万卷书   首页 > 电脑书籍 > Web服务器 > Web恶意内容入侵分析及应对措施之四
 

Perl


#! The first function takes the negative approach.
#! Use a list of bad characters to filter the data
sub FilterNeg {
local( $fd ) = @_;
$fd =~ s/[\<\>\"\'\%\;\)\(\&\+]//g;
return( $fd ) ;
}

#! The second function takes the positive approach.
#! Use a list of good characters to filter the data
sub FilterPos {
local( $fd ) = @_;
$fd =~ tr/A-Za-z0-9\ //dc;
return( $fd ) ;
}

$Data = "This is a test string<script>";
$Data = &FilterNeg( $Data );
print "$Data\n";

$Data = "This is a test string<script>";
$Data = &FilterPos( $Data );
print "$Data\n";

第五步:检查Cookies值

   攻击者还可能将恶意内容写入cookie中,因此,Web开发者应该仔细地检查接受的cookie值,并使用上面提及的过滤技术以验证它们是否包含了恶意内容。

上一页