spring boot / cloud (一) 使用filter防止XSS


声明:本文转载自https://my.oschina.net/u/3738405/blog/1582247,转载目的在于传递更多信息,仅供学习交流之用。如有侵权行为,请联系我,我会及时删除。

spring boot / cloud (一) 使用filter防止XSS

##一.前言

###XSS(跨站脚本攻击) >跨站脚本攻击(Cross Site Scripting),为不和层叠样式表(Cascading Style Sheets, CSS)的缩写混淆,故将跨站脚本攻击缩写为XSS。恶意攻击者往Web页面里插入恶意Script代码,当用户浏览该页之时,嵌入其中Web里面的Script代码会被执行,从而达到恶意攻击用户的目的。

##二.思路

###基于filter拦截,将特殊字符替换为html转意字符 (如: "<" 转意为 "<") , 需要拦截的点如下:

  • 请求头 requestHeader

  • 请求体 requestBody

  • 请求参数 requestParameter

##三.实现

###1.创建XssHttpServletRequestWrapper类

在获取请求头,请求参数的这些地方,将目标值使用HtmlUtils.htmlEscape方法转意为html字符,而避免恶意代码参与到后续的流程中

 /**  * XssHttpServletRequestWrapper.java  * Created at 2016-09-19  * Created by wangkang  * Copyright (C) 2016 egridcloud.com, All rights reserved.  */ package com.egridcloud.udf.core.xss;  import javax.servlet.http.HttpServletRequest; import javax.servlet.http.HttpServletRequestWrapper;  import org.springframework.web.util.HtmlUtils;  /**  * 描述 : 跨站请求防范  *  * @author wangkang  *  */ public class XssHttpServletRequestWrapper extends HttpServletRequestWrapper {    /**    * 描述 : 构造函数    *    * @param request 请求对象    */   public XssHttpServletRequestWrapper(HttpServletRequest request) {     super(request);   }    @Override   public String getHeader(String name) {     String value = super.getHeader(name);     return HtmlUtils.htmlEscape(value);   }    @Override   public String getParameter(String name) {     String value = super.getParameter(name);     return HtmlUtils.htmlEscape(value);   }    @Override   public String[] getParameterValues(String name) {     String[] values = super.getParameterValues(name);     if (values != null) {       int length = values.length;       String[] escapseValues = new String[length];       for (int i = 0; i < length; i++) {         escapseValues[i] = HtmlUtils.htmlEscape(values[i]);       }       return escapseValues;     }     return super.getParameterValues(name);   }  }  

###2.创建XssStringJsonSerializer类

其次是涉及到json转换的地方,也一样需要进行转意,比如,rerquestBody,responseBody

 /**  * XssStringJsonSerializer.java  * Created at 2016-09-19  * Created by wangkang  * Copyright (C) 2016 egridcloud.com, All rights reserved.  */ package com.egridcloud.udf.core.xss;  import java.io.IOException;  import org.springframework.web.util.HtmlUtils;  import com.fasterxml.jackson.core.JsonGenerator; import com.fasterxml.jackson.databind.JsonSerializer; import com.fasterxml.jackson.databind.SerializerProvider;  /**  * 描述 : 基于xss的JsonSerializer  *  * @author wangkang  *  */ public class XssStringJsonSerializer extends JsonSerializer<String> {    @Override   public Class<String> handledType() {     return String.class;   }    @Override   public void serialize(String value, JsonGenerator jsonGenerator,       SerializerProvider serializerProvider) throws IOException {     if (value != null) {       String encodedValue = HtmlUtils.htmlEscape(value);       jsonGenerator.writeString(encodedValue);     }   }  }  

###3.创建Bean

在启动类中,创建XssObjectMapper的bean,替换spring boot原有的实例,用于整个系统的json转换.

   /**    * 描述 : xssObjectMapper    *    * @param builder builder    * @return xssObjectMapper    */   @Bean   @Primary   public ObjectMapper xssObjectMapper(Jackson2ObjectMapperBuilder builder) {     //解析器     ObjectMapper objectMapper = builder.createXmlMapper(false).build();     //注册xss解析器     SimpleModule xssModule = new SimpleModule("XssStringJsonSerializer");     xssModule.addSerializer(new XssStringJsonSerializer());     objectMapper.registerModule(xssModule);     //返回     return objectMapper;   }  

###4.创建XssFilter

首先是拦截所有的请求,然后在doFilter方法中,将HttpServletRequest强制类型转换成XssHttpServletRequestWrapper

然后传递下去.

 /**  * XssFilter.java  * Created at 2016-09-19  * Created by wangkang  * Copyright (C) 2016 egridcloud.com, All rights reserved.  */ package com.egridcloud.udf.core.xss;  import java.io.IOException;  import javax.servlet.Filter; import javax.servlet.FilterChain; import javax.servlet.FilterConfig; import javax.servlet.ServletException; import javax.servlet.ServletRequest; import javax.servlet.ServletResponse; import javax.servlet.annotation.WebFilter; import javax.servlet.http.HttpServletRequest;  import org.slf4j.Logger; import org.slf4j.LoggerFactory;  /**  * 描述 : 跨站请求防范  *  * @author wangkang  *  */ @WebFilter(filterName = "xssFilter", urlPatterns = "/*", asyncSupported = true) public class XssFilter implements Filter {    /**    * 描述 : 日志    */   private static final Logger LOGGER = LoggerFactory.getLogger(XssFilter.class);    @Override   public void init(FilterConfig filterConfig) throws ServletException {     LOGGER.debug("(XssFilter) initialize");   }    @Override   public void doFilter(ServletRequest request, ServletResponse response, FilterChain chain)       throws IOException, ServletException {     XssHttpServletRequestWrapper xssRequest =         new XssHttpServletRequestWrapper((HttpServletRequest) request);     chain.doFilter(xssRequest, response);   }    @Override   public void destroy() {     LOGGER.debug("(XssFilter) destroy");   }  }  

##四.结束

本文虽基于spring boot实现主题,但是思路是一致的,不限于任何框架.

本文发表于2017年11月30日 22:33
(c)注:本文转载自https://my.oschina.net/u/3738405/blog/1582247,转载目的在于传递更多信息,并不代表本网赞同其观点和对其真实性负责。如有侵权行为,请联系我们,我们会及时删除.

阅读 1966 讨论 0 喜欢 0

抢先体验

扫码体验
趣味小程序
文字表情生成器

闪念胶囊

你要过得好哇,这样我才能恨你啊,你要是过得不好,我都不知道该恨你还是拥抱你啊。

直抵黄龙府,与诸君痛饮尔。

那时陪伴我的人啊,你们如今在何方。

不出意外的话,我们再也不会见了,祝你前程似锦。

这世界真好,吃野东西也要留出这条命来看看

快捷链接
网站地图
提交友链
Copyright © 2016 - 2021 Cion.
All Rights Reserved.
京ICP备2021004668号-1