<ruby id="bdb3f"></ruby>

    <p id="bdb3f"><cite id="bdb3f"></cite></p>

      <p id="bdb3f"><cite id="bdb3f"><th id="bdb3f"></th></cite></p><p id="bdb3f"></p>
        <p id="bdb3f"><cite id="bdb3f"></cite></p>

          <pre id="bdb3f"></pre>
          <pre id="bdb3f"><del id="bdb3f"><thead id="bdb3f"></thead></del></pre>

          <ruby id="bdb3f"><mark id="bdb3f"></mark></ruby><ruby id="bdb3f"></ruby>
          <pre id="bdb3f"><pre id="bdb3f"><mark id="bdb3f"></mark></pre></pre><output id="bdb3f"></output><p id="bdb3f"></p><p id="bdb3f"></p>

          <pre id="bdb3f"><del id="bdb3f"><progress id="bdb3f"></progress></del></pre>

                <ruby id="bdb3f"></ruby>

                ThinkChat2.0新版上線,更智能更精彩,支持會話、畫圖、視頻、閱讀、搜索等,送10W Token,即刻開啟你的AI之旅 廣告
                # 特征 * 用戶親手操作 * 用戶不知情 * …… # 危害 * 盜取用戶資金(轉賬、消費) * 獲取用戶敏感信息 * …… # 原理 目標網站以透明的`iframe`的形式嵌入到攻擊網站中。 # 防御 ## Javascript 禁止內嵌 ```javascript // top:攻擊者文檔的window對象; // window:被嵌入的iframe文檔的window對象 if (top.location !== window.location) { top.location = window.location; } ``` 但這種辦法并不能完全防御,比如: ```html <!doctype html> <html> <head> <meta charset="utf-8"/> <title>csrf demo</title> </head> <body style="background:url(clickhijack.png) no-repeat"> <iframe style="opacity:0" src="http://localhost:1521/post/1" sandbox="allow-form" width="800" height="600"></iframe> </body> </html> ``` > 當`iframe`標簽中設置了sandbox屬性時,嵌入頁面`http://localhost:1521/post/1`中的腳本會被禁止運行,自然`top.location = window.location`這段防御腳本就沒用了。 > `sandbox="allow-form"`是說禁止包括腳本運行在內的很多功能,但是允許表單提交。 ## X-FRAME-OPTIONS 禁止內嵌 對某個網頁設置`http`頭`X-Frame-Options` > X-Frame-Options: DENY // 該網頁不允許被內嵌 > X-Frame-Options: SAMEORIGIN // 該網頁僅允許被同域名的網頁內嵌 > X-Frame-Options: ALLOW-FROM // 該網頁僅允許被指定的網頁內嵌 ## 其他輔助手段 比如:驗證碼
                  <ruby id="bdb3f"></ruby>

                  <p id="bdb3f"><cite id="bdb3f"></cite></p>

                    <p id="bdb3f"><cite id="bdb3f"><th id="bdb3f"></th></cite></p><p id="bdb3f"></p>
                      <p id="bdb3f"><cite id="bdb3f"></cite></p>

                        <pre id="bdb3f"></pre>
                        <pre id="bdb3f"><del id="bdb3f"><thead id="bdb3f"></thead></del></pre>

                        <ruby id="bdb3f"><mark id="bdb3f"></mark></ruby><ruby id="bdb3f"></ruby>
                        <pre id="bdb3f"><pre id="bdb3f"><mark id="bdb3f"></mark></pre></pre><output id="bdb3f"></output><p id="bdb3f"></p><p id="bdb3f"></p>

                        <pre id="bdb3f"><del id="bdb3f"><progress id="bdb3f"></progress></del></pre>

                              <ruby id="bdb3f"></ruby>

                              哎呀哎呀视频在线观看