Asp NetÍøÕ¾°²È«
1£ºSQL ×¢È룺
½â¾ö·½°¸£º
a. Õâ¸öÎÊÌâÖ÷ÒªÊÇÓÉÓÚ´«ÈëÌØÊâ×Ö·ûÒýÆðµÄÎÒÃÇ¿ÉÒÔÔÚ¶ÔÊäÈëµÄÓû§ÃûÃÜÂë½øÈë¹ýÂËÌØÊâ×Ö·û´¦Àí¡£
b. ʹÓô洢¹ý³Ìͨ¹ý´«Èë²ÎÊýµÄ·½·¨¿É½â¾ö´ËÀàÎÊÌ⣨עÒ⣺ÔÚ´æ´¢¹ý³ÌÖв»¿ÉʹÓÃÆ´½ÓʵÏÖ£¬²»È»ºÍûÓô洢¹ýºÍÊÇÒ»ÑùµÄ£©¡£
2. XSS£¨¿çÕ¾½Å±¾¹¥»÷£©£º
½â¾ö·½°¸£º
¡¡¡¡a. ͨ¹ýÔÚ Page Ö¸Áî»ò ÅäÖýÚÖÐÉèÖà validateRequest="false" ½ûÓÃÇëÇóÑéÖ¤£¬È»ºóÎÒÃǶÔÓû§Ìá½»µÄÊý¾Ý½øÐÐ HtmlEncode£¬±àÂëºóµÄ¾Í²»»á³öÏÖÕâÖÖÎÊÌâÁË£¨ASP.NET ÖбàÂë·½·¨£ºServer.HtmlEncode(string)£©¡£
¡¡¡¡b. µÚ¶þÖÖÊǹýÂËÌØÊâ×Ö·û£¬ÕâÖÖ·½·¨¾Í²»Ì«ÌᳫÁË£¬Èç¹ûÓû§ÏëÊäÈëСÓںţ¨<£©Ò²»á±»¹ýÂ˵ô
3.CSRF£¨¿çÕ¾µãÇëÇóαÔ죩£º
½â¾ö·½°¸£º
¡¡¡¡ÐÞ¸ÄÐÅϢʱÌí¼ÓÑéÖ¤Âë»òÌí¼Ó Session ÁîÅÆ£¨ASP.NETÖÐÒѾÌṩһ¸ö×Ô¶¯·À·¶µÄ·½·¨£¬¾ÍÊÇÓÃÒ³ÃæÊôÐÔ ViewStateUserKey¡£ÔÚPage_Init·½·¨ÖÐÉèÖÃÆäÖµ£ºthis.ViewStateUserKey = Session.SessionID£©¡£
4. ÎļþÉÏ´«£º
½â¾ö·½°¸£º
ÔÚÓû§µÇ¼ʱ¼ÓÈëÊÇ·ñ¿ÉÉÏ´«ÎļþµÄ Session ±êÖ¾¡£Æäʵ Fckeditor ÒѾдºÃÁË¡£Ö±½Ó°ÑÑéÖ¤º¯Êý CheckAuthentication() ÖеÄ×¢ÊͶÎÖÐCheckAuthentication()
return ( Session[ "IsAuthorized" ] != null && (bool)Session[ "IsAuthorized" ] == true );
¡¡¡¡×¢ÊÍÈ¥µô¡£ÔڵǼ³É¹¦¼ÓÈëµÇ¼³É¹¦ JS ´úÂë
Session[“IsAuthorized”] = true;
£±£ºSQL ×¢Èë
ÒýÆðÔÒò£º
ÆäʵÏÖÔںܶàÍøÕ¾Öж¼´æÔÚÕâÖÖÎÊÌâ¡£¾ÍÊdzÌÐòÖÐÖ±½Ó½øÐÐSQLÓï¾äÆ´½Ó¡£¿ÉÄÜÓÐЩ¶ÁÕß²»Ì«Ã÷°×¡£ÏÂÃæÍ¨¹ýÒ»¸öµÇ¼ʱ¶ÔÓû§ÑéÖ¤À´ËµÃ÷£º
code:
Ñé֤ʱµÄsqlÓï¾ä: select * from where user='"+txtUsername.Text+"' and pwd='"+txtPwd.Text+"'
ÕâÊÇÒ»¶Î´ÓÊý¾Ý¿âÖвéѯÓû§£¬¶ÔÓû§Ãû£¬ÃÜÂëÑéÖ¤¡£
¿´ÉÏÈ¥ºÃÏóûÓÐʲôÎÊÌ⣬µ«ÊÇʵ¼ÊÕâÀïÃæÇ³²Ø×ÅÎÊÌ⣬Óû§Ãû£ºadmin ÃÜÂ룺 admin£¬
select * from where user='admin' and pwd='admin'
Èç¹ûÓû§ºÍÃÜÂëÕýÈ·¾Í¿ÉͨÑéÖ¤¡£Èç¹ûÎÒÓû§Ãû£ºasdf' or 1=1 -- ÃÜÂë£ºËæÒâÊäÈë.
ÎÒÃÇÔÙÀ´¿´Óï¾ä£º
select * from where user=‘asdf' or 1=1 -- and pwd=''
Ö´Ðк󿴵½Ê²Ã´£¿ÊDz»ÊÇËùÓмǼ£¬Èç¹û³ÌÐòÖ»ÊǼòµ¥ÅжϷµ»ØµÄÌõÊý£¬ÕâÖÖ·½·¨¾Í¿ÉÒÔͨÑéÖ¤¡£
Ïà¹ØÎĵµ£º
³£ÓõĽű¾ÓïÑÔÓÐ Javascript ºÍ VBscript ¡£
ʹÓÃÄÄÖÖÓïÑÔÐèÏÈÉ趨¡£ÈçÉϽڴúÂëÖеÄ<%@ LANGUAGE="JSCRIPT" ... %>¡£
Èç¹ûûÓÐÖ¸¶¨£¬ÏµÍ³¾Í»áʹÓà IIS ³ÌÐòÖ¸¶¨µÄ½Å±¾ÓïÑÔ¡£
VBscript Ó÷¨
VBscript Ò»°ã·ÅÔÚ <head> Óë </head> ÄÚµÄ <% ºÍ %> Ö®¼ä¡£
´ú ......
ASP.NET MVC FrameworkÊÇ΢Èí¹Ù·½ÌṩµÄMVCģʽ±àдASP.NET WebÓ¦ÓóÌÐòµÄÒ»¸ö¿ò¼Ü.ÒÑÓÚ2009Äê3ÔÂ19ÈÕÕýʽ·¢²¼. MVC(Model-View-Controller)ÓÃÓÚ±íʾһÖÖÈí¼þ¼Ü¹¹Ä£Ê½.Ëü°ÑÈí¼þϵͳ·ÖΪÈý¸ö»ù±¾²¿·Ö:Ä£ÐÍ(Model),ÊÓͼ(View)ºÍ¿ØÖÆÆ÷(Controller). ¼ÈÈ»ÊÇÒ»¸öÓÅÐãµÄ¿ò¼Ü£¬ÄÇô¾ÍÖµµÃȥѧϰһ°Ñ£¬ÍøÉÏËÑË÷ÁËÐí¶à×ÊÁÏ£¬Ï£Íû¶ÔÓ ......
FormatDateTime
·µ»Ø±í´ïʽ£¬´Ë±í´ïʽÒѱ»¸ñʽ»¯ÎªÈÕÆÚ»òʱ¼ä¡£
FormatDateTime(Date[, NamedFormat])
²ÎÊý
Date
±ØÑ¡Ïî¡£Òª±»¸ñʽ»¯µÄÈÕÆÚ±í´ïʽ¡£
NamedFormat
¿ÉÑ¡ÏָʾËùʹÓõÄÈÕÆÚ/ʱ¼ä¸ñʽµÄÊýÖµ£¬Èç¹ûÊ¡ÂÔ£¬ÔòʹÓà vbGeneralDate¡£
ÉèÖÃ
NamedFormat ²ÎÊý¿ÉÒÔÓÐÒÔÏÂÖµ£º
³£Êý Öµ ÃèÊö
vbGeneralDate ......
Á÷³Ì¿ØÖÆÓï¾ä
ÒÔÏÂÓÃʵÀýÀ´ÑÝʾÁ÷³Ì¿ØÖÆÓï¾äÖеÄÑ»·Óï¾äÓëÌõ¼þÓï¾ä£º
Ìõ¼þÓï¾ä£ºif ...else
ÒÔÏÂΪÒýÓÃÄÚÈÝ£º
<%@LANGUAGE="VBSCRIPT" CODEPAGE="65001"%>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns ......
Active Server Pages ÌṩÄÚ½¨¶ÔÏó£¬ÕâЩ¶ÔÏóʹÓû§¸üÈÝÒ×ÊÕ¼¯Í¨¹ýä¯ÀÀÆ÷ÇëÇó·¢Ë͵ÄÐÅÏ¢¡¢ÏìÓ¦ä¯ÀÀÆ÷ÒÔ¼°´æ´¢Óû§ÐÅÏ¢£¨ÈçÓû§Ê×Ñ¡Ï¡£±¾ÎļòҪ˵Ã÷ÿһ¸ö¶ÔÏó¡£
Application ¶ÔÏó
¿ÉÒÔʹÓà Application ¶ÔÏóʹ¸ø¶¨Ó¦ÓóÌÐòµÄËùÓÐÓû§¹²ÏíÐÅÏ¢¡£
Request ¶ÔÏó
¿ÉÒÔʹÓà Request ¶ÔÏó·ÃÎÊÈκÎÓà HTTP Çë ......