
using System;

using System.IO;

using System.Text;

using System.Text.RegularExpressions;

using System.Runtime.Remoting;

using System.Runtime.Remoting.Proxies;

using System.Runtime.Remoting.Messaging;

using System.Reflection;


namespace FilterRealProxy
{
/// <summary>
/// FilterRealProxy類:一個真實代理, 攔截它所代理對象中方法的傳回值,并對需要過濾的傳回值進行過濾。
/// </summary>
public class FilterRealProxy:RealProxy
{
private MarshalByRefObject target;
public FilterRealProxy(MarshalByRefObject target):base(target.GetType())
{
this.target=target;
}
public override IMessage Invoke(IMessage msg)
IMethodCallMessage callMsg=msg as IMethodCallMessage;
IMethodReturnMessage returnMsg = RemotingServices.ExecuteMessage(target,callMsg);
//檢查傳回值是否為String,如果不是String,就沒必要進行過濾
if(this.IsMatchType(returnMsg.ReturnValue))
{
string returnValue=this.Filter(returnMsg.ReturnValue.ToString(),returnMsg.MethodName);
return new ReturnMessage(returnValue,null,0,null,callMsg);
}
return returnMsg;
}
protected string Filter(string ReturnValue,string MethodName)
MethodInfo methodInfo=target.GetType().GetMethod(MethodName);
object[] attributes=methodInfo.GetCustomAttributes(typeof(StringFilter),true);
foreach (object attrib in attributes)
return FilterHandler.Process(((StringFilter)attrib).FilterType,ReturnValue);
return ReturnValue;
protected bool IsMatchType(object obj)
return obj is System.String;
}
///<summary>
/// StringFilter類:自定義屬性類, 定義目标元素的過濾類型
///</summary>
public class StringFilter:Attribute
protected FilterType _filterType;
public StringFilter(FilterType filterType)
this._filterType=filterType;
public FilterType FilterType
get
return _filterType;
/// 枚舉類:用于指定過濾類型,例如:對script過濾還是對html進行過濾?
[Flags()]
public enum FilterType
Script = 1,
Html =2,
Object=3,
AHrefScript=4,
Iframe=5,
Frameset=6,
Src=7,
BadWords=8,
//Include=9,
All=16
/// 過濾處理類:根據過濾類型,調用相應的過濾處理方法。
public class FilterHandler
private FilterHandler()
public static string Process(FilterType filterType,string filterContent)
switch(filterType)
case FilterType.Script:
filterContent=FilterScript(filterContent);
break;
case FilterType.Html:
filterContent=FilterHtml(filterContent);
case FilterType.Object:
filterContent=FilterObject(filterContent);
case FilterType.AHrefScript:
filterContent=FilterAHrefScript(filterContent);
case FilterType.Iframe:
filterContent=FilterIframe(filterContent);
case FilterType.Frameset:
filterContent=FilterFrameset(filterContent);
case FilterType.Src:
filterContent=FilterSrc(filterContent);
//case FilterType.Include:
// filterContent=FilterInclude(filterContent);
// break;
case FilterType.BadWords:
filterContent=FilterBadWords(filterContent);
case FilterType.All:
filterContent=FilterAll(filterContent);
default:
//do nothing
return filterContent;
public static string FilterScript(string content)
string commentPattern = @"(?'comment'<!--.*?--[ \n\r]*>)" ;
string embeddedScriptComments = @"(\/\*.*?\*\/|\/\/.*?[\n\r])" ;
string scriptPattern = String.Format(@"(?'script'<[ \n\r]*script[^>]*>(.*?{0}?)*<[ \n\r]*/script[^>]*>)", embeddedScriptComments ) ;
// 包含注釋和Script語句
string pattern = String.Format(@"(?s)({0}|{1})", commentPattern, scriptPattern) ;
return StripScriptAttributesFromTags(Regex.Replace(content,pattern,string.Empty,RegexOptions.IgnoreCase));
private static string StripScriptAttributesFromTags( string content )
string eventAttribs = @"on(blur|c(hange|lick)|dblclick|focus|keypress|(key|mouse)(down|up)|(un)?load
|mouse(move|o(ut|ver))|reset|s(elect|ubmit))" ;
string pattern = String.Format(@"(?inx)
\<(\w+)\s+
(
(?'attribute'
(?'attributeName'{0})\s*=\s*
(?'delim'['""]?)
(?'attributeValue'[^'"">]+)
(\3)
)
|
(?'attribute'
(?'attributeName'href)\s*=\s*
(?'attributeValue'javascript[^'"">]+)
[^>]
)*
\>", eventAttribs ) ;
Regex re = new Regex( pattern ) ;
// 使用MatchEvaluator的委托
return re.Replace( content, new MatchEvaluator( StripAttributesHandler ) ) ;
private static string StripAttributesHandler( Match m )
if( m.Groups["attribute"].Success )
return m.Value.Replace( m.Groups["attribute"].Value, "") ;
else
return m.Value ;
public static string FilterAHrefScript(string content)
string newstr=FilterScript(content);
string regexstr=@" href[ ^=]*= *[\s\S]*script *:";
return Regex.Replace(newstr,regexstr,string.Empty,RegexOptions.IgnoreCase);
public static string FilterSrc(string content)
string regexstr=@" src *= *['""]?[^\.]+\.(js|vbs|asp|aspx|php|jsp)['""]";
return Regex.Replace(newstr,regexstr,@"",RegexOptions.IgnoreCase);
/*
public static string FilterInclude(string content)
string regexstr=@"<[\s\S]*include *(file|virtual) *= *[\s\S]*\.(js|vbs|asp|aspx|php|jsp)[^>]*>";
*/
public static string FilterHtml(string content)
string regexstr=@"<[^>]*>";
public static string FilterObject(string content)
string regexstr=@"(?i)<Object([^>])*>(\w|\W)*</Object([^>])*>";
return Regex.Replace(content,regexstr,string.Empty,RegexOptions.IgnoreCase);
public static string FilterIframe(string content)
string regexstr=@"(?i)<Iframe([^>])*>(\w|\W)*</Iframe([^>])*>";
public static string FilterFrameset(string content)
string regexstr=@"(?i)<Frameset([^>])*>(\w|\W)*</Frameset([^>])*>";
//移除非法或不友好字元
private static string FilterBadWords(string chkStr)
//這裡的非法和不友好字元由你任意加,用“|”分隔,支援正規表達式,由于本Blog禁止貼非法和不友好字元,是以這裡無法加上。
string BadWords=@"
";
if (chkStr == "")
return "";
string[] bwords = BadWords.Split('#');
int i,j;
string str;
StringBuilder sb = new StringBuilder();
for(i = 0; i< bwords.Length; i++)
str=bwords[i].ToString().Trim();
string regStr,toStr;
regStr=str;
Regex r=new Regex(regStr,RegexOptions.IgnoreCase | RegexOptions.Singleline| RegexOptions.Multiline);
Match m=r.Match(chkStr);
if(m.Success)
{
j=m.Value.Length;
sb.Insert(0,"*",j);
toStr=sb.ToString();
chkStr=Regex.Replace(chkStr,regStr,toStr,RegexOptions.IgnoreCase | RegexOptions.Singleline| RegexOptions.Multiline);
}
sb.Remove(0,sb.Length);
return chkStr;
public static string FilterAll(string content)
content = FilterHtml(content);
content = FilterScript(content);
content = FilterAHrefScript(content);
content = FilterObject(content);
content = FilterIframe(content);
content = FilterFrameset(content);
content = FilterSrc(content);
content = FilterBadWords(content);
//content = FilterInclude(content);
return content;
}

本文轉自高海東部落格園部落格,原文連結:http://www.cnblogs.com/ghd258/archive/2006/03/21/354970.html,如需轉載請自行聯系原作者