ASP.NET¶ÁÈ¡ASPÉèÖõÄCookie
ÕâÀàÎÊÌâͨ³£ÔÚÕûºÏ»ò¶þ´Î¿ª·¢ASPÍøÕ¾Ê±Óöµ½¡£°´³£ÀíÀ´Ëµ£¬ä¯ÀÀÆ÷µÄCookie´æ·ÅÔÚ¿Í»§¶Ë£¬Êµ¼ÊÉÏÓë·þÎñ¶ËʹÓÃʲôÓïÑÔÎ޹أ¬µ«ÎÒÃÇÔÚʵ¼Ê²Ù×÷¹ý³ÌÖУ¬×Ü»áÓöµ½Ò»Ð©ÒâÏë²»µ½µÄÎÊÌâ¡£
1. µ±ASPдµÄCookieµÄKeyÖдøÓÐÏ»®Ïߣ¬ÀýÈçÎÒÃÇÔÚASPÖÐÕâÑùÉèÖÃCookie:
Response.Cookies("Admin_User")="¹ÜÀíÔ±";
ÄÇôÔÚaspx.csµÄÒ³Ãæ£¬Ê¹ÓÃRequest.Cookie["Admin_User"] £¬ÊÇÔõô¶¼¶Á²»µ½µÄ¡£ÔÚÕâÀïÎÒдÁËÒ»¸öÑ»·£¬½«µ±Ç°cookieµÄËùÓÐNameÓëValue¶¼Êä³öÁËÒ»±é£¬·¢ÏÖÏ»®Ïß“_”ÒѾתÒå³ÉÁË“%5F”£¬¶øÊ¹ÓÃRequest.Cookie["Admin%5FUser"] ¾Í¿ÉÒԵõ½ÎÒÃÇÏëÒªµÄ“¹ÜÀíÔ±”ÁË¡£
Óöµ½ÀàËÆÎÊÌâµÄÅóÓÑ£¬²»·Á×öÕâÑùµÄ³¢ÊÔ¡£
2. »¹ÐèҪעÒâÖÐÎÄÂÒÂëµÄÎÊÌ⣬²»¹ÜÎÒ½«×Ö·û¼¯ÉèÖÃΪGB2312£¬»¹ÊÇGBK£¬ÉõÖÁÊÇUTF-8¶¼Ã»·¨»ñµÃÕýÈ·µÄÖÐÎÄ£¬Êµ¼ÊÉÏÎÊÌâ³öÔÚASPÄDZߣ¬ASPÒ³ÃæÏÔʾ¼òÌåÖÐÎÄʱ£¬ÐèÒªÉèÖÓ´úÂëÒ³”£¨Ëü¿É¶Áд£¬ÕûÐÍÊý£¬ÓÃÓÚ±íʾÏÔʾҳÄÚÈݵÄ×Ö·û¼¯£¬¼òÌåÖÐÎÄΪ936£¬ÈÕÎÄΪ932£¬ANSIΪ1252£©¡£
string cookie = System.Web.HttpUtility.UrlDecode(Request.Cookies["Admin%5FUser"].Value, System.Text.Encoding.GetEncoding(936));
ʹÓÃÒÔÉϵķ½Ê½£¬±ã¿ÉÒÔ»ñÈ¡°üº¬ÖÐÎĵÄCookieÁË¡£
Ïà¹ØÎĵµ£º
ASP.NET´úÂëÓÅ»¯Ò»¡¢Ò³ÃæºÍ·þÎñÆ÷¿Ø¼þ´¦Àí
1¡¢ASP.NET´úÂëÓÅ»¯±ÜÃâµ½·þÎñÆ÷µÄ²»±ØÒªµÄÍù·µÐгÌ
ÔÚijЩÇé¿öϲ»±ØÊ¹Óà ASP.NET ·þÎñÆ÷¿Ø¼þºÍÖ´Ðлط¢Ê¼þ´¦Àí¡£ÀýÈ磬ÔÚ ASP.NET ÍøÒ³ÖÐÑéÖ¤Óû§ÊäÈë¾³£¿ÉÔÚÊý¾ÝÌá½»µ½·þÎñÆ÷֮ǰÔÚ¿Í»§¶Ë½øÐС£Í¨³££¬Èç¹û²»ÐèÒª½«ÐÅÏ¢´«µÝµ½·þÎñÆ÷ÒÔ½øÐÐÑéÖ¤»ò½«ÆäдÈëÊý¾Ý´æ´¢Çø£¬Çë±ÜÃâÊ ......
Trustwave's SpiderLabs Security Advisory TWSL2010-001:
Multiplatform View State Tampering Vulnerabilities
Published: 2010-02-08 Version: 1.1
SpiderLabs has documented view state tampering
vulnerabilities in three products from separate vendors.
View states are used by some web application frame ......
´ó¼ÒÖªµÀÔÚÍøÕ¾µÄÿ¸öÒ³ÃæÉÏ,´æ´¢Ò»Ð©È«¾Ö´¦ÀíÐÅÏ¢£¬ÀíÏëµÄ×ö·¨Êǽ«ÕâЩÐÅÏ¢Ò»´ÎÐԵļ¯Öд洢ÔÚ×ÊÁϵµ°¸¿âÖУ¬¶ø²»ÊÇÔÚÍøÕ¾µÄÿ¸öÒ³ÃæÉ϶¼Öظ´ÕâÑùµÄ²Ù×÷¡£
±ÈÈç˵Êý¾Ý¿âÁ¬½Ó´®¾ÍÊÇÕâÑùµÄÐÅÏ¢£¬Èç¹ûÕâЩÐÅÏ¢²»ÊǼ¯Öд洢ÔÚÌØ¶¨ÇøÓòÖУ¬¶øÊÇÔÚÍøÕ¾µÄÿ¸öÐèÒªÁ¬½ÓÊý¾Ý¿âµÄÒ³ÃæÉÏÊÖ¹¤ÊäÈ룬¿ÉÒÔÉèÏ룺µ±Êý ......
±¾ÎĽéÉܵÄÕâ¸ö¹¦ÄÜÊÇ£º½ûÓÃÒ³Ãæ»º´æµÄ½â¾ö·½·¨£¬ÊÊÓÃÓÚIEºÍFireFoxä¯ÀÀÆ÷Ï£¬ÔÚweb¿ª·¢ÖкÏÀíʹÓûº´æ¿ÉÒÔÓÐЧµÄÌá¸ßÍøÕ¾µÄÐÔÄÜ£¬µ«ÊÇÔÚijЩ³¡ºÏÏÂÒòΪ»º´æµÄ´æÔÚ»á´øÀ´ºÜ¶àµÄÎÊÌâ¡£ÀýÈ磺ÒòΪ»º´æµÄ´æÔÚ»áÔì³ÉÖØ¸´Ìá½»Êý¾ÝµÄÎÊÌ⣬ÑéÖ¤ÂëͼƬ²»ÄÜÕýÈ·ÏÔʾµÄÎÊÌ⣬µÈµÈ¡£Õâ¸öʱºòÎÒÃǾÍÒª½ûÓÃÒ³Ãæ»º´æµÄ¹¦ÄÜ¡£&nbs ......
vs2005 ûÓÐASP.NET WEBÓ¦ÓóÌÐò£¨Application£©µÄ½â¾ö·½°¸
vs2005 sp1ÏÂÔØµØÖ·
2009-02-21 09:08
VS80sp1-KB926604-X86-CHS.exe
WebApplicationProjectSetup.msi
Ïà¹ØÎÄÕÂ:
×î½ü°ïͬʰ²×°ÁËVs2005ºÍsp1,·¢ÏÖ¸ù±¾´ò²»¿ªÔÀ´µÄ³ÌÐò£¬Ð½¨ÏîÄ¿ÖÐûÓÐASP.NET WEBÓ¦ÓóÌÐò,ͬʵÄϵͳÊÇwindows 2003,¶øÔÚwi ......