Ò׽ؽØͼÈí¼þ¡¢µ¥Îļþ¡¢Ãâ°²×°¡¢´¿ÂÌÉ«¡¢½ö160KB

[ת]Java WebÓ¦ÓõÄPolicy°²È«ÅäÖÃÖµµÃÉî˼

ÐÅÏ¢À´Ô´£ºÐ°¶ñ°Ë½øÖÆÐÅÏ¢°²È«ÍŶӣ¨www.eviloctal.com£©
Author:kj021320
תÔØÇë×¢Ãû³ö´¦¡£
JavaÓ¦ÓóÌÐò»·¾³µÄ°²È«²ßÂÔ£¬Ïêϸ˵Ã÷Á˶ÔÓÚ²»Í¬µÄ´úÂëËùÓµÓеIJ»Í¬×ÊÔ´µÄÐí¿É£¬ËüÓÉÒ»¸öPolicy¶ÔÏóÀ´±í´ï¡£
ΪÁËÈÃapplet£¨»òÕßÔËÐÐÔÚSecurityManagerϵÄÒ»¸öÓ¦ÓóÌÐò£©Äܹ»Ö´ÐÐÊܱ£»¤µÄÐÐΪ£¬ÀýÈç¶ÁдÎļþ£¬applet£¨»òJavaÓ¦ÓóÌÐò£©±ØÐë»ñµÃÄÇÏî²Ù×÷µÄÐí¿É,°²È«²ßÂÔÎļþ¾ÍÊÇÓÃÀ´ÊµÏÖÕâЩÐí¿É¡£
Policy¶ÔÏó¿ÉÄÜÓжà¸öʵÌ壬ËäÈ»ÈκÎʱºòÖ»ÄÜÓÐÒ»¸öÆð×÷Óá£
µ±Ç°°²×°µÄPolicy¶ÔÏó£¬ÔÚ³ÌÐòÖпÉÒÔͨ¹ýµ÷Óà getPolicy·½·¨µÃµ½£¬Ò²¿ÉÒÔͨ¹ýµ÷ÓÃsetPolicy·½·¨¸Ä±ä¡£Policy¶ÔÏóÆÀ¹ÀÕû¸ö²ßÂÔ£¬·µ»ØÒ»¸öÊʵ±µÄPermissions¶ÔÏó£¬Ïêϸ˵Ã÷ÄÇЩ´úÂë¿ÉÒÔ·ÃÎÊÄÇЩ×ÊÔ´¡£
¿É¼û ͨ¹ýÅäÖÃpolicyÀ´´ïµ½¿ØÖÆSecurityManager£¬ÔÚApplet RMIÉÏÃæÒѾ­¼ûµ½ºÜ´óµÄ³ÉЧ¡£
µ«ºÜ¶àÏÖÔÚWEBÈÝÆ÷ÈçTOMCAT RESINµÈµÈ¶¼Í¨¹ýÖ¸µ¼Óû§ÅäÖÃpolicyÀ´¹ÜÀí×Ô¼ºJAVAÍøÕ¾µÄ°²È«¡£
¶ÔÓÚ³õ¼¶hacker ¿ÉÄÜ»á´ïµ½Ò»¶¨³ÉЧ£¬µ«ÊÇÎÒ¸öÈ˳ֱ£ÁôÒâ¼û¡£
Ê×Ïȼòµ¥¿´¿´JAVA WEBÈÝÆ÷webappsµÄ¹ÜÀí²ßÂÔ¡£
ÿ¸öapp¶¼ÊÇÕ¼ÓøÃÈÝÆ÷ͬһ½ø³Ì£¬¶ø²»Í¬ÓÚ¸÷×Եİü¹ÜÀí£¬ÇëÇó¿ØÖƶ¼ÊDzÉÓà MultiThread + ClassLoader µÄ.
ËùÒÔдserlvet/filter publicµÄÊôÐÔÐèҪעÒâ²¢·¢£¬¶ø¸÷¸öwebapp¶¼Óи÷×ÔµÄlibµÈµÈ¡£
ÖÁÓÚÕâÑùµÄ¶ÔÓÚ°²È«À´Ëµ»á¼«Æä¶ñÐÄ...
ÎÊÌâ1: A webapp µ÷ÓÃÁË system.exit µ¼ÖÂWEBÈÝÆ÷¹ÒÁË¡£
ÎÊÌâ2: A webapp ÒòΪ´úÂëÖÊÁ¿ÎÊÌâÄÚ´æй¶£¬µ¼ÖÂB webapp·ÃÎʲ»ÁË¡£
ÎÊÌâ3: webapp µ÷Óà runtime.exec Ö´ÐÐϵͳÃüÁî¹¥»÷²Ù×÷ϵͳ¡£
¶øÕë¶ÔÒÔÉÏÕâЩÎÊÌ⣬ÎÒ¹À¼ÆsunÓ¦¸Ã±È½ÏÞÏÞεÄÁË£¬ÈÝÆ÷ÌṩÉÌÃǶ¼Ö»ÄܲÉÓÃÁËjava×Ô´øµÄ²Ù×÷·½·¨¡£¾ÍÊÇÅäÖÃpolicy
ÈçºÎÅäÖÃѽ£¿
TOMCAT¿ÉÒÔ¿´¿´ http://tomcat.apache.org/tomcat-5.5-doc/security-manager-howto.html
RESIN ¿ÉÒÔËÑË÷ <<ResinÐéÄâÖ÷»úµÄjava°²È«É³ÏäÉèÖÃ>>
»ù±¾ÉϾÍÊÇÏÞÖÆÓû§²Ù×÷ java.io java.net java.awt java.runtime java.util ...
µ«ÊǺÜÒź¶¸æËßÄ㣬ÕâЩ¶¼ÊÇ¿ÉÒÔbypassµÄ£¡ÎªÊ²Ã´£¿ÒòΪJAVAÀïÃæɳÏäÏÞÖƶ¼ÊÇÔÚjava class²ã¿ØÖƵÄ
¶ø ²ÉÓà reflect ¿ÉÒÔÈƹýÕâЩ½ø¶ø²Ù×÷JNIµÈµÈ...ÈçºÎ²Ù×÷¿ÉÒÔ¿´Õâpaper
http://blog.csdn.net/kj021320/archive/2007/10/10/1819205.aspx
ÄÇÈç¹û°ÑreflectҲͬÑùÏÞÖÆÁËÄØ£¿¸úappletÒ»ÑùÑϸñ£¡ OK ÏÖÔÚÎÒÃÇÀ´¿´¿´Êµ¼ÊÇé¿ö
Ê×ÏÈwebapp ³£ÓõĿò¼Ü spring  ibatis  hiber


Ïà¹ØÎĵµ£º

JavaÖеÄÊý¾Ý±È½Ï£¨ÔÙ̸==ÓëequalsµÄÇø±ð£©

JavaÖеıäÁ¿Óë¶ÔÏóÓÐÇø±ðÂð£¿
Òý×Ó£º±äÁ¿Óë¶ÔÏó
±äÁ¿ÊÇJavaÖÐ×î»ù±¾µÄ´æ´¢µ¥Ôª£¬Îª±äÁ¿¸³Öµ¿ÉÒÔʹÓø³Öµ±í´ïʽ¡£È磺
int i = 10;
¸Ã±í´ïʽµÄº¬ÒåÊǽ«Ò»¸ö×ÖÃæÁ¿£¨literal£©10¸³Öµ¸øÒ»¸öÀàÐÍΪintÐ͵ıäÁ¿£¬±äÁ¿ÃûΪi¡£ÕâÊÇÒ»¸öΪ»ù±¾Êý¾ÝÀàÐ͵ıäÁ¿¸³ÖµµÄÀý×Ó£¬Ëü±í´ïÁËÒ»¸ö·Ç³£ÆÓËصÄÐÅÏ¢£¬ÄǾÍÊDZäÁ¿iµÄֵΪ10¡£
Ä ......

javaҹδÃß

          ×Ô´ÓѧϰJavaÒÔÀ´ÒѾ­Ò»ÄêÓÐÓàÁË£¬¶ÔJava»¹Ö»Êdzõ½×¶ÎµÄÁ˽⣬¶¼¹ÖÔÚѧУµÄʱºòÌ°ÍæûÓÐÓÐЧµÄÀûÓÃʱ¼ä£¬ÏÖÔÚÔÚÒ»¸öÅàѵѧУѧϰJava£¬ÏÖÔÚ¾ÍÒª×öÏîÄ¿ÁË»¹ÊÇʲô¶¼²»¶®£¬»¹ºÃÓÐCsdn¡£
      ÔÚCsdnµÄÈÕ×ÓÀï½ÐÎÒÕÒµ½Á˼ҵĸоõ£¬µÃµ½Á輆 ......

Java+MysqlµÄÊý¾Ý¿â²éÕÒʵÏÖ


public class select {
 public List XiuGai_select(String keyword){
  List list=new ArrayList();
        Connection conn = null;
  Statement stmt = null;
  String sql=null;
  ResultSet res = null;
  get ......

¶ÁÈ¡formÊý¾Ýʱ£¬java·´ÉäµÄÒ»µãÓ¦ÓÃ

package com.gis.biz;
import java.lang.reflect.Field;
import java.lang.reflect.InvocationTargetException;
import java.lang.reflect.Method;
import java.util.Enumeration;
import java.util.HashMap;
import java.util.Iterator;
import java.util.Map;
import java.util.Set;
import javax.servlet.http. ......
© 2009 ej38.com All Rights Reserved. ¹ØÓÚE½¡ÍøÁªÏµÎÒÃÇ | Õ¾µãµØͼ | ¸ÓICP±¸09004571ºÅ