关于web应用程序安全的思考(一)
2008-11-26 13:35:59 来源:WEB开发网相关的aspx.cs程序如下﹕
using System;
using System.Data;
using System.Configuration;
using System.Collections;
using System.Web;
using System.Web.Security;
using System.Web.UI;
using System.Web.UI.WebControls;
using System.Web.UI.WebControls.WebParts;
using System.Web.UI.HtmlControls;
using System.IO;
public partial class TestRequest : System.Web.UI.Page
{
protected void Page_Load(object sender, EventArgs e)
{
Request.SaveAs("c:/test.txt",true);
using(StreamReader sr = new StreamReader("c:/test.txt"))
{
tt_request.Value = (sr.ReadToEnd());
}
foreach (string key in Request.QueryString.AllKeys)
div_querystring.Value += string.Format("{0}:{1}rn", key, Request[key]);
if (Session["firsttime"] == null)
{
Session["firsttime"] = DateTime.Now.ToString("yyyy/MM/dd HH:mm:ss");
Response.Write("<b style='color:red'>first request</b></br>");
}
Response.Write("First Time:" + Session["firsttime"].ToString());
}
}
aspx页面:
<%@ Page Language="C#" AutoEventWireup="true" CodeFile="TestRequest.aspx.cs" Inherits="TestRequest" %>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" >
<head runat="server">
<title>请求字串提取示例</title>
</head>
<body>
这是Request字符串﹕<br />
<textarea style="width:100%;height:200px" id="tt_request" runat="server">
</textarea>
以下是程式直接提取的参数﹕<br />
<textarea id="div_querystring" runat="server" style="width:100%;height:100px">
</textarea>
</body>
</html>
更多精彩
赞助商链接