我在配置CsrfGuard时遇到问题。我使用来自github的配置(在这里-> https://github.com/aramrami/OWASP-CSRFGuard/tree/d197506c122aefa09af807ac48e944d778bf624c/csrfguard-test)。
我尝试实现令牌同步器模式。
当我使用它时,我仍然警告:潜在的跨站点请求伪造(CSRF)攻击受阻(user :, ip:0:0:0:0:0:0:0:0:1,error:required token is missing from请求)。我了解出了什么问题,但我不知道如何将令牌添加到我的2个html文件中。
我不使用jsp,因为我的旧应用程序具有很多html文件,因此无法使用jsp。我在简单的登录项目上尝试
我不知道我在做什么错。

当我添加此:
<script src="/JavaScriptServlet"></script>
我在控制台中得到了这个:
Failed to load resource: the server responded with a status of 404 () JavaScriptServlet:1
当我将js文件复制到项目中时(路径:/WEB-INF/Owasp.CsrfGuard.js),我遇到了这样的变量问题:%DOMAIN_STRICT%。我知道该变量是从某个文件中检索的,但我不知道是哪个文件。
我不知道我在做什么错?我应该用Java编写一些代码还是不能在html中工作?

这是我在index.html中的代码(整个body标签):

<form method="POST" action="login">
    <label for="username">Username:</label>
    <input type="text" name="username" id="username">
    <label for="password">Password:</label>
    <input type="text" name="password" id="password">
    <button>Submit</button>
</form>
<script src="/JavaScriptServlet"></script>


这些都是属性(很少修改我的代码,也许是错误的):

org.owasp.csrfguard.Logger=org.owasp.csrfguard.log.JavaLogger
org.owasp.csrfguard.NewTokenLandingPage=
org.owasp.csrfguard.configuration.provider.factory = org.owasp.csrfguard.config.overlay.ConfigurationAutodetectProviderFactory
org.owasp.csrfguard.Enabled = true
org.owasp.csrfguard.ValidateWhenNoSessionExists = true
org.owasp.csrfguard.TokenPerPage=true
org.owasp.csrfguard.TokenPerPagePrecreate=true
org.owasp.csrfguard.Ajax=true
org.owasp.csrfguard.protected.Protected=/hello.html
org.owasp.csrfguard.unprotected.Index=%servletContext%/index.html
org.owasp.csrfguard.action.Log=org.owasp.csrfguard.action.Log
org.owasp.csrfguard.action.Log.Message=potential cross-site request forgery (CSRF) attack thwarted (user:%user%, ip:%remote_ip%, uri:%request_uri%, error:%exception_message%)
org.owasp.csrfguard.action.Redirect=org.owasp.csrfguard.action.Redirect
org.owasp.csrfguard.action.Redirect.Page=%servletContext%/error.html
org.owasp.csrfguard.action.Rotate=org.owasp.csrfguard.action.Rotate
org.owasp.csrfguard.TokenName=OWASP-CSRFTOKEN
org.owasp.csrfguard.PRNG=SHA1PRNG
org.owasp.csrfguard.PRNG.Provider=SUN
org.owasp.csrfguard.Config.Print = true
org.owasp.csrfguard.JavascriptServlet.sourceFile = /script/Owasp.CsrfGuard.js
org.owasp.csrfguard.JavascriptServlet.domainStrict = true
org.owasp.csrfguard.JavascriptServlet.cacheControl = private, maxage=28800
org.owasp.csrfguard.JavascriptServlet.refererPattern = .*
org.owasp.csrfguard.JavascriptServlet.refererMatchDomain = true
org.owasp.csrfguard.JavascriptServlet.injectIntoForms = true
org.owasp.csrfguard.JavascriptServlet.injectGetForms = false
org.owasp.csrfguard.JavascriptServlet.injectFormAttributes = true
org.owasp.csrfguard.JavascriptServlet.injectIntoAttributes = true
org.owasp.csrfguard.JavascriptServlet.xRequestedWith = OWASP CSRFGuard Project
org.owasp.csrfguard.configOverlay.hierarchy = classpath:Owasp.CsrfGuard.properties, classpath:Owasp.CsrfGuard.overlay.properties
org.owasp.csrfguard.configOverlay.secondsBetweenUpdateChecks = 60

最佳答案

您没有web.xml配置:

Failed to load resource: the server responded with a status of 404 ()   JavaScriptServlet:1


将此添加到web.xml:

  <servlet>
    <servlet-name>JavaScriptServlet</servlet-name>
    <servlet-class>org.owasp.csrfguard.servlet.JavaScriptServlet</servlet-class>
  </servlet>
  <servlet-mapping>
    <servlet-name>JavaScriptServlet</servlet-name>
    <url-pattern>/JavaScriptServlet</url-pattern>
  </servlet-mapping>


您可能没有所有CSRF Guard的web.xml配置。

<?xml version="1.0" encoding="UTF-8"?>
<web-app xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://java.sun.com/xml/ns/javaee" xmlns:web="http://java.sun.com/xml/ns/javaee/web-app_2_5.xsd" xsi:schemaLocation="http://java.sun.com/xml/ns/javaee http://java.sun.com/xml/ns/javaee/web-app_2_5.xsd" id="WebApp_ID" version="2.5">

  <context-param>
    <param-name>Owasp.CsrfGuard.Config</param-name>
    <param-value>csrfguard.properties</param-value>
  </context-param>

  <listener>
    <listener-class>org.owasp.csrfguard.CsrfGuardServletContextListener</listener-class>
  </listener>

  <listener>
    <listener-class>org.owasp.csrfguard.CsrfGuardHttpSessionListener</listener-class>
  </listener>

  <filter>
    <filter-name>CSRFGuardFilter</filter-name>
    <filter-class>org.owasp.csrfguard.CsrfGuardFilter</filter-class>
  </filter>

  <filter-mapping>
    <filter-name>CSRFGuardFilter</filter-name>
    <url-pattern>/hello.html</url-pattern>
  </filter-mapping>

  <servlet>
    <servlet-name>JavaScriptServlet</servlet-name>
    <servlet-class>org.owasp.csrfguard.servlet.JavaScriptServlet</servlet-class>
  </servlet>

  <servlet-mapping>
    <servlet-name>JavaScriptServlet</servlet-name>
    <url-pattern>/JavaScriptServlet</url-pattern>
  </servlet-mapping>

</web-app>


将项目添加到WEB-INF/classes文件csrfguard.propertiesWEB-INF/lib文件csrfguard.jar

添加到您的hello.html:

<script type="text/javascript" src="/JavaScriptServlet"></script>


示例csrfguard.properties

关于java - CsrfGuard出现问题。尽管从官方站点进行了配置,但csrf引发了问题,我们在Stack Overflow上找到一个类似的问题:https://stackoverflow.com/questions/57668708/

10-11 03:41