Ò׽ؽØͼÈí¼þ¡¢µ¥Îļþ¡¢Ãâ°²×°¡¢´¿ÂÌÉ«¡¢½ö160KB

ASP.NETÖÐʹÓÃweb.configÅäÖÃÊý¾Ý¿âÁ¬½Ó

ASP.NETÖÐʹÓÃweb.configÅäÖÃÊý¾Ý¿âÁ¬½Ó 
 ÔÚweb.configÎļþÖб£´æÊý¾Ý¿âÁ¬½ÓÅäÖÃÐÅÏ¢,¿ÉÒÔÈÃÄãÎÞÐëÖØбàÒëÓ¦ÓóÌÐò¼´¿É¸üÐÂÓ¦ÓóÌÐòµÄijЩÊôÐÔ¡£µ±ÄãÏë°ÑÊý¾Ý¿âǨÒƵ½ÁíÒ»¸ö²»Í¬µÄ·þÎñÆ÷£¬ÄãÖ»ÐèÒªÐÞ¸Äweb.configÎļþÖеÄÊý¾Ý¿âÁ¬½ÓÅäÖÃÐÅÏ¢¶øÒÑ£¬²¢²»ÐèÒªÖØбàÒëºÍÖØв¿ÊðÕâ¸öÓ¦ÓóÌÐòÒÔÊÊӦеķþÎñÆ÷µÄÒªÇó¡£
       Äã»á¾­³£Åöµ½ÕâÖÖÇé¿ö£º¼¸ºõÔÚÍøÕ¾µÄÿ¸öÒ³ÃæÉÏ,´æ´¢Ò»Ð©È«¾Ö´¦ÀíÐÅÏ¢¡£ÀíÏëµÄ×ö·¨Êǽ«ÕâЩÐÅÏ¢Ò»´ÎÐԵļ¯Öд洢ÔÚ×ÊÁϵµ°¸¿âÖУ¬¶ø²»ÊÇÔÚÍøÕ¾µÄÿ¸öÒ³ÃæÉ϶¼Öظ´ÕâÑùµÄ²Ù×÷¡£±ÈÈç˵Êý¾Ý¿âÁ¬½Ó´®¾ÍÊÇÕâÑùµÄÐÅÏ¢£¬Èç¹ûÕâЩÐÅÏ¢²»ÊǼ¯Öд洢ÔÚÌض¨ÇøÓòÖУ¬¶øÊÇÔÚÍøÕ¾µÄÿ¸öÐèÒªÁ¬½ÓÊý¾Ý¿âµÄÒ³ÃæÉÏÊÖ¹¤ÊäÈ룬¿ÉÒÔÉèÏ룺µ±Êý¾Ý¿âÁ¬½Ó´®¸Ä¶¯Ê±½«»áÁîÈËÍ·Í´£¬Äã±ØÐë±éÀúÍøÕ¾ÖÐËùÓÐÁ¬½ÓÊý¾Ý¿âµÄÒ³ÃæÈ¥Ð޸ģ¡
ÔÚASP.NETÖУ¬Í¨¹ýWeb.config£¬Äã¿ÉΪʹÓÃ<appSettings>±ê¼Ç£¬ÔÚÕâ¸ö±ê¼ÇÖУ¬Äã¿ÉÓÃ<add.../>±ê¼Ç¶¨Òå0µ½¶à¸öÉèÖᣱ¾ÎÄÖÐÎÒÃÇÖ÷ÒªÌÖÂÛÁËÈçºÎʹÓÃweb.configÀ´ÅäÖÃÒ»¸öwebÓ¦ÓóÌÐòÖеÄÊý¾Ý¿âÁ¬½Ó¡£
web.configÎļþÊDZê×¼µÄxmlÎļþ£¬ÎÒÃÇ¿ÉÒÔʹÓÃËüÀ´ÎªÒ»Ì¨»úÆ÷ϵÄÿһ¸öwebÓ¦ÓóÌÐò»òij¸öÓ¦ÓóÌÐò»òÒ»¸öĿ¼ÏµÄasp.netÒ³ÃæÀ´½øÐÐÉèÖ㬵±È»£¬ËüÒ²¿ÉÒÔΪһ¸öµ¥¶ÀµÄwebÒ³Ãæ½øÐÐÉèÖá£
È磺ÍøÕ¾µÄÖ÷Ŀ¼ÊÇinetpubwwwroot£¬ÄÇôÎÒÃǽ«web.config·ÅÖÃÓÚÆäÏ£¬ÄÇôÕâ¸öÍøÕ¾ÖеÄÓ¦ÓóÌÐò½«±»web.configÖеÄÉèÖÃËùÓ°Ïì¡£
e.g.£º
<?xmlversion="1.0"encoding="gb2312"?>
<configuration>
<system.web>
<compilationdefaultlanguage="vb"debug="true"/>
<customerrorsmode="remoteonly"defaultredirect="js/error.htm">
 <errorstatuscode="404"redirect="js/filenotfound.aspx"/>
 <errorstatuscode="500"redirect="js/error.htm"/>
</customerrors>
<authenticationmode="windows"/>
<authorization>
 <allowusers="*"/>
</authorization>
<httpruntimemaxrequestlength="4000"usefullyqualifiedredirecturl="true"executiontimeout="45"/>
<traceenabled="false"requestlimit="10"pageoutput="false"tracemode="sortbytime"localonly="true"/>
<sessionstatemode="inproc"stateconnectionstring="tcpip=127.0.0.1:43444"cookieless="false


Ïà¹ØÎĵµ£º

ASP.NET AJAX ½Ìѧ±Ê¼Ç(Èý) 1

Ajax¿ª·¢ÈËÔ±ÐèÒªµÄJavaScript֪ʶ
  JavaScriptµ®ÉúÓÚ1995 Ä꣬×î×³ÉÔÚNetsCape Navigatorä¯ÀÀÆ÷ÖС£Microsoft ÔÚIE3Öм¯³É¡£1998Äê±»±ê×¼»¯ÎªECMAScript.
  Microsoft Ajax Library¸ÄÉÆÁËJavaScriptµÄÃæÏò¶ÔÏóÄ£ÐÍ¡£
3.1ʹÓöÔÏó
   JavaScriptÖеĶÔÏó²¢²»ÊÇÀàÐ͵ÄʵÀý£¬ÒòΪJavaScript²»Ö§³ ......

ASP.NET SQL ×¢ÈëÃâ·Ñ½â¾ö·½°¸

 UrlScanµÄ3.1ÊÇÒ»¸ö°²È«µÄ¹¤¾ß£¬ÏÞÖÆÁËIISµÄHTTPÇëÇ󽫴¦ÀíÀàÐÍ¡£ ͨ¹ý×èÖ¹Ìض¨µÄHTTPÇëÇó£¬ÔÚURLScan 3.1°²È«¹¤¾ßÓÐÖúÓÚ·ÀÖ¹¶Ô·þÎñÆ÷Ó¦ÓóÌÐò¿ÉÄÜÓꦵÄÇëÇó¡£  UrlScanµÄ3.1ÊÇURLScan 2.5µÄ¸üа汾¡£Ö§³ÖIIS 5.1ÖУ¬IIS 6.0ºÍIIS 7.0ÔÚWindows VistaºÍWindows Server 2008¡£ÏÂÔصØÖ·http://download.csdn.net ......

asp.net viewstat Tampering Vulnerabilities

Trustwave's SpiderLabs Security Advisory TWSL2010-001:
Multiplatform View State Tampering Vulnerabilities
Published: 2010-02-08 Version: 1.1
SpiderLabs has documented view state tampering
vulnerabilities in three products from separate vendors.
View states are used by some web application frame ......

ASP.NETÒ³Ãæ´«Êý¾ÝµÄ¸÷ÖÖ·½·¨ºÍ·ÖÎö

WebÒ³ÃæÊÇÎÞ״̬µÄ£¬ ·þÎñÆ÷¶Ôÿһ´ÎÇëÇó¶¼ÈÏΪÀ´×Ô²»Í¬Óû§£¬Òò´Ë£¬±äÁ¿µÄ״̬ÔÚÁ¬Ðø¶ÔͬһҳÃæµÄ¶à´ÎÇëÇóÖ®¼ä»òÔÚÒ³ÃæÌøתʱ²»»á±»±£Áô¡£ÔÚÓÃASP.NET Éè¼Æ¿ª·¢Ò»¸öWebϵͳʱ£¬ Óöµ½Ò»¸öÖØÒªµÄÎÊÌâÊÇÈçºÎ±£Ö¤Êý¾ÝÔÚÒ³Ãæ¼ä½øÐÐÕýÈ·¡¢°²È«ºÍ¸ßЧµØ´«ËÍ£¬Asp.net ÌṩÁË״̬¹ÜÀíµÈ¶àÖÖ¼¼ÊõÀ´½â¾ö±£´æºÍ´« ......
© 2009 ej38.com All Rights Reserved. ¹ØÓÚE½¡ÍøÁªÏµÎÒÃÇ | Õ¾µãµØͼ | ¸ÓICP±¸09004571ºÅ