zoukankan      html  css  js  c++  java
  • XSS工具类,清除参数中的特殊字符

    package com.xss;
    
    import java.util.regex.Pattern;
    
    
    /**
     * XssUtil 工具类
     */
    public class XssUtil {
    
        static Pattern scriptPattern = Pattern.compile("<script>(.*?)</script>", Pattern.CASE_INSENSITIVE);
    
    
        static Pattern scriptPatternSrc = Pattern.compile("src="(.*?)",Pattern.CASE_INSENSITIVE );
    
        static Pattern scriptPatternHref = Pattern.compile("href="(.*?)",Pattern.CASE_INSENSITIVE );
    
        static Pattern singleScriptPattern = scriptPattern = Pattern.compile("</script>", Pattern.CASE_INSENSITIVE);
        static Pattern singleBeginScriptPattern = Pattern.compile("<script(.*?)>",
                Pattern.CASE_INSENSITIVE | Pattern.MULTILINE | Pattern.DOTALL);
    
        static Pattern singleBeginIframePattern = Pattern.compile("<iframe(.*?)>",
                Pattern.CASE_INSENSITIVE | Pattern.MULTILINE | Pattern.DOTALL);
    
        static Pattern criptPattern = Pattern.compile("eval\((.*?)\)",
                Pattern.CASE_INSENSITIVE | Pattern.MULTILINE | Pattern.DOTALL);
        static Pattern expressionPattern = Pattern.compile("expression\((.*?)\)",
                Pattern.CASE_INSENSITIVE | Pattern.MULTILINE | Pattern.DOTALL);
    
        static Pattern javascriptPattern = Pattern.compile("javascript:", Pattern.CASE_INSENSITIVE);
        //alert
        static Pattern alertPattern = Pattern.compile("(.*?)alert(.*?)", Pattern.CASE_INSENSITIVE);
    
        static Pattern importPattern = Pattern.compile("(.*?)import(.*?)", Pattern.CASE_INSENSITIVE);
    
        static Pattern functionPattern = Pattern.compile("(.*?)function(.*?)", Pattern.CASE_INSENSITIVE);
    
        static Pattern vbscriptPattern = Pattern.compile("vbscript:", Pattern.CASE_INSENSITIVE);
    
        static Pattern onScriptPattern = Pattern.compile("on(.*?)=['|"](.*?)['|"]",
                Pattern.CASE_INSENSITIVE | Pattern.MULTILINE | Pattern.DOTALL);
    
    
    
        /**
         * 清理xss特殊字符
         * @param value 过滤的字符串
         * @return: String
         */
        public static String cleanXSS(String value) {
            if (value != null) {
                // 避免script 标签
                value = scriptPattern.matcher(value).replaceAll("");
    
                // 避免src形式的表达式
                value = scriptPatternSrc.matcher(value).replaceAll("");
    
                // 避免href形式的表达式
                value = scriptPatternHref.matcher(value).replaceAll("");
                // 删除单个的 </script> 标签
                value = singleScriptPattern.matcher(value).replaceAll("");
    
                // 删除单个的<script ...> 标签
                value = singleBeginScriptPattern.matcher(value).replaceAll("");
                // 删除单个的<iframe ...> 标签
                value = singleBeginIframePattern.matcher(value).replaceAll("");
                // 避免 eval(...) 形式表达式
                value = criptPattern.matcher(value).replaceAll("");
    
                // 避免 e­xpression(...) 表达式
                value = expressionPattern.matcher(value).replaceAll("");
    
                // 避免 javascript: 表达式
                value = javascriptPattern.matcher(value).replaceAll("");
    
                value = alertPattern.matcher(value).replaceAll("");
    
                value = importPattern.matcher(value).replaceAll("");
    
                value = functionPattern.matcher(value).replaceAll("");
    
                // 避免 vbscript: 表达式
                value = vbscriptPattern.matcher(value).replaceAll("");
                // 避免 onXX= 表达式
                value = onScriptPattern.matcher(value).replaceAll("");
    
            }
            return value;
        }
    
    
    }
  • 相关阅读:
    常用业务接口界面化 in python flask
    git命令中带有特殊符号如@
    生成唯一标识 字符串跟时间戳的结合
    MD5 in JAVA
    修改(同步)linux时间
    jenkins 从git拉取代码
    Git 默认不区分大小写
    postman也可以使用F12功能
    Session
    WebXML部署服务
  • 原文地址:https://www.cnblogs.com/pxblog/p/13360929.html
Copyright © 2011-2022 走看看