www ÓÐÄÄЩÎó²î
www Îó²î¿ÉÄܵ¼ÖÂÊý¾Ý͵ÇÔ¡¢ÏµÍ³ÆÆËðµÈÎÊÌâ¡£³£¼ûµÄÎó²î°üÀ¨£º¿çÕ¾¾ç±¾ (xss)¡¢sql ×¢Èë¡¢¿çÕ¾µãÇëÇóαÔì (csrf)¡¢Îļþ°üÀ¨¡¢Éí·ÝÑéÖ¤ºÍÊÚȨÎÊÌâ¡¢ÊäÈëÑéÖ¤ºÍÊý¾Ýй¶¡£Ô¤·À²½·¥°üÀ¨Çå¾²µÄ±àÂëʵ¼ù¡¢°´ÆÚÈí¼þ¸üС¢Çå¾²¿Ø¼þ¡¢Çå¾²Éó¼ÆºÍÉø͸²âÊÔ£¬ÒÔ¼°Óû§ÍøÂçÇå¾²½ÌÓý¡£
WWWÎó²î´óÈ«
ÏÈÈÝ
WWW£¨ÍòάÍø£©ÊÇÒ»ÖÖÆÕ±éÂþÑܵÄÐÅϢϵͳ£¬ËüÔÊÐíÓû§Í¨¹ý»¥ÁªÍø»á¼ûÎĵµºÍ×ÊÔ´¡£È»¶ø£¬ÓÉÓÚÆäÖØ´óÐÔ£¬WWW ±£´æÐí¶àDZÔÚµÄÎó²î£¬¿É±»¹¥»÷ÕßÓÃÀ´ÇÔÈ¡Êý¾Ý¡¢ÆÆËðϵͳ»òÒÔÆäËû·½·¨Ëðº¦Óû§¡£
³£¼ûÎó²î
1. ¿çÕ¾¾ç±¾£¨XSS£©
XSS Îó²îÔÊÐí¹¥»÷ÕßÔÚÄ¿µÄÍøÕ¾ÉÏ×¢Èë²¢Ö´ÐжñÒâ¾ç±¾£¬´Ó¶øÇÔÈ¡Óû§»á»° cookie¡¢Öض¨ÏòÁ÷Á¿»òÈö²¥¶ñÒâÈí¼þ¡£
2. SQL ×¢Èë
SQL ×¢ÈëÎó²îʹ¹¥»÷ÕßÄܹ»ÔÚ Web Ó¦ÓóÌÐò·¢Ë͵½Êý¾Ý¿âµÄ SQL ÅÌÎÊÖÐ×¢Èë¶ñÒâ´úÂ룬´Ó¶ø¼ìË÷Ãô¸ÐÊý¾Ý»òÐÞ¸ÄÊý¾Ý¿âÄÚÈÝ¡£
3. ¿çÕ¾µãÇëÇóαÔ죨CSRF£©
CSRF Îó²îÔÊÐí¹¥»÷ÕßÓÕÆÓû§ä¯ÀÀÆ÷ÔÚ²»ÊÜÓû§ÖªÇé»òÊÚȨµÄÇéÐÎÏÂÏòÄ¿µÄÍøÕ¾·¢ËÍÇëÇ󣬴ӶøÒý·¢Î´¾ÊÚȨµÄ²Ù×÷¡£
4. Îļþ°üÀ¨
Îļþ°üÀ¨Îó²îʹ¹¥»÷ÕßÄܹ»°üÀ¨í§ÒâÎļþµ½ Web Ó¦ÓóÌÐòÖУ¬´Ó¶øÖ´ÐжñÒâ´úÂë»ò»á¼ûÃô¸ÐÐÅÏ¢¡£
5. Éí·ÝÑéÖ¤ºÍÊÚȨÎÊÌâ
Éí·ÝÑéÖ¤ºÍÊÚȨÎÊÌâ¿Éʹ¹¥»÷ÕßÈƹýÇå¾²¿ØÖƲ¢»ñµÃ¶ÔÊܱ£»¤×ÊÔ´»ò¹¦Ð§µÄδÊÚȨ»á¼û£¬ÀýÈçÓû§ÕÊ»§»òÃô¸ÐÊý¾Ý¡£
6. ÊäÈëÑéÖ¤
ÊäÈëÑéÖ¤Îó²îʹ¹¥»÷ÕßÄܹ»Èƹý¶ÔÊäÈëÊý¾ÝµÄ¼ì²é£¬´Ó¶øÖ´ÐжñÒâ²Ù×÷»ò×¢Èë¶ñÒâÄÚÈÝ¡£
7. Êý¾Ýй¶
Êý¾Ýй¶Îó²îʹ¹¥»÷ÕßÄܹ»»á¼û»òÇÔÈ¡´æ´¢ÔÚ Web Ó¦ÓóÌÐò»òÊý¾Ý¿âÖеÄÃô¸ÐÐÅÏ¢£¬ÀýÈçÐÅÓÿ¨ºÅ»òСÎÒ˽¼ÒÉí·ÝÐÅÏ¢¡£
Ô¤·À²½·¥
±ÜÃâ WWW Îó²îµÄ×î¼ÑÒªÁì°üÀ¨£º
- ʹÓÃÇå¾²µÄ±àÂëʵ¼ù
- °´ÆÚ¸üÐÂÈí¼þºÍÐÞ²¹³ÌÐò
- ʵÑéÇå¾²¿Ø¼þ£¬ÀýÈçÊäÈëÑéÖ¤¡¢Éí·ÝÑéÖ¤ºÍÊÚȨ
- °´ÆÚ¾ÙÐÐÇå¾²Éó¼ÆºÍÉø͸²âÊÔ
- ½ÌÓýÓû§ÓйØÍøÂçÇ徲Σº¦
ÒÔÉϾÍÊÇwww ÓÐÄÄЩÎó²îµÄÏêϸÄÚÈÝ£¬¸ü¶àÇë¹Ø×¢±¾ÍøÄÚÆäËüÏà¹ØÎÄÕ£¡