xss

11 篇文章 0 订阅

 

using System.Text.RegularExpressions;
using System.Web;
using System.Web.Mvc;
using DonvvTools.Log;

namespace Test.Framework.Filters
{
    /// <summary>
    /// 防止SXX攻击过滤器
    /// </summary>
    public class SafeFilter : ActionFilterAttribute
    {
        private const string strRegex = @"<[^>]+?style=[\w]+?:expression\(|\b(alert|confirm|prompt)\b|^\+/v(8|9)|<[^>]*?=[^>]*?&#[^>]*?>|\b(and|or)\b.{1,6}?(=|>|<|\bin\b|\blike\b)|/\*.+?\*/|<\s*script\b|<\s*img\b|\bEXEC\b|UNION.+?SELECT|UPDATE.+?SET|INSERT\s+INTO.+?VALUES|(SELECT|DELETE).+?FROM|(CREATE|ALTER|DROP|TRUNCATE)\s+(TABLE|DATABASE)"; 
        private static bool _verify = true;
        public override void OnActionExecuting(ActionExecutingContext filterContext)
        {
            var request = HttpContext.Current.Request;
            if ((request.Cookies != null && !VerifyCookie())
                || (request.HttpMethod.ToUpper() == "GET" && !VerifyGetData())
                || (request.HttpMethod.ToUpper() == "POST" && !VerifyPostData())
                || !VerifyReferrer())
                filterContext.Result = new RedirectResult($"/Account/Login");
        }

        public static bool VerifyPostData()
        {
            for (int i = 0; i < HttpContext.Current.Request.Form.Count; i++)
            {
                _verify = CheckData(HttpContext.Current.Request.Form[i].ToString());
                if (!_verify)
                    break;
            }
            return _verify;
        }
        
        public static bool VerifyGetData()
        {
            for (int i = 0; i < HttpContext.Current.Request.QueryString.Count; i++)
            {
                _verify = CheckData(HttpContext.Current.Request.QueryString[i].ToString());
                if (!_verify)
                    break;
            }
            return _verify;
        }
        public static bool VerifyCookie()
        {
            for (int i = 0; i < HttpContext.Current.Request.Cookies.Count; i++)
            {
                _verify = CheckData(HttpContext.Current.Request.Cookies[i].Value.ToLower());
                if (!_verify)
                    break;
            }
            return _verify;
        }
        public static bool VerifyReferrer() => CheckData(HttpContext.Current.Request.UrlReferrer.ToString());

        public static bool CheckData(string inputData)
        {
            if (Regex.IsMatch(inputData, strRegex))
            {
                Logger.Debug("链接中含恶意字符串", $"请求链接:{HttpContext.Current.Request.RawUrl}");
                return false;
            }
            return true;
        }
    }
}

 

  • 2
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值