zoukankan      html  css  js  c++  java
  • spring boot / cloud (一) 使用filter防止XSS obejct

    spring boot / cloud (一) 使用filter防止XSS

    前言

    XSS(跨站脚本攻击)

    跨站脚本攻击(Cross Site Scripting),为不和层叠样式表(Cascading Style Sheets, CSS)的缩写混淆,故将跨站脚本攻击缩写为XSS。恶意攻击者往Web页面里插入恶意Script代码,当用户浏览该页之时,嵌入其中Web里面的Script代码会被执行,从而达到恶意攻击用户的目的。

    思路

    基于filter拦截,将特殊字符替换为html转意字符 (如: "<" 转意为 "&lt;") , 需要拦截的点如下:

    • 请求头 requestHeader

    • 请求体 requestBody

    • 请求参数 requestParameter

    实现

    1.创建XssHttpServletRequestWrapper类

    在获取请求头,请求参数的这些地方,将目标值使用HtmlUtils.htmlEscape方法转意为html字符,而避免恶意代码参与到后续的流程中

    
    /**
     * XssHttpServletRequestWrapper.java
     * Created at 2016-09-19
     * Created by wangkang
     * Copyright (C) 2016 egridcloud.com, All rights reserved.
     */
    package org.itkk.udf.core.xss;
    
    import javax.servlet.http.HttpServletRequest;
    import javax.servlet.http.HttpServletRequestWrapper;
    
    import org.springframework.web.util.HtmlUtils;
    
    /**
     * 描述 : 跨站请求防范
     *
     * @author wangkang
     *
     */
    public class XssHttpServletRequestWrapper extends HttpServletRequestWrapper {
    
      /**
       * 描述 : 构造函数
       *
       * @param request 请求对象
       */
      public XssHttpServletRequestWrapper(HttpServletRequest request) {
        super(request);
      }
    
      @Override
      public String getHeader(String name) {
        String value = super.getHeader(name);
        return HtmlUtils.htmlEscape(value);
      }
    
      @Override
      public String getParameter(String name) {
        String value = super.getParameter(name);
        return HtmlUtils.htmlEscape(value);
      }
    
      @Override
      public String[] getParameterValues(String name) {
        String[] values = super.getParameterValues(name);
        if (values != null) {
          int length = values.length;
          String[] escapseValues = new String[length];
          for (int i = 0; i < length; i++) {
            escapseValues[i] = HtmlUtils.htmlEscape(values[i]);
          }
          return escapseValues;
        }
        return super.getParameterValues(name);
      }
    
    }
    
    

    2.创建XssStringJsonSerializer类

    其次是涉及到json转换的地方,也一样需要进行转意,比如,rerquestBody,responseBody

    
    /**
     * XssStringJsonSerializer.java
     * Created at 2016-09-19
     * Created by wangkang
     * Copyright (C) 2016 egridcloud.com, All rights reserved.
     */
    package org.itkk.udf.core.xss;
    
    import java.io.IOException;
    
    import org.springframework.web.util.HtmlUtils;
    
    import com.fasterxml.jackson.core.JsonGenerator;
    import com.fasterxml.jackson.databind.JsonSerializer;
    import com.fasterxml.jackson.databind.SerializerProvider;
    
    /**
     * 描述 : 基于xss的JsonSerializer
     *
     * @author wangkang
     *
     */
    public class XssStringJsonSerializer extends JsonSerializer<String> {
    
      @Override
      public Class<String> handledType() {
        return String.class;
      }
    
      @Override
      public void serialize(String value, JsonGenerator jsonGenerator,
          SerializerProvider serializerProvider) throws IOException {
        if (value != null) {
          String encodedValue = HtmlUtils.htmlEscape(value);
          jsonGenerator.writeString(encodedValue);
        }
      }
    
    }
    
    

    3.创建Bean

    在启动类中,创建XssObjectMapper的bean,替换spring boot原有的实例,用于整个系统的json转换.

    
      /**
       * 描述 : xssObjectMapper
       *
       * @param builder builder
       * @return xssObjectMapper
       */
      @Bean
      @Primary
      public ObjectMapper xssObjectMapper(Jackson2ObjectMapperBuilder builder) {
        //解析器
        ObjectMapper objectMapper = builder.createXmlMapper(false).build();
        //注册xss解析器
        SimpleModule xssModule = new SimpleModule("XssStringJsonSerializer");
        xssModule.addSerializer(new XssStringJsonSerializer());
        objectMapper.registerModule(xssModule);
        //返回
        return objectMapper;
      }
    
    

    4.创建XssFilter

    首先是拦截所有的请求,然后在doFilter方法中,将HttpServletRequest强制类型转换成XssHttpServletRequestWrapper

    然后传递下去.

    
    /**
     * XssFilter.java
     * Created at 2016-09-19
     * Created by wangkang
     * Copyright (C) 2016 egridcloud.com, All rights reserved.
     */
    package org.itkk.udf.core.xss;
    
    import java.io.IOException;
    
    import javax.servlet.Filter;
    import javax.servlet.FilterChain;
    import javax.servlet.FilterConfig;
    import javax.servlet.ServletException;
    import javax.servlet.ServletRequest;
    import javax.servlet.ServletResponse;
    import javax.servlet.annotation.WebFilter;
    import javax.servlet.http.HttpServletRequest;
    
    import org.slf4j.Logger;
    import org.slf4j.LoggerFactory;
    
    /**
     * 描述 : 跨站请求防范
     *
     * @author wangkang
     *
     */
    @WebFilter(filterName = "xssFilter", urlPatterns = "/*", asyncSupported = true)
    public class XssFilter implements Filter {
    
      /**
       * 描述 : 日志
       */
      private static final Logger LOGGER = LoggerFactory.getLogger(XssFilter.class);
    
      @Override
      public void init(FilterConfig filterConfig) throws ServletException {
      
      }
    
      @Override
      public void doFilter(ServletRequest request, ServletResponse response, FilterChain chain)
          throws IOException, ServletException {
        XssHttpServletRequestWrapper xssRequest =
            new XssHttpServletRequestWrapper((HttpServletRequest) request);
        chain.doFilter(xssRequest, response);
      }
    
      @Override
      public void destroy() {
      }
    
    }
    
    

    代码仓库 (博客配套代码)

    结束

    本文虽基于spring boot实现主题,但是思路是一致的,不限于任何框架.


    想获得最快更新,请关注公众号

    想获得最快更新,请关注公众号

  • 相关阅读:
    google
    html页面清除缓存
    EF中使用SQL语句或存储过程
    在存储过程中编写正确的事务处理代码
    .Net中Math.Round与四舍五入
    WebService中实现上传下载文件
    tony_linux下网站压力测试工具webbench
    把Nginx加为系统服务(service nginx start/stop/restart)
    Nginx+Tomcat+Keepalived+Memcache 负载均衡动静分离技术
    python学习笔记(1)--遍历txt文件,正则匹配替换文字
  • 原文地址:https://www.cnblogs.com/itkk/p/7441453.html
Copyright © 2011-2022 走看看