php用appscan扫描后出现的全局验证安全问题应该怎么解决?
get edit_info.php?username=18511333333&gender=&birthday=1996-03-02 http/1.1
accept: application/x-ms-application, image/jpeg, application/xaml+xml, image/gif, image/pjpeg, application/x-ms-xbap, */*
accept-language: zh-cn
user-agent: mozilla/4.0 (compatible; msie 8.0; windows nt 6.1; win64; x64; trident/4.0; .net clr 2.0.50727; slcc2; .net clr 3.5.30729; .net clr 3.0.30729; media center pc 6.0; tablet pc 2.0)
connection: keep-alive
host: cqc.xunsmart.com
http/1.1 200 ok
connection: close
date: sat, 30 may 2015 16:44:31 gmt
server: microsoft-iis/6.0
x-powered-by: asp.net
x-powered-by: php/5.2.17
content-type: text/html
?{status:ok,msg:\u4fee\u6539\u6210\u529f!,data:[{uid:256,username:18511333333,password:25f9e794323b453885f5181f1b624d0b,myname:gan
------解决思路----------------------
看起来好像是请求这个地址返回了一些关于用户的关键信息(甚至包括密码)
------解决思路----------------------
不要轻信所谓专家危言耸听的结论,要对自己有信心
不要随意的在 url 中附加本不该公开的信息,尽可能的使用 post 或 put 方式传递数据