ÀûÓÃhttpµÄrefererÍ·ºÍServletÒþ²ØJavaScript´úÂë
1. ¶¨ÒåÒ»¸öÓÃÓÚÊä³öJavaScript´úÂë µÄServletÀà¡£
package com.mycompany.response.servlet;
import java.io.IOException;
import java.io.PrintWriter;
import javax.servlet.ServletException;
import javax.servlet.http.HttpServlet;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;
public class HideJavaScript extends HttpServlet {
protected void service(HttpServletRequest request,
HttpServletResponse response) throws ServletException, IOException {
response.setHeader("Pragma", "No-cache");
response.setHeader("Cache-Control", "no-cache");
response.setDateHeader("Expires", 0);
response.setContentType("text/javascript;charset=UTF-8");
PrintWriter out = response.getWriter();
String referer = request.getHeader("referer");
if(!(referer==null)&&!referer.equalsIgnoreCase("")&&referer.startsWith("http://localhost:8080/response/"))
{
out.println("document.write('ÕâЩ¾ÍÊÇÒþ²ØµÄJavaScript´úÂë!')");
out.println("window.alert('Ö´ÐÐÁË´Ë´úÂë!')");
}
&n
Ïà¹ØÎĵµ£º
¼¼ÊõµÄjsµÄreplaceĬÈÏÖ»Ìæ»»µÚÒ»¸ö£¬Õâ²»ÖªµÀÄĸöÉè¼ÆµÄ£¬Èç¹ûÎÒÊÇ A / B / C / D µÄ×Ö·û´®Òª±ä³É A-B-C-D ¾ÍÒªÔÚ±»×ªÄÚÈÝʹÓúó¼Ó/g£¬ÒòΪÓÖ´øÁË/£¬¼ÓÉϸ÷¿Õ¸ñ£¬ÔÚreplace µÄµÚÒ»¸ö²ÎÊýÓ¦¸ÃÊÇ
var rut = /\/ /g;
È»ºó
replace(rut, "-"); ......
×î½üÔÚÍøÉϲéÔÄÁ˲»ÉÙJavascript±Õ°ü(closure)Ïà¹ØµÄ×ÊÁÏ£¬Ð´µÄ´ó¶àÊǷdz£µÄѧÊõºÍרҵ¡£¶ÔÓÚ³õѧÕßÀ´Ëµ±ð˵Àí½â±Õ°üÁË£¬¾ÍÁ¬ÎÄ×ÖÐðÊö¶¼ºÜÄÑ¿´¶®¡£×«Ð´´ËÎĵÄÄ¿µÄ¾ÍÊÇÓÃ×îͨË×µÄÎÄ×Ö½Ò¿ªJavascript±Õ°üµÄÕæÊµÃæÄ¿¡£
Ò»¡¢Ê²Ã´ÊDZհü£¿
“¹Ù·½”µÄ½âÊÍÊÇ£ºËùν“±Õ°ü”£¬Ö¸µÄÊÇÒ»¸öÓµÓÐÐí¶à±äÁ¿ºÍ°ó¶¨Á ......
µÚÒ»ÖÖ:
+Õ¹¿ª
-HTML
<html>
<head>
</head>
<body>
<form name="form1">
<input type="text" name="getinfo" value="http://www.shuwo.net" size="40"><button onclick="alert(document.form1.getinfo.value ......
Ò»¡¢Ê²Ã´ÊDZհü£¿ ¡°¹Ù·½¡±µÄ½âÊÍÊÇ£º±Õ°üÊÇÒ»¸öÓµÓÐÐí¶à±äÁ¿ºÍ°ó¶¨ÁËÕâЩ±äÁ¿µÄ»·¾³µÄ±í´ïʽ£¨Í¨³£ÊÇÒ»¸öº¯Êý£©£¬Òò¶øÕâЩ±äÁ¿Ò²ÊǸñí´ïʽµÄÒ»²¿·Ö¡£
ÏàÐźÜÉÙÓÐÈËÄÜÖ±½Ó¿´¶®Õâ¾ä»°£¬ÒòΪËûÃèÊöµÄ̫ѧÊõ¡£ÆäʵÕâ¾ä»°Í¨Ë×µÄÀ´Ëµ¾ÍÊÇ£ºJavaScriptÖÐËùÓеÄfunction¶¼ÊÇÒ»¸ö±Õ°ü¡£²»¹ýÒ»°ãÀ´Ëµ£¬Ç¶Ì×µÄfunctionËù²úÉúµÄ± ......
×î½üһֱΪ´ËÍ·Í´£¬¹ÃÇÒ°ÑÎÒÄÜÏëµ½µÄ¶«Î÷¶¼Ð´³öÀ´°É¡£ÓÉÓÚ²»ÊǼòµ¥°ÑÒ³ÃæÉÏÊÖдµÄscriptתΪjavascriptÌí¼Ó£¬ÎÒÃÇÐèÒª¿¼ÂǵĶ«Î÷Ö÷ÒªÓÐÁ½¸ö£º¼ÓÔØµÄ˳Ðò£¬¼ÓÔØÇ°ºó½Å±¾µÄÔË×÷¡£
ÏÈ˵µÚÒ»¸ö£¬¼ÙÈçÎÒÃÇÒÑÓÐÒ»¼ÓÔØ»úÖÆÁË£¬Òª¼ÓÔØÒ»¸öÐÂÄ£¿é£¬µ±È»ÐÂÄ£¿éÊÇÔÚÁíÒ»¸öJSÎļþÖС£Õâʱ£¬ÎÒÃÇ¿ÉÒÔÃèÊöΪ£º
loader ---> a.js
Õâ¸ö¼Ó ......