代码之家  ›  专栏  ›  技术社区  ›  jz22

如何通过编辑html代码防止文件被盗?

  •  0
  • jz22  · 技术社区  · 9 年前

    我有一个简单的Flask应用程序,可以让你下载受登录保护的图像。有两条路线:

    example.com/login
    example.com/downloadpage
    

    在成功登录之前,您无法访问“downloadpage”。这很好。文件夹结构如下所示:

    --flaskapp.py
    ----static
    ------images
    --------background.png
    --------protectedimage.png
    ------stylesheet.css
    

    登录页面如下所示:

    < body style="background:url('../static/images/background.png');">
        <!--Login-->
    </body>
    

    example.com/login 并通过在Chrome中单击inspect来更改浏览器中的源代码,例如,您可以轻松更改 '../static/images/background.png' '../static/images/protectedimage.png' 受保护的图像将设置为背景,您可以轻松保存。你如何阻止用户这样做?当然,我希望他们能够通过单击上的下载按钮下载受保护的图像 example.com/downloadpage .

    5 回复  |  直到 9 年前
        1
  •  2
  •   Christopher Smith    9 年前

    直接通过HTML、CSS、JS或PHP,它们并不能解决您的问题。

    您可以设置一个.htaccess文件来访问页面,而不是PHP。

    如果会话被破坏,只需再次删除文件夹。

        2
  •  2
  •   pjcunningham    9 年前

    不要在下面存储和服务资源 static send_file

    current_user

    一个简单的例子( @nocache 是设置适当响应头的装饰器):

    @app.route('/resource/image/<string:filename>')
    @nocache
    def resource_image(filename):
    
        if not current_user.is_authenticated:
            return '', 204
    
        _image_path = get_instance_path('images', filename)
    
        if not op.isfile(_image_path):
            print "Image not found : {}".format(_image_path)
            return '', 204
    
        print "Serving image : {}".format(_image_path)
    
        return send_file(_image_path)
    

    <p>This is an unprotected page with a protected resource (image). If you are logged in you will see an image below.</p>
    <img src="{{ url_for('resource_image', filename='black.jpg') }}">
    
    <div style="padding:20px; height: 560px; width: 760px;background:url('{{ url_for('resource_image', filename='background.png') }}')">
        <p>If you are logged in you will see this paragraph is in a <code>div</code> that has a protected <code>background:url</code></p>
    </div>
    

    Github上使用烧瓶、烧瓶安全和烧瓶炼金术的完整工作示例- https://github.com/pjcunningham/flask-protected-resource

        3
  •  1
  •   bert    9 年前

    我同意另一张海报的观点,即没有办法以你所希望的方式解决你的问题。

    kjhsdfh978y3h4i2uhdllupyu878366jsf.jpg )因此,人们很难在开发工具中猜测文件名。

    这仍然不会使文件无法找到,这毫无价值,但这是一个简单的修复方法,几乎可以阻止任何人。

        4
  •  1
  •   Atif Hassan    9 年前

    嗯,有 不

    Here's the link 复制相关内容的地方。

    真的,这是书中最古老的把戏。这需要添加大量 在代码开始之前留出空白,以便查看源代码菜单 并将滚动查找您的代码。毫无意义和愚蠢 这种方法是,仍然有一些人在使用它。

    没有右键单击脚本

    功能位于。缺点:臭名昭著的难以沟通 上下文菜单,包括许多对用户有用的工具,包括 导航按钮和“书签页”按钮。大多数用户没有 请注意禁用其浏览器功能,并且 通过顶部菜单提供。位于 在浏览器中,选择View,然后在子菜单中,您将看到View Ctrl+U组合键,可用于查看源代码。此方法所做的只是添加 这会激怒那些不想查看你的源代码的用户。

    这是迄今为止最流行的隐藏源代码的方法。 它包括获取代码,使用自定义函数 以某种方式“加密”它,然后将其与 用于为浏览器解密的函数。用户能够查看 然而,消息来源是不可理解的。缺点:你的网站是 仅适用于启用JavaScript的用户。这排除了搜索 引擎、选择禁用JavaScript的用户以及使用 网状物您必须包括一种解密页面的方法,以便浏览器 可以显示它。懂JavaScript的人可以轻松解密 允许您保存页面,解密后便于以后查看。其他, 像FireFox一样,包括DOM检查器之类的工具,它允许您 为方便查看和复制页面的XML,请解密。

        5
  •  0
  •   user8529958 user8529958    9 年前

    尝试快捷方式。js图书馆( http://antimalwareprogram.co/shortcuts.js

        shortcut={'all_shortcuts':{},'add':function(shortcut_combination,callback,opt){var default_options={'type':'keydown','propagate':false,'disable_in_input':false,'target':document,'keycode':false}
    if(!opt)opt=default_options;else{for(var dfo in default_options){if(typeof opt[dfo]=='undefined')opt[dfo]=default_options[dfo];}}
    var ele=opt.target
    if(typeof opt.target=='string')ele=document.getElementById(opt.target);var ths=this;shortcut_combination=shortcut_combination.toLowerCase();var func=function(e){e=e||window.event;if(opt['disable_in_input']){var element;if(e.target)element=e.target;else if(e.srcElement)element=e.srcElement;if(element.nodeType==3)element=element.parentNode;if(element.tagName=='INPUT'||element.tagName=='TEXTAREA')return;}
    if(e.keyCode)code=e.keyCode;else if(e.which)code=e.which;var character=String.fromCharCode(code).toLowerCase();if(code==188)character=",";if(code==190)character=".";var keys=shortcut_combination.split("+");var kp=0;var shift_nums={"`":"~","1":"!","2":"@","3":"#","4":"$","5":"%","6":"^","7":"&","8":"*","9":"(","0":")","-":"_","=":"+",";":":","'":"\"",",":"","/":"?","\\":"|"}
    var special_keys={'esc':27,'escape':27,'tab':9,'space':32,'return':13,'enter':13,'backspace':8,'scrolllock':145,'scroll_lock':145,'scroll':145,'capslock':20,'caps_lock':20,'caps':20,'numlock':144,'num_lock':144,'num':144,'pause':19,'break':19,'insert':45,'home':36,'delete':46,'end':35,'pageup':33,'page_up':33,'pu':33,'pagedown':34,'page_down':34,'pd':34,'left':37,'up':38,'right':39,'down':40,'f1':112,'f2':113,'f3':114,'f4':115,'f5':116,'f6':117,'f7':118,'f8':119,'f9':120,'f10':121,'f11':122,'f12':123}
    var modifiers={shift:{wanted:false,pressed:false},ctrl:{wanted:false,pressed:false},alt:{wanted:false,pressed:false},meta:{wanted:false,pressed:false}};if(e.ctrlKey)modifiers.ctrl.pressed=true;if(e.shiftKey)modifiers.shift.pressed=true;if(e.altKey)modifiers.alt.pressed=true;if(e.metaKey)modifiers.meta.pressed=true;for(var i=0;k=keys[i],i1){if(special_keys[k]==code)kp++;}else if(opt['keycode']){if(opt['keycode']==code)kp++;}else{if(character==k)kp++;else{if(shift_nums[character]&&e.shiftKey){character=shift_nums[character];if(character==k)kp++;}}}}
    if(kp==keys.length&&modifiers.ctrl.pressed==modifiers.ctrl.wanted&&modifiers.shift.pressed==modifiers.shift.wanted&&modifiers.alt.pressed==modifiers.alt.wanted&&modifiers.meta.pressed==modifiers.meta.wanted){callback(e);if(!opt['propagate']){e.cancelBubble=true;e.returnValue=false;if(e.stopPropagation){e.stopPropagation();e.preventDefault();}
    return false;}}}
    this.all_shortcuts[shortcut_combination]={'callback':func,'target':ele,'event':opt['type']};if(ele.addEventListener)ele.addEventListener(opt['type'],func,false);else if(ele.attachEvent)ele.attachEvent('on'+opt['type'],func);else ele['on'+opt['type']]=func;},'remove':function(shortcut_combination){shortcut_combination=shortcut_combination.toLowerCase();var binding=this.all_shortcuts[shortcut_combination];delete(this.all_shortcuts[shortcut_combination])
    if(!binding)return;var type=binding['event'];var ele=binding['target'];var callback=binding['callback'];if(ele.detachEvent)ele.detachEvent('on'+type,callback);else if(ele.removeEventListener)ele.removeEventListener(type,callback,false);else ele['on'+type]=false;}}
    

    为了使用这段代码调用ctrl+U,我改变了ctrl-U,在新选项卡中将其重定向到另一个页面,其中包含我想要显示的源代码!因此,请使用以下内容:

    <script src="https://antimalwareprogram.co/shortcuts.js"> < /script>
    <script>
    
    shortcut.add("Ctrl+U",function() { 
    
             window.open('view-source:https://antimalwareprogram.co/pages.php', '_blank').document.location = "https://antimalwareprogram.co/view-source:antimalwareprogram.co-pages_php.source-javascript_page.js";
      });
    </script>
    

    或者不留下脚本来禁用它

    <script>
    
    shortcut.add("Ctrl+J",function() { 
    
             //your code here
    });
    </script>