# 漏洞盒子「提交漏洞」表单填充清单

> **任务 ID**: V-011
> **项目**: 千寻位置SRC
> **生成时间**: 2026-07-27T00:43:21
> **下一步**: 复制下面 HTML 到漏洞盒子提交页 → 勾「同意协议」→ 点「提交漏洞」

---

## 📋 字段对照（按漏洞盒子表单顺序）

| # | 字段 | 类型 | 值 |
|---|---|---|---|
| 1 | 项目名称 | 输入框 | `千寻位置SRC` |
| 2 | 漏洞标题 | 输入框 | `千寻位置 qxwz.com 缺失关键 HTTP 安全响应头` |
| 3 | 漏洞域名 | 输入框 | `https://www.qxwz.com` |
| 4 | 漏洞类型 | 下拉框 | `缺失安全响应头` |
| 5 | 漏洞等级 | 单选 | `中危` ⬅ 点选 |
| 6 | 漏洞简述 | 多行文本 | 见下方 |
| 7 | 复现步骤 | **HTML 富文本** | 见下方 HTML |
| 8 | 修复建议 | **HTML 富文本** | 见下方 HTML |
| 9 | 文件上传 | 文件框 | 0 个文件（路径见附录） |
| 10 | 用户协议 | 复选框 | **手动勾选** |
| 11 | 提交漏洞 | 按钮 | **手动点击** |

---

## 6️⃣ 漏洞简述（多行文本，复制此段）

```
千寻位置 (https://www.qxwz.com) 缺失多个关键 HTTP 安全响应头，包括 Strict-Transport-Security、Content-Security-Policy、X-Frame-Options、Referrer-Policy、X-Content-Type-Options、Permissions-Policy。攻击者可利用此缺陷实施点击劫持、中间人攻击、跨站脚本攻击等。影响范围涉及所有访问该站点的用户。
```

---

## 7️⃣ 复现步骤 HTML（粘贴到富文本编辑器「HTML 模式」）

```html
1. 打开命令行终端<br>2. 执行命令：<code>curl -sI https://www.qxwz.com</code><br>3. 观察响应头：<br>&nbsp;&nbsp;- <strong>Strict-Transport-Security</strong>: 未设置<br>&nbsp;&nbsp;- <strong>Content-Security-Policy</strong>: 未设置<br>&nbsp;&nbsp;- <strong>X-Frame-Options</strong>: 未设置<br>&nbsp;&nbsp;- <strong>Referrer-Policy</strong>: 未设置<br>&nbsp;&nbsp;- <strong>X-Content-Type-Options</strong>: 未设置<br>&nbsp;&nbsp;- <strong>Permissions-Policy</strong>: 未设置<br>4. 使用浏览器开发者工具 (F12 → Network → Headers) 可获得同样结果<br>5. 验证: 在另一台机器通过中间人代理抓包可看到所有响应均无以上安全头
```

---

## 8️⃣ 修复建议 HTML（粘贴到富文本编辑器「HTML 模式」）

```html
1. <strong>添加 HSTS</strong>: Nginx 配置 <code>add_header Strict-Transport-Security "max-age=31536000; includeSubDomains; preload" always;</code><br>2. <strong>添加 CSP</strong>: <code>add_header Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval'; style-src 'self' 'unsafe-inline'; img-src 'self' data: https:; font-src 'self' data:;" always;</code><br>3. <strong>防点击劫持</strong>: <code>add_header X-Frame-Options "SAMEORIGIN" always;</code> 或使用 CSP 的 frame-ancestors<br>4. <strong>Referrer 控制</strong>: <code>add_header Referrer-Policy "strict-origin-when-cross-origin" always;</code><br>5. <strong>MIME 嗅探防护</strong>: <code>add_header X-Content-Type-Options "nosniff" always;</code><br>6. <strong>特性策略</strong>: <code>add_header Permissions-Policy "geolocation=(), microphone=(), camera=()" always;</code><br>7. 配置完成后使用 <a href='https://securityheaders.com/'>https://securityheaders.com/</a> 验证评分 A+
```

---

## 📎 附件清单（手动拖到「文件上传」框）

（未提供截图，需手动附加）

---

## ⚠️ 提交前自检清单

- [ ] 漏洞标题前缀（**部分 SRC 要求**）：OPPO 加 `[OPPO]` / vivo 加 `[vivo]` / PayPal 加 `[PPSRC]`（具体看 SRC 公告）
- [ ] 漏洞域名是否在**资产清单**（`C:\Users\Administrator\srccrawler\渗透任务跟踪表.xlsx` 的「资产清单」sheet）
- [ ] 截图是否覆盖 3 类：①异常响应 ②实际利用成功 ③影响范围
- [ ] 复现步骤是否带具体 curl / sqlmap / burp 命令（不要只写"手工测试"）
- [ ] 修复建议是否给代码 diff，不是"加 WAF"这种空话
- [ ] 「同意《漏洞盒子平台用户协议》」**勾上**
- [ ] 「提交漏洞」or「预存」（预存=草稿箱，不会真提交）

---

## 📊 回填到 Excel（提交成功后）

`C:\Users\Administrator\srccrawler\渗透任务跟踪表.xlsx` 的「漏洞追踪」sheet：

| 发现日期 | 任务ID | SRC平台 | 项目 | 漏洞名 | 严重等级 | 状态 | 奖励金额 |
|---|---|---|---|---|---|---|---|
| 2026-07-27 | V-011 | vulbox | 千寻位置SRC | 千寻位置 qxwz.com 缺失关键 HTTP 安全响应头 | 中危 | 已提交 | （提交后填） |
