¹ØÓÚASP.NetµÄvalidateRequest=false£¨ÑéÖ¤ÇëÇó£©
ASP.NetµÄvalidateRequest=false
validateRequest="false" Ö¸ÊÇ·ñÒªIISÑéÖ¤Ò³ÃæÌá½»µÄ·Ç·¨×Ö·û£¬±ÈÈ磺>,<ºÅµÈ,µ±ÎÒÃÇÐèÒª½«Ò»¶¨¸ñʽµÃhtml´úÂë»ñµÃ£¬²åÈëÊý¾Ý¿âʱºò£¬¾ÍÒª½«Õâ¸öÊôÐÔÉèÖÃΪfalse,ÀýÈçÄ㽫×ÖÌå¼Ó´ÖµÈ²Ù×÷ʱ¡£
ASP.Net 1.1ºóÒýÈëÁ˶ÔÌá½»±íµ¥×Ô¶¯¼ì²éÊÇ·ñ´æÔÚXSS(¿çÕ¾½Å±¾¹¥»÷)µÄÄÜÁ¦¡£µ±Óû§ÊÔͼÓÃÖ®ÀàµÄÊäÈëÓ°ÏìÒ³Ãæ·µ»Ø½á¹ûµÄʱºò£¬ASP.NetµÄÒýÇæ»áÒý·¢Ò»¸ö HttpRequestValidationExceptioin¡£Ä¬ÈÏÇé¿öÏ»᷵»ØÈçÏÂÎÄ×ÖµÄÒ³Ãæ£º
ÒÔÏÂÊÇÒýÓÃÆ¬¶Î£º
Server Error in '/YourApplicationPath' Application
A potentially dangerous Request.Form value was detected from the client
(txtName="<b>").
Description: Request Validation has detected a potentially dangerous client input value, and processing of the request has been aborted. This value may indicate an attempt to compromise the security of your application, such as a cross-site scripting attack. You can disable request validation by setting validateRequest=false in the Page directive or in the configuration section. However, it is strongly recommended that your application explicitly check all inputs in this case.
Exception Details: System.Web.HttpRequestValidationException: A potentially dangerous Request.Form value was detected from the client (txtName="<b>").
....
¡¡¡¡ÕâÊÇASP.NetÌṩµÄÒ»¸öºÜÖØÒªµÄ°²È«ÌØÐÔ¡£ÒòΪºÜ¶à³ÌÐòÔ±¶Ô°²È«Ã»ÓиÅÄÉõÖÁ¶¼²»ÖªµÀXSSÕâÖÖ¹¥»÷µÄ´æÔÚ£¬ÖªµÀÖ÷¶¯È¥·À»¤µÄ¾Í¸üÉÙÁË¡£ASP.NetÔÚÕâÒ»µãÉÏ×öµ½Ä¬Èϰ²È«¡£ÕâÑùÈö԰²È«²»ÊǺÜÁ˽âµÄ³ÌÐòÔ±ÒÀ¾É¿ÉÒÔд³öÓÐÒ»¶¨°²È«·À»¤ÄÜÁ¦µÄÍøÕ¾¡£
¡¡¡¡µ«ÊÇ£¬µ±ÎÒGoogleËÑË÷ HttpRequestValidationException »òÕß "A potentially dangerous Request.Form value was detected from the client"µÄʱºò£¬¾ªÆæµÄ·¢Ïִ󲿷ÖÈ˸ø³öµÄ½â¾ö·½°¸¾¹È»ÊÇÔÚASP.NetÒ³ÃæÃèÊöÖÐͨ¹ýÉèÖà validateRequest=false À´½ûÓÃÕâ¸öÌØÐÔ£¬¶ø²»È¥¹ØÐÄÄǸö³ÌÐòÔ±µÄÍøÕ¾ÊÇ·ñÕæµÄ²»ÐèÒªÕâ¸öÌØÐÔ¡£¿´µÃÎÒÕâ½ÐÒ»¸öµ¨Õ½Ðľª¡£°²È«ÒâʶӦ¸Ãʱʱ¿Ì¿ÌÔÚÿһ¸ö³ÌÐòÔ±µÄÐÄÀ²»¹ÜÄã¶Ô°²È«µÄ¸ÅÄîÁ˽â¶àÉÙ£¬Ò»¸öÖ÷¶¯µÄÒâʶÔÚÄÔ×ÓÀÄãµÄÕ¾µã¾Í»á°²È«ºÜ¶à¡£
¡¡¡¡ÎªÊ²Ã´ºÜ¶à³ÌÐòÔ±ÏëÒª½ûÖ¹
Ïà¹ØÎĵµ£º
¼¸¸öÔÂǰ£¬×öÓû§×¢²áÄ£¿éÒªÓõ½·¢ËÍÓʼþ¹¦ÄÜ£¬Ò²Åöµ½ÁËЩ»ò´ó»òСµÄÎÊÌ⣬ÏÖÔÚ×ܽáһϣº
ÎÒÏÈÌù³ö·¢ËÍÓʼþÓõ½µÄ´úÂ룺
public void SendEmail(string stremail, string content,string title)
{
MailMessage mm = new MailMessage();
mm.from = new MailAddress(¹«Ë¾ÓÊÏä) ......
Dotjum 這邊Òª½é紹Ò²ÊÇÒ»個ºÜ經µäµÄ ASP.NET ÀÏ問題£¬¾ÍÊÇÔõ麼ÒªÔÚÏÂÀ選項ÖУ¬Ò»開ʼ DataBind() 資ÁÏ繫結時£¬
¾ÍÏȳö現預設選項 請選擇£¬Æä實×ö這個· ......
ASP.NETĬÈÏÀ©Õ¹ÃûΪ.aspx£¬¿ÉÊÇÎÒÃÇ¿´µ½Ðí¶àÍøÕ¾µÄÀ©Õ¹ÃûºÜÌØ±ð£¬±ÈÈçУÄÚµÄdo¡£¸öÐÔÖ®Ó໹¿ÉÒÔʵÏÖ¼òµ¥µÄα¾²Ì¬£¨¼´°Ñºó׺¸ÄΪhtml£©²»¹ýÏà¶ÔURLRewriterÀ´Ëµ£¬ÊÇÓеã¼òª£¨Ö»ÄܸĵôÁ¬½ÓÖеÄ.aspx£©£¬²»¹ý²»Ê§ÎªÒ»ÖÖ·½·¨¡£ÏÂÃæÎÒÃǾÍÀ´ÊµÏÖËû£¡
ÏÈÀ´ËµÒ»ÏÂASP.NET 1.1Öеķ½·¨£º
......
ÏÖÔÚASP.NETÐéÄâÖ÷»úÒ»°ã¶¼¿ÉÒ԰󶨶à¸öÓòÃû£¬µ«ÊÇͨ¹ýÕ⼸¸öÓòÃû´ò¿ªµÄÒ³Ãæ¶¼Ò»Ñù¡£ÈçºÎʹ°óµÄÕ⼸¸öÓòÃû·Ö±ð´ò¿ª²»Í¨µÄÒ³Ãæ£¨¼´ÊµÏÖ×ÓÍøÕ¾µÄ¹¦ÄÜ£©ÄØ£¿ ÆäʵºÜ¼òµ¥£¬Ö»Ðè4¸ö²½Ö裺
1£©¸øÐéÄâÖ÷»ú°ó¶¨¼¸¸öÓòÃû£»ÀýÈ磺www.abc.com£¬services.abc.com£¬support.abc.com¡£
2 ......
Êý¾Ý¿â·ÃÎÊÐÔÄÜÓÅ»¯
Êý¾Ý¿âµÄÁ¬½ÓºÍ¹Ø±Õ
¡¡¡¡·ÃÎÊÊý¾Ý¿â×ÊÔ´ÐèÒª´´½¨Á¬½Ó¡¢´ò¿ªÁ¬½ÓºÍ¹Ø±ÕÁ¬½Ó¼¸¸ö²Ù×÷¡£ÕâЩ¹ý³ÌÐèÒª¶à´ÎÓëÊý¾Ý¿â½»»»ÐÅÏ¢ÒÔͨ¹ýÉí·ÝÑéÖ¤£¬±È½ÏºÄ·Ñ·þÎñÆ÷×ÊÔ´¡£ ASP.NETÖÐÌṩÁËÁ¬½Ó³Ø(Connection Pool)¸ÄÉÆ´ò¿ªºÍ¹Ø±ÕÊý¾Ý¿â¶ÔÐÔÄܵÄÓ°Ï졣ϵͳ½«Óû§µÄÊý¾Ý¿âÁ¬½Ó·ÅÔÚÁ¬½Ó³ØÖУ¬ÐèҪʱȡ³ö£¬¹Ø±ÕʱÊÕ» ......