ajax °²È«¶ÁÊé±Ê¼Ç
1.ÅÖ¿Í»§¶ËµÄ²¿Êð·½°¸
java web start
.net clickonce
2.ÈëÇÖ˼·
HTTPÊý¾ÝµÄ¼Ç¼->·¢ÏÖajax¿ÉÄÜ´æÔÚÎÊÌâµÄµã->ÈÆ¹ýjavascriptµÄһЩÏÞÖÆºÍÆÆ½âjavascript»ìÏý´úÂë->ÕÒµ½jsonµÄsql×¢Èëµã->ÕÒµ½ajax¿ÉÒÔÌí¼Ó¹ÜÀíÔ±µÄ»Øµ÷º¯ÊýºÍjsonÏà¹Ø
3.sql×¢ÈëС¼¼ÇÉ
union select name from sysobjects where xtype='U'Ö»ÒªµÃµ½ÏàͬµÄ×Ö¶Î
4.¿Í»§¶ËÈ¡ÏûcookieÈÏÖ¤²»ÊDZ£Ö¤Á˰²È«£¬¶øÊǰÑÍþвÓÖÎÞÐÎÀ©´óÁË
5.ajax¹¥»÷²ãÃæ°üÀ¨ÁË´«Í³µÄWEB©¶´+WEB SERIVCES©¶´¡£
6. ±¨Í·ÖпÉÄÜ´æÔÚΣÏÕµÄ×¢Èë
7.RSS×¢Èë(Íⲿ×ÊÁÏ¿ÉÒԲο¼ black hat 2006ÄêRobert Auger
http://www.cgisecurity.com/papers/RSS-Security.pptµÄÎÄÕÂ)
8.jsonµÄ©¶´±ØÐëÒªÑéÖ¤ÐòÁл¯Êý¾Ý(Íⲿ²Î¿¼×ÊÁÏblack hat 2005 Attack web Services: The next Generation of vulneralbe enterprise appsÏÂÔØµØÖ·http://www.blackhat.com/presentations/bh-usa-05/bh-us-05-stamos.pdf
ºÍHackInTheBoxµÄpentesting java/j2ee)
9.douglas·ÀÓùJsonµÄeval×¢Èë
Ïà¹ØÎĵµ£º
jQuery Ajax È«½âÎö
±¾ÎĵØÖ·: jQuery Ajax È«½âÎö
±¾ÎÄ×÷ÕߣºQLeelulu
×ªÔØÇë±êÃ÷³ö´¦£¡
jQueryȷʵÊÇÒ»¸öͦºÃµÄÇáÁ¿¼¶µÄJS¿ò¼Ü£¬ÄܰïÖúÎÒÃÇ¿ìËٵĿª·¢JSÓ¦Ó㬲¢ÔÚÒ»¶¨³Ì¶ÈÉϸıäÁËÎÒÃÇдJavaScript´úÂëµÄϰ¹ß¡£
·Ï»°ÉÙ˵£¬Ö±½Ó½øÈëÕýÌ⣬ÎÒÃÇÏÈÀ´¿´Ò»Ð©¼òµ¥µÄ·½·¨£¬ÕâЩ·½·¨¶¼ÊǶÔjQuery.ajax()½øÐзâ×°ÒÔ·½±ãÎÒÃÇÊ ......
//JS´úÂë
function checkname() {
var Msg = document.getElementById("d_username");
var chk = CheckN();
if (chk) {
$.ajax({ url: 'registerOK.aspx',
& ......
´«Í³ÐÍASP.NET Web FormsÊÇ»ùÓÚͬʱ°üº¬Á˱íÏÖ²ãºÍºǫ́´úÂëµÄWebÒ³Ãæ£¬ËùÒÔ£¬½ôËæÆäºó³öÏÖµÄASP.NET AJAX£¬ÌرðÊÇÕâ¸ö¿ò¼ÜµÄ·þÎñÆ÷¶Ë¿Ø¼þ²¢Ã»ÓÐÏñËüÃDZ¾Ó¦¸ÃµÄÄÇÑù¹ââËÄÉä¡£ÓÚÊÇ£¬ºÜ¶à¸úËæAJAXʱ÷ÖµÄASP.NET¿ª·¢ÕßÖ»ÊÇÏòASP.NETÒ³ÃæÖÐËæÒâµØ·ÅÖÃһЩUpdatePanel¿Ø¼þÒÔ±ãʹÆä³ÌÐòʵÏÖ»ù±¾µÄAJAXÖ§³Ö¡£Êµ¼Ê ......
Ò»¸öajaxÇëÇóÒ»¸öjspÎļþ£¬²Ù×÷³É¹¦,jspÎļþout.println("1");µ«ÊÇÿ´Î³É¹¦ºóxmlHttp.responseText=='1'×ÜÊÇΪfalse£¬
ÓÃencodeURIComponent¿´xmlHttp.responseText£¬·¢ÏÖ×îºó¶àÁË%0A%0D£¬°Ù¶ÈһϠÓÃÀ´ÊÇ»»ÐУ¬
jspÎļþÖеÄout.println……°ÑlnÈ¥µôÔÙ´Î±È½Ï ³É¹¦ = =¡ ......
function verify() {
//½â¾öÖÐÎÄÂÒÂéÎÊÌâµÄ·½·¨1£¬Ò³Ãæ¶Ë·¢³öµÄÊý¾Ý×÷Ò»´ÎencodeURI£¬·þÎñÆ÷¶ÎʹÓÃnew String(old.getBytes("iso8859-1"),"UTF-8");
//½â¾öÖÐÎÄÂÒÂéÎÊÌâµÄ·½·¨2£¬Ò³Ãæ¶Ë·¢³öµÄÊý¾Ý×÷Á½´ÎencodeURI£¬·þÎñÆ÷¶ÎʹÓÃURLDecoder.decode(old,"UTF-8")
var url = &qu ......