一、XSS的原理分析與解剖.net
http://netsecurity.51cto.com/art/201408/448305_all.htmhtm
二、Java實現XSS防護blog
http://blog.csdn.net/shuaicihai/article/details/76099805ci