AppScan安全漏洞报告
1.会话cookie中缺少HttpOnly属性。
修复任务:向所有会话cookie添加“HttpOnly”属性
解决方案,过滤器中,
HttpServletResponse response2 = (HttpServletResponse)response; //httponly是微软对cookie做的扩展,该值指定 Cookie 是否可通过客户端脚本访问, //解决用户的cookie可能被盗用的问题,减少跨站脚本攻击 response2.setHeader( "Set-Cookie", "name=value; HttpOnly");
2.跨站点请求伪造。修复任务:拒绝恶意请求。
解决方案,过滤器中
//HTTP 头设置 Referer过滤 String referer = request2.getHeader("Referer"); //REFRESH if(referer!=null && referer.indexOf(basePath)<0){ request2.getRequestDispatcher(request2.getRequestURI()).forward(request2, response); }
3.AutocompleteHTMLAttributeNotDisabledforPasswordField
修复任务:Correctlysetthe"autocomplete"attributeto"off"
密 码: <input name="userinfo.userPwd" type="password" autocomplete = "off"/>
4.HTML注释敏感信息泄露。删除注释信息。
5.跨站点脚本编制,SQL盲注,通过框架钓鱼,链接注入(便于跨站请求伪造)。修复任务:过滤掉用户输入中的危险字符
private String filterDangerString(String value) { if (value == null) { return null; } value = value.replaceAll("\\|", ""); value = value.replaceAll("&", "&"); value = value.replaceAll(";", ""); value = value.replaceAll("@", ""); value = value.replaceAll("'", ""); value = value.replaceAll("\"", ""); value = value.replaceAll("\\'", ""); value = value.replaceAll("\\\"", ""); value = value.replaceAll("<", "<"); value = value.replaceAll(">", ">"); value = value.replaceAll("\\(", ""); value = value.replaceAll("\\)", ""); value = value.replaceAll("\\+", ""); value = value.replaceAll("\r", ""); value = value.replaceAll("\n", ""); value = value.replaceAll("script", ""); value = value.replaceAll("%27", ""); value = value.replaceAll("%22", ""); value = value.replaceAll("%3E", ""); value = value.replaceAll("%3C", ""); value = value.replaceAll("%3D", ""); value = value.replaceAll("%2F", ""); return value; }
摘自:http://www.linuxso.com/architecture/38094.html
相关推荐
xhpscdx 2020-05-31
houmenghu 2020-11-17
kentrl 2020-11-10
逍遥友 2020-10-26
jincheng 2020-09-01
Blueberry 2020-08-15
xclxcl 2020-08-03
zmzmmf 2020-08-03
阳光之吻 2020-08-03
PkJY 2020-07-08
hzyuhz 2020-07-04
89407707 2020-06-27
服务器端攻城师 2020-06-26
阳光岛主 2020-06-25
笨重的蜗牛 2020-06-20
xuanwenchao 2020-06-14
Lophole 2020-06-13
明瞳 2020-06-12