ajax °²È«¶ÁÊé±Ê¼Ç
1.ÅÖ¿Í»§¶ËµÄ²¿Êð·½°¸
java web start
.net clickonce
2.ÈëÇÖ˼·
HTTPÊý¾ÝµÄ¼Ç¼->·¢ÏÖajax¿ÉÄÜ´æÔÚÎÊÌâµÄµã->ÈÆ¹ýjavascriptµÄһЩÏÞÖÆºÍÆÆ½âjavascript»ìÏý´úÂë->ÕÒµ½jsonµÄsql×¢Èëµã->ÕÒµ½ajax¿ÉÒÔÌí¼Ó¹ÜÀíÔ±µÄ»Øµ÷º¯ÊýºÍjsonÏà¹Ø
3.sql×¢ÈëС¼¼ÇÉ
union select name from sysobjects where xtype='U'Ö»ÒªµÃµ½ÏàͬµÄ×Ö¶Î
4.¿Í»§¶ËÈ¡ÏûcookieÈÏÖ¤²»ÊDZ£Ö¤Á˰²È«£¬¶øÊǰÑÍþвÓÖÎÞÐÎÀ©´óÁË
5.ajax¹¥»÷²ãÃæ°üÀ¨ÁË´«Í³µÄWEB©¶´+WEB SERIVCES©¶´¡£
6. ±¨Í·ÖпÉÄÜ´æÔÚΣÏÕµÄ×¢Èë
7.RSS×¢Èë(Íⲿ×ÊÁÏ¿ÉÒԲο¼ black hat 2006ÄêRobert Auger
http://www.cgisecurity.com/papers/RSS-Security.pptµÄÎÄÕÂ)
8.jsonµÄ©¶´±ØÐëÒªÑéÖ¤ÐòÁл¯Êý¾Ý(Íⲿ²Î¿¼×ÊÁÏblack hat 2005 Attack web Services: The next Generation of vulneralbe enterprise appsÏÂÔØµØÖ·http://www.blackhat.com/presentations/bh-usa-05/bh-us-05-stamos.pdf
ºÍHackInTheBoxµÄpentesting java/j2ee)
9.douglas·ÀÓùJsonµÄeval×¢Èë
Ïà¹ØÎĵµ£º
´«Í³ÐÍASP.NET Web FormsÊÇ»ùÓÚͬʱ°üº¬Á˱íÏÖ²ãºÍºǫ́´úÂëµÄWebÒ³Ãæ£¬ËùÒÔ£¬½ôËæÆäºó³öÏÖµÄASP.NET AJAX£¬ÌرðÊÇÕâ¸ö¿ò¼ÜµÄ·þÎñÆ÷¶Ë¿Ø¼þ²¢Ã»ÓÐÏñËüÃDZ¾Ó¦¸ÃµÄÄÇÑù¹ââËÄÉä¡£ÓÚÊÇ£¬ºÜ¶à¸úËæAJAXʱ÷ÖµÄASP.NET¿ª·¢ÕßÖ»ÊÇÏòASP.NETÒ³ÃæÖÐËæÒâµØ·ÅÖÃһЩUpdatePanel¿Ø¼þÒÔ±ãʹÆä³ÌÐòʵÏÖ»ù±¾µÄAJAXÖ§³Ö¡£Êµ¼Ê ......
<script type="text/javascript">
//¶¨ÒåXMLHttpRequest¶ÔÏó±äÁ¿
var xmlHttpRequest;
/*
* ´´½¨XMLHttpRequest¶ÔÏó¡£
* ±¾º¯ÊýÖ÷ÒªÍê³ÉXMLHttpRequest¶ÔÏóµÄ´´½¨£¬ºËÐÄ·ÖΪÒÔÏÂÁ½¸ö²¿·Ö£º
* µÚÒ»²½£ºÊ×ÏÈÅж ......
¹«Ë¾×î½ü¸øÎÒÒ»¸öÈÎÎñ£º°ÑÒ»¸öÓÃiframe×öµÄÁôÑÔ°å¸ÄдÓÃAjax×ö£¬ÕâÑù×öµÄÔÒòÊÇ£º¶ÔËÑË÷ÒýÇæµÄÓÅ»¯¡£ËäÈ»ºÜÔç¾ÍÖªµÀAjax¿ÉÒÔ×ö¾Ö²¿Ë¢Ð£¬µ«ÒòΪ×Ô¼ºÊǸձÏÒµÈëÖ°µÄ²ËÄñ£¬½ö½öÊÇÖªµÀÓÐÕâô¸ö¼¼Êõ¿ÉÒÔ×öÕâÑùÒ»¹¦ÄܶøÒÑ¡£Ò»±ßѧһ±ß×ö¡£ÏÖÔÚÕ⹦ÄÜ»¹Ã»ÍêȫŪºÃ£¬ÏÈ×ܽáÏÂ˼·ÒÔ±ã¸üºÃµÄѧϰ£º
ÒµÎñÂß¼£ºÔÚÏßÑÐÌֻᣬÌáÎÊÕßÒ³ ......
Dynatrace AJAX EditionÊÇÎÒÈÏΪ×îΪǿ´óµÄWeb Performance Profile¹¤¾ß¡£·Ï»°²»ËµÁË£¬Ö±½ÓÉÏͼ½éÉÜÆäÖ÷Òª¹¦ÄÜ¡£
ÏÈÓÃIE·ÃÎÊÄãÐèÒªprofileµÄÍøÕ¾£¬ÀýÈçgoogle£¬¿ÉÒÔµã»÷dynatrace¹¤¾ßÀ¸À´Æô¶¯¡£Õâʱºòdynatrace¾Í¿ªÊ¼¼Ç¼Õâ¸öÍøÕ¾´¥·¢µÄÒ»ÇÐʼþ¡£
ÎÒ¼òµ¥²âÊÔһϣ¬µã»÷google map£¬²¢ÇÒËÑË÷shanghai£¬È»ºó»ØÈ¥¿´¿´dyn ......
ÈçºÎÔÚ¿Í»§¶ËÖ±½Óµ÷ÓÃWebServiceÖеķ½·¨£¿
ÕâÀï½áºÏ¾Ñé×Ô¼ºÐ´Ò»Ð´
1.Ê×ÏÈн¨Ò»¸ö ASP.NET AJAX-Enabled Web Site,ÕâÑùϵͳΪÎÒÃÇ×Ô¶¯ÅäÖúÃÁË»·¾³£¬ÕâÖ÷ÒªÌåÏÖÔÚWeb.configÕâ¸öÎļþÉÏ£¬Èç¹ûÒÑÓÐÍøÕ¾²»ÊÇASP.NET AJAX-Enabled Web SiteÒ²¿ÉÒÔ¶ÔÕÕÐÞ¸ÄÏÂWeb.config£¬Ò²¿ÉÒÔ´ïµ½ÏàͬµÄЧ¹û¡£
2.н¨Ò»¸öweb·þÎñ£¬WebSer ......