防止路径操控,命令注入

public class Test
{
    public static void main(String[] args)
    {
        System.out.println(getSafeCommand("abcd&efg"));
        System.out.println(getSafePath("abcd/efg"));
    }

    /**
     * Get the safe path
     * @param filePath Enter the path
     * @return Safe path
     */
    public static String getSafePath(String filePath)
    {
        // return safe path
        StringBuffer safePath = new StringBuffer();
        // safe path white list
        String whiteList = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz1234567890-=[];',. ~!@#$%^&*()_+\"{}|:<>?";
        char[] safePathChars = filePath.toCharArray();

        for (int i = 0, length = safePathChars.length; i < length; i++)
        {
            int whiteListIndex = whiteList.indexOf(safePathChars[i]);
            if (-1 == whiteListIndex)
            {
                return safePath.toString();
            }
            safePath.append(whiteList.charAt(whiteListIndex));
        }
        return safePath.toString();
    }

    /**
     * Get the safe command
     * @param command Enter the command
     * @return Safe command
     */
    public static String getSafeCommand(String command)
    {
        // return safe command
        StringBuffer safeCommand = new StringBuffer();
        // safe command white list
        String whiteList = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz1234567890-=[]\\',./ ~!@#$%^*()_+\"{}:<>?";
        char[] safeCommandChars = command.toCharArray();

        for (int i = 0, length = safeCommandChars.length; i < length; i++)
        {
            int whiteListIndex = whiteList.indexOf(safeCommandChars[i]);
            if (-1 == whiteListIndex)
            {
                return safeCommand.toString();
            }
            safeCommand.append(whiteList.charAt(whiteListIndex));
        }
        return safeCommand.toString();
    }
}

输出结果:

abcd
abcd

防止路径操控:预防路径跨越,路径中不能出现/../,安全字符中不能出现 /  \ 字符

防止命令注入:预防命令批量执行,命令中不能出现 &  |  ;

  • 2
    点赞
  • 4
    收藏
    觉得还不错? 一键收藏
  • 1
    评论
评论 1
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值