douwo8140 2016-03-21 06:22
浏览 59
已采纳

为什么我在我的网站上获得这些超链接? 安全漏洞?

In the image below is where I recently found these malicious hyperlinks.

I tried to log into my web-host and I couldn't find any hyperlinks attached to the elements in my files.

enter image description here

My Questions:

  1. How do I avoid these?
  2. How can I remove them?
  3. Despite these hyperlinks, Is my website vulnerable to any XSS attacks? If yes, please specify the holes i should fill.

I am using Ajax to send an instant response if the email already exists or not; Would this influence the attacker to easily send XMLHTTPRequests to the server?

I just want to make my website 100% safe as in a matter of none would ever get into the database ( confidentiality, integrity, and availability ) considering I have SSL certificate over HTTPS. Even if it's only login system website without many complicated input stuff.

I heard using SQL stored procedures help, also HTML encoding.

Please visit the website and take a look over the code www.tarsh.tk

Any Help/Hints/Tips/Links would be appreciated.

  • 写回答

1条回答 默认 最新

  • dongwen6743 2016-03-21 06:31
    关注

    The site at www.tarsh.tk does not have any hyperlinks for me see http://picpaste.com/Screen_Shot_2016-03-20_at_11.29.02_PM-F7OsKLUZ.png.

    Maybe it isn't the site and it is your browser. Have you tried a different browser?

    I used Chrome 49 and Safari 9, both are rendering the site without hyperlinks.

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论

报告相同问题?

悬赏问题

  • ¥15 (希望可以解决问题)ma和mb文件无法正常打开,打开后是空白,但是有正常内存占用,但可以在打开Maya应用程序后打开场景ma和mb格式。
  • ¥20 ML307A在使用AT命令连接EMQX平台的MQTT时被拒绝
  • ¥20 腾讯企业邮箱邮件可以恢复么
  • ¥15 有人知道怎么将自己的迁移策略布到edgecloudsim上使用吗?
  • ¥15 错误 LNK2001 无法解析的外部符号
  • ¥50 安装pyaudiokits失败
  • ¥15 计组这些题应该咋做呀
  • ¥60 更换迈创SOL6M4AE卡的时候,驱动要重新装才能使用,怎么解决?
  • ¥15 让node服务器有自动加载文件的功能
  • ¥15 jmeter脚本回放有的是对的有的是错的