Asp.net µÇ¼ÎÊÌâ - .NET¼¼Êõ / ASP.NET
Severity :Critical Privacy Violation: Unencrypted Password Submission .00 URL/File Names: 1. http://172.16.1.121:888/ This page may submit a password via an unencrypted connection. Found text: [<input name="txtPassword" type="password",]. 2. http://172.16.1.121:888/LoginForm.aspx This page may submit a password via an unencrypted connection. Found text: [<input name="txtPassword" type="password",]. ²âÊÔʱ µÇ¼ʱÃÜÂëû¼ÓÃÜ ÈçºÎ½â¾ö£¿
û¿´Ã÷°×£¬Ã»¼ÓÃܾͼÓÃÜÒ»ÏÂß md5 û¼û¹ý UP ÓÃmd5¼ÓÃÜ ¿É²»¿ÉÒÔÉèΪ¼ÓÃÜµÄ±íµ¥Ìá½»£¿ string pwd = this.TextBox1.Text; string pwdSec = System.Web.Security.FormsAuthentication.HashPasswordForStoringInConfigFile(pwd, "md5"); ×ÅÕâ¸ö²»£¿ ʹÓÃMD5¼ÓÃÜ this.MD5(this.txtpwd.text) ÏÂÔØÒ»¸ömd5¼ÓÃÜjsº¯Êý£¬¼ÓÃܺóÌá½»ÒýÓà Õâ¸öÎÊÌâÊÇÃ÷ÃÜÂë·¢ËÍÎÊÌâ ΪÁ˰²È«ÒªÔÚÓû§µã»÷µÇ¼ʱ¾ÍÒªÏȽøÐмÓÃÜ Ê×ÏÈÓû§µã»÷ʱ£¨mousedown£©ÓÃAjaxÇëÇóloginServer.ashx ·µ»Ø¼ÓÃÜ´® JScript code <script type="text/javascript"> $(document).ready(function() { $("#¡¡ ºÜÃ÷ÁËÁË¡¢ ÌáʾµÄÊÇûÓмÓÃܵÄÁ¬½Ó£¬²»ÊÇÃÜÂë Äã×öµÄÊÇhttpsÀàÐ͵ÄÍøÕ¾°É
Ïà¹ØÎÊ´ð£º
function CheckOpwd(){//ÑéÖ¤Óû§Ãû var pwd=document.all.txtOpwd; var div1=document.getElementById("divPwd"); if (pwd.value=="") { ......
ÎÒÓÃasp.net¿ª·¢wapÕ¾µã£¬Íê³ÉºóÈ¥http://validator.w3.org/ÕâÀïÑéÖ¤ÎÒµÄWapÒ³ÃæÊÇ·ñ±ê×¼£¬ÆäËüÎÊÌâ¶¼¸ÄºÃÁË£¬ ¾ÍÊ£ÕâÒ»¸ö´íÎóÁË£¬°´×ÖÃæÒâ˼Àí½âÊÇ˵nameÊôÐÔÒÑ´æÔÚ£¬ÀàËÆÕâÑùµÄ´íÎó»¹Óв»ÄÜÓÃborder ,align,sizeµ ......
1.asp.net×öµÄÒ»¸ö´ðÌâÒ³Ãæ£¬ÈçºÎʵʱÏÞʱºó×Ô¶¯Ìá½»£¬Çë´ó¼Ò¸øµã˼· ÏÞʱµÄʱ¼äÐÅÏ¢´æ·ÅÔÚÊý¾Ý¿âÖÐ 2.Èç¹û´ðÌâʱ¼äÉèÖõĽϳ¤£¬ÈçºÎ·½Ê½session³¬Ê±ºóÒ³ÃæÎÞЧ лл ÓÃjs·½·¨À´¿ØÖÆ »Ø¸´ÄÚÈÝÌ«¶ÌÁË¡£¡£ js ......
ÎÒÓÐÁ½¸ödropdownlist¶¼°óºÃÁËÖµ£¬ÏëÑ¡ÖÐÒ»¸ödropdownlistÖеÄÖµ£¬È»ºóÔÚÁíÒ»¸ödropdownlistÖÐÑ¡ÖÐÏàÓ¦µÄÒ»Ïî¡£ ²»ÊÇ´Óа󶨵ڶþ¸ödropdownlist£¬ÊÇÔÚÒѾ°óºÃµÄÖµµ±ÖÐÑ¡ÖÐÒ»¸ö¡£ ÎÒÏëÓÃjsд ÇóÖú Äã¿ÉÒÔ°Ñdrop ......
´ó¼ÒºÃ£¬ÎÒÏÖÔÚÓÐÒ»¸öÓÃaspдµÄÁÄÌìÊÒ£¬ÏÖÔÚµÄÏëÌí¼ÓÒ»¸ö¹¦ÄÜ£¬¾ÍÊǵ±ÓÐÈËÉÏÏßµÄʱºò£¬·¢³öÌáʾ£¬±ÈÈçÉùÒôÏìһϣ¬ÏÖÔÚÏëÓÃjavaʵÏÖÕâ¸ö¹¦ÄÜ£¬ÇëÎÊ´ó¼ÒÔõôʵÏÖ£¿ ллÁË£¬ÎÒ»á¼Ó·ÖµÄ aspºÍjavaÕûºÏµ½Ò»ÆðÈ¥£¿ºÎ±Ø ......