ASP.NETÒ³ÃæÔËÐлúÖÆÒÔ¼°ÇëÇó´¦ÀíÁ÷³Ì
IIS´¦ÀíÒ³ÃæµÄÔËÐлúÖÆ£º
IIS×ÔÉíÊDz»ÄÜ´¦ÀíÏñASPXÀ©Õ¹ÃûÕâÑùµÄÒ³Ãæ£¬Ö»ÄÜÖ±½ÓÇëÇóÏñHTMLÕâÑùµÄ¾²Ì¬Îļþ£¬Ö®ËùÒÔÄÜ´¦ÀíASPXÕâÑùÀ©Õ¹ÃûµÄÒ³Ãæ£¬ÊÇÒòΪIISÓÐÒ»¸öISAPI¹ýÂËÆ÷£¬ËüÊÇÒ»¸öCOM×é¼þ¡£ASP.NET·þÎñÔÚ×¢²áµ½IISµÄʱºò£¬¾Í»áÌí¼ÓÒ»¸öWin32µÄÀ©Õ¹¶¯Ì¬¿âaspnet_isapi.dll¡£²¢½«À©Õ¹¿ÉÒÔ´¦ÀíµÄÒ³ÃæÀ©Õ¹Ãû£¨ÈçASPX£©×¢²áµ½IISÀïÃæ¡£À©Õ¹Æô¶¯ºó£¬¾Í¸ù¾Ý¶¨ÒåºÃµÄ·½Ê½À´´¦ÀíIISËù²»ÄÜ´¦ÀíµÄÒ³Ãæ¡£
µ±¿Í»§¶ËÇëÇóÒ»¸ö·þÎñÆ÷×ÊԴʱ£¬Õâ¸öHTTPÇëÇó»á±»inetinfo.exe½ø³Ì½Ø»ñ£¨www·þÎñ£©£¬È»ºóCheckÇëÇó×ÊÔ´µÄÀàÐÍ£¬²¢ÒÀ¾Ý×ÊÔ´Ó³ÉäÐÅÏ¢£¨´æ´¢ÔÚIISÔª¿âÖУ¬Ò»ÖÖIISרÓõÄÅäÖÃÊý¾Ý¿â£©½«ÇëÇóµÄ×ÊÔ´·ÖÅä¸øÌØ¶¨µÄ´¦Àí³ÌÐòÄ£¿é¡£ÈôÇëÇóµÄÊǾ²Ì¬×ÊÔ´£¨img,text,htmlµÈ£©ÔòÓÉIIS´¦Àí£¨IISÔÚ±¾µØWeb ServerÉÏ·ÃÎÊÇëÇóµÄÎļþ£©£¬½«ÄÚÈÝÊä³öµ½¿ØÖÆÌ¨£¬·¢³öÇëÇóµÄä¯ÀÀÆ÷¾ÍÄܽÓÊÕµ½ËüÁË¡£ÈôÐèÒªÔÚ·þÎñÆ÷¶Ë´¦ÀíµÄÇëÇó£¬Ôò»á±»´«µ½ÒÑ×¢²áµÄÀ©Õ¹Ä£¿éÖУ¬aspxÇëÇó»á±»·ÖÅ䏸aspnet_isapi.dll£¬ÈÃÕâ¸ö³ÌÐò¿ªÊ¼´¦Àí´úÂ룬Éú³É±ê×¼µÄHTML´úÂ룬Ȼºó½«ÕâЩHTML¼ÓÈëµ½ÔÓеÄHTMLÖУ¬×îºó°ÑÍêÕûµÄHTML·µ»Ø¸øIIS£¬IISÔÙ°ÑÄÚÈÝ·¢Ë͵½¿Í»§ä¯ÀÀÆ÷¡£
ASP.NET FrameWork¶ÔÇëÇóµÄ´¦Àí£º
ÉÏÃæËµµ½IIS½«ÏñASPXÕâÑùµÄÒ³Ãæ·ÖÅ䏸aspnet_isapi.dll£¬½Ó×Å´¦ÀíÈçÏ£º
1¡¢aspnet_isapi.dllÔò»áͨ¹ýÒ»¸öHttp PipeLineµÄ¹ÜµÀ½«Õâ¸öHttpÇëÇ󷢸øw3wp.exe£¨iis ¹¤×÷Õß½ø³Ì£¬IIS6.0ÖнÐ×ö w3wq.exe£¬IIS5.0ÖнÐ×ö aspnet_wp.exe)£¬Ö®ºóasp.net framework¾Í»áͨ¹ýHttpRuntimeÀ´´¦ÀíÕâ¸öHttpÇëÇó¡£
2¡¢HttpRuntimeÊ×ÏÈ»áÈ·¶¨´¦Àí¸ÃÇëÇóµÄÀàÃû£¬HttpRuntimeͨ¹ý¹«¹²½Ó¿ÚIHttpHandlerÀ´µ÷ÓøÃÀà»ñÈ¡±»ÇëÇó×ÊÔ´µÄÀàµÄʵÀý¡£
3¡¢µ÷ÓÃHttpRuntime.ProcessRequest¿ªÊ¼´¦ÀíÒª·¢Ë͵½ä¯ÀÀÆ÷µÄÒ³Ãæ£¬¾ßÌå˵¾ÍÊÇ´´½¨Ò»¸öHttpContextʵÀý£¬Ëü·â×°ÁËËùÓÐÓëÇëÇóÓйصÄhttpÌØÓеÄÐÅÏ¢£¬²¢³õʼ»¯Ò»¸öWrite¶ÔÏóÓÃÓÚ»º´æ±ê¼Ç´úÂë¡£
4¡¢HttpRuntimeʹÓÃÉÏÏÂÎÄÐÅÏ¢²éÕÒ»òн¨ÄÜ´¦Àí¸ÃÇëÇóµÄWEBÓ¦ÓóÌÐòµÄ¶ÔÏó¡£ÓÉHttpApplication Factory¸ºÔð·µ»ØHttpApplicationʵÀý¡£
5¡¢HttpApplicationʵÀý»á¶ÁÈ¡web.configÖÐËùÓÐHttpModuleµÄÅäÖá£
5¡¢HttpApplication¶ÔÏóʹÓÃIHttpHandlerFactoryÀàÐ͵ÄʵÀý·µ»ØHttpHandler£¨http´¦Àí³ÌÐò£©¸øHttpRuntime¶ÔÏó¡£Ò»¸öÒ³ÃæÖ»ÊǸöhttp´¦Àí³ÌÐò¶ÔÏó¡£
6¡¢×îºóÓÉHttpRuntime¶ÔÏóµ÷ÓÃIHttpHandlerµÄÒ³Ãæ¶ÔÏóµÄProcessRequest·½·¨¡£
from http://space.itpub.net/12639
Ïà¹ØÎĵµ£º
UrlScanµÄ3.1ÊÇÒ»¸ö°²È«µÄ¹¤¾ß£¬ÏÞÖÆÁËIISµÄHTTPÇëÇ󽫴¦ÀíÀàÐÍ¡£ ͨ¹ý×èÖ¹ÌØ¶¨µÄHTTPÇëÇó£¬ÔÚURLScan 3.1°²È«¹¤¾ßÓÐÖúÓÚ·ÀÖ¹¶Ô·þÎñÆ÷Ó¦ÓóÌÐò¿ÉÄÜÓꦵÄÇëÇó¡£ UrlScanµÄ3.1ÊÇURLScan 2.5µÄ¸üа汾¡£Ö§³ÖIIS 5.1ÖУ¬IIS 6.0ºÍIIS 7.0ÔÚWindows VistaºÍWindows Server 2008¡£ÏÂÔØµØÖ·http://download.csdn.net ......
±¾ÎÄÎÒÃǽ«ÌÖÂÛµÄÊÇASP.NETÒ³Ãæ¼äÊý¾Ý´«µÝµÄ¼¸ÖÖ·½·¨£¬¶Ô´ËÏ£ÍûÄܰïÖú´ó¼ÒÕýÈ·µÄÀí½âASP.NETÒ³Ãæ¼äÊý¾Ý´«µÝµÄÓô¦ÒÔ¼°±ãÀûÐÔ¡£
0¡¢ÒýÑÔ
WebÒ³ÃæÊÇÎÞ״̬µÄ£¬ ·þÎñÆ÷¶Ôÿһ´ÎÇëÇó¶¼ÈÏΪÀ´×Ô²»Í¬Óû§£¬Òò´Ë£¬±äÁ¿µÄ״̬ÔÚÁ¬Ðø¶ÔÍ¬Ò»Ò³ÃæµÄ¶à´ÎÇëÇóÖ®¼ä»òÔÚÒ³ÃæÌø×ªÊ±²»»á±»±£Áô¡£ÔÚÓÃASP.NET Éè¼Æ¿ª·¢Ò»¸öWebϵͳʱ£¬ Óöµ ......
1.Ö÷ÒªÃüÃû¿Õ¼ä:
1.<% @ Import Namespace="System.Data" %> ´¦ÀíÊý¾ÝʱÓõ½
2. <% @ Import Namespace="System.Data.ADO" % > ʹÓÃADO.net ʱÓõ½
3. <% @ Import Namespace="System.Data.SQL" %> SQL Server Êý¾Ý¿âרÓÃ
4. <% @ ......
Trustwave's SpiderLabs Security Advisory TWSL2010-001:
Multiplatform View State Tampering Vulnerabilities
Published: 2010-02-08 Version: 1.1
SpiderLabs has documented view state tampering
vulnerabilities in three products from separate vendors.
View states are used by some web application frame ......
WebÒ³ÃæÊÇÎÞ״̬µÄ£¬ ·þÎñÆ÷¶Ôÿһ´ÎÇëÇó¶¼ÈÏΪÀ´×Ô²»Í¬Óû§£¬Òò´Ë£¬±äÁ¿µÄ״̬ÔÚÁ¬Ðø¶ÔÍ¬Ò»Ò³ÃæµÄ¶à´ÎÇëÇóÖ®¼ä»òÔÚÒ³ÃæÌø×ªÊ±²»»á±»±£Áô¡£ÔÚÓÃASP.NET Éè¼Æ¿ª·¢Ò»¸öWebϵͳʱ£¬ Óöµ½Ò»¸öÖØÒªµÄÎÊÌâÊÇÈçºÎ±£Ö¤Êý¾ÝÔÚÒ³Ãæ¼ä½øÐÐÕýÈ·¡¢°²È«ºÍ¸ßЧµØ´«ËÍ£¬Asp.net ÌṩÁË״̬¹ÜÀíµÈ¶àÖÖ¼¼ÊõÀ´½â¾ö±£´æºÍ´« ......