHA1 \u662f\u4ec0\u4e48\uff1f\u4e3a\u4ec0\u4e48\u5b83\u4eec\u88ab\u7834\u89e3\u4e86\uff1f<\/h2>\n\n\n\n<p>MD5 \u548c SHA1 \u90fd\u662f<strong>\u54c8\u5e0c\u51fd\u6570 (Hash Functions)<\/strong>\uff0c\u5b83\u4eec\u5c5e\u4e8e\u5bc6\u7801\u5b66\u54c8\u5e0c\u51fd\u6570\uff0c\u65e8\u5728\u5c06\u4efb\u610f\u957f\u5ea6\u7684\u6570\u636e\u6620\u5c04\u4e3a\u56fa\u5b9a\u957f\u5ea6\u7684\u54c8\u5e0c\u503c\uff08\u6216\u79f0\u4e3a\u6d88\u606f\u6458\u8981\u3001\u6307\u7eb9\uff09\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>MD5 (Message-Digest Algorithm 5)\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li>\u7531 Ronald Rivest \u5728 1991 \u5e74\u8bbe\u8ba1\u3002<\/li>\n\n\n\n<li>\u751f\u6210\u4e00\u4e2a <strong>128 \u4f4d (16 \u5b57\u8282)<\/strong> \u7684\u54c8\u5e0c\u503c\u3002<\/li>\n\n\n\n<li>\u66fe\u7ecf\u5e7f\u6cdb\u7528\u4e8e\u6570\u636e\u5b8c\u6574\u6027\u6821\u9a8c\u548c\u5bc6\u7801\u5b58\u50a8\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>SHA1 (Secure Hash Algorithm 1)\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li>\u7531\u7f8e\u56fd\u56fd\u5bb6\u5b89\u5168\u5c40 (NSA) \u8bbe\u8ba1\uff0c\u662f SHA-0 \u7684\u6539\u8fdb\u7248\u672c\u3002<\/li>\n\n\n\n<li>\u751f\u6210\u4e00\u4e2a <strong>160 \u4f4d (20 \u5b57\u8282)<\/strong> \u7684\u54c8\u5e0c\u503c\u3002<\/li>\n\n\n\n<li>\u66fe\u7ecf\u5e7f\u6cdb\u7528\u4e8e\u6570\u5b57\u7b7e\u540d\u3001\u8bc1\u4e66\u548c\u5bc6\u7801\u5b58\u50a8\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">\u4e3a\u4ec0\u4e48\u5b83\u4eec\u88ab\u201c\u7834\u89e3\u201d\u4e86\uff1f<\/h4>\n\n\n\n<p>\u8fd9\u91cc\u7684\u201c\u7834\u89e3\u201d\u4e3b\u8981\u6307\u7684\u662f\u53d1\u73b0\u4e86\u5b83\u4eec\u7684<strong>\u78b0\u649e\u653b\u51fb (Collision Attack)<\/strong> \u548c<strong>\u539f\u50cf\u653b\u51fb (Preimage Attack)<\/strong> \u7684\u53ef\u884c\u6027\uff0c\u8fd9\u4f7f\u5f97\u5b83\u4eec\u4e0d\u518d\u9002\u7528\u4e8e\u9700\u8981\u9ad8\u5b89\u5168\u6027\u7684\u573a\u666f\u3002<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u78b0\u649e\u653b\u51fb (Collision Attack)\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u5b9a\u4e49\uff1a<\/strong> \u627e\u5230<strong>\u4e24\u4e2a\u4e0d\u540c\u7684\u8f93\u5165<\/strong>\uff0c\u5b83\u4eec\u7ecf\u8fc7\u54c8\u5e0c\u51fd\u6570\u8ba1\u7b97\u540e\uff0c\u4f1a\u4ea7\u751f<strong>\u76f8\u540c\u7684\u54c8\u5e0c\u503c<\/strong>\u3002<\/li>\n\n\n\n<li>MD5 \u7684\u7834\u89e3\uff1a\n<ul class=\"wp-block-list\">\n<li>\u65e9\u5728 2004 \u5e74\uff0c\u4e2d\u56fd\u5bc6\u7801\u5b66\u5bb6\u738b\u5c0f\u4e91\u6559\u6388\u7b49\u4eba\u5c31\u9996\u6b21\u516c\u5e03\u4e86 MD5 \u7684\u78b0\u649e\u653b\u51fb\u65b9\u6cd5\uff0c\u53ef\u4ee5\u5728\u5408\u7406\u7684\u65f6\u95f4\u5185\uff08\u51e0\u5206\u949f\u5230\u51e0\u5c0f\u65f6\uff09\u627e\u5230 MD5 \u78b0\u649e\u3002<\/li>\n\n\n\n<li>\u8fd9\u610f\u5473\u7740\u653b\u51fb\u8005\u53ef\u4ee5\u6784\u9020\u4e24\u4e2a\u4e0d\u540c\u7684\u6587\u4ef6\uff08\u4f8b\u5982\u4e00\u4e2a\u65e0\u5bb3\u6587\u4ef6\u548c\u4e00\u4e2a\u6076\u610f\u6587\u4ef6\uff09\uff0c\u4f46\u5b83\u4eec\u62e5\u6709\u76f8\u540c\u7684 MD5 \u54c8\u5e0c\u503c\u3002\u5982\u679c\u7cfb\u7edf\u4ec5\u901a\u8fc7 MD5 \u54c8\u5e0c\u503c\u6765\u9a8c\u8bc1\u6587\u4ef6\u5b8c\u6574\u6027\uff0c\u653b\u51fb\u8005\u5c31\u53ef\u4ee5\u7528\u6076\u610f\u6587\u4ef6\u66ff\u6362\u65e0\u5bb3\u6587\u4ef6\u800c\u4e0d\u88ab\u53d1\u73b0\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>SHA1 \u7684\u7834\u89e3\uff1a\n<ul class=\"wp-block-list\">\n<li>2005 \u5e74\uff0c\u738b\u5c0f\u4e91\u6559\u6388\u7b49\u4eba\u4e5f\u516c\u5e03\u4e86\u5bf9 SHA1 \u7684\u78b0\u649e\u653b\u51fb\u65b9\u6cd5\u3002<\/li>\n\n\n\n<li>2017 \u5e74\uff0cGoogle \u5ba3\u5e03\u6210\u529f\u8fdb\u884c\u4e86\u9996\u6b21\u516c\u5f00\u7684 SHA1 \u5b9e\u9645\u78b0\u649e\u653b\u51fb\uff08SHAttered\uff09\uff0c\u5728\u4e91\u5e73\u53f0\u4e0a\u82b1\u8d39\u4e86\u5927\u7ea6 110,000 \u4e2a CPU \u6838\u65f6\u548c 6,500 \u4e2a GPU \u6838\u65f6\u3002\u8fd9\u8bc1\u660e\u4e86 SHA1 \u78b0\u649e\u653b\u51fb\u5728\u8ba1\u7b97\u4e0a\u662f\u53ef\u884c\u7684\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u5f71\u54cd\uff1a<\/strong> \u78b0\u649e\u653b\u51fb\u4f7f\u5f97 MD5 \u548c SHA1 \u4e0d\u518d\u9002\u5408\u7528\u4e8e\u6570\u5b57\u7b7e\u540d\uff08\u56e0\u4e3a\u53ef\u4ee5\u4f2a\u9020\u7b7e\u540d\uff09\u3001\u6587\u4ef6\u5b8c\u6574\u6027\u6821\u9a8c\uff08\u56e0\u4e3a\u53ef\u4ee5\u66ff\u6362\u6587\u4ef6\uff09\u7b49\u9700\u8981\u552f\u4e00\u6027\u7684\u573a\u666f\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u539f\u50cf\u653b\u51fb (Preimage Attack) \u548c \u7b2c\u4e8c\u539f\u50cf\u653b\u51fb (Second Preimage Attack)\uff1a<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>\u539f\u50cf\u653b\u51fb\uff1a<\/strong> \u7ed9\u5b9a\u4e00\u4e2a\u54c8\u5e0c\u503c <code>H<\/code>\uff0c\u627e\u5230\u4e00\u4e2a\u8f93\u5165 <code>M<\/code>\uff0c\u4f7f\u5f97 <code>hash(M) = H<\/code>\u3002\u8fd9\u76f8\u5f53\u4e8e\u4ece\u54c8\u5e0c\u503c\u9006\u63a8\u539f\u59cb\u8f93\u5165\u3002<\/li>\n\n\n\n<li><strong>\u7b2c\u4e8c\u539f\u50cf\u653b\u51fb\uff1a<\/strong> \u7ed9\u5b9a\u4e00\u4e2a\u8f93\u5165 <code>M1<\/code> \u53ca\u5176\u54c8\u5e0c\u503c <code>H = hash(M1)<\/code>\uff0c\u627e\u5230\u53e6\u4e00\u4e2a\u4e0d\u540c\u7684\u8f93\u5165 <code>M2<\/code>\uff0c\u4f7f\u5f97 <code>hash(M2) = H<\/code>\u3002<\/li>\n\n\n\n<li><strong>MD5 \u548c SHA1 \u7684\u73b0\u72b6\uff1a<\/strong> \u5c3d\u7ba1\u78b0\u649e\u653b\u51fb\u5df2\u7ecf\u53ef\u884c\uff0c\u4f46\u5bf9\u4e8e MD5 \u548c SHA1 \u6765\u8bf4\uff0c<strong>\u539f\u50cf\u653b\u51fb\u4ecd\u7136\u662f\u8ba1\u7b97\u4e0d\u53ef\u884c\u7684<\/strong>\uff08\u5373\uff0c\u4ece\u54c8\u5e0c\u503c\u9006\u63a8\u539f\u59cb\u5bc6\u7801\u4ecd\u7136\u6781\u5176\u56f0\u96be\uff09\u3002<\/li>\n\n\n\n<li><strong>\u5f71\u54cd\uff1a<\/strong> \u8fd9\u610f\u5473\u7740\u5728\u52a0\u76d0\u7684\u60c5\u51b5\u4e0b\uff0cMD5 \u548c SHA1 \u4ecd\u7136\u53ef\u4ee5\u5728\u4e00\u5b9a\u7a0b\u5ea6\u4e0a\u7528\u4e8e\u5bc6\u7801\u5b58\u50a8\uff08\u56e0\u4e3a\u5f69\u8679\u8868\u653b\u51fb\u88ab\u963b\u6b62\uff0c\u800c\u539f\u50cf\u653b\u51fb\u4f9d\u7136\u56f0\u96be\uff09\u3002\u7136\u800c\uff0c\u7531\u4e8e\u5b83\u4eec\u901f\u5ea6\u5feb\uff0c\u5bb9\u6613\u53d7\u5230<strong>\u66b4\u529b\u7834\u89e3\u653b\u51fb<\/strong>\uff08\u653b\u51fb\u8005\u5c1d\u8bd5\u6240\u6709\u53ef\u80fd\u7684\u5bc6\u7801\uff0c\u5e76\u8ba1\u7b97\u5b83\u4eec\u7684\u54c8\u5e0c\u503c\u6765\u5339\u914d\uff09\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n\n\n\n<h4 class=\"wp-block-heading\">\u4e3a\u4ec0\u4e48\u901f\u5ea6\u5feb\u53cd\u800c\u6210\u4e3a\u7f3a\u70b9\uff1f<\/h4>\n\n\n\n<p>\u5bf9\u4e8e\u5bc6\u7801\u54c8\u5e0c\u6765\u8bf4\uff0c\u54c8\u5e0c\u51fd\u6570\u7684\u901f\u5ea6\u5feb\u662f\u4e00\u4e2a<strong>\u5de8\u5927\u7684\u5b89\u5168\u9690\u60a3<\/strong>\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u653b\u51fb\u8005\u53ef\u4ee5\u5229\u7528 MD5 \u548c SHA1 \u7684\u9ad8\u901f\u7279\u6027\uff0c\u5728\u77ed\u65f6\u95f4\u5185\u5c1d\u8bd5\u6570\u4e07\u4ebf\u4e2a\u5bc6\u7801\u7ec4\u5408\uff0c\u8fdb\u884c<strong>\u66b4\u529b\u7834\u89e3<\/strong>\u3002<\/li>\n\n\n\n<li>\u5373\u4f7f\u52a0\u4e86\u76d0\uff0c\u66b4\u529b\u7834\u89e3\u4ecd\u7136\u662f\u53ef\u884c\u7684\uff0c\u56e0\u4e3a\u653b\u51fb\u8005\u53ea\u9700\u8981\u4e3a\u6bcf\u4e2a\u5c1d\u8bd5\u7684\u5bc6\u7801\u548c\u5df2\u77e5\u7684\u76d0\u8ba1\u7b97\u4e00\u6b21\u54c8\u5e0c\u3002<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">\u73b0\u4ee3\u5bc6\u7801\u54c8\u5e0c\u63a8\u8350<\/h4>\n\n\n\n<p>\u7531\u4e8e MD5 \u548c SHA1 \u7684\u8fd9\u4e9b\u5f31\u70b9\uff0c\u5b83\u4eec\u5df2\u7ecf<strong>\u4e0d\u63a8\u8350\u7528\u4e8e\u65b0\u7684\u5b89\u5168\u5e94\u7528<\/strong>\uff0c\u7279\u522b\u662f\u5bc6\u7801\u5b58\u50a8\u3002<\/p>\n\n\n\n<p>\u73b0\u4ee3\u5bc6\u7801\u54c8\u5e0c\u63a8\u8350\u4f7f\u7528\u4e13\u95e8\u4e3a\u5bc6\u7801\u5b58\u50a8\u8bbe\u8ba1\u7684<strong>\u5bc6\u94a5\u6d3e\u751f\u51fd\u6570 (Key Derivation Functions, KDFs)<\/strong>\uff0c\u5b83\u4eec\u5177\u6709\u4ee5\u4e0b\u7279\u6027\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u8ba1\u7b97\u5f00\u9500\u5927 (Slow Hashing)\uff1a<\/strong> \u8fd9\u4e9b\u7b97\u6cd5\u88ab\u8bbe\u8ba1\u6210\u8ba1\u7b97\u901f\u5ea6\u6162\uff0c\u4ee5\u589e\u52a0\u66b4\u529b\u7834\u89e3\u7684\u6210\u672c\u3002<\/li>\n\n\n\n<li><strong>\u52a0\u76d0 (Salting)\uff1a<\/strong> \u5f3a\u5236\u4f7f\u7528\u76d0\u3002<\/li>\n\n\n\n<li><strong>\u8fed\u4ee3\u6b21\u6570 (Iterations)\uff1a<\/strong> \u53ef\u4ee5\u6307\u5b9a\u54c8\u5e0c\u8ba1\u7b97\u7684\u8fed\u4ee3\u6b21\u6570\uff0c\u8fdb\u4e00\u6b65\u589e\u52a0\u8ba1\u7b97\u5f00\u9500\u3002<\/li>\n\n\n\n<li><strong>\u5185\u5b58\u6d88\u8017 (Memory Hardness)\uff1a<\/strong> \u67d0\u4e9b KDF\uff08\u5982 Argon2\uff09\u8fd8\u4f1a\u6d88\u8017\u5927\u91cf\u5185\u5b58\uff0c\u8fdb\u4e00\u6b65\u589e\u52a0\u5e76\u884c\u653b\u51fb\u7684\u6210\u672c\u3002<\/li>\n<\/ul>\n\n\n\n<p><strong>\u63a8\u8350\u7684 KDFs \u5305\u62ec\uff1a<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Argon2 (\u76ee\u524d NIST \u63a8\u8350\u7684\u5bc6\u7801\u54c8\u5e0c\u7b97\u6cd5)<\/strong><\/li>\n\n\n\n<li><strong>Bcrypt<\/strong><\/li>\n\n\n\n<li><strong>Scrypt<\/strong><\/li>\n\n\n\n<li><strong>PBKDF2<\/strong><\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">\u7b2c2\u6b21\u4f1a\u8bae\u524d\u6574\u7406\uff08AI\u68b3\u7406\uff0c\u6682\u672a\u770b\uff09<\/h2>\n\n\n\n<p>\u4f5c\u4e3a\u4e00\u540d\u6b63\u5728\u5b66\u4e60CTF\u7684\u4fe1\u606f\u5b89\u5168\u5b66\u751f\uff0c\u6211\u5f88\u4e50\u610f\u4e3a\u4f60\u7ec6\u81f4\u6574\u7406\u8fd9\u4e9b\u5185\u5bb9\u3002\u7406\u89e3\u8fd9\u4e9b\u57fa\u7840\u77e5\u8bc6\u5bf9\u4e8eCTF\u4e2d\u7684Web\u6e17\u900f\u548c\u7f51\u7edc\u5206\u6790\u81f3\u5173\u91cd\u8981\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">1. \u4e3b\u673aIP\u5730\u5740\u83b7\u53d6\uff08DNS\u57df\u540d\u89e3\u6790\u8fc7\u7a0b\uff09<\/h3>\n\n\n\n<p>\u5f53\u4f60\u8f93\u5165\u4e00\u4e2aURL\u65f6\uff0c\u6d4f\u89c8\u5668\u9700\u8981\u77e5\u9053\u8be5\u57df\u540d\u5bf9\u5e94\u7684\u670d\u52a1\u5668IP\u5730\u5740\u624d\u80fd\u5efa\u7acb\u8fde\u63a5\u3002\u8fd9\u4e2a\u8fc7\u7a0b\u5c31\u662fDNS\uff08Domain Name System\uff09\u57df\u540d\u89e3\u6790\u3002<\/p>\n\n\n\n<p><strong>DNS\u57df\u540d\u89e3\u6790\u7684\u8be6\u7ec6\u6b65\u9aa4\uff1a<\/strong><\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u6d4f\u89c8\u5668\u7f13\u5b58\u68c0\u67e5 (Browser Cache)<\/strong>\uff1a\n<ul class=\"wp-block-list\">\n<li>\u5f53\u4f60\u5728\u6d4f\u89c8\u5668\u4e2d\u8f93\u5165\u4e00\u4e2aURL\u65f6\uff0c\u6d4f\u89c8\u5668\u4f1a\u9996\u5148\u68c0\u67e5\u81ea\u5df1\u7684DNS\u7f13\u5b58\u3002\u5982\u679c\u4e4b\u524d\u8bbf\u95ee\u8fc7\u8be5\u57df\u540d\uff0c\u5e76\u4e14\u7f13\u5b58\u672a\u8fc7\u671f\uff0c\u6d4f\u89c8\u5668\u4f1a\u76f4\u63a5\u4f7f\u7528\u7f13\u5b58\u4e2d\u7684IP\u5730\u5740\uff0c\u8df3\u8fc7\u540e\u7eed\u89e3\u6790\u6b65\u9aa4\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u64cd\u4f5c\u7cfb\u7edf\u7f13\u5b58\u68c0\u67e5 (OS Cache \/ hosts\u6587\u4ef6)<\/strong>\uff1a\n<ul class=\"wp-block-list\">\n<li>\u5982\u679c\u6d4f\u89c8\u5668\u7f13\u5b58\u4e2d\u6ca1\u6709\uff0c\u6d4f\u89c8\u5668\u4f1a\u5411\u64cd\u4f5c\u7cfb\u7edf\u53d1\u8d77\u67e5\u8be2\u3002\u64cd\u4f5c\u7cfb\u7edf\u4f1a\u68c0\u67e5\u81ea\u5df1\u7684DNS\u7f13\u5b58\u3002<\/li>\n\n\n\n<li>\u540c\u65f6\uff0c\u64cd\u4f5c\u7cfb\u7edf\u8fd8\u4f1a\u68c0\u67e5\u672c\u5730\u7684<code>hosts<\/code>\u6587\u4ef6\uff08\u5728Windows\u4e2d\u901a\u5e38\u4f4d\u4e8e<code>C:\\Windows\\System32\\drivers\\etc\\hosts<\/code>\uff0c\u5728Linux\/macOS\u4e2d\u4f4d\u4e8e<code>\/etc\/hosts<\/code>\uff09\u3002\u5982\u679c<code>hosts<\/code>\u6587\u4ef6\u4e2d\u6709\u5bf9\u5e94\u7684\u57df\u540d-IP\u6620\u5c04\uff0c\u64cd\u4f5c\u7cfb\u7edf\u4f1a\u76f4\u63a5\u8fd4\u56deIP\u5730\u5740\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u672c\u5730DNS\u670d\u52a1\u5668\u67e5\u8be2 (Local DNS Resolver)<\/strong>\uff1a\n<ul class=\"wp-block-list\">\n<li>\u5982\u679c\u6d4f\u89c8\u5668\u548c\u64cd\u4f5c\u7cfb\u7edf\u7f13\u5b58\u4e2d\u90fd\u6ca1\u6709\uff0c\u64cd\u4f5c\u7cfb\u7edf\u4f1a\u5c06\u57df\u540d\u89e3\u6790\u8bf7\u6c42\u53d1\u9001\u7ed9\u672c\u5730DNS\u670d\u52a1\u5668\uff08\u4e5f\u79f0\u4e3aDNS\u89e3\u6790\u5668\u6216ISP\u7684DNS\u670d\u52a1\u5668\uff09\u3002\u8fd9\u4e2a\u672c\u5730DNS\u670d\u52a1\u5668\u901a\u5e38\u7531\u4f60\u7684\u4e92\u8054\u7f51\u670d\u52a1\u63d0\u4f9b\u5546\uff08ISP\uff09\u63d0\u4f9b\uff0c\u6216\u8005\u4f60\u53ef\u4ee5\u624b\u52a8\u914d\u7f6e\uff08\u5982Google DNS 8.8.8.8\uff09\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u9012\u5f52\u67e5\u8be2\u5230\u6839\u57df\u540d\u670d\u52a1\u5668 (Root DNS Server)<\/strong>\uff1a\n<ul class=\"wp-block-list\">\n<li>\u672c\u5730DNS\u670d\u52a1\u5668\u6536\u5230\u8bf7\u6c42\u540e\uff0c\u4f1a\u9996\u5148\u5411<strong>\u6839\u57df\u540d\u670d\u52a1\u5668<\/strong>\uff08Root DNS Server\uff09\u53d1\u8d77\u67e5\u8be2\u3002\u6839\u57df\u540d\u670d\u52a1\u5668\u662fDNS\u5c42\u6b21\u7ed3\u6784\u7684\u9876\u5c42\uff0c\u5b83\u4e0d\u76f4\u63a5\u5b58\u50a8\u57df\u540d\u7684IP\u5730\u5740\uff0c\u800c\u662f\u544a\u77e5\u672c\u5730DNS\u670d\u52a1\u5668\u5e94\u8be5\u53bb\u54ea\u4e2a\u9876\u7ea7\u57df\u540d\u670d\u52a1\u5668\uff08TLD DNS Server\uff09\u67e5\u8be2\u3002\u4f8b\u5982\uff0c\u5bf9\u4e8e<code>www.example.com<\/code>\uff0c\u6839\u57df\u540d\u670d\u52a1\u5668\u4f1a\u544a\u8bc9\u672c\u5730DNS\u670d\u52a1\u5668\u53bb<code>.com<\/code>\u7684TLD\u670d\u52a1\u5668\u67e5\u8be2\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u8fed\u4ee3\u67e5\u8be2\u5230\u9876\u7ea7\u57df\u540d\u670d\u52a1\u5668 (TLD DNS Server)<\/strong>\uff1a\n<ul class=\"wp-block-list\">\n<li>\u672c\u5730DNS\u670d\u52a1\u5668\u6839\u636e\u6839\u57df\u540d\u670d\u52a1\u5668\u7684\u6307\u5f15\uff0c\u5411\u8d1f\u8d23<code>.com<\/code>\u57df\u540d\u7684<strong>\u9876\u7ea7\u57df\u540d\u670d\u52a1\u5668<\/strong>\uff08Top-Level Domain DNS Server\uff09\u53d1\u8d77\u67e5\u8be2\u3002TLD\u670d\u52a1\u5668\u4f1a\u544a\u77e5\u672c\u5730DNS\u670d\u52a1\u5668\u5e94\u8be5\u53bb\u54ea\u4e2a<strong>\u6743\u5a01\u57df\u540d\u670d\u52a1\u5668<\/strong>\uff08Authoritative DNS Server\uff09\u67e5\u8be2<code>example.com<\/code>\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u8fed\u4ee3\u67e5\u8be2\u5230\u6743\u5a01\u57df\u540d\u670d\u52a1\u5668 (Authoritative DNS Server)<\/strong>\uff1a\n<ul class=\"wp-block-list\">\n<li>\u672c\u5730DNS\u670d\u52a1\u5668\u6839\u636eTLD\u670d\u52a1\u5668\u7684\u6307\u5f15\uff0c\u5411\u8d1f\u8d23<code>example.com<\/code>\u8fd9\u4e2a\u7279\u5b9a\u57df\u540d\u7684<strong>\u6743\u5a01\u57df\u540d\u670d\u52a1\u5668<\/strong>\u53d1\u8d77\u67e5\u8be2\u3002\u6743\u5a01\u57df\u540d\u670d\u52a1\u5668\u662f\u771f\u6b63\u5b58\u50a8\u57df\u540d\u4e0eIP\u5730\u5740\u6620\u5c04\u5173\u7cfb\u7684\u5730\u65b9\uff0c\u5b83\u4f1a\u8fd4\u56de<code>www.example.com<\/code>\u5bf9\u5e94\u7684IP\u5730\u5740\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>IP\u5730\u5740\u8fd4\u56de\u4e0e\u7f13\u5b58 (IP Address Return and Caching)<\/strong>\uff1a\n<ul class=\"wp-block-list\">\n<li>\u6743\u5a01\u57df\u540d\u670d\u52a1\u5668\u5c06IP\u5730\u5740\u8fd4\u56de\u7ed9\u672c\u5730DNS\u670d\u52a1\u5668\u3002<\/li>\n\n\n\n<li>\u672c\u5730DNS\u670d\u52a1\u5668\u4f1a\u5c06\u8fd9\u4e2aIP\u5730\u5740\u7f13\u5b58\u8d77\u6765\uff08\u4ee5\u4fbf\u4e0b\u6b21\u67e5\u8be2\u540c\u4e00\u57df\u540d\u65f6\u80fd\u66f4\u5feb\u54cd\u5e94\uff09\uff0c\u7136\u540e\u5c06IP\u5730\u5740\u8fd4\u56de\u7ed9\u64cd\u4f5c\u7cfb\u7edf\u3002<\/li>\n\n\n\n<li>\u64cd\u4f5c\u7cfb\u7edf\u4e5f\u4f1a\u5c06IP\u5730\u5740\u7f13\u5b58\u8d77\u6765\uff0c\u5e76\u6700\u7ec8\u5c06IP\u5730\u5740\u8fd4\u56de\u7ed9\u6d4f\u89c8\u5668\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u6d4f\u89c8\u5668\u5efa\u7acb\u8fde\u63a5 (Browser Connects)<\/strong>\uff1a\n<ul class=\"wp-block-list\">\n<li>\u6d4f\u89c8\u5668\u73b0\u5728\u83b7\u5f97\u4e86<code>www.example.com<\/code>\u7684IP\u5730\u5740\uff0c\u5c31\u53ef\u4ee5\u4f7f\u7528\u8fd9\u4e2aIP\u5730\u5740\u4e0e\u76ee\u6807\u670d\u52a1\u5668\u5efa\u7acbTCP\u8fde\u63a5\uff0c\u5e76\u53d1\u9001HTTP\u8bf7\u6c42\u4e86\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n\n\n\n<p>\u8fd9\u4e2a\u8fc7\u7a0b\u901a\u5e38\u5728\u6beb\u79d2\u7ea7\u5b8c\u6210\uff0c\u5bf9\u7528\u6237\u6765\u8bf4\u662f\u900f\u660e\u7684\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">2. HTTP\u4e2d\u5e38\u89c1\u7684\u5305\u5934\u548c\u72b6\u6001\u7801<\/h3>\n\n\n\n<p>HTTP\uff08Hypertext Transfer Protocol\uff09\u662f\u5ba2\u6237\u7aef\u548c\u670d\u52a1\u5668\u4e4b\u95f4\u4f20\u8f93\u6570\u636e\u7684\u534f\u8bae\u3002\u7406\u89e3HTTP\u8bf7\u6c42\u5934\u3001\u54cd\u5e94\u5934\u548c\u72b6\u6001\u7801\u5bf9\u4e8eWeb\u5b89\u5168\u5206\u6790\u81f3\u5173\u91cd\u8981\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">2.1 \u5e38\u89c1\u7684HTTP\u8bf7\u6c42\u5934 (Request Headers)<\/h4>\n\n\n\n<p>\u8bf7\u6c42\u5934\u63d0\u4f9b\u4e86\u5173\u4e8e\u8bf7\u6c42\u3001\u5ba2\u6237\u7aef\u6216\u88ab\u8bf7\u6c42\u8d44\u6e90\u7684\u4fe1\u606f\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Host<\/strong>: <code>Host: www.example.com<\/code>\n<ul class=\"wp-block-list\">\n<li>\u6307\u5b9a\u4e86\u8bf7\u6c42\u7684\u76ee\u6807\u4e3b\u673a\u540d\u548c\u7aef\u53e3\u53f7\u3002\u5728\u540c\u4e00\u4e2aIP\u5730\u5740\u4e0a\u6258\u7ba1\u591a\u4e2a\u7f51\u7ad9\uff08\u865a\u62df\u4e3b\u673a\uff09\u65f6\uff0c\u670d\u52a1\u5668\u901a\u8fc7<code>Host<\/code>\u5934\u6765\u533a\u5206\u8bf7\u6c42\u7684\u662f\u54ea\u4e2a\u7f51\u7ad9\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>User-Agent<\/strong>: <code>User-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/107.0.0.0 Safari\/537.36<\/code>\n<ul class=\"wp-block-list\">\n<li>\u63d0\u4f9b\u4e86\u53d1\u8d77\u8bf7\u6c42\u7684\u5ba2\u6237\u7aef\uff08\u901a\u5e38\u662f\u6d4f\u89c8\u5668\uff09\u7684\u7c7b\u578b\u3001\u64cd\u4f5c\u7cfb\u7edf\u3001\u6e32\u67d3\u5f15\u64ce\u7b49\u4fe1\u606f\u3002\u5728CTF\u4e2d\uff0c\u6709\u65f6\u9700\u8981\u4f2a\u9020<code>User-Agent<\/code>\u6765\u7ed5\u8fc7\u67d0\u4e9b\u57fa\u4e8e\u5ba2\u6237\u7aef\u7c7b\u578b\u7684\u9650\u5236\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>Referer<\/strong>: <code>Referer: https:\/\/www.google.com\/<\/code>\n<ul class=\"wp-block-list\">\n<li>\u6307\u793a\u4e86\u5f53\u524d\u8bf7\u6c42\u7684\u6765\u6e90\u9875\u9762URL\u3002\u670d\u52a1\u5668\u53ef\u4ee5\u901a\u8fc7<code>Referer<\/code>\u5934\u6765\u5224\u65ad\u7528\u6237\u662f\u4ece\u54ea\u4e2a\u9875\u9762\u94fe\u63a5\u8fc7\u6765\u7684\uff0c\u5e38\u7528\u4e8e\u7edf\u8ba1\u3001\u9632\u76d7\u94fe\u6216\u5b89\u5168\u68c0\u67e5\u3002\u6ce8\u610f\u62fc\u5199\u662f<code>Referer<\/code>\u800c\u4e0d\u662f<code>Referrer<\/code>\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>Cookie<\/strong>: <code>Cookie: sessionid=abcdef123456; username=test<\/code>\n<ul class=\"wp-block-list\">\n<li>\u5305\u542b\u4e86\u5ba2\u6237\u7aef\u5b58\u50a8\u7684HTTP Cookie\u3002\u670d\u52a1\u5668\u901a\u8fc7<code>Set-Cookie<\/code>\u54cd\u5e94\u5934\u53d1\u9001Cookie\u7ed9\u5ba2\u6237\u7aef\uff0c\u5ba2\u6237\u7aef\u5728\u540e\u7eed\u8bf7\u6c42\u4e2d\u5c06\u8fd9\u4e9bCookie\u53d1\u9001\u56de\u670d\u52a1\u5668\uff0c\u7528\u4e8e\u4f1a\u8bdd\u7ba1\u7406\u3001\u7528\u6237\u8eab\u4efd\u8ba4\u8bc1\u548c\u4e2a\u6027\u5316\u8bbe\u7f6e\u3002\u5728CTF\u4e2d\uff0cCookie\u662f\u83b7\u53d6\u4f1a\u8bdd\u3001\u7ed5\u8fc7\u8ba4\u8bc1\u7684\u5173\u952e\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>Content-Type<\/strong>: <code>Content-Type: application\/x-www-form-urlencoded<\/code> \u6216 <code>Content-Type: application\/json<\/code>\n<ul class=\"wp-block-list\">\n<li>\u6307\u793a\u4e86\u8bf7\u6c42\u4f53\u4e2d\u53d1\u9001\u7684\u6570\u636e\u7684\u5a92\u4f53\u7c7b\u578b\uff08MIME\u7c7b\u578b\uff09\u3002\u4f8b\u5982\uff0c<code>application\/x-www-form-urlencoded<\/code>\u7528\u4e8eHTML\u8868\u5355\u63d0\u4ea4\uff0c<code>application\/json<\/code>\u7528\u4e8eJSON\u6570\u636e\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>X-Forwarded-For (XFF)<\/strong>: <code>X-Forwarded-For: 192.168.1.100, 10.0.0.5<\/code>\n<ul class=\"wp-block-list\">\n<li>\u8fd9\u662f\u4e00\u4e2a\u975e\u6807\u51c6\u7684\uff08\u4f46\u5e7f\u6cdb\u4f7f\u7528\u7684\uff09HTTP\u8bf7\u6c42\u5934\uff0c\u7528\u4e8e\u6807\u8bc6\u901a\u8fc7HTTP\u4ee3\u7406\u6216\u8d1f\u8f7d\u5747\u8861\u5668\u8fde\u63a5\u5230Web\u670d\u52a1\u5668\u7684\u5ba2\u6237\u7aef\u7684\u539f\u59cbIP\u5730\u5740\u3002\u5f53\u8bf7\u6c42\u7ecf\u8fc7\u591a\u4e2a\u4ee3\u7406\u65f6\uff0c\u5b83\u4f1a\u5305\u542b\u4e00\u4e2a\u7531\u9017\u53f7\u5206\u9694\u7684IP\u5730\u5740\u5217\u8868\uff0c\u6700\u5de6\u8fb9\u7684IP\u5730\u5740\u662f\u539f\u59cb\u5ba2\u6237\u7aef\u7684IP\u3002\u5728CTF\u4e2d\uff0c\u5e38\u7528\u4e8eIP\u4f2a\u9020\u7ed5\u8fc7\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>Accept<\/strong>: <code>Accept: text\/html,application\/xhtml+xml,application\/xml;q=0.9,image\/webp,*\/*;q=0.8<\/code>\n<ul class=\"wp-block-list\">\n<li>\u544a\u77e5\u670d\u52a1\u5668\u5ba2\u6237\u7aef\u80fd\u591f\u5904\u7406\u7684\u5a92\u4f53\u7c7b\u578b\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>Accept-Encoding<\/strong>: <code>Accept-Encoding: gzip, deflate, br<\/code>\n<ul class=\"wp-block-list\">\n<li>\u544a\u77e5\u670d\u52a1\u5668\u5ba2\u6237\u7aef\u652f\u6301\u7684\u7f16\u7801\u65b9\u5f0f\uff08\u5982\u538b\u7f29\u7b97\u6cd5\uff09\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>Connection<\/strong>: <code>Connection: keep-alive<\/code>\n<ul class=\"wp-block-list\">\n<li>\u6307\u793a\u5ba2\u6237\u7aef\u4e0e\u670d\u52a1\u5668\u7684\u8fde\u63a5\u65b9\u5f0f\uff0c<code>keep-alive<\/code>\u8868\u793a\u6301\u4e45\u8fde\u63a5\uff0c\u53ef\u4ee5\u590d\u7528\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>Content-Length<\/strong>: <code>Content-Length: 123<\/code>\n<ul class=\"wp-block-list\">\n<li>\u6307\u793a\u8bf7\u6c42\u4f53\u7684\u5927\u5c0f\uff08\u4ee5\u5b57\u8282\u4e3a\u5355\u4f4d\uff09\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">2.2 \u5e38\u89c1\u7684HTTP\u54cd\u5e94\u5934 (Response Headers)<\/h4>\n\n\n\n<p>\u54cd\u5e94\u5934\u63d0\u4f9b\u4e86\u5173\u4e8e\u54cd\u5e94\u3001\u670d\u52a1\u5668\u6216\u88ab\u8bf7\u6c42\u8d44\u6e90\u7684\u4fe1\u606f\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Content-Type<\/strong>: <code>Content-Type: text\/html; charset=UTF-8<\/code>\n<ul class=\"wp-block-list\">\n<li>\u6307\u793a\u4e86\u54cd\u5e94\u4f53\u4e2d\u8fd4\u56de\u7684\u6570\u636e\u7684\u5a92\u4f53\u7c7b\u578b\u548c\u5b57\u7b26\u7f16\u7801\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>Set-Cookie<\/strong>: <code>Set-Cookie: sessionid=abcdef123456; Expires=Sat, 07-Nov-2026 10:00:00 GMT; Path=\/; HttpOnly<\/code>\n<ul class=\"wp-block-list\">\n<li>\u670d\u52a1\u5668\u7528\u6765\u5411\u5ba2\u6237\u7aef\u53d1\u9001Cookie\u3002\u5ba2\u6237\u7aef\u6536\u5230\u540e\u4f1a\u5b58\u50a8\u8fd9\u4e9bCookie\uff0c\u5e76\u5728\u540e\u7eed\u8bf7\u6c42\u4e2d\u901a\u8fc7<code>Cookie<\/code>\u8bf7\u6c42\u5934\u53d1\u9001\u56de\u53bb\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>Server<\/strong>: <code>Server: Apache\/2.4.41 (Ubuntu)<\/code>\n<ul class=\"wp-block-list\">\n<li>\u6307\u793a\u4e86\u5904\u7406\u8bf7\u6c42\u7684Web\u670d\u52a1\u5668\u8f6f\u4ef6\u7684\u4fe1\u606f\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>Location<\/strong>: <code>Location: https:\/\/www.example.com\/new-page<\/code>\n<ul class=\"wp-block-list\">\n<li>\u7528\u4e8e\u91cd\u5b9a\u5411\u3002\u5f53\u670d\u52a1\u5668\u8fd4\u56de3xx\u72b6\u6001\u7801\u65f6\uff0c<code>Location<\/code>\u5934\u6307\u5b9a\u4e86\u5ba2\u6237\u7aef\u5e94\u8be5\u91cd\u5b9a\u5411\u5230\u7684\u65b0URL\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>Cache-Control<\/strong>: <code>Cache-Control: max-age=3600, public<\/code>\n<ul class=\"wp-block-list\">\n<li>\u63a7\u5236\u5ba2\u6237\u7aef\u548c\u4ee3\u7406\u670d\u52a1\u5668\u7684\u7f13\u5b58\u884c\u4e3a\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>Date<\/strong>: <code>Date: Fri, 15 Nov 2025 10:30:00 GMT<\/code>\n<ul class=\"wp-block-list\">\n<li>\u54cd\u5e94\u751f\u6210\u7684\u65f6\u95f4\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">2.3 \u5e38\u89c1\u7684HTTP\u72b6\u6001\u7801 (Status Codes)<\/h4>\n\n\n\n<p>\u72b6\u6001\u7801\u662f\u670d\u52a1\u5668\u5bf9\u8bf7\u6c42\u7684\u5904\u7406\u7ed3\u679c\u7684\u6570\u5b57\u4ee3\u7801\uff0c\u5206\u4e3a\u4e94\u7c7b\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>1xx - \u4fe1\u606f\u54cd\u5e94 (Informational Responses)<\/strong>\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>100 Continue<\/strong>: \u670d\u52a1\u5668\u5df2\u6536\u5230\u8bf7\u6c42\u7684\u521d\u59cb\u90e8\u5206\uff0c\u5ba2\u6237\u7aef\u5e94\u7ee7\u7eed\u53d1\u9001\u8bf7\u6c42\u7684\u5176\u4f59\u90e8\u5206\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>2xx - \u6210\u529f\u54cd\u5e94 (Successful Responses)<\/strong>\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>200 OK<\/strong>: \u8bf7\u6c42\u6210\u529f\uff0c\u670d\u52a1\u5668\u5df2\u6210\u529f\u5904\u7406\u8bf7\u6c42\u3002\u8fd9\u662f\u6700\u5e38\u89c1\u7684\u6210\u529f\u72b6\u6001\u7801\u3002<\/li>\n\n\n\n<li><strong>201 Created<\/strong>: \u8bf7\u6c42\u6210\u529f\uff0c\u5e76\u4e14\u670d\u52a1\u5668\u521b\u5efa\u4e86\u65b0\u7684\u8d44\u6e90\u3002<\/li>\n\n\n\n<li><strong>204 No Content<\/strong>: \u670d\u52a1\u5668\u6210\u529f\u5904\u7406\u4e86\u8bf7\u6c42\uff0c\u4f46\u6ca1\u6709\u8fd4\u56de\u4efb\u4f55\u5185\u5bb9\u3002<\/li>\n\n\n\n<li><strong>206 Partial Content<\/strong>: \u670d\u52a1\u5668\u6210\u529f\u5904\u7406\u4e86\u90e8\u5206GET\u8bf7\u6c42\uff08\u4f8b\u5982\uff0c\u6587\u4ef6\u4e0b\u8f7d\u65f6\u7684\u65ad\u70b9\u7eed\u4f20\uff09\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>3xx - \u91cd\u5b9a\u5411 (Redirection)<\/strong>\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>301 Moved Permanently<\/strong>: \u8d44\u6e90\u5df2\u88ab\u6c38\u4e45\u79fb\u52a8\u5230\u65b0\u7684URL\uff0c\u5ba2\u6237\u7aef\u5e94\u4f7f\u7528\u65b0\u7684URL\u3002<\/li>\n\n\n\n<li><strong>302 Found (Previously \"Moved Temporarily\")<\/strong>: \u8d44\u6e90\u6682\u65f6\u79fb\u52a8\u5230\u65b0\u7684URL\u3002\u5ba2\u6237\u7aef\u5e94\u7ee7\u7eed\u4f7f\u7528\u65e7\u7684URL\u8fdb\u884c\u672a\u6765\u7684\u8bf7\u6c42\u3002<\/li>\n\n\n\n<li><strong>304 Not Modified<\/strong>: \u5ba2\u6237\u7aef\u7684\u7f13\u5b58\u8d44\u6e90\u4ecd\u7136\u662f\u6700\u65b0\u7684\uff0c\u65e0\u9700\u518d\u6b21\u4f20\u8f93\u3002<\/li>\n\n\n\n<li><strong>307 Temporary Redirect<\/strong>: \u8d44\u6e90\u6682\u65f6\u79fb\u52a8\uff0c\u4e0e302\u7c7b\u4f3c\uff0c\u4f46\u8981\u6c42\u5ba2\u6237\u7aef\u4f7f\u7528\u76f8\u540c\u7684HTTP\u65b9\u6cd5\u8fdb\u884c\u91cd\u5b9a\u5411\u3002<\/li>\n\n\n\n<li><strong>308 Permanent Redirect<\/strong>: \u8d44\u6e90\u6c38\u4e45\u79fb\u52a8\uff0c\u4e0e301\u7c7b\u4f3c\uff0c\u4f46\u8981\u6c42\u5ba2\u6237\u7aef\u4f7f\u7528\u76f8\u540c\u7684HTTP\u65b9\u6cd5\u8fdb\u884c\u91cd\u5b9a\u5411\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>4xx - \u5ba2\u6237\u7aef\u9519\u8bef (Client Errors)<\/strong>\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>400 Bad Request<\/strong>: \u670d\u52a1\u5668\u65e0\u6cd5\u7406\u89e3\u5ba2\u6237\u7aef\u53d1\u9001\u7684\u8bf7\u6c42\uff0c\u901a\u5e38\u662f\u8bf7\u6c42\u8bed\u6cd5\u9519\u8bef\u3002<\/li>\n\n\n\n<li><strong>401 Unauthorized<\/strong>: \u8bf7\u6c42\u9700\u8981\u7528\u6237\u8eab\u4efd\u9a8c\u8bc1\u3002<\/li>\n\n\n\n<li><strong>403 Forbidden<\/strong>: \u670d\u52a1\u5668\u7406\u89e3\u8bf7\u6c42\uff0c\u4f46\u62d2\u7edd\u6267\u884c\u3002\u901a\u5e38\u662f\u6743\u9650\u4e0d\u8db3\u3002<\/li>\n\n\n\n<li><strong>404 Not Found<\/strong>: \u670d\u52a1\u5668\u627e\u4e0d\u5230\u8bf7\u6c42\u7684\u8d44\u6e90\u3002\u8fd9\u662f\u6700\u5e38\u89c1\u7684\u9519\u8bef\u72b6\u6001\u7801\u3002<\/li>\n\n\n\n<li><strong>405 Method Not Allowed<\/strong>: \u8bf7\u6c42\u65b9\u6cd5\uff08\u5982GET\u3001POST\uff09\u4e0d\u88ab\u5141\u8bb8\u7528\u4e8e\u8bf7\u6c42\u7684\u8d44\u6e90\u3002<\/li>\n\n\n\n<li><strong>408 Request Timeout<\/strong>: \u670d\u52a1\u5668\u7b49\u5f85\u5ba2\u6237\u7aef\u53d1\u9001\u8bf7\u6c42\u7684\u65f6\u95f4\u8fc7\u957f\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>5xx - \u670d\u52a1\u5668\u9519\u8bef (Server Errors)<\/strong>\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>500 Internal Server Error<\/strong>: \u670d\u52a1\u5668\u9047\u5230\u4e86\u4e00\u4e2a\u610f\u5916\u60c5\u51b5\uff0c\u5bfc\u81f4\u65e0\u6cd5\u5b8c\u6210\u8bf7\u6c42\u3002\u8fd9\u662f\u6700\u5e38\u89c1\u7684\u670d\u52a1\u5668\u7aef\u9519\u8bef\u3002<\/li>\n\n\n\n<li><strong>502 Bad Gateway<\/strong>: \u4f5c\u4e3a\u7f51\u5173\u6216\u4ee3\u7406\u7684\u670d\u52a1\u5668\u4ece\u4e0a\u6e38\u670d\u52a1\u5668\u6536\u5230\u65e0\u6548\u54cd\u5e94\u3002<\/li>\n\n\n\n<li><strong>503 Service Unavailable<\/strong>: \u670d\u52a1\u5668\u5f53\u524d\u65e0\u6cd5\u5904\u7406\u8bf7\u6c42\uff0c\u901a\u5e38\u662f\u7531\u4e8e\u8fc7\u8f7d\u6216\u7ef4\u62a4\u3002<\/li>\n\n\n\n<li><strong>504 Gateway Timeout<\/strong>: \u4f5c\u4e3a\u7f51\u5173\u6216\u4ee3\u7406\u7684\u670d\u52a1\u5668\u5728\u7b49\u5f85\u4e0a\u6e38\u670d\u52a1\u5668\u54cd\u5e94\u65f6\u8d85\u65f6\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">3. \u6574\u5408\u6d41\u7a0b\uff1a\u4ece\u8f93\u5165URL\u5230\u89e3\u6790\u5b8c\u6210\u5c55\u793a<\/h3>\n\n\n\n<p>\u8fd9\u662f\u4e00\u4e2a\u6db5\u76d6\u5ba2\u6237\u7aef\u3001\u7f51\u7edc\u548c\u670d\u52a1\u5668\u7aef\u7684\u5b8c\u6574\u4ea4\u4e92\u6d41\u7a0b\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">3.1 \u5ba2\u6237\u7aef (\u6d4f\u89c8\u5668) \u4fa7\u53d1\u751f\u4ec0\u4e48<\/h4>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u7528\u6237\u8f93\u5165URL\u5e76\u56de\u8f66<\/strong>: \u7528\u6237\u5728\u6d4f\u89c8\u5668\u7684\u5730\u5740\u680f\u4e2d\u8f93\u5165\u4e00\u4e2aURL\uff08\u4f8b\u5982 <code>https:\/\/www.example.com\/index.html<\/code>\uff09\uff0c\u7136\u540e\u6309\u4e0b\u56de\u8f66\u952e\u3002<\/li>\n\n\n\n<li><strong>URL\u89e3\u6790<\/strong>: \u6d4f\u89c8\u5668\u89e3\u6790URL\uff0c\u8bc6\u522b\u51fa\u534f\u8bae\uff08<code>https<\/code>\uff09\u3001\u4e3b\u673a\u540d\uff08<code>www.example.com<\/code>\uff09\u3001\u8def\u5f84\uff08<code>\/index.html<\/code>\uff09\u7b49\u3002<\/li>\n\n\n\n<li><strong>HSTS\u68c0\u67e5 (\u5982\u679c\u4f7f\u7528HTTPS)<\/strong>: \u5982\u679c\u662fHTTPS\u8fde\u63a5\uff0c\u6d4f\u89c8\u5668\u4f1a\u68c0\u67e5\u662f\u5426\u5df2\u4e3a\u8be5\u57df\u914d\u7f6e\u4e86HTTP\u4e25\u683c\u4f20\u8f93\u5b89\u5168\uff08HSTS\uff09\u3002\u5982\u679c\u914d\u7f6e\u4e86\uff0c\u6d4f\u89c8\u5668\u4f1a\u76f4\u63a5\u4f7f\u7528HTTPS\uff0c\u5373\u4f7fURL\u4e2d\u6307\u5b9a\u7684\u662fHTTP\u3002<\/li>\n\n\n\n<li><strong>DNS\u57df\u540d\u89e3\u6790<\/strong>: \u6d4f\u89c8\u5668\u6267\u884c\u4e0a\u8ff0<strong>\u4e3b\u673aIP\u5730\u5740\u83b7\u53d6<\/strong>\u7684DNS\u89e3\u6790\u8fc7\u7a0b\uff0c\u5c06<code>www.example.com<\/code>\u89e3\u6790\u4e3a\u5bf9\u5e94\u7684IP\u5730\u5740\uff08\u4f8b\u5982 <code>192.0.2.1<\/code>\uff09\u3002<\/li>\n\n\n\n<li><strong>\u5efa\u7acbTCP\u8fde\u63a5<\/strong>:\n<ul class=\"wp-block-list\">\n<li>\u6d4f\u89c8\u5668\u4f7f\u7528\u89e3\u6790\u5230\u7684IP\u5730\u5740\u548c\u7aef\u53e3\u53f7\uff08HTTP\u9ed8\u8ba480\uff0cHTTPS\u9ed8\u8ba4443\uff09\u4e0e\u670d\u52a1\u5668\u5efa\u7acbTCP\u8fde\u63a5\u3002<\/li>\n\n\n\n<li>\u8fd9\u6d89\u53caTCP\u4e09\u6b21\u63e1\u624b\uff1a\u5ba2\u6237\u7aef\u53d1\u9001<code>SYN<\/code>\u5305\uff0c\u670d\u52a1\u5668\u56de\u590d<code>SYN-ACK<\/code>\u5305\uff0c\u5ba2\u6237\u7aef\u518d\u56de\u590d<code>ACK<\/code>\u5305\uff0c\u8fde\u63a5\u5efa\u7acb\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>TLS\/SSL\u63e1\u624b (\u5982\u679c\u4f7f\u7528HTTPS)<\/strong>:\n<ul class=\"wp-block-list\">\n<li>\u5728TCP\u8fde\u63a5\u5efa\u7acb\u540e\uff0c\u5982\u679c\u662fHTTPS\uff0c\u6d4f\u89c8\u5668\u548c\u670d\u52a1\u5668\u4f1a\u8fdb\u884cTLS\/SSL\u63e1\u624b\uff0c\u534f\u5546\u52a0\u5bc6\u7b97\u6cd5\u3001\u4ea4\u6362\u5bc6\u94a5\uff0c\u5e76\u9a8c\u8bc1\u670d\u52a1\u5668\u8bc1\u4e66\u3002\u8fd9\u786e\u4fdd\u4e86\u540e\u7eed\u901a\u4fe1\u7684\u673a\u5bc6\u6027\u548c\u5b8c\u6574\u6027\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u53d1\u9001HTTP\u8bf7\u6c42<\/strong>:\n<ul class=\"wp-block-list\">\n<li>\u6d4f\u89c8\u5668\u6784\u5efaHTTP\u8bf7\u6c42\u62a5\u6587\uff0c\u5305\u62ec\u8bf7\u6c42\u884c\uff08\u65b9\u6cd5\u3001\u8def\u5f84\u3001\u534f\u8bae\u7248\u672c\uff09\u548c\u8bf7\u6c42\u5934\u3002<\/li>\n\n\n\n<li><strong>\u8bf7\u6c42\u5934\u793a\u4f8b<\/strong>:\n<ul class=\"wp-block-list\">\n<li><code>GET \/index.html HTTP\/1.1<\/code><\/li>\n\n\n\n<li><code>Host: www.example.com<\/code><\/li>\n\n\n\n<li><code>User-Agent: ...<\/code> (\u544a\u77e5\u670d\u52a1\u5668\u5ba2\u6237\u7aef\u7c7b\u578b)<\/li>\n\n\n\n<li><code>Accept: ...<\/code> (\u544a\u77e5\u670d\u52a1\u5668\u5ba2\u6237\u7aef\u80fd\u63a5\u53d7\u7684\u54cd\u5e94\u7c7b\u578b)<\/li>\n\n\n\n<li><code>Accept-Encoding: ...<\/code> (\u544a\u77e5\u670d\u52a1\u5668\u5ba2\u6237\u7aef\u652f\u6301\u7684\u538b\u7f29\u65b9\u5f0f)<\/li>\n\n\n\n<li><code>Connection: keep-alive<\/code><\/li>\n\n\n\n<li><code>Cookie: sessionid=...<\/code> (\u5982\u679c\u4e4b\u524d\u670d\u52a1\u5668\u8bbe\u7f6e\u8fc7Cookie\uff0c\u6d4f\u89c8\u5668\u4f1a\u5e26\u4e0a)<\/li>\n\n\n\n<li><code>Referer: ...<\/code> (\u5982\u679c\u7528\u6237\u662f\u4ece\u5176\u4ed6\u9875\u9762\u70b9\u51fb\u94fe\u63a5\u8fc7\u6765\u7684)<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>\u6d4f\u89c8\u5668\u5c06\u8fd9\u4e2a\u8bf7\u6c42\u62a5\u6587\u901a\u8fc7\u5df2\u5efa\u7acb\u7684TCP\/TLS\u8fde\u63a5\u53d1\u9001\u7ed9\u670d\u52a1\u5668\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n\n\n\n<h4 class=\"wp-block-heading\">3.2 \u7f51\u7edc\u4fa7\u53d1\u751f\u4ec0\u4e48<\/h4>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u6570\u636e\u5305\u5c01\u88c5\u4e0e\u4f20\u8f93<\/strong>: \u5ba2\u6237\u7aef\u7684HTTP\u8bf7\u6c42\u62a5\u6587\u88ab\u5c01\u88c5\u6210TCP\u6bb5\uff0c\u518d\u5c01\u88c5\u6210IP\u6570\u636e\u5305\uff0c\u7136\u540e\u901a\u8fc7\u7f51\u7edc\u63a5\u53e3\u53d1\u9001\u51fa\u53bb\u3002<\/li>\n\n\n\n<li><strong>\u8def\u7531\u4e0e\u8f6c\u53d1<\/strong>: IP\u6570\u636e\u5305\u5728\u4e92\u8054\u7f51\u4e2d\u901a\u8fc7\u4e00\u7cfb\u5217\u8def\u7531\u5668\u3001\u4ea4\u6362\u673a\u8fdb\u884c\u8f6c\u53d1\uff0c\u6839\u636e\u76ee\u6807IP\u5730\u5740\u627e\u5230\u5230\u8fbe\u670d\u52a1\u5668\u7684\u6700\u4f73\u8def\u5f84\u3002<\/li>\n\n\n\n<li><strong>NAT\/\u4ee3\u7406\/\u8d1f\u8f7d\u5747\u8861<\/strong>:\n<ul class=\"wp-block-list\">\n<li>\u5982\u679c\u5ba2\u6237\u7aef\u5728\u79c1\u6709\u7f51\u7edc\u4e2d\uff0c\u53ef\u80fd\u4f1a\u7ecf\u8fc7<strong>\u7f51\u7edc\u5730\u5740\u8f6c\u6362 (NAT)<\/strong> \u8bbe\u5907\uff0c\u5c06\u79c1\u6709IP\u8f6c\u6362\u4e3a\u516c\u6709IP\u3002<\/li>\n\n\n\n<li>\u8bf7\u6c42\u53ef\u80fd\u7ecf\u8fc7<strong>\u4ee3\u7406\u670d\u52a1\u5668<\/strong>\uff0c\u4ee3\u7406\u670d\u52a1\u5668\u4f1a\u4ee3\u8868\u5ba2\u6237\u7aef\u53d1\u9001\u8bf7\u6c42\uff0c\u5e76\u53ef\u80fd\u4fee\u6539\u8bf7\u6c42\u5934\uff08\u4f8b\u5982\u6dfb\u52a0<code>X-Forwarded-For<\/code>\uff09\u3002<\/li>\n\n\n\n<li>\u8bf7\u6c42\u4e5f\u53ef\u80fd\u7ecf\u8fc7<strong>\u8d1f\u8f7d\u5747\u8861\u5668<\/strong>\uff0c\u8d1f\u8f7d\u5747\u8861\u5668\u4f1a\u5c06\u8bf7\u6c42\u5206\u53d1\u5230\u540e\u7aef\u591a\u53f0\u670d\u52a1\u5668\u4e2d\u7684\u4e00\u53f0\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u9632\u706b\u5899<\/strong>: \u8bf7\u6c42\u4f1a\u7ecf\u8fc7\u5404\u79cd\u9632\u706b\u5899\uff0c\u9632\u706b\u5899\u4f1a\u6839\u636e\u89c4\u5219\u5141\u8bb8\u6216\u62d2\u7edd\u6d41\u91cf\u3002<\/li>\n<\/ol>\n\n\n\n<h4 class=\"wp-block-heading\">3.3 \u670d\u52a1\u7aef\u4fa7\u53d1\u751f\u4ec0\u4e48<\/h4>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u670d\u52a1\u5668\u63a5\u6536\u8bf7\u6c42<\/strong>: \u76ee\u6807\u670d\u52a1\u5668\uff08\u901a\u5e38\u662fWeb\u670d\u52a1\u5668\uff0c\u5982Apache, Nginx, IIS\uff09\u5728\u76d1\u542c\u7684\u7aef\u53e3\u4e0a\u63a5\u6536\u5230\u5ba2\u6237\u7aef\u53d1\u9001\u7684HTTP\u8bf7\u6c42\u3002<\/li>\n\n\n\n<li><strong>\u8bf7\u6c42\u5904\u7406<\/strong>:\n<ul class=\"wp-block-list\">\n<li>Web\u670d\u52a1\u5668\u89e3\u6790HTTP\u8bf7\u6c42\u62a5\u6587\uff0c\u8bfb\u53d6\u8bf7\u6c42\u884c\u3001\u8bf7\u6c42\u5934\u548c\u8bf7\u6c42\u4f53\u3002<\/li>\n\n\n\n<li>\u670d\u52a1\u5668\u6839\u636e<code>Host<\/code>\u5934\u786e\u5b9a\u8bf7\u6c42\u7684\u662f\u54ea\u4e2a\u865a\u62df\u4e3b\u673a\u3002<\/li>\n\n\n\n<li>\u670d\u52a1\u5668\u6839\u636e\u8bf7\u6c42\u7684\u8def\u5f84\uff08<code>\/index.html<\/code>\uff09\u67e5\u627e\u5bf9\u5e94\u7684\u8d44\u6e90\u3002<\/li>\n\n\n\n<li>\u5982\u679c\u8bf7\u6c42\u7684\u662f\u9759\u6001\u6587\u4ef6\uff08\u5982HTML\u3001CSS\u3001JS\u3001\u56fe\u7247\uff09\uff0c\u670d\u52a1\u5668\u76f4\u63a5\u8bfb\u53d6\u6587\u4ef6\u5185\u5bb9\u3002<\/li>\n\n\n\n<li>\u5982\u679c\u8bf7\u6c42\u7684\u662f\u52a8\u6001\u8d44\u6e90\uff08\u5982PHP\u3001Python\u3001Java\u7a0b\u5e8f\uff09\uff0cWeb\u670d\u52a1\u5668\u4f1a\u5c06\u8bf7\u6c42\u8f6c\u53d1\u7ed9\u76f8\u5e94\u7684\u5e94\u7528\u670d\u52a1\u5668\u6216\u811a\u672c\u89e3\u91ca\u5668\u8fdb\u884c\u5904\u7406\u3002\u5e94\u7528\u670d\u52a1\u5668\u4f1a\u6267\u884c\u4e1a\u52a1\u903b\u8f91\uff0c\u53ef\u80fd\u6d89\u53ca\u6570\u636e\u5e93\u67e5\u8be2\u3001\u6587\u4ef6\u64cd\u4f5c\u7b49\u3002<\/li>\n\n\n\n<li>\u5728\u5904\u7406\u8fc7\u7a0b\u4e2d\uff0c\u670d\u52a1\u5668\u53ef\u80fd\u4f1a\u8bfb\u53d6\u6216\u8bbe\u7f6eCookie\uff0c\u8fdb\u884c\u8eab\u4efd\u9a8c\u8bc1\u3001\u6743\u9650\u68c0\u67e5\u7b49\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u6784\u5efaHTTP\u54cd\u5e94<\/strong>:\n<ul class=\"wp-block-list\">\n<li>\u670d\u52a1\u5668\u6839\u636e\u5904\u7406\u7ed3\u679c\u6784\u5efaHTTP\u54cd\u5e94\u62a5\u6587\uff0c\u5305\u62ec\u72b6\u6001\u884c\uff08\u534f\u8bae\u7248\u672c\u3001\u72b6\u6001\u7801\u3001\u72b6\u6001\u63cf\u8ff0\uff09\u548c\u54cd\u5e94\u5934\uff0c\u4ee5\u53ca\u54cd\u5e94\u4f53\uff08\u5b9e\u9645\u8fd4\u56de\u7684\u5185\u5bb9\uff09\u3002<\/li>\n\n\n\n<li><strong>\u72b6\u6001\u884c\u793a\u4f8b<\/strong>: <code>HTTP\/1.1 200 OK<\/code><\/li>\n\n\n\n<li><strong>\u54cd\u5e94\u5934\u793a\u4f8b<\/strong>:\n<ul class=\"wp-block-list\">\n<li><code>Content-Type: text\/html; charset=UTF-8<\/code> (\u544a\u77e5\u6d4f\u89c8\u5668\u54cd\u5e94\u4f53\u7684\u6570\u636e\u7c7b\u578b\u548c\u7f16\u7801)<\/li>\n\n\n\n<li><code>Content-Length: 12345<\/code> (\u544a\u77e5\u6d4f\u89c8\u5668\u54cd\u5e94\u4f53\u7684\u5927\u5c0f)<\/li>\n\n\n\n<li><code>Server: Nginx\/1.18.0<\/code> (\u544a\u77e5\u6d4f\u89c8\u5668\u670d\u52a1\u5668\u8f6f\u4ef6\u4fe1\u606f)<\/li>\n\n\n\n<li><code>Set-Cookie: sessionid=new_session_id; Path=\/; HttpOnly<\/code> (\u5982\u679c\u9700\u8981\u8bbe\u7f6e\u65b0\u7684Cookie)<\/li>\n\n\n\n<li><code>Cache-Control: public, max-age=3600<\/code> (\u6307\u793a\u6d4f\u89c8\u5668\u5982\u4f55\u7f13\u5b58\u5185\u5bb9)<\/li>\n\n\n\n<li><code>Date: ...<\/code><\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u54cd\u5e94\u4f53<\/strong>: \u5305\u542b\u5b9e\u9645\u7684HTML\u3001JSON\u3001\u56fe\u7247\u7b49\u6570\u636e\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u53d1\u9001HTTP\u54cd\u5e94<\/strong>: \u670d\u52a1\u5668\u5c06\u6784\u5efa\u597d\u7684HTTP\u54cd\u5e94\u62a5\u6587\u901a\u8fc7\u5df2\u5efa\u7acb\u7684TCP\/TLS\u8fde\u63a5\u53d1\u9001\u56de\u5ba2\u6237\u7aef\u3002<\/li>\n<\/ol>\n\n\n\n<h4 class=\"wp-block-heading\">3.4 \u5ba2\u6237\u7aef (\u6d4f\u89c8\u5668) \u4fa7\u7ee7\u7eed\u53d1\u751f\u4ec0\u4e48<\/h4>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>\u6d4f\u89c8\u5668\u63a5\u6536\u54cd\u5e94<\/strong>: \u6d4f\u89c8\u5668\u63a5\u6536\u5230\u670d\u52a1\u5668\u53d1\u9001\u7684HTTP\u54cd\u5e94\u62a5\u6587\u3002<\/li>\n\n\n\n<li><strong>\u89e3\u6790\u54cd\u5e94<\/strong>:\n<ul class=\"wp-block-list\">\n<li>\u6d4f\u89c8\u5668\u89e3\u6790\u54cd\u5e94\u72b6\u6001\u884c\uff0c\u6839\u636e\u72b6\u6001\u7801\u5224\u65ad\u8bf7\u6c42\u662f\u5426\u6210\u529f\uff08\u4f8b\u5982200 OK\uff09\u3002<\/li>\n\n\n\n<li>\u6d4f\u89c8\u5668\u89e3\u6790\u54cd\u5e94\u5934\u3002\u5982\u679c\u9047\u5230<code>Set-Cookie<\/code>\u5934\uff0c\u6d4f\u89c8\u5668\u4f1a\u5b58\u50a8\u5bf9\u5e94\u7684Cookie\u3002<\/li>\n\n\n\n<li>\u5982\u679c\u72b6\u6001\u7801\u662f3xx\uff08\u91cd\u5b9a\u5411\uff09\uff0c\u6d4f\u89c8\u5668\u4f1a\u8bfb\u53d6<code>Location<\/code>\u5934\u4e2d\u7684\u65b0URL\uff0c\u7136\u540e\u91cd\u65b0\u5f00\u59cb\u6574\u4e2a\u6d41\u7a0b\uff08DNS\u89e3\u6790\u3001\u5efa\u7acb\u8fde\u63a5\u3001\u53d1\u9001\u8bf7\u6c42\uff09\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u6e32\u67d3\u9875\u9762<\/strong>:\n<ul class=\"wp-block-list\">\n<li>\u5982\u679c\u54cd\u5e94\u4f53\u662fHTML\u5185\u5bb9\uff0c\u6d4f\u89c8\u5668\u4f1a\u5f00\u59cb\u89e3\u6790HTML\u3001\u6784\u5efaDOM\u6811\u3002<\/li>\n\n\n\n<li>\u5728\u89e3\u6790HTML\u7684\u8fc7\u7a0b\u4e2d\uff0c\u5982\u679c\u9047\u5230<code>&lt;img><\/code>\u3001<code>&lt;link><\/code>\uff08CSS\uff09\u3001<code>&lt;script><\/code>\uff08JavaScript\uff09\u7b49\u6807\u7b7e\uff0c\u6d4f\u89c8\u5668\u4f1a\u4e3a\u8fd9\u4e9b\u8d44\u6e90\u518d\u6b21\u53d1\u8d77\u72ec\u7acb\u7684HTTP\u8bf7\u6c42\uff08\u91cd\u590d\u4e0a\u8ff0DNS\u89e3\u6790\u3001TCP\u8fde\u63a5\u3001\u8bf7\u6c42\u3001\u54cd\u5e94\u8fc7\u7a0b\uff09\u3002<\/li>\n\n\n\n<li>\u6d4f\u89c8\u5668\u4f1a\u4e0b\u8f7dCSS\u6587\u4ef6\u5e76\u89e3\u6790\uff0c\u6784\u5efaCSSOM\u6811\u3002<\/li>\n\n\n\n<li>\u6d4f\u89c8\u5668\u4f1a\u4e0b\u8f7dJavaScript\u6587\u4ef6\u5e76\u6267\u884c\u3002JavaScript\u53ef\u80fd\u4f1a\u4fee\u6539DOM\u3001\u53d1\u9001AJAX\u8bf7\u6c42\u7b49\u3002<\/li>\n\n\n\n<li>\u6d4f\u89c8\u5668\u5c06DOM\u6811\u548cCSSOM\u6811\u7ed3\u5408\uff0c\u751f\u6210\u6e32\u67d3\u6811\uff0c\u5e76\u8fdb\u884c\u5e03\u5c40\uff08Layout\uff09\u548c\u7ed8\u5236\uff08Paint\uff09\uff0c\u6700\u7ec8\u5c06\u9875\u9762\u5185\u5bb9\u5448\u73b0\u5728\u7528\u6237\u5c4f\u5e55\u4e0a\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u5173\u95ed\u6216\u4fdd\u6301\u8fde\u63a5<\/strong>:\n<ul class=\"wp-block-list\">\n<li>\u5982\u679c\u54cd\u5e94\u5934\u4e2d<code>Connection: close<\/code>\uff0c\u6d4f\u89c8\u5668\u4f1a\u5173\u95edTCP\u8fde\u63a5\u3002<\/li>\n\n\n\n<li>\u5982\u679c<code>Connection: keep-alive<\/code>\uff0c\u8fde\u63a5\u4f1a\u4fdd\u6301\u4e00\u6bb5\u65f6\u95f4\uff0c\u4ee5\u4fbf\u5728\u540e\u7eed\u8bf7\u6c42\u4e2d\u590d\u7528\uff0c\u63d0\u9ad8\u6548\u7387\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n\n\n\n<p>\u6574\u4e2a\u8fc7\u7a0b\u662f\u4e00\u4e2a\u590d\u6742\u7684\u534f\u4f5c\uff0c\u6d89\u53ca\u5230\u591a\u4e2a\u534f\u8bae\u548c\u7ec4\u4ef6\uff0c\u4f46\u5bf9\u7528\u6237\u800c\u8a00\uff0c\u901a\u5e38\u53ea\u662f\u4e00\u4e2a\u77ac\u95f4\u7684\u9875\u9762\u52a0\u8f7d\u3002\u5728CTF\u4e2d\uff0c\u5bf9\u8fd9\u4e2a\u6d41\u7a0b\u7684\u6df1\u5165\u7406\u89e3\u80fd\u5e2e\u52a9\u4f60\u8bc6\u522b\u6f5c\u5728\u7684\u653b\u51fb\u70b9\uff0c\u4f8b\u5982DNS\u52ab\u6301\u3001HTTP\u8bf7\u6c42\u8d70\u79c1\u3001Cookie\u4f2a\u9020\u3001XSS\u3001CSRF\u3001SQL\u6ce8\u5165\u7b49\u3002<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">CTF\u4e2d\u7684\u7f51\u7edc\u534f\u8bae\u4e0eHTTP\u653b\u9632\u6280\u672f\u8be6\u89e3<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">1. \u4eceURL\u8f93\u5165\u5230\u9875\u9762\u5c55\u793a\uff1a\u7f51\u7edc\u6570\u636e\u5305\u4f20\u8f93\u5168\u6d41\u7a0b\u89e3\u6790<\/h2>\n\n\n\n<p>\u5f53\u7528\u6237\u5728\u6d4f\u89c8\u5668\u5730\u5740\u680f\u8f93\u5165\u4e00\u4e2aURL\u5e76\u6309\u4e0b\u56de\u8f66\u952e\u65f6\uff0c\u4e00\u4e2a\u590d\u6742\u800c\u7cbe\u5bc6\u7684\u7f51\u7edc\u901a\u4fe1\u8fc7\u7a0b\u4fbf\u6084\u7136\u542f\u52a8\u3002\u8fd9\u4e2a\u8fc7\u7a0b\u6d89\u53ca\u4ece\u5e94\u7528\u5c42\u5230\u7269\u7406\u5c42\u7684\u591a\u4e2a\u7f51\u7edc\u534f\u8bae\u534f\u540c\u5de5\u4f5c\uff0c\u6700\u7ec8\u5c06\u8fdc\u7a0b\u670d\u52a1\u5668\u4e0a\u7684\u8d44\u6e90\u5448\u73b0\u7ed9\u7528\u6237\u3002\u5bf9\u4e8eCTF\uff08Capture The Flag\uff09\u7ade\u8d5b\u800c\u8a00\uff0c\u6df1\u5165\u7406\u89e3\u8fd9\u4e00\u6d41\u7a0b\u4e2d\u7684\u6bcf\u4e00\u4e2a\u7ec6\u8282\uff0c\u5c24\u5176\u662f\u6570\u636e\u5305\u7684\u4f20\u8f93\u4e0e\u4ea4\u4e92\u673a\u5236\uff0c\u662f\u8fdb\u884cWeb\u5b89\u5168\u653b\u9632\u3001\u6d41\u91cf\u5206\u6790\u548c\u6f0f\u6d1e\u6316\u6398\u7684\u57fa\u7840\u3002\u6574\u4e2a\u8fc7\u7a0b\u53ef\u4ee5\u6982\u62ec\u4e3aDNS\u89e3\u6790\u3001TCP\u8fde\u63a5\u5efa\u7acb\u3001HTTP\u8bf7\u6c42\u4e0e\u54cd\u5e94\u3001\u4ee5\u53ca\u6d4f\u89c8\u5668\u6e32\u67d3\u7b49\u5173\u952e\u6b65\u9aa4 \u3002\u5728CTF\u7684\u6d41\u91cf\u5206\u6790\u9898\u76ee\u4e2d\uff0c\u53c2\u8d5b\u8005\u5e38\u5e38\u9700\u8981\u5229\u7528Wireshark\u7b49\u5de5\u5177\uff0c\u4ece\u6355\u83b7\u7684pcap\u6587\u4ef6\u4e2d\u8fd8\u539f\u8fd9\u4e00\u8fc7\u7a0b\uff0c\u5bfb\u627e\u9690\u85cf\u7684flag\u6216\u653b\u51fb\u7ebf\u7d22 \u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">1.1 \u5e94\u7528\u5c42\uff1aURL\u89e3\u6790\u4e0eHTTP\u534f\u8bae<\/h3>\n\n\n\n<p>\u5e94\u7528\u5c42\u662f\u7f51\u7edc\u534f\u8bae\u6808\u7684\u6700\u9ad8\u5c42\uff0c\u76f4\u63a5\u9762\u5411\u7528\u6237\u7684\u5e94\u7528\u7a0b\u5e8f\uff0c\u5982\u6d4f\u89c8\u5668\u3002\u5728Web\u8bbf\u95ee\u8fc7\u7a0b\u4e2d\uff0c\u5e94\u7528\u5c42\u4e3b\u8981\u8d1f\u8d23URL\u7684\u89e3\u6790\u3001HTTP\u8bf7\u6c42\u62a5\u6587\u7684\u6784\u5efa\u4e0e\u53d1\u9001\uff0c\u4ee5\u53caHTTP\u54cd\u5e94\u62a5\u6587\u7684\u63a5\u6536\u4e0e\u89e3\u6790\u3002\u5728CTF\u7684\u6d41\u91cf\u5206\u6790\u9898\u76ee\u4e2d\uff0c\u5e94\u7528\u5c42\u6570\u636e\uff0c\u7279\u522b\u662fHTTP\u534f\u8bae\u7684\u7ec6\u8282\uff0c\u662f\u5bfb\u627eFlag\u7684\u5173\u952e \u3002\u4f8b\u5982\uff0c\u901a\u8fc7\u5206\u6790PCAP\u6587\u4ef6\u4e2d\u7684HTTP\u8bf7\u6c42\uff0c\u53ef\u4ee5\u53d1\u73b0\u653b\u51fb\u8005\u5c1d\u8bd5\u7684SQL\u6ce8\u5165\u3001XSS\u7b49\u653b\u51fb\u8f7d\u8377 \u3002\u540c\u6837\uff0cHTTP\u54cd\u5e94\u4e2d\u53ef\u80fd\u5305\u542b\u670d\u52a1\u5668\u9519\u8bef\u4fe1\u606f\u3001\u9690\u85cf\u7684\u6ce8\u91ca\u6216\u7ecf\u8fc7\u7f16\u7801\u7684\u654f\u611f\u6570\u636e\u3002Wireshark\u7b49\u5de5\u5177\u63d0\u4f9b\u4e86\u5f3a\u5927\u7684\u8fc7\u6ee4\u5668\uff0c\u5982<code>http.request.method == \"GET\"<\/code>\u6216<code>http contains \"flag\"<\/code>\uff0c\u5e2e\u52a9\u5206\u6790\u4eba\u5458\u5feb\u901f\u5b9a\u4f4d\u5230\u5173\u952e\u7684HTTP\u6570\u636e\u5305 \u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">1.1.1 URL\u89e3\u6790\u4e0e\u53c2\u6570\u63d0\u53d6<\/h4>\n\n\n\n<p>URL\uff08Uniform Resource Locator\uff0c\u7edf\u4e00\u8d44\u6e90\u5b9a\u4f4d\u7b26\uff09\u662f\u4e92\u8054\u7f51\u4e0a\u8d44\u6e90\u7684\u552f\u4e00\u5730\u5740\u3002\u4e00\u4e2a\u6807\u51c6\u7684URL\u7ed3\u6784\u53ef\u4ee5\u88ab\u5206\u89e3\u4e3a\u591a\u4e2a\u90e8\u5206\uff0c\u6bcf\u4e2a\u90e8\u5206\u90fd\u627f\u8f7d\u7740\u7279\u5b9a\u7684\u4fe1\u606f\uff0c\u5bf9\u4e8e\u7406\u89e3\u8bf7\u6c42\u7684\u76ee\u6807\u548c\u610f\u56fe\u81f3\u5173\u91cd\u8981\u3002\u5176\u901a\u7528\u683c\u5f0f\u4e3a\uff1a<code>scheme:\/\/[userinfo@]host[:port]\/path[?query][#fragment]<\/code>\u3002\u4f8b\u5982\uff0c\u5728URL <a href=\"https:\/\/user\" target=\"_blank\"  rel=\"nofollow\" ><code>https:\/\/user<\/code><\/a><code>:<\/code><a href=\"mailto:pass@example.com\" target=\"_blank\"  rel=\"nofollow\" ><code>pass@example.com<\/code><\/a><code>:8080\/path\/to\/resource?key1=value1&amp;key2=value2#section<\/code> \u4e2d\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><em><strong>*\u534f\u8bae\uff08Scheme\uff09*<\/strong><\/em> \uff1a<code>https<\/code>\uff0c\u6307\u660e\u4e86\u8bbf\u95ee\u8d44\u6e90\u6240\u4f7f\u7528\u7684\u534f\u8bae\uff0c\u5982HTTP\u3001HTTPS\u3001FTP\u7b49\u3002<\/li>\n\n\n\n<li><em><strong>*\u4e3b\u673a\u540d\uff08Host\uff09*<\/strong><\/em> \uff1a<a href=\"https:\/\/example.com\" target=\"_blank\"  rel=\"nofollow\" ><code>example.com<\/code><\/a>\uff0c\u6307\u660e\u4e86\u8d44\u6e90\u6240\u5728\u7684\u670d\u52a1\u5668\u7684\u57df\u540d\u6216IP\u5730\u5740\u3002<\/li>\n\n\n\n<li><em><strong>*\u7aef\u53e3\u53f7\uff08Port\uff09*<\/strong><\/em> \uff1a<code>8080<\/code>\uff0c\u6307\u660e\u4e86\u670d\u52a1\u5668\u4e0a\u7528\u4e8e\u76d1\u542c\u8be5\u534f\u8bae\u8bf7\u6c42\u7684\u7aef\u53e3\u3002\u5982\u679c\u7701\u7565\uff0c\u5219\u4f7f\u7528\u534f\u8bae\u7684\u9ed8\u8ba4\u7aef\u53e3\uff08HTTP\u4e3a80\uff0cHTTPS\u4e3a443\uff09\u3002<\/li>\n\n\n\n<li><em><strong>*\u8def\u5f84\uff08Path\uff09*<\/strong><\/em> \uff1a<code>\/path\/to\/resource<\/code>\uff0c\u6307\u660e\u4e86\u670d\u52a1\u5668\u4e0a\u8d44\u6e90\u7684\u5177\u4f53\u8def\u5f84\u3002<\/li>\n\n\n\n<li><em><strong>*\u67e5\u8be2\u53c2\u6570\uff08Query\uff09*<\/strong><\/em> \uff1a<code>?key1=value1&amp;key2=value2<\/code>\uff0c\u4ee5\u952e\u503c\u5bf9\u7684\u5f62\u5f0f\u5411\u670d\u52a1\u5668\u4f20\u9012\u989d\u5916\u7684\u53c2\u6570\u4fe1\u606f\uff0c\u591a\u4e2a\u53c2\u6570\u4e4b\u95f4\u7528<code>&amp;<\/code>\u8fde\u63a5\u3002<\/li>\n\n\n\n<li><em><strong>*\u7247\u6bb5\uff08Fragment\uff09*<\/strong><\/em> \uff1a<code>#section<\/code>\uff0c\u7528\u4e8e\u6307\u5b9a\u9875\u9762\u5185\u7684\u67d0\u4e2a\u951a\u70b9\uff0c\u6d4f\u89c8\u5668\u4f1a\u6839\u636e\u6b64\u7247\u6bb5\u5c06\u9875\u9762\u6eda\u52a8\u5230\u76f8\u5e94\u4f4d\u7f6e\uff0c\u8be5\u90e8\u5206\u4e0d\u4f1a\u88ab\u53d1\u9001\u5230\u670d\u52a1\u5668\u3002<\/li>\n<\/ul>\n\n\n\n<p>\u5728CTF\u4e2d\uff0c\u5bf9URL\u7684\u89e3\u6790\u548c\u5904\u7406\u4e0d\u5f53\u53ef\u80fd\u5bfc\u81f4\u591a\u79cd\u6f0f\u6d1e\u3002\u4f8b\u5982\uff0c\u670d\u52a1\u5668\u7aef\u4ee3\u7801\u53ef\u80fd\u5bf9URL\u7684<code>path<\/code>\u6216<code>query<\/code>\u90e8\u5206\u8fdb\u884c\u4e0d\u5b89\u5168\u7684\u5904\u7406\uff0c\u5bfc\u81f4\u8def\u5f84\u904d\u5386\u6216\u547d\u4ee4\u6267\u884c\u3002\u4e00\u4e2a\u5177\u4f53\u7684\u4f8b\u5b50\u662f\uff0c\u5982\u679c\u5e94\u7528\u7a0b\u5e8f\u4f7f\u7528<code>urljoin<\/code>\u548c<code>urlparse<\/code>\u7b49\u51fd\u6570\u5904\u7406\u7528\u6237\u8f93\u5165\u7684URL\uff0c\u653b\u51fb\u8005\u53ef\u80fd\u6784\u9020\u7279\u6b8a\u7684URL\uff08\u5982\u5305\u542b<code>@<\/code>\u7b26\u53f7\u6216\u7279\u6b8a\u7f16\u7801\uff09\u6765\u7ed5\u8fc7\u5b89\u5168\u68c0\u67e5\uff0c\u8bbf\u95ee\u672c\u4e0d\u5e94\u8bbf\u95ee\u7684\u5185\u90e8\u8d44\u6e90 \u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">1.1.2 HTTP\u8bf7\u6c42\u62a5\u6587\u7684\u6784\u5efa<\/h4>\n\n\n\n<p>\u5728URL\u89e3\u6790\u5b8c\u6210\u5e76\u83b7\u5f97\u670d\u52a1\u5668\u7684IP\u5730\u5740\u540e\uff0c\u6d4f\u89c8\u5668\u4f1a\u6784\u5efa\u4e00\u4e2aHTTP\u8bf7\u6c42\u62a5\u6587\u3002\u8fd9\u4e2a\u62a5\u6587\u7531\u8bf7\u6c42\u884c\u3001\u8bf7\u6c42\u5934\u90e8\uff08Headers\uff09\u548c\u8bf7\u6c42\u4f53\uff08Body\uff09\u4e09\u90e8\u5206\u7ec4\u6210\u3002\u8bf7\u6c42\u884c\u5305\u542b\u4e86\u8bf7\u6c42\u65b9\u6cd5\uff08\u5982GET, POST\uff09\u3001\u8bf7\u6c42\u7684\u8d44\u6e90\u8def\u5f84\uff08URL\u7684path\u548cquery\u90e8\u5206\uff09\u4ee5\u53caHTTP\u534f\u8bae\u7248\u672c\uff08\u5982HTTP\/1.1\uff09\u3002\u8bf7\u6c42\u5934\u90e8\u5305\u542b\u4e86\u5173\u4e8e\u5ba2\u6237\u7aef\u73af\u5883\u548c\u8bf7\u6c42\u7684\u5143\u6570\u636e\uff0c\u4f8b\u5982<code>Host<\/code>\u5934\u6307\u5b9a\u4e86\u76ee\u6807\u4e3b\u673a\u540d\uff0c<code>User-Agent<\/code>\u5934\u6807\u8bc6\u4e86\u5ba2\u6237\u7aef\u7684\u6d4f\u89c8\u5668\u548c\u64cd\u4f5c\u7cfb\u7edf\uff0c<code>Cookie<\/code>\u5934\u643a\u5e26\u4e86\u4e4b\u524d\u670d\u52a1\u5668\u8bbe\u7f6e\u7684\u4f1a\u8bdd\u4fe1\u606f\uff0c<code>Referer<\/code>\u5934\u6307\u793a\u4e86\u8bf7\u6c42\u7684\u6765\u6e90\u9875\u9762\uff0c<code>Content-Type<\/code>\u5934\u5b9a\u4e49\u4e86\u8bf7\u6c42\u4f53\u7684MIME\u7c7b\u578b\uff08\u5982<code>application\/x-www-form-urlencoded<\/code>\u6216<code>application\/json<\/code>\uff09\uff0c\u800c<code>X-Forwarded-For<\/code>\u5934\u5219\u7528\u4e8e\u6807\u8bc6\u5ba2\u6237\u7aef\u7684\u771f\u5b9eIP\u5730\u5740\uff0c\u5c24\u5176\u662f\u5728\u5b58\u5728\u4ee3\u7406\u7684\u60c5\u51b5\u4e0b \u3002<\/p>\n\n\n\n<p>\u5728CTF\u4e2d\uff0c\u8fd9\u4e9b\u8bf7\u6c42\u5934\u90fd\u662f\u6f5c\u5728\u7684\u653b\u51fb\u5411\u91cf\u3002\u4f8b\u5982\uff0c\u901a\u8fc7\u4fee\u6539<code>User-Agent<\/code>\u5934\uff0c\u53ef\u4ee5\u4f2a\u88c5\u6210\u7279\u5b9a\u7684\u6d4f\u89c8\u5668\u6216\u8bbe\u5907\uff0c\u7ed5\u8fc7\u57fa\u4e8e\u5ba2\u6237\u7aef\u7c7b\u578b\u7684\u8bbf\u95ee\u9650\u5236 \u3002\u901a\u8fc7\u4f2a\u9020<code>X-Forwarded-For<\/code>\u5934\uff0c\u53ef\u4ee5\u7ed5\u8fc7\u57fa\u4e8eIP\u5730\u5740\u7684\u8bbf\u95ee\u63a7\u5236\u6216\u6295\u7968\u9650\u5236 \u3002\u800c<code>Cookie<\/code>\u5934\u5219\u662f\u4f1a\u8bdd\u52ab\u6301\u548c\u6743\u9650\u63d0\u5347\u653b\u51fb\u7684\u5e38\u89c1\u76ee\u6807 \u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">1.1.3 HTTP\u54cd\u5e94\u62a5\u6587\u7684\u63a5\u6536\u4e0e\u89e3\u6790<\/h4>\n\n\n\n<p>\u670d\u52a1\u5668\u5904\u7406\u5b8cHTTP\u8bf7\u6c42\u540e\uff0c\u4f1a\u8fd4\u56de\u4e00\u4e2aHTTP\u54cd\u5e94\u62a5\u6587\u3002\u8be5\u62a5\u6587\u7531\u72b6\u6001\u884c\u3001\u54cd\u5e94\u5934\u90e8\uff08Headers\uff09\u548c\u54cd\u5e94\u4f53\uff08Body\uff09\u7ec4\u6210\u3002\u72b6\u6001\u884c\u5305\u542b\u4e86HTTP\u534f\u8bae\u7248\u672c\u3001\u4e00\u4e2a\u4e09\u4f4d\u6570\u7684\u72b6\u6001\u7801\uff08\u5982200, 301, 404, 500\uff09\u4ee5\u53ca\u4e00\u4e2a\u63cf\u8ff0\u6027\u7684\u77ed\u8bed\u3002\u72b6\u6001\u7801\u662f\u670d\u52a1\u5668\u5904\u7406\u7ed3\u679c\u7684\u76f4\u63a5\u53cd\u9988\uff0c\u5728CTF\u4e2d\u5177\u6709\u6781\u9ad8\u7684\u5206\u6790\u4ef7\u503c\u3002\u4f8b\u5982\uff0c<code>200 OK<\/code>\u8868\u793a\u8bf7\u6c42\u6210\u529f\uff0c<code>301\/302<\/code>\u8868\u793a\u91cd\u5b9a\u5411\uff0c\u53ef\u80fd\u6307\u5411\u9690\u85cf\u7684\u9875\u9762\u6216\u7528\u4e8e\u5f00\u653e\u91cd\u5b9a\u5411\u653b\u51fb \u3002<code>401\/403<\/code>\u8868\u793a\u8ba4\u8bc1\u6216\u6388\u6743\u5931\u8d25\uff0c\u4f46\u54cd\u5e94\u5934\u4e2d\u53ef\u80fd\u5305\u542b<code>WWW-Authenticate<\/code>\u7b49\u4fe1\u606f\uff0c\u6216\u8005\u901a\u8fc7\u7279\u5b9a\u7684\u8bf7\u6c42\u5934\u53ef\u4ee5\u7ed5\u8fc7 \u3002<code>5xx<\/code>\u7cfb\u5217\u9519\u8bef\u5219\u53ef\u80fd\u6cc4\u9732\u670d\u52a1\u5668\u7684\u5185\u90e8\u7ed3\u6784\u6216\u654f\u611f\u4fe1\u606f\u3002<\/p>\n\n\n\n<p>\u54cd\u5e94\u5934\u90e8\u5305\u542b\u4e86\u5173\u4e8e\u670d\u52a1\u5668\u548c\u54cd\u5e94\u5185\u5bb9\u7684\u5143\u6570\u636e\uff0c\u5982<code>Content-Type<\/code>\uff08\u5b9a\u4e49\u54cd\u5e94\u4f53\u7684\u7c7b\u578b\uff0c\u5982<code>text\/html<\/code>\uff09\u3001<code>Content-Length<\/code>\uff08\u54cd\u5e94\u4f53\u957f\u5ea6\uff09\u3001<code>Set-Cookie<\/code>\uff08\u8bbe\u7f6e\u65b0\u7684Cookie\uff09\u3001<code>Location<\/code>\uff08\u5728\u91cd\u5b9a\u5411\u65f6\u6307\u5b9a\u65b0\u5730\u5740\uff09\u7b49\u3002\u5728CTF\u7684\u6d41\u91cf\u5206\u6790\u4e2d\uff0c\u4ed4\u7ec6\u68c0\u67e5\u54cd\u5e94\u5934\u548c\u54cd\u5e94\u4f53\u662f\u53d1\u73b0Flag\u7684\u5173\u952e\u6b65\u9aa4\u3002\u4f8b\u5982\uff0cFlag\u53ef\u80fd\u9690\u85cf\u5728\u54cd\u5e94\u5934\u7684\u67d0\u4e2a\u81ea\u5b9a\u4e49\u5b57\u6bb5\u4e2d\uff0c\u6216\u8005\u7f16\u7801\u5728\u54cd\u5e94\u4f53\u7684HTML\u6ce8\u91ca\u3001JavaScript\u4ee3\u7801\u91cc \u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">1.2 \u4f20\u8f93\u5c42\uff1aTCP\u4e09\u6b21\u63e1\u624b\u4e0e\u56db\u6b21\u6325\u624b<\/h3>\n\n\n\n<p>\u4f20\u8f93\u5c42\u4e3b\u8981\u8d1f\u8d23\u7aef\u5230\u7aef\u7684\u901a\u4fe1\uff0c\u4e3a\u5e94\u7528\u5c42\u63d0\u4f9b\u53ef\u9760\u7684\u6570\u636e\u4f20\u8f93\u670d\u52a1\u3002\u5728Web\u901a\u4fe1\u4e2d\uff0c\u4f20\u8f93\u5c42\u4e3b\u8981\u4f7f\u7528TCP\uff08Transmission Control Protocol\uff09\u534f\u8bae\u3002TCP\u662f\u4e00\u79cd\u9762\u5411\u8fde\u63a5\u7684\u534f\u8bae\uff0c\u5728\u6570\u636e\u4f20\u8f93\u524d\u9700\u8981\u5efa\u7acb\u8fde\u63a5\uff0c\u4f20\u8f93\u5b8c\u6210\u540e\u9700\u8981\u65ad\u5f00\u8fde\u63a5\u3002\u8fd9\u4e2a\u8fc7\u7a0b\u901a\u8fc7\u201c\u4e09\u6b21\u63e1\u624b\u201d\u548c\u201c\u56db\u6b21\u6325\u624b\u201d\u6765\u5b9e\u73b0\u3002\u5728CTF\u7684\u7f51\u7edc\u6d41\u91cf\u5206\u6790\u4e2d\uff0c\u89c2\u5bdfTCP\u63e1\u624b\u8fc7\u7a0b\u53ef\u4ee5\u5e2e\u52a9\u786e\u8ba4\u901a\u4fe1\u662f\u5426\u6b63\u5e38\u5efa\u7acb\uff0c\u800c\u5206\u6790TCP\u6d41\u5219\u53ef\u4ee5\u91cd\u5efa\u5b8c\u6574\u7684\u4f1a\u8bdd\u6570\u636e\uff0c\u5373\u4f7f\u6570\u636e\u88ab\u5206\u5272\u6210\u591a\u4e2a\u6570\u636e\u5305 \u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">1.2.1 \u5efa\u7acb\u8fde\u63a5\uff1aTCP\u4e09\u6b21\u63e1\u624b\u8fc7\u7a0b<\/h4>\n\n\n\n<p>TCP\u4e09\u6b21\u63e1\u624b\u662f\u5efa\u7acb\u4e00\u4e2aTCP\u8fde\u63a5\u7684\u6807\u51c6\u8fc7\u7a0b\uff0c\u786e\u4fdd\u4e86\u8fde\u63a5\u7684\u53cc\u65b9\u90fd\u51c6\u5907\u597d\u8fdb\u884c\u6570\u636e\u4f20\u8f93\u3002\u8fd9\u4e2a\u8fc7\u7a0b\u6d89\u53ca\u4e09\u4e2a\u6570\u636e\u5305\u7684\u4ea4\u6362\uff1a<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><em><strong>*\u7b2c\u4e00\u6b21\u63e1\u624b\uff08SYN\uff09*<\/strong><\/em> \uff1a\u5ba2\u6237\u7aef\u5411\u670d\u52a1\u5668\u53d1\u9001\u4e00\u4e2aTCP\u6570\u636e\u5305\uff0c\u8be5\u5305\u7684TCP\u5934\u90e8\u4e2d\u7684<code>SYN<\/code>\uff08Synchronize\uff09\u6807\u5fd7\u4f4d\u88ab\u7f6e\u4e3a1\u3002\u8fd9\u4e2a\u6570\u636e\u5305\u8fd8\u5305\u542b\u4e00\u4e2a\u521d\u59cb\u5e8f\u5217\u53f7\uff08Sequence Number, <code>seq=x<\/code>\uff09\uff0c\u7528\u4e8e\u540e\u7eed\u7684\u6570\u636e\u6392\u5e8f\u548c\u786e\u8ba4\u3002\u8fd9\u4e2a<code>SYN<\/code>\u5305\u8868\u793a\u5ba2\u6237\u7aef\u8bf7\u6c42\u5efa\u7acb\u8fde\u63a5\u3002<\/li>\n\n\n\n<li><em><strong>*\u7b2c\u4e8c\u6b21\u63e1\u624b\uff08SYN-ACK\uff09*<\/strong><\/em> \uff1a\u670d\u52a1\u5668\u6536\u5230\u5ba2\u6237\u7aef\u7684<code>SYN<\/code>\u5305\u540e\uff0c\u5982\u679c\u540c\u610f\u5efa\u7acb\u8fde\u63a5\uff0c\u4f1a\u8fd4\u56de\u4e00\u4e2a\u54cd\u5e94\u6570\u636e\u5305\u3002\u8fd9\u4e2a\u6570\u636e\u5305\u7684<code>SYN<\/code>\u548c<code>ACK<\/code>\uff08Acknowledgment\uff09\u6807\u5fd7\u4f4d\u90fd\u88ab\u7f6e\u4e3a1\u3002<code>ACK<\/code>\u6807\u5fd7\u4f4d\u8868\u793a\u5bf9\u5ba2\u6237\u7aef<code>SYN<\/code>\u5305\u7684\u786e\u8ba4\uff0c\u5176\u786e\u8ba4\u53f7\uff08Acknowledgment Number, <code>ack=x+1<\/code>\uff09\u662f\u5ba2\u6237\u7aef\u521d\u59cb\u5e8f\u5217\u53f7\u52a01\u3002\u540c\u65f6\uff0c\u670d\u52a1\u5668\u4e5f\u4f1a\u53d1\u9001\u81ea\u5df1\u7684\u521d\u59cb\u5e8f\u5217\u53f7\uff08<code>seq=y<\/code>\uff09\u3002<\/li>\n\n\n\n<li><em><strong>*\u7b2c\u4e09\u6b21\u63e1\u624b\uff08ACK\uff09*<\/strong><\/em> \uff1a\u5ba2\u6237\u7aef\u6536\u5230\u670d\u52a1\u5668\u7684<code>SYN-ACK<\/code>\u5305\u540e\uff0c\u4f1a\u518d\u53d1\u9001\u4e00\u4e2a<code>ACK<\/code>\u5305\u7ed9\u670d\u52a1\u5668\u3002\u8fd9\u4e2a\u5305\u7684<code>ACK<\/code>\u6807\u5fd7\u4f4d\u88ab\u7f6e\u4e3a1\uff0c\u786e\u8ba4\u53f7\u662f\u670d\u52a1\u5668\u7684\u521d\u59cb\u5e8f\u5217\u53f7\u52a01\uff08<code>ack=y+1<\/code>\uff09\uff0c\u5e8f\u5217\u53f7\u5219\u662f<code>x+1<\/code>\u3002<\/li>\n<\/ol>\n\n\n\n<p>\u5b8c\u6210\u8fd9\u4e09\u6b21\u63e1\u624b\u540e\uff0c\u4e00\u4e2a\u53ef\u9760\u7684TCP\u8fde\u63a5\u5c31\u5efa\u7acb\u8d77\u6765\u4e86\uff0c\u5ba2\u6237\u7aef\u548c\u670d\u52a1\u5668\u53ef\u4ee5\u5f00\u59cb\u901a\u8fc7\u8be5\u8fde\u63a5\u53d1\u9001HTTP\u8bf7\u6c42\u548c\u54cd\u5e94\u6570\u636e\u3002\u5728Wireshark\u4e2d\uff0c\u53ef\u4ee5\u901a\u8fc7\u8fc7\u6ee4\u5668<code>tcp.flags.syn == 1 and tcp.flags.ack == 0<\/code>\u6765\u627e\u5230\u7b2c\u4e00\u6b21\u63e1\u624b\u7684<code>SYN<\/code>\u5305\uff0c\u901a\u8fc7<code>tcp.flags.syn == 1 and tcp.flags.ack == 1<\/code>\u627e\u5230\u7b2c\u4e8c\u6b21\u63e1\u624b\u7684<code>SYN-ACK<\/code>\u5305\uff0c\u4ece\u800c\u6e05\u6670\u5730\u8ffd\u8e2a\u8fde\u63a5\u5efa\u7acb\u7684\u8fc7\u7a0b \u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">1.2.2 \u6570\u636e\u4f20\u8f93\u4e0e\u6d41\u91cf\u63a7\u5236<\/h4>\n\n\n\n<p>TCP\u8fde\u63a5\u5efa\u7acb\u540e\uff0c\u6570\u636e\u5c31\u53ef\u4ee5\u5728\u5ba2\u6237\u7aef\u548c\u670d\u52a1\u5668\u4e4b\u95f4\u53cc\u5411\u4f20\u8f93\u3002TCP\u901a\u8fc7\u5e8f\u5217\u53f7\u548c\u786e\u8ba4\u53f7\u673a\u5236\u6765\u4fdd\u8bc1\u6570\u636e\u7684\u6709\u5e8f\u548c\u53ef\u9760\u4f20\u8f93\u3002\u53d1\u9001\u65b9\u4e3a\u6bcf\u4e2a\u5b57\u8282\u7684\u6570\u636e\u5206\u914d\u4e00\u4e2a\u5e8f\u5217\u53f7\uff0c\u63a5\u6536\u65b9\u901a\u8fc7\u53d1\u9001\u786e\u8ba4\u53f7\uff08\u671f\u671b\u6536\u5230\u7684\u4e0b\u4e00\u4e2a\u5b57\u8282\u7684\u5e8f\u5217\u53f7\uff09\u6765\u544a\u77e5\u53d1\u9001\u65b9\u54ea\u4e9b\u6570\u636e\u5df2\u6210\u529f\u63a5\u6536\u3002\u5982\u679c\u53d1\u9001\u65b9\u5728\u4e00\u5b9a\u65f6\u95f4\u5185\u6ca1\u6709\u6536\u5230\u67d0\u4e2a\u6570\u636e\u5305\u7684\u786e\u8ba4\uff0c\u5b83\u4f1a\u91cd\u4f20\u8be5\u6570\u636e\u5305\u3002\u6b64\u5916\uff0cTCP\u8fd8\u4f7f\u7528\u6ed1\u52a8\u7a97\u53e3\u673a\u5236\u8fdb\u884c\u6d41\u91cf\u63a7\u5236\u3002\u63a5\u6536\u65b9\u4f1a\u5728\u5176<code>ACK<\/code>\u5305\u4e2d\u901a\u544a\u4e00\u4e2a\u201c\u7a97\u53e3\u5927\u5c0f\u201d\uff08Window Size\uff09\uff0c\u544a\u8bc9\u53d1\u9001\u65b9\u5b83\u5f53\u524d\u80fd\u63a5\u6536\u591a\u5c11\u6570\u636e\u3002\u53d1\u9001\u65b9\u6839\u636e\u8fd9\u4e2a\u7a97\u53e3\u5927\u5c0f\u6765\u8c03\u6574\u5176\u53d1\u9001\u901f\u7387\uff0c\u9632\u6b62\u56e0\u53d1\u9001\u8fc7\u5feb\u800c\u5bfc\u81f4\u63a5\u6536\u65b9\u7f13\u51b2\u533a\u6ea2\u51fa\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">1.2.3 \u65ad\u5f00\u8fde\u63a5\uff1aTCP\u56db\u6b21\u6325\u624b\u8fc7\u7a0b<\/h4>\n\n\n\n<p>\u5f53\u6570\u636e\u4f20\u8f93\u5b8c\u6210\u540e\uff0cTCP\u8fde\u63a5\u9700\u8981\u901a\u8fc7\u56db\u6b21\u6325\u624b\u6765\u4f18\u96c5\u5730\u5173\u95ed\u3002\u8fd9\u4e2a\u8fc7\u7a0b\u786e\u4fdd\u4e86\u53cc\u65b9\u90fd\u5b8c\u6210\u4e86\u6570\u636e\u53d1\u9001\uff0c\u5e76\u51c6\u5907\u597d\u65ad\u5f00\u8fde\u63a5\u3002<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><em><strong>*\u7b2c\u4e00\u6b21\u6325\u624b\uff08FIN\uff09*<\/strong><\/em> \uff1a\u5047\u8bbe\u5ba2\u6237\u7aef\u5b8c\u6210\u6570\u636e\u53d1\u9001\uff0c\u5e0c\u671b\u5173\u95ed\u8fde\u63a5\u3002\u5b83\u4f1a\u53d1\u9001\u4e00\u4e2a<code>FIN<\/code>\uff08Finish\uff09\u6807\u5fd7\u4f4d\u4e3a1\u7684\u6570\u636e\u5305\uff0c\u5e8f\u5217\u53f7\u4e3a<code>seq=u<\/code>\u3002<\/li>\n\n\n\n<li><em><strong>*\u7b2c\u4e8c\u6b21\u6325\u624b\uff08ACK\uff09*<\/strong><\/em> \uff1a\u670d\u52a1\u5668\u6536\u5230<code>FIN<\/code>\u5305\u540e\uff0c\u53d1\u9001\u4e00\u4e2a<code>ACK<\/code>\u5305\u4f5c\u4e3a\u54cd\u5e94\uff0c\u786e\u8ba4\u53f7\u4e3a<code>ack=u+1<\/code>\u3002\u6b64\u65f6\uff0c\u4ece\u5ba2\u6237\u7aef\u5230\u670d\u52a1\u5668\u7684\u65b9\u5411\u8fde\u63a5\u88ab\u5173\u95ed\uff0c\u4f46\u670d\u52a1\u5668\u5230\u5ba2\u6237\u7aef\u7684\u65b9\u5411\u4ecd\u7136\u53ef\u4ee5\u53d1\u9001\u6570\u636e\uff08\u534a\u5173\u95ed\u72b6\u6001\uff09\u3002<\/li>\n\n\n\n<li><em><strong>*\u7b2c\u4e09\u6b21\u6325\u624b\uff08FIN\uff09*<\/strong><\/em> \uff1a\u5f53\u670d\u52a1\u5668\u4e5f\u5b8c\u6210\u6570\u636e\u53d1\u9001\u540e\uff0c\u5b83\u4f1a\u53d1\u9001\u4e00\u4e2a<code>FIN<\/code>\u5305\u7ed9\u5ba2\u6237\u7aef\uff0c\u5e8f\u5217\u53f7\u4e3a<code>seq=w<\/code>\uff08\u5047\u8bbe\u670d\u52a1\u5668\u5728\u6b64\u671f\u95f4\u53c8\u53d1\u9001\u4e86\u4e00\u4e9b\u6570\u636e\uff09\u3002<\/li>\n\n\n\n<li><em><strong>*\u7b2c\u56db\u6b21\u6325\u624b\uff08ACK\uff09*<\/strong><\/em> \uff1a\u5ba2\u6237\u7aef\u6536\u5230\u670d\u52a1\u5668\u7684<code>FIN<\/code>\u5305\u540e\uff0c\u53d1\u9001\u4e00\u4e2a<code>ACK<\/code>\u5305\u4f5c\u4e3a\u54cd\u5e94\u3002\u7136\u540e\u5ba2\u6237\u7aef\u8fdb\u5165<code>TIME-WAIT<\/code>\u72b6\u6001\uff0c\u7b49\u5f85\u8db3\u591f\u7684\u65f6\u95f4\uff082MSL\uff0cMaximum Segment Lifetime\uff09\u4ee5\u786e\u4fdd\u670d\u52a1\u5668\u6536\u5230\u4e86ACK\u62a5\u6587\u3002\u670d\u52a1\u5668\u6536\u5230ACK\u540e\uff0c\u8fde\u63a5\u5b8c\u5168\u5173\u95ed\u3002<\/li>\n<\/ol>\n\n\n\n<p>\u8fd9\u4e2a\u56db\u6b21\u6325\u624b\u7684\u8fc7\u7a0b\u786e\u4fdd\u4e86\u53cc\u5411\u901a\u4fe1\u7684\u53ef\u9760\u7ec8\u6b62\u3002\u5728Wireshark\u4e2d\uff0c\u53ef\u4ee5\u901a\u8fc7\u8fc7\u6ee4\u5668<code>tcp.flags.fin == 1<\/code>\u6765\u8ffd\u8e2a\u8fde\u63a5\u5173\u95ed\u7684\u8fc7\u7a0b\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">1.3 \u7f51\u7edc\u5c42\uff1aIP\u5bfb\u5740\u4e0e\u8def\u7531<\/h3>\n\n\n\n<p>\u7f51\u7edc\u5c42\u8d1f\u8d23\u5c06\u6570\u636e\u5305\u4ece\u6e90\u4e3b\u673a\u53d1\u9001\u5230\u76ee\u6807\u4e3b\u673a\uff0c\u5176\u6838\u5fc3\u529f\u80fd\u662f\u903b\u8f91\u5bfb\u5740\uff08IP\u5730\u5740\uff09\u548c\u8def\u7531\u9009\u62e9\u3002\u5728Web\u8bbf\u95ee\u6d41\u7a0b\u4e2d\uff0c\u5f53\u5e94\u7528\u5c42\u548c\u4f20\u8f93\u5c42\u51c6\u5907\u597d\u6570\u636e\u6bb5\uff08TCP segment\uff09\u540e\uff0c\u7f51\u7edc\u5c42\u4f1a\u4e3a\u5176\u6dfb\u52a0IP\u5934\u90e8\uff0c\u5f62\u6210IP\u6570\u636e\u62a5\uff08IP datagram\uff09\u3002IP\u5934\u90e8\u5305\u542b\u4e86\u6e90IP\u5730\u5740\uff08\u5ba2\u6237\u7aef\u7684IP\uff09\u548c\u76ee\u6807IP\u5730\u5740\uff08\u670d\u52a1\u5668\u7684IP\uff0c\u901a\u8fc7DNS\u89e3\u6790\u83b7\u5f97\uff09\u3002\u8fd9\u4e2a\u5bfb\u5740\u8fc7\u7a0b\u4f7f\u5f97\u6570\u636e\u5305\u80fd\u591f\u5728\u590d\u6742\u7684\u7f51\u7edc\u4e2d\u627e\u5230\u76ee\u7684\u5730\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">1.3.1 \u6e90IP\u4e0e\u76ee\u6807IP\u7684\u5c01\u88c5<\/h4>\n\n\n\n<p>\u5728\u6570\u636e\u5305\u4ece\u4f20\u8f93\u5c42\u4f20\u9012\u5230\u7f51\u7edc\u5c42\u65f6\uff0cIP\u534f\u8bae\u4f1a\u4e3a\u6570\u636e\u6bb5\u5c01\u88c5\u4e00\u4e2aIP\u5934\u90e8\u3002\u8fd9\u4e2a\u5934\u90e8\u5305\u542b\u4e86\u591a\u4e2a\u5173\u952e\u5b57\u6bb5\uff0c\u5176\u4e2d\u6700\u91cd\u8981\u7684\u662f\u6e90IP\u5730\u5740\u548c\u76ee\u6807IP\u5730\u5740\u3002\u6e90IP\u5730\u5740\u662f\u53d1\u8d77\u901a\u4fe1\u7684\u5ba2\u6237\u7aef\u7684\u516c\u7f51IP\u5730\u5740\uff08\u6216\u7ecf\u8fc7NAT\u8f6c\u6362\u540e\u7684\u5730\u5740\uff09\uff0c\u5b83\u6807\u8bc6\u4e86\u6570\u636e\u5305\u7684\u53d1\u9001\u65b9\u3002\u76ee\u6807IP\u5730\u5740\u662f\u901a\u8fc7DNS\u89e3\u6790\u5f97\u5230\u7684Web\u670d\u52a1\u5668\u7684IP\u5730\u5740\uff0c\u5b83\u51b3\u5b9a\u4e86\u6570\u636e\u5305\u7684\u6700\u7ec8\u76ee\u7684\u5730\u3002\u9664\u4e86\u5730\u5740\u4fe1\u606f\uff0cIP\u5934\u90e8\u8fd8\u5305\u542b\u7248\u672c\uff08IPv4\u6216IPv6\uff09\u3001\u9996\u90e8\u957f\u5ea6\u3001\u670d\u52a1\u7c7b\u578b\uff08ToS\uff09\u3001\u603b\u957f\u5ea6\u3001\u6807\u8bc6\u3001\u6807\u5fd7\uff08\u7528\u4e8e\u5206\u7247\uff09\u3001\u7247\u504f\u79fb\u3001\u751f\u5b58\u65f6\u95f4\uff08TTL\uff09\u3001\u534f\u8bae\uff08\u6307\u793a\u4e0a\u5c42\u534f\u8bae\uff0c\u5982TCP\u6216UDP\uff09\u4ee5\u53ca\u5934\u90e8\u6821\u9a8c\u548c\u7b49\u5b57\u6bb5\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">1.3.2 \u6570\u636e\u5305\u7684\u8def\u7531\u4e0e\u8f6c\u53d1<\/h4>\n\n\n\n<p>IP\u6570\u636e\u62a5\u88ab\u521b\u5efa\u540e\uff0c\u4f1a\u88ab\u53d1\u9001\u5230\u672c\u5730\u7f51\u7edc\u3002\u5982\u679c\u76ee\u6807IP\u5730\u5740\u4e0e\u6e90IP\u5730\u5740\u5728\u540c\u4e00\u5b50\u7f51\u5185\uff0c\u6570\u636e\u5305\u4f1a\u76f4\u63a5\u901a\u8fc7\u6570\u636e\u94fe\u8def\u5c42\u53d1\u9001\u5230\u76ee\u6807\u4e3b\u673a\u3002\u5982\u679c\u76ee\u6807IP\u5730\u5740\u5728\u4e0d\u540c\u7684\u7f51\u7edc\u4e2d\uff0c\u6570\u636e\u5305\u4f1a\u88ab\u53d1\u9001\u5230\u9ed8\u8ba4\u7f51\u5173\uff08\u901a\u5e38\u662f\u8def\u7531\u5668\uff09\u3002\u8def\u7531\u5668\u63a5\u6536\u5230\u6570\u636e\u5305\u540e\uff0c\u4f1a\u6839\u636e\u5176\u8def\u7531\u8868\u6765\u51b3\u5b9a\u5c06\u6570\u636e\u5305\u8f6c\u53d1\u5230\u54ea\u4e2a\u4e0b\u4e00\u8df3\u8def\u7531\u5668\u3002\u8fd9\u4e2a\u8fc7\u7a0b\u4f1a\u4e00\u76f4\u91cd\u590d\uff0c\u76f4\u5230\u6570\u636e\u5305\u5230\u8fbe\u76ee\u6807\u7f51\u7edc\u3002\u5728\u76ee\u6807\u7f51\u7edc\u4e2d\uff0c\u6700\u540e\u7684\u8def\u7531\u5668\u4f1a\u5c06\u6570\u636e\u5305\u53d1\u9001\u7ed9\u76ee\u6807\u4e3b\u673a\u3002\u8fd9\u4e2a\u8def\u7531\u548c\u8f6c\u53d1\u7684\u8fc7\u7a0b\u662f\u4e92\u8054\u7f51\u80fd\u591f\u6b63\u5e38\u5de5\u4f5c\u7684\u57fa\u7840\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">1.4 \u6570\u636e\u94fe\u8def\u5c42\uff1aMAC\u5730\u5740\u4e0e\u5e27\u4f20\u8f93<\/h3>\n\n\n\n<p>\u6570\u636e\u94fe\u8def\u5c42\u662fOSI\u6a21\u578b\u7684\u7b2c\u4e8c\u5c42\uff0c\u8d1f\u8d23\u5728\u7269\u7406\u7f51\u7edc\u6bb5\uff08\u5982\u4ee5\u592a\u7f51\uff09\u4e0a\u7684\u8282\u70b9\u4e4b\u95f4\u53ef\u9760\u5730\u4f20\u8f93\u6570\u636e\u3002\u5b83\u5c06\u7f51\u7edc\u5c42\u4f20\u6765\u7684IP\u6570\u636e\u62a5\u5c01\u88c5\u6210\u5e27\uff08Frame\uff09\uff0c\u5e76\u901a\u8fc7\u7269\u7406\u5c42\u8fdb\u884c\u4f20\u8f93\u3002\u5e27\u7684\u5934\u90e8\u5305\u542b\u4e86\u6e90MAC\u5730\u5740\u548c\u76ee\u6807MAC\u5730\u5740\u3002MAC\u5730\u5740\u662f\u7f51\u5361\u7684\u7269\u7406\u5730\u5740\uff0c\u5728\u5168\u7403\u8303\u56f4\u5185\u662f\u552f\u4e00\u7684\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">1.4.1 \u4ee5\u592a\u7f51\u5e27\u7684\u5c01\u88c5<\/h4>\n\n\n\n<p>\u5f53IP\u6570\u636e\u62a5\u5230\u8fbe\u6570\u636e\u94fe\u8def\u5c42\u65f6\uff0c\u5b83\u4f1a\u88ab\u5c01\u88c5\u5728\u4e00\u4e2a\u4ee5\u592a\u7f51\u5e27\u4e2d\u3002\u4ee5\u592a\u7f51\u5e27\u7684\u683c\u5f0f\u901a\u5e38\u5305\u62ec\u4ee5\u4e0b\u51e0\u4e2a\u90e8\u5206\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><em><strong>*\u524d\u540c\u6b65\u7801\uff08Preamble\uff09\u548c\u5e27\u5f00\u59cb\u5b9a\u754c\u7b26\uff08SFD\uff09*<\/strong><\/em> \uff1a\u7528\u4e8e\u540c\u6b65\u63a5\u6536\u65b9\u7684\u65f6\u949f\u3002<\/li>\n\n\n\n<li><em><strong>*\u76ee\u6807MAC\u5730\u5740\uff08Destination MAC Address\uff09*<\/strong><\/em> \uff1a\u63a5\u6536\u65b9\u7f51\u5361\u7684\u7269\u7406\u5730\u5740\u3002<\/li>\n\n\n\n<li><em><strong>*\u6e90MAC\u5730\u5740\uff08Source MAC Address\uff09*<\/strong><\/em> \uff1a\u53d1\u9001\u65b9\u7f51\u5361\u7684\u7269\u7406\u5730\u5740\u3002<\/li>\n\n\n\n<li><em><strong>*\u7c7b\u578b\/\u957f\u5ea6\uff08Type\/Length\uff09*<\/strong><\/em> \uff1a\u6307\u793a\u5e27\u4e2d\u5c01\u88c5\u7684\u4e0a\u5c42\u534f\u8bae\u7c7b\u578b\uff08\u5982IPv4, IPv6, ARP\uff09\u6216\u5e27\u7684\u957f\u5ea6\u3002<\/li>\n\n\n\n<li><em><strong>*\u6570\u636e\uff08Data\uff09*<\/strong><\/em> \uff1a\u5c01\u88c5\u7684\u4e0a\u5c42\u6570\u636e\uff0c\u5373IP\u6570\u636e\u62a5\u3002<\/li>\n\n\n\n<li><em><strong>*\u5e27\u6821\u9a8c\u5e8f\u5217\uff08Frame Check Sequence, FCS\uff09*<\/strong><\/em> \uff1a\u7528\u4e8e\u68c0\u6d4b\u5e27\u5728\u4f20\u8f93\u8fc7\u7a0b\u4e2d\u662f\u5426\u53d1\u751f\u9519\u8bef\u3002<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">1.4.2 \u7269\u7406\u4ecb\u8d28\u4e0a\u7684\u6570\u636e\u4f20\u8f93<\/h4>\n\n\n\n<p>\u7269\u7406\u5c42\u662fOSI\u6a21\u578b\u7684\u6700\u5e95\u5c42\uff0c\u8d1f\u8d23\u5c06\u6570\u636e\u94fe\u8def\u5c42\u4f20\u6765\u7684\u6bd4\u7279\u6d41\uff080\u548c1\uff09\u901a\u8fc7\u7269\u7406\u4ecb\u8d28\uff08\u5982\u53cc\u7ede\u7ebf\u3001\u5149\u7ea4\u3001\u65e0\u7ebf\u7535\u6ce2\uff09\u8fdb\u884c\u4f20\u8f93\u3002\u5b83\u5b9a\u4e49\u4e86\u7535\u6c14\u3001\u673a\u68b0\u3001\u89c4\u7a0b\u548c\u529f\u80fd\u4e0a\u7684\u63a5\u53e3\uff0c\u4f8b\u5982\u7535\u538b\u6c34\u5e73\u3001\u6570\u636e\u901f\u7387\u3001\u6700\u5927\u4f20\u8f93\u8ddd\u79bb\u7b49\u3002\u7269\u7406\u5c42\u4e0d\u5173\u5fc3\u6570\u636e\u7684\u542b\u4e49\uff0c\u53ea\u8d1f\u8d23\u53ef\u9760\u5730\u4f20\u8f93\u6bd4\u7279\u3002\u5728CTF\u4e2d\uff0c\u867d\u7136\u76f4\u63a5\u64cd\u4f5c\u7269\u7406\u5c42\u7684\u60c5\u51b5\u8f83\u5c11\uff0c\u4f46\u7406\u89e3\u5176\u57fa\u672c\u539f\u7406\u6709\u52a9\u4e8e\u5168\u9762\u638c\u63e1\u7f51\u7edc\u901a\u4fe1\u3002<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">2. \u4e3b\u673aIP\u5730\u5740\u83b7\u53d6\uff1aDNS\u57df\u540d\u89e3\u6790\u8fc7\u7a0b<\/h2>\n\n\n\n<p>\u5728Web\u8bbf\u95ee\u7684\u521d\u59cb\u9636\u6bb5\uff0c\u6d4f\u89c8\u5668\u9700\u8981\u5c06\u7528\u6237\u8f93\u5165\u7684\u57df\u540d\uff08\u5982 <a href=\"https:\/\/www.example.com\" target=\"_blank\"  rel=\"nofollow\" ><code>www.example.com<\/code><\/a>\uff09\u89e3\u6790\u4e3a\u673a\u5668\u53ef\u8bfb\u7684IP\u5730\u5740\uff08\u5982 <code>93.184.216.34<\/code>\uff09\u3002\u8fd9\u4e2a\u8fc7\u7a0b\u7531\u57df\u540d\u7cfb\u7edf\uff08DNS\uff09\u5b8c\u6210\u3002DNS\u662f\u4e00\u4e2a\u5206\u5e03\u5f0f\u7684\u3001\u5c42\u6b21\u5316\u7684\u6570\u636e\u5e93\u7cfb\u7edf\uff0c\u5b83\u5c06\u57df\u540d\u6620\u5c04\u5230IP\u5730\u5740\u3002\u6574\u4e2a\u89e3\u6790\u8fc7\u7a0b\u662f\u4e00\u4e2a\u9012\u5f52\u67e5\u8be2\u548c\u8fed\u4ee3\u67e5\u8be2\u76f8\u7ed3\u5408\u7684\u8fc7\u7a0b\uff0c\u65e8\u5728\u9ad8\u6548\u3001\u53ef\u9760\u5730\u5c06\u57df\u540d\u8f6c\u6362\u4e3aIP\u5730\u5740\u3002\u5728CTF\u4e2d\uff0cDNS\u4e0d\u4ec5\u662f\u7f51\u7edc\u901a\u4fe1\u7684\u57fa\u7840\uff0c\u5176\u672c\u8eab\u4e5f\u53ef\u80fd\u6210\u4e3a\u653b\u51fb\u76ee\u6807\u6216\u4fe1\u606f\u6cc4\u9732\u7684\u6e20\u9053\u3002\u4f8b\u5982\uff0cDNS\u7f13\u5b58\u6295\u6bd2\u653b\u51fb\u53ef\u4ee5\u52ab\u6301\u7528\u6237\u7684\u6d41\u91cf\uff0c\u800cDNS\u96a7\u9053\u6280\u672f\u5219\u53ef\u4ee5\u5229\u7528DNS\u67e5\u8be2\u6765\u9690\u853d\u5730\u4f20\u8f93\u6570\u636e \u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/usual1009.oss-cn-shanghai.aliyuncs.com\/img\/202511291927136.png\" alt=\"img\"\/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/usual1009.oss-cn-shanghai.aliyuncs.com\/img\/202511291927318.jpeg\" alt=\"img\"\/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">2.1 \u672c\u5730DNS\u7f13\u5b58\u67e5\u8be2<\/h3>\n\n\n\n<p>\u4e3a\u4e86\u63d0\u9ad8\u89e3\u6790\u6548\u7387\u5e76\u51cf\u5c11\u7f51\u7edc\u6d41\u91cf\uff0c\u64cd\u4f5c\u7cfb\u7edf\u548c\u6d4f\u89c8\u5668\u90fd\u4f1a\u5bf9DNS\u67e5\u8be2\u7ed3\u679c\u8fdb\u884c\u7f13\u5b58\u3002\u5f53\u9700\u8981\u89e3\u6790\u4e00\u4e2a\u57df\u540d\u65f6\uff0c\u7cfb\u7edf\u4f1a\u9996\u5148\u68c0\u67e5\u672c\u5730\u7f13\u5b58\uff0c\u5982\u679c\u627e\u5230\u5bf9\u5e94\u7684\u8bb0\u5f55\uff0c\u5219\u76f4\u63a5\u4f7f\u7528\uff0c\u65e0\u9700\u8fdb\u884c\u540e\u7eed\u7684\u7f51\u7edc\u67e5\u8be2\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">2.1.1 \u6d4f\u89c8\u5668\u7f13\u5b58\u68c0\u67e5<\/h4>\n\n\n\n<p>\u73b0\u4ee3\u6d4f\u89c8\u5668\uff08\u5982Chrome, Firefox\uff09\u90fd\u5185\u7f6e\u4e86\u81ea\u5df1\u7684DNS\u7f13\u5b58\u3002\u5f53\u7528\u6237\u5728\u5730\u5740\u680f\u8f93\u5165\u4e00\u4e2aURL\u65f6\uff0c\u6d4f\u89c8\u5668\u4f1a\u9996\u5148\u5728\u81ea\u5df1\u7684\u7f13\u5b58\u4e2d\u67e5\u627e\u8be5\u57df\u540d\u5bf9\u5e94\u7684IP\u5730\u5740\u3002\u8fd9\u4e2a\u7f13\u5b58\u7684\u751f\u547d\u5468\u671f\u901a\u5e38\u8f83\u77ed\uff08\u4f8b\u5982\uff0cChrome\u7684\u7f13\u5b58\u65f6\u95f4\u5927\u7ea6\u4e3a1\u5206\u949f\uff09\uff0c\u5e76\u4e14\u7531\u6d4f\u89c8\u5668\u72ec\u7acb\u7ba1\u7406\u3002\u5982\u679c\u7f13\u5b58\u547d\u4e2d\uff0c\u89e3\u6790\u8fc7\u7a0b\u7acb\u5373\u7ed3\u675f\uff0c\u901f\u5ea6\u975e\u5e38\u5feb\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">2.1.2 \u64cd\u4f5c\u7cfb\u7edf\u7f13\u5b58\u68c0\u67e5<\/h4>\n\n\n\n<p>\u5982\u679c\u6d4f\u89c8\u5668\u7f13\u5b58\u4e2d\u6ca1\u6709\u627e\u5230\u8bb0\u5f55\uff0c\u67e5\u8be2\u8bf7\u6c42\u4f1a\u4f20\u9012\u7ed9\u64cd\u4f5c\u7cfb\u7edf\u3002\u64cd\u4f5c\u7cfb\u7edf\uff08\u5982Windows, Linux\uff09\u4e5f\u7ef4\u62a4\u7740\u4e00\u4e2aDNS\u7f13\u5b58\uff0c\u79f0\u4e3aDNS\u89e3\u6790\u5668\u7f13\u5b58\uff08DNS Resolver Cache\uff09\u3002\u8fd9\u4e2a\u7f13\u5b58\u7684\u751f\u547d\u5468\u671f\u6bd4\u6d4f\u89c8\u5668\u7f13\u5b58\u957f\uff0c\u5e76\u4e14\u53ef\u4ee5\u901a\u8fc7\u547d\u4ee4\u884c\u5de5\u5177\u8fdb\u884c\u7ba1\u7406\uff08\u4f8b\u5982\uff0c\u5728Windows\u4e0a\u4f7f\u7528<code>ipconfig \/flushdns<\/code>\u547d\u4ee4\u53ef\u4ee5\u6e05\u7a7a\u7f13\u5b58\uff09\u3002\u64cd\u4f5c\u7cfb\u7edf\u4f1a\u68c0\u67e5\u81ea\u5df1\u7684\u7f13\u5b58\uff0c\u5982\u679c\u627e\u5230\u8bb0\u5f55\uff0c\u5219\u8fd4\u56de\u7ed9\u6d4f\u89c8\u5668\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">2.1.3 Hosts\u6587\u4ef6\u67e5\u8be2<\/h4>\n\n\n\n<p>\u5982\u679c\u64cd\u4f5c\u7cfb\u7edf\u7f13\u5b58\u4e2d\u4e5f\u6ca1\u6709\u627e\u5230\u8bb0\u5f55\uff0c\u7cfb\u7edf\u4f1a\u68c0\u67e5\u4e00\u4e2a\u540d\u4e3a<code>hosts<\/code>\u7684\u6587\u4ef6\u3002\u8fd9\u4e2a\u6587\u4ef6\u662f\u4e00\u4e2a\u672c\u5730\u7684\u9759\u6001\u6620\u5c04\u6587\u4ef6\uff0c\u5141\u8bb8\u7528\u6237\u624b\u52a8\u5c06\u7279\u5b9a\u7684\u57df\u540d\u6620\u5c04\u5230\u7279\u5b9a\u7684IP\u5730\u5740\u3002\u5728Windows\u7cfb\u7edf\u4e2d\uff0c\u8be5\u6587\u4ef6\u901a\u5e38\u4f4d\u4e8e<code>C:\\Windows\\System32\\drivers\\etc\\hosts<\/code>\uff1b\u5728Linux\u548cmacOS\u7cfb\u7edf\u4e2d\uff0c\u4f4d\u4e8e<code>\/etc\/hosts<\/code>\u3002<code>hosts<\/code>\u6587\u4ef6\u4e2d\u7684\u6761\u76ee\u5177\u6709\u6700\u9ad8\u7684\u4f18\u5148\u7ea7\uff0c\u4f1a\u8986\u76d6\u4efb\u4f55DNS\u670d\u52a1\u5668\u7684\u67e5\u8be2\u7ed3\u679c\u3002\u5728CTF\u4e2d\uff0c<code>hosts<\/code>\u6587\u4ef6\u662f\u4e00\u4e2a\u5e38\u89c1\u7684\u653b\u51fb\u6216\u914d\u7f6e\u70b9\u3002\u4f8b\u5982\uff0c\u653b\u51fb\u8005\u53ef\u80fd\u901a\u8fc7\u4fee\u6539\u53d7\u5bb3\u8005\u7684<code>hosts<\/code>\u6587\u4ef6\uff0c\u5c06\u67d0\u4e2a\u5e38\u7528\u57df\u540d\uff08\u5982\u94f6\u884c\u7f51\u7ad9\uff09\u6307\u5411\u4e00\u4e2a\u6076\u610f\u7684\u9493\u9c7c\u7f51\u7ad9IP\u5730\u5740\uff0c\u4ece\u800c\u5b9e\u73b0DNS\u52ab\u6301\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/usual1009.oss-cn-shanghai.aliyuncs.com\/img\/202511291927536.png\" alt=\"img\"\/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">2.2 \u9012\u5f52\u67e5\u8be2\u4e0e\u8fed\u4ee3\u67e5\u8be2<\/h3>\n\n\n\n<p>\u5982\u679c\u672c\u5730\u6240\u6709\u7f13\u5b58\u548c<code>hosts<\/code>\u6587\u4ef6\u90fd\u65e0\u6cd5\u63d0\u4f9b\u89e3\u6790\u7ed3\u679c\uff0c\u64cd\u4f5c\u7cfb\u7edf\u4f1a\u5c06\u67e5\u8be2\u8bf7\u6c42\u53d1\u9001\u7ed9\u914d\u7f6e\u7684\u672c\u5730DNS\u670d\u52a1\u5668\uff08LDNS\uff09\u3002\u4ece\u8fd9\u4e00\u6b65\u5f00\u59cb\uff0cDNS\u89e3\u6790\u8fc7\u7a0b\u8fdb\u5165\u4e86\u7f51\u7edc\u67e5\u8be2\u9636\u6bb5\uff0c\u4e3b\u8981\u6d89\u53ca\u9012\u5f52\u67e5\u8be2\u548c\u8fed\u4ee3\u67e5\u8be2\u4e24\u79cd\u65b9\u5f0f\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">2.2.1 \u672c\u5730DNS\u670d\u52a1\u5668\uff08LDNS\uff09\u7684\u89d2\u8272<\/h4>\n\n\n\n<p>\u672c\u5730DNS\u670d\u52a1\u5668\uff08Local DNS Server, LDNS\uff09\u901a\u5e38\u7531\u7528\u6237\u7684\u4e92\u8054\u7f51\u670d\u52a1\u63d0\u4f9b\u5546\uff08ISP\uff09\u63d0\u4f9b\uff0c\u6216\u8005\u662f\u5728\u4f01\u4e1a\u7f51\u7edc\u3001\u5bb6\u5ead\u8def\u7531\u5668\u4e2d\u914d\u7f6e\u7684DNS\u670d\u52a1\u5668\uff08\u5982Google\u7684<code>8.8.8.8<\/code>\u6216Cloudflare\u7684<code>1.1.1.1<\/code>\uff09\u3002\u5f53\u64cd\u4f5c\u7cfb\u7edf\u5411LDNS\u53d1\u8d77\u67e5\u8be2\u8bf7\u6c42\u65f6\uff0cLDNS\u4f1a\u4ee3\u8868\u5ba2\u6237\u7aef\u5b8c\u6210\u6574\u4e2a\u89e3\u6790\u8fc7\u7a0b\u3002\u8fd9\u4e2a\u8fc7\u7a0b\u5bf9\u5ba2\u6237\u7aef\u6765\u8bf4\u662f\u201c\u9012\u5f52\u201d\u7684\uff0c\u5373\u5ba2\u6237\u7aef\u53ea\u9700\u8981\u53d1\u9001\u4e00\u4e2a\u8bf7\u6c42\u5e76\u7b49\u5f85\u6700\u7ec8\u7684\u7b54\u6848\uff0c\u800c\u65e0\u9700\u5173\u5fc3\u4e2d\u95f4\u590d\u6742\u7684\u67e5\u8be2\u6b65\u9aa4\u3002LDNS\u4f1a\u9996\u5148\u68c0\u67e5\u81ea\u5df1\u7684\u7f13\u5b58\uff0c\u5982\u679c\u627e\u5230\u8bb0\u5f55\uff0c\u5219\u76f4\u63a5\u8fd4\u56de\u3002\u5982\u679c\u6ca1\u6709\uff0cLDNS\u5c06\u4f5c\u4e3a\u5ba2\u6237\u7aef\u7684\u4ee3\u7406\uff0c\u5f00\u59cb\u4e00\u7cfb\u5217\u7684\u8fed\u4ee3\u67e5\u8be2\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">2.2.2 \u6839\u57df\u540d\u670d\u52a1\u5668\u67e5\u8be2<\/h4>\n\n\n\n<p>\u5982\u679cLDNS\u7684\u7f13\u5b58\u4e2d\u6ca1\u6709\u76ee\u6807\u57df\u540d\u7684\u8bb0\u5f55\uff0c\u5b83\u4f1a\u5411\u4e92\u8054\u7f51\u4e0a\u7684\u6839\u57df\u540d\u670d\u52a1\u5668\uff08Root Name Server\uff09\u53d1\u8d77\u67e5\u8be2\u3002\u5168\u7403\u5171\u670913\u7ec4\u6839\u57df\u540d\u670d\u52a1\u5668\uff0c\u5b83\u4eec\u662f\u6574\u4e2aDNS\u7cfb\u7edf\u7684\u6700\u9ad8\u5c42\u7ea7\uff0c\u8d1f\u8d23\u7ba1\u7406\u6240\u6709\u9876\u7ea7\u57df\u540d\uff08TLD\uff09\u670d\u52a1\u5668\u7684\u4fe1\u606f\u3002LDNS\u5411\u6839\u670d\u52a1\u5668\u67e5\u8be2\u7684\u662f\u76ee\u6807\u57df\u540d\u7684\u9876\u7ea7\u57df\uff08\u5982<code>.com<\/code>, <code>.org<\/code>, <code>.net<\/code>\uff09\u7684\u6743\u5a01\u670d\u52a1\u5668\u5730\u5740\u3002\u6839\u670d\u52a1\u5668\u4e0d\u4f1a\u76f4\u63a5\u8fd4\u56de\u6700\u7ec8\u7684IP\u5730\u5740\uff0c\u800c\u662f\u8fd4\u56de\u4e00\u4e2a\u6307\u5411\u76f8\u5e94\u9876\u7ea7\u57df\uff08TLD\uff09\u670d\u52a1\u5668\u7684\u5217\u8868\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">2.2.3 \u9876\u7ea7\u57df\u540d\uff08TLD\uff09\u670d\u52a1\u5668\u67e5\u8be2<\/h4>\n\n\n\n<p>LDNS\u6536\u5230\u6839\u670d\u52a1\u5668\u8fd4\u56de\u7684TLD\u670d\u52a1\u5668\u5730\u5740\u540e\uff0c\u4f1a\u9009\u62e9\u5176\u4e2d\u4e00\u4e2a\u5e76\u5411\u5176\u53d1\u8d77\u67e5\u8be2\u3002TLD\u670d\u52a1\u5668\u8d1f\u8d23\u7ba1\u7406\u5176\u4e0b\u6240\u6709\u4e8c\u7ea7\u57df\u540d\u7684\u6743\u5a01\u57df\u540d\u670d\u52a1\u5668\u4fe1\u606f\u3002\u4f8b\u5982\uff0c<code>.com<\/code> \u7684TLD\u670d\u52a1\u5668\u4f1a\u77e5\u9053 <a href=\"https:\/\/example.com\" target=\"_blank\"  rel=\"nofollow\" ><code>example.com<\/code><\/a> \u7684\u6743\u5a01\u57df\u540d\u670d\u52a1\u5668\uff08Name Server, NS\uff09\u7684\u5730\u5740\u3002\u540c\u6837\uff0cTLD\u670d\u52a1\u5668\u4e5f\u4e0d\u4f1a\u8fd4\u56de\u6700\u7ec8\u7684IP\u5730\u5740\uff0c\u800c\u662f\u8fd4\u56de\u4e00\u4e2a\u6216\u591a\u4e2a\u6743\u5a01\u57df\u540d\u670d\u52a1\u5668\u7684\u5730\u5740\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">2.2.4 \u6743\u5a01\u57df\u540d\u670d\u52a1\u5668\u67e5\u8be2<\/h4>\n\n\n\n<p>\u6700\u540e\uff0cLDNS\u4f1a\u5411\u6743\u5a01\u57df\u540d\u670d\u52a1\u5668\u53d1\u8d77\u67e5\u8be2\u3002\u6743\u5a01\u57df\u540d\u670d\u52a1\u5668\u662f\u8d1f\u8d23\u5b58\u50a8\u7279\u5b9a\u57df\u540d\uff08\u5982 <a href=\"https:\/\/example.com\" target=\"_blank\"  rel=\"nofollow\" ><code>example.com<\/code><\/a>\uff09\u6240\u6709DNS\u8bb0\u5f55\uff08\u5305\u62ecA\u8bb0\u5f55\u3001MX\u8bb0\u5f55\u3001CNAME\u8bb0\u5f55\u7b49\uff09\u7684\u670d\u52a1\u5668\u3002\u5f53\u6743\u5a01\u57df\u540d\u670d\u52a1\u5668\u6536\u5230LDNS\u7684\u67e5\u8be2\u8bf7\u6c42\u540e\uff0c\u5b83\u4f1a\u67e5\u627e <a href=\"https:\/\/www.example.com\" target=\"_blank\"  rel=\"nofollow\" ><code>www.example.com<\/code><\/a> \u7684A\u8bb0\u5f55\uff08Address Record\uff09\uff0c\u5e76\u5c06\u5bf9\u5e94\u7684IP\u5730\u5740\u8fd4\u56de\u7ed9LDNS\u3002LDNS\u6536\u5230\u8fd9\u4e2aIP\u5730\u5740\u540e\uff0c\u4f1a\u5c06\u5176\u8fd4\u56de\u7ed9\u6700\u521d\u53d1\u8d77\u67e5\u8be2\u7684\u5ba2\u6237\u7aef\u64cd\u4f5c\u7cfb\u7edf\uff0c\u540c\u65f6\uff0cLDNS\u4f1a\u5c06\u8fd9\u4e2a\u7ed3\u679c\u7f13\u5b58\u8d77\u6765\uff0c\u4ee5\u4fbf\u540e\u7eed\u76f8\u540c\u7684\u67e5\u8be2\u53ef\u4ee5\u76f4\u63a5\u4ece\u7f13\u5b58\u4e2d\u83b7\u53d6\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">2.3 DNS\u89e3\u6790\u7ed3\u679c\u7684\u8fd4\u56de\u4e0e\u7f13\u5b58<\/h3>\n\n\n\n<p>\u5f53\u5ba2\u6237\u7aef\u7684\u64cd\u4f5c\u7cfb\u7edf\u4eceLDNS\u6536\u5230\u6700\u7ec8\u7684IP\u5730\u5740\u540e\uff0c\u5b83\u4f1a\u5c06\u8fd9\u4e2a\u7ed3\u679c\u8fd4\u56de\u7ed9\u6d4f\u89c8\u5668\uff0c\u5e76\u540c\u65f6\u5c06\u5176\u5b58\u5165\u81ea\u5df1\u7684DNS\u7f13\u5b58\u4e2d\u3002\u6d4f\u89c8\u5668\u6536\u5230IP\u5730\u5740\u540e\uff0c\u5c31\u53ef\u4ee5\u5f00\u59cb\u5efa\u7acbTCP\u8fde\u63a5\uff0c\u53d1\u8d77HTTP\u8bf7\u6c42\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">2.3.1 IP\u5730\u5740\u7684\u8fd4\u56de<\/h4>\n\n\n\n<p>\u89e3\u6790\u5f97\u5230\u7684IP\u5730\u5740\u662f\u5ba2\u6237\u7aef\u4e0eWeb\u670d\u52a1\u5668\u5efa\u7acb\u8fde\u63a5\u7684\u5173\u952e\u3002\u6d4f\u89c8\u5668\u4f7f\u7528\u8fd9\u4e2aIP\u5730\u5740\u548cURL\u4e2d\u6307\u5b9a\u7684\u7aef\u53e3\u53f7\uff08\u6216\u9ed8\u8ba4\u7aef\u53e380\/443\uff09\u6765\u53d1\u8d77TCP\u4e09\u6b21\u63e1\u624b\u3002\u4e00\u65e6TCP\u8fde\u63a5\u5efa\u7acb\uff0cHTTP\u8bf7\u6c42\u62a5\u6587\u5c31\u4f1a\u88ab\u53d1\u9001\u51fa\u53bb\u3002\u5728CTF\u7684\u6d41\u91cf\u5206\u6790\u4e2d\uff0cDNS\u67e5\u8be2\u548c\u54cd\u5e94\u5305\u662f\u5206\u6790\u7f51\u7edc\u6d3b\u52a8\u7684\u91cd\u8981\u7ebf\u7d22\u3002\u901a\u8fc7\u8fc7\u6ee4DNS\u534f\u8bae\uff08<code>dns<\/code>\uff09\uff0c\u53ef\u4ee5\u67e5\u770b\u6240\u6709\u57df\u540d\u89e3\u6790\u6d3b\u52a8\uff0c\u4e86\u89e3\u76ee\u6807\u4e3b\u673a\u8bbf\u95ee\u4e86\u54ea\u4e9b\u57df\u540d\uff0c\u4ece\u800c\u63a8\u65ad\u5176\u884c\u4e3a \u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">2.3.2 DNS\u8bb0\u5f55\u7684TTL\u4e0e\u7f13\u5b58\u66f4\u65b0<\/h4>\n\n\n\n<p>DNS\u8bb0\u5f55\u4e2d\u6709\u4e00\u4e2a\u91cd\u8981\u7684\u5b57\u6bb5\u53eb\u505aTTL\uff08Time To Live\uff09\uff0c\u5b83\u5b9a\u4e49\u4e86\u8be5\u8bb0\u5f55\u5728\u7f13\u5b58\u4e2d\u6709\u6548\u7684\u65f6\u95f4\uff08\u4ee5\u79d2\u4e3a\u5355\u4f4d\uff09\u3002LDNS\u548c\u64cd\u4f5c\u7cfb\u7edf\u90fd\u4f1a\u6839\u636eTTL\u6765\u51b3\u5b9a\u7f13\u5b58\u8bb0\u5f55\u7684\u4fdd\u7559\u65f6\u95f4\u3002\u5f53TTL\u8fc7\u671f\u540e\uff0c\u7f13\u5b58\u4e2d\u7684\u8bb0\u5f55\u4f1a\u88ab\u89c6\u4e3a\u65e0\u6548\uff0c\u4e0b\u6b21\u67e5\u8be2\u65f6\u9700\u8981\u91cd\u65b0\u8fdb\u884c\u5b8c\u6574\u7684DNS\u89e3\u6790\u6d41\u7a0b\u3002TTL\u7684\u8bbe\u7f6e\u662f\u4e00\u4e2a\u6743\u8861\uff1a\u8f83\u77ed\u7684TTL\u53ef\u4ee5\u4f7fDNS\u8bb0\u5f55\u7684\u66f4\u65b0\u66f4\u5feb\u5730\u4f20\u64ad\u5230\u5168\u7f51\uff0c\u4f46\u4f1a\u589e\u52a0DNS\u670d\u52a1\u5668\u7684\u8d1f\u8f7d\u548c\u67e5\u8be2\u5ef6\u8fdf\uff1b\u8f83\u957f\u7684TTL\u53ef\u4ee5\u51cf\u8f7b\u670d\u52a1\u5668\u8d1f\u8f7d\u5e76\u63d0\u9ad8\u89e3\u6790\u901f\u5ea6\uff0c\u4f46\u5f53\u670d\u52a1\u5668IP\u5730\u5740\u53d8\u66f4\u65f6\uff0c\u66f4\u65b0\u751f\u6548\u7684\u65f6\u95f4\u4f1a\u66f4\u957f\u3002<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">3. HTTP\u8bf7\u6c42\u5934\uff08Headers\uff09\u5728CTF\u4e2d\u7684\u5229\u7528\u4e0e\u5206\u6790<\/h2>\n\n\n\n<p>HTTP\u8bf7\u6c42\u5934\u662fHTTP\u8bf7\u6c42\u62a5\u6587\u7684\u91cd\u8981\u7ec4\u6210\u90e8\u5206\uff0c\u5b83\u643a\u5e26\u4e86\u5173\u4e8e\u5ba2\u6237\u7aef\u3001\u8bf7\u6c42\u548c\u54cd\u5e94\u7684\u5143\u6570\u636e\u3002\u5728CTF\u7ade\u8d5b\u4e2d\uff0cHTTP\u8bf7\u6c42\u5934\u5f80\u5f80\u662fWeb\u6f0f\u6d1e\u5229\u7528\u7684\u5173\u952e\u5207\u5165\u70b9\u3002\u670d\u52a1\u5668\u7aef\u5e94\u7528\u7a0b\u5e8f\u901a\u5e38\u4f1a\u4f9d\u8d56\u8bf7\u6c42\u5934\u4e2d\u7684\u4fe1\u606f\u6765\u8fdb\u884c\u8eab\u4efd\u9a8c\u8bc1\u3001\u8bbf\u95ee\u63a7\u5236\u3001\u4f1a\u8bdd\u7ba1\u7406\u7b49\u529f\u80fd\u3002\u5982\u679c\u670d\u52a1\u5668\u5bf9\u8fd9\u4e9b\u5934\u90e8\u5b57\u6bb5\u7684\u9a8c\u8bc1\u548c\u5904\u7406\u4e0d\u5f53\uff0c\u5c31\u53ef\u80fd\u5bfc\u81f4\u5404\u79cd\u5b89\u5168\u6f0f\u6d1e\u3002\u56e0\u6b64\uff0c\u719f\u7ec3\u638c\u63e1\u5404\u79cdHTTP\u8bf7\u6c42\u5934\u7684\u4f5c\u7528\uff0c\u5e76\u4e86\u89e3\u5b83\u4eec\u5728CTF\u4e2d\u7684\u5e38\u89c1\u5229\u7528\u65b9\u5f0f\uff0c\u5bf9\u4e8e\u89e3\u51b3Web\u7c7b\u9898\u76ee\u81f3\u5173\u91cd\u8981\u3002<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th><em><strong>*\u8bf7\u6c42\u5934 (Header)*<\/strong><\/em><\/th><th><em><strong>*\u4e3b\u8981\u4f5c\u7528*<\/strong><\/em><\/th><th><em><strong>*CTF\u4e2d\u7684\u5e38\u89c1\u5229\u7528\u65b9\u5f0f*<\/strong><\/em><\/th><\/tr><\/thead><tbody><tr><td><em><strong>*Referer*<\/strong><\/em><\/td><td>\u6307\u793a\u8bf7\u6c42\u7684\u6765\u6e90\u9875\u9762URL\u3002<\/td><td><em><strong>*\u4f2a\u9020\u6765\u6e90*<\/strong><\/em>\uff0c\u7ed5\u8fc7\u57fa\u4e8e\u6765\u6e90\u7684CSRF\u9632\u62a4\u6216\u8bbf\u95ee\u63a7\u5236\u3002<\/td><\/tr><tr><td><em><strong>*User-Agent*<\/strong><\/em><\/td><td>\u6807\u8bc6\u5ba2\u6237\u7aef\u8f6f\u4ef6\uff08\u6d4f\u89c8\u5668\u3001\u64cd\u4f5c\u7cfb\u7edf\u7b49\uff09\u3002<\/td><td><em><strong>*\u4f2a\u88c5\u5ba2\u6237\u7aef*<\/strong><\/em>\uff0c\u7ed5\u8fc7\u5bf9\u7279\u5b9a\u6d4f\u89c8\u5668\u3001\u8bbe\u5907\u6216\u722c\u866b\u7684\u9650\u5236\u3002<\/td><\/tr><tr><td><em><strong>*Host*<\/strong><\/em><\/td><td>\u6307\u5b9a\u8bf7\u6c42\u7684\u76ee\u6807\u4e3b\u673a\u540d\u548c\u7aef\u53e3\u53f7\u3002<\/td><td><em><strong>*Host\u5934\u6ce8\u5165*<\/strong><\/em>\uff0c\u7ed5\u8fc7\u8bbf\u95ee\u63a7\u5236\u3001\u7f13\u5b58\u6295\u6bd2\u3001\u5bc6\u7801\u91cd\u7f6e\u4e2d\u6bd2\u3002<\/td><\/tr><tr><td><em><strong>*Content-Type*<\/strong><\/em><\/td><td>\u6307\u793a\u8bf7\u6c42\u4f53\u7684\u5a92\u4f53\u7c7b\u578b\uff08MIME\uff09\u3002<\/td><td><em><strong>*MIME\u7c7b\u578b\u6df7\u6dc6*<\/strong><\/em>\uff0c\u7ed5\u8fc7\u6587\u4ef6\u4e0a\u4f20\u9650\u5236\u3002<\/td><\/tr><tr><td><em><strong>*X-Forwarded-For*<\/strong><\/em><\/td><td>\u6807\u8bc6\u5ba2\u6237\u7aef\u7684\u539f\u59cbIP\u5730\u5740\uff08\u901a\u8fc7\u4ee3\u7406\u65f6\uff09\u3002<\/td><td><em><strong>*\u4f2a\u9020IP\u5730\u5740*<\/strong><\/em>\uff0c\u7ed5\u8fc7\u57fa\u4e8eIP\u7684\u8bbf\u95ee\u63a7\u5236\uff08\u767d\u540d\u5355\/\u9ed1\u540d\u5355\uff09\u3002<\/td><\/tr><tr><td><em><strong>*Cookie*<\/strong><\/em><\/td><td>\u5b58\u50a8\u4f1a\u8bdd\u4fe1\u606f\u3001\u7528\u6237\u504f\u597d\u7b49\u3002<\/td><td><em><strong>*\u4f1a\u8bdd\u52ab\u6301\u3001\u6743\u9650\u63d0\u5347*<\/strong><\/em>\uff0c\u901a\u8fc7\u7be1\u6539Cookie\u4e2d\u7684\u4f1a\u8bddID\u6216\u7528\u6237\u89d2\u8272\u3002<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p><strong>Table 1: \u5e38\u89c1HTTP\u8bf7\u6c42\u5934\u53ca\u5176\u5728CTF\u4e2d\u7684\u5229\u7528<\/strong><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">3.1 Referer\u5934\uff1a\u4f2a\u9020\u6765\u6e90\u4e0e\u7ed5\u8fc7\u9650\u5236<\/h3>\n\n\n\n<p><code>Referer<\/code>\uff08\u6ce8\u610f\u62fc\u5199\u9519\u8bef\uff0c\u4f46\u5df2\u6210\u4e3a\u6807\u51c6\uff09\u8bf7\u6c42\u5934\u5305\u542b\u4e86\u5f53\u524d\u8bf7\u6c42\u9875\u9762\u7684\u6765\u6e90\u9875\u9762\u7684\u5730\u5740\u3002\u5f53\u7528\u6237\u70b9\u51fb\u4e00\u4e2a\u94fe\u63a5\u6216\u63d0\u4ea4\u4e00\u4e2a\u8868\u5355\u65f6\uff0c\u6d4f\u89c8\u5668\u901a\u5e38\u4f1a\u5728\u8bf7\u6c42\u5934\u4e2d\u5e26\u4e0a<code>Referer<\/code>\u4fe1\u606f\uff0c\u544a\u8bc9\u670d\u52a1\u5668\u7528\u6237\u662f\u4ece\u54ea\u4e2a\u9875\u9762\u8df3\u8f6c\u8fc7\u6765\u7684\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">3.1.1 Referer\u5934\u7684\u4f5c\u7528\u4e0e\u683c\u5f0f<\/h4>\n\n\n\n<p><code>Referer<\/code>\u5934\u7684\u4e3b\u8981\u4f5c\u7528\u662f\u7528\u4e8e\u7edf\u8ba1\u5206\u6790\uff08\u4e86\u89e3\u6d41\u91cf\u6765\u6e90\uff09\u3001\u9632\u76d7\u94fe\uff08\u9632\u6b62\u8d44\u6e90\u88ab\u5176\u4ed6\u7f51\u7ad9\u76f4\u63a5\u5f15\u7528\uff09\u4ee5\u53ca\u5b9e\u73b0\u4e00\u4e9b\u5b89\u5168\u673a\u5236\uff0c\u5982CSRF\uff08Cross-Site Request Forgery\uff0c\u8de8\u7ad9\u8bf7\u6c42\u4f2a\u9020\uff09\u9632\u62a4\u3002\u5176\u683c\u5f0f\u662f\u4e00\u4e2a\u5b8c\u6574\u7684URL\uff0c\u4f8b\u5982\uff1a<code>Referer:<\/code><a href=\"https:\/\/www.google.com\/search?q=ctf\" target=\"_blank\"  rel=\"nofollow\" ><code>https:\/\/www.google.com\/search?q=ctf<\/code><\/a>\u3002\u8fd9\u4e2a\u5934\u4fe1\u606f\u8868\u660e\uff0c\u5f53\u524d\u8bf7\u6c42\u662f\u4eceGoogle\u7684\u641c\u7d22\u7ed3\u679c\u9875\u9762\u53d1\u8d77\u7684\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">3.1.2 CTF\u4e2d\u7684\u5229\u7528\u573a\u666f\uff1a\u7ed5\u8fc7CSRF\u9632\u62a4<\/h4>\n\n\n\n<p>\u5728CTF\u4e2d\uff0c<code>Referer<\/code>\u5934\u6700\u5e38\u89c1\u7684\u5229\u7528\u573a\u666f\u662f\u7ed5\u8fc7\u57fa\u4e8e<code>Referer<\/code>\u7684CSRF\u9632\u62a4\u3002\u4e00\u4e9bWeb\u5e94\u7528\u4f1a\u68c0\u67e5\u8bf7\u6c42\u7684<code>Referer<\/code>\u5934\uff0c\u53ea\u6709\u5f53\u8bf7\u6c42\u6765\u6e90\u4e8e\u672c\u7ad9\u7684\u67d0\u4e2a\u9875\u9762\u65f6\uff0c\u624d\u8ba4\u4e3a\u8be5\u8bf7\u6c42\u662f\u5408\u6cd5\u7684\u3002\u653b\u51fb\u8005\u53ef\u4ee5\u901a\u8fc7\u6293\u5305\u5de5\u5177\uff08\u5982Burp Suite\uff09\u6355\u83b7\u81ea\u5df1\u7684\u8bf7\u6c42\uff0c\u7136\u540e\u4fee\u6539<code>Referer<\/code>\u5934\u7684\u503c\uff0c\u5c06\u5176\u4f2a\u9020\u4e3a\u670d\u52a1\u5668\u671f\u671b\u7684\u6765\u6e90\u9875\u9762\uff0c\u4ece\u800c\u7ed5\u8fc7\u8fd9\u79cd\u9632\u62a4\u673a\u5236\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">3.1.3 CTF\u5b9e\u4f8b\uff1a\u901a\u8fc7\u4fee\u6539Referer\u7ed5\u8fc7\u8bbf\u95ee\u63a7\u5236<\/h4>\n\n\n\n<p>\u4e00\u4e2a\u5178\u578b\u7684CTF\u9898\u76ee\u53ef\u80fd\u4f1a\u8bbe\u7f6e\u4e00\u4e2a\u9875\u9762\uff0c\u53ea\u6709\u4ece\u7279\u5b9a\u7684\u201c\u5185\u90e8\u201d\u6216\u201c\u6388\u6743\u201d\u9875\u9762\u8df3\u8f6c\u8fc7\u6765\u624d\u80fd\u8bbf\u95ee\u3002\u4f8b\u5982\uff0c\u4e00\u4e2a\u540d\u4e3a<code>Secret.php<\/code>\u7684\u9875\u9762\u53ef\u80fd\u8981\u6c42\u8bf7\u6c42\u5fc5\u987b\u6765\u81ea<a href=\"https:\/\/www.Sycsecret.com\" target=\"_blank\"  rel=\"nofollow\" ><code>https:\/\/www.Sycsecret.com<\/code><\/a>\u3002\u5f53\u76f4\u63a5\u8bbf\u95ee<code>Secret.php<\/code>\u65f6\uff0c\u670d\u52a1\u5668\u4f1a\u8fd4\u56de\u9519\u8bef\u4fe1\u606f\u3002\u6b64\u65f6\uff0c\u89e3\u9898\u8005\u9700\u8981\u4f7f\u7528Burp Suite\u7b49\u5de5\u5177\u62e6\u622aHTTP\u8bf7\u6c42\uff0c\u5e76\u5728\u8bf7\u6c42\u5934\u4e2d\u6dfb\u52a0\u6216\u4fee\u6539<code>Referer<\/code>\u5b57\u6bb5\uff1a<code>Referer:<\/code><a href=\"https:\/\/www.Sycsecret.com\" target=\"_blank\"  rel=\"nofollow\" ><code>https:\/\/www.Sycsecret.com<\/code><\/a>\u3002\u901a\u8fc7\u4f2a\u9020\u6765\u6e90\uff0c\u670d\u52a1\u5668\u4f1a\u8ba4\u4e3a\u8bf7\u6c42\u662f\u5408\u6cd5\u7684\uff0c\u4ece\u800c\u8fd4\u56de\u5305\u542bFlag\u7684\u9875\u9762\u5185\u5bb9\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">3.2 User-Agent\u5934\uff1a\u4f2a\u88c5\u5ba2\u6237\u7aef\u4e0e\u7ed5\u8fc7\u68c0\u6d4b<\/h3>\n\n\n\n<p><code>User-Agent<\/code>\u8bf7\u6c42\u5934\u662f\u4e00\u4e2a\u7279\u5f81\u5b57\u7b26\u4e32\uff0c\u5b83\u8ba9\u670d\u52a1\u5668\u80fd\u591f\u8bc6\u522b\u53d1\u8d77\u8bf7\u6c42\u7684\u5ba2\u6237\u7aef\u7684\u8f6f\u4ef6\u7c7b\u578b\u3001\u64cd\u4f5c\u7cfb\u7edf\u3001\u6d4f\u89c8\u5668\u7248\u672c\u3001\u6e32\u67d3\u5f15\u64ce\u7b49\u4fe1\u606f\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">3.2.1 User-Agent\u5934\u7684\u4f5c\u7528\u4e0e\u683c\u5f0f<\/h4>\n\n\n\n<p><code>User-Agent<\/code>\u5934\u7684\u683c\u5f0f\u901a\u5e38\u5f88\u590d\u6742\uff0c\u5305\u542b\u4e86\u5927\u91cf\u7684\u4fe1\u606f\u3002\u4f8b\u5982\uff0c\u4e00\u4e2a\u5178\u578b\u7684Chrome\u6d4f\u89c8\u5668\u7684<code>User-Agent<\/code>\u5b57\u7b26\u4e32\u5982\u4e0b\uff1a<code>User-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/91.0.4472.124 Safari\/537.36<\/code>\u3002\u670d\u52a1\u5668\u53ef\u4ee5\u6839\u636e<code>User-Agent<\/code>\u5934\u6765\u8fd4\u56de\u9488\u5bf9\u4e0d\u540c\u6d4f\u89c8\u5668\u6216\u8bbe\u5907\u4f18\u5316\u7684\u9875\u9762\u5185\u5bb9\uff0c\u6216\u8005\u62d2\u7edd\u4e3a\u67d0\u4e9b\u8fc7\u65f6\u7684\u6216\u4e0d\u652f\u6301\u7684\u6d4f\u89c8\u5668\u63d0\u4f9b\u670d\u52a1\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">3.2.2 CTF\u4e2d\u7684\u5229\u7528\u573a\u666f\uff1a\u7ed5\u8fc7\u8bbe\u5907\u6216\u6d4f\u89c8\u5668\u9650\u5236<\/h4>\n\n\n\n<p>\u5728CTF\u4e2d\uff0c\u670d\u52a1\u5668\u53ef\u80fd\u4f1a\u68c0\u67e5<code>User-Agent<\/code>\u5934\uff0c\u5e76\u53ea\u5141\u8bb8\u7279\u5b9a\u7684\u201c\u6d4f\u89c8\u5668\u201d\u6216\u201c\u8bbe\u5907\u201d\u8bbf\u95ee\u3002\u4f8b\u5982\uff0c\u9898\u76ee\u53ef\u80fd\u63d0\u793a\u201c\u5fc5\u987b\u4f7f\u7528Syclover\u6d4f\u89c8\u5668\u624d\u80fd\u67e5\u770b\u6b64\u9875\u9762\u201d\u3002\u7531\u4e8e\u201cSyclover\u6d4f\u89c8\u5668\u201d\u53ef\u80fd\u662f\u4e00\u4e2a\u865a\u6784\u7684\u6216\u975e\u5e38\u5c0f\u4f17\u7684\u6d4f\u89c8\u5668\uff0c\u5176<code>User-Agent<\/code>\u5b57\u7b26\u4e32\u662f\u5df2\u77e5\u7684\u3002\u89e3\u9898\u8005\u53ea\u9700\u5728\u8bf7\u6c42\u5934\u4e2d\u5c06<code>User-Agent<\/code>\u7684\u503c\u4fee\u6539\u4e3a\u8be5\u7279\u5b9a\u6d4f\u89c8\u5668\u7684\u5b57\u7b26\u4e32\u5373\u53ef\u7ed5\u8fc7\u9650\u5236\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">3.2.3 CTF\u5b9e\u4f8b\uff1a\u4f2a\u88c5\u6210\u7279\u5b9a\u6d4f\u89c8\u5668\u6216\u722c\u866b<\/h4>\n\n\n\n<p>\u53e6\u4e00\u4e2a\u5e38\u89c1\u7684\u573a\u666f\u662f\uff0c\u670d\u52a1\u5668\u53ea\u5141\u8bb8\u641c\u7d22\u5f15\u64ce\u7684\u722c\u866b\uff08\u5982Googlebot\uff09\u8bbf\u95ee\u67d0\u4e9b\u654f\u611f\u9875\u9762\u3002\u89e3\u9898\u8005\u53ef\u4ee5\u901a\u8fc7\u5c06<code>User-Agent<\/code>\u8bbe\u7f6e\u4e3a\u641c\u7d22\u5f15\u64ce\u722c\u866b\u7684\u5b57\u7b26\u4e32\u6765\u4f2a\u88c5\u81ea\u5df1\uff0c\u4f8b\u5982\uff1a<code>User-Agent: Mozilla\/5.0 (compatible; Googlebot\/2.1; +<\/code><a href=\"http:\/\/www.google.com\/bot.html\" target=\"_blank\"  rel=\"nofollow\" ><code>http:\/\/www.google.com\/bot.html)<\/code><\/a>)\u3002\u901a\u8fc7\u8fd9\u79cd\u65b9\u5f0f\uff0c\u53ef\u4ee5\u6b3a\u9a97\u670d\u52a1\u5668\uff0c\u4f7f\u5176\u8ba4\u4e3a\u8bf7\u6c42\u6765\u81ea\u5408\u6cd5\u7684\u641c\u7d22\u5f15\u64ce\u722c\u866b\uff0c\u4ece\u800c\u6388\u4e88\u8bbf\u95ee\u6743\u9650\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">3.3 Host\u5934\uff1aHost\u5934\u6ce8\u5165\u653b\u51fb<\/h3>\n\n\n\n<p><code>Host<\/code>\u8bf7\u6c42\u5934\u6307\u660e\u4e86\u8bf7\u6c42\u5c06\u8981\u53d1\u9001\u5230\u7684\u670d\u52a1\u5668\u7684\u4e3b\u673a\u540d\u548c\u7aef\u53e3\u53f7\u3002\u5b83\u662fHTTP\/1.1\u534f\u8bae\u4e2d\u4e00\u4e2a\u5fc5\u9700\u7684\u8bf7\u6c42\u5934\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">3.3.1 Host\u5934\u7684\u4f5c\u7528\u4e0e\u683c\u5f0f<\/h4>\n\n\n\n<p><code>Host<\/code>\u5934\u7684\u683c\u5f0f\u901a\u5e38\u662f<code>Host: &lt;domain&gt;:&lt;port&gt;<\/code>\u3002\u4f8b\u5982\uff1a<code>Host:<\/code><a href=\"https:\/\/www.example.com:8080\" target=\"_blank\"  rel=\"nofollow\" ><code>www.example.com:8080<\/code><\/a>\u3002\u5728\u865a\u62df\u4e3b\u673a\uff08Virtual Hosting\uff09\u73af\u5883\u4e2d\uff0c\u4e00\u53f0\u7269\u7406\u670d\u52a1\u5668\u53ef\u80fd\u6258\u7ba1\u4e86\u591a\u4e2a\u57df\u540d\u4e0d\u540c\u7684\u7f51\u7ad9\u3002\u670d\u52a1\u5668\u901a\u8fc7\u68c0\u67e5\u8bf7\u6c42\u5934\u4e2d\u7684<code>Host<\/code>\u5b57\u6bb5\u6765\u5224\u65ad\u5ba2\u6237\u7aef\u8bf7\u6c42\u7684\u662f\u54ea\u4e2a\u7f51\u7ad9\uff0c\u5e76\u5c06\u8bf7\u6c42\u8def\u7531\u5230\u6b63\u786e\u7684Web\u5e94\u7528\u7a0b\u5e8f\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">3.3.2 CTF\u4e2d\u7684\u5229\u7528\u573a\u666f\uff1a\u7ed5\u8fc7\u8bbf\u95ee\u63a7\u5236\u4e0e\u7f13\u5b58\u6295\u6bd2<\/h4>\n\n\n\n<p><code>Host<\/code>\u5934\u7684\u5b89\u5168\u95ee\u9898\u4e3b\u8981\u6e90\u4e8e\u670d\u52a1\u5668\u7aef\u5bf9\u5176\u503c\u7684\u4e0d\u5f53\u5904\u7406\u3002\u5982\u679cWeb\u5e94\u7528\u7a0b\u5e8f\u76f4\u63a5\u4f7f\u7528<code>Host<\/code>\u5934\u7684\u503c\u6765\u6784\u5efaURL\u3001\u8fdb\u884c\u91cd\u5b9a\u5411\u6216\u751f\u6210\u90ae\u4ef6\u5185\u5bb9\uff0c\u800c\u6ca1\u6709\u8fdb\u884c\u5145\u5206\u7684\u9a8c\u8bc1\uff0c\u5c31\u53ef\u80fd\u5bfc\u81f4<em><strong>*Host\u5934\u6ce8\u5165*<\/strong><\/em>\u6f0f\u6d1e\u3002\u653b\u51fb\u8005\u53ef\u4ee5\u901a\u8fc7\u4fee\u6539<code>Host<\/code>\u5934\u7684\u503c\uff0c\u6765\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><em><strong>*\u7ed5\u8fc7\u8bbf\u95ee\u63a7\u5236*<\/strong><\/em>\uff1a\u5982\u679c\u670d\u52a1\u5668\u6839\u636e<code>Host<\/code>\u5934\u6765\u5224\u65ad\u8bf7\u6c42\u662f\u5426\u6765\u81ea\u5185\u90e8\u7f51\u7edc\uff0c\u653b\u51fb\u8005\u53ef\u4ee5\u4f2a\u9020<code>Host<\/code>\u5934\u6765\u8bbf\u95ee\u5185\u7f51\u8d44\u6e90\u3002<\/li>\n\n\n\n<li><em><strong>*\u7f13\u5b58\u6295\u6bd2*<\/strong><\/em>\uff1a\u653b\u51fb\u8005\u53ef\u4ee5\u53d1\u9001\u4e00\u4e2a\u5e26\u6709\u6076\u610f<code>Host<\/code>\u5934\u7684\u8bf7\u6c42\uff0c\u5982\u679c\u7f13\u5b58\u670d\u52a1\u5668\uff08\u5982CDN\uff09\u6ca1\u6709\u6b63\u786e\u9a8c\u8bc1<code>Host<\/code>\u5934\uff0c\u53ef\u80fd\u4f1a\u5c06\u8fd9\u4e2a\u6076\u610f\u54cd\u5e94\u7f13\u5b58\u8d77\u6765\uff0c\u5e76\u8fd4\u56de\u7ed9\u540e\u7eed\u8bbf\u95ee\u8be5\u57df\u540d\u7684\u6240\u6709\u7528\u6237\u3002<\/li>\n\n\n\n<li><em><strong>*\u5bc6\u7801\u91cd\u7f6e\u4e2d\u6bd2*<\/strong><\/em>\uff1a\u5728\u5bc6\u7801\u91cd\u7f6e\u529f\u80fd\u4e2d\uff0c\u5982\u679c\u91cd\u7f6e\u94fe\u63a5\u7684\u751f\u6210\u4f9d\u8d56\u4e8e<code>Host<\/code>\u5934\uff0c\u653b\u51fb\u8005\u53ef\u4ee5\u4fee\u6539<code>Host<\/code>\u5934\uff0c\u5c06\u91cd\u7f6e\u94fe\u63a5\u6307\u5411\u81ea\u5df1\u63a7\u5236\u7684\u670d\u52a1\u5668\uff0c\u4ece\u800c\u7a83\u53d6\u7528\u6237\u7684\u5bc6\u7801\u91cd\u7f6e\u4ee4\u724c\u3002<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">3.3.3 CTF\u5b9e\u4f8b\uff1a\u901a\u8fc7Host\u5934\u6ce8\u5165\u8bbf\u95ee\u5185\u7f51\u8d44\u6e90<\/h4>\n\n\n\n<p>\u5047\u8bbe\u4e00\u4e2aWeb\u5e94\u7528\u90e8\u7f72\u5728\u5185\u7f51\uff0c\u5e76\u901a\u8fc7\u53cd\u5411\u4ee3\u7406\u5bf9\u5916\u63d0\u4f9b\u670d\u52a1\u3002\u53cd\u5411\u4ee3\u7406\u4f1a\u6839\u636e<code>Host<\/code>\u5934\u5c06\u8bf7\u6c42\u8f6c\u53d1\u5230\u5185\u7f51\u7684\u4e0d\u540c\u670d\u52a1\u5668\u3002\u5982\u679c\u53cd\u5411\u4ee3\u7406\u7684\u914d\u7f6e\u5b58\u5728\u7f3a\u9677\uff0c\u653b\u51fb\u8005\u53ef\u4ee5\u901a\u8fc7\u4fee\u6539<code>Host<\/code>\u5934\u4e3a\u5185\u7f51\u670d\u52a1\u5668\u7684\u5730\u5740\uff08\u5982<code>Host: 192.168.1.100<\/code>\uff09\uff0c\u4ece\u800c\u7ed5\u8fc7\u4ee3\u7406\u7684\u8bbf\u95ee\u63a7\u5236\uff0c\u76f4\u63a5\u4e0e\u5185\u7f51\u670d\u52a1\u5668\u8fdb\u884c\u901a\u4fe1\uff0c\u83b7\u53d6\u654f\u611f\u4fe1\u606f\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">3.4 Content-Type\u5934\uff1aMIME\u7c7b\u578b\u6df7\u6dc6\u4e0e\u6587\u4ef6\u4e0a\u4f20\u6f0f\u6d1e<\/h3>\n\n\n\n<p><code>Content-Type<\/code>\u5b9e\u4f53\u5934\uff08\u5728\u8bf7\u6c42\u4e2d\uff09\u7528\u4e8e\u6307\u793a\u53d1\u9001\u7ed9\u670d\u52a1\u5668\u7684\u5b9e\u4f53\u4e3b\u4f53\u7684\u5a92\u4f53\u7c7b\u578b\uff08MIME\u7c7b\u578b\uff09\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">3.4.1 Content-Type\u5934\u7684\u4f5c\u7528\u4e0e\u683c\u5f0f<\/h4>\n\n\n\n<p><code>Content-Type<\/code>\u5934\u7684\u683c\u5f0f\u662f<code>type\/subtype<\/code>\uff0c\u540e\u9762\u53ef\u4ee5\u8ddf\u4e00\u4e9b\u53ef\u9009\u7684\u53c2\u6570\uff0c\u5982\u5b57\u7b26\u96c6\u3002\u4f8b\u5982\uff1a<code>Content-Type: application\/x-www-form-urlencoded; charset=UTF-8<\/code>\u3002\u5728POST\u8bf7\u6c42\u4e2d\uff0c<code>Content-Type<\/code>\u5934\u544a\u8bc9\u670d\u52a1\u5668\u8bf7\u6c42\u4f53\u4e2d\u7684\u6570\u636e\u662f\u4ec0\u4e48\u683c\u5f0f\uff0c\u4ee5\u4fbf\u670d\u52a1\u5668\u80fd\u591f\u6b63\u786e\u5730\u89e3\u6790\u3002\u5e38\u89c1\u7684\u7c7b\u578b\u6709\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><code>application\/x-www-form-urlencoded<\/code>\uff1a\u7528\u4e8e\u63d0\u4ea4HTML\u8868\u5355\u6570\u636e\uff0c\u6570\u636e\u88ab\u7f16\u7801\u4e3a\u952e\u503c\u5bf9\u3002<\/li>\n\n\n\n<li><code>multipart\/form-data<\/code>\uff1a\u7528\u4e8e\u4e0a\u4f20\u6587\u4ef6\u6216\u5305\u542b\u4e8c\u8fdb\u5236\u6570\u636e\u7684\u8868\u5355\u3002<\/li>\n\n\n\n<li><code>application\/json<\/code>\uff1a\u7528\u4e8e\u63d0\u4ea4JSON\u683c\u5f0f\u7684\u6570\u636e\u3002<\/li>\n\n\n\n<li><code>text\/plain<\/code>\uff1a\u7eaf\u6587\u672c\u3002<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">3.4.2 CTF\u4e2d\u7684\u5229\u7528\u573a\u666f\uff1a\u7ed5\u8fc7\u6587\u4ef6\u4e0a\u4f20\u9650\u5236<\/h4>\n\n\n\n<p>\u6587\u4ef6\u4e0a\u4f20\u529f\u80fd\u662fWeb\u5e94\u7528\u4e2d\u5e38\u89c1\u7684\u6f0f\u6d1e\u70b9\u3002\u670d\u52a1\u5668\u901a\u5e38\u4f1a\u901a\u8fc7\u68c0\u67e5\u4e0a\u4f20\u6587\u4ef6\u7684\u6269\u5c55\u540d\u548c<code>Content-Type<\/code>\u5934\u6765\u9650\u5236\u4e0a\u4f20\u6587\u4ef6\u7684\u7c7b\u578b\u3002\u5982\u679c\u670d\u52a1\u5668\u5bf9<code>Content-Type<\/code>\u7684\u9a8c\u8bc1\u8fc7\u4e8e\u7b80\u5355\uff08\u4f8b\u5982\uff0c\u53ea\u68c0\u67e5\u662f\u5426\u5305\u542b<code>image\/<\/code>\uff09\uff0c\u653b\u51fb\u8005\u5c31\u53ef\u4ee5\u901a\u8fc7\u4fee\u6539<code>Content-Type<\/code>\u5934\u6765\u7ed5\u8fc7\u9650\u5236\u3002\u4f8b\u5982\uff0c\u5c06\u4e00\u4e2aPHP webshell\u7684<code>Content-Type<\/code>\u4ece<code>application\/x-httpd-php<\/code>\u4fee\u6539\u4e3a<code>image\/jpeg<\/code>\uff0c\u5982\u679c\u670d\u52a1\u5668\u53ea\u9a8c\u8bc1<code>Content-Type<\/code>\u800c\u5ffd\u7565\u6587\u4ef6\u5185\u5bb9\uff0c\u5c31\u53ef\u80fd\u5141\u8bb8\u4e0a\u4f20\uff0c\u4ece\u800c\u5bfc\u81f4\u8fdc\u7a0b\u4ee3\u7801\u6267\u884c\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">3.4.3 CTF\u5b9e\u4f8b\uff1a\u901a\u8fc7\u4fee\u6539Content-Type\u4e0a\u4f20\u6076\u610f\u6587\u4ef6<\/h4>\n\n\n\n<p>\u5728\u4e00\u4e2a\u5178\u578b\u7684\u6587\u4ef6\u4e0a\u4f20CTF\u9898\u76ee\u4e2d\uff0c\u670d\u52a1\u5668\u53ea\u5141\u8bb8\u4e0a\u4f20\u56fe\u7247\u6587\u4ef6\uff0c\u5e76\u68c0\u67e5\u4e86\u6587\u4ef6\u6269\u5c55\u540d\uff08\u5982<code>.jpg<\/code>, <code>.png<\/code>\uff09\u548c<code>Content-Type<\/code>\u5934\uff08\u5982<code>image\/jpeg<\/code>\uff09\u3002\u653b\u51fb\u8005\u53ef\u4ee5\u521b\u5efa\u4e00\u4e2a\u540d\u4e3a<code>shell.php.jpg<\/code>\u7684\u6587\u4ef6\uff0c\u5176\u5185\u5bb9\u4e3aPHP\u4ee3\u7801\uff0c\u4f46\u5728HTTP\u8bf7\u6c42\u4e2d\uff0c\u5c06<code>Content-Type<\/code>\u5934\u8bbe\u7f6e\u4e3a<code>image\/jpeg<\/code>\u3002\u5982\u679c\u670d\u52a1\u5668\u7684\u9a8c\u8bc1\u903b\u8f91\u5b58\u5728\u7f3a\u9677\uff0c\u4f8b\u5982\u53ea\u68c0\u67e5\u4e86<code>Content-Type<\/code>\u5934\u800c\u6ca1\u6709\u5bf9\u6587\u4ef6\u5185\u5bb9\u8fdb\u884c\u6df1\u5ea6\u68c0\u6d4b\uff08\u5982\u4f7f\u7528<code>file<\/code>\u547d\u4ee4\u6216\u68c0\u67e5\u6587\u4ef6\u5934\u9b54\u672f\u6570\uff09\uff0c\u90a3\u4e48\u8fd9\u4e2a\u6076\u610f\u7684PHP\u6587\u4ef6\u5c31\u53ef\u80fd\u88ab\u6210\u529f\u4e0a\u4f20\u3002\u4e4b\u540e\uff0c\u653b\u51fb\u8005\u901a\u8fc7\u8bbf\u95ee<code>shell.php.jpg<\/code>\uff0c\u5c31\u53ef\u4ee5\u6267\u884c\u5176\u4e2d\u7684PHP\u4ee3\u7801\uff0c\u4ece\u800c\u83b7\u53d6\u670d\u52a1\u5668\u6743\u9650\u5e76\u8bfb\u53d6flag\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">3.5 X-Forwarded-For\u5934\uff1a\u4f2a\u9020IP\u5730\u5740\u4e0e\u7ed5\u8fc7\u9650\u5236<\/h3>\n\n\n\n<p><code>X-Forwarded-For<\/code>\uff08XFF\uff09\u662f\u4e00\u4e2a\u4e8b\u5b9e\u4e0a\u7684\u6807\u51c6HTTP\u5934\uff0c\u7528\u4e8e\u8bc6\u522b\u901a\u8fc7HTTP\u4ee3\u7406\u6216\u8d1f\u8f7d\u5747\u8861\u5668\u8fde\u63a5\u5230Web\u670d\u52a1\u5668\u7684\u5ba2\u6237\u7aef\u7684\u539f\u59cbIP\u5730\u5740\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">3.5.1 X-Forwarded-For\u5934\u7684\u4f5c\u7528\u4e0e\u683c\u5f0f<\/h4>\n\n\n\n<p><code>X-Forwarded-For<\/code>\u5934\u7684\u4e3b\u8981\u4f5c\u7528\u662f\u5728\u5ba2\u6237\u7aef\u548c\u670d\u52a1\u5668\u4e4b\u95f4\u5b58\u5728\u4ee3\u7406\u6216\u8d1f\u8f7d\u5747\u8861\u5668\u65f6\uff0c\u5e2e\u52a9\u670d\u52a1\u5668\u83b7\u53d6\u5ba2\u6237\u7aef\u7684\u771f\u5b9eIP\u5730\u5740\u3002\u5f53\u4e00\u4e2a\u8bf7\u6c42\u7ecf\u8fc7\u591a\u4e2a\u4ee3\u7406\u65f6\uff0c\u6bcf\u4e2a\u4ee3\u7406\u90fd\u4f1a\u5c06\u5176\u770b\u5230\u7684\u5ba2\u6237\u7aefIP\u5730\u5740\u8ffd\u52a0\u5230<code>X-Forwarded-For<\/code>\u5934\u7684\u672b\u5c3e\uff0c\u5f62\u6210\u4e00\u4e2a\u9017\u53f7\u5206\u9694\u7684IP\u5730\u5740\u5217\u8868\u3002\u4f8b\u5982\uff0c<code>X-Forwarded-For: client, proxy1, proxy2<\/code>\u3002\u6700\u5de6\u8fb9\u7684IP\u5730\u5740\u901a\u5e38\u88ab\u8ba4\u4e3a\u662f\u539f\u59cb\u5ba2\u6237\u7aef\u7684IP\u3002\u7136\u800c\uff0c\u7531\u4e8e\u8fd9\u4e2a\u5934\u662f\u7531\u5ba2\u6237\u7aef\u6216\u4ee3\u7406\u6dfb\u52a0\u7684\uff0c\u56e0\u6b64\u5b83\u5e76\u4e0d\u53ef\u4fe1\uff0c\u53ef\u4ee5\u88ab\u4f2a\u9020\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">3.5.2 CTF\u4e2d\u7684\u5229\u7528\u573a\u666f\uff1a\u7ed5\u8fc7IP\u767d\u540d\u5355\/\u9ed1\u540d\u5355<\/h4>\n\n\n\n<p>\u8bb8\u591aWeb\u5e94\u7528\u4f1a\u4f7f\u7528IP\u5730\u5740\u4f5c\u4e3a\u8bbf\u95ee\u63a7\u5236\u7684\u624b\u6bb5\uff0c\u4f8b\u5982\uff0c\u53ea\u5141\u8bb8\u6765\u81ea\u7279\u5b9aIP\u5730\u5740\uff08\u767d\u540d\u5355\uff09\u7684\u7ba1\u7406\u5458\u8bbf\u95ee\uff0c\u6216\u8005\u963b\u6b62\u6765\u81ea\u5df2\u77e5\u6076\u610fIP\u5730\u5740\uff08\u9ed1\u540d\u5355\uff09\u7684\u8bbf\u95ee\u3002\u5982\u679c\u670d\u52a1\u5668\u76f4\u63a5\u4fe1\u4efb<code>X-Forwarded-For<\/code>\u5934\u4e2d\u7684IP\u5730\u5740\u6765\u5224\u65ad\u5ba2\u6237\u7aef\u7684\u771f\u5b9eIP\uff0c\u653b\u51fb\u8005\u5c31\u53ef\u4ee5\u901a\u8fc7\u4f2a\u9020<code>X-Forwarded-For<\/code>\u5934\u6765\u7ed5\u8fc7\u8fd9\u4e9b\u9650\u5236\u3002\u4f8b\u5982\uff0c\u5982\u679c\u670d\u52a1\u5668\u53ea\u5141\u8bb8<code>127.0.0.1<\/code>\uff08\u672c\u5730\u4e3b\u673a\uff09\u8bbf\u95ee\u7ba1\u7406\u9875\u9762\uff0c\u653b\u51fb\u8005\u53ef\u4ee5\u5728\u8bf7\u6c42\u4e2d\u6dfb\u52a0<code>X-Forwarded-For: 127.0.0.1<\/code>\uff0c\u4ece\u800c\u4f2a\u88c5\u6210\u672c\u5730\u8bf7\u6c42\uff0c\u7ed5\u8fc7IP\u767d\u540d\u5355\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">3.5.3 CTF\u5b9e\u4f8b\uff1a\u901a\u8fc7\u4f2a\u9020XFF\u5934\u7ed5\u8fc7IP\u8bbf\u95ee\u9650\u5236<\/h4>\n\n\n\n<p>\u5728\u4e00\u4e2aCTF\u9898\u76ee\u4e2d\uff0c\u4e00\u4e2a\u7ba1\u7406\u540e\u53f0\u88ab\u914d\u7f6e\u4e3a\u53ea\u5141\u8bb8\u4ece\u672c\u5730IP\uff08<code>127.0.0.1<\/code>\uff09\u8bbf\u95ee\u3002\u670d\u52a1\u5668\u90e8\u7f72\u5728\u53cd\u5411\u4ee3\u7406\u4e4b\u540e\uff0c\u5e76\u4e14\u9519\u8bef\u5730\u914d\u7f6e\u4e86\u4ece<code>X-Forwarded-For<\/code>\u5934\u4e2d\u83b7\u53d6\u5ba2\u6237\u7aefIP\u3002\u653b\u51fb\u8005\u53ef\u4ee5\u4ece\u5916\u90e8\u7f51\u7edc\u76f4\u63a5\u8bbf\u95ee\u8be5\u540e\u53f0\uff0c\u53ea\u9700\u5728HTTP\u8bf7\u6c42\u5934\u4e2d\u6dfb\u52a0<code>X-Forwarded-For: 127.0.0.1<\/code>\u3002\u670d\u52a1\u5668\u63a5\u6536\u5230\u8bf7\u6c42\u540e\uff0c\u4f1a\u68c0\u67e5<code>X-Forwarded-For<\/code>\u5934\uff0c\u53d1\u73b0\u5176\u503c\u4e3a<code>127.0.0.1<\/code>\uff0c\u4fbf\u8bef\u8ba4\u4e3a\u8bf7\u6c42\u6765\u81ea\u672c\u5730\uff0c\u4ece\u800c\u6388\u4e88\u8bbf\u95ee\u6743\u9650\u3002\u8fd9\u79cd\u653b\u51fb\u7684\u6210\u529f\u4f9d\u8d56\u4e8e\u670d\u52a1\u5668\u5bf9<code>X-Forwarded-For<\/code>\u5934\u7684\u76f2\u76ee\u4fe1\u4efb\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">3.6 Cookie\u5934\uff1a\u4f1a\u8bdd\u7ba1\u7406\u4e0e\u6743\u9650\u63d0\u5347<\/h3>\n\n\n\n<p><code>Cookie<\/code>\u662f\u670d\u52a1\u5668\u53d1\u9001\u5230\u7528\u6237\u6d4f\u89c8\u5668\u5e76\u4fdd\u5b58\u5728\u672c\u5730\u7684\u4e00\u5c0f\u5757\u6570\u636e\u3002\u6d4f\u89c8\u5668\u4f1a\u5728\u540e\u7eed\u5bf9\u540c\u4e00\u670d\u52a1\u5668\u7684\u8bf7\u6c42\u4e2d\u81ea\u52a8\u643a\u5e26\u8fd9\u4e9bCookie\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">3.6.1 Cookie\u5934\u7684\u4f5c\u7528\u4e0e\u683c\u5f0f<\/h4>\n\n\n\n<p><code>Cookie<\/code>\u4e3b\u8981\u7528\u4e8e\u4f1a\u8bdd\u7ba1\u7406\uff08\u5982\u4fdd\u5b58\u767b\u5f55\u72b6\u6001\uff09\u3001\u4e2a\u6027\u5316\u8bbe\u7f6e\uff08\u5982\u7528\u6237\u504f\u597d\uff09\u548c\u8ddf\u8e2a\u7528\u6237\u884c\u4e3a\u3002\u4e00\u4e2aCookie\u901a\u5e38\u5305\u542b\u540d\u79f0\u3001\u503c\u3001\u57df\u3001\u8def\u5f84\u3001\u8fc7\u671f\u65f6\u95f4\u7b49\u5c5e\u6027\u3002\u7531\u4e8eHTTP\u534f\u8bae\u662f\u65e0\u72b6\u6001\u7684\uff0cCookie\u4e3a\u670d\u52a1\u5668\u63d0\u4f9b\u4e86\u4e00\u79cd\u5728\u591a\u4e2a\u8bf7\u6c42\u4e4b\u95f4\u7ef4\u62a4\u72b6\u6001\uff08\u5982\u7528\u6237\u8eab\u4efd\uff09\u7684\u673a\u5236\u3002\u5728CTF\u4e2d\uff0cCookie\u662f\u653b\u51fb\u7684\u91cd\u70b9\u76ee\u6807\uff0c\u56e0\u4e3a\u5b83\u7ecf\u5e38\u5305\u542b\u654f\u611f\u4fe1\u606f\uff0c\u5982\u4f1a\u8bddID\uff08Session ID\uff09\u3001\u7528\u6237\u89d2\u8272\u3001\u6743\u9650\u6807\u5fd7\u7b49\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">3.6.2 CTF\u4e2d\u7684\u5229\u7528\u573a\u666f\uff1aCookie\u7be1\u6539\u4e0e\u4f2a\u9020<\/h4>\n\n\n\n<p>\u7531\u4e8eCookie\u5b58\u50a8\u5728\u5ba2\u6237\u7aef\uff0c\u7528\u6237\u53ef\u4ee5\u81ea\u7531\u5730\u67e5\u770b\u548c\u4fee\u6539\u5176\u5185\u5bb9\u3002\u5982\u679c\u670d\u52a1\u5668\u6ca1\u6709\u5bf9\u8fd9\u4e9bCookie\u8fdb\u884c\u6709\u6548\u7684\u4fdd\u62a4\uff08\u5982\u52a0\u5bc6\u548c\u7b7e\u540d\uff09\uff0c\u653b\u51fb\u8005\u5c31\u53ef\u4ee5\u901a\u8fc7\u7be1\u6539Cookie\u6765\u5b9e\u65bd\u653b\u51fb\u3002\u5e38\u89c1\u7684\u5229\u7528\u573a\u666f\u5305\u62ec\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><em><strong>*\u6743\u9650\u63d0\u5347*<\/strong><\/em>\uff1a\u5982\u679c\u670d\u52a1\u5668\u5c06\u7528\u6237\u7684\u89d2\u8272\u6216\u6743\u9650\u4fe1\u606f\u76f4\u63a5\u5b58\u50a8\u5728Cookie\u4e2d\uff08\u4f8b\u5982\uff0c<code>role=user<\/code>\uff09\uff0c\u653b\u51fb\u8005\u53ef\u4ee5\u5c06\u5176\u4fee\u6539\u4e3a<code>role=admin<\/code>\uff0c\u4ece\u800c\u63d0\u5347\u81ea\u5df1\u7684\u6743\u9650\uff0c\u8bbf\u95ee\u7ba1\u7406\u529f\u80fd \u3002<\/li>\n\n\n\n<li><em><strong>*\u4f1a\u8bdd\u52ab\u6301*<\/strong><\/em>\uff1a\u5982\u679c\u4f1a\u8bddID\uff08Session ID\uff09\u662f\u53ef\u9884\u6d4b\u7684\u6216\u672a\u7ecf\u52a0\u5bc6\u4fdd\u62a4\u7684\uff0c\u653b\u51fb\u8005\u53ef\u4ee5\u731c\u6d4b\u6216\u4f2a\u9020\u4e00\u4e2a\u6709\u6548\u7684Session ID\uff0c\u4ece\u800c\u5192\u5145\u5176\u4ed6\u7528\u6237\u767b\u5f55\u3002<\/li>\n\n\n\n<li><em><strong>*\u7ed5\u8fc7\u8ba4\u8bc1*<\/strong><\/em>\uff1a\u6709\u4e9b\u5e94\u7528\u53ef\u80fd\u7b80\u5355\u5730\u68c0\u67e5Cookie\u4e2d\u662f\u5426\u5b58\u5728\u67d0\u4e2a\u6807\u5fd7\u4f4d\uff08\u4f8b\u5982\uff0c<code>login=1<\/code>\uff09\uff0c\u653b\u51fb\u8005\u53ea\u9700\u624b\u52a8\u6dfb\u52a0\u8fd9\u4e2aCookie\uff0c\u5c31\u53ef\u4ee5\u7ed5\u8fc7\u767b\u5f55\u9a8c\u8bc1 \u3002<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">3.6.3 CTF\u5b9e\u4f8b\uff1a\u901a\u8fc7\u4fee\u6539Cookie\u4e2d\u7684\u7528\u6237\u8eab\u4efd\u6807\u8bc6\u83b7\u53d6\u66f4\u9ad8\u6743\u9650<\/h4>\n\n\n\n<p>\u5728\u4e00\u4e2apicoCTF\u7684\u201cPower Cookie\u201d\u6311\u6218\u4e2d\uff0c\u9875\u9762\u63d0\u4f9b\u4e86\u4e00\u4e2a\u201cContinue as guest\u201d\u6309\u94ae\u3002\u70b9\u51fb\u540e\uff0c\u670d\u52a1\u5668\u8bbe\u7f6e\u4e86\u4e00\u4e2a\u540d\u4e3a<code>isAdmin<\/code>\u7684Cookie\uff0c\u5176\u503c\u4e3a<code>0<\/code> \u3002\u5f53\u8bf7\u6c42\u88ab\u53d1\u9001\u5230<code>\/check.php<\/code>\u65f6\uff0c\u670d\u52a1\u5668\u68c0\u67e5\u5230\u8fd9\u4e2aCookie\uff0c\u5e76\u8fd4\u56de\u201c\u6ca1\u6709\u8bbf\u5ba2\u670d\u52a1\u201d\u7684\u6d88\u606f\u3002\u653b\u51fb\u8005\u901a\u8fc7Burp Suite\u62e6\u622a\u8bf7\u6c42\uff0c\u53d1\u73b0<code>isAdmin=0<\/code>\u7684Cookie\uff0c\u5e76\u5c06\u5176\u503c\u4fee\u6539\u4e3a<code>1<\/code>\u540e\u91cd\u65b0\u53d1\u9001\u3002\u670d\u52a1\u5668\u63a5\u6536\u5230\u4fee\u6539\u540e\u7684Cookie\uff0c\u8ba4\u4e3a\u7528\u6237\u662f\u7ba1\u7406\u5458\uff0c\u4ece\u800c\u8fd4\u56de\u4e86flag\u3002\u8fd9\u4e2a\u7b80\u5355\u7684\u4f8b\u5b50\u6e05\u6670\u5730\u5c55\u793a\u4e86Cookie\u7be1\u6539\u5728\u6743\u9650\u63d0\u5347\u653b\u51fb\u4e2d\u7684\u5a01\u529b\u3002<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">4. HTTP\u72b6\u6001\u7801\u5728CTF\u4e2d\u7684\u7279\u6b8a\u5229\u7528\u4ef7\u503c<\/h2>\n\n\n\n<p>HTTP\u72b6\u6001\u7801\u662f\u670d\u52a1\u5668\u5bf9\u5ba2\u6237\u7aef\u8bf7\u6c42\u7684\u54cd\u5e94\uff0c\u5b83\u662f\u4e00\u4e2a\u4e09\u4f4d\u6570\u7684\u4ee3\u7801\uff0c\u8868\u793a\u8bf7\u6c42\u5904\u7406\u7684\u7ed3\u679c\u3002\u5728CTF\u4e2d\uff0c\u9664\u4e86\u5e38\u89c1\u7684200\uff08\u6210\u529f\uff09\u3001404\uff08\u672a\u627e\u5230\uff09\u7b49\u72b6\u6001\u7801\uff0c\u4e00\u4e9b\u7279\u5b9a\u7684\u72b6\u6001\u7801\u4e5f\u8574\u542b\u7740\u653b\u51fb\u673a\u4f1a\u3002<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th><em><strong>*\u72b6\u6001\u7801\u7cfb\u5217*<\/strong><\/em><\/th><th><em><strong>*\u72b6\u6001\u7801*<\/strong><\/em><\/th><th><em><strong>*\u542b\u4e49*<\/strong><\/em><\/th><th><em><strong>*CTF\u4e2d\u7684\u5229\u7528\u4ef7\u503c*<\/strong><\/em><\/th><\/tr><\/thead><tbody><tr><td><em><strong>*3xx \u91cd\u5b9a\u5411*<\/strong><\/em><\/td><td><em><strong>*301\/302*<\/strong><\/em><\/td><td>\u8d44\u6e90\u5df2\u6c38\u4e45\/\u4e34\u65f6\u79fb\u52a8\u3002<\/td><td><em><strong>*\u5f00\u653e\u91cd\u5b9a\u5411\u6f0f\u6d1e*<\/strong><\/em>\uff0c\u7ed5\u8fc7URL\u9ed1\u540d\u5355\uff0c\u914d\u5408\u5176\u4ed6\u6f0f\u6d1e\u6269\u5927\u653b\u51fb\u9762\u3002<\/td><\/tr><tr><td><em><strong>*4xx \u5ba2\u6237\u7aef\u9519\u8bef*<\/strong><\/em><\/td><td><em><strong>*401*<\/strong><\/em><\/td><td>\u672a\u6388\u6743\uff0c\u9700\u8981\u8ba4\u8bc1\u3002<\/td><td><em><strong>*\u8ba4\u8bc1\u7ed5\u8fc7*<\/strong><\/em>\uff0c\u5c1d\u8bd5\u5f31\u5bc6\u7801\u3001\u4f2a\u9020Session\/Cookie\u3002<\/td><\/tr><tr><td><\/td><td><em><strong>*403*<\/strong><\/em><\/td><td>\u7981\u6b62\u8bbf\u95ee\uff0c\u6743\u9650\u4e0d\u8db3\u3002<\/td><td><em><strong>*\u6743\u9650\u63d0\u5347*<\/strong><\/em>\uff0c\u5c1d\u8bd5\u4e0d\u540cHTTP\u65b9\u6cd5\u3001\u8def\u5f84\u6df7\u6dc6\u3001\u4f2a\u9020\u8bf7\u6c42\u5934\u3002<\/td><\/tr><tr><td><em><strong>*5xx \u670d\u52a1\u5668\u9519\u8bef*<\/strong><\/em><\/td><td><em><strong>*503*<\/strong><\/em><\/td><td>\u670d\u52a1\u4e0d\u53ef\u7528\u3002<\/td><td><em><strong>*\u4fe1\u606f\u6cc4\u9732*<\/strong><\/em>\uff0c\u9519\u8bef\u9875\u9762\u53ef\u80fd\u5305\u542b\u5806\u6808\u8ddf\u8e2a\u3001\u5185\u90e8\u8def\u5f84\u7b49\u654f\u611f\u4fe1\u606f\u3002<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p><strong>Table 2: CTF\u4e2d\u5177\u6709\u7279\u6b8a\u5229\u7528\u4ef7\u503c\u7684HTTP\u72b6\u6001\u7801<\/strong><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">4.1 3xx\u91cd\u5b9a\u5411\u72b6\u6001\u7801<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">4.1.1 301\/302\u72b6\u6001\u7801\u7684\u542b\u4e49\u4e0e\u533a\u522b<\/h4>\n\n\n\n<p>3xx\u7cfb\u5217\u72b6\u6001\u7801\u8868\u793a\u5ba2\u6237\u7aef\u9700\u8981\u6267\u884c\u67d0\u4e9b\u989d\u5916\u7684\u64cd\u4f5c\u624d\u80fd\u5b8c\u6210\u8bf7\u6c42\uff0c\u6700\u5e38\u89c1\u7684\u5c31\u662f\u91cd\u5b9a\u5411\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><em><strong>*301 Moved Permanently*<\/strong><\/em>\uff1a\u8868\u793a\u8bf7\u6c42\u7684\u8d44\u6e90\u5df2\u88ab\u6c38\u4e45\u79fb\u52a8\u5230\u65b0\u7684URL\u3002\u6d4f\u89c8\u5668\u5728\u6536\u5230301\u54cd\u5e94\u540e\uff0c\u4f1a\u81ea\u52a8\u5411\u65b0\u7684URL\u53d1\u8d77\u8bf7\u6c42\uff0c\u5e76\u4e14\u901a\u5e38\u4f1a\u7f13\u5b58\u8fd9\u4e2a\u91cd\u5b9a\u5411\u3002<\/li>\n\n\n\n<li><em><strong>*302 Found*<\/strong><\/em>\uff08\u6216\u65e9\u671fHTTP\/1.0\u4e2d\u7684<code>Moved Temporarily<\/code>\uff09\uff1a\u8868\u793a\u8bf7\u6c42\u7684\u8d44\u6e90\u4e34\u65f6\u4f4d\u4e8e\u65b0\u7684URL\u3002\u6d4f\u89c8\u5668\u540c\u6837\u4f1a\u81ea\u52a8\u8df3\u8f6c\uff0c\u4f46\u901a\u5e38\u4e0d\u4f1a\u7f13\u5b58\u8fd9\u4e2a\u91cd\u5b9a\u5411\u3002<\/li>\n<\/ul>\n\n\n\n<p>\u5728CTF\u4e2d\uff0c\u8fd9\u4e24\u79cd\u72b6\u6001\u7801\u90fd\u53ef\u80fd\u88ab\u5229\u7528\uff0c\u4f46302\u66f4\u4e3a\u5e38\u89c1\uff0c\u56e0\u4e3a\u5b83\u8868\u793a\u4e00\u4e2a\u4e34\u65f6\u7684\u3001\u53ef\u53d8\u7684\u91cd\u5b9a\u5411\uff0c\u66f4\u5bb9\u6613\u88ab\u653b\u51fb\u8005\u64cd\u63a7\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">4.1.2 CTF\u4e2d\u7684\u5229\u7528\u573a\u666f\uff1a\u5f00\u653e\u91cd\u5b9a\u5411\u6f0f\u6d1e<\/h4>\n\n\n\n<p>\u5f00\u653e\u91cd\u5b9a\u5411\uff08Open Redirect\uff09\u6f0f\u6d1e\u662f\u6307Web\u5e94\u7528\u63a5\u53d7\u7528\u6237\u53ef\u63a7\u7684\u8f93\u5165\u4f5c\u4e3a\u91cd\u5b9a\u5411\u7684\u76ee\u6807URL\uff0c\u5e76\u4e14\u6ca1\u6709\u5bf9\u5176\u8fdb\u884c\u5145\u5206\u7684\u9a8c\u8bc1\uff0c\u5bfc\u81f4\u653b\u51fb\u8005\u53ef\u4ee5\u5c06\u7528\u6237\u91cd\u5b9a\u5411\u5230\u4efb\u610f\u7f51\u7ad9\u3002\u8fd9\u79cd\u6f0f\u6d1e\u901a\u5e38\u51fa\u73b0\u5728\u767b\u5f55\u3001\u9000\u51fa\u3001\u8df3\u8f6c\u7b49\u529f\u80fd\u4e2d\u3002\u4f8b\u5982\uff0c\u4e00\u4e2a\u767b\u5f55URL\u53ef\u80fd\u5f62\u5982<a href=\"https:\/\/example.com\/login?redirect=\/dashboard\" target=\"_blank\"  rel=\"nofollow\" ><code>https:\/\/example.com\/login?redirect=\/dashboard<\/code><\/a>\uff0c\u7528\u6237\u5728\u767b\u5f55\u6210\u529f\u540e\u4f1a\u8df3\u8f6c\u5230<code>redirect<\/code>\u53c2\u6570\u6307\u5b9a\u7684\u9875\u9762\u3002\u5982\u679c\u670d\u52a1\u5668\u76f4\u63a5\u5c06<code>redirect<\/code>\u53c2\u6570\u7684\u503c\u62fc\u63a5\u5230<code>Location<\/code>\u54cd\u5e94\u5934\u4e2d\uff0c\u653b\u51fb\u8005\u5c31\u53ef\u4ee5\u6784\u9020\u4e00\u4e2a\u6076\u610f\u94fe\u63a5\uff0c\u5982<a href=\"https:\/\/example.com\/login?redirect=https:\/\/evil.com\" target=\"_blank\"  rel=\"nofollow\" ><code>https:\/\/example.com\/login?redirect=https:\/\/evil.com<\/code><\/a>\uff0c\u5f53\u7528\u6237\u70b9\u51fb\u8fd9\u4e2a\u94fe\u63a5\u5e76\u6210\u529f\u767b\u5f55\u540e\uff0c\u5c31\u4f1a\u88ab\u91cd\u5b9a\u5411\u5230\u653b\u51fb\u8005\u7684\u9493\u9c7c\u7f51\u7ad9 \u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">4.1.3 CTF\u5b9e\u4f8b\uff1a\u5229\u7528\u91cd\u5b9a\u5411\u7ed5\u8fc7\u8bbf\u95ee\u63a7\u5236<\/h4>\n\n\n\n<p>\u5728CTF\u4e2d\uff0c\u5f00\u653e\u91cd\u5b9a\u5411\u6f0f\u6d1e\u7684\u5371\u5bb3\u8fdc\u4e0d\u6b62\u4e8e\u9493\u9c7c\u3002\u5b83\u53ef\u4ee5\u88ab\u7528\u6765\uff1a<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><em><strong>*\u7ed5\u8fc7URL\u9ed1\u540d\u5355*<\/strong><\/em>\uff1a\u5982\u679c\u67d0\u4e2a\u529f\u80fd\uff08\u5982SSRF\u9632\u62a4\uff09\u7981\u6b62\u8bbf\u95ee\u5185\u7f51IP\uff0c\u4f46\u5141\u8bb8\u901a\u8fc7\u91cd\u5b9a\u5411\u8df3\u8f6c\uff0c\u653b\u51fb\u8005\u53ef\u4ee5\u5148\u8bf7\u6c42\u4e00\u4e2a\u5141\u8bb8\u7684\u5916\u90e8URL\uff0c\u7136\u540e\u8ba9\u8be5URL\u8fd4\u56de\u4e00\u4e2a302\u91cd\u5b9a\u5411\u5230\u5185\u7f51IP\uff0c\u4ece\u800c\u7ed5\u8fc7\u9ed1\u540d\u5355\u3002<\/li>\n\n\n\n<li><em><strong>*\u914d\u5408\u5176\u4ed6\u6f0f\u6d1e*<\/strong><\/em>\uff1a\u5f00\u653e\u91cd\u5b9a\u5411\u53ef\u4ee5\u4e0eXSS\u3001CSRF\u7b49\u6f0f\u6d1e\u7ed3\u5408\uff0c\u6269\u5927\u653b\u51fb\u9762\u3002\u4f8b\u5982\uff0c\u4e00\u4e2aDOM-based\u7684\u91cd\u5b9a\u5411\u6f0f\u6d1e\u53ef\u4ee5\u88ab\u5347\u7ea7\u4e3aXSS\u6f0f\u6d1e \u3002<\/li>\n\n\n\n<li><em><strong>*\u7a83\u53d6OAuth Token*<\/strong><\/em>\uff1a\u5728OAuth\u6388\u6743\u6d41\u7a0b\u4e2d\uff0c\u5982\u679c<code>redirect_uri<\/code>\u53c2\u6570\u53ef\u4ee5\u88ab\u7be1\u6539\uff0c\u653b\u51fb\u8005\u53ef\u4ee5\u5c06\u6388\u6743\u7801\u6216Token\u91cd\u5b9a\u5411\u5230\u81ea\u5df1\u7684\u670d\u52a1\u5668\uff0c\u4ece\u800c\u52ab\u6301\u7528\u6237\u8d26\u6237\u3002<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">4.2 4xx\u5ba2\u6237\u7aef\u9519\u8bef\u72b6\u6001\u7801<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">4.2.1 401\/403\u72b6\u6001\u7801\u7684\u542b\u4e49\u4e0e\u533a\u522b<\/h4>\n\n\n\n<p>4xx\u7cfb\u5217\u72b6\u6001\u7801\u8868\u793a\u5ba2\u6237\u7aef\u7684\u8bf7\u6c42\u6709\u8bed\u6cd5\u9519\u8bef\u6216\u8bf7\u6c42\u65e0\u6cd5\u5b9e\u73b0\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><em><strong>*401 Unauthorized*<\/strong><\/em>\uff1a\u8868\u793a\u8bf7\u6c42\u9700\u8981\u7528\u6237\u8ba4\u8bc1\u3002\u670d\u52a1\u5668\u901a\u5e38\u4f1a\u5728\u54cd\u5e94\u4e2d\u5305\u542b\u4e00\u4e2a<code>WWW-Authenticate<\/code>\u5934\uff0c\u6307\u660e\u8ba4\u8bc1\u65b9\u5f0f\uff08\u5982Basic, Bearer\u7b49\uff09\u3002\u8fd9\u4e2a\u72b6\u6001\u7801\u610f\u5473\u7740\u7528\u6237\u5c1a\u672a\u63d0\u4f9b\u6709\u6548\u7684\u8ba4\u8bc1\u51ed\u636e\uff0c\u6216\u8005\u63d0\u4f9b\u7684\u51ed\u636e\u662f\u9519\u8bef\u7684\u3002<\/li>\n\n\n\n<li><em><strong>*403 Forbidden*<\/strong><\/em>\uff1a\u8868\u793a\u670d\u52a1\u5668\u7406\u89e3\u4e86\u5ba2\u6237\u7aef\u7684\u8bf7\u6c42\uff0c\u4f46\u662f\u62d2\u7edd\u6267\u884c\u6b64\u8bf7\u6c42\u3002\u8fd9\u901a\u5e38\u610f\u5473\u7740\u7528\u6237\u5df2\u7ecf\u901a\u8fc7\u4e86\u8ba4\u8bc1\uff0c\u4f46\u6ca1\u6709\u8db3\u591f\u7684\u6743\u9650\u8bbf\u95ee\u6240\u8bf7\u6c42\u7684\u8d44\u6e90\u3002\u4e0e401\u4e0d\u540c\uff0c403\u8868\u793a\u670d\u52a1\u5668\u77e5\u9053\u7528\u6237\u662f\u8c01\uff0c\u4f46\u660e\u786e\u62d2\u7edd\u5176\u8bbf\u95ee\u3002<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">4.2.2 CTF\u4e2d\u7684\u5229\u7528\u573a\u666f\uff1a\u8ba4\u8bc1\u7ed5\u8fc7\u4e0e\u6743\u9650\u63d0\u5347<\/h4>\n\n\n\n<p>\u5f53\u9047\u5230401\u6216403\u9519\u8bef\u65f6\uff0c\u653b\u51fb\u8005\u53ef\u4ee5\u5c1d\u8bd5\u4ee5\u4e0b\u65b9\u6cd5\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><em><strong>*\u7ed5\u8fc7\u8ba4\u8bc1\uff08\u9488\u5bf9401\uff09*<\/strong><\/em> \uff1a\n<ul class=\"wp-block-list\">\n<li><em><strong>*\u5f31\u5bc6\u7801\/\u9ed8\u8ba4\u51ed\u636e*<\/strong><\/em>\uff1a\u5c1d\u8bd5\u4f7f\u7528\u5e38\u89c1\u7684\u5f31\u5bc6\u7801\u6216\u5e94\u7528\u7684\u9ed8\u8ba4\u7ba1\u7406\u5458\u51ed\u636e\u3002<\/li>\n\n\n\n<li><em><strong>*\u8ba4\u8bc1\u903b\u8f91\u6f0f\u6d1e*<\/strong><\/em>\uff1a\u68c0\u67e5\u8ba4\u8bc1\u8fc7\u7a0b\u662f\u5426\u5b58\u5728\u903b\u8f91\u7f3a\u9677\uff0c\u4f8b\u5982\uff0c\u662f\u5426\u53ef\u4ee5\u901a\u8fc7\u4fee\u6539\u54cd\u5e94\u5305\u6765\u6b3a\u9a97\u5ba2\u6237\u7aef\u8ba4\u4e3a\u8ba4\u8bc1\u6210\u529f\u3002<\/li>\n\n\n\n<li><em><strong>*Session\/Cookie\u4f2a\u9020*<\/strong><\/em>\uff1a\u5206\u6790Session ID\u6216Cookie\u7684\u751f\u6210\u7b97\u6cd5\uff0c\u5c1d\u8bd5\u4f2a\u9020\u4e00\u4e2a\u6709\u6548\u7684\u4f1a\u8bdd\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><em><strong>*\u7ed5\u8fc7\u6388\u6743\uff08\u9488\u5bf9403\uff09*<\/strong><\/em> \uff1a\n<ul class=\"wp-block-list\">\n<li><em><strong>*HTTP\u65b9\u6cd5\u7ed5\u8fc7*<\/strong><\/em>\uff1a\u5c1d\u8bd5\u4f7f\u7528\u4e0d\u540c\u7684HTTP\u65b9\u6cd5\uff08\u5982<code>GET<\/code>, <code>POST<\/code>, <code>PUT<\/code>, <code>DELETE<\/code>, <code>HEAD<\/code>, <code>PATCH<\/code>\u7b49\uff09\u8bbf\u95ee\u540c\u4e00\u8d44\u6e90\u3002\u6709\u65f6\u670d\u52a1\u5668\u53ef\u80fd\u53ea\u5bf9\u7279\u5b9a\u65b9\u6cd5\u8fdb\u884c\u4e86\u6743\u9650\u63a7\u5236\u3002<\/li>\n\n\n\n<li><em><strong>*\u8def\u5f84\u6df7\u6dc6*<\/strong><\/em>\uff1a\u5c1d\u8bd5\u5728URL\u8def\u5f84\u4e2d\u6dfb\u52a0<code>\/<\/code>\u3001<code>\/.\/<\/code>\u3001<code>\/..\/<\/code>\u3001 <code>%2e%2e%2f<\/code>\uff08URL\u7f16\u7801\u7684<code>..\/<\/code>\uff09\u7b49\u7279\u6b8a\u5b57\u7b26\uff0c\u53ef\u80fd\u4f1a\u7ed5\u8fc7\u57fa\u4e8e\u8def\u5f84\u7684\u8bbf\u95ee\u63a7\u5236\u3002<\/li>\n\n\n\n<li><em><strong>*\u8bf7\u6c42\u5934\u7ed5\u8fc7*<\/strong><\/em>\uff1a\u4fee\u6539\u6216\u6dfb\u52a0\u7279\u5b9a\u7684\u8bf7\u6c42\u5934\uff0c\u5982<code>X-Original-URL<\/code>, <code>X-Rewrite-URL<\/code>, <code>Referer<\/code>, <code>Host<\/code>\u7b49\uff0c\u6709\u65f6\u53ef\u4ee5\u6b3a\u9a97\u670d\u52a1\u5668\uff0c\u4f7f\u5176\u8ba4\u4e3a\u8bf7\u6c42\u6765\u81ea\u5185\u90e8\u6216\u5177\u6709\u66f4\u9ad8\u6743\u9650\u3002<\/li>\n\n\n\n<li><em><strong>*IP\u4f2a\u9020*<\/strong><\/em>\uff1a\u5982\u679c403\u662f\u57fa\u4e8eIP\u5730\u5740\u7684\uff0c\u53ef\u4ee5\u5c1d\u8bd5\u4f2a\u9020<code>X-Forwarded-For<\/code>\u6216<code>X-Real-IP<\/code>\u5934\u6765\u7ed5\u8fc7\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">4.2.3 CTF\u5b9e\u4f8b\uff1a\u901a\u8fc7\u4fee\u6539\u8bf7\u6c42\u5934\u7ed5\u8fc7401\/403\u9650\u5236<\/h4>\n\n\n\n<p>\u5728\u4e00\u4e2aCTF\u6311\u6218\u4e2d\uff0c\u8bbf\u95ee<code>\/admin<\/code>\u8def\u5f84\u8fd4\u56de403 Forbidden\u3002\u653b\u51fb\u8005\u5c1d\u8bd5\u4e86\u591a\u79cd\u65b9\u6cd5\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u5c06\u8bf7\u6c42\u65b9\u6cd5\u4ece<code>GET<\/code>\u6539\u4e3a<code>POST<\/code>\uff0c\u4ecd\u7136\u8fd4\u56de403\u3002<\/li>\n\n\n\n<li>\u5c1d\u8bd5\u8bbf\u95ee<code>\/admin\/<\/code>\uff0c<code>\/admin\/.<\/code>\uff0c<code>\/admin\/\/<\/code>\u7b49\uff0c\u5747\u5931\u8d25\u3002<\/li>\n\n\n\n<li>\u5728\u8bf7\u6c42\u5934\u4e2d\u6dfb\u52a0<code>X-Original-URL: \/admin<\/code>\uff0c\u5e76\u5c06\u8bf7\u6c42\u884c\u4e2d\u7684\u8def\u5f84\u6539\u4e3a<code>\/<\/code>\uff0c\u7ed3\u679c\u6210\u529f\u8bbf\u95ee\u5230\u4e86\u7ba1\u7406\u9875\u9762\u3002\u8fd9\u8868\u660e\u670d\u52a1\u5668\u7684\u6743\u9650\u63a7\u5236\u903b\u8f91\u662f\u57fa\u4e8e\u8bf7\u6c42\u884c\u4e2d\u7684\u8def\u5f84\uff0c\u800c\u5ffd\u7565\u4e86<code>X-Original-URL<\/code>\u5934\uff0c\u4ece\u800c\u88ab\u6210\u529f\u7ed5\u8fc7\u3002<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">4.3 5xx\u670d\u52a1\u5668\u9519\u8bef\u72b6\u6001\u7801<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">4.3.1 503\u72b6\u6001\u7801\u7684\u542b\u4e49<\/h4>\n\n\n\n<p>5xx\u7cfb\u5217\u72b6\u6001\u7801\u8868\u793a\u670d\u52a1\u5668\u5728\u5904\u7406\u8bf7\u6c42\u7684\u8fc7\u7a0b\u4e2d\u53d1\u751f\u4e86\u9519\u8bef\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><em><strong>*503 Service Unavailable*<\/strong><\/em>\uff1a\u8868\u793a\u670d\u52a1\u5668\u5f53\u524d\u4e0d\u80fd\u5904\u7406\u5ba2\u6237\u7aef\u7684\u8bf7\u6c42\uff0c\u4e00\u6bb5\u65f6\u95f4\u540e\u53ef\u80fd\u6062\u590d\u6b63\u5e38\u3002\u8fd9\u901a\u5e38\u662f\u7531\u4e8e\u670d\u52a1\u5668\u8fc7\u8f7d\u3001\u505c\u673a\u7ef4\u62a4\u6216\u67d0\u4e9b\u4f9d\u8d56\u670d\u52a1\uff08\u5982\u6570\u636e\u5e93\uff09\u4e0d\u53ef\u7528\u5bfc\u81f4\u7684\u3002\u670d\u52a1\u5668\u53ef\u4ee5\u9009\u62e9\u5728\u54cd\u5e94\u4e2d\u5305\u542b\u4e00\u4e2a<code>Retry-After<\/code>\u5934\uff0c\u544a\u77e5\u5ba2\u6237\u7aef\u4f55\u65f6\u53ef\u4ee5\u91cd\u8bd5\u3002<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">4.3.2 CTF\u4e2d\u7684\u5229\u7528\u573a\u666f\uff1a\u4fe1\u606f\u6cc4\u9732\u4e0e\u62d2\u7edd\u670d\u52a1<\/h4>\n\n\n\n<p>\u5728CTF\u4e2d\uff0c503\u9519\u8bef\u867d\u7136\u4e0d\u76f4\u63a5\u63d0\u4f9bflag\uff0c\u4f46\u5b83\u53ef\u80fd\u6cc4\u9732\u6709\u4ef7\u503c\u7684\u4fe1\u606f\u6216\u6210\u4e3a\u653b\u51fb\u7684\u5207\u5165\u70b9\u3002<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><em><strong>*\u4fe1\u606f\u6cc4\u9732*<\/strong><\/em>\uff1a\u5f53\u670d\u52a1\u5668\u8fd4\u56de503\u9519\u8bef\u65f6\uff0c\u5176\u54cd\u5e94\u4f53\u4e2d\u53ef\u80fd\u5305\u542b\u5806\u6808\u8ddf\u8e2a\u3001\u670d\u52a1\u5668\u8f6f\u4ef6\u7248\u672c\u3001\u5185\u90e8\u6587\u4ef6\u8def\u5f84\u7b49\u654f\u611f\u4fe1\u606f\u3002\u8fd9\u4e9b\u4fe1\u606f\u5bf9\u4e8e\u540e\u7eed\u7684\u6f0f\u6d1e\u5229\u7528\u975e\u5e38\u6709\u5e2e\u52a9\u3002<\/li>\n\n\n\n<li><em><strong>*\u89e6\u53d1\u7279\u5b9a\u903b\u8f91*<\/strong><\/em>\uff1a\u5728\u67d0\u4e9b\u590d\u6742\u7684\u4e1a\u52a1\u903b\u8f91\u4e2d\uff0c\u89e6\u53d1503\u9519\u8bef\u53ef\u80fd\u662f\u8fbe\u6210\u67d0\u79cd\u72b6\u6001\u7684\u5173\u952e\u6b65\u9aa4\u3002\u4f8b\u5982\uff0c\u4e00\u4e2a\u591a\u6b65\u9aa4\u7684\u652f\u4ed8\u6d41\u7a0b\uff0c\u5982\u679c\u5728\u67d0\u4e00\u6b65\u9aa4\u4e2d\u6545\u610f\u8ba9\u4f9d\u8d56\u670d\u52a1\u8d85\u65f6\uff0c\u53ef\u80fd\u4f1a\u8fdb\u5165\u4e00\u4e2a\u7279\u6b8a\u7684\u9519\u8bef\u5904\u7406\u5206\u652f\uff0c\u800c\u8fd9\u4e2a\u5206\u652f\u4e2d\u53ef\u80fd\u5b58\u5728\u6f0f\u6d1e\u3002<\/li>\n\n\n\n<li><em><strong>*\u62d2\u7edd\u670d\u52a1\uff08DoS\uff09*<\/strong><\/em> \uff1a\u5982\u679c\u670d\u52a1\u5668\u5728\u5904\u7406\u7279\u5b9a\u8bf7\u6c42\u65f6\u5bb9\u6613\u8fd4\u56de503\uff0c\u653b\u51fb\u8005\u53ef\u4ee5\u901a\u8fc7\u53d1\u9001\u5927\u91cf\u6b64\u7c7b\u8bf7\u6c42\u6765\u8017\u5c3d\u670d\u52a1\u5668\u8d44\u6e90\uff0c\u4f7f\u5176\u5bf9\u6240\u6709\u7528\u6237\u90fd\u8fd4\u56de503\uff0c\u4ece\u800c\u5b9e\u73b0\u62d2\u7edd\u670d\u52a1\u653b\u51fb\u3002<\/li>\n<\/ol>\n\n\n\n<h4 class=\"wp-block-heading\">4.3.3 CTF\u5b9e\u4f8b\uff1a\u901a\u8fc7\u89e6\u53d1503\u9519\u8bef\u83b7\u53d6\u670d\u52a1\u5668\u654f\u611f\u4fe1\u606f<\/h4>\n\n\n\n<p><\/p>\n\n\n\n<p>\u5728\u4e00\u4e2aCTF\u6311\u6218\u4e2d\uff0c\u4e00\u4e2aAPI\u7aef\u70b9\u5728\u5904\u7406\u5f02\u5e38\u5927\u7684\u8f93\u5165\u65f6\u4f1a\u8fd4\u56de503 Service Unavailable\u3002\u653b\u51fb\u8005\u901a\u8fc7\u53d1\u9001\u4e00\u4e2a\u8d85\u957f\u7684\u5b57\u7b26\u4e32\u4f5c\u4e3a\u53c2\u6570\uff0c\u6210\u529f\u89e6\u53d1\u4e86503\u9519\u8bef\u3002\u5728\u670d\u52a1\u5668\u8fd4\u56de\u7684\u9519\u8bef\u9875\u9762\u4e2d\uff0c\u5305\u542b\u4e86\u5b8c\u6574\u7684Python\u5806\u6808\u8ddf\u8e2a\u4fe1\u606f\u3002\u901a\u8fc7\u5206\u6790\u5806\u6808\u8ddf\u8e2a\uff0c\u653b\u51fb\u8005\u53d1\u73b0\u4e86\u670d\u52a1\u5668\u5185\u90e8\u4f7f\u7528\u7684\u5e93\u548c\u51fd\u6570\uff0c\u5e76\u627e\u5230\u4e86\u4e00\u4e2a\u672a\u516c\u5f00\u7684API\u7aef\u70b9\uff0c\u6700\u7ec8\u901a\u8fc7\u8fd9\u4e2a\u7aef\u70b9\u83b7\u53d6\u4e86flag\u3002\u8fd9\u4e2a\u4f8b\u5b50\u8bf4\u660e\uff0c\u5373\u4f7f\u662f\u770b\u4f3c\u201c\u5931\u8d25\u201d\u7684\u54cd\u5e94\uff0c\u4e5f\u53ef\u80fd\u9690\u85cf\u7740\u901a\u5f80\u6210\u529f\u7684\u7ebf\u7d22\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u7f51\u7edc\u57fa\u7840\u5c0f\u77e5\u8bc6 \u4e92\u8054\u7f51\u662f\u600e\u4e48\u5de5\u4f5c\u7684 URL\u662f\u4ec0\u4e48 URL \u662f Uniform Resource Locator \u7684\u7f29\u5199\uff0c\u4e2d\u6587\u901a\u5e38\u7ffb ...<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"emotion":"","emotion_color":"","title_style":"","license":""},"categories":[26],"tags":[],"class_list":["post-335","post","type-post","status-publish","format-standard","hentry","category-internet"],"_links":{"self":[{"href":"https:\/\/index.cmiteam.cn\/index.php\/wp-json\/wp\/v2\/posts\/335","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/index.cmiteam.cn\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/index.cmiteam.cn\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/index.cmiteam.cn\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/index.cmiteam.cn\/index.php\/wp-json\/wp\/v2\/comments?post=335"}],"version-history":[{"count":0,"href":"https:\/\/index.cmiteam.cn\/index.php\/wp-json\/wp\/v2\/posts\/335\/revisions"}],"wp:attachment":[{"href":"https:\/\/index.cmiteam.cn\/index.php\/wp-json\/wp\/v2\/media?parent=335"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/index.cmiteam.cn\/index.php\/wp-json\/wp\/v2\/categories?post=335"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/index.cmiteam.cn\/index.php\/wp-json\/wp\/v2\/tags?post=335"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}