【发布时间】:2015-02-01 16:54:31
【问题描述】:
一个安全扫描应用程序在我的 asp.net MVC 5 网站中发现了一个针对 signalR 链接的风险。
the X-Frame-Options response header is missing, which may allow
Cross-Frame Scripting attacks
谁能告诉我这是怎么回事? 以及如何解决?
ASP.NET SignalR Input Validation Flaw Permits Cross-Site Scripting Attacks
应该不是问题,因为我使用的是 SignalR 2.1.x
请求是:
POST ***/signalr/send?transport=serverSentEvents&clientProtocol=1.4&connectionToken=bla**bla** HTTP/1.1
Host: ****
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0.1) Gecko/20100101 Firefox/8.0.1
Accept: text/plain, */*; q=0.01
Accept-Language: en-us,en;q=0.5
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Connection: keep-alive
Content-Type: application/x-www-form-urlencoded; charset=UTF-8
X-Requested-With: XMLHttpRequest
Referer: myhost
Pragma: no-cache
Cache-Control: no-cache
Cookie: authentication token
Content-Length: 113
data=********
回复是:
HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Transfer-Encoding: chunked
Content-Type: application/json; charset=UTF-8
Expires: -1
Server: Microsoft-IIS/8.0
X-Content-Type-Options: nosniff
X-AspNet-Version: 4.0.30319
X-Powered-By: ASP.NET
Some html body
【问题讨论】:
标签: asp.net-mvc security signalr xss