*DVWA使用
http://www.219.me/posts/category/security/%E6%94%BB%E9%98%B2%E5%AE%9E%E9%AA%8C%E5%AE%A4/dvwa
http://www.219.me/posts/category/security/%E6%94%BB%E9%98%B2%E5%AE%9E%E9%AA%8C%E5%AE%A4/dvwa/page/2
*基于DVWA
http://www.myhack58.com/Article/html/3/8/2016/70778.htm
http://www.219.me/posts/2431.html
*CSRF与XSS的区别
http://selfcontroller.iteye.com/blog/1844653
http://www.cnblogs.com/wangyuyu/p/3388180.html