¶Ô WEB Ó¦ÓýøÐÐ XSS ©¶´²âÊÔ£¬²»Äܽö½ö¾ÖÏÞÓÚÔÚ WEB Ò³ÃæÊäÈë
XSS ¹¥»÷×ֶΣ¬È»ºóÌá½»¡£Èƹý JavaScript µÄ¼ì²â£¬ÊäÈë XSS ½Å±¾£¬Í¨³£±»²âÊÔÈËÔ±ºöÂÔ¡£ÏÂͼΪ
XSS ¶ñÒâÊäÈëÈÆ¹ý JavaScript ¼ì²âµÄ¹¥»÷·¾¶¡£

³£¼ûµÄ XSS ÊäÈë
XSS ÊäÈëͨ³£°üº¬ JavaScript ½Å±¾£¬È絯³ö¶ñÒ⾯¸æ¿ò£º<script>alert("XSS");</script>
XSS ÊäÈëÒ²¿ÉÄÜÊÇ HTML ´úÂë¶Î£¬Æ©È磺
ÍøÒ³²»Í£µØË¢Ð <meta http-equiv="refresh"
content="0;">
ǶÈëÆäËüÍøÕ¾µÄÁ´½Ó <iframe src=http://xxxx
width=250 height=250></iframe>
XSS (Cross Site Scripting) Cheat Sheet
ά»¤ÁËÒ»·Ý³£¼ûµÄ XSS ¹¥»÷½Å±¾ÁÐ±í£¬¿ÉÓÃÀ´×÷Ϊ¼ì²â WEB Ó¦ÓÃÊÇ·ñ´æÔÚ XSS ©¶´µÄ²âÊÔÓÃÀýÊäÈë¡£³õ´Î½Ó´¥
XSS ¹¥»÷µÄ¿ª·¢ÈËÔ±¿ÉÄÜ»á¶ÔÁбíÌṩµÄһЩ XSS ÊäÈë²»ÊǺÜÀí½â£¬±¾Îĵڶþ²¿·Ö½«»áÕë¶Ô²»Í¬´úÂëÉÏÏÂÎĵÄ
XSS ÊäÈë×÷½øÒ»²½µÄ½âÊÍ¡£
²âÊÔ¹¤¾ß
ºÜ¶à¹¤¾ß¿ÉÒÔÔÚä¯ÀÀÆ÷·¢ËÍ Get/Post ÇëÇóǰ½«Æä½ØÈ¡£¬¹¥»÷Õß¿ÉÒÔÐÞ¸ÄÇëÇóÖеÄÊý¾Ý£¬´Ó¶øÈƹý
JavaScript µÄ¼ìÑ齫¶ñÒâÊý¾Ý×¢Èë·þÎñÆ÷¡£ÒÔÏÂÊÇһЩ³£ÓõĽØÈ¡ HTTP ÇëÇóµÄ¹¤¾ßÁÐ±í¡£
Paros proxy (http://www.parosproxy.org) Fiddler (http://www.fiddlertool.com/fiddler) Burp proxy (http://www.portswigger.net/proxy/) TamperIE (http://www.bayden.com/dl/TamperIESetup.exe) |
±ÊÕßÔø¾Ê¹Óà TamperIE ¶Ô WEB Ó¦ÓýøÐа²È«ÐÔ²âÊÔ¡£TamperIE СÇÉÒ×Óã¬Äܹ»½ØÈ¡
IE ä¯ÀÀÆ÷·¢Ë굀 Get/Post ÇëÇó£¬ÉõÖÁÄÜÈÆ¹ý SSL ¼ÓÃÜ¡£²»¹ý TamperIE + IE7
¹¤×÷²»Îȶ¨¡£IE7 ÌṩÁË¶Ô IPV6 µÄÖ§³Ö£¬Èç¹ûÄã²¢²»¼Æ»®²âÊÔÄãµÄ Web Ó¦ÓÃ¶Ô IPV6 µÄÖ§³Ö£¬½¨Ò黹ÊÇʹÓÃ
TamperIE + IE6 µÄ×éºÏ¡£
Èçͼ2Ëùʾ: TamperIE ÈÆ¹ý¿Í»§¶Ëä¯ÀÀÆ÷ JavaScript µÄУÑ飬ÔÚ POST ÇëÇóÌύʱ½«Æä½ØÈ¡£¬Óû§¿ÉÒÔÈÎÒâÐÞ¸Ä±íµ¥ÊäÈëÏî
name ºÍ message µÄÖµ£¬Æ©È罫 message µÄÖµÐÞ¸ÄΪ "<script>alert(¡°XSS
hole!!¡±);</script>"£¬È»ºóµã»÷ ¡±Send altered
data¡± °´Å¥£¬½«Ð޸ĺóµÄ¶ñÒâÊý¾Ý·¢Ë͸ø Web ·þÎñÆ÷¡£
ͼ 2. ʹÓà TamperIE ½ØÈ¡ Post ÇëÇó
ÔÚÊä³ö¶Ë¶Ô¶¯Ì¬ÄÚÈݽøÐбàÂë
¶ÔÒ»¸ö Web Ó¦ÓöøÑÔ£¬Æä¶¯Ì¬ÄÚÈÝ¿ÉÄÜÀ´Ô´ÓÚÓû§ÊäÈë¡¢ºǫ́Êý¾Ý¿â¡¢Ó²¼þ״̬¸Ä±ä»òÊÇÍøÂçÐÅÏ¢µÈ¡£¶¯Ì¬ÄÚÈÝÌØ±ðÊÇÀ´×ÔÓû§ÊäÈëµÄ¶¯Ì¬ÄÚÈݺÜÓпÉÄܰüº¬¶ñÒâÊý¾Ý£¬´Ó¶øÓ°ÏìÍøÒ³µÄÕý³£ÏÔʾ»òÊÇÖ´ÐжñÒâ½Å±¾¡£½«¶¯Ì¬ÄÚÈݰ²È«µØÏÔʾÔÚä¯ÀÀÆ÷¶ËÓ붯̬ÄÚÈÝËù´¦µÄÉÏÏÂÎı³¾°Óйأ¬Æ©È綯̬ÄÚÈÝ´¦ÔÚ
HTML ÕýÎÄ¡¢±íµ¥ÔªËصÄÊôÐÔ¡¢»òÊÇ JavaScript ´úÂë¶ÎÖС£¶ÔÓÚÒ»¸ö»ùÓÚ PHP ÓïÑ﵀ Web
Ó¦Ó㬵±Ö´ÐÐ"echo"¡¢"print"¡¢"printf"¡¢"<?="
µÈÓï¾äʱ±íʾÕýÔÚ´¦Àí¶¯Ì¬ÄÚÈÝ¡£±¾½Ú½«Ê×ÏȽéÉÜ PHP ÌṩµÄ¿âº¯Êý htmlspecialchars()µÄÓ÷¨£¬´Ëº¯ÊýÄܽ«
5 ¸ö HTML ÌØÊâ×Ö·ûת»¯Îª¿ÉÔÚÍøÒ³ÏÔʾµÄ HTML ʵÌå±àÂ룻Ȼºó½«½éÉÜһЩ³£¼û±³¾°Ï嵀 XSS
¹¥»÷ÊäÈ룬ÒÔ¼°ÈçºÎÔÚÊä³ö¶Ë¶Ô¶¯Ì¬ÄÚÈݽøÐÐתÒå¡¢±àÂë´Ó¶ø±ÜÃâ XSS ¹¥»÷¡£
ʹÓà PHP µÄ htmlspecialchars() ÏÔʾ HTML
ÌØÊâ×Ö·û
´ÓÉÏÎÄÁÐ¾ÙµÄ XSS ¶ñÒâÊäÈë¿ÉÒÔ¿´µ½£¬ÕâЩÊäÈëÖаüº¬ÁËÒ»Ð©ÌØÊâµÄ HTML ×Ö·ûÈç "<"¡¢">"¡£µ±´«Ë͵½¿Í»§¶Ëä¯ÀÀÆ÷ÏÔʾʱ£¬ä¯ÀÀÆ÷»á½âÊÍÖ´ÐÐÕâЩ
HTML »òJavaScript ´úÂë¶ø²»ÊÇÖ±½ÓÏÔʾÕâЩ×Ö·û´®¡£< > &
¡° µÈ×Ö·ûÔÚHTMLÓïÑÔÖÐÓÐÌØÊ⺬Ò壬¶ÔÓÚÓû§ÊäÈëµÄÌØÊâ×Ö·û£¬ÈçºÎÖ±½ÓÏÔʾÔÚÍøÒ³Öжø²»ÊDZ»ä¯ÀÀÆ÷µ±×÷ÌØÊâ×Ö·û½øÐнâÎö?
HTML×Ö·ûʵÌåÓÉ & ·ûºÅ¡¢ÊµÌåÃû×Ö»òÕß # ¼ÓÉÏʵÌå±àºÅ¡¢·ÖºÅÈý²¿·Ö×é³É¡£ÒÔÏÂΪ
HTML ÖÐÒ»Ð©ÌØÊâ×Ö·ûµÄ±àÂë¡£ÓеÄ×Ö·ûʵÌåÖ»ÓÐʵÌå±àºÅ£¬Ã»ÓжÔÓ¦µÄʵÌåÃû×Ö£¬Æ©Èçµ¥ÒýºÅ¡£

PHP ÌṩÁËhtmlspecialchars()º¯Êý¿ÉÒÔ½« HTML ÌØÊâ×Ö·ûת»¯³ÉÔÚÍøÒ³ÉÏÏÔʾµÄ×Ö·ûʵÌå±àÂë¡£ÕâÑù¼´Ê¹Óû§ÊäÈëÁ˸÷ÖÖ
HTML ±ê¼Ç£¬ÔÚ¶Á»Øµ½ä¯ÀÀÆ÷ʱ£¬»áÖ±½ÓÏÔʾÕâЩ HTML ±ê¼Ç£¬¶ø²»ÊǽâÊÍÖ´ÐС£htmlspecialchars()º¯Êý¿ÉÒÔ½«ÒÔÏÂÎåÖÖ
HTML ÌØÊâ×Ö·ûת³É×Ö·ûʵÌå±àÂ룺
& ת³É &amp; ¡° ת³É &quot; < ת³É &lt; > ת³É &gt; ¡® ת³É &#39; |
µ±Ö±½Óµ÷Óà htmlspecialchars($str)ʱ, & " <
> ±»×ªÒå¡£
µ±ÉèÖà ENT_QUOTES ±ê¼Çʱ, ¼´µ÷ÓÃhtmlspecialchars($str, ENT_QUOTES)ʱ£¬µ¥ÒýºÅÒ²±»×ªÒå¡£
µ±ÉèÖà ENT_NOQUOTES ±ê¼Çʱ£¬µ¥ÒýºÅºÍË«ÒýºÅ¶¼²»»á±»×ªÒå¡£¼´µ÷Óà htmlspecialchars($str,
ENT_NOQUOTES)ʱ£¬Ö»ÓÐ& < > ±»×ªÒå¡£
²»Í¬±³¾°ÏµĶ¯Ì¬ÄÚÈÝµÄ XSS ¹¥»÷¼°½â¾ö·½°¸
XSS ¹¥»÷ÊäÈëÓ붯̬ÄÚÈÝËù´¦µÄ´úÂë±³¾°Ïà¹Ø£¬Æ©È綯̬ÄÚÈÝΪ±íµ¥ÔªËØÊôÐÔµÄÖµ¡¢Î»ÓÚ HTML ÕýÎÄ¡¢»òÊÇ
Javascript ´úÂë¶ÎÖеȵȡ£
HTML±ê¼ÇµÄÊôÐÔΪ¶¯Ì¬ÄÚÈÝ
Web Ó¦ÓÃÖУ¬"input"¡¢"style"¡¢"color"
µÈ HTML ±ê¼ÇµÄÊôÐÔ¶¼¿ÉÄÜΪ¶¯Ì¬ÄÚÈÝ£¬ÆäÖÐ"input" ±ê¼ÇµÄ "value"
ÊôÐÔͨ³£Îª¶¯Ì¬ÄÚÈÝ¡£
Àý×Ó1
<form¡><INPUT type=text name="msg" id="msg" size=10 maxlength=8 value="<?= $msg?>"></form> |
¹¥»÷XSSÊäÈë
Hello"><script>evil_script()</script> |
½«¶¯Ì¬ÄÚÈÝÌæ»»
½« $msg Ìæ»»Îª¶ñÒâ XSS ÊäÈë:
<form¡><INPUT type=text name="msg" id="msg" size=10 maxlength=8
value="Hello"><script>evil_script()</script>"></form> |
Àý×Ó2
<form¡><INPUT type=text name="msg" id="msg" size=10 maxlength=8 value=<?= $msg?>></form> |
¹¥»÷ XSS ÊäÈë
Hello onmouseover=evil_script() |
½«¶¯Ì¬ÄÚÈÝÌæ»»
½« $msg Ìæ»»Îª¶ñÒâ XSS ÊäÈë:
<form¡><INPUT type=text name="msg" id="msg" size=10 maxlength=8
value=Hello onmouseover=evil_script()></form> |
·ÖÎö
´ÓÀý×Ó 1 ¿ÉÒÔ¿´µ½Æä XSS¹¥»÷ÊäÈëÖаüº¬ÁË HTML ÌØÊâ×Ö·û < >
"
´ÓÀý×Ó 2 ¿ÉÒÔ¿´µ½Æä XSS ¹¥»÷ÊäÈëÖÐûÓаüº¬ÉϽÚÖÐÌáµ½µÄÎåÖÖ HTML ×Ö·û£¬ µ«ÊÇ "value"ÊôÐÔֵûÓÐʹÓÃË«ÒýºÅ°üΧ¡£
½â¾ö·½°¸
µ÷ÓÃhtmlspecialchars($str, ENT_QUOTES)½«ÒÔÏ 5 ÖÖ HTML ÌØÊâ×Ö·û
< > &¡® ¡° תÒ壻ͬʱʹÊôÐÔÖµ±»Ë«ÒýºÅ°üΧ¡£Æ©È磺
<form¡><INPUT type=text name="msg" id="msg" size=10 maxlength=8
value="<?= htmlspecialchars($msg, ENT_QUOTES))?>"></form> |
×¢ÒâÊÂÏî
½« input µÄ value ½øÐÐתÒ壬±ØÐ뿼ÂÇÏÔʾºÍ´æ´¢Êý¾ÝµÄÒ»ÖÂÐÔÎÊÌ⣬¼´ÏÔʾÔÚä¯ÀÀÆ÷¶ËºÍ´æ´¢ÔÚ·þÎñÆ÷¶Ëºǫ́µÄÊý¾Ý¿ÉÄÜÒòΪתÒå¶ø±äµÃ²»Ò»Ö¡£Æ©Èç´æ´¢ÔÚ·þÎñÆ÷¶ËµÄºǫ́ÔʼÊý¾Ý°üº¬ÁËÒÔÉÏ
5 ÖÖÌØÊâ×Ö·û£¬µ«ÊÇûÓÐתÒ壬ΪÁË·ÀÖ¹ XSS ¹¥»÷£¬ÔÚä¯ÀÀÆ÷¶ËÊä³öʱ¶Ô HTML ÌØÊâ×Ö·û½øÐÐÁËתÒ壺
1. µ±ÔٶȽ«±íµ¥Ìύʱ£¬´æ´¢µÄÄÚÈݽ«»á±ä³ÉתÒåºóµÄÖµ¡£
2. µ±Ê¹Óà JavaScript ²Ù×÷±íµ¥ÔªËØ£¬ÐèҪʹÓõ½±íµ¥ÔªËصÄֵʱ£¬±ØÐ뿼Âǵ½Öµ¿ÉÄÜÒѾ±»×ªÒå¡£
HTMLÎı¾Îª¶¯Ì¬ÄÚÈÝ
Àý×Ó
<b> »¶Ó£º<?= $welcome_msg?></b> ¹¥»÷XSSÊäÈë <script>evil_script()</script> ½«¶¯Ì¬ÄÚÈÝÌæ»» ½«$welcome_msg Ìæ»»Îª¶ñÒâ XSS ÊäÈë: <b>»¶Ó£º<script>evil_script()</script></b> |
·ÖÎö
ÔÚ HTML ÕýÎı³¾°Ï£¬< > ×Ö·û»áÒýÈë HTML ±ê¼Ç£¬&
¿ÉÄÜ»áÈÏΪ×Ö·ûʵÌå±àÂëµÄ¿ªÊ¼£¬ËùÒÔÐèÒª½« < > & תÒå
½â¾ö·½°¸
Ϊ¼ò½àÆð¼û£¬Ö±½ÓʹÓà htmlspecialchars()½« 5 ÖÖ HTML ÌØÊâ×Ö·ûתÒ壬È磺
<b>Ȧ<?= htmlspecialchars($welcome_msg,, ENT_NOQUOTES)?></b> |
URLµÄֵΪ¶¯Ì¬ÄÚÈÝ
Script/Style/Img/ActiveX/Applet/Frameset¡ µÈ±ê¼ÇµÄ src
»ò href ÊôÐÔÈç¹ûΪ¶¯Ì¬ÄÚÈÝ£¬±ØÐëÈ·±£ÕâЩ URL ûÓÐÖ¸Ïò¶ñÒâÁ´½Ó¡£
Àý×Ó1
<script src=<?= "$script_url>"> ¹¥»÷XSSÊäÈë http://evil.org/evil.js ½«¶¯Ì¬ÄÚÈÝÌæ»» ½«$script_urlÌæ»»Îª¶ñÒâ XSS ÊäÈë: <script src="http://evil.org/evil.js"> |
Àý×Ó2
<img src=¡±<?= $img_url>¡±> ¹¥»÷XSSÊäÈë javascript:evil_script() ½«¶¯Ì¬ÄÚÈÝÌæ»» ½«$img_urlÌæ»»Îª¶ñÒâXSSÊäÈë: <img src=¡± javascript:evil_script()¡±> |
·ÖÎö
Ò»°ãÇé¿öϾ¡Á¿²»ÒªÈà URL µÄÖµ±»Óû§¿ØÖÆ¡£Èç¹ûÓû§ÐèÒª×Ô¼º¶¨Òå×Ô¼ºµÄ·ç¸ñ¼°ÏÔʾЧ¹û£¬Ò²²»ÄÜÈÃÓû§Ö±½Ó¿ØÖÆÕû¸ö
URL µÄÄÚÈÝ£¬¶øÊÇÌṩԤ¶¨ÒåºÃµÄ·ç¸ñ¹©Óû§ÉèÖá¢×°Å䣬ȻºóÓɺǫ́³ÌÐò¸ù¾ÝÓû§µÄÑ¡Ôñ×éºÏ³É°²È«µÄ URL
Êä³ö¡£
×Ö·û¼¯±àÂë
ä¯ÀÀÆ÷ÐèÒªÖªµÀ×Ö·û¼¯±àÂë²ÅÄÜÕýÈ·µØÏÔÊ¾ÍøÒ³¡£Èç¹û×Ö·û¼¯±àÂëûÓÐÏÔʽÔÚ content-type »òmeta
Öж¨Ò壬ä¯ÀÀÆ÷»áÓÐËã·¨²Â²âÍøÒ³µÄ×Ö·û¼¯±àÂ롣ƩÈç<script>alert(document.cookie)</script>
µÄ UTF-7 ±àÂëΪ£º
+ADw-script+AD4-alert(document.cookie)+ADw-/script+AD4- |
Èç¹û+ADw-script+AD4-alert(document.cookie)+ADw-/script+AD4-×÷Ϊ¶¯Ì¬ÄÚÈÝλÓÚÍøÒ³µÄ¶¥¶Ë²¢´«Ë͵½ä¯ÀÀÆ÷¶Ë£¬IE
»áÈÏΪ´ËÍøÒ³ÊÇ UTF-7 ±àÂ룬´Ó¶øÊ¹ÍøÒ³²»ÄÜÕý³£ÏÔʾ¡£
½â¾ö·½°¸
ÏÔʽ¶¨ÒåÍøÒ³µÄ×Ö·û¼¯±àÂ룬ƩÈç
<meta http-equiv=content-type content="text/html; charset=UTF-8"> |
¶¯Ì¬ÄÚÈÝΪJavaScriptʼþ´¦Àíº¯ÊýµÄ²ÎÊý
JavaScript ʼþ´¦Àíº¯ÊýÈç onClick/onLoad/onError/onMouseOver/
µÄ²ÎÊý¿ÉÄܰüº¬¶¯Ì¬ÄÚÈÝ¡£
Àý×Ó
<input type="button" value="go to" onClick='goto_url("<?= $target_url>");'> ¹¥»÷XSSÊäÈë foo&quot;);evil_script(&quot; ½«¶¯Ì¬ÄÚÈÝÌæ»» HTML ½âÎöÆ÷»áÏÈÓÚ JavaScript ½âÎöÆ÷½âÎöÍøÒ³£¬½«$target_url Ìæ»»Îª¶ñÒâ XSS ÊäÈë: <input type="button" value="go to" onClick='goto_url("foo");evil_script("");'> ¶¯Ì¬ÄÚÈÝλÓÚ JavaScript ´úÂë¶ÎÖÐ |
Àý×Ó
<SCRIPT language="javascript1.2"> var msg='<?= $welcome_msg?> '; // ¡ </SCRIPT> ¹¥»÷XSSÊäÈë1 Hello'; evil_script(); // ½«¶¯Ì¬ÄÚÈÝÌæ»» ½« $welcome_msg Ìæ»»Îª¶ñÒâ XSS ÊäÈë: <SCRIPT language="javascript1.2"> var msg='Hello'; evil_script(); //'; // ¡ </SCRIPT> ¹¥»÷XSSÊäÈë2 Hello</script><script>evil_script();</script><script> ½«¶¯Ì¬ÄÚÈÝÌæ»» ½«$welcome_msg Ìæ»»Îª¶ñÒâ XSS ÊäÈë: <script> var msg = 'Hello</script> <script>evil_script();</script> <script>'
// ... // do something with msg_text </script> |
·ÖÎö
ÈçÉÏÎÄËùʾ£¬ÔÚ JavaScript ±³¾°ÖÐʹÓö¯Ì¬ÄÚÈÝÐèÒª·Ç³£½÷É÷¡£Ò»°ãÇé¿öÏ£¬¾¡Á¿±ÜÃâ»ò¼õÉÙÔÚ
Javascript µÄ±³¾°ÏÂʹÓö¯Ì¬ÄÚÈÝ£¬Èç¹û±ØÐëʹÓö¯Ì¬ÄÚÈÝ£¬ÔÚ¿ª·¢»ò´úÂëÉó¼ÆÊ±±ØÐ뿼ÂÇÕâЩ¶¯Ì¬ÄÚÈÝ¿ÉÄܵÄȡֵ£¬ÊÇ·ñ»áµ¼ÖÂ
XSS ¹¥»÷¡£
½¨Á¢PHP¿âº¯ÊýУÑéÊäÈë
Web ¿ª·¢ÈËÔ±±ØÐëÁ˽⣬½ö½öÔÚ¿Í»§¶ËʹÓà JavaScript º¯Êý¶Ô·Ç·¨ÊäÈë½øÐмì²â¹ýÂ˶ÔÓÚ¹¹½¨°²È«µÄ
WEB Ó¦ÓÃÊDz»¹»µÄ¡£ÈçÉÏÎÄËùÊö£¬¹¥»÷Õß¿ÉÒÔÇáÒ׵ؽèÖú¹¤¾ßÈÆ¹ý JavaScript УÑéÉõÖÁ SSL
¼ÓÃÜÊäÈë¶ñÒâÊý¾Ý¡£ÔÚÊä³ö¶Ë¶Ô¶¯Ì¬ÄÚÈݽøÐбàÂëÒ²Ö»ÄÜÆðµ½Ò»ÖÖË«ÖØ±£»¤µÄ×÷Ó㬸üÖØÒªµÄÓ¦¸ÃÔÚ·þÎñÆ÷¶Ë¶ÔÊäÈë½øÐÐУÑé¡£PHP
ÌṩÁËstrpos()¡¢strstr()¡¢preg_match()µÈº¯Êý¿ÉÓÃÓÚ¼ì²â·Ç·¨×Ö·ûºÍ×Ö·û´®£»preg_replace()
º¯Êý¿ÉÓÃÓÚÌæ»»·Ç·¨×Ö·û´®¡£OWASP PHP Filters ¿ªÔ´ÏîÄ¿ÌṩÁËһЩ PHP ¿âº¯ÊýÓÃÓÚ¹ýÂË·Ç·¨ÊäÈë¿É×÷Ϊ²Î¿¼¡£Ò»Ð©³£¼ûµÄ¼ì²âºÍ¹ýÂ˰üÀ¨£º
ÊäÈëÊÇ·ñ½ö½ö°üº¬ºÏ·¨µÄ×Ö·û£»
ÊäÈëÈç¹ûΪÊý×Ö£¬Êý×ÖÊÇ·ñÔÚÖ¸¶¨µÄ·¶Î§£»
ÊäÈë×Ö·û´®ÊÇ·ñ³¬¹ý×î´ó³¤¶ÈÏÞÖÆ£»
ÊäÈëÊÇ·ñ·ûºÏÌØÊâµÄ¸ñʽҪÇ󣬯©Èçemail µØÖ·¡¢IP µØÖ·£»
²»Í¬µÄÊäÈë¿òÔÚÂß¼ÉÏ´æÔÚµÄñîºÏºÍÏÞÖÆµÄ¹ØÏµ£»
³ýÈ¥ÊäÈëÊ×βµÄ¿Õ¸ñ£»
×ܽá
Web Ó¦ÓõݲȫÐÔÊÇÒ»¸öºÜÖØÒª¡¢¸²¸Ç·¶Î§ºÜ¹ã·ºµÄÖ÷Ì⡣ΪÁË·ÀÖ¹³£¼ûµÄ XSS µÄ¹¥»÷£¬Web ¿ª·¢ÈËÔ±±ØÐëÃ÷°×²»Äܽö½öÖ»ÔÚ¿Í»§¶ËʹÓÃ
JavaScript ¶ÔÊäÈë½øÐмì²â¡¢¹ýÂË£»Í¬Ê±»¹Ó¦½¨Á¢·þÎñÆ÷¶ËµÄÊäÈëУÑé¡¢Êä³ö±àÂë¿âº¯Êý£»ÔÚ·þÎñÆ÷¶Ë¼ì²â¡¢¹ýÂËÊäÈ룻¸ù¾Ý¶¯Ì¬ÄÚÈÝËù´¦µÄ±³¾°½«ÌØÊâ×Ö·û½øÐбàÂëºóÔÙ´«Ë͸øä¯ÀÀÆ÷¶ËÏÔʾ¡£
|