CSP
大佬的CSP全家桶,看到好的再贴过来,把这几篇先看完
http://lorexxar.cn/2016/08/08/ccsp/
http://lorexxar.cn/2017/02/16/cdn-bypass-csp/
http://lorexxar.cn/2016/04/20/gif-ccsp/
http://lorexxar.cn/2016/04/08/input-bypasscsrf/
大佬多次提到的<link rel="prefetch" herf="xxxxxxx">
mark一下先