2018-05-08 16:08:19 2253次浏览 1条回答 0 悬赏 20 金钱

用的是YII2自身生成的标准的登录模块。问题在哪儿
监测工具监测结果如下

Attack details
URL encoded POST input LoginForm%5bpassword%5d was set to login-button='"()&%<acx><ScRiPt >prompt(964753)</ScRiPt>

 View HTTP headers 
Request
POST /hengtai/backend/web/site/login HTTP/1.1
Content-Length: 236
Content-Type: application/x-www-form-urlencoded
Referer: http://localhost:80/hengtai/backend/web/site/login
Cookie: ht=97j58lmjliajndpuhtn4mc9s95
Host: localhost
Connection: Keep-alive
Accept-Encoding: gzip,deflate
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36
Accept: */*

login-button=&LoginForm%5bpassword%5d=login-button%3d'%22()%26%25<acx><ScRiPt%20>prompt(964753)</ScRiPt>&LoginForm%5brememberMe%5d=0&LoginForm%5brememberMe%5d=1&LoginForm%5busername%5d=hdchpnvr&LoginForm%5bverifyCode%5d=g00dPa%24%24w0rDResponse
HTTP/1.1 500 Internal Server Error
Date: Tue, 08 May 2018 07:45:38 GMT
Server: Apache/2.4.23 (Win32) OpenSSL/1.0.2j mod_fcgid/2.3.9
X-Powered-By: PHP/7.0.12
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate
Pragma: no-cache
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 93299
  • 回答于 2018-05-09 14:00 举报

    是不是关闭了csrf验证?

    1 条回复
    回复于 2018-05-09 15:58 回复

    没有,登录页面抛出异常,就是报错。然后出现弹出框

您需要登录后才可以回答。登录 | 立即注册
WGTwgt
主管

WGTwgt

注册时间:2017-07-29
最后登录:2018-08-16
在线时长:5小时6分
  • 粉丝0
  • 金钱555
  • 威望0
  • 积分605

热门问题