JAVA实现XML攻击——过滤恶意脚本

  • Post author:
  • Post category:java


package test01;
import org.owasp.validator.html.AntiSamy;
import org.owasp.validator.html.Policy;

public class Demo1 {

	public static void main(String[] args) {
		// TODO Auto-generated method stub
		String temp="HelloWorld<img src='null' οnerrοr='alert(1234)'>";
		String path=Demo1.class.getResource("antisamy.xml").getPath().toString();
		try {
			Policy policy=Policy.getInstance(path);
			AntiSamy samy=new AntiSamy();
			String result=samy.scan(temp,policy).getCleanHTML();
			System.out.println(result);
		} catch(Exception e) {
			e.printStackTrace();
		}
	}
}



版权声明:本文为weixin_43303023原创文章,遵循 CC 4.0 BY-SA 版权协议,转载请附上原文出处链接和本声明。