Common/SecurityHelper.cs
(开头部分) 24KB这里只显示每个文件的开头 60 行。登录后可以解锁完整代码。
using System;
using System.Collections.Generic;
using System.IO;
using System.Linq;
using System.Security.Cryptography;
using System.Text;
using System.Text.RegularExpressions;
using System.Web;
namespace OPMS.Common
{
/// <summary>
/// 防止xss 攻击和Sql注入
/// </summary>
public class SecurityHelper
{
#region 加密
private static readonly byte[] _aeskeys = new byte[] { 0x12, 0x34, 0x56, 120, 0x90, 0xab, 0xcd, 0xef, 0x12, 0x34, 0x56, 120, 0x90, 0xab, 0xcd, 0xef };
private static Regex _base64regex = new Regex(@"[A-Za-z0-9\=\/\+]");
private static Regex _sqlkeywordregex = new Regex(@"(select|insert|delete|from|count\(|drop|table|update|truncate|asc\(|mid\(|char\(|xp_cmdshell|exec|master|net|local|group|administrators|user|or|and|-|;|,|\(|\)|\[|\]|\{|\}|%|@|\*|!|\')", RegexOptions.IgnoreCase);
public static string AESDecrypt(string decryptStr, string decryptKey)
{
if (string.IsNullOrWhiteSpace(decryptStr))
{
return string.Empty;
}
decryptKey = StringHelper.SubString(decryptKey, 0x20);
decryptKey = decryptKey.PadRight(0x20, ' ');
byte[] buffer = Convert.FromBase64String(decryptStr);
SymmetricAlgorithm algorithm = Rijndael.Create();
algorithm.Key = Encoding.UTF8.GetBytes(decryptKey);
algorithm.IV = _aeskeys;
byte[] buffer2 = new byte[buffer.Length];
using (MemoryStream stream = new MemoryStream(buffer))
{
using (CryptoStream stream2 = new CryptoStream(stream, algorithm.CreateDecryptor(), CryptoStreamMode.Read))
{
stream2.Read(buffer2, 0, buffer2.Length);
stream2.Close();
stream.Close();
}
}
return Encoding.UTF8.GetString(buffer2).Replace("\0", "");
}
public static string AESEncrypt(string encryptStr, string encryptKey)
{
if (string.IsNullOrWhiteSpace(encryptStr))
{
return string.Empty;
}
encryptKey = StringHelper.SubString(encryptKey, 0x20);
encryptKey = encryptKey.PadRight(0x20, ' ');
SymmetricAlgorithm algorithm = Rijndael.Create();
byte[] bytes = Encoding.UTF8.GetBytes(encryptStr);
algorithm.Key = Encoding.UTF8.GetBytes(encryptKey);
algorithm.IV = _aeskeys;
byte[] inArray = null;
using (MemoryStream stream = new MemoryStream())
后面还有 518 行代码,购买后查看完整代码
24 小时内免费解锁 3 个项目,之后 1 积分/个。 规则说明
AI 解读
登录后可用,每次 10 积分,解读结果公开显示在下面。
还没有人解读过这个文件。
