Äú¿ÉÒÔ¾èÖú£¬Ö§³ÖÎÒÃǵĹ«ÒæÊÂÒµ¡£

1Ôª 10Ôª 50Ôª





ÈÏÖ¤Â룺  ÑéÖ¤Âë,¿´²»Çå³þ?Çëµã»÷Ë¢ÐÂÑéÖ¤Âë ±ØÌî



  ÇóÖª ÎÄÕ ÎÄ¿â Lib ÊÓÆµ iPerson ¿Î³Ì ÈÏÖ¤ ×Éѯ ¹¤¾ß ½²×ù Modeler   Code  
»áÔ±   
 
   
 
 
     
   
 ¶©ÔÄ
  ¾èÖú
WebÓ¦ÓýøÐÐXSS©¶´²âÊÔ
 
×÷Õß seiitsu£¬»ðÁú¹ûÈí¼þ    ·¢²¼ÓÚ 2014-07-16
  9008  次浏览      28
 

¶Ô WEB Ó¦ÓýøÐÐ XSS ©¶´²âÊÔ£¬²»Äܽö½ö¾ÖÏÞÓÚÔÚ WEB Ò³ÃæÊäÈë XSS ¹¥»÷×ֶΣ¬È»ºóÌá½»¡£Èƹý JavaScript µÄ¼ì²â£¬ÊäÈë XSS ½Å±¾£¬Í¨³£±»²âÊÔÈËÔ±ºöÂÔ¡£ÏÂͼΪ XSS ¶ñÒâÊäÈëÈÆ¹ý JavaScript ¼ì²âµÄ¹¥»÷·¾¶¡£

³£¼ûµÄ XSS ÊäÈë

XSS ÊäÈëͨ³£°üº¬ JavaScript ½Å±¾£¬È絯³ö¶ñÒ⾯¸æ¿ò£º<script>alert("XSS");</script>

XSS ÊäÈëÒ²¿ÉÄÜÊÇ HTML ´úÂë¶Î£¬Æ©È磺

ÍøÒ³²»Í£µØË¢Ð <meta http-equiv="refresh" content="0;">

ǶÈëÆäËüÍøÕ¾µÄÁ´½Ó <iframe src=http://xxxx width=250 height=250></iframe>

XSS (Cross Site Scripting) Cheat Sheet ά»¤ÁËÒ»·Ý³£¼ûµÄ XSS ¹¥»÷½Å±¾ÁÐ±í£¬¿ÉÓÃÀ´×÷Ϊ¼ì²â WEB Ó¦ÓÃÊÇ·ñ´æÔÚ XSS ©¶´µÄ²âÊÔÓÃÀýÊäÈë¡£³õ´Î½Ó´¥ XSS ¹¥»÷µÄ¿ª·¢ÈËÔ±¿ÉÄÜ»á¶ÔÁбíÌṩµÄһЩ XSS ÊäÈë²»ÊǺÜÀí½â£¬±¾Îĵڶþ²¿·Ö½«»áÕë¶Ô²»Í¬´úÂëÉÏÏÂÎÄµÄ XSS ÊäÈë×÷½øÒ»²½µÄ½âÊÍ¡£

²âÊÔ¹¤¾ß

ºÜ¶à¹¤¾ß¿ÉÒÔÔÚä¯ÀÀÆ÷·¢ËÍ Get/Post ÇëÇóǰ½«Æä½ØÈ¡£¬¹¥»÷Õß¿ÉÒÔÐÞ¸ÄÇëÇóÖеÄÊý¾Ý£¬´Ó¶øÈƹý JavaScript µÄ¼ìÑ齫¶ñÒâÊý¾Ý×¢Èë·þÎñÆ÷¡£ÒÔÏÂÊÇһЩ³£ÓõĽØÈ¡ HTTP ÇëÇóµÄ¹¤¾ßÁÐ±í¡£

Paros proxy (http://www.parosproxy.org)
Fiddler (http://www.fiddlertool.com/fiddler)
Burp proxy (http://www.portswigger.net/proxy/)
TamperIE (http://www.bayden.com/dl/TamperIESetup.exe)

±ÊÕßÔø¾­Ê¹Óà TamperIE ¶Ô WEB Ó¦ÓýøÐа²È«ÐÔ²âÊÔ¡£TamperIE СÇÉÒ×Óã¬Äܹ»½ØÈ¡ IE ä¯ÀÀÆ÷·¢Ë굀 Get/Post ÇëÇó£¬ÉõÖÁÄÜÈÆ¹ý SSL ¼ÓÃÜ¡£²»¹ý TamperIE + IE7 ¹¤×÷²»Îȶ¨¡£IE7 ÌṩÁË¶Ô IPV6 µÄÖ§³Ö£¬Èç¹ûÄã²¢²»¼Æ»®²âÊÔÄãµÄ Web Ó¦ÓÃ¶Ô IPV6 µÄÖ§³Ö£¬½¨Ò黹ÊÇʹÓà TamperIE + IE6 µÄ×éºÏ¡£

Èçͼ2Ëùʾ: TamperIE ÈÆ¹ý¿Í»§¶Ëä¯ÀÀÆ÷ JavaScript µÄУÑ飬ÔÚ POST ÇëÇóÌύʱ½«Æä½ØÈ¡£¬Óû§¿ÉÒÔÈÎÒâÐÞ¸Ä±íµ¥ÊäÈëÏî name ºÍ message µÄÖµ£¬Æ©È罫 message µÄÖµÐÞ¸ÄΪ "<script>alert(¡°XSS hole!!¡±);</script>"£¬È»ºóµã»÷ ¡±Send altered data¡± °´Å¥£¬½«Ð޸ĺóµÄ¶ñÒâÊý¾Ý·¢Ë͸ø Web ·þÎñÆ÷¡£

ͼ 2. ʹÓà TamperIE ½ØÈ¡ Post ÇëÇó

ÔÚÊä³ö¶Ë¶Ô¶¯Ì¬ÄÚÈݽøÐбàÂë

¶ÔÒ»¸ö Web Ó¦ÓöøÑÔ£¬Æä¶¯Ì¬ÄÚÈÝ¿ÉÄÜÀ´Ô´ÓÚÓû§ÊäÈë¡¢ºǫ́Êý¾Ý¿â¡¢Ó²¼þ״̬¸Ä±ä»òÊÇÍøÂçÐÅÏ¢µÈ¡£¶¯Ì¬ÄÚÈÝÌØ±ðÊÇÀ´×ÔÓû§ÊäÈëµÄ¶¯Ì¬ÄÚÈݺÜÓпÉÄܰüº¬¶ñÒâÊý¾Ý£¬´Ó¶øÓ°ÏìÍøÒ³µÄÕý³£ÏÔʾ»òÊÇÖ´ÐжñÒâ½Å±¾¡£½«¶¯Ì¬ÄÚÈݰ²È«µØÏÔʾÔÚä¯ÀÀÆ÷¶ËÓ붯̬ÄÚÈÝËù´¦µÄÉÏÏÂÎı³¾°Óйأ¬Æ©È綯̬ÄÚÈÝ´¦ÔÚ HTML ÕýÎÄ¡¢±íµ¥ÔªËصÄÊôÐÔ¡¢»òÊÇ JavaScript ´úÂë¶ÎÖС£¶ÔÓÚÒ»¸ö»ùÓÚ PHP ÓïÑ﵀ Web Ó¦Ó㬵±Ö´ÐÐ"echo"¡¢"print"¡¢"printf"¡¢"<?=" µÈÓï¾äʱ±íʾÕýÔÚ´¦Àí¶¯Ì¬ÄÚÈÝ¡£±¾½Ú½«Ê×ÏȽéÉÜ PHP ÌṩµÄ¿âº¯Êý htmlspecialchars()µÄÓ÷¨£¬´Ëº¯ÊýÄܽ« 5 ¸ö HTML ÌØÊâ×Ö·ûת»¯Îª¿ÉÔÚÍøÒ³ÏÔʾµÄ HTML ʵÌå±àÂ룻Ȼºó½«½éÉÜһЩ³£¼û±³¾°Ï嵀 XSS ¹¥»÷ÊäÈ룬ÒÔ¼°ÈçºÎÔÚÊä³ö¶Ë¶Ô¶¯Ì¬ÄÚÈݽøÐÐתÒå¡¢±àÂë´Ó¶ø±ÜÃâ XSS ¹¥»÷¡£

ʹÓà PHP µÄ htmlspecialchars() ÏÔʾ HTML ÌØÊâ×Ö·û

´ÓÉÏÎÄÁÐ¾ÙµÄ XSS ¶ñÒâÊäÈë¿ÉÒÔ¿´µ½£¬ÕâЩÊäÈëÖаüº¬ÁËÒ»Ð©ÌØÊâµÄ HTML ×Ö·ûÈç "<"¡¢">"¡£µ±´«Ë͵½¿Í»§¶Ëä¯ÀÀÆ÷ÏÔʾʱ£¬ä¯ÀÀÆ÷»á½âÊÍÖ´ÐÐÕâЩ HTML »òJavaScript ´úÂë¶ø²»ÊÇÖ±½ÓÏÔʾÕâЩ×Ö·û´®¡£< > & ¡° µÈ×Ö·ûÔÚHTMLÓïÑÔÖÐÓÐÌØÊ⺬Ò壬¶ÔÓÚÓû§ÊäÈëµÄÌØÊâ×Ö·û£¬ÈçºÎÖ±½ÓÏÔʾÔÚÍøÒ³Öжø²»ÊDZ»ä¯ÀÀÆ÷µ±×÷ÌØÊâ×Ö·û½øÐнâÎö?

HTML×Ö·ûʵÌåÓÉ & ·ûºÅ¡¢ÊµÌåÃû×Ö»òÕß # ¼ÓÉÏʵÌå±àºÅ¡¢·ÖºÅÈý²¿·Ö×é³É¡£ÒÔÏÂΪ HTML ÖÐÒ»Ð©ÌØÊâ×Ö·ûµÄ±àÂë¡£ÓеÄ×Ö·ûʵÌåÖ»ÓÐʵÌå±àºÅ£¬Ã»ÓжÔÓ¦µÄʵÌåÃû×Ö£¬Æ©Èçµ¥ÒýºÅ¡£

PHP ÌṩÁËhtmlspecialchars()º¯Êý¿ÉÒÔ½« HTML ÌØÊâ×Ö·ûת»¯³ÉÔÚÍøÒ³ÉÏÏÔʾµÄ×Ö·ûʵÌå±àÂë¡£ÕâÑù¼´Ê¹Óû§ÊäÈëÁ˸÷ÖÖ HTML ±ê¼Ç£¬ÔÚ¶Á»Øµ½ä¯ÀÀÆ÷ʱ£¬»áÖ±½ÓÏÔʾÕâЩ HTML ±ê¼Ç£¬¶ø²»ÊǽâÊÍÖ´ÐС£htmlspecialchars()º¯Êý¿ÉÒÔ½«ÒÔÏÂÎåÖÖ HTML ÌØÊâ×Ö·ûת³É×Ö·ûʵÌå±àÂ룺

& ת³É &
¡° ת³É "
< ת³É <
> ת³É >
¡® ת³É '

µ±Ö±½Óµ÷Óà htmlspecialchars($str)ʱ, & " < > ±»×ªÒå¡£

µ±ÉèÖà ENT_QUOTES ±ê¼Çʱ, ¼´µ÷ÓÃhtmlspecialchars($str, ENT_QUOTES)ʱ£¬µ¥ÒýºÅÒ²±»×ªÒå¡£

µ±ÉèÖà ENT_NOQUOTES ±ê¼Çʱ£¬µ¥ÒýºÅºÍË«ÒýºÅ¶¼²»»á±»×ªÒå¡£¼´µ÷Óà htmlspecialchars($str, ENT_NOQUOTES)ʱ£¬Ö»ÓÐ& < > ±»×ªÒå¡£

²»Í¬±³¾°ÏµĶ¯Ì¬ÄÚÈÝµÄ XSS ¹¥»÷¼°½â¾ö·½°¸

XSS ¹¥»÷ÊäÈëÓ붯̬ÄÚÈÝËù´¦µÄ´úÂë±³¾°Ïà¹Ø£¬Æ©È綯̬ÄÚÈÝΪ±íµ¥ÔªËØÊôÐÔµÄÖµ¡¢Î»ÓÚ HTML ÕýÎÄ¡¢»òÊÇ Javascript ´úÂë¶ÎÖеȵȡ£

HTML±ê¼ÇµÄÊôÐÔΪ¶¯Ì¬ÄÚÈÝ

Web Ó¦ÓÃÖУ¬"input"¡¢"style"¡¢"color" µÈ HTML ±ê¼ÇµÄÊôÐÔ¶¼¿ÉÄÜΪ¶¯Ì¬ÄÚÈÝ£¬ÆäÖÐ"input" ±ê¼ÇµÄ "value" ÊôÐÔͨ³£Îª¶¯Ì¬ÄÚÈÝ¡£

Àý×Ó1

<form¡­><INPUT type=text name="msg" id="msg" size=10 maxlength=8 value="<?= $msg?>"></form>

¹¥»÷XSSÊäÈë

Hello"><script>evil_script()</script>

½«¶¯Ì¬ÄÚÈÝÌæ»»

½« $msg Ìæ»»Îª¶ñÒâ XSS ÊäÈë:

<form¡­><INPUT type=text name="msg" id="msg" size=10 maxlength=8 
value="Hello"><script>evil_script()</script>"></form>

Àý×Ó2

<form¡­><INPUT type=text name="msg" id="msg" size=10 maxlength=8 value=<?= $msg?>></form>

¹¥»÷ XSS ÊäÈë

Hello onmouseover=evil_script()

½«¶¯Ì¬ÄÚÈÝÌæ»»

½« $msg Ìæ»»Îª¶ñÒâ XSS ÊäÈë:

<form¡­><INPUT type=text name="msg" id="msg" size=10 maxlength=8 
value=Hello onmouseover=evil_script()></form>

·ÖÎö

´ÓÀý×Ó 1 ¿ÉÒÔ¿´µ½Æä XSS¹¥»÷ÊäÈëÖаüº¬ÁË HTML ÌØÊâ×Ö·û < > "

´ÓÀý×Ó 2 ¿ÉÒÔ¿´µ½Æä XSS ¹¥»÷ÊäÈëÖÐûÓаüº¬ÉϽÚÖÐÌáµ½µÄÎåÖÖ HTML ×Ö·û£¬ µ«ÊÇ "value"ÊôÐÔֵûÓÐʹÓÃË«ÒýºÅ°üΧ¡£

½â¾ö·½°¸

µ÷ÓÃhtmlspecialchars($str, ENT_QUOTES)½«ÒÔÏ 5 ÖÖ HTML ÌØÊâ×Ö·û < > &¡® ¡° תÒ壻ͬʱʹÊôÐÔÖµ±»Ë«ÒýºÅ°üΧ¡£Æ©È磺

<form¡­><INPUT type=text name="msg" id="msg" size=10 maxlength=8 
value="<?= htmlspecialchars($msg, ENT_QUOTES))?>"></form>

×¢ÒâÊÂÏî

½« input µÄ value ½øÐÐתÒ壬±ØÐ뿼ÂÇÏÔʾºÍ´æ´¢Êý¾ÝµÄÒ»ÖÂÐÔÎÊÌ⣬¼´ÏÔʾÔÚä¯ÀÀÆ÷¶ËºÍ´æ´¢ÔÚ·þÎñÆ÷¶Ëºǫ́µÄÊý¾Ý¿ÉÄÜÒòΪתÒå¶ø±äµÃ²»Ò»Ö¡£Æ©Èç´æ´¢ÔÚ·þÎñÆ÷¶ËµÄºǫ́ԭʼÊý¾Ý°üº¬ÁËÒÔÉÏ 5 ÖÖÌØÊâ×Ö·û£¬µ«ÊÇûÓÐתÒ壬ΪÁË·ÀÖ¹ XSS ¹¥»÷£¬ÔÚä¯ÀÀÆ÷¶ËÊä³öʱ¶Ô HTML ÌØÊâ×Ö·û½øÐÐÁËתÒ壺

1. µ±ÔٶȽ«±íµ¥Ìύʱ£¬´æ´¢µÄÄÚÈݽ«»á±ä³ÉתÒåºóµÄÖµ¡£

2. µ±Ê¹Óà JavaScript ²Ù×÷±íµ¥ÔªËØ£¬ÐèҪʹÓõ½±íµ¥ÔªËصÄֵʱ£¬±ØÐ뿼Âǵ½Öµ¿ÉÄÜÒѾ­±»×ªÒå¡£

HTMLÎı¾Îª¶¯Ì¬ÄÚÈÝ

Àý×Ó

<b> »¶Ó­£º<?= $welcome_msg?></b>
¹¥»÷XSSÊäÈë
<script>evil_script()</script>
½«¶¯Ì¬ÄÚÈÝÌæ»»
½«$welcome_msg Ìæ»»Îª¶ñÒâ XSS ÊäÈë:
<b>»¶Ó­£º<script>evil_script()</script></b>

·ÖÎö

ÔÚ HTML ÕýÎı³¾°Ï£¬< > ×Ö·û»áÒýÈë HTML ±ê¼Ç£¬& ¿ÉÄÜ»áÈÏΪ×Ö·ûʵÌå±àÂëµÄ¿ªÊ¼£¬ËùÒÔÐèÒª½« < > & תÒå

½â¾ö·½°¸

Ϊ¼ò½àÆð¼û£¬Ö±½ÓʹÓà htmlspecialchars()½« 5 ÖÖ HTML ÌØÊâ×Ö·ûתÒ壬È磺

<b>»¶Ó­£º<?= htmlspecialchars($welcome_msg,, ENT_NOQUOTES)?></b>

URLµÄֵΪ¶¯Ì¬ÄÚÈÝ

Script/Style/Img/ActiveX/Applet/Frameset¡­ µÈ±ê¼ÇµÄ src »ò href ÊôÐÔÈç¹ûΪ¶¯Ì¬ÄÚÈÝ£¬±ØÐëÈ·±£ÕâЩ URL ûÓÐÖ¸Ïò¶ñÒâÁ´½Ó¡£

Àý×Ó1

<script src=<?= "$script_url>">
¹¥»÷XSSÊäÈë
http://evil.org/evil.js
½«¶¯Ì¬ÄÚÈÝÌæ»»
½«$script_urlÌæ»»Îª¶ñÒâ XSS ÊäÈë:
<script src="http://evil.org/evil.js">

Àý×Ó2

<img src=¡±<?= $img_url>¡±>
¹¥»÷XSSÊäÈë
javascript:evil_script()
½«¶¯Ì¬ÄÚÈÝÌæ»»
½«$img_urlÌæ»»Îª¶ñÒâXSSÊäÈë:
<img src=¡± javascript:evil_script()¡±>

·ÖÎö

Ò»°ãÇé¿öϾ¡Á¿²»ÒªÈà URL µÄÖµ±»Óû§¿ØÖÆ¡£Èç¹ûÓû§ÐèÒª×Ô¼º¶¨Òå×Ô¼ºµÄ·ç¸ñ¼°ÏÔʾЧ¹û£¬Ò²²»ÄÜÈÃÓû§Ö±½Ó¿ØÖÆÕû¸ö URL µÄÄÚÈÝ£¬¶øÊÇÌṩԤ¶¨ÒåºÃµÄ·ç¸ñ¹©Óû§ÉèÖá¢×°Å䣬ȻºóÓɺǫ́³ÌÐò¸ù¾ÝÓû§µÄÑ¡Ôñ×éºÏ³É°²È«µÄ URL Êä³ö¡£

×Ö·û¼¯±àÂë

ä¯ÀÀÆ÷ÐèÒªÖªµÀ×Ö·û¼¯±àÂë²ÅÄÜÕýÈ·µØÏÔÊ¾ÍøÒ³¡£Èç¹û×Ö·û¼¯±àÂëûÓÐÏÔʽÔÚ content-type »òmeta Öж¨Ò壬ä¯ÀÀÆ÷»áÓÐËã·¨²Â²âÍøÒ³µÄ×Ö·û¼¯±àÂ롣ƩÈç<script>alert(document.cookie)</script> µÄ UTF-7 ±àÂëΪ£º

+ADw-script+AD4-alert(document.cookie)+ADw-/script+AD4-

Èç¹û+ADw-script+AD4-alert(document.cookie)+ADw-/script+AD4-×÷Ϊ¶¯Ì¬ÄÚÈÝλÓÚÍøÒ³µÄ¶¥¶Ë²¢´«Ë͵½ä¯ÀÀÆ÷¶Ë£¬IE »áÈÏΪ´ËÍøÒ³ÊÇ UTF-7 ±àÂ룬´Ó¶øÊ¹ÍøÒ³²»ÄÜÕý³£ÏÔʾ¡£

½â¾ö·½°¸

ÏÔʽ¶¨ÒåÍøÒ³µÄ×Ö·û¼¯±àÂ룬ƩÈç

<meta http-equiv=content-type content="text/html; charset=UTF-8">

¶¯Ì¬ÄÚÈÝΪJavaScriptʼþ´¦Àíº¯ÊýµÄ²ÎÊý

JavaScript ʼþ´¦Àíº¯ÊýÈç onClick/onLoad/onError/onMouseOver/ µÄ²ÎÊý¿ÉÄܰüº¬¶¯Ì¬ÄÚÈÝ¡£

Àý×Ó

<input type="button" value="go to" onClick='goto_url("<?= $target_url>");'>
¹¥»÷XSSÊäÈë
foo");evil_script("
½«¶¯Ì¬ÄÚÈÝÌæ»»
HTML ½âÎöÆ÷»áÏÈÓÚ JavaScript ½âÎöÆ÷½âÎöÍøÒ³£¬½«$target_url Ìæ»»Îª¶ñÒâ XSS ÊäÈë:
<input type="button" value="go to" onClick='goto_url("foo");evil_script("");'>
¶¯Ì¬ÄÚÈÝλÓÚ JavaScript ´úÂë¶ÎÖÐ

Àý×Ó

<SCRIPT language="javascript1.2"> var msg='<?= $welcome_msg?> '; // ¡­ </SCRIPT>
¹¥»÷XSSÊäÈë1
Hello'; evil_script(); //
½«¶¯Ì¬ÄÚÈÝÌæ»»
½« $welcome_msg Ìæ»»Îª¶ñÒâ XSS ÊäÈë:
<SCRIPT language="javascript1.2"> var msg='Hello'; evil_script(); //'; // ¡­ </SCRIPT>
¹¥»÷XSSÊäÈë2
Hello</script><script>evil_script();</script><script>
½«¶¯Ì¬ÄÚÈÝÌæ»»
½«$welcome_msg Ìæ»»Îª¶ñÒâ XSS ÊäÈë:
<script> var msg = 'Hello</script> <script>evil_script();</script> <script>' // ... // do something with msg_text </script>

·ÖÎö

ÈçÉÏÎÄËùʾ£¬ÔÚ JavaScript ±³¾°ÖÐʹÓö¯Ì¬ÄÚÈÝÐèÒª·Ç³£½÷É÷¡£Ò»°ãÇé¿öÏ£¬¾¡Á¿±ÜÃâ»ò¼õÉÙÔÚ Javascript µÄ±³¾°ÏÂʹÓö¯Ì¬ÄÚÈÝ£¬Èç¹û±ØÐëʹÓö¯Ì¬ÄÚÈÝ£¬ÔÚ¿ª·¢»ò´úÂëÉó¼ÆÊ±±ØÐ뿼ÂÇÕâЩ¶¯Ì¬ÄÚÈÝ¿ÉÄܵÄȡֵ£¬ÊÇ·ñ»áµ¼Ö XSS ¹¥»÷¡£

½¨Á¢PHP¿âº¯ÊýУÑéÊäÈë

Web ¿ª·¢ÈËÔ±±ØÐëÁ˽⣬½ö½öÔÚ¿Í»§¶ËʹÓà JavaScript º¯Êý¶Ô·Ç·¨ÊäÈë½øÐмì²â¹ýÂ˶ÔÓÚ¹¹½¨°²È«µÄ WEB Ó¦ÓÃÊDz»¹»µÄ¡£ÈçÉÏÎÄËùÊö£¬¹¥»÷Õß¿ÉÒÔÇáÒ׵ؽèÖú¹¤¾ßÈÆ¹ý JavaScript УÑéÉõÖÁ SSL ¼ÓÃÜÊäÈë¶ñÒâÊý¾Ý¡£ÔÚÊä³ö¶Ë¶Ô¶¯Ì¬ÄÚÈݽøÐбàÂëÒ²Ö»ÄÜÆðµ½Ò»ÖÖË«ÖØ±£»¤µÄ×÷Ó㬸üÖØÒªµÄÓ¦¸ÃÔÚ·þÎñÆ÷¶Ë¶ÔÊäÈë½øÐÐУÑé¡£PHP ÌṩÁËstrpos()¡¢strstr()¡¢preg_match()µÈº¯Êý¿ÉÓÃÓÚ¼ì²â·Ç·¨×Ö·ûºÍ×Ö·û´®£»preg_replace() º¯Êý¿ÉÓÃÓÚÌæ»»·Ç·¨×Ö·û´®¡£OWASP PHP Filters ¿ªÔ´ÏîÄ¿ÌṩÁËһЩ PHP ¿âº¯ÊýÓÃÓÚ¹ýÂË·Ç·¨ÊäÈë¿É×÷Ϊ²Î¿¼¡£Ò»Ð©³£¼ûµÄ¼ì²âºÍ¹ýÂ˰üÀ¨£º

ÊäÈëÊÇ·ñ½ö½ö°üº¬ºÏ·¨µÄ×Ö·û£»

ÊäÈëÈç¹ûΪÊý×Ö£¬Êý×ÖÊÇ·ñÔÚÖ¸¶¨µÄ·¶Î§£»

ÊäÈë×Ö·û´®ÊÇ·ñ³¬¹ý×î´ó³¤¶ÈÏÞÖÆ£»

ÊäÈëÊÇ·ñ·ûºÏÌØÊâµÄ¸ñʽҪÇ󣬯©Èçemail µØÖ·¡¢IP µØÖ·£»

²»Í¬µÄÊäÈë¿òÔÚÂß¼­ÉÏ´æÔÚµÄñîºÏºÍÏÞÖÆµÄ¹ØÏµ£»

³ýÈ¥ÊäÈëÊ×βµÄ¿Õ¸ñ£»

×ܽá

Web Ó¦ÓõݲȫÐÔÊÇÒ»¸öºÜÖØÒª¡¢¸²¸Ç·¶Î§ºÜ¹ã·ºµÄÖ÷Ì⡣ΪÁË·ÀÖ¹³£¼ûµÄ XSS µÄ¹¥»÷£¬Web ¿ª·¢ÈËÔ±±ØÐëÃ÷°×²»Äܽö½öÖ»ÔÚ¿Í»§¶ËʹÓà JavaScript ¶ÔÊäÈë½øÐмì²â¡¢¹ýÂË£»Í¬Ê±»¹Ó¦½¨Á¢·þÎñÆ÷¶ËµÄÊäÈëУÑé¡¢Êä³ö±àÂë¿âº¯Êý£»ÔÚ·þÎñÆ÷¶Ë¼ì²â¡¢¹ýÂËÊäÈ룻¸ù¾Ý¶¯Ì¬ÄÚÈÝËù´¦µÄ±³¾°½«ÌØÊâ×Ö·û½øÐбàÂëºóÔÙ´«Ë͸øä¯ÀÀÆ÷¶ËÏÔʾ¡£

   
9008 ´Îä¯ÀÀ       28
Ïà¹ØÎÄÕÂ

΢·þÎñ²âÊÔÖ®µ¥Ôª²âÊÔ
һƪͼÎÄ´øÄãÁ˽â°×ºÐ²âÊÔÓÃÀýÉè¼Æ·½·¨
È«ÃæµÄÖÊÁ¿±£ÕÏÌåϵ֮»Ø¹é²âÊÔ²ßÂÔ
È˹¤ÖÇÄÜ×Ô¶¯»¯²âÊÔ̽Ë÷
Ïà¹ØÎĵµ

×Ô¶¯»¯½Ó¿Ú²âÊÔʵ¼ù֮·
jenkins³ÖÐø¼¯³É²âÊÔ
ÐÔÄܲâÊÔÕï¶Ï·ÖÎöÓëÓÅ»¯
ÐÔÄܲâÊÔʵÀý
Ïà¹Ø¿Î³Ì

³ÖÐø¼¯³É²âÊÔ×î¼Ñʵ¼ù
×Ô¶¯»¯²âÊÔÌåϵ½¨ÉèÓë×î¼Ñʵ¼ù
²âÊԼܹ¹µÄ¹¹½¨ÓëÓ¦ÓÃʵ¼ù
DevOpsʱ´úµÄ²âÊÔ¼¼ÊõÓë×î¼Ñʵ¼ù
×îл¼Æ»®
DeepSeekÔÚÈí¼þ²âÊÔÓ¦ÓÃʵ¼ù 4-12[ÔÚÏß]
DeepSeek´óÄ£ÐÍÓ¦Óÿª·¢Êµ¼ù 4-19[ÔÚÏß]
UAF¼Ü¹¹ÌåϵÓëʵ¼ù 4-11[±±¾©]
AIÖÇÄÜ»¯Èí¼þ²âÊÔ·½·¨Óëʵ¼ù 5-23[ÉϺ£]
»ùÓÚ UML ºÍEA½øÐзÖÎöÉè¼Æ 4-26[±±¾©]
ÒµÎñ¼Ü¹¹Éè¼ÆÓ뽨ģ 4-18[±±¾©]

LoadRunnerÐÔÄܲâÊÔ»ù´¡
Èí¼þ²âÊÔ½á¹û·ÖÎöºÍÖÊÁ¿±¨¸æ
ÃæÏò¶ÔÏóÈí¼þ²âÊÔ¼¼ÊõÑо¿
Éè¼Æ²âÊÔÓÃÀýµÄËÄÌõÔ­Ôò
¹¦ÄܲâÊÔÖйÊÕÏÄ£Ð͵Ľ¨Á¢
ÐÔÄܲâÊÔ×ÛÊö


ÐÔÄܲâÊÔ·½·¨Óë¼¼Êõ
²âÊÔ¹ý³ÌÓëÍŶӹÜÀí
LoadRunner½øÐÐÐÔÄܲâÊÔ
WEBÓ¦ÓõÄÈí¼þ²âÊÔ
ÊÖ»úÈí¼þ²âÊÔ
°×ºÐ²âÊÔ·½·¨Óë¼¼Êõ


ij²©²ÊÐÐÒµ Êý¾Ý¿â×Ô¶¯»¯²âÊÔ
IT·þÎñÉÌ Web°²È«²âÊÔ
IT·þÎñÉÌ ×Ô¶¯»¯²âÊÔ¿ò¼Ü
º£º½¹É·Ý µ¥Ôª²âÊÔ¡¢Öع¹
²âÊÔÐèÇó·ÖÎöÓë²âÊÔÓÃÀý·ÖÎö
»¥ÁªÍøweb²âÊÔ·½·¨Óëʵ¼ù
»ùÓÚSeleniumµÄWeb×Ô¶¯»¯²âÊÔ