ASP.NETµÄWeb.configÎļþÖпÉÅäÖÃÄÄЩÉí·ÝÑéÖ¤·½Ê½
http://rzchina.net/node/3210
Web.configÎļþÖпÉÅäÖõÄÉí·ÝÑéÖ¤·½Ê½ÓÐWindows¡¢Forms¡¢PassPort¡¢None¡£
Web.configÎļþÖÐ<authentication>½Úµã£¬Éí·ÝÑéÖ¤·½Ê½È¡¾öÓڸýڵã“mode”ÊôÐÔµÄÉèÖá£
1£®None
None±íʾ²»Ö´ÐÐÉí·ÝÑéÖ¤¡£
2£®Windows
IIS¸ù¾ÝÓ¦ÓóÌÐòµÄÉèÖÃÖ´ÐÐÉí·ÝÑéÖ¤£¬ÆäÖаüº¬ÄäÃûÉí·ÝÑéÖ¤¡¢NTLMÉí·ÝÑéÖ¤¡¢base64±àÂëÉí·ÝÑéÖ¤µÈ¡£´ËÍ⣬NTFSÔÚÎļþºÍĿ¼ÉϵÄȨÏÞ£¨·ÃÎÊ¿ØÖÆÁÐ±í£©½«¾ö¶¨¶ÔĿ¼ÖÐ×ÊÔ´µÄ·ÃÎÊ¡£
3£®Forms
±à³ÌÕß´´½¨Ò»¸öÓÃÓڵǼµÄWEB´°Ì壬ȻºóÔÚÓ¦ÓóÌÐòÖÐÓÃÓÚÑéÖ¤ËùÓÐä¯ÀÀÓû§µÄÉí·Ý¡£Óû§µÚÒ»´Î·ÃÎʳÌÐòÖÐÈκδ°Ìå¶¼½«±»Öض¨Ïòµ½Õâ¸öµÇ¼´°Ì壬µ±Óû§µÇ¼³É¹¦ºó£¬ÆäµÇ¼ÐÅÏ¢±»´æ´¢ÔÚCookieÖУ¬²¢×ªÏòËù·ÃÎʹýµÄÆäËû´°Ìå¡£
4£®Passport
PassportÉí·ÝÑéÖ¤ÊÇͨ¹ýMicrosoftµÄ¼¯ÖÐÉí·ÝÑéÖ¤·þÎñÖ´Ðеģ¬ËüΪ³ÉÔ±Õ¾µãÌṩµ¥¶ÀµÇ¼ºÍºËÐÄÅäÖÃÎļþ·þÎñ¡£
ĬÈÏÇé¿öÏ£¬Web.configÎļþÖÐ<authentication>½Úµã²ÉÓÃWindowsÉí·ÝÑéÖ¤¡£Èç¹ûÐèҪʹÓÃFormsÑéÖ¤·½Ê½£¬²¢Ö¸¶¨µÇ¼´°ÌåΪÏîÄ¿¸ùĿ¼ÏµÄLogin.aspx£¬ÐÞ¸Ä<authentication>½ÚµãÈçÒÔÏ´úÂëËùʾ¡£
<authentication mode="Forms">
<forms loginUrl="lg.aspx" name=".cookiename"></forms>
</authentication>
<authorization>
<deny users="?" />
</authorization>
ÔÚ<authentication>½ÚµãÏÂÌí¼Ó<forms>×ӽڵ㼴¿ÉÉèÖÃFormsÑéÖ¤µÄ¸÷ÖÖϸ½Ú£¬Èç“loginUrl”ÓÃÓÚÖ¸¶¨µÇÂ¼Ò³ÃæÂ·¾¶£¬“name”ÊôÐÔÓÃÓÚÖ¸¶¨µÇ¼ÐÅÏ¢Ëù´æ´¢CookieµÄÃû³Æ¡£ÎªÁËʹÑéÖ¤ÉúЧ£¬±ØÐëÅäºÏ<authorization>½ÚµãÒ»ÆðÉèÖã¬ÔڸýڵãÏÂÌí¼Ó<deny>×ӽڵ㣬ͨ¹ý“users”ÊôÐÔÉèÖþܾøËùÓзǷ¨Óû§¡£
˵Ã÷£ºASP.NETÓ¦ÓóÌÐòÏÂÿ¸ö×ÓĿ¼¶¼¿ÉÒÔÓм̳ÐÓÚ¸ùĿ¼ÅäÖÃÎļþµÄWeb.configÎļþ£¬µ«Ò»¸öÓ¦ÓóÌÐòÖ»ÄÜÓÐÒ»¸öÉí·ÝÑéÖ¤µÇÂ¼Ò³Ãæ£¬¼´ÒÔÉÏ´úÂëÖÐ<forms>×Ó½Úµã“loginUrl”ÊôÐÔËùÖ¸¶¨µÄÒ³Ãæ¡£Èç¹ûÔÚ×ÓĿ¼µÄWeb.configÎļþÖгöÏÖÁË<authentication>½ÚµãµÄÅäÖ㬳ÌÐò½«³ö´í£¬³ý·Ç½«´ËĿ¼ÅäÖÃΪÐéÄâĿ¼½øÐзÃÎÊ¡£
Ïà¹ØÎĵµ£º
Èç¹ûÄãÒѾÓн϶àµÄÃæÏò¶ÔÏ󿪷¢¾Ñé£¬Ìø¹ýÒÔÏÂÕâÁ½²½£º
µÚÒ»²½¡¡ÕÆÎÕÒ»ÃÅ.NETÃæÏò¶ÔÏóÓïÑÔ£¬C#»òVB.NET ÎÒÇ¿ÁÒ·´¶ÔÔÚûϵͳѧ¹ýÒ»ÃÅÃæÏò¶ÔÏó(OO)ÓïÑÔµÄǰÌáÏÂȥѧASP.NET¡£ ASP.NETÊÇÒ»¸öÈ«ÃæÏò¶ÔÏóµÄ¼¼Êõ£¬²»¶®OO£¬ÄǾø¶Ôѧ²»ÏÂÈ¥!
µÚ¶þ²½¡¡¶Ô.NET FrameworkÀà¿âÓÐÒ»¶¨µÄÁ˽⠿ÉÒÔͨ¹ý¿ª·¢Windows FormÓ¦ÓóÌÐòÀ´Ñ§Ï°NE ......
ASP.NET´úÂëÓÅ»¯Ò»¡¢Ò³ÃæºÍ·þÎñÆ÷¿Ø¼þ´¦Àí
1¡¢ASP.NET´úÂëÓÅ»¯±ÜÃâµ½·þÎñÆ÷µÄ²»±ØÒªµÄÍù·µÐгÌ
ÔÚijЩÇé¿öϲ»±ØÊ¹Óà ASP.NET ·þÎñÆ÷¿Ø¼þºÍÖ´Ðлط¢Ê¼þ´¦Àí¡£ÀýÈ磬ÔÚ ASP.NET ÍøÒ³ÖÐÑéÖ¤Óû§ÊäÈë¾³£¿ÉÔÚÊý¾ÝÌá½»µ½·þÎñÆ÷֮ǰÔÚ¿Í»§¶Ë½øÐС£Í¨³££¬Èç¹û²»ÐèÒª½«ÐÅÏ¢´«µÝµ½·þÎñÆ÷ÒÔ½øÐÐÑéÖ¤»ò½«ÆäдÈëÊý¾Ý´æ´¢Çø£¬Çë±ÜÃâÊ ......
Trustwave's SpiderLabs Security Advisory TWSL2010-001:
Multiplatform View State Tampering Vulnerabilities
Published: 2010-02-08 Version: 1.1
SpiderLabs has documented view state tampering
vulnerabilities in three products from separate vendors.
View states are used by some web application frame ......
ASP.NET ÔËÐлúÖÆ×ܽá
ÕâЩÌì¿´ÁËһЩ¹ØÓÚASP.NETµ×²ãµÄÎÄÕÂ,ÊÜÒæ·Ëdz¡£
ΪʲôҪÁ˽âÕâЩµ×²ãÄØ£¿ÎÒ¾õµÃ×öΪһ¸öϲ»¶¿ª·¢ASP.NET³ÌÐòÔ±£¬ÎÒ²»ÃDz»½öÒªÖªµÀ“Ôõô×ö”£¬ÎÒÃǸüÓ¦¸ÃÖªµÀ“ΪʲôÕâô×ö”£¬ÕâÑùµÄÎÒÃDzÅÄÜ×öµÃ¸üºÃ¡£Õâ ......
ASP.NETÖÐʹÓÃweb.configÅäÖÃÊý¾Ý¿âÁ¬½Ó
ÔÚweb.configÎļþÖб£´æÊý¾Ý¿âÁ¬½ÓÅäÖÃÐÅÏ¢,¿ÉÒÔÈÃÄãÎÞÐëÖØÐ±àÒëÓ¦ÓóÌÐò¼´¿É¸üÐÂÓ¦ÓóÌÐòµÄijЩÊôÐÔ¡£µ±ÄãÏë°ÑÊý¾Ý¿âÇ¨ÒÆµ½ÁíÒ»¸ö²»Í¬µÄ·þÎñÆ÷£¬ÄãÖ»ÐèÒªÐÞ¸Äweb.configÎļþÖеÄÊý¾Ý¿âÁ¬½ÓÅäÖÃÐÅÏ¢¶øÒÑ£¬²¢²»ÐèÒªÖØÐ±àÒëºÍÖØÐ²¿ÊðÕâ¸öÓ¦ÓóÌÐòÒÔÊÊӦеķþÎñÆ÷µÄÒ ......