xss漏洞修复思路

public static String htmlSecurityEscape(String str) {
        if (str == null) {
            return null;
        } else {
            StringBuilder sb = null;
            int len = str.length();

            try {
                for(int i = 0; i < len; ++i) {
                    char ch = str.charAt(i);
                    switch(ch) {
                    case '"':
                        if (sb == null) {
                            sb = new StringBuilder(str.length() << 1);
                            sb.append(str, 0, i);
                        }

                        sb.append("&quot;");
                        break;
                    case '&':
                        int in = str.indexOf(59, i + 1);
                        if (in != -1 && in - i < 9 && str.substring(i + 1, in).indexOf(38) == -1) {
                            if (sb != null) {
                                sb.append(ch);
                            }
                            break;
                        }

                        if (sb == null) {
                            sb = new StringBuilder(str.length() << 1);
                            sb.append(str, 0, i);
                        }

                        sb.append("&amp;");
                        break;
                    case '\'':
                        if (sb == null) {
                            sb = new StringBuilder(str.length() << 1);
                            sb.append(str, 0, i);
                        }

                        sb.append("&#39;");
                        break;
                    case '*':
                        if (i + 1 < str.length() && str.charAt(i + 1) == '/') {
                            if (sb == null) {
                                sb = new StringBuilder(str.length() << 1);
                                sb.append(str, 0, i);
                            }

                            sb.append("&#42;&#47;");
                            ++i;
                        } else if (sb != null) {
                            sb.append(ch);
                        }
                        break;
                    case '/':
                        if (i + 1 < str.length() && str.charAt(i + 1) == '*') {
                            if (sb == null) {
                                sb = new StringBuilder(str.length() << 1);
                                sb.append(str, 0, i);
                            }

                            sb.append("&#47;&#42;");
                            ++i;
                        } else if (sb != null) {
                            sb.append(ch);
                        }
                        break;
                    case '<':
                        if (sb == null) {
                            sb = new StringBuilder(str.length() << 1);
                            sb.append(str, 0, i);
                        }

                        sb.append("&lt;");
                        break;
                    case '>':
                        if (sb == null) {
                            sb = new StringBuilder(str.length() << 1);
                            sb.append(str, 0, i);
                        }

                        sb.append("&gt;");
                        break;
                    case '\\':
                        if (sb == null) {
                            sb = new StringBuilder(str.length() << 1);
                            sb.append(str, 0, i);
                        }

                        sb.append("\\&shy;");
                        break;
                    default:
                        if (Character.getDirectionality(ch) != 2 && Character.getDirectionality(ch) != 16 && Character.getDirectionality(ch) != 17) {
                            if (sb != null) {
                                sb.append(ch);
                            }
                        } else if (sb == null) {
                            sb = new StringBuilder(str.length() << 1);
                            sb.append(str, 0, i);
                        }
                    }
                }
            } catch (Exception var6) {
                var6.printStackTrace();
                System.err.println(str);
            }

            return null != sb ? sb.toString() : str;
        }
    }
评论 2
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值