ÓÃÓÚ·ÀÖ¹sql×¢Èë¹¥»÷ - .NET¼¼Êõ / ASP.NET
ÓÃÓÚ·ÀÖ¹sql×¢Èë¹¥»÷µÄ
¡¶Ò»¡·
function ForSqlForm()
dim fqys,errc,i,items
dim nothis(18)
nothis(0)="net user"
nothis(1)="xp_cmdshell"
nothis(2)="/add"
nothis(3)="exec%20master.dbo.xp_cmdshell"
nothis(4)="net localgroup administrators"
nothis(5)="select"
nothis(6)="count"
nothis(7)="asc"
nothis(8)="char"
nothis(9)="mid"
nothis(10)="'"
nothis(11)=":"
nothis(12)=""""
nothis(13)="insert"
nothis(14)="delete"
nothis(15)="drop"
nothis(16)="truncate"
nothis(17)="from"
nothis(18)="%"
'nothis(19)="@"
errc=false
for i= 0 to ubound(nothis)
for each items in request.Form
if instr(request.Form(items),nothis(i))<>0 then
response.write("<div>")
response.write("ÄãËùÌîдµÄÐÅÏ¢:" & server.HTMLEncode(request.Form(items)) & "<br>º¬·Ç·¨×Ö·û:" & nothis(i))
response.write("</div>")
response.write("¶Ô²»Æð,ÄãËùÌîдµÄÐÅÏ¢º¬·Ç·¨×Ö·û£¡<a href=""
Ïà¹ØÎÊ´ð£º
¿ÉÄÜÒòΪ¹¤×÷µÄÔÒò ½Ó´¥Êý¾Ý¿âÕâ¿é±È½ÏÉÙ£¬Ö®Ç°¶¼ÊÇ×ö³ÌÐòÕâ¿é£¬Êý¾Ý¿âÕâ¿é¶¼ÓÐרÃŵÄÈËÀ´×ö ·Ö¹¤¶¼ºÜÃ÷ϸ ËùÒÔ¶ÔÊý¾Ý¿âÕâÒ»¿éÍêÈ«²»Á˽⡣ǰ¶Îʱ¼ä È¥ÃæÊÔÁ˼¸¼Ò¹«Ë¾ ¼¸ºõ¶¼ÊÇÔÚÊý¾Ý¿âÕâ¿é¹ÒµôµÄ Á¬¸ö¼òµ¥µÄSQ ......
±¾ÈËÊDzËÄñÒ»¸ö£¬Æ½Ê±Òª×öÉúÒ⣬µ«ÊÇÕÒÁ˺ܶàÈË×öÍøÕ¾£¬¾ù±»ÆÁË¡£×öµÃ²»Èý²»ËÄ£¬ÏÖÔÚ¾öÐÄ×Ô¼ºÀ´×öÒ»¸ö£¬ÒÑѧϰASP.NETÏà¹ØµÄÍøÒ³ÖÆ×÷֪ʶ£¬ÓÐDW»ù´¡£¬¿ÉÒÔ˵ÊÇĿǰֻÓÐÀíÂÛ֪ʶ£¬µ«ÊÇÔÚʵ¼Ê¾ßÌå²Ù×÷µÄʱºò£¬×ÜÊÇÓöµ ......
1.asp.net×öµÄÒ»¸ö´ðÌâÒ³Ãæ£¬ÈçºÎʵʱÏÞʱºó×Ô¶¯Ìá½»£¬Çë´ó¼Ò¸øµã˼·
ÏÞʱµÄʱ¼äÐÅÏ¢´æ·ÅÔÚÊý¾Ý¿âÖÐ
2.Èç¹û´ðÌâʱ¼äÉèÖõĽϳ¤£¬ÈçºÎ·½Ê½session³¬Ê±ºóÒ³ÃæÎÞЧ
лл
ÓÃjs·½·¨À´¿ØÖÆ
»Ø¸´ÄÚÈÝÌ«¶ÌÁË¡£¡£
js ......
¸÷λ´óÏÀ£¬ÎÒѧϰµÄÊÇASP.NET£¬ÏëÖªµÀÏà¹Ø¼¼ÊõÓÐÄÄЩ£¬¾ÍÏñJAVA EEÖÐÓÐstruct sping jsp severlet µÈ£¬ASP.NET»¹ÓÐÄÄЩЩÏà¹Ø¼¼Êõ¡£
http://topic.csdn.net/u/20090914/21/af27de99-f0f3-4cfd-9379-13764f8ec6b1.ht ......