ӦõļܹƺзǶܽ˹ȫӦõʮƴʩƺͿԱİȫʶӦõİȫԡʮʩУеĺܾ壬еֻͨõķ࣬еǼԵģеǹصġ
ָDzģԱӦõĻΪ˿ȫӦãҪΪṩҪİ֧֡дWeb ӦõԱҪպϰְȫļWeb Ӧõÿһ㣬û桢ҵԼݿ룬ڱдʱ뽫ȫμģǷdzѵһΪԱû̫లȫ֪ʶWeb ӦõԺͿڰȫͨȱҪĿơƽΣҲйеȱݣ֯ΪԱṩԼָDZдȫĴ롣 1. ѯ
SQL עWeb ӦΣյ©֮һΪSQL עΪױڿ̽һӦôԵĴֻWeb ӦעһĶSQLݿܾͻᱻȡߴ۸ġݿϣԽWeb ӦִΣյIJϵͳΪ˷ֹSQL ע룬ԱֹЩε룬Щ뽫ΪSQL һ֡Ҫʵһ㣬õһַʽʹñѯQuery Parameterizationı̼
磬Java ֮Уѯʾ
1. String newName = request.getParameter(\); 2. String id = request.getParameter(\); 3. PreparedStatement pstmt = con.prepareStatement(\EMPLOYEES SET NAME = ? WHERE ID = ?\); 4. pstmt.setString(1, newName); 5. pstmt.setString(2, id); 2. ݽб
루encodingһǿĹߣڷܶ͵Ĺע빥ǽַתɶԵȵַתַĿ˵еġڱһǷֹվűXSSCross SiteScriptingWeb Աᶯ̬عWeb ҳ棬ҳаԱHTML/JavaScriptԼݿеݣЩûġӦñΪΣյģڹȫWeb ӦʱҪĴƭûִжJavaScript ʱͻᷢվű߸ǡس֮ΪJavaScript ע룬ЩJavaScript űǹWeb վеģXSS ûִУ˻ָӰ졣
磬XSS վͿģ
1. ־ûXSSPersistent XSS洢XSSStored XSSָXSS Ƕ뵽վݿļϵͳ֮ˡXSS ΪΣգΪִеʱûѾ¼վˡXSS URL ĽβʱᷢXSSReflected XSSƭܺ߷ʸURLʵʱͻᴥֹXSSĹؼ̼룬ʱִУ
ûĻҲڽεӵHTML еʱֹܹXSS ıʽHTMLʵ롢JavaScript Լٷֺű루ҲΪURL 룩 3. Уе
дȫӦʱҪһǽӦⲿ루ƶͻˣⲿϵͳļΪεġWeb Ӧ˵HTTPͷcookies ԼGET POST ֮ܶҲκι߿ֵݡȫWeb ӦõһҪûܹύWeb Ӧ֮е롣ûļ֮ΪУ顱Web ӦõķˣУͨõʽУ飬ֱΪ͡У顣ͼõʲôӵģ κβƥ䡰롱붼ᱻܾУͼ֪̽ĹֻܾЩͷǷַУΪѣΪͨαװƹڹȫWeb ӦʱƼʹáЩʱʽDzģӦҪmarkupҲDzεлHTML ƬΣĻѽУ飬ҲǺѵģΪĻƻеıǩʱҪһܹHTMLʽıĿ⣬OWASP Java HTML Sanitizer 4. ʵʵķʿ
ȨAuthorizationAccess ControlָҪضԴʱҪжϸǸǾܾʿƿܻdzӣӦÿijʼΣҪǵһЩķʿİȫУ
ʿǺҪһݣҪгֿǣ ? ǿеͨʿƼ
ĿֻܺԱָԣ֮෴ǸȫΪĵġԿʹùԶԱ֤еҪij͵ķʿƼ顣 ? ĬϾܾ
ԶķʿƼ飬ҪǾܾû÷ʿƵԡͨ»ȡ෴Ҳ´ԻԶûʣֱԱΪ˰ȫĹܡ ? ڴУҪӲڲԵķʿƼ
ͨ£ʿƲӲӦ֮еġĻƻ֤İȫԻ÷dzҺʱܵĻʿƲԺӦôӦ÷뿪 ? Ի
ڴWeb лὫڽɫķʿΪҪڷʿƻУʹýɫǿԽܵģӦôضĽɫһַģʽڴҪûDzȨijԣǼû߱ʲôĽɫ
? ʿƼǷ˵Ŀ
ʿƾߵʱ漰ܶݣ¼û˭û߱ʲôȨޡʿƲʲôԺʲôʱʲôλЩӦͨˡWeb Web