duankeng1911 2015-02-03 21:58
浏览 28

防止ajax呼叫被劫持

I've run into this issue several times and have never come up with an elegant solution, so I'm hoping that I have just missed it in my hours of Googling.

Situation: I have an AJAX endpoint that submits data. The javascript is hosted/generated on my server (think Google Analytics). I have no way of validating said data, aside from checking that it's a valid email address syntactically. I want to prevent a script from calling the endpoint endlessly.

Attempted solutions / why they won't necessarily work:

  • Limit calls by IP / Can't always predict the total # of calls over a period of time, especially since IPs can be proxied and/or several people may be behind one IP

  • Generate tokens / Can literally be viewed in the source and simply scraped up before re-submitting

  • $_SERVER['HTTP_X_REQUESTED_WITH'] / Totally spoofable

I'm no security expert, but I know that this is a vulnerability that would easily skew data in an environment where some precision is needed.

  • 写回答

0条回答 默认 最新

    报告相同问题?

    悬赏问题

    • ¥15 不是,这到底错哪儿了😭
    • ¥15 2020长安杯与连接网探
    • ¥15 关于#matlab#的问题:在模糊控制器中选出线路信息,在simulink中根据线路信息生成速度时间目标曲线(初速度为20m/s,15秒后减为0的速度时间图像)我想问线路信息是什么
    • ¥15 banner广告展示设置多少时间不怎么会消耗用户价值
    • ¥16 mybatis的代理对象无法通过@Autowired装填
    • ¥15 可见光定位matlab仿真
    • ¥15 arduino 四自由度机械臂
    • ¥15 wordpress 产品图片 GIF 没法显示
    • ¥15 求三国群英传pl国战时间的修改方法
    • ¥15 matlab代码代写,需写出详细代码,代价私