能否通过IIS Request Filtering阻止ASP.Net登录表单的SQL注入攻击?
能否用IIS Request Filtering阻止ASP.NET登录表单的SQL注入?
首先直接给结论:可以,但你的当前配置没覆盖登录表单的POST字段扫描,这就是漏洞仍存在的核心原因。
你的现有规则只开启了scanQueryString="true",也就是仅扫描URL里的查询字符串,但登录页面的用户名/密码是通过POST请求的表单体提交的,完全不在规则的扫描范围内——这就是你用username' WAITFOR DELAY '0:0:10'--测试时没被拦截的关键问题。
调整IIS Request Filtering规则
要让规则覆盖POST表单字段,你需要在filteringRule元素里添加scanForm="true"属性,同时建议开启caseSensitive="false"避免大小写绕过,修改后的完整配置如下:
<requestFiltering> <filteringRules> <filteringRule name="SQLInjectionQuery" scanUrl="false" scanQueryString="true" scanForm="true" scanAllRaw="true" caseSensitive="false"> <appliesTo> <clear /> <add fileExtension=".aspx" /> </appliesTo> <denyStrings> <clear /> <add string="--" /> <add string=";" /> <add string="/*" /> <add string="@" /> <add string="char" /> <add string="alter" /> <add string="begin" /> <add string="cast" /> <add string="create" /> <add string="cursor" /> <add string="declare" /> <add string="delete" /> <add string="drop" /> <add string="end" /> <add string="exec" /> <add string="fetch" /> <add string="insert" /> <add string="kill" /> <add string="open" /> <add string="select" /> <add string="sys" /> <add string="table" /> <add string="update" /> <add string="waitfor" /> <add string="delay" /> </denyStrings> <scanHeaders> <clear /> </scanHeaders> </filteringRule> </filteringRules> </requestFiltering>
关键调整说明:
scanForm="true":告诉IIS扫描POST请求中的表单数据(这是你之前缺失的核心配置)caseSensitive="false":避免攻击者用WAITFOR(大写)绕过你配置的waitfor(小写)规则scanAllRaw="true":确保扫描原始请求内容,覆盖一些特殊编码的提交方式
更可靠的替代方案:URL Rewrite模块
虽然调整Request Filtering能缓解问题,但它的黑名单式字符串匹配容易被绕过(比如攻击者用编码、关键字变形等方式)。如果你有IIS URL Rewrite模块,建议用它创建更精准的规则,比如只针对登录页面的POST字段做正则匹配:
<rewrite> <rules> <rule name="Block SQL Injection in Login Form" stopProcessing="true"> <!-- 只匹配登录页面,替换成你的实际登录页URL --> <match url="^login\.aspx$" /> <conditions logicalGrouping="MatchAny"> <!-- 只针对POST请求 --> <add input="{REQUEST_METHOD}" pattern="POST" /> <!-- 检查username字段是否包含SQL注入关键字 --> <add input="{FORM:username}" pattern="(--|;|/\*|\*/|@|char|alter|begin|cast|create|cursor|declare|delete|drop|end|exec|fetch|insert|kill|open|select|sys|table|update|waitfor|delay)" ignoreCase="true" /> <!-- 检查password字段是否包含SQL注入关键字 --> <add input="{FORM:password}" pattern="(--|;|/\*|\*/|@|char|alter|begin|cast|create|cursor|declare|delete|drop|end|exec|fetch|insert|kill|open|select|sys|table|update|waitfor|delay)" ignoreCase="true" /> </conditions> <!-- 匹配到就终止请求 --> <action type="AbortRequest" /> </rule> </rules> </rewrite>
这个规则的优势是:只针对登录页面生效,避免影响其他功能;用正则匹配更灵活,还能指定检查特定表单字段。
长期最优解:Web应用防火墙(WAF)
如果你的系统允许,部署WAF是最可靠的方案。WAF(比如ModSecurity、Azure WAF等)有成熟的SQL注入防护规则库,能识别各种变形的注入攻击,甚至基于行为分析拦截异常请求,比自定义规则的防护能力强得多,非常适合无法修改源码的遗留系统。
内容的提问来源于stack exchange,提问作者John-Rock Bilodeau
相关产品推荐
相关产品推荐

