gpt4 book ai didi

asp.net - 绕过路径遍历过滤器

转载 作者:行者123 更新时间:2023-12-02 16:47:49 25 4
gpt4 key购买 nike

在我的网络应用程序中,我删除了这些字符:

( < ,> ,: ," ,/ ,\ , | ,? ,* )

来 self 的文件下载网址以防止路径遍历。

有什么办法可以绕过这个吗?

安全吗?

最佳答案

查看以下指南:http://msdn.microsoft.com/en-us/library/ff647397.aspx但与您的问题相关的部分在下面突出显示。

If you must accept file names as input, use the full name of the file by using System.IO.Path.GetFileName.

如果您想进一步保护您的网站:

Using Code Access Security to Restrict File I/O An administrator can restrict an application's file I/O to its own virtual directory hierarchy by configuring the application to run with Medium trust. In this event, .NET code access security ensures that no file access is permitted outside of the application's virtual directory hierarchy.

You configure an application to run with Medium trust by setting the element in Web.config or Machine.config. <trust level="Medium" />

关于asp.net - 绕过路径遍历过滤器,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/19505485/

25 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com