xss¼ì²â¹¤¾ßÓÐÄÄЩ
xss ¼ì²â¹¤¾ß°üÀ¨ÔÚÏß¹¤¾ß£¨Èç xss ray¡¢hackbar¡¢websecurify xss scanner£©ºÍÍâµØ¹¤¾ß£¨Èç owasp zed attack proxy¡¢burp suite¡¢acunetix£©¡£Ñ¡Ôñ¹¤¾ßÈ¡¾öÓÚÐèÇó£¬ÔÚÏß¹¤¾ßÊʺϿìËÙɨÃ裬ÍâµØ¹¤¾ß¸üÇ¿Ê¢£¬ÆäËû¹¤¾ßÌṩÌض¨¹¦Ð§¡£
XSS ¼ì²â¹¤¾ß
XSS£¨¿çÕ¾¾ç±¾¹¥»÷£©ÊÇÒ»ÖÖ³£¼ûµÄÍøÂçÇå¾²Îó²î£¬ÔÊÐí¹¥»÷ÕßÔÚÊܺ¦ÕßµÄä¯ÀÀÆ÷ÖÐÖ´ÐÐí§Òâ¾ç±¾¡£ÎªÁ˼ì²âºÍ±ÜÃâ XSS ¹¥»÷£¬¿ÉÒÔʹÓÃÖÖÖÖ¹¤¾ß¡£
ÔÚÏß¹¤¾ß£º
XSS Ray£ºÒ»¿îÒ×ÓÚʹÓõÄÔÚÏß XSS ¼ì²â¹¤¾ß£¬¿Éͨ¹ýÔÚÏß±íµ¥»òץȡ URL ɨÃè¡£
HackBar£ºChrome ä¯ÀÀÆ÷µÄÀ©Õ¹³ÌÐò£¬Ìṩ XSS ¼ì²âºÍÔ¤·À¹¦Ð§¡£
Websecurify XSS Scanner£ºÒ»¿î¸ß¼¶ÔÚÏßɨÃèÆ÷£¬¿É¼ì²â¸ß¼¶ XSS Îó²î¡£
ÍâµØ¹¤¾ß£º
OWASP Zed Attack Proxy£¨ZAP£©£ºÒ»¿î¿ªÔ´µÄÉø͸²âÊÔ¹¤¾ß£¬¾ßÓÐ XSS ¼ì²â¹¦Ð§¡£
Burp Suite£ºÒ»¿îÉÌÒµÉø͸²âÊÔ¹¤¾ß£¬ÌṩǿʢµÄ XSS ¼ì²âÄ£¿é¡£
Acunetix£ºÒ»¿îÖÜÈ«µÄÍøÂçÇ徲ɨÃèÆ÷£¬°üÀ¨ XSS ¼ì²âÄÜÁ¦¡£
ÆäËû¹¤¾ß£º
XSS-Proxy£ºÒ»¿îÓÃÓÚ¼ì²âºÍÆÊÎö XSS ¹¥»÷µÄÖÐÐÄÈËÊðÀí¡£
NoScript£ºÒ»¿îä¯ÀÀÆ÷À©Õ¹³ÌÐò£¬¿É½ûÓÃδ¾ÐÅÍеľ籾£¬´Ó¶ø±ÜÃâ XSS ¹¥»÷¡£
HTMLPurifier£ºÒ»¿î PHP ¿â£¬¿ÉÕûÀíÓû§ÊäÈë²¢±ÜÃâ XSS Îó²î¡£
Ñ¡Ôñ¹¤¾ßµÄ½¨Ò飺
Ñ¡ÔñºÏÊ浀 XSS ¼ì²â¹¤¾ßÈ¡¾öÓÚÏêϸÐèÇó¡£
ÔÚÏß¹¤¾ßºÜÊÇÊʺϿìËÙɨÃèºÍÆðÔ´ÆÀ¹À¡£
ÍâµØ¹¤¾ß¸üÇ¿Ê¢£¬µ«ÐèҪװÖúÍÉèÖá£
ÆäËû¹¤¾ßÌṩÌض¨µÄ¹¦Ð§£¬ÀýÈçÊðÀí»ò¾ç±¾ÕûÀí¡£
ÒÔÉϾÍÊÇxss¼ì²â¹¤¾ßÓÐÄÄЩµÄÏêϸÄÚÈÝ£¬¸ü¶àÇë¹Ø×¢±¾ÍøÄÚÆäËüÏà¹ØÎÄÕ£¡