本页内容

Qt Remote Objects 安全注意事项

概述

Qt Remote Objects 的目的是能够调用位于不同进程或不同主机上的对象的方法,就好像它们位于同一个进程中一样。然而,Qt Remote Objects 模块在设计时并未考虑安全性,也不提供对其他主机的身份验证。 该协议无法检测两个主机是否使用不同版本的共享对象,攻击者发送随机数据可能会导致程序行为异常或崩溃。由于所有主机对共享对象上的相同方法具有同等访问权限,因此单个主机可以通过高频率的方法调用和大量数据淹没其他主机。 因此,必须在受保护且与互联网隔离的可信环境中使用该模块。

警告:将 Qt Remote Objects 直接暴露 在互联网上会带来安全风险。Qt Remote Objects 未针对网络攻击进行加固。

如果需要通过互联网访问Qt Remote Objects 功能,请将Qt Remote Objects 节点隔离在经过加固的应用程序级网关之后,该网关仅暴露所需的特定操作。

© 2026 The Qt Company Ltd. Documentation contributions included herein are the copyrights of their respective owners. The documentation provided herein is licensed under the terms of the GNU Free Documentation License version 1.3 as published by the Free Software Foundation. Qt and respective logos are trademarks of The Qt Company Ltd. in Finland and/or other countries worldwide. All other trademarks are property of their respective owners.