关于web应用程序安全的思考(序)
2008-11-26 13:36:02 来源:WEB开发网Aspx.cs代码如下:
using System;
using System.Data;
using System.Configuration;
using System.Collections;
using System.Web;
using System.Web.Security;
using System.Web.UI;
using System.Web.UI.WebControls;
using System.Web.UI.WebControls.WebParts;
using System.Web.UI.HtmlControls;
public partial class form : System.Web.UI.Page
{
protected void Page_Load(object sender, EventArgs e)
{
}
protected void Button1_Click(object sender, EventArgs e)
{
Label2.Text = "你输入的名字是:" + TextBox1.Text;
}
}
当输入“小生”并按钮“送出”按钮时,实际上就是发送下面的这样一段Request
POST /TestWeb/form.aspx HTTP/1.1
Cache-Control: no-cache
Connection: close
Content-Length: 206
Content-Type: application/x-www-form-urlencoded
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, */*
Accept-Encoding: gzip, deflate
Accept-Language: zh-tw
Cookie: ASP.NET_SessionId=jd14mp2k4e0dyga4hjz1zgby
Host: localhost
Referer: http://localhost/TestWeb/form.aspx
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; SV1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30)
UA-CPU: x86
__VIEWSTATE=%2FwEPDwUJODUwMjI0NzE3ZGQgpj%2Fm%2BSOD2vEbxBDW9BpDvogpgA%3D%3D&TextBox1=%E5%B0%
8F
%E7%94%
9F
&Button1=%E9%80%81%E5%87%BA&__EVENTVALIDATION=%2FwEWAwKdv8y5BwLs0bLrBgKM54rGBj5ZvpRog0Ox
8f
9YoKD3sYnCmNxG
更多精彩
赞助商链接