Martinjc ±zŠn¡G
«Ü·PÁ±z¥D°Êšó§U€á¬FšÆ°È©ÒÀ°§Ú§ï€F©m€F
¥i±€šä¥L¬ÛÃöªºÃÒ¥ó¡BÃҮѡA±z§Ñ€F¶¶«KÀ°Š£§ï
®`§ÚÁÙn¿ËŠÛšì³\ŠhŠa€è¥h§ï©m¡A¹³Ša¬FšÆ°È©Ò¡BºÊ²z©Ò¡BŸÇ®Õ¡E¡E¡E XD
šÌ·Ó±zªºnšD¡A±z¥i¥Hקï€U±³ošâÓ³]©w¡G
NormalizeUrlBeforeScan=0
VerifyNormalization=0
ìŠ]Šp€U¡G
1. Šb¶Ç°e¶išÓ¥B€wžg canonicalization ªº URL €~·|³Q UrlScan §ìšÓÀˬd¡A°²³]
client °e¶išÓªº¬O ¡uAlex%20Chuo¡v©Î¬O¡uAlex+Chuo¡v¡AŠb UrlScan šÓ¬Ý³£¬O€@ŒËªº¡G¡uAlex Chuo¡v¡AŠÓ±zì¥ýnªýŸ×ªº¬O¥]§t¡u%20¡v»P¡u+¡vªºŠrŠê ¡AžÕ°Ý³oŒË¬O§_³s¥¿
±`ªº¡uAlex Chuo¡v³£€@šÖ³QªýŸ×€F©O¡H
¬°€FÁקK³oºØ±¡ªp¡A©Ò¥HnÅý raw URL ì쥻¥»Ša°eµ¹ UrlScan šÓÀˬd¡An³]©w¡GNormalizeUrlBeforeScan=0
2.·í URL ¥]§t¡u%2520¡v¡Ašä€€¡u%25¡v©Ò¥Nªíªº·N«ä¬O¡u%¡v³oӲ޹¡AŠ]Š¹žg¹L
canonicalization €§«á¡AŠ¹®É UrlScan ©Ò¬Ýšìªº±N¬O¡u%20¡v¡AŠÓ«D¡u%2520¡v¡A³oŽN¬O¬°€°»òÓ€Hn±z³]©wVerifyNormalization=0ªºìŠ]¡C
§_«h request ·|Šb [DenyUrlSequences] €§«e¡AŽN¥ý³Q filter ±Œ¡C
¥H€W¡AœÐ°ÑŠÒ¡C
ŠAŠž±jœÕ¡Gclient °e¹LšÓªº URL request ²ÕŠX€d€džUžUºØ¡A¥ú¬O % ³oӲ޹ŽN¥i¥HŠ³«ÜŠhºØ²ÕŠX¡AYŠAŠÒŒ{ Unicode ªº²ÕŠX¡A€ñŠp»¡¡G%26»P
%u0026³ošâªÌ©Ò¥Nªíªº·Nžq¬O€@ŒËªº¡A¥i¬OŠb§Ú̪œ±µ¬Ý©Î¬O UrlScan šÓ¬Ý¡A³£€£€@ŒË°Ú¡IŠ]¬°Šr€žªø«×ŽN€£€@ŒË¡A¬OšS¿ù¡AŠý¬O°eµ¹ IIS šÓžÑªRªº®ÉÔ¡AŽN¬O€@ŒË°Ú¡I
ŽN¬OŠ]¬°³oºØ²ÕŠXªºÃD¥Ø¥i¥HŒgӜ׀å€F¡A³o€]¬O¬°€°»òÓ€HŠb¥ý«eªºŠ^ÂЀ€¡A·|«Øij³z¹L«áºÝ AP šÓ³B²z SQL injection¡A²Š³º€@Ó¬O±q®Ú¥»µÛ€â¡A€@Ó¬OÀYµhÂåÀY¡Až}µhÂå
ž}¡C·íµM°Õ¡I³Ì«áªº¿ïŸÜÅv¬OŠb±z€âÀY€W¡AnŠpŠó³B²z¡AºÝµø±zªºšM©w¡C
--
³¹¥ß¥Á¬ãšs«Ç
·s®Ñ§Y±N°Ý¥@¡GVisual C# 2005 µ{Š¡¶}µo»P€¶±³]p¯µ³Z
€wžgµoŠæªº®Ñ¡GVisual Basic 2005 µ{Š¡¶}µo»P€¶±³]p¯µ³Z
·L³n³ÌŠ³»ùȱM®a
Microsoft MVP
šô¥ß¥Á (Alex Chuo) for Windows Help
\==================================
|| Y§Úªº»¡©ú¹ï±zŠ³À°§U¡AœÐŠ^À³¡F
|| Y§Úªº»¡©ú¬O¿ù»~ªº¡A¥çœÐŠ^À³¡C
/==================================
€£ŽN¥ôŠóµoªíªºŠ^À³žê°T§@¥ôŠó©Ó¿Õ¡A¥B€£t¥ôŠóŸá«O³d¥ô¡C
This posting is provided "AS IS" with no warranties, and confers no rights.
³¹¥ý¥Í±zŠn¡G
ŠbURLSCAN€€¡AŠpŠó¥h±NSQLinjectionªº¬YšÇŠrœXªýŸ×°_šÓ
Š]¬°²{Šbµo²{ªº°ÝÃDŽN¬OŠ³€H±N³oŒË€lªº»yªk¶KŠbURL€W
·Q»¡³oŒË€l¬O§_Š³€èŠ¡¥i¥HªýŸ×
°²³]€£§ïµ{Š¡ªºžÜ
"Microsoft MVP ??? for Windows Help" šÓšç¡G
Post by Microsoft MVP šô¥Ã¥à for Windows Help±zŠn¡G
--
³¹¥ß¥Á¬ãšs«Ç
€wžgµoŠæªº®Ñ¡GVisual Basic 2005 µ{Š¡¶}µo»P€¶±³]p¯µ³Z
·L³n³ÌŠ³»ùȱM®a
Microsoft MVP
šô¥ß¥Á (Alex Chuo) for Windows Help
\==================================
|| Y§Úªº»¡©ú¹ï±zŠ³À°§U¡AœÐŠ^À³¡F
|| Y§Úªº»¡©ú¬O¿ù»~ªº¡A¥çœÐŠ^À³¡C
/==================================
This posting is provided "AS IS" with no warranties, and confers no rights.
€£Šn·N«ä¡A©Ò¥H¬O»¡ŽNºâ±NSQLinjectionªº¬YšÇŠrœX©ñŠb[DenyUrlSequences]€€¡A€]µLªkªýŸ×³oŒËªºšÆ±¡µo¥Í¶Ü¡H
"æ£æ£" šÓšç¡G
³q±`ÁôœX§ðÀ»¬OŠb Form žÌ±ªº Text ©Î TextArea ¡A«Ü€Öªœ±µ©ñŠb url €º¡AŽNºâ©ñŠb url €º¡A€]·|°µ urlEncode ¡A©Ò¥HšS®t§a~
ŠbUrlScan.iniÀÉ€€
[DenyUrlSequences]ªº³¡¥÷
Š]¬°¥Ø«e°£€F¹w³]ªºŽXÓžU¥ÎŠr€ž¥i¥H±µšü¥~
¥i¬OŽúžÕµ²ªGÁÙ¬O¥i¥H³q¹L
œÐ°ÝÃö©óSQLinjectionªº³¡¥÷
¬O§_¥i¥HŠbUrlScan€€ªýŸ×?
n¬O¥i¥HªºžÜ¡A¬O§_ŽN¬O¥[Šb[DenyUrlSequences]šä€€¡AŽN¥i¥H€F
³Â·Ð·|ªº€H¥i¥H§i¶D§Ú£ž€U¡A«ô°U«ô°U
ÁÂÁÂ