一、什么是验证码
验证码(CAPTCHA)是“Completely Automated Public Turing test to tell Computers and Humans Apart”(全自动区分计算机和人类的图灵测试)的缩写,是一种区分用户是计算机还是人的公共全自动程序。
二、验证码的作用
可以防止:恶意破解密码、刷票、论坛灌水,有效防止某个黑客对某一个特定注册用户用特定程序暴力破解方式进行不断的登陆尝试,实际上用验证码是现在很多网站通行的方式,我们利用比较简易的方式实现了这个功能。这个问题可以由计算机生成并评判,但是必须只有人类才能解答。由于计算机无法解答CAPTCHA的问题,所以回答出问题的用户就可以被认为是人类。
三、验证码示例(一个简单的验证码):
loginOne.JSP
<title>Insert title here</title>
<script type="text/javascript">
function reload(){
//alert("....");
document.getElementById("image").src="<%=request.getContextPath() %>/imageServlet.do?date="+new Date().getTime();
}
</script>
</head>
<body>
<form action="login.do" method="post">
用户名:<input type="text" name="uname"/><br/>
密 码:<input type="password" name="upass"/><br/>
验证码:<input type="text" name="validateCode"/><br/>
<img src="imageServlet.do" id="image"> <a href="javascript:reload();">换一张</a><br/>
<input type="submit" value="提交"/>
</form>
</body>
web.xml
<display-name>Web_22</display-name>
<servlet>
<servlet-name>LOGINSERVLET</servlet-name>
<servlet-class>com.sun.servlet.LoginServlet</servlet-class>
</servlet>
<servlet>
<servlet-name>IMAGESERVLET</servlet-name>
<servlet-class>com.sun.servlet.ImageServlet</servlet-class>
</servlet>
<servlet-mapping>
<servlet-name>LOGINSERVLET</servlet-name>
<url-pattern>/login.do</url-pattern>
</servlet-mapping>
<servlet-mapping>
<servlet-name>IMAGESERVLET</servlet-name>
<url-pattern>/imageServlet.do</url-pattern>
</servlet-mapping>
package com.sun.servlet;
import java.awt.Color;
import java.awt.Font;
import java.awt.Graphics;
import java.awt.image.BufferedImage;
import java.io.IOException;
import java.util.Random;
import javax.imageio.ImageIO;
import javax.servlet.ServletException;
import javax.servlet.ServletOutputStream;
import javax.servlet.http.HttpServlet;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;
public class ImageServlet extends HttpServlet{
//定义图片的大小
//宽
private int width=100;
//高
private int height=30;
//定义一个随机数组
private String date[]={"A","B","C","D","E","F","G","H","I","J",
"K","L","M","N","O","P","Q","R","S","T","U","V","W","X","Y","Z","0","1",
"2","3","4","5","6","7","8","9","a","b","c","d","e","f","g","h","i","j"
,"k","l","m","n","o","p","q","r","s","t","u","v","w","x","y","z"};
Random random=new Random();
@Override
protected void doGet(HttpServletRequest req, HttpServletResponse resp) throws ServletException, IOException {
//1、画图(图片)
//1.1画布
BufferedImage bufferedImage=new BufferedImage(width, height, BufferedImage.TYPE_INT_BGR);
//1.2画笔
Graphics graphics=bufferedImage.getGraphics();
//1.2.1设置画笔颜色
graphics.setColor(Color.pink);
//1.2.2设置画布的颜色
graphics.fillRect(0, 0, width, height);
//2、随机数
StringBuffer stringBuffer=new StringBuffer();
for (int i = 0; i < 4; i++) {
//随机date[]中的下标
int index=random.nextInt(date.length);
String str=date[index];
stringBuffer.append(str+" ");
}
//2.1将随机数存到session中去
req.getSession().setAttribute("code", stringBuffer.toString().replace(" ", ""));
//3、将随机数添加至图片上
//3.1再次设置画笔颜色(设置随机数颜色)
graphics.setColor(Color.white);
//3.2设置字体
graphics.setFont(new Font("宋体",Font.BOLD, 20));
//3.3给画布增加干扰线
//3.3.1设置干扰点
for (int i = 0; i < 200; i++) {
//3.3.1.1起始坐标
int x=random.nextInt(100);
int y=random.nextInt(30);
//3.3.1.2最终坐标就是上面的坐标(所以才是点)
graphics.drawLine(x, y, x, y);
}
//3.3.2设置干扰线
for (int i = 0; i < 10; i++) {
//3.3.2.1起始坐标
int x=random.nextInt(100);
int y=random.nextInt(30);
//3.3.2.2最终坐标
int xx=random.nextInt(100);
int yy=random.nextInt(30);
graphics.drawLine(x, y, xx, yy);
}
//3.4画到图片上
graphics.drawString(stringBuffer.toString(), 10, 20);
//4.将生成的图片放到页面上
ServletOutputStream sos=resp.getOutputStream();
ImageIO.write(bufferedImage, "gif", sos);
}
}
package com.sun.servlet;
import java.io.IOException;
import javax.servlet.ServletException;
import javax.servlet.http.HttpServlet;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;
public class LoginServlet extends HttpServlet{
@Override
protected void doPost(HttpServletRequest req, HttpServletResponse resp) throws ServletException, IOException {
String result=null;
//1.拿到用户输入的验证码
String validateCodefromUser=req.getParameter("validateCode");
//2.拿到图片上的验证码
String codefromServlet=req.getSession().getAttribute("code").toString();
//3.进行匹配(校验)
if(codefromServlet.equals(validateCodefromUser)){
//3.1成功(跳转到成功页面)
result="index.jsp";
}else{
//3.2失败(到本页面)
result="loginOne.jsp";
}
req.getRequestDispatcher(result).forward(req, resp);
}
}