CRSF 跨站请求伪造

<form>

 <input type="hidden" value="<%=CreateToken() %>" name="GUID" />

  <input type="hidden" value="<%=CreateTokenName() %>" name="TokenName" />

</form>


 

 

protected string cookieName = "";

 

/// <summary>
    /// 创建Toke
    /// </summary>
    /// <returns></returns>
    protected string CreateToken()
    {        
        string gid =  Guid.NewGuid().ToString() + "123546";
        string desString = EncryptedString(gid, DESKey);
              
       
        HttpCookie cookie = Request.Cookies.Get(cookieName);

        if (cookie == null)
        {
            cookie = new HttpCookie(cookieName);
            cookie.Value = desString;
            cookie.Expires = DateTime.Now.AddMinutes(2);
            cookie.HttpOnly = true;
            Response.Cookies.Add(cookie);
        }
        else
        {
            cookie.Value = desString;
            cookie.HttpOnly = true;
            Response.Cookies.Set(cookie);
        }        

        return desString;
    }


 

/// <summary>
    /// 检查token
    /// </summary>
    /// <param name="token"></param>
    /// <returns></returns>
    protected bool CheckToken(string token)
    {
        bool flag = false;

        try
        {
            HttpCookie cookie = Request.Cookies.Get(GetTokenName());
            if (cookie != null)
            {
                string desString = DecryptedString(cookie.Value, DESKey);
                token = DecryptedString(token, DESKey);
                if (token == desString)
                {
                    flag = true;
                }
            }

        }
        catch (DecryptErrorException ex)
        {
            flag = false;
        }
        catch(SourceIsNullOrEmptyException ex)
        {
            flag = false;
        }
        return flag;
    }


 

 protected string CreateTokenName()
    {
        cookieName = Guid.NewGuid().ToString();
        return cookieName;
    }

    protected string GetTokenName()
    {
        return Utils.GetFormString("TokenName");
    }


 

post验证cookie与提交的token是否一致

string token = Request.From["GUID"];  
 if (!this.CheckToken(token))  
 {  
	return false;  
  }  



 

 


  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值