asp.net網站在web.config添加防注入代碼
廣告:
<?xml version="1.0" encoding="UTF-8"?>
<configuration>
<system.webServer>
<defaultDocument>
<files>
<remove value="index.htm" />
<remove value="index.html" />
<remove value="Default.htm" />
<remove value="Default.asp" />
<remove value="iisstart.htm" />
<add value="index.html" />
<add value="index.asp" />
</files>
</defaultDocument>
<security>
<requestFiltering>
<denyQueryStringSequences>
<add sequence="'" />
<add sequence="select" />
<add sequence="insert" />
<add sequence="union" />
<add sequence="load_file" />
<add sequence="outfile" />
<add sequence="into" />
<add sequence=";" />
<add sequence="0x27" />
<add sequence="%3b" />
<add sequence="exec" />
<add sequence="--" />
<add sequence="%20" />
<add sequence="%" />
<add sequence="or" />
<add sequence="exists" />
<add sequence="eval" />
<add sequence=")" />
</denyQueryStringSequences>
<fileExtensions>
<add fileExtension=".exe" allowed="false" />
<add fileExtension=".cmd" allowed="false" />
<add fileExtension=".com" allowed="false" />
<add fileExtension=".bat" allowed="false" />
</fileExtensions>
<filteringRules>
<filteringRule name="deny_sql_injetction" scanUrl="true" scanQueryString="false">
<scanHeaders>
<clear />
<add requestHeader="http" />
</scanHeaders>
<appliesTo>
<clear />
<add fileExtension=".asp" />
<add fileExtension=".aspx" />
<add fileExtension=".js" />
<add fileExtension=".xml" />
<add fileExtension=".html" />
</appliesTo>
<denyStrings>
<clear />
<add string="%3b" />
<add string="exec" />
<add string="select" />
<add string="delete" />
<add string="union" />
<add string="--" />
<add string="@" />
<add string="alter" />
<add string="begin" />
<add string="cast" />
<add string="convert" />
<add string="drop" />
<add string="end" />
<add string="insert" />
<add string="kill" />
<add string="sys" />
<add string="update" />
<add string="%20" />
<add string="&quot;" />
<add string="<" />
<add string=">" />
<add string="&lt;" />
<add string="&gt;" />
</denyStrings>
</filteringRule>
</filteringRules>
</requestFiltering>
</security>
</system.webServer>
</configuration>
廣告: