• XSS工具类,清除参数中的特殊字符


    package com.xss;
    
    import java.util.regex.Pattern;
    
    
    /**
     * XssUtil 工具类
     */
    public class XssUtil {
    
        static Pattern scriptPattern = Pattern.compile("<script>(.*?)</script>", Pattern.CASE_INSENSITIVE);
    
    
        static Pattern scriptPatternSrc = Pattern.compile("src="(.*?)",Pattern.CASE_INSENSITIVE );
    
        static Pattern scriptPatternHref = Pattern.compile("href="(.*?)",Pattern.CASE_INSENSITIVE );
    
        static Pattern singleScriptPattern = scriptPattern = Pattern.compile("</script>", Pattern.CASE_INSENSITIVE);
        static Pattern singleBeginScriptPattern = Pattern.compile("<script(.*?)>",
                Pattern.CASE_INSENSITIVE | Pattern.MULTILINE | Pattern.DOTALL);
    
        static Pattern singleBeginIframePattern = Pattern.compile("<iframe(.*?)>",
                Pattern.CASE_INSENSITIVE | Pattern.MULTILINE | Pattern.DOTALL);
    
        static Pattern criptPattern = Pattern.compile("eval\((.*?)\)",
                Pattern.CASE_INSENSITIVE | Pattern.MULTILINE | Pattern.DOTALL);
        static Pattern expressionPattern = Pattern.compile("expression\((.*?)\)",
                Pattern.CASE_INSENSITIVE | Pattern.MULTILINE | Pattern.DOTALL);
    
        static Pattern javascriptPattern = Pattern.compile("javascript:", Pattern.CASE_INSENSITIVE);
        //alert
        static Pattern alertPattern = Pattern.compile("(.*?)alert(.*?)", Pattern.CASE_INSENSITIVE);
    
        static Pattern importPattern = Pattern.compile("(.*?)import(.*?)", Pattern.CASE_INSENSITIVE);
    
        static Pattern functionPattern = Pattern.compile("(.*?)function(.*?)", Pattern.CASE_INSENSITIVE);
    
        static Pattern vbscriptPattern = Pattern.compile("vbscript:", Pattern.CASE_INSENSITIVE);
    
        static Pattern onScriptPattern = Pattern.compile("on(.*?)=['|"](.*?)['|"]",
                Pattern.CASE_INSENSITIVE | Pattern.MULTILINE | Pattern.DOTALL);
    
    
    
        /**
         * 清理xss特殊字符
         * @param value 过滤的字符串
         * @return: String
         */
        public static String cleanXSS(String value) {
            if (value != null) {
                // 避免script 标签
                value = scriptPattern.matcher(value).replaceAll("");
    
                // 避免src形式的表达式
                value = scriptPatternSrc.matcher(value).replaceAll("");
    
                // 避免href形式的表达式
                value = scriptPatternHref.matcher(value).replaceAll("");
                // 删除单个的 </script> 标签
                value = singleScriptPattern.matcher(value).replaceAll("");
    
                // 删除单个的<script ...> 标签
                value = singleBeginScriptPattern.matcher(value).replaceAll("");
                // 删除单个的<iframe ...> 标签
                value = singleBeginIframePattern.matcher(value).replaceAll("");
                // 避免 eval(...) 形式表达式
                value = criptPattern.matcher(value).replaceAll("");
    
                // 避免 e­xpression(...) 表达式
                value = expressionPattern.matcher(value).replaceAll("");
    
                // 避免 javascript: 表达式
                value = javascriptPattern.matcher(value).replaceAll("");
    
                value = alertPattern.matcher(value).replaceAll("");
    
                value = importPattern.matcher(value).replaceAll("");
    
                value = functionPattern.matcher(value).replaceAll("");
    
                // 避免 vbscript: 表达式
                value = vbscriptPattern.matcher(value).replaceAll("");
                // 避免 onXX= 表达式
                value = onScriptPattern.matcher(value).replaceAll("");
    
            }
            return value;
        }
    
    
    }
  • 相关阅读:
    Word 2003 Excel 2003 的迟绑定(late binding) 方法 时空地图TimeGIS
    快手之友情链接 时空地图TimeGIS
    InfoVista.NET 概述 时空地图TimeGIS
    快手博客 时空地图TimeGIS
    快手文档 www.kuaishou.net 时空地图TimeGIS
    快手之Excel篇 www.kuaishou.net 时空地图TimeGIS
    InfoVista.NET Beta 时空地图TimeGIS
    中国互联网络发展状况统计报告2009年 时空地图TimeGIS
    http://wiki.kuaishou.net 时空地图TimeGIS
    快手影音 www.timegis.com 时空地图TimeGIS
  • 原文地址:https://www.cnblogs.com/pxblog/p/13360929.html
Copyright © 2020-2023  润新知