欢迎您访问 最编程 本站为您分享编程语言代码,编程技术文章!
您现在的位置是: 首页

Java: 消除字符串中的换行符与特殊字符,防范SQL注入问题

最编程 2024-07-22 16:45:55
...
package cn.kepu.filter; import java.io.IOException; import java.util.ArrayList; import java.util.Arrays; import java.util.List; import java.util.Map; import java.util.Set; import javax.servlet.Filter; import javax.servlet.FilterChain; import javax.servlet.FilterConfig; import javax.servlet.ServletException; import javax.servlet.ServletRequest; import javax.servlet.ServletResponse; import javax.servlet.http.HttpServletRequest; import javax.servlet.http.HttpServletResponse; /** * 防止sql注入,自定义filter * cn.kepu.filter.SqlInjectFilter.java * @author ffr * created at 2012-7-12 */ public class SqlInjectFilter implements Filter { private static List<String> invalidsql = new ArrayList<String>(); private static String error = "/error.jsp"; private static boolean debug = false; public void destroy() { } public void doFilter(ServletRequest req, ServletResponse res, FilterChain fc) throws IOException, ServletException { if(debug){ System.out.println("prevent sql inject filter works"); } HttpServletRequest request = (HttpServletRequest)req; HttpServletResponse response = (HttpServletResponse)res; Map<String, String> params = request.getParameterMap(); Set<String> keys = params.keySet(); for(String key : keys){ String value = request.getParameter(key); if(debug){ System.out.println("process params <key, value>: <"+key+", "+value+">"); } for(String word : invalidsql){ if(word.equalsIgnoreCase(value) || value.contains(word)){ if(value.contains("<")){ value = value.replace("<", "<"); } if(value.contains(">")){ value = value.replace(">", ">"); } request.getSession().setAttribute("sqlInjectError", "the request parameter \""+value+"\" contains keyword: \""+word+"\""); response.sendRedirect(request.getContextPath()+error); return; } } } fc.doFilter(req, res); } public void init(FilterConfig conf) throws ServletException { String sql = conf.getInitParameter("invalidsql"); String errorpage = conf.getInitParameter("error"); String de = conf.getInitParameter("debug"); if(errorpage != null){ error = errorpage; } if(sql != null){ invalidsql = Arrays.asList(sql.split(" ")); } if(de != null && Boolean.parseBoolean(de)){ debug = true; System.out.println("PreventSQLInject Filter staring..."); System.out.println("print filter details"); System.out.println("invalid words as fllows (split with blank):"); for(String s : invalidsql){ System.out.print(s+" "); } System.out.println(); System.out.println("error page as fllows"); System.out.println(error); System.out.println(); } } }

推荐阅读