ÏÖÔÚÔ½À´Ô½¶àµÄ³ÌÐòԱʹÓÃB/SģʽÀ´±àд³ÌÐò¡£µ«ÊÇÓÉÓÚ³ÌÐòÔ±µÄˮƽ¼°¾Ñé²»½üÏàͬ£¬ËùÒÔÏ൱´óÒ»²¿·Ö³ÌÐòÔ±ÔÚ±àд´úÂëµÄʱºò£¬Ã»ÓжÔÓû§ÊäÈëÊý¾ÝµÄºÏ·¨ÐÔ½øÐÐÅжϣ¬Ê¹µÃÓ¦ÓóÌÐò´æÔÚ°²È«Òþ»¼¡£Óû§¿ÉÒÔÌá½»Ò»¶ÎÊý¾Ý¿â²éѯ´úÂ룬¸ù¾Ý³ÌÐò·µ»ØµÄ½á¹û£¬»ñµÃijЩËûÏëµÃÖªµÄÊý¾Ý£¬Õâ¾ÍÊÇËùνµÄSQL Injection£¬¼´SQL×¢Èë¡£
SQL×¢ÈëÊÇ´ÓÕý³£µÄWWW¶Ë¿Ú·ÃÎÊ£¬¶øÇÒ±íÃæ¿´ÆðÀ´¸úÒ»°ãµÄWebÒ³Ãæ·ÃÎÊÃ»Ê²Ã´Çø±ð£¬ËùÒÔĿǰÊÐÃæµÄ·À»ðǽ¶¼²»»á¶ÔSQL×¢Èë·¢³ö¾¯±¨£¬Èç¹û¹ÜÀíԱû²é¿´IISÈÕÖ¾µÄϰ¹ß£¬¿ÉÄܱ»ÈëÇֺܳ¤Ê±¼ä¶¼²»»á·¢¾õ¡£
µ«ÊÇ£¬SQL×¢ÈëµÄÊÖ·¨Ï൱Áé»î£¬ÔÚ×¢ÈëµÄʱºò»áÅöµ½ºÜ¶àÒâÍâµÄÇé¿ö¡£Äܲ»Äܸù¾Ý¾ßÌåÇé¿ö½øÐзÖÎö£¬¹¹ÔìÇÉÃîµÄSQLÓï¾ä£¬´Ó¶ø³É¹¦»ñÈ¡ÏëÒªµÄÊý¾Ý£¬ÊǸßÊÖÓ듲ËÄñ”µÄ¸ù±¾Çø±ð¡£
¸ù¾Ý¹úÇ飬¹úÄÚµÄÍøÕ¾ÓÃASP+Access»òSQLServerµÄÕ¼70%ÒÔÉÏ£¬PHP+MySQÕ¼L20%£¬ÆäËûµÄ²»×ã10%¡£ÔÚ±¾ÎÄ£¬ÎÒÃÇ´Ó·ÖÈëÃÅ¡¢½ø½×ÖÁ¸ß¼¶½²½âÒ»ÏÂASP×¢ÈëµÄ·½·¨¼°¼¼ÇÉ£¬PHP×¢ÈëµÄÎÄÕÂÓÉNBÁªÃ˵ÄÁíһλÅóÓÑzwell׫д£¬Ï£Íû¶Ô°²È«¹¤×÷ÕߺͳÌÐòÔ±¶¼ÓÐÓô¦¡£Á˽âASP×¢ÈëµÄÅóÓÑÒ²Çë²»ÒªÌø¹ýÈëÃÅÆª£¬ÒòΪ²¿·ÖÈ˶Ô×¢ÈëµÄ»ù±¾ÅжϷ½·¨»¹´æÔÚÎóÇø¡£´ó¼Ò×¼±¸ºÃÁËÂð£¿Let's Go...
......
¾³£½øÐвéѯ£¬Ð´×Åselect * from Ì«·Ñʱ¼ä£¬Äܲ»ÄÜÖ±½ÓÊäÈëÒ»¸ös ¾ÍÄÜ×Ô¶¯³öÀ´ select * from Âð£¿
·¢ÏÖpl/sqlÖпÉÒÔÅäÖÃ×Ô¶¯Ìæ»»
ÔÚPL/SQLµÄ°²×°Ä¿Â¼ÏÂÃæ£º$\PLSQL Developer\PlugIns ÖÐÌí¼ÓÒ»¸öÎı¾Îļþ£¬±ÈÈçÃüÃûΪ:AutoReplace.txt¡£Îı¾ÎļþÖÐÌîдÈçÏÂÄÚÈÝ£º
st = select t.* ,t.rowid from t
s = select a.* from a
d = delete from where
u = update a set a. where a.
w = where
´ò¿ªPL/SQL£¬ÔÚTools->Perferences->EditorÖÐAutoreplaceÑ¡ÔñÅäÖõÄAutoReplace.txtÎļþ
È»ºóTools->Perferences->Key Configuration ÖУ¬ÅäÖÃÒ»ÏÂEditor:AutoReplace Öаѿì½Ý¼üÉèÖÃһϡ£
okÁË¡£ ......
*´æ´¢¹ý³Ì*/
sp_databases --Áгö·þÎñÆ÷ÉϵÄËùÓÐÊý¾Ý¿â
sp_server_info --Áгö·þÎñÆ÷ÐÅÏ¢£¬Èç×Ö·û¼¯£¬°æ±¾ºÍÅÅÁÐ˳Ðò
sp_stored_procedures--Áгöµ±Ç°»·¾³ÖеÄËùÓд洢¹ý³Ì
sp_tables --Áгöµ±Ç°»·¾³ÖÐËùÓпÉÒÔ²éѯµÄ¶ÔÏó
sp_start_job --Á¢¼´Æô¶¯×Ô¶¯»¯ÈÎÎñ
sp_stop_job --Í£Ö¹ÕýÔÚÖ´ÐеÄ×Ô¶¯»¯ÈÎÎñ
sp_password --Ìí¼Ó»òÐ޸ĵǼÕÊ»§µÄÃÜÂë
sp_configure --ÏÔʾ(²»´øÑ¡Ïî)»ò¸ü¸Ä(´øÑ¡Ïî)µ±Ç°·þÎñÆ÷µÄÈ«¾ÖÅäÖÃÉèÖÃ
sp_help --·µ»Ø±íµÄÁÐÃû£¬Êý¾ÝÀàÐÍ£¬Ô¼ÊøÀàÐ͵È
sp_helptext --ÏÔʾ¹æÔò£¬Ä¬ÈÏÖµ£¬Î´¼ÓÃܵĴ洢¹ý³Ì£¬Óû§¶¨ÒåµÄº¯Êý£¬
--´¥·¢Æ÷»òÊÓͼµÄʵ¼ÊÎı¾
sp_helpfile --²é¿´µ±Ç°Êý¾Ý¿âÐÅÏ¢
sp_dboption --ÏÔʾ»ò¸ü¸ÄÊý¾Ý¿âÑ¡Ïî
sp_detach_db --·ÖÀëÊý¾Ý¿â
sp_attach_db --¸½¼ÓÊý¾Ý¿â
sp_addumpdevice --Ìí¼ÓÉ豸
sp_dropdevice --ɾ³ýÉ豸
sp_pkeys --²é¿´Ö÷¼ü
sp_fkeys --²é¿´Íâ¼ü
sp_helpdb --²é¿´Ö¸¶¨Êý¾Ý¿âÏà¹ØÎļþÐÅÏ¢
sp_addtype --×Ô½¨Êý¾ÝÀàÐÍ
sp_droptype --ɾ³ý×Ô½¨Êý¾ÝÀàÐÍ
sp_rename --ÖØÐÂÃüÃûÊý¾Ý¿â
sp_executesql --Ö´ÐÐSQLÓï¾ä
sp_addlogin --Ìí¼ÓµÇ½
sp_droplogin --ɾ³ýµÇ¼
sp_grantdbaccess --°ÑÓû§Ó³Éäµ½µÇ¼£¬¼´Ì ......
н¨±í£º
create table [±íÃû]
(
[×Ô¶¯±àºÅ×Ö¶Î] int IDENTITY (1,1) PRIMARY KEY ,
[×Ö¶Î1] nVarChar(50) default 'ĬÈÏÖµ' null ,
[×Ö¶Î2] ntext null ,
[×Ö¶Î3] datetime,
[×Ö¶Î4] money null ,
[×Ö¶Î5] int default 0,
[×Ö¶Î6] Decimal (12,4) default 0,
[×Ö¶Î7] image null ,
)
ɾ³ý±í£º
Drop table [±íÃû]
²åÈëÊý¾Ý£º
INSERT INTO [±íÃû] (×Ö¶Î1,×Ö¶Î2) VALUES (100,'51WINDOWS.NET')
ɾ³ýÊý¾Ý£º
DELETE from [±íÃû] WHERE [×Ö¶ÎÃû]>100
¸üÐÂÊý¾Ý£º
UPDATE [±íÃû] SET [×Ö¶Î1] = 200,[×Ö¶Î2] = '51WINDOWS.NET' WHERE [×Ö¶ÎÈý] = 'HAIWA'
ÐÂÔö×ֶΣº
ALTER TABLE [±íÃû] ADD [×Ö¶ÎÃû] NVARCHAR (50) NULL
ɾ³ý×ֶΣº
ALTER TABLE [±íÃû] DROP COLUMN [×Ö¶ÎÃû]
ÐÞ¸Ä×ֶΣº
ALTER TABLE [±íÃû] ALTER COLUMN [×Ö¶ÎÃû] NVARCHAR (50) NULL
ÖØÃüÃû±í£º(Access ÖØÃüÃû±í£¬Çë²Î¿¼ÎÄÕ£ºÔÚAccessÊý¾Ý¿âÖÐÖØÃüÃû±í)
sp_rename '±íÃû', 'бíÃû', 'OBJECT'
н¨Ô¼Êø£º
ALTER TABLE [±íÃû] ADD CONSTRAINT Ô¼ÊøÃû CHECK ([Ô¼Êø×Ö¶Î] <= '2000-1-1')
ɾ³ýÔ¼Êø£º
ALTER TABLE [±íÃû] DROP CONSTRAINT Ô¼ÊøÃû
н¨Ä¬ÈÏÖµ
ALTER TABLE [±íÃû] ......
/*
±ÈÈçExcelÓÐÁ½ÁУ¬AÁкÍBÁÐÐèÒªµ¼Èëµ½SQL±íÖУ¬·´ÕýÎÒÒѾÓм¸Äê²»ÓÃDTSÖ®ÀàµÄ¹¤¾ßÁË¡£
ÔÚExcelÖеÄеÄÒ»ÁÐÖУ¬Ö±½Óд¹«Ê½
=CONCATENATE("Insert #tmp values('",A1,"','",B1,"')")
°ÑÿһÐж¼Éè³ÉͬÑùµÄ¹«Ê½(Ë«»÷¼´¿ÉÍê³É)¡£
°ÑÕûÁи´ÖÆÏÂÀ´£¬·Åµ½²éѯ·ÖÎöÆ÷ÖÐÖ±½ÓÔËÐоͺÃÁË¡£
Ò²¿ÉÒ԰ѹ«Ê½¸Ä³É =CONCATENATE("select '",A1,"','",B1,"' Union all")
ÕâÑùµÄºÃ´¦¶à
1: ²»ÓùÜÄãʲô¸ñʽ£¬¾ø¶Ô²»»áÂÒ¡£
2£º¿ì½Ý·½±ã£¨ÁÐÊý²»Ì«¶àµÄ»°Ò»°ãÒ»·ÖÖÓÖ®ÄÚ¿ÉÒԸ㶨£©
3: ²»»á³ö´í£¬ÉõÖÁ¶¼²»ÐèÒªºË¶Ô¡£
......
*/
ת×Ô£ºhttp://topic.csdn.net/u/20091020/08/2162e737-577f-4f0c-9a4c-592ba97c698c.html?seed=1969593865&r=60535884#r_60535884
......
¹¤×÷ÖлýÔܵö×Ô¶¨ÒåSQLº¯Êý:
-- =============================================
-- Author: <Author,,Name>
-- Create date: <Create Date, ,>
-- Description: ×Ö·û´®ÇиÊý
-- =============================================
ALTER function [dbo].[Split]
(
@Text nvarchar(4000),
@Sign nvarchar(4000)
)
returns @tempTable table(id int identity(1,1) primary key,[value] nvarchar(4000))
AS
begin
declare @StartIndex int --¿ªÊ¼²éÕÒµÄλÖÃ
declare @FindIndex int --ÕÒµ½µÄλÖÃ
declare @Content varchar(4000) --ÕÒµ½µÄÖµ
set @StartIndex = 1
set @FindIndex=0
& ......