ASP³£¼ûµÄ°²È«Â©¶´
¡¡¡¡ASPµÄ©¶´ÒѾËãºÜÉÙµÄÁË£¬ÏëÒªÕÒµ½Êý¾Ý¿âµÄʵ¼ÊλÖÃÒ²²»¼òµ¥£¬µ«Õâ²»±íÃ÷ºÚ¿ÍÎ޿׿ÉÈ룬ҲÕýÊÇÕâ¸ö¹Ûµã£¬Ò»°ãµÄ³ÌÐòÉè¼ÆÔ±³£³£Íü¼Ç×ÐϸµÄ¼ì²éÊÇ·ñÓЩ¶´£¬ËùÒÔ²ÅÓпÉÄܵ¼ÖÂÍøÕ¾×ÊÁϱ»ÇÔÈ¡µÄʼþ·¢Éú¡£½ñÌìÎÒÔÚÕâÀïºÍ´ó¼Ò̸̸ASP³£¼ûµÄ°²È«Â©¶´£¬ÒÔÒýÆð´ó¼ÒµÄÖØÊÓ¼°²ÉÈ¡ÓÐЧµÄ·À·¶´ëÊ©¡£(×¢Ò⣬ÔÚ±¾ÎÄÖÐËù½éÉܵķ½·¨Çë´ó¼Ò²»ÒªÊÔÓã¬Çë´ó¼Ò×Ô¾õ×ñÊØÍøÂç×¼Ôò£¬Ð»Ð»!)
¡¡¡¡Microsoft µÄ Internet Information Server(IIS)ÌṩÀûÓà Active Server Pages(ASPs)¶ø¶¯Ì¬²úÉúµÄÍøÒ³·þÎñ¡£Ò»¸öASPÎļþ£¬¾ÍÊÇÒ»¸öÔÚ HTML ÍøÒ³ÖУ¬Ö±½ÓÄÚº¬³ÌÐò´úÂëµÄÎļþ¡£»ØÑ¯(request)Ò»¸ö ASP Îļþ£¬»á´Ùʹ IIS ÔËÐÐÍøÒ³ÖÐÄÚǶµÄ³ÌÐò´úÂ룬Ȼºó½«ÆäÔËÐнá¹ûÖ±½Ó»ØË͵½ä¯ÀÀÆ÷ÉÏÃæ¡£ÁíÒ»·½Ã棬¾²Ì¬µÄ HTML ÍøÒ³£¬Êǰ´ÕÕÆäÔÀ´µÄÑù×ӻش«µ½ä¯ÀÀÆ÷ÉÏÃæ£¬Ã»Óо¹ýÈκεĽâÎö´¦Àí¡£ÔÚÕâÀIIS ÊÇÀûÓõµ°¸µÄ¸½¼ÓµµÃûÀ´Çø±ðµµ°¸µÄÐÍ̬¡£Ò»¸ö¸½¼ÓµµÃûΪ .htm »ò .html µÄµµ°¸ÊÇÊôÓÚ¾²Ì¬µÄ HTML µµ°¸£¬¶ø¸½¼ÓµµÃûΪ .asp µÄµµ°¸ÔòΪһ¸öActive Server Pages µµ°¸¡£ÕýÒòΪÈç´Ë£¬ÕâÒ»¸öActive Server Pages ¾Í¸ø±ðÈËÁôÁ˺óÃÅ¡£
¡¡¡¡ÀýÈ磬ͨ¹ýÀûÓÃÕâ¸ö¼òµ¥µÄ²ÎÊý£¬¾Í»áÏÔʾËüËùÔÚµÄϵͳµÄʱ¼ä¡£ÈÕÆÚÊÇ×Ô¶¯´ÓϵͳȡµÃµÄ£¬¶øÒÔÍøÒ³µÄ·½Ê½´«ËͳöÀ´¡£Í¨¹ýä¯ÀÀÆ÷»ØÑ¯Õâ¸öÍøÒ³£¬ÎÒÃDz»»á¿´µ½¸Õ¸ÕµÄ³ÌÐò´úÂ룬¶øÊÇ¿´µ½³ÌÐò´úÂëµÄÖ´Ðнá¹û£¬»òÐíÔÚËùÓÐÍøÂ簲ȫ©¶´ÀïÃæ£¬×î²»ÊÜÖØÊӵľÍÊÇδ¾¹ý½âÎöµÄÎļþÄÚÈÝ»ò³ÌÐò´úÂëÎÞÒâÖб»ÏÔʾ³öÀ´µÄ°²È«Â©¶´¡£¼òµ¥µÄ˵£¬ÕâЩ°²È«Â©¶´ÔÊÐíʹÓÃÕß´ÓÍøÒ³·þÎñÆ÷ÆÈ¡¶¯Ì¬ÍøÒ³ÀïÃæµÄ³ÌÐò´úÂë¡£
¡¡¡¡ÒÔǰ×îÔçÈËÃÇÀûÓà ASP°²È«Â©¶´µÄ·½Ê½£¬¾ÍÊÇÀûÓà Windows NT µÄÊý¾Ý´«Êä´®ÐеÄÌØÐÔÈ¥´æÈ¡µµ°¸¡£ÄãÖ»ÒªÀûÓÃÒ»¸ö×î¼òµ¥µÄ²ÎÊý(::$DATA)Äã¾Í¿ÉÒÔ¿´µ½ ASP µÄÔʼ³ÌÐòÁË¡£
¡¡¡¡ÀýÈ磬ÒÔÏ嵀 URL£º
¡¡¡¡http://10.1.1.11/login.asp::$DATA
¡¡¡¡Äã»áÈ¡µÃÒ»¸ö½Ð×ölogin.aspµÄµµ°¸ÖÐδ¾¹ý½âÎöµÄ ASP ³ÌÐò´úÂë¡£ÒòΪÕâ¸ö URL ×Ö·û´®²¢Ã»ÓÐÒÔ .asp ×ö½áÊø£¬IIS ¾ÍûÓа취¾ö¶¨Õâ¸ö±»»ØÑ¯µÄµµ°¸ÊÇ·ñΪһ¸ö ASP µµ¡£
¡¡¡¡ÏÔʾµÄ³ÌÐò´úÂëÈçÏ£º xxxx alert("ÇëÊäÈëÄúµÄ ÃÜÂë!!") } else { document.f1.action="checkuser.asp"¡¡document.f1.submit() } } xxxx
¡¡¡¡×¢£ºcheckuser.asp ¾ÍÊǼì²éÕʺÅÃÜÂëµÄ¶«Î÷!
¡¡¡¡µ±È»ÁË£¬²¢·ÇËùÓеijÌÐò´úÂëÉϰ²È«Â©¶´¶¼¹é¾ÌÓÚÍøÒ³·þÎñÆ÷Èí¼þ¡£ÀýÈ磬Èç¹ûÄã²ÉÓõäÐͰ²×° Widows NT Option Pack 4.0µÄ»°£¬°²×°³ÌÐò»á½«Exploration
Ïà¹ØÎĵµ£º
1£ºSQL ×¢È룺
½â¾ö·½°¸£º
a. Õâ¸öÎÊÌâÖ÷ÒªÊÇÓÉÓÚ´«ÈëÌØÊâ×Ö·ûÒýÆðµÄÎÒÃÇ¿ÉÒÔÔÚ¶ÔÊäÈëµÄÓû§ÃûÃÜÂë½øÈë¹ýÂËÌØÊâ×Ö·û´¦Àí¡£
b. ʹÓô洢¹ý³Ìͨ¹ý´«Èë²ÎÊýµÄ·½·¨¿É½â¾ö´ËÀàÎÊÌ⣨עÒ⣺ÔÚ´æ´¢¹ý³ÌÖв»¿ÉʹÓÃÆ´½ÓʵÏÖ£¬²»È»ºÍûÓô洢¹ýºÍÊÇÒ»ÑùµÄ£©¡£
2. XSS£¨¿çÕ¾½Å±¾¹¥»÷£©£º
½â¾ö·½°¸£º
¡¡¡¡a. ͨ¹ýÔÚ Page Ö¸Áî»ò Å ......
µ÷ÊÔ³ÌÐòºÍ×ö³ÌÐòµÄʱºò£¬ºÃ¶àÖØ¸´µÄ´úÂëÒ»Ö±ÊäÈëºÜÂé·³£¬Ò²ºÜûÓÐЧÂÊ£¬·â×°Ò»¸ö×Ô¼ºµÄAsp°ü°ü£¬Í¦ÓÐÓеÄ
ÏÂÔØ¸ö¾«¼ò°æµÄVB6.0£¬Ð½¨ ActiveX dll£¬ÒÔÏÂÊÇ·â×°µÄ´úÂë£¬ÖØÒª²¿·Ö¶¼ÓÐ×¢ÊÍ£¬²»¶®¿ÉÒÔ¸úÌû
Option Explicit
Public Resp As Response, Requ As Request, Appl As Application, Serv As Server, Sess As Sessio ......
Ê×ÏÈ£¬Ò»°ã²Ù×÷ϵͳĬÈϾù²»°²×°IIS·þÎñ£¬Òò´Ë±ØÐëÏȰ²×°IIS·þÎñ¡£°²×°¹ý³ÌÖУ¬ÐèÒªÓõ½²Ù×÷ϵͳµÄ°²×°ÅÌ£¬ÓÐЩϵͳ»¹ÐèÒªÌØ¶¨°æ±¾µÄ²¹¶¡¡£±ÈÈçXPÐèÒªSP2¡£
´Ë´¦²»ÔÙ½éÉÜÍøÕ¾µÄÊôÐÔÅäÖã¬ÒòΪÓÐÖî¶àµÄÎÄÕ¶¼»á½«Õâ·½ÃæµÄÄÚÈÝ¡£
1¡£VISTA HOME BASIC
²»Äܰ²×°IIS·þÎñ
2¡£WINDOWS XP
ÐèҪȷ±£ÔÚASPÍøÕ¾Ä¿Â¼µÄ°²È ......
×î¼òµ¥ÓÃVB°Ñasp·â×°³ÉdllµÄÈëÃųÌÐò
µ±IIS±»ÇëÇóÖ´ÐÐÒ»¸öASP³ÌÐò,ËüÊ×ÏÈ»áÔÚASPÎļþÖÐÕÒµ½<%%>±êǩ֮¼äµÄ´úÂë,²¢ÇÒÖ´ÐÐËü(Ò²¿ÉÒÔÊÇ<scri ptrunat=server></script....>Ö®¼äµÄ´úÂë).Èç¹ûÕâ¸öASP³ÌÐòÔÚÏÈǰ±»µ÷Óùý,ÄÇôËü¾Í»áÓÃÄÚ´æÖеıàÒë¹ýµÄ³ÌÐòÀ´ÏòÓû§·µ»ØHTML´úÂë,Èç¹ûûÓÐ,ÄÇôËü¾ÍÖØÐ±àÒë.Õ ......
'º¯ÊýÃû£ºCodeCookie
'×÷ ÓãºCookie·ÀÂÒÂëдÈëʱÓÃ
'²Î Êý£ºstr ---- ×Ö·û´®
'·µ»ØÖµ£ºÕûÀíºóµÄ×Ö·û´®
'ʾ Àý£º
'**************************************************
Public Function CodeCookie(str)
If is ......