ASP.NET MVC AJAX请求偶现返回混淆脚本而非Partial View求助
Troubleshooting AJAX Partial View Returning Obfuscated Eval Code in Load-Balanced ASP.NET MVC App
1. Check Load Balancing Session Consistency
Since your app runs on two load-balanced nodes, inconsistent session state across servers could trigger unexpected responses:
- Ensure sticky sessions are enabled on your load balancer. This keeps a user's requests tied to the same server for their session, avoiding state mismatches.
- If sticky sessions aren’t feasible, implement a distributed session store (e.g., SQL Server, Redis) so both servers share identical session data.
2. Rule Out Server Compromise or Malicious Code Injection
The obfuscated eval code is a critical warning sign—one or both servers may be compromised:
- Bypass the load balancer to send requests directly to each server node. Identify which node is returning the malicious response.
- Run full malware scans on both servers, and audit application files (views, controllers,
web.config) for unauthorized modifications. - Validate your deployment pipeline: check build artifacts and deployment scripts to ensure no malicious code is introduced during deployments.
3. Validate jQuery AJAX Request Configuration
Review your generic AJAX code for potential issues:
- Add
cache: falseto AJAX requests for dynamic partial views. Cached malicious responses can persist across requests. - Set
dataType: 'html'explicitly. If jQuery guesses the wrong data type, it may execute unexpected script content. - Check for global AJAX handlers (e.g.,
$.ajaxSetup(),$(document).ajaxComplete()) that might alter response content.
Example corrected AJAX snippet:
$.ajax({ url: '/Controller/Action', type: 'GET', dataType: 'html', cache: false, success: function(response) { $('#targetElement').html(response); }, error: function(xhr) { console.error('AJAX Error:', xhr.statusText); } });
4. Inspect Server-Side Response Logic
- Compare partial view files and controller actions on both server nodes to ensure they’re identical. A mismatched view or action on one node could return unexpected content.
- Check IIS settings on both servers: look for URL rewrite rules, custom modules, or output caching configurations that might inject or modify response content.
- Audit controller actions for server-specific conditional logic that could return different content based on the node it’s running on.
5. Verify SSL/TLS and Network Security
If using HTTPS:
- Confirm both servers have valid, uncompromised SSL certificates. Misconfigured certificates or man-in-the-middle attacks can lead to code injection.
- Ensure the load balancer properly terminates SSL and forwards requests securely to backend servers without modifying response content.
内容的提问来源于stack exchange,提问作者Abdul tayyeb shabbir
相关产品推荐
相关产品推荐

