Äú¿ÉÒÔ¾èÖú£¬Ö§³ÖÎÒÃǵĹ«ÒæÊÂÒµ¡£

1Ôª 10Ôª 50Ôª





ÈÏÖ¤Â룺  ÑéÖ¤Âë,¿´²»Çå³þ?Çëµã»÷Ë¢ÐÂÑéÖ¤Âë ±ØÌî



  ÇóÖª ÎÄÕ ÎÄ¿â Lib ÊÓÆµ iPerson ¿Î³Ì ÈÏÖ¤ ×Éѯ ¹¤¾ß ½²×ù Model Center   Code  
»áÔ±   
   
 
     
   
 ¶©ÔÄ
  ¾èÖú
Web°²È«Ö®XSS¹¥»÷Óë·ÀÓùС½á
 
×÷ÕߣºCynthia£¨Ð¡Ó¢×Ó£©
  2136  次浏览      31
2020-12-10
 
±à¼­ÍƼö:
±¾ÎĽéÉÜÁËWeb°²È«Ö®XSS¹¥»÷Óë·ÀÓùС½á£¬XSSµÄ¶¨Òå¡¢Ô­Àí¡¢¹¥»÷·½Ê½¡¢·ÀÓù´ëÊ©¼°Ó¦ÓÃʾÀý£¬ Ï£Íû¶ÔÄúµÄѧϰÓÐËù°ïÖú¡£
±¾ÎÄÀ´×ÔÓڽű¾Ö®¼Ò£¬ÓÉ»ðÁú¹ûÈí¼þLinda±à¼­¡¢ÍƼö¡£

Web°²È«Ö®XSS¹¥·À

1. XSSµÄ¶¨Òå

¿çÕ¾½Å±¾¹¥»÷(Cross Site Scripting)£¬ËõдΪXSS¡£¶ñÒâ¹¥»÷ÕßÍùWebÒ³ÃæÀï²åÈë¶ñÒâScript´úÂ룬µ±Óû§ä¯ÀÀ¸Ãҳ֮ʱ£¬Ç¶ÈëÆäÖÐWebÀïÃæµÄScript´úÂë»á±»Ö´ÐУ¬´Ó¶ø´ïµ½¶ñÒâ¹¥»÷Óû§µÄÄ¿µÄ¡£

2. XSSµÄÔ­Àí

¹¥»÷Õß¶Ôº¬ÓЩ¶´µÄ·þÎñÆ÷·¢ÆðXSS¹¥»÷£¨×¢ÈëJS´úÂ룩¡£

ÓÕʹÊܺ¦Õß´ò¿ªÊܵ½¹¥»÷µÄ·þÎñÆ÷URL¡£

Êܺ¦ÕßÔÚWebä¯ÀÀÆ÷Öдò¿ªURL£¬¶ñÒâ½Å±¾Ö´ÐС£

3. XSSµÄ¹¥»÷·½Ê½

£¨1£©·´ÉäÐÍ£º ·¢³öÇëÇóʱ£¬XSS´úÂë³öÏÖÔÚURLÖУ¬×÷ΪÊäÈëÌá½»µ½·þÎñÆ÷¶Ë£¬·þÎñÆ÷¶Ë½âÎöºóÏìÓ¦£¬XSSËæÏìÓ¦ÄÚÈÝÒ»Æð·µ»Ø¸øä¯ÀÀÆ÷£¬×îºóä¯ÀÀÆ÷½âÎöÖ´ÐÐXSS´úÂ룬Õâ¸ö¹ý³Ì¾ÍÏñÒ»´Î·¢É䣬ËùÒԽз´ÉäÐÍXSS¡£

£¨2£©´æ´¢ÐÍ: ´æ´¢ÐÍXSSºÍ·´ÉäÐ͵ÄXSS²î±ð¾ÍÔÚÓÚ£¬´æ´¢Ð͵ÄXSSÌá½»µÄ´úÂë»á´æ´¢ÔÚ·þÎñÆ÷¶Ë£¨Êý¾Ý¿â£¬Äڴ棬ÎļþϵͳµÈ£©£¬Ï´ÎÇëÇóÄ¿±êÒ³ÃæÊ±²»ÓÃÔÙÌá½»XSS´úÂë¡£

4. XSSµÄ·ÀÓù´ëÊ©

£¨1£©±àÂ룺¶ÔÓû§ÊäÈëµÄÊý¾Ý½øÐÐHTML Entity±àÂë

£¨2£©¹ýÂË£ºÒƳýÓû§ÉÏ´«µÄDOMÊôÐÔ£¬ÈçonerrorµÈ£¬ÒƳýÓû§ÉÏ´«µÄstyle½Úµã£¬script½Úµã£¬iframe½ÚµãµÈ¡£

£¨3£©Ð£Õý£º±ÜÃâÖ±½Ó¶ÔHTML Entity±àÂ룬ʹÓÃDOM Praseת»»£¬Ð£Õý²»Åä¶ÔµÄDOM±êÇ©¡£

5. Ó¦ÓÃʾÀý

¹¹½¨nodeÓ¦Óã¬ÑÝʾ·´ÉäÐÍXSS¹¥»÷¡££¨Linux²Ù×÷ϵͳÖУ©

±¾Àý×ӵĴúÂëµØÖ·£ºhttps://github.com/Xganying/Web-XSS £¨xss_test1£©

(1) н¨Ò»¸öÎļþ¼Ðxss£º mkdir xss_test1

(2) Çл»Ä¿Â¼µ½¸ÃÎļþ¼ÐÏ£º cd xss

(3) °²×°express: express -e ./

(4) ¹¹½¨Ó¦ÓÃÒÀÀµ£º npm install

(5) ´ò¿ª¹¹½¨ºÃµÄnodeÓ¦Ó㬵õ½Ä¿Â¼£º

(6) ¿ªÆônode·þÎñ£ºnpm start

(7) ÔÚä¯ÀÀÆ÷µØÖ·À¸ÊäÈ룺localhost:3000 ,µÃµ½£º

(8) ¼ÓÈëxss

ÐÞ¸Äxss_test1ÎļþroutersÄ¿åhϵÄindex.jsÎļþ£º

ÐÞ¸Äxss_test1ÎļþviewsĿ¼ÏµÄindex.ejsÎļþ£º

(9) ÖØÆônode·þÎñ£ºnpm start £¬´ò¿ªä¯ÀÀÆ÷

a. ÔÚµØÖ·À¸ÊäÈë: localhost:3000/?xss=hello

ÔËÐнá¹ûµÃµ½£º

b. ÔÚµØÖ·À¸ÊäÈ룺localhost:3000/?xss=<img src="null" onerror="alert(1)">

ÔËÐнá¹ûµÃµ½£º

˵Ã÷£º Èç¹û´úÂëÖÐûÓÐ res.set('X-XSS-Protection', 0); Ôò»á·¢ÏÖûÓе¯³ö¿ò£¬ÕâÊÇÒòΪä¯ÀÀÆ÷×Ô¶¯ÉèÖÃÁËÀ¹½ØXSS£¬ËùÒÔonerrorʼþ²¢²»»áÖ´ÐУ¬¶ø¼ÓÉÏÁË£ºres.set('X-XSS-Protection', 0); ²Å»á³öÏÖµ¯¿ò£¬Õâ²ÅÍê³ÉÁËÒ»´Îxss¹¥»÷¡£

c. ÔÚµØÖ·À¸ÊäÈ룺localhost:3000/?xss=<p onclick="alert(%µãÎÒ%)">µãÎÒ</p>

ÔËÐнá¹ûµÃµ½£º

˵Ã÷£º ÕâÖÖ¹¥»÷¾ÍÊdz£ÓÃÓÚ´Û¸ÄÒ³ÃæÄÚÈÝ£¬ÆÆ»µÒ³Ãæ½á¹¹£¬ÒýÓÕÓû§È¥µã»÷һЩµöÓãµÈÍøÕ¾µÄÊֶΡ£

d. ÔÚµØÖ·À¸ÊäÈ룺localhost:3000/?xss=<iframe src="//baidu.com/t.html"></iframe>

ÔËÐнá¹ûµÃµ½£º

˵Ã÷£ºÕâÖÖ¹¥»÷¾Í³£ÓÃÓÚ¹ã¸æÖ²ÈëµÈ¡£

¼òµ¥×ܽá¾ÍÊÇ£º img±êÇ©ÊÇ×Ô¶¯´¥·¢¶øÊܵ½¹¥»÷µÄ£¬p±êÇ©ÊÇÒýÓÕ³ö·¢¶øÊܵ½¹¥»÷µÄµÄ£¬¶øiframeÔòÊÇ¹ã¸æÖ²Èë¹¥»÷µÄ¡£

ÒÔÉϾÍÊDZ¾ÎĵÄÈ«²¿ÄÚÈÝ£¬Ï£Íû¶Ô´ó¼ÒµÄѧϰÓÐËù°ïÖú£¬Ò²Ï£Íû´ó¼Ò¶à¶àÖ§³Ö½Å±¾Ö®¼Ò¡£

 

   
2136 ´Îä¯ÀÀ       31
 
Ïà¹ØÎÄÕÂ

iOSÓ¦Óð²È«¿ª·¢£¬Äã²»ÖªµÀµÄÄÇЩÊÂÊõ
Web°²È«Ö®SQL×¢Èë¹¥»÷
ÒÆ¶¯APP°²È«ÔÚÉøÍ¸²âÊÔÖеÄÓ¦ÓÃ
´ÓGoogle±¸·Ý»¥ÁªÍø¿´¡°Êý¾Ý°²È«¡±
 
Ïà¹ØÎĵµ

web°²È«Éè¼ÆÓë·À»¤
»¥ÁªÍøº£Á¿ÄÚÈݰ²È«´¦Àí¼¼Êõ
ºÚ¿Í¹¥»÷Óë·À·¶¼¼Êõ
WEBºÚºÐ°²È«¼ì²â
 
Ïà¹Ø¿Î³Ì

WEBÍøÕ¾ÓëÓ¦Óð²È«Ô­ÀíÓëʵ¼ù
webÓ¦Óð²È«¼Ü¹¹Éè¼Æ
´´½¨°²È«µÄJ2EE WebÓ¦ÓôúÂë
ÐÅÏ¢°²È«ÎÊÌâÓë·À·¶
×îл¼Æ»®
DeepSeekÔÚÈí¼þ²âÊÔÓ¦ÓÃʵ¼ù 4-12[ÔÚÏß]
DeepSeek´óÄ£ÐÍÓ¦Óÿª·¢Êµ¼ù 4-19[ÔÚÏß]
UAF¼Ü¹¹ÌåϵÓëʵ¼ù 4-11[±±¾©]
AIÖÇÄÜ»¯Èí¼þ²âÊÔ·½·¨Óëʵ¼ù 5-23[ÉϺ£]
»ùÓÚ UML ºÍEA½øÐзÖÎöÉè¼Æ 4-26[±±¾©]
ÒµÎñ¼Ü¹¹Éè¼ÆÓ뽨ģ 4-18[±±¾©]
 
×îÐÂÎÄÕÂ
ÎïÁªÍø°²È«¸ÅÊö
Ê·ÉÏ×îÏêϸµÄÇø¿éÁ´¼¼Êõ¼Ü¹¹·ÖÎö
Ò»ÎĶÁ¶®Çø¿éÁ´ÕûÌå¼Ü¹¹¼°Ó¦Óð¸Àý
Çø¿éÁ´¼¼Êõ¼Ü¹¹
°²È«¼Ü¹¹ÆÀÉóʵս
×îпγÌ
WebÓ¦Óð²È«¼Ü¹¹¡¢ÈëÇÖ¼ì²âÓë·À»¤
ÎïÁªÍø¹Ø¼ü¼¼Êõ¡¢°²È«Óë±ßÔµ¼ÆËã
Çø¿éÁ´°²È«¼¼Êõʵ¼ùÖ¸ÄÏ
ÔÆ·þÎñÓ밲ȫ¼Ü¹¹
»¥ÁªÍø°²È«¿ª·¢·½·¨Óëʵ¼ù
³É¹¦°¸Àý
ÖйúÒøÐÐ ÐÅÏ¢°²È«¼¼Êõ¼°Éî¶È·ÀÓù
±±¾© WebÓ¦Óð²È«¼Ü¹¹¡¢ÈëÇÖ¼ì²âÓë·À»¤
ij²ÆË°ÁìÓòÖªÃûIT·þÎñÉÌ Web°²È«²âÊÔ
ÆÕÈð¿Ë˹ web°²È«Éè¼Æ¡¢²âÊÔÓëÓÅ»¯
±±¾©ºÍÀûʱ ÐÔÄܺͰ²È«ÐÔ²âÊÔ