Common/SecurityHelper.cs

(开头部分) 24KB

这里只显示每个文件的开头 60 行。登录后可以解锁完整代码。

using System;
using System.Collections.Generic;
using System.IO;
using System.Linq;
using System.Security.Cryptography;
using System.Text;
using System.Text.RegularExpressions;
using System.Web;

namespace OPMS.Common
{
    /// <summary>
    /// 防止xss 攻击和Sql注入
    /// </summary>
    public class SecurityHelper
    {
        #region 加密
        private static readonly byte[] _aeskeys = new byte[] { 0x12, 0x34, 0x56, 120, 0x90, 0xab, 0xcd, 0xef, 0x12, 0x34, 0x56, 120, 0x90, 0xab, 0xcd, 0xef };
        private static Regex _base64regex = new Regex(@"[A-Za-z0-9\=\/\+]");
        private static Regex _sqlkeywordregex = new Regex(@"(select|insert|delete|from|count\(|drop|table|update|truncate|asc\(|mid\(|char\(|xp_cmdshell|exec|master|net|local|group|administrators|user|or|and|-|;|,|\(|\)|\[|\]|\{|\}|%|@|\*|!|\')", RegexOptions.IgnoreCase);

        public static string AESDecrypt(string decryptStr, string decryptKey)
        {
            if (string.IsNullOrWhiteSpace(decryptStr))
            {
                return string.Empty;
            }
            decryptKey = StringHelper.SubString(decryptKey, 0x20);
            decryptKey = decryptKey.PadRight(0x20, ' ');
            byte[] buffer = Convert.FromBase64String(decryptStr);
            SymmetricAlgorithm algorithm = Rijndael.Create();
            algorithm.Key = Encoding.UTF8.GetBytes(decryptKey);
            algorithm.IV = _aeskeys;
            byte[] buffer2 = new byte[buffer.Length];
            using (MemoryStream stream = new MemoryStream(buffer))
            {
                using (CryptoStream stream2 = new CryptoStream(stream, algorithm.CreateDecryptor(), CryptoStreamMode.Read))
                {
                    stream2.Read(buffer2, 0, buffer2.Length);
                    stream2.Close();
                    stream.Close();
                }
            }
            return Encoding.UTF8.GetString(buffer2).Replace("\0", "");
        }

        public static string AESEncrypt(string encryptStr, string encryptKey)
        {
            if (string.IsNullOrWhiteSpace(encryptStr))
            {
                return string.Empty;
            }
            encryptKey = StringHelper.SubString(encryptKey, 0x20);
            encryptKey = encryptKey.PadRight(0x20, ' ');
            SymmetricAlgorithm algorithm = Rijndael.Create();
            byte[] bytes = Encoding.UTF8.GetBytes(encryptStr);
            algorithm.Key = Encoding.UTF8.GetBytes(encryptKey);
            algorithm.IV = _aeskeys;
            byte[] inArray = null;
            using (MemoryStream stream = new MemoryStream())
后面还有 518 行代码,购买后查看完整代码

24 小时内免费解锁 3 个项目,之后 1 积分/个。 规则说明

AI 解读

登录后可用,每次 10 积分,解读结果公开显示在下面。

还没有人解读过这个文件。