Ò׽ؽØͼÈí¼þ¡¢µ¥Îļþ¡¢Ãâ°²×°¡¢´¿ÂÌÉ«¡¢½ö160KB

ASP.NETÒ³Ãæ´«Êý¾ÝµÄ¸÷ÖÖ·½·¨ºÍ·ÖÎö

WebÒ³ÃæÊÇÎÞ״̬µÄ£¬ ·þÎñÆ÷¶Ôÿһ´ÎÇëÇó¶¼ÈÏΪÀ´×Ô²»Í¬Óû§£¬Òò´Ë£¬±äÁ¿µÄ״̬ÔÚÁ¬Ðø¶ÔͬһҳÃæµÄ¶à´ÎÇëÇóÖ®¼ä»òÔÚÒ³ÃæÌøתʱ²»»á±»±£Áô¡£ÔÚÓÃASP.NET Éè¼Æ¿ª·¢Ò»¸öWebϵͳʱ£¬ Óöµ½Ò»¸öÖØÒªµÄÎÊÌâÊÇÈçºÎ±£Ö¤Êý¾ÝÔÚÒ³Ãæ¼ä½øÐÐÕýÈ·¡¢°²È«ºÍ¸ßЧµØ´«ËÍ£¬Asp.net ÌṩÁË״̬¹ÜÀíµÈ¶àÖÖ¼¼ÊõÀ´½â¾ö±£´æºÍ´«µÝÊý¾ÝÎÊÌ⣬ÒÔÏÂÀ´Ì½ÌÖ.NET ÏµĽâ¾ö´ËÎÊÌâµÄ¸÷ÖÖ·½·¨ºÍ¸÷×ÔµÄÊÊÓó¡ºÏ¡£ 
1.1 Ê¹ÓÃQuerystring ·½·¨ 
QueryString Ò²½Ð²éѯ×Ö·û´®£¬ ÕâÖÖ·½·¨½«Òª´«µÝµÄÊý¾Ý¸½¼ÓÔÚÍøÒ³µØÖ·(URL)ºóÃæ½øÐд«µÝ¡£ÈçÒ³ÃæA.aspx Ìøתµ½Ò³ÃæB.aspx£¬¿ÉÒÔÓÃRequest.Redirect("B.aspx?²ÎÊýÃû³Æ=²ÎÊýÖµ")·½·¨£¬Ò²¿ÉÒÔÓó¬Á´½Ó£º£¬Ò³ÃæÌøתºó£¬ÔÚÄ¿±êÒ³ÃæÖпÉÓÃRuquest["²ÎÊýÃû³Æ"]À´½ÓÊÕ²ÎÊý¡£Ê¹ÓÃQuerySting ·½·¨µÄÓŵãÊÇʵÏÖ¼òµ¥£¬ ²»Ê¹Ó÷þÎñÆ÷×ÊÔ´£»È±µãÊÇ´«µÝµÄÖµ»áÏÔʾÔÚä¯ÀÀÆ÷µÄµØÖ·À¸ÉÏ£¬Óб»´Û¸ÄµÄ·çÏÕ£¬²»ÄÜ´«µÝ¶ÔÏó£¬Ö»ÓÐÔÚͨ¹ýURL ÇëÇóҳʱ²éѯ×Ö·û´®²ÅÊÇ¿ÉÐеġ£
1.2 ÀûÓÃÒþ²ØÓò 
Òþ²ØÓò²»»áÏÔʾÔÚÓû§µÄä¯ÀÀÆ÷ÖУ¬ Ò»°ãÊÇÔÚÒ³ÃæÖмÓÈëÒ»¸öÒþ²Ø¿Ø¼þ£¬ Óë·þÎñÆ÷½øÐн»»¥Ê±°ÑÖµ¸³¸øÒþ²Ø¿Ø¼þ²¢Ìá½»¸øÏÂÒ»Ò³Ãæ¡£Òþ²ØÓò¿ÉÒÔÊÇÈκδ洢ÔÚÍøÒ³ÖеÄÓëÍøÒ³ÓйصÄÐÅÏ¢µÄ´æ´¢¿â¡£Ê¹ÓÃÒþ²ØÓò´æÈëÊýֵʱÓãºhidden ¿Ø¼þ.value=ÊýÖµ£¬È¡³ö½ÓÊÕÊýֵʱÓ㺱äÁ¿=hidden ¿Ø¼þ.value¡£Ê¹ÓÃÒþ²ØÓòµÄÓŵãÊÇʵÏÖ¼òµ¥£¬ Òþ²ØÓòÊDZê×¼µÄHTML ¿Ø¼þ£¬²»ÐèÒª¸´Ôӵıà³ÌÂß¼­¡£Òþ²ØÓòÔÚÒ³ÉÏ´æ´¢ºÍ¶ÁÈ¡£¬²»ÐèÒªÈκηþÎñÆ÷×ÊÔ´£¬¼¸ºõËùÓÐä¯ÀÀÆ÷ºÍ¿Í»§¶ËÉ豸¶¼Ö§³Ö¾ßÓÐÒþ²ØÓòµÄ´°Ì塣ȱµãÊÇ´æ´¢½á¹¹ÉÙ£¬½ö½öÖ§³Ö¼òµ¥µÄÊý¾Ý½á¹¹£¬´æ´¢Á¿ÉÙ£¬ÒòΪËü±»´æ´¢ÔÚÒ³Ãæ±¾Éí£¬ËùÒÔÎÞ·¨´æ´¢½Ï´óµÄÖµ£¬¶øÇÒ´óµÄÊý¾ÝÁ¿»áÊܵ½·À»ðǽºÍ´úÀíµÄ×èÖ¹¡£
1.3 ViewState 
ViewState ÊÇÓÉASP.NET Ò³Ãæ¿ò¼Ü¹ÜÀíµÄÒ»¸öÒþ²ØµÄ´°Ìå×ֶΡ£µ±ASP.NET Ö´ÐÐij¸öÒ³Ãæʱ£¬¸ÃÒ³ÃæÉϵÄViewState ÖµºÍËùÓпؼþ½«±»ÊÕ¼¯²¢¸ñʽ»¯³ÉÒ»¸ö±àÂë×Ö·û´®£¬ È»ºó±»·ÖÅä¸øÒþ²Ø´°Ìå×ֶεÄÖµÊôÐÔ¡£Ê¹ÓÃViewState ´«µÝÊý¾Ýʱ¿ÉÓãºViewState [" ±äÁ¿Ãû"]=ÊýÖµ£¬ÔÚÈ¡³öÊý¾ÝʱÓ㺱äÁ¿=ViewState["±äÁ¿Ãû"]¡£Ê¹ÓÃViewState µÄÓŵãÊÇ£ºÔÚ¶ÔͬһҳµÄ¶à¸öÇëÇó¼ä×Ô¶¯±£ÁôÖµ£¬²»Ó÷þÎñÆ÷¶Ë×ÊÔ´£¬ÊµÏÖ¼òµ¥£¬ÊÓͼ״̬ÖеÄÖµ¾­¹ý¹þÏ£¼ÆËãºÍѹËõ£¬²¢ÇÒÕë¶ÔUnicode&


Ïà¹ØÎĵµ£º

asp.net¸÷ÖÖÈÕÆÚ²Ù×÷


±¾ÎÄÎÒÃǽ«ÌÖÂÛµÄÊÇASP.NETÒ³Ãæ¼äÊý¾Ý´«µÝµÄ¼¸ÖÖ·½·¨£¬¶Ô´ËÏ£ÍûÄÜ°ïÖú´ó¼ÒÕýÈ·µÄÀí½âASP.NETÒ³Ãæ¼äÊý¾Ý´«µÝµÄÓô¦ÒÔ¼°±ãÀûÐÔ¡£
0¡¢ÒýÑÔ
WebÒ³ÃæÊÇÎÞ״̬µÄ£¬ ·þÎñÆ÷¶Ôÿһ´ÎÇëÇó¶¼ÈÏΪÀ´×Ô²»Í¬Óû§£¬Òò´Ë£¬±äÁ¿µÄ״̬ÔÚÁ¬Ðø¶ÔͬһҳÃæµÄ¶à´ÎÇëÇóÖ®¼ä»òÔÚÒ³ÃæÌøתʱ²»»á±»±£Áô¡£ÔÚÓÃASP.NET Éè¼Æ¿ª·¢Ò»¸öWebϵͳʱ£¬ Óöµ ......

ASP.NETʵÓÃÐÔ¼¼Çɾ«ÝÍ

1.Ö÷ÒªÃüÃû¿Õ¼ä:
1.<% @ Import Namespace="System.Data" %> ´¦ÀíÊý¾ÝʱÓõ½
2.   <% @ Import Namespace="System.Data.ADO" % >   ʹÓÃADO.net ʱÓõ½
3.   <% @ Import Namespace="System.Data.SQL" %>   SQL Server Êý¾Ý¿âרÓÃ
4.   <% @ ......

asp.net viewstat Tampering Vulnerabilities

Trustwave's SpiderLabs Security Advisory TWSL2010-001:
Multiplatform View State Tampering Vulnerabilities
Published: 2010-02-08 Version: 1.1
SpiderLabs has documented view state tampering
vulnerabilities in three products from separate vendors.
View states are used by some web application frame ......

ÔÚASP.NET 4ÖÐÈçºÎ×Ô¶¯Æô¶¯WebÓ¦Óã¿

ÓÐЩwebÓ¦ÓÃÔÚ¿ÉÒÔ´¦ÀíÓû§·ÃÎÊ֮ǰ£¬ÐèҪװÔغܶàµÄÊý¾Ý£¬»ò×öһЩ»¨·ÑºÜ´óµÄ³õʼ»¯´¦Àí¡£½ñÌìʹÓà ASP.NET µÄ¿ª·¢ÈËÔ±¾­³£Ê¹ÓÃÓ¦ÓõÄGlobal.asax ÎļþÖÐµÄ “Application_Start”ʼþ´¦Àíº¯ÊýÀ´×öÕâЩ¹¤×÷£¨¸ÃʼþÊÇÔÚµÚÒ»¸öÇëÇóÖ´ÐÐʱ´¥·¢µÄ£©¡£ËûÃÇҪôÉè¼Æ¶¨Öƽű¾£¬ÖÜÆÚÐÔµØÏòÓ¦Ó÷¢¼ÙµÄÇëÇó£¬À´“»½Ð ......

SocketͨÐÅδÍê³É£¬×ÔѧASP.NETСÓгÉЧ£¬³õʶAjax

½øÈ¥º®¼Ù£¬ÓÉÓÚÒ»¸ö»ë»ëججµÄѧÆÚ½áÊøÁË£¬²»ÏëÁî×Ô¼º¼ÌÐø³ÁÄçÔÚÄÇ»èÌìºÚµØÖ®ÖУ¬ÓÚÊÇÈ¥Library½èÁËÒ»±¾ºÜºñºÜÖصÄC# ASP.NETµÄÊ飬¸½¹âÅÌ¡£ÓÐȤµÄ£¬ÎÒÓÃÀúÀ´Ñ§Ï°¿Î±¾ÖªÊ¶µÄ·ÅѧѧϰC#ºÍÊìϤVS»·¾³£¬»¹×öÁ˲»ÉÙ¶ÁÊé±Ê¼Ç£¬°¥£¬ÕæµÄûÄǸö±ØÒª°¡£¬²»¹ý¿´ÁË1-2ÖÜÖ®ºó£¬¶ÔÓÚ·þÎñÆ÷¶Ë¿Ø¼þµÄÈ·ÊÇÊìϤ²»ÉÙ£¬¶ÔÓڱ߽߱ŽŵÄһЩҳÃæ ......
© 2009 ej38.com All Rights Reserved. ¹ØÓÚE½¡ÍøÁªÏµÎÒÃÇ | Õ¾µãµØͼ | ¸ÓICP±¸09004571ºÅ