You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ASP.Net C#中Body Parameters Accepted in Query漏洞修复求助

修复ViewGeneratedLicense.aspx的Body Parameters Accepted in Query漏洞

这个漏洞的核心问题是你的页面同时接受本该放在POST请求体中的参数通过URL查询字符串(Query String)传递,导致敏感参数可能被日志记录、劫持或诱导用户通过不安全的方式提交。以下是针对ASP.NET环境的具体修复实现:

1. 强制页面仅接受POST请求(优先推荐)

如果该页面的功能是提交或处理敏感数据(比如生成许可证),本身就应该只允许POST请求。

方式一:在页面后台代码中校验

打开ViewGeneratedLicense.aspx.cs,在Page_Load方法开头添加请求方法校验:

protected void Page_Load(object sender, EventArgs e)
{
    if (!Request.HttpMethod.Equals("POST", StringComparison.OrdinalIgnoreCase))
    {
        Response.StatusCode = 405; // 返回"方法不允许"状态码
        Response.StatusDescription = "Only POST requests are allowed";
        Response.End();
        return;
    }
    // 原有业务逻辑代码
}

方式二:通过Web.config全局配置

在项目的Web.config中添加位置节点限制该页面的请求方法:

<location path="ViewGeneratedLicense.aspx">
    <system.web>
        <authorization>
            <allow verbs="POST" users="*"/>
            <deny verbs="GET,HEAD,PUT,DELETE" users="*"/>
        </authorization>
    </system.web>
</location>

2. 仅从请求体读取敏感参数(兼容GET场景)

如果页面确实需要支持GET请求(比如展示许可证内容),必须确保所有敏感参数仅从Request.Form读取,禁止使用Request["参数名"](该方式会优先从Query String读取参数)。

修改原有参数读取代码:

// 错误写法:会从Query String或Form中读取参数
// string licenseKey = Request["LicenseKey"];

// 正确写法:仅从POST请求体读取
string licenseKey = Request.Form["LicenseKey"];
if (string.IsNullOrEmpty(licenseKey))
{
    Response.StatusCode = 400; // 参数缺失,返回错误
    Response.Write("Required parameters are missing");
    Response.End();
    return;
}

3. 拦截Query String中的敏感参数

如果无法完全禁用GET请求,需主动检查Query String中是否包含敏感参数,存在则直接拒绝请求:

protected void Page_Load(object sender, EventArgs e)
{
    // 定义需要保护的敏感参数列表
    var sensitiveParams = new List<string> { "LicenseKey", "UserId", "CustomerEmail" };
    
    foreach (var param in sensitiveParams)
    {
        if (!string.IsNullOrEmpty(Request.QueryString[param]))
        {
            Response.StatusCode = 400;
            Response.Write("Sensitive parameters cannot be passed in URL");
            Response.End();
            return;
        }
    }
    // 后续业务逻辑
}

额外加固建议

  • 启用HTTPS加密传输,避免URL或请求体中的参数被明文捕获
  • 配置服务器日志规则,禁止记录Query String中的敏感参数
  • 对敏感参数进行加密后再传输,即使在POST请求体中也增加一层保护

内容的提问来源于stack exchange,提问作者Yageshwaran Arumaikannan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.16 04:01:03