V2EX = way to explore
V2EX 是一个关于分享和探索的地方
Sign Up Now
For Existing Member  Sign In
• 请不要在回答技术问题时复制粘贴 AI 生成的内容
hacker1031
V2EX  ›  程序员

如何预防邮件表头注入?

  •  
  •   hacker1031 · Nov 21, 2013 · 2959 views
    This topic created in 4546 days ago, the information mentioned may be changed or developed.
    想问的是,如何注入邮件表头,可使我们的程序更安全。

    要注入一个“To”表头到网站联系页面的邮箱输入文本框中,常用的注入方式是添加一个新行

    [email protected]%0D%0ATo:[email protected]

    但这样的结果如下

    From: <[email protected]%0D%0ATo:[email protected]>
    To: [email protected]
    Subject: ...

    不是想像中的

    From: <[email protected]>;
    To: [email protected]
    To: [email protected]
    Subject: ...

    想重现攻击效果,哪里有问题呢?
    1 replies    1970-01-01 08:00:00 +08:00
    krafttuc
        1
    krafttuc  
       Nov 23, 2013
    你的from从表单拿到后做了escape html处理?
    About   ·   Help   ·   Advertise   ·   Blog   ·   API   ·   FAQ   ·   Solana   ·   2369 Online   Highest 6679   ·     Select Language
    创意工作者们的社区
    World is powered by solitude
    VERSION: 3.9.8.5 · 41ms · UTC 01:40 · PVG 09:40 · LAX 18:40 · JFK 21:40
    ♥ Do have faith in what you're doing.