Asp.net µÇ¼ÎÊÌâ - .NET¼¼Êõ / ASP.NET
Severity :Critical Privacy Violation: Unencrypted Password Submission .00 URL/File Names: 1. http://172.16.1.121:888/ This page may submit a password via an unencrypted connection. Found text: [<input name="txtPassword" type="password",]. 2. http://172.16.1.121:888/LoginForm.aspx This page may submit a password via an unencrypted connection. Found text: [<input name="txtPassword" type="password",]. ²âÊÔʱ µÇ¼ʱÃÜÂëû¼ÓÃÜ ÈçºÎ½â¾ö£¿
û¿´Ã÷°×£¬Ã»¼ÓÃܾͼÓÃÜÒ»ÏÂß md5 û¼û¹ý UP ÓÃmd5¼ÓÃÜ ¿É²»¿ÉÒÔÉèΪ¼ÓÃÜµÄ±íµ¥Ìá½»£¿ string pwd = this.TextBox1.Text; string pwdSec = System.Web.Security.FormsAuthentication.HashPasswordForStoringInConfigFile(pwd, "md5"); ×ÅÕâ¸ö²»£¿ ʹÓÃMD5¼ÓÃÜ this.MD5(this.txtpwd.text) ÏÂÔØÒ»¸ömd5¼ÓÃÜjsº¯Êý£¬¼ÓÃܺóÌá½»ÒýÓà Õâ¸öÎÊÌâÊÇÃ÷ÃÜÂë·¢ËÍÎÊÌâ ΪÁ˰²È«ÒªÔÚÓû§µã»÷µÇ¼ʱ¾ÍÒªÏȽøÐмÓÃÜ Ê×ÏÈÓû§µã»÷ʱ£¨mousedown£©ÓÃAjaxÇëÇóloginServer.ashx ·µ»Ø¼ÓÃÜ´® JScript code <script type="text/javascript"> $(document).ready(function() { $("#¡¡ ºÜÃ÷ÁËÁË¡¢ ÌáʾµÄÊÇûÓмÓÃܵÄÁ¬½Ó£¬²»ÊÇÃÜÂë Äã×öµÄÊÇhttpsÀàÐ͵ÄÍøÕ¾°É
Ïà¹ØÎÊ´ð£º
ÎÒÓÃasp.net¿ª·¢wapÕ¾µã£¬Íê³ÉºóÈ¥http://validator.w3.org/ÕâÀïÑéÖ¤ÎÒµÄWapÒ³ÃæÊÇ·ñ±ê×¼£¬ÆäËüÎÊÌâ¶¼¸ÄºÃÁË£¬ ¾ÍÊ£ÕâÒ»¸ö´íÎóÁË£¬°´×ÖÃæÒâ˼Àí½âÊÇ˵nameÊôÐÔÒÑ´æÔÚ£¬ÀàËÆÕâÑùµÄ´íÎó»¹Óв»ÄÜÓÃborder ,align,sizeµ ......
1.asp.net×öµÄÒ»¸ö´ðÌâÒ³Ãæ£¬ÈçºÎʵʱÏÞʱºó×Ô¶¯Ìá½»£¬Çë´ó¼Ò¸øµã˼· ÏÞʱµÄʱ¼äÐÅÏ¢´æ·ÅÔÚÊý¾Ý¿âÖÐ 2.Èç¹û´ðÌâʱ¼äÉèÖõĽϳ¤£¬ÈçºÎ·½Ê½session³¬Ê±ºóÒ³ÃæÎÞЧ лл ÓÃjs·½·¨À´¿ØÖÆ »Ø¸´ÄÚÈÝÌ«¶ÌÁË¡£¡£ js ......
ÎÒÓÐÁ½¸ödropdownlist¶¼°óºÃÁËÖµ£¬ÏëÑ¡ÖÐÒ»¸ödropdownlistÖеÄÖµ£¬È»ºóÔÚÁíÒ»¸ödropdownlistÖÐÑ¡ÖÐÏàÓ¦µÄÒ»Ïî¡£ ²»ÊÇ´Óа󶨵ڶþ¸ödropdownlist£¬ÊÇÔÚÒѾ°óºÃµÄÖµµ±ÖÐÑ¡ÖÐÒ»¸ö¡£ ÎÒÏëÓÃjsд ÇóÖú Äã¿ÉÒÔ°Ñdrop ......
ÎÒ×î½ü×öÁËÒ»¸öÍøÕ¾ÊǹØÓÚ²úƷչʾµÄ ~ Õû¸öÍøÕ¾Í¼Æ¬¶¼Õ¼ÓÃÁËÒ»´ó°ë ÕâÑùµÄ»°·ÃÎÊËٶȾͷdz£Âý ÓÐʲô°ì·¨¿ÉÒÔ½â¾öÂ𣿠Âé·³´ó¼Ò¶à¶à¸øµãÒâ¼û £¡ ÓÐʲô¾¡¹Ü˵ 3Q´ó¼Ò htmlÒ³Ãæ. Õâ¸ö,¼ÈÈ»Ö÷Ò ......