Asp.net ºǫ́µ÷ÓÃjs·½·¨
Asp.net ºǫ́µ÷ÓÃjs·½·¨(ת)
1. ÓÃResponse.Write·½·¨
¡¡¡¡´úÂëÈçÏ£º
Response.Write("<script type='text/javascript'>alert("XXX");</script>");
´Ë·½·¨È±ÏݾÍÊDz»Äܵ÷Óýű¾ÎļþÖеÄ×Ô¶¨ÒåµÄº¯Êý£¬Ö»Äܵ÷ÓÃÄÚ²¿º¯Êý£¬¾ßÌåµ÷ÓÃ×Ô¶¨ÒåµÄº¯ÊýÖ»ÄÜÔÚResponse.WriteдÉϺ¯Êý¶¨ Ò壬±ÈÈç
Response.Write("<script type='text/javascript'>function myfun(){}</script>");
2.ÓÃClientScriptÀà
¡¡¡¡´úÂëÈçÏ£ºÔÚÏëµ÷ÓÃij¸öjavascript½Å±¾º¯ÊýµÄµØ·½Ìí¼Ó´úÂ룬עÒâÒª±£Ö¤MyFunÒѾÔڽű¾ÎļþÖж¨Òå¹ýÁË¡£
ClientScript.RegisterStartupScript(ClientScript.GetType(), "myscript", "<script>MyFun();</script>");
¡¡¡¡Õâ¸ö·½·¨±ÈResponse.Write¸ü·½±ãһЩ£¬¿ÉÒÔÖ±½Óµ÷Óýű¾ÎļþÖеÄ×Ô¶¨Ò庯Êý¡£
3.ÆÕͨµÄÌí¼Ó¿Ø¼þµÄAttributesÊôÐÔ
¡¡¡¡¶ÔÓÚÆÕͨ°´Å¥¾ÍÊÇ£ºButton1.Attributes.Add("onclick","MyFun();");
¡¡¡¡Ö»ÄÜÔÚOnloadÖлòÀàËÆÓÚonloadµÄ³õʼ»¯¹ý³ÌÖÐÌí¼Ó²ÅÓÐЧ¡£¶øÇÒÊÇÏÈÖ´Ðнű¾º¯Êý£¬ÎÞ·¨¸Ä±äÖ´ÐÐ˳Ðò¡£
×¢Ò⣬ÒÔÉÏËùÓз½·¨ÖУ¬ºǫ́´úÂë¶¼²»ÄÜÓÐת»¯µ±Ç°Ò³µÄ´úÂ룬±ÈÈçRedirectµÈ£¬Òª°Ñתҳ´úÂë·ÅÔڽű¾ÀïÃæ
±¾ÎÄÀ´×ÔCSDN²©¿Í£¬×ªÔØÇë±êÃ÷³ö´¦£ºhttp://blog.csdn.net/lingtw/archive/2009/11/28/4888621.aspx
Ïà¹ØÎĵµ£º
ǰ¼¸ÌìÎÒûÊÂÔÚͼÊé¹Ý½è±¾··ºÙºÙ£¬Í¦ÓÐÒâ˼µÄ£¬ÁíÍâÄÇÌìÔÚÌù°É¿´µ½µÄÒ»²ÅÅ®µÄÎÊÌâͻȻÏëµ½ÁË··¾Í¿´ÁË¿´£¬Í¦ÓÐÒâ˼µÄ¡£
¾ßÌå×ܽáµÄÄÚÈÝÎÒ½ñÌìд³öÀ´£¬¿ÏÄÜÓе㳤£¬µ«ÊǶÔÍøÕ¾¾ø¶ÔÓÐÓá£
Ò³ÃæµÄ´¦ÀíĬÈÏÇé¿öÏ£¬´¦ÀíASP¡£NETÒ³ÃæµÄÄ£Ðͱ¾ÖÊÉÏÊÇͬ²½µÄ¡£Õâ˵Ã÷£¬Ò³ÃæµÄÁ÷³ÌÊǹ̶¨µÄ£¬Ã¿Ò ......
¸Õ±ÏÒµ£¬×î½üÔÚ¸ã±ÏÒµÂÛÎÄ¡£
˵Æð±ÏÒµÂÛÎÄÎÒ¾ÍÍ·ÌÛ£¬ÎÒÃÇÈýÈËÒ»×飬±¾À´ÎÒÖ÷ÕÅÓÃC#д£¬Ì×ÓÃÒ»¸öÍâ¹úµÄÄ£ÐÍBalloonShopÔÚÏß¹ºÎïÍøÕ¾£¬C#ÊÇ×ÔѧµÄ¡£µ«ÊÇͬ×éµÄÒ»¸öͬѧVBѧµÃ²»´í£¬ÒªÓÃVB¡£ÎÒÏëÄãÒªÓÃVBдµÄ»°ÎÒÊDz»Ì«¶®£¬ÄÇÖ»ÄÜÄã×Ô¼ºÐ´ºÃÁË£¬ÎÒ×î¶àÒ²¾Í´î°ÑÊÖ¶øÒÑ£¬Ê¡ÐÄÁË£¬ºÎÀÖ¶ø²»ÎªÄØ£¡
×îºó×÷Æ·×ö³öÀ´»¹Ëã²»´í£¬¾Í ......
Òì³£Ïêϸ£º
1. ´íÎóÁбíûÓмǼ£¬±àÒëͨ¹ý¡£
2. ÏÔʾÊä³ö:
“WebDev.WebServer.EXE”(ÍйÜ): ÒѼÓÔØ“C:\WINDOWS\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll”£¬ÒÑÌø¹ý·ûºÅ¼ÓÔØ¡£ÒѶÔÄ£¿é½øÐÐÁËÓÅ»¯²¢ÆôÓÃÁ˵÷ÊÔÆ÷Ñ¡ÏöÎҵĴúÂ딡£
“WebDev.WebServer ......
ÎҵĻú×ÓÔ±¾¾ÍÓÐInternetÐÅÏ¢·þÎñ£¨IIS£©µÄ°²×°Ñ¡ÏÏÂÁËºÜ¶à°æ±¾µÄIIS»òi386Îļþ¿É¾ÍÊÇȱÕâȱÄǵģ¬Èç:iisapp.vbs
°´ÍøÉÏ˵µÄÐÞ¸´Êý¾ÝÒ²ºÁÎÞÆðÉ«£¬×îºó
½â¾ö·½°¸£º
Ê×ÏÈÔÚ“¿ªÊ¼”²Ëµ¥µÄ“ÔËÐДÖÐÊäÈë“c:\Windows\inf\sysoc.inf”£¬ÏµÍ³»á×Ô¶¯Ê¹ÓüÇʱ¾´ò¿ªsy ......
ÔÚASP.NET 1.1ÖУ¬Òª×ö1¸öµ¯³öµÄÈ·È϶Ի°¿òµÄ»°£¬Ò»°ãÊÇÔÚ·þÎñ¶ËµÄ´úÂëÖÐÕâÑùд£º
private void Page_Load(object sender, System.EventArgs e)
{
btnClick.Attributes.Add("onclick", "return confirm('Are you sure?');");
// Button1.Attributes["OnClick"] = "return conf ......