ASP.NET¶ÁÈ¡ASPÉèÖõÄCookie
ÕâÀàÎÊÌâͨ³£ÔÚÕûºÏ»ò¶þ´Î¿ª·¢ASPÍøվʱÓöµ½¡£°´³£ÀíÀ´Ëµ£¬ä¯ÀÀÆ÷µÄCookie´æ·ÅÔÚ¿Í»§¶Ë£¬Êµ¼ÊÉÏÓë·þÎñ¶ËʹÓÃʲôÓïÑÔÎ޹أ¬µ«ÎÒÃÇÔÚʵ¼Ê²Ù×÷¹ý³ÌÖУ¬×Ü»áÓöµ½Ò»Ð©ÒâÏë²»µ½µÄÎÊÌâ¡£
1. µ±ASPдµÄCookieµÄKeyÖдøÓÐÏ»®Ïߣ¬ÀýÈçÎÒÃÇÔÚASPÖÐÕâÑùÉèÖÃCookie:
Response.Cookies("Admin_User")="¹ÜÀíÔ±";
ÄÇôÔÚaspx.csµÄÒ³Ã棬ʹÓÃRequest.Cookie["Admin_User"] £¬ÊÇÔõô¶¼¶Á²»µ½µÄ¡£ÔÚÕâÀïÎÒдÁËÒ»¸öÑ»·£¬½«µ±Ç°cookieµÄËùÓÐNameÓëValue¶¼Êä³öÁËÒ»±é£¬·¢ÏÖÏ»®Ïß“_”ÒѾתÒå³ÉÁË“%5F”£¬¶øʹÓÃRequest.Cookie["Admin%5FUser"] ¾Í¿ÉÒԵõ½ÎÒÃÇÏëÒªµÄ“¹ÜÀíÔ±”ÁË¡£
Óöµ½ÀàËÆÎÊÌâµÄÅóÓÑ£¬²»·Á×öÕâÑùµÄ³¢ÊÔ¡£
2. »¹ÐèҪעÒâÖÐÎÄÂÒÂëµÄÎÊÌ⣬²»¹ÜÎÒ½«×Ö·û¼¯ÉèÖÃΪGB2312£¬»¹ÊÇGBK£¬ÉõÖÁÊÇUTF-8¶¼Ã»·¨»ñµÃÕýÈ·µÄÖÐÎÄ£¬Êµ¼ÊÉÏÎÊÌâ³öÔÚASPÄDZߣ¬ASPÒ³ÃæÏÔʾ¼òÌåÖÐÎÄʱ£¬ÐèÒªÉèÖÓ´úÂëÒ³”£¨Ëü¿É¶Áд£¬ÕûÐÍÊý£¬ÓÃÓÚ±íʾÏÔʾҳÄÚÈݵÄ×Ö·û¼¯£¬¼òÌåÖÐÎÄΪ936£¬ÈÕÎÄΪ932£¬ANSIΪ1252£©¡£
string cookie = System.Web.HttpUtility.UrlDecode(Request.Cookies["Admin%5FUser"].Value, System.Text.Encoding.GetEncoding(936));
ʹÓÃÒÔÉϵķ½Ê½£¬±ã¿ÉÒÔ»ñÈ¡°üº¬ÖÐÎĵÄCookieÁË¡£
Ïà¹ØÎĵµ£º
ASP.NET´úÂëÓÅ»¯Ò»¡¢Ò³ÃæºÍ·þÎñÆ÷¿Ø¼þ´¦Àí
1¡¢ASP.NET´úÂëÓÅ»¯±ÜÃâµ½·þÎñÆ÷µÄ²»±ØÒªµÄÍù·µÐгÌ
ÔÚijЩÇé¿öϲ»±ØʹÓà ASP.NET ·þÎñÆ÷¿Ø¼þºÍÖ´Ðлط¢Ê¼þ´¦Àí¡£ÀýÈ磬ÔÚ ASP.NET ÍøÒ³ÖÐÑéÖ¤Óû§ÊäÈë¾³£¿ÉÔÚÊý¾ÝÌá½»µ½·þÎñÆ÷֮ǰÔÚ¿Í»§¶Ë½øÐС£Í¨³££¬Èç¹û²»ÐèÒª½«ÐÅÏ¢´«µÝµ½·þÎñÆ÷ÒÔ½øÐÐÑéÖ¤»ò½«ÆäдÈëÊý¾Ý´æ´¢Çø£¬Çë±ÜÃâÊ ......
Trustwave's SpiderLabs Security Advisory TWSL2010-001:
Multiplatform View State Tampering Vulnerabilities
Published: 2010-02-08 Version: 1.1
SpiderLabs has documented view state tampering
vulnerabilities in three products from separate vendors.
View states are used by some web application frame ......
Ç°¶Îʱ¼ä¶ÁÁ˲»ÉÙ¹ØÓÚMVCµÄÎÄÕ£¬ÊÔ×ÅÔÚASPÖÐÓ¦ÓÃÁËһϣ¬·¢ÏÖ¶ÔÓÚС³ÌÐò£¬´úÂëÁ¿»á´ó·ù¶ÈÔö¼Ó£¬µ«ÊÇÂß¼ÇåÎú£¬Êý¾Ý·â×°ºÜºÏÀí£¬ÒÔÇ°ÐèÒª×Ðϸ¹æ»®µÄ´úÂ븴Óþ¹È»³ÉÁËÀíËùµ±È»µÄÊÂÇé¡£
ËùνMVC£¬¼´Model£¨Ä£ÐÍ£©£¬View£¨ÊÓͼ£©£¬Control£¨¿ØÖÆ£©Èý²ã¼Ü¹¹¡£¸÷²¿·Ö¸÷˾ÆäÖ°£¬Model¼´µ×²ã¹¹¼Ü£¬°üº¬ÓëÊý¾Ý¿âÁ¬½ÓµÄ²¿·Ö£¬View ......
< align=middle src=http://player.youku.com/player.php/sid/XMTQ3NTE2NzIw/v.swf width=480 height=400 type=application/x-shockwave-flash allowScriptAccess="sameDomain" quality="high" mce_src="http://player.youku.com/player.php/sid/XMTQ3NTE2NzIw/v.swf"> ......
´ó¼ÒÖªµÀÔÚÍøÕ¾µÄÿ¸öÒ³ÃæÉÏ,´æ´¢Ò»Ð©È«¾Ö´¦ÀíÐÅÏ¢£¬ÀíÏëµÄ×ö·¨Êǽ«ÕâЩÐÅÏ¢Ò»´ÎÐԵļ¯Öд洢ÔÚ×ÊÁϵµ°¸¿âÖУ¬¶ø²»ÊÇÔÚÍøÕ¾µÄÿ¸öÒ³ÃæÉ϶¼Öظ´ÕâÑùµÄ²Ù×÷¡£
±ÈÈç˵Êý¾Ý¿âÁ¬½Ó´®¾ÍÊÇÕâÑùµÄÐÅÏ¢£¬Èç¹ûÕâЩÐÅÏ¢²»ÊǼ¯Öд洢ÔÚÌض¨ÇøÓòÖУ¬¶øÊÇÔÚÍøÕ¾µÄÿ¸öÐèÒªÁ¬½ÓÊý¾Ý¿âµÄÒ³ÃæÉÏÊÖ¹¤ÊäÈ룬¿ÉÒÔÉèÏ룺µ±Êý ......