¹ØÓÚjavascriptÄ£¿é¼ÓÔØµÄ˼Ë÷2
¾¼¸Ìì˼¿¼£¬Ïëµ½Ò»¸ö½Ð¡°ÎļþÓëÄ£¿é¡±µÄÎÊÌâ¡£ÎÒÃǵÄÄ£¿é¿Ï¶¨Ð´ÔÚÒ»¸öJSÎļþÖУ¬ÕâЩģ¿éÓÖ¿ÉÒÔ·ÖΪºËÐÄÄ£¿éÓëÍâΧģ¿é¡£ºËÐÄÄ£¿éµ±È»Ð´ÔÚÖ÷ÎļþÖУ¬ËüÓ¦¸Ã°üº¬×îÖØÒªµÄÂß¼£¬¼ÓÔØÆ÷£¬Áжӣ¬ÃüÃû¿Õ¼ä¹¹ÔìÆ÷µÈµÈ¡£µ«Èç¹ûÒ»¸öÎļþÖ»´æÔÚÒ»¸öÄ£¿éÕâҲ̫ÀË·ÑÁË£¬¶øÇһᵼÖÂÇëÇ󷨹ý¶à£¬Òò´Ë³öÏÖ¶à¸öÄ£¿é¡°¹²Éú¡±ÓÚÒ»¸öÎļþµÄÇé¿ö¡£ÔÚÖ÷ÎļþµÄÄÇЩ·ÇºËÐÄÄ£¿é£¬ÎÒ³ÆÖ®ÎªÄÚΧģ¿é¡£ÆäËûÄÚΧÓëÍâΧûÓÐÊ²Ã´Çø±ð£¬Ö»ÊÇËùÔÚÎļþ²»Í¬¶øÒÑ¡£²»µØÎªÁË·½±ãÆð¼û£¬ÄÚΧģ¿é²»ÒªÒÀÀµÍâΧģ¿é£¡
µ«ÎÒÃÇÓÃscript±êÇ©ÒýÓÃJSÎļþʱ£¬Ëü¾Í»©À²À²µØÖ´ÐÐÀïÃæµÄ½Å±¾£¬×îÖ÷ÒªµÄÂß¼¿ÉÒÔÎÞËù¹ËÂǵصõ½½âÎö¡£µ«¶ÔÓÚÄÚΧģ¿é£¬ËüÃǵÄÂß¼ÊǷŵ½Ò»¸öº¯ÊýÌåÖУ¬¿ØÖÆÁ÷Ö»ÄÜ´ÓËüÃÇÉÏÃæÂÓ¹ý£¬´¥Ãþ²»ÁËËüÀïÃæµÄ¶«Î÷¡£Õâ¸öÄ£¿éÃûÓë»Øµ÷º¯ÊýÓëÏà¹ØµÄÅäÖý«½øÈëÒ»¸ö´¦Àíº¯Êý(ÏÂÎijÆÖ®Îªuse)£¬ÔÙ·ÅÈëÒ»¸ö´¦ÀíÁжӡ£Èç¹û´æÔÚÒÀÀµ£¬Ôò¼ì²âÒÀÀµÄ£¿éËùÔÚµÄÎļþÓÐûÓмÓÔØ£¬Ã»ÓоͼÓÔØÎļþ£¬Èç¹ûÎļþÒѼÓÔØ£¬Ôò¼ì²â´ËÄ£¿éÒÑ×°Åäµ½¿ò¼ÜµÄÃüÃû¿Õ¼äÖУ¬×îºóÖ´Ðлص÷º¯Êý¡£
´ÓÉÏÃæ·ÖÎö¿ÉÖª£¬ÕâÀïÃæµÄ²Ù×÷´óÌå¿É·ÖΪ¼¸ÀࣺÎļþ¼ÓÔØ£¬Ä£¿é×°ÅäÓëÖ´Ðлص÷£¬ËüÃÇÖ»ÄÜÒÀ´ÎÖ´ÐС£×Û¹Û´ó¶àÊýÀà¿â¿ò¼Ü£¬¸ø³öµÄ½â¾ö·½°¸¾ÍÊÇÕâÁ½ÖÖ£º¶¯Ì¬script²åÈëÓëAjax»Øµ÷½âÎö¡£
¶¯Ì¬script²åÈ룬¾ÍÊÇÉú³ÉÒ»¸öscript½Úµã£¬ÉèÖÃÆäÄ¿±êsrc£¬È»ºó²åÈëhead½ÚµãÖС£Ö®ËùÒÔ²»ÓÃdocument.write£¬ÄÇÊDzåÈëµ½bodyÖУ¬¶øÇÒ»¹ÓÐÐí¶àȱÏÝ£¬¾ßÌå²Î¿´ÎÒÕâÆªÎÄÕ¡£
Ajax»Øµ÷½âÎö£¬¾ÍÊÇÀûÓÃXMLHttp¶ÔÏ󣬽«ÇëÇó»ØÀ´µÄresponseTextÔÙÈ«¾Ö½âÎö¡£×¢Ò⣬ÊÇÈ«¾Ö½âÎö£¬ÒªÊµÏÖËü¾Í±ØÐëÓõ½window.eval(±ê×¼ä¯ÀÀÆ÷)»òwindow.execScript(IE)£¬»òÕßÔÙ¸ãÒ»¸öscript±êÇ©½øÐнâÎö¡£¿É¼ûÕâ·½·¨ÐèÒª´¦ÀíÐí¶à¼æÈÝÎÊÌ⣬Áí´îÉÏ¿çÓòÎÊÌâ¡¡¡£
ÎÒµÄÁ¢³¡ºÜÃ÷ÏÔÁË£¬Ê¹ÓõÚÒ»ÖÖ¡£µ«script±êÇ©¹ØÓڻص÷µÄ´¦Àí»¹ÊÇÓÐÐí¶àÎÊÌâ¡£
var script = dom.genScriptNode();
script.src = url
dom.head().appendChild(script);
script.onload = script.onreadystatechange = function(){
if ((!this.readyState) || this.readyState == "loaded" || this.readyState == "complete" ){
if(!dom.done[name]){
alert("¼ÓÔØÊ§°Ü1")
dom.
Ïà¹ØÎĵµ£º
ÉÏÃæËù˵ÓйØHTMLµÄÄÚÈݷdz£ÉÙÓÖ¼òµ¥,µ«¶ÔÒѾÁ˽âµÄÈËÀ´Ëµ¾ÍÊÇûÓõÄ.
ÈçÓÐÎÊÌâ¿Éµ½È¨ÍþÍø http://www.html.com/ Éϲ鿴
ÒÔÏ¿ªÊ¼ËµËµ¹ØÓÚXMLµÄһЩ֪ʶ.
XMLÒ²ÊDZê¼ÇÓïÑÔ,¿ÉËüÊÇ×Ô¶¨ÒåµÄ,ûÓÐÒѸø¶¨¸ñʽ.²»¾ßÌå˵Ëü,¸ø³öÀý×ӾͿÉÃ÷ÁË.
Èç
<NAME>TOM</NAME>
<SEX>M</SEX>
ÒÔÉÏÄÚÈݵÄ< ......
Õâ¸öËæ±ÊÆäʵÊÇΪÁ˸ÐлÇå·çЦ¸øµÄÒ»¸öÌáʾ£¬²»½ö½öÊǸæËßÎÒÔõôÅжÏÊý×飬¸üÈÃÎÒÓÐÁËÈÏÕæ¶ÁÒ»¶Á ¡¶javascriptȨÍþÖ¸ÄÏ¡·µÄÏë·¨¡£
±È½ÏºÍ¿½±´ÆäʵÊÇÒ»»ØÊ£¬´úÂëÈçÏ£º
//
//Compare object function
//
function Compare(fobj,sobj)
{
var ftype = typ ......
JavascriptÖеļ̳лúÖÆÊÇËùνµÄÔÐͶÔÏó¼Ì³Ð£¬Í¨¹ýÊôÐÔ·ÃÎÊ»úÖÆµÄÌØÊâÐÔÀ´ÊµÏּ̳еġ£Ö®Ç°ÎÒÒ»Ö±ÒÔΪËùÓжÔÏóµÄÔÐͶÔÏó¾ÍÊÇprototypeËùÖ¸µÄÄǸö¶ÔÏ󡣺óÀ´ÔÚ¿´javascriptÉè¼ÆÄ£Ê½µÄʱºò·¢ÏÖ×÷Õß×¢ÖÐÓÐÒ»¾ä»°ÓëÎÒ֮ǰµÄÀí½â²»Í¬£¬Ëû˵“ÿ¸ö¶ÔÏó¶¼ÓÐÒ»¸öÔÐͶÔÏ󣬵«Õâ²¢²»Òâζ×Åÿ¸ö¶ÔÏó¶ ......
<html>
<body>
<script type="text/javascript">
//·½·¨Ò»
var num_arr= [];
for (var i = 0 ; i < 10 ; i ++)
{
num_arr[i] = i;
}
document.write(num_arr+'</br>');
//·½·¨¶þ
var obj_arr=new Array();
obj_arr[6]='ss';
document.write(obj_arr.len ......
XMLHttpRequest Script Injection XHR½Å±¾×¢Èë
Another approach to nonblocking scripts is to retrieve the JavaScript code using an XMLHttpRequest (XHR) object and then inject the script into the page. This technique involves creating an XHR object, downloading the JavaScript f ......