1. 程式人生 > 實用技巧 >XSS工具類,清除引數中的特殊字元

XSS工具類,清除引數中的特殊字元

package com.xss;

import java.util.regex.Pattern;


/**
 * XssUtil 工具類
 */
public class XssUtil {

    static Pattern scriptPattern = Pattern.compile("<script>(.*?)</script>", Pattern.CASE_INSENSITIVE);


    static Pattern scriptPatternSrc = Pattern.compile("src=\"(.*?)",Pattern.CASE_INSENSITIVE );

    
static Pattern scriptPatternHref = Pattern.compile("href=\"(.*?)",Pattern.CASE_INSENSITIVE ); static Pattern singleScriptPattern = scriptPattern = Pattern.compile("</script>", Pattern.CASE_INSENSITIVE); static Pattern singleBeginScriptPattern = Pattern.compile("<script(.*?)>", Pattern.CASE_INSENSITIVE
| Pattern.MULTILINE | Pattern.DOTALL); static Pattern singleBeginIframePattern = Pattern.compile("<iframe(.*?)>", Pattern.CASE_INSENSITIVE | Pattern.MULTILINE | Pattern.DOTALL); static Pattern criptPattern = Pattern.compile("eval\\((.*?)\\)", Pattern.CASE_INSENSITIVE
| Pattern.MULTILINE | Pattern.DOTALL); static Pattern expressionPattern = Pattern.compile("expression\\((.*?)\\)", Pattern.CASE_INSENSITIVE | Pattern.MULTILINE | Pattern.DOTALL); static Pattern javascriptPattern = Pattern.compile("javascript:", Pattern.CASE_INSENSITIVE); //alert static Pattern alertPattern = Pattern.compile("(.*?)alert(.*?)", Pattern.CASE_INSENSITIVE); static Pattern importPattern = Pattern.compile("(.*?)import(.*?)", Pattern.CASE_INSENSITIVE); static Pattern functionPattern = Pattern.compile("(.*?)function(.*?)", Pattern.CASE_INSENSITIVE); static Pattern vbscriptPattern = Pattern.compile("vbscript:", Pattern.CASE_INSENSITIVE); static Pattern onScriptPattern = Pattern.compile("on(.*?)=['|\"](.*?)['|\"]", Pattern.CASE_INSENSITIVE | Pattern.MULTILINE | Pattern.DOTALL); /** * 清理xss特殊字元 * @param value 過濾的字串 * @return: String */ public static String cleanXSS(String value) { if (value != null) { // 避免script 標籤 value = scriptPattern.matcher(value).replaceAll(""); // 避免src形式的表示式 value = scriptPatternSrc.matcher(value).replaceAll(""); // 避免href形式的表示式 value = scriptPatternHref.matcher(value).replaceAll(""); // 刪除單個的 </script> 標籤 value = singleScriptPattern.matcher(value).replaceAll(""); // 刪除單個的<script ...> 標籤 value = singleBeginScriptPattern.matcher(value).replaceAll(""); // 刪除單個的<iframe ...> 標籤 value = singleBeginIframePattern.matcher(value).replaceAll(""); // 避免 eval(...) 形式表示式 value = criptPattern.matcher(value).replaceAll(""); // 避免 e­xpression(...) 表示式 value = expressionPattern.matcher(value).replaceAll(""); // 避免 javascript: 表示式 value = javascriptPattern.matcher(value).replaceAll(""); value = alertPattern.matcher(value).replaceAll(""); value = importPattern.matcher(value).replaceAll(""); value = functionPattern.matcher(value).replaceAll(""); // 避免 vbscript: 表示式 value = vbscriptPattern.matcher(value).replaceAll(""); // 避免 onXX= 表示式 value = onScriptPattern.matcher(value).replaceAll(""); } return value; } }