ASP.NETÒ³Ãæ´«Êý¾ÝµÄ¸÷ÖÖ·½·¨ºÍ·ÖÎö
WebÒ³ÃæÊÇÎÞ״̬µÄ£¬ ·þÎñÆ÷¶Ôÿһ´ÎÇëÇó¶¼ÈÏΪÀ´×Ô²»Í¬Óû§£¬Òò´Ë£¬±äÁ¿µÄ״̬ÔÚÁ¬Ðø¶ÔÍ¬Ò»Ò³ÃæµÄ¶à´ÎÇëÇóÖ®¼ä»òÔÚÒ³ÃæÌø×ªÊ±²»»á±»±£Áô¡£ÔÚÓÃASP.NET Éè¼Æ¿ª·¢Ò»¸öWebϵͳʱ£¬ Óöµ½Ò»¸öÖØÒªµÄÎÊÌâÊÇÈçºÎ±£Ö¤Êý¾ÝÔÚÒ³Ãæ¼ä½øÐÐÕýÈ·¡¢°²È«ºÍ¸ßЧµØ´«ËÍ£¬Asp.net ÌṩÁË״̬¹ÜÀíµÈ¶àÖÖ¼¼ÊõÀ´½â¾ö±£´æºÍ´«µÝÊý¾ÝÎÊÌ⣬ÒÔÏÂÀ´Ì½ÌÖ.NET ϵĽâ¾ö´ËÎÊÌâµÄ¸÷ÖÖ·½·¨ºÍ¸÷×ÔµÄÊÊÓó¡ºÏ¡£
1.1 ʹÓÃQuerystring ·½·¨
QueryString Ò²½Ð²éѯ×Ö·û´®£¬ ÕâÖÖ·½·¨½«Òª´«µÝµÄÊý¾Ý¸½¼ÓÔÚÍøÒ³µØÖ·(URL)ºóÃæ½øÐд«µÝ¡£ÈçÒ³ÃæA.aspx Ìø×ªµ½Ò³ÃæB.aspx£¬¿ÉÒÔÓÃRequest.Redirect("B.aspx?²ÎÊýÃû³Æ=²ÎÊýÖµ")·½·¨£¬Ò²¿ÉÒÔÓó¬Á´½Ó£º£¬Ò³ÃæÌø×ªºó£¬ÔÚÄ¿±êÒ³ÃæÖпÉÓÃRuquest["²ÎÊýÃû³Æ"]À´½ÓÊÕ²ÎÊý¡£Ê¹ÓÃQuerySting ·½·¨µÄÓŵãÊÇʵÏÖ¼òµ¥£¬ ²»Ê¹Ó÷þÎñÆ÷×ÊÔ´£»È±µãÊÇ´«µÝµÄÖµ»áÏÔʾÔÚä¯ÀÀÆ÷µÄµØÖ·À¸ÉÏ£¬Óб»´Û¸ÄµÄ·çÏÕ£¬²»ÄÜ´«µÝ¶ÔÏó£¬Ö»ÓÐÔÚͨ¹ýURL ÇëÇóҳʱ²éѯ×Ö·û´®²ÅÊÇ¿ÉÐеġ£
1.2 ÀûÓÃÒþ²ØÓò
Òþ²ØÓò²»»áÏÔʾÔÚÓû§µÄä¯ÀÀÆ÷ÖУ¬ Ò»°ãÊÇÔÚÒ³ÃæÖмÓÈëÒ»¸öÒþ²Ø¿Ø¼þ£¬ Óë·þÎñÆ÷½øÐн»»¥Ê±°ÑÖµ¸³¸øÒþ²Ø¿Ø¼þ²¢Ìá½»¸øÏÂÒ»Ò³Ãæ¡£Òþ²ØÓò¿ÉÒÔÊÇÈκδ洢ÔÚÍøÒ³ÖеÄÓëÍøÒ³ÓйصÄÐÅÏ¢µÄ´æ´¢¿â¡£Ê¹ÓÃÒþ²ØÓò´æÈëÊýֵʱÓãºhidden ¿Ø¼þ.value=ÊýÖµ£¬È¡³ö½ÓÊÕÊýֵʱÓ㺱äÁ¿=hidden ¿Ø¼þ.value¡£Ê¹ÓÃÒþ²ØÓòµÄÓŵãÊÇʵÏÖ¼òµ¥£¬ Òþ²ØÓòÊDZê×¼µÄHTML ¿Ø¼þ£¬²»ÐèÒª¸´Ôӵıà³ÌÂß¼¡£Òþ²ØÓòÔÚÒ³ÉÏ´æ´¢ºÍ¶ÁÈ¡£¬²»ÐèÒªÈκηþÎñÆ÷×ÊÔ´£¬¼¸ºõËùÓÐä¯ÀÀÆ÷ºÍ¿Í»§¶ËÉ豸¶¼Ö§³Ö¾ßÓÐÒþ²ØÓòµÄ´°Ì塣ȱµãÊÇ´æ´¢½á¹¹ÉÙ£¬½ö½öÖ§³Ö¼òµ¥µÄÊý¾Ý½á¹¹£¬´æ´¢Á¿ÉÙ£¬ÒòΪËü±»´æ´¢ÔÚÒ³Ãæ±¾Éí£¬ËùÒÔÎÞ·¨´æ´¢½Ï´óµÄÖµ£¬¶øÇÒ´óµÄÊý¾ÝÁ¿»áÊܵ½·À»ðǽºÍ´úÀíµÄ×èÖ¹¡£
1.3 ViewState
ViewState ÊÇÓÉASP.NET Ò³Ãæ¿ò¼Ü¹ÜÀíµÄÒ»¸öÒþ²ØµÄ´°Ìå×ֶΡ£µ±ASP.NET Ö´ÐÐij¸öÒ³ÃæÊ±£¬¸ÃÒ³ÃæÉϵÄViewState ÖµºÍËùÓпؼþ½«±»ÊÕ¼¯²¢¸ñʽ»¯³ÉÒ»¸ö±àÂë×Ö·û´®£¬ È»ºó±»·ÖÅ䏸Òþ²Ø´°Ìå×ֶεÄÖµÊôÐÔ¡£Ê¹ÓÃViewState ´«µÝÊý¾Ýʱ¿ÉÓãºViewState [" ±äÁ¿Ãû"]=ÊýÖµ£¬ÔÚÈ¡³öÊý¾ÝʱÓ㺱äÁ¿=ViewState["±äÁ¿Ãû"]¡£Ê¹ÓÃViewState µÄÓŵãÊÇ£ºÔÚ¶ÔͬһҳµÄ¶à¸öÇëÇó¼ä×Ô¶¯±£ÁôÖµ£¬²»Ó÷þÎñÆ÷¶Ë×ÊÔ´£¬ÊµÏÖ¼òµ¥£¬ÊÓͼ״̬ÖеÄÖµ¾¹ý¹þÏ£¼ÆËãºÍѹËõ£¬²¢ÇÒÕë¶ÔUnicode&
Ïà¹ØÎĵµ£º
½¨Á¢Ò»¸öWEB¹¤³Ì£¬Ìí¼ÓÐÂÏî->HTMLÒ³Ãæ£¬ÃüÃûΪProgressBar.htm£¬ÄÚÈÝÈçÏ£º
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" id="mainWindo ......
ValidationSummary:¸Ã¿Õ¼äµÄ×÷ÓÃÊǰÑËùÓÐÑéÖ¤´íÎóµÄÁбíÏÔʾÔÚÒ³ÃæµÄͬһ¸öµØ·½¡£
ÊôÐÔ£ºDisplayMode:ÏÔʾ´íÎóÐÅÏ¢µÄ·½Ê½£ºBulletList·ÅÔÚ<ul><li></li></ul>ÀList·ÅÔÚ<div>´íÎó1<br/>´íÎó2</div>ÖУ¬²»Í¬ÐÅϢʹÓÃ<br/>¸ô¿ª£»SingleParagraph·ÅÔÚ<div>& ......
ASP.NET´úÂëÓÅ»¯Ò»¡¢Ò³ÃæºÍ·þÎñÆ÷¿Ø¼þ´¦Àí
1¡¢ASP.NET´úÂëÓÅ»¯±ÜÃâµ½·þÎñÆ÷µÄ²»±ØÒªµÄÍù·µÐгÌ
ÔÚijЩÇé¿öϲ»±ØÊ¹Óà ASP.NET ·þÎñÆ÷¿Ø¼þºÍÖ´Ðлط¢Ê¼þ´¦Àí¡£ÀýÈ磬ÔÚ ASP.NET ÍøÒ³ÖÐÑéÖ¤Óû§ÊäÈë¾³£¿ÉÔÚÊý¾ÝÌá½»µ½·þÎñÆ÷֮ǰÔÚ¿Í»§¶Ë½øÐС£Í¨³££¬Èç¹û²»ÐèÒª½«ÐÅÏ¢´«µÝµ½·þÎñÆ÷ÒÔ½øÐÐÑéÖ¤»ò½«ÆäдÈëÊý¾Ý´æ´¢Çø£¬Çë±ÜÃâÊ ......
Trustwave's SpiderLabs Security Advisory TWSL2010-001:
Multiplatform View State Tampering Vulnerabilities
Published: 2010-02-08 Version: 1.1
SpiderLabs has documented view state tampering
vulnerabilities in three products from separate vendors.
View states are used by some web application frame ......
< align=middle src=http://player.youku.com/player.php/sid/XMTQ3NTE2NzIw/v.swf width=480 height=400 type=application/x-shockwave-flash allowScriptAccess="sameDomain" quality="high" mce_src="http://player.youku.com/player.php/sid/XMTQ3NTE2NzIw/v.swf"> ......