http://www.xiaonei.com/crossdomain.xml
<!– http://www.xiaonei.com/ –> ? <cross-domain-policy> <allow-access-from domain=”*.xiaonei.com”/> <allow-access-from domain=”xiaonei.com”/> </cross-domain-policy>
这是很标准的做法,我就让我自己的域以及我的子域来获取数据。
淘宝的:
http://www.taobao.com/crossdomain.xml
<cross-domain-policy> <allow-access-from domain=”*.taobao.com”/> <allow-access-from domain=”*.taobao.net”/> <allow-access-from domain=”*.taobaocdn.com”/> <allow-access-from domain=”*.allyes.com”/> </cross-domain-policy>
绿色的一行是淘宝的广告商了,http://www.allyes.com/好耶广告网络,只是不清楚是不是仍然再卖淘宝的广告?
多看几个大网站的crossdomain.xml,也可以知道可能是什么网络广告商给它们在打广告。
比如彭博:http://www.bloomberg.com/crossdomain.xml
<cross-domain-policy> <allow-access-from domain=”localhost”/> <allow-access-from domain=”10.16.136.107″/> <allow-access-from domain=”*.bloomberg.com”/> <allow-access-from domain=”*.pointroll.com”/> <allow-access-from domain=”*.pointroll.net”/> </cross-domain-policy>
红色的就太不专业了,把内部IP都给暴露了。。。。。。
绿色的是彭博的广告商:PointRoll
路透的:
http://www.reuters.com/crossdomain.xml
<cross-domain-policy> <allow-access-from domain=”*.reuters.com” secure=”false”/> <allow-access-from domain=”ad.doubleclick.net” secure=”false”/> <allow-access-from domain=”ad.uk.doubleclick.net” secure=”false”/> <allow-access-from domain=”m.2mdn.net” secure=”false”/> <allow-access-from domain=”m2.2mdn.net” secure=”false”/> </cross-domain-policy>
广告给了doubleclick来做(绿色)
2mdn.net看不懂是干嘛的,大概是个cdn吧。
滥情的facebook:
http://www.facebook.com/crossdomain.xml
<?xml version=”1.0″?> <!DOCTYPE cross-domain-policy SYSTEM “http://www.adobe.com/xml/dtds/cross-domain-policy.dtd”> <cross-domain-policy> <site-control permitted-cross-domain-policies=”master-only” /> <allow-access-from domain=”s-static.facebook.com” /> <allow-access-from domain=”static.facebook.com” /> <allow-access-from domain=”static.api.ak.facebook.com” /> <allow-access-from domain=”*.static.ak.facebook.com” /> <allow-access-from domain=”s-static.thefacebook.com” /> <allow-access-from domain=”static.thefacebook.com” /> <allow-access-from domain=”static.api.ak.thefacebook.com” /> <allow-access-from domain=”*.static.ak.thefacebook.com” /> <allow-access-from domain=”*.static.ak.fbcdn.com” /> <allow-access-from domain=”external.ak.fbcdn.com” /> <allow-access-from domain=”*.static.ak.fbcdn.net” /> <allow-access-from domain=”external.ak.fbcdn.net” /> <allow-access-from domain=”www.facebook.com” /> <allow-access-from domain=”www.new.facebook.com” /> <allow-access-from domain=”register.facebook.com” /> <allow-access-from domain=”login.facebook.com” /> <allow-access-from domain=”ssl.facebook.com” /> <allow-access-from domain=”secure.facebook.com” /> </cross-domain-policy>
这么多!有子域,有CDN,有thefacebook(facebook的旧域名吧?)
还是google的专业:
<?xml version=”1.0″?> <!DOCTYPE cross-domain-policy SYSTEM “http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd”> <cross-domain-policy> <site-control permitted-cross-domain-policies=”by-content-type” /> </cross-domain-policy>
蓝色行的意思是,要符合要求的文件你才能取,不管你是哪来的flash数据请求。符合要求的文档必须满足:Content-Type: text/x-cross-domain-policy
扫码关注腾讯云开发者
领取腾讯云代金券
Copyright © 2013 - 2025 Tencent Cloud. All Rights Reserved. 腾讯云 版权所有
深圳市腾讯计算机系统有限公司 ICP备案/许可证号:粤B2-20090059 深公网安备号 44030502008569
腾讯云计算(北京)有限责任公司 京ICP证150476号 | 京ICP备11018762号 | 京公网安备号11010802020287
Copyright © 2013 - 2025 Tencent Cloud.
All Rights Reserved. 腾讯云 版权所有