asp.netÌá½»html±ê¼ÇºóµÄ×îÓŰ²È«´¦Àí
ASP.Net 1.1ºóÒýÈëÁ˶ÔÌá½»±íµ¥×Ô¶¯¼ì²éÊÇ·ñ´æÔÚXSS(¿çÕ¾½Å±¾¹¥»÷)µÄÄÜÁ¦¡£µ±Óû§ÊÔͼÓÃÖ®ÀàµÄÊäÈëÓ°ÏìÒ³Ãæ·µ»Ø½á¹ûµÄʱºò£¬ASP.NetµÄÒýÇæ»áÒý·¢Ò»¸ö HttpRequestValidationExceptioin¡£Ä¬ÈÏÇé¿öÏ»᷵»ØÈçÏÂÎÄ×ÖµÄÒ³Ãæ£º
ÒÔÏÂÊÇÒýÓÃÆ¬¶Î£º
Server Error in '/YourApplicationPath' Application
A potentially dangerous Request.Form value was detected from the client
(txtName="<b>").
Description: Request Validation has detected a potentially dangerous client input value, and processing of the request has been aborted. This value may indicate an attempt to compromise the security of your application, such as a cross-site scripting attack. You can disable request validation by setting validateRequest=false in the Page directive or in the configuration section. However, it is strongly recommended that your application explicitly check all inputs in this case.
Exception Details: System.Web.HttpRequestValidationException: A potentially dangerous Request.Form value was detected from the client (txtName="<b>").
....
¡¡¡¡ÕâÊÇASP.NetÌṩµÄÒ»¸öºÜÖØÒªµÄ°²È«ÌØÐÔ¡£ÒòΪºÜ¶à³ÌÐòÔ±¶Ô°²È«Ã»ÓиÅÄÉõÖÁ¶¼²»ÖªµÀXSSÕâÖÖ¹¥»÷µÄ´æÔÚ£¬ÖªµÀÖ÷¶¯È¥·À»¤µÄ¾Í¸üÉÙÁË¡£ASP.NetÔÚÕâÒ»µãÉÏ×öµ½Ä¬Èϰ²È«¡£ÕâÑùÈö԰²È«²»ÊǺÜÁ˽âµÄ³ÌÐòÔ±ÒÀ¾É¿ÉÒÔд³öÓÐÒ»¶¨°²È«·À»¤ÄÜÁ¦µÄÍøÕ¾¡£
¡¡¡¡µ«ÊÇ£¬µ±ÎÒGoogleËÑË÷ HttpRequestValidationException »òÕß "A potentially dangerous Request.Form value was detected from the client"µÄʱºò£¬¾ªÆæµÄ·¢Ïִ󲿷ÖÈ˸ø³öµÄ½â¾ö·½°¸¾¹È»ÊÇÔÚASP.NetÒ³ÃæÃèÊöÖÐͨ¹ýÉèÖà validateRequest=false À´½ûÓÃÕâ¸öÌØÐÔ£¬¶ø²»È¥¹ØÐÄÄǸö³ÌÐòÔ±µÄÍøÕ¾ÊÇ·ñÕæµÄ²»ÐèÒªÕâ¸öÌØÐÔ¡£¿´µÃÎÒÕâ½ÐÒ»¸öµ¨Õ½Ðľª¡£°²È«ÒâʶӦ¸Ãʱʱ¿Ì¿ÌÔÚÿһ¸ö³ÌÐòÔ±µÄÐÄÀ²»¹ÜÄã¶Ô°²È«µÄ¸ÅÄîÁ˽â¶àÉÙ£¬Ò»¸öÖ÷¶¯µÄÒâʶÔÚÄÔ×ÓÀÄãµÄÕ¾µã¾Í»á°²È«ºÜ¶à¡£
¡¡¡¡ÎªÊ²Ã´ºÜ¶à³ÌÐòÔ±ÏëÒª½ûÖ¹ validateRequest ÄØ?ÓÐÒ»²¿·ÖÊÇÕæµÄÐèÒªÓû§ÊäÈë"<>"Ö®ÀàµÄ×Ö·û¡£Õâ¾Í²»±ØËµÁË¡£»¹ÓÐÒ»²¿·ÖÆäʵ²¢²»ÊÇÓû§ÔÊÐíÊäÈëÄÇЩÈÝÒ×ÒýÆðXSSµÄ×Ö·û£¬¶øÊÇÌÖÑáÕâÖÖ±¨´íµÄÐÎʽ£¬±Ï¾¹Ò»´ó¶ÎÓ¢ÎļÓÉÏÒ»¸öASP.NetµäÐÍÒì³£´íÎóÐÅÏ¢£¬ÏÔµÃÕâ¸öÕ¾µã³ö´íÁË£¬¶ø²»ÊÇÓû§ÊäÈëÁË·Ç·¨µÄ×Ö·û£¬¿ÉÊÇ×Ô¼ºÓÖ²»ÖªµÀÔõô²»ÈÃË
Ïà¹ØÎĵµ£º
¿ª·¢»·¾³:WIN XP VS2005
Êý¾Ý¿â:SQL server 2000
´Ë´¦²»¿¼Âǰ²È«ÎÊÌâ.
¾ßÌåÈçÏÂ:
Ê×ÏȽ¨Á¢Ò»¸öÊý¾Ý¿âºÍÒ»¸ö±í½á¹¹²¢ÔÚ±íÖÐÊäÈëһЩÊý¾ÝÒÔ±ã²âÊÔ:´Ë²½ÂÔ¹ý
´ò¿ªVS2005н¨Ò»¸öÍøÕ¾²¢Ìí¼ÓÒ»¸öHTMLÒ³
ÔÚĬÈϵÄDefault.aspxÖзÅÈëGridview¿Ø¼þÓÃÓÚÏÔʾÊý¾Ý
.cs´úÂë
using System;
using System.Data;
usi ......
Ò»¡¢Ð§¹ûͼ
1.¼òµ¥ÊôÐÔ
2.ÏÂÀ¿òÊôÐÔ
3.ÑÕÉ«ÊôÐÔ
4.°üº¬ÊôÐÔ
5.¼¯ºÏÊôÐÔ
±à¼Æ÷
6.ÈÕÆÚÊôÐÍ
¶þ¡¢³ÌÐò´úÂë
using System;
using System.Collections.Generic;
using System.ComponentModel;
using System.Text;
using System.Web;
using System.Web.UI;
using System.Web.UI.WebControls;
using System.Draw ......
ÈÎÖ°×ʸñ:
1. ´óѧ±¾¿ÆÒÔÉÏѧÀú£¬ÈýÄêÒÔÉÏÈí¼þ¿ª·¢¹¤×÷¾Ñé»ò»¥ÁªÍø¿ª·¢¾Ñ飻¾ßÓжþ¸ö¼°ÒÔÉÏÖÐÐÍÏîÄ¿µÄ³É¹¦ÊµÊ©¾Ñ飻
2. ÓÐ׼ȷÀí½âÐèÇ󡢼ܹ¹ÄÜÁ¦£¬ÓнÏÇ¿µÄ³ÌÐòÉè¼ÆÄÜÁ¦, ÊìÏ¤ÃæÏò¶ÔÏó·ÖÎö¡¢Èí¼þ¹¤³Ì¡¢UMLµÈÏà¹Ø¼¼Êõ£»
3. ÊìÁ·ÕÆÎÕ¼ÆËã»ú±à³ÌÒ»°ã˼ÏëºÍ·½·¨£»ÊìϤһÖÁÁ½ÖÖÃæÏò¶ÔÏó±à³ÌÓïÑÔ£»¾«Í¨.NET¡¢ C#¡¢ASP.net¡ ......
Ëü»¹»áÔÚÖ¸¶¨µÄÊý¾Ý¿âÖÐÔö¼Ó¼¸¸ö´æ´¢¹ý³Ì£¬ÓÃÀ´ÈÃASP.NETÒýÇæ²éѯ׷×ÙµÄÊý¾Ý±íµÄÇé¿ö¡£
È»ºó£¬Ëü»á¸øÎÒÃÇҪ׷×ÙµÄTable¼ÓÉϼ¸¸öTrigger£¬·Ö±ð¶ÔÓ¦µ½Insert¡¢Update¡¢Delete²Ù×÷£¬Õ⼸¸öTriggerµÄÓï¾ä·Ç³£¼òµ¥£¬¾ÍÊǰѓAspNet_SqlCacheTablesF ......
using System;
using System.Web;
using System.Text.RegularExpressions;
public static string NoHTML(string Htmlstring)
{
//ɾ³ý½Å±¾
Htmlstring = Regex.Replace(Htmlstring,@"<script[^>]*?>.*?&l ......