JavaScriptµÄ Cross Site ½Å±¾×¢Èë·çÏÕ
½ñÌìÓÐÈËÀ´¹«Ë¾ÍÆÏúÍøÕ¾°²È«É¨ÃèÈí¼þ£¬ÑÝʾÁ˶ÔJSµÄ¿çÓò½Å±¾×¢Èë·çÏÕµÄɨÃ裬ÒÔǰûÒâʶµ½£¬½ñÌìÓÐËùÁ˽⡣Èç¹ûÄúµÄ³ÌÐòÒ³ÃæÓÐÒÔÏÂÇé¿ö£¬ÄÇôJS½Å±¾×¢ÈëµÄ·çÏվͺܴó£º
1£©Ò³Ãæ´ò¿ªÊ±£¬URL ÓÐij¸ö²ÎÊý£¬ÀýÈç XXPage.aspx?XXParam=XXValue
2£©aspxÒ³ÃæÀïÓÐÈçÏ´úÂ룺
<script>
var p = "<%=Request["XXParam"];%>";
</script>
×¢Èë·çÏÕÈçÏ£º
1£©ºÚ¿Í¼ÙÃ°ÍøÕ¾Éí·Ý·¢ËÍÓʼþ¸øÓû§£¬Óû§´ò¿ªÍøÒ³Á´½Ó£¬Á´½ÓËäÈ»ÊÇÖ¸Ïò XXPage.aspx£¬µ« XXParam È´±»×öÁ˸ÄÔ죬ÀýÈ磺XXParam ±»ÉèÖÃΪ "; document.location.href = 'http://www.xxx.com/XXFakePage.aspx';//"¡£×¢Òâ£¬Ç°ÃæµÄË«ÒýºÅÊÇÓÃÀ´ÆÁ±Î var p = " µÄ£¬ºóÃæ½ô½ÓמÍÊÇÒ»¸öJSÒ³ÃæÌø×ªÓï¾ä£»×îºóÃæµÄ //" ÊÇÓÃÀ´ÆÁ±Î JS ½Å±¾ÖеĺóÒýºÅµÄ¡£
Äã²Â½á¹û»áÔõôÑù£¿Ò³ÃæÖ±½Ó±»Ìø×ªµ½ http://www.xxx.com/XXFakePage.aspx£¬Èç¹ûÕâ¸öÒ³ÃæÊǼÙÃ°Ò³Ãæ£¬²¢ÇÒÕâ¸öÒ³ÃæÊÇǶÈëÔÚ Frameset ÀïµÄ£¬ÄÇÓû§»áÔÚºÁÎÞ¾õ²ìµÄÇé¿öÏ£¬°Ñ×¢ÈëÓû§Ãû¡¢ÃÜÂë¡¢ÒøÐп¨Õ˺ÅÃÜÂëÌá½»µ½¼ÙÃ°Ò³ÃæÉÏ£¡£¡
¶Ô²ß£º
·½·¨Ò»£º²»ÒªÓà <%=Request["XXParam"];%> À´½âÎö²ÎÊýÖµ£¬¶øÖ±½ÓÓà JS ½Å±¾´ÓURL»ñÈ¡²ÎÊýÖµ
·½·¨¶þ£º°Ñ²ÎÊýÖµÏÈ·ÅÔÚ HIDDEN ¿Ø¼þÀÀýÈç: <input type=hidden id=xxhid value="<%=Server.HtmlEncode(Request["XXParam"]);%>"> ÀȻºóÔÚ JS Àï¸ÄΪ var p = document.all.xxhid.value;
Ó¦¸Ã»¹ÓÐÆäËû·½·¨£¬ÒÔÉÏ·½·¨Ö»ÊÇʾÒ⣬ûÓÐÈ¥±àÒ룬½ö¹©²Î¿¼¡£
Ïà¹ØÎĵµ£º
1. oncontextmenu="window.event.returnValue=false" ½«³¹µ×ÆÁ±ÎÊó±êÓÒ¼ü
<table border oncontextmenu=return(false)><td>no</table> ¿ÉÓÃÓÚTable
2. <body onselectstart="return false"> È¡Ïûѡȡ¡¢·ÀÖ¹¸´ÖÆ
3. onpaste="return false" ²»×¼Õ³Ìù
4. oncopy="return false;" oncut="re ......
Èç¹ûʹÓÃhtml¿Ø¼þ»¹ºÃһЩ£¬·þÎñÆ÷¿Ø¼þ¾Í±È½ÏÓôÃÆÒ»Ð©£¬ÒòΪGridViewÉú³ÉÖ®ºóÊǶàÐеģ¬ËùÒÔÕâ¸öÎı¾¿òÒ²»áÓкܶà¸ö£¬ÁíÒ»·½Ãæasp.net»á×Ô¶¯ÖØÐÂÃüÃû¿Ø¼þ£¬ËùÒÔÏëͨ¹ýID»ñÈ¡ÒѾ²»¿ÉÄÜÁË£¬ºÜ²»ÐÒµÄÊÇÁ¬nameÊôÐÔ¶¼±»×Ô¶¯Éú³ÉÁË£¬ÄÄÅÂÄãÌí¼ÓÁËnameÊôÐÔ£¬Ò²ÎÞ·¨¸²¸ÇÉú³ÉµÄname£¬¶øÊÇ»á³öÀ´Á½¸önameÊôÐÔ
ÄÇô¾ÍÏë±ðµÄ°ì·¨£¬ ......
JavaScriptµÄ·½·¨ºÍ¼¼ÇÉ ÊÕ²Ø
ÓÐЩʱºòÄ㾫ͨһÃÅÓïÑÔ£¬µ«ÊǻᷢÏÖÄãÆäʵÕûÌìÔÚºÍÆäËüÓïÑÔ´ò½»µÀ£¬Ò²ÐíÄãÒÔΪÕâЩ΢²»×ãµÀ£¬²»ÖÁÓÚÓ°ÏìÄãµÄ¿ª·¢½ø¶È£¬µ«Ç¡Ç¡ÊÇÕâЩÄã²»ÖØÊӵĶ«Î÷»áÀË·Ñ ÄãºÜ¶àʱ¼ä£¬ÎÒÒ»Ö±ÒÔΪÎÒÔçÔÚ¼¸Äêǰ¾ÍÒѾ¾«Í¨JavaScriptÁË£¬Ö±µ½Ä¿Ç°£¬ÎÒ²ÅÔ½À´Ô½¾õµÃJavaScriptÔ¶±ÈÎÒÏëÏóµÄ¸´ÔÓºÍÇ¿´ó£¬ÎÒ¿ªÊ¼³ç ......
<asp:TextBox ID="TextBox1" runat="server" onkeydown="return NotAllowSpace(this);"/></asp:TextBox>
<mce:script type="text/javascript" language="javascript"><!--
function NotAllowSpace(e)
{
var keyVal =(window.event) ? event.keyCode : e.keyCode; ......
×ªÔØ:JavaScript»ñÈ¡Ò³Ãæ¿í¶È¸ß¶È´óÈ«
µØÖ·:http://www.cnblogs.com/wcg249165510/archive/2009/02/20/1394749.html
ÍøÒ³¿É¼ûÇøÓò¿í£ºdocument.body.clientWidth
ÍøÒ³¿É¼ûÇøÓò¸ß£ºdocument.body.clientHeight
ÍøÒ³¿É¼ûÇøÓò¿í£ºdocument.body.offsetWidth(°üÀ¨±ßÏߵĿí)
ÍøÒ³¿É¼ûÇøÓò¸ß£ºdocument.body.offsetHeight(° ......