ÎÒÏëÔÚaspÖмÓÒ»¸öÁ´½Ó£¬Ö¸Ïòasp.netÍøÒ³£¬µ«asp.netµÄÍøÖ·ÊǾ¹ýHttpUtility.UrlEncode±äÐκÍHttpUtility.UrlDecode±ä»ØµÄ£¬¶øaspµÄserver.urlencodeÈ´²úÉú²»Á˺ÍHttpUtility.UrlEncodeÒ»ÑùµÄ±àÂ룬ÇëÎÊÓÐûÓнâ¾ö°ì·¨
²¹³ä£ºÔÀ´asp.netµÄÊÇ"web.aspx?str="+HttpUtility.UrlEncode(str)
ºÍHttpUtility.UrlDecode(Request.QueryString["str"].ToString().Trim())
¶øaspµÄÊÇ"web.aspx?web.aspx?str="+server.urlEncode( server.URLpathencode(str))
asp.netÌá½»¶ËΪ£º"web.aspx?str="+ HttpUtility.UrlEncode( str£¬System.Text.Encoding.GetEncoding("gb2312"))
asp.net½ÓÊÕ¶ËΪ£ºstr= HttpUtility.UrlDecode(Request.QueryString["str"].ToString().Trim(),System.Text.Encoding.GetEncoding("gb2312"))
ÆäÖÐstrΪÐèÒª´«µÝµÄ±äÁ¿ ......
ÎÒÏëÔÚaspÖмÓÒ»¸öÁ´½Ó£¬Ö¸Ïòasp.netÍøÒ³£¬µ«asp.netµÄÍøÖ·ÊǾ¹ýHttpUtility.UrlEncode±äÐκÍHttpUtility.UrlDecode±ä»ØµÄ£¬¶øaspµÄserver.urlencodeÈ´²úÉú²»Á˺ÍHttpUtility.UrlEncodeÒ»ÑùµÄ±àÂ룬ÇëÎÊÓÐûÓнâ¾ö°ì·¨
²¹³ä£ºÔÀ´asp.netµÄÊÇ"web.aspx?str="+HttpUtility.UrlEncode(str)
ºÍHttpUtility.UrlDecode(Request.QueryString["str"].ToString().Trim())
¶øaspµÄÊÇ"web.aspx?web.aspx?str="+server.urlEncode( server.URLpathencode(str))
asp.netÌá½»¶ËΪ£º"web.aspx?str="+ HttpUtility.UrlEncode( str£¬System.Text.Encoding.GetEncoding("gb2312"))
asp.net½ÓÊÕ¶ËΪ£ºstr= HttpUtility.UrlDecode(Request.QueryString["str"].ToString().Trim(),System.Text.Encoding.GetEncoding("gb2312"))
ÆäÖÐstrΪÐèÒª´«µÝµÄ±äÁ¿ ......
‘·À×¢Èë°ÑËü¼Óµ½connÀïÕâÑù¾ÍokÁË
dim sql_injdata
SQL_injdata = "’|and|exec|insert|select|delete|update|count|*|%|chr|mid|master|truncate|char|declare"
SQL_inj = split(SQL_Injdata,"|")
If Request.QueryString<>"" Then
For Each SQL_Get In Request.QueryString
For SQL_Data=0 To Ubound(SQL_inj)
if instr(Request.QueryString(SQL_Get),Sql_Inj(Sql_DATA))>0 Then
Response.Write "<Script>alert(‘Çë²»ÒªÔÚ²ÎÊýÖаüº¬·Ç·¨×Ö·û³¢ÊÔ×¢È룡’);history.back(-1)</Script>"
Response.end
end if
next
Next
End If
If Request.Form<>"" Then
For Each Sql_Post In Request.Form
For SQL_Data=0 To Ubound(SQL_inj)
if instr(Request.Form(Sql_Post),Sql_Inj(Sql_DATA))>0 Then
Response.Write "<Script>alert(‘Çë²»ÒªÔÚ²ÎÊýÖаüº¬·Ç·¨×Ö·û³¢ÊÔ×¢È룡’);history.back(-1)</Script>"
Response.end
end if
next
next
end if ......
ASP²¿·Ö½²Êö£º ¶ÔÓÚASPÀ´ËµÏàÐÅ´ó¼Ò¶¼²¢²»Ä°Éú£¬ÔÚÕâÀïÎҾͲ»ÀË·ÑÌ«¶àµÄʱ¼äÀ´½øÐвûÊöÁË¡£
ÎÒÕâÀïÖ÷ÒªÊǼǼÁËÎÒÔÚ¶ÁASPʱµÄһЩÐĵúÍÎÒ×Ô¼ºÈÏΪӦ¸Ã×¢ÒâµÄµØ·½£¬Ï£ÍûÕâЩµãµãµÎµÎÄܹ»ÎªÄÇЩ³õѧµÄÅóÓÑÓÐÒ»¶¨µÄ°ïÖú£¬Í¬Ê±Ò²Ï£ÍûºÍÒѾÓкÜÉî¾ÑéºÍ¶ÔASPÓÐËùÑо¿µÄÈ˽øÐÐỊֽ̀¬»¹Ï£ÍûÅóÓÑÃDz»Áߴͽ̰¡£¡ºÇºÇ£¡
ºÃÁËÎÒÒ²¾Í²»¶à˵ʲôÁË£¬ÏÂÀ´ÎҾͽ«ÎҵĺÜСµÄÒ»²¿·Ö Ðĵúʹó¼Ò·ÖÏí£º
request.form <"±íµ¥ÔªËØÃû">
request.querystring¡¶µØÖ·À¸²ÎÊýÃû“¡·
formatdatetime º¯Êý ¹¦ÄÜ£º¸ñʽ»¯ÈÕÆÚ»òʱ¼ä
abs£¨number£© ¹¦ÄÜ£º Çó¾ø¶ÔÖµ
& ......
ÒÔÏÂÊÇ·¢ÔÚ÷×ÓÂÛ̳µÄÌù×Ó£¬×ª·¢¹ýÀ´£¬Ï£Íû¸øÓõÃ×ŵĺüÓѲο¼¡£
ÎҵijÌÐòÒÔÇ°Ò»Ö±ÊÇÓû¨Éú¿Ç°ó¶¨IPʵÏÖµÄÔ¶³Ì£¬ÓÉÓÚ¿Í»§·þÎñÆ÷ºÍ¿Í»§¶Ë¶¼ÊÇͨ¹ý¿í´øÉÏÍø£¬Ò»°ãµÄ²Ù×÷£¨¿ª½ø»õµ¥¡¢ÏúÊÛµ¥µÈ£©ËÙ¶ÈÒ²»¹²»´í£¬µ«ÊÇÔÚÔ¶³Ì¿Í»§¶ËÐÞ¸ÄÉÌÆ·×ÊÁÏ£¨10000¶àÌõ¼Ç¼£©¡¢²éѯһ¶ÎʱÆڵĽøÏú´æÁ÷Ë®£¨Ò»ÖÜ5000ÌõÒÔÉÏ£©µÈÉæ¼°µ½È¡¼Ç¼Á¿´óµÄ²Ù×÷ʱ·Ç³£Âý¡£
Ç°¶Îʱ¼ä²Î¿¼ZXS4785°æÖ÷¼°ÆäËüºüÓѵĴúÂëºó£¬¶Ô·þÎñÆ÷»·¾³¼°³ÌÐò½øÐÐvfp/(asp/vfpdll/Sql)ģʽ¸ÄÔì¡£ÓÉÓÚ¼ÓÈëmyfll.fll½øÐÐÊý¾ÝѹËõ£¬Ô¶³Ì²Ù×÷ËٶȽÏÒÔÇ°´óΪ¸ÄÉÆ¡£³ÃÕâÁ½ÌìÓÐʱ¼ä£¬Ìؽ«ÊµÏÖ·½·¨¼°Ïà¹Ø´úÂë½éÉÜÈçÏ£¬Îª³õ½Ó´¥ÕßÌṩ²Î¿¼£¬ÀÏÊÖ×Ô¿ÉһЦ¶ø¹ý¿©£¬ºÇºÇ¡£ÔÚ´Ë£¬Ð»¹ýZXS4785Óëľ¹ÏÏÈ£¡
Ò».·þÎñÆ÷ÉèÖÃ
1.»¨Éú¿Ç£º°ó¶¨IPÖ®Óã¬Èç¹û·þÎñÓй̶¨IP³ýÍâ¡£
2.IIS£ºÎÒÓõÄÊÇ5.1£¬WinϵͳÊÇXP SP2¡£°²×°ºóIISºó£¬½¨ÒéÉèÖÃTCP¶Ë¿ÚΪ80Ö®ÍâµÄÆäËü¶Ë¿ÚÆ©Èç8080£¬ÒòΪÓÐЩµØÇøµÄµçÐÅ·â80¶Ë¿Ú(Õâ¾ÍÊDZ¾»úÄÜ·ÃÎÊÍøÒ³£¬¶øÔ¶³Ì²»ÄÜ·ÃÎʵÄÒ»´óÔÒò)¡£
3.É趨ĬÈÏÍøÕ¾µÄÖ÷Ŀ¼£¬ºóÃæÌáµ½µÄsqlexec.asp¼°twcom.dll¶¼Òª·ÅÔÚÖ÷Ŀ¼ÖУ¬ÒÔÌṩ¸ø¿Í»§¶Ëµ÷Óá£
4.½«myfll.fll¸´ÖƵ½WINDOWSϵͳÎļþ¼Ð£¬ÕâÒ»µã·Ç³£ÖØÒª£¬·ñÔòÖ´ÐÐasp½«ÌáʾÕÒ²»µ½A ......
ÒÔÏÂÊÇ·¢ÔÚ÷×ÓÂÛ̳µÄÌù×Ó£¬×ª·¢¹ýÀ´£¬Ï£Íû¸øÓõÃ×ŵĺüÓѲο¼¡£
ÎҵijÌÐòÒÔÇ°Ò»Ö±ÊÇÓû¨Éú¿Ç°ó¶¨IPʵÏÖµÄÔ¶³Ì£¬ÓÉÓÚ¿Í»§·þÎñÆ÷ºÍ¿Í»§¶Ë¶¼ÊÇͨ¹ý¿í´øÉÏÍø£¬Ò»°ãµÄ²Ù×÷£¨¿ª½ø»õµ¥¡¢ÏúÊÛµ¥µÈ£©ËÙ¶ÈÒ²»¹²»´í£¬µ«ÊÇÔÚÔ¶³Ì¿Í»§¶ËÐÞ¸ÄÉÌÆ·×ÊÁÏ£¨10000¶àÌõ¼Ç¼£©¡¢²éѯһ¶ÎʱÆڵĽøÏú´æÁ÷Ë®£¨Ò»ÖÜ5000ÌõÒÔÉÏ£©µÈÉæ¼°µ½È¡¼Ç¼Á¿´óµÄ²Ù×÷ʱ·Ç³£Âý¡£
Ç°¶Îʱ¼ä²Î¿¼ZXS4785°æÖ÷¼°ÆäËüºüÓѵĴúÂëºó£¬¶Ô·þÎñÆ÷»·¾³¼°³ÌÐò½øÐÐvfp/(asp/vfpdll/Sql)ģʽ¸ÄÔì¡£ÓÉÓÚ¼ÓÈëmyfll.fll½øÐÐÊý¾ÝѹËõ£¬Ô¶³Ì²Ù×÷ËٶȽÏÒÔÇ°´óΪ¸ÄÉÆ¡£³ÃÕâÁ½ÌìÓÐʱ¼ä£¬Ìؽ«ÊµÏÖ·½·¨¼°Ïà¹Ø´úÂë½éÉÜÈçÏ£¬Îª³õ½Ó´¥ÕßÌṩ²Î¿¼£¬ÀÏÊÖ×Ô¿ÉһЦ¶ø¹ý¿©£¬ºÇºÇ¡£ÔÚ´Ë£¬Ð»¹ýZXS4785Óëľ¹ÏÏÈ£¡
Ò».·þÎñÆ÷ÉèÖÃ
1.»¨Éú¿Ç£º°ó¶¨IPÖ®Óã¬Èç¹û·þÎñÓй̶¨IP³ýÍâ¡£
2.IIS£ºÎÒÓõÄÊÇ5.1£¬WinϵͳÊÇXP SP2¡£°²×°ºóIISºó£¬½¨ÒéÉèÖÃTCP¶Ë¿ÚΪ80Ö®ÍâµÄÆäËü¶Ë¿ÚÆ©Èç8080£¬ÒòΪÓÐЩµØÇøµÄµçÐÅ·â80¶Ë¿Ú(Õâ¾ÍÊDZ¾»úÄÜ·ÃÎÊÍøÒ³£¬¶øÔ¶³Ì²»ÄÜ·ÃÎʵÄÒ»´óÔÒò)¡£
3.É趨ĬÈÏÍøÕ¾µÄÖ÷Ŀ¼£¬ºóÃæÌáµ½µÄsqlexec.asp¼°twcom.dll¶¼Òª·ÅÔÚÖ÷Ŀ¼ÖУ¬ÒÔÌṩ¸ø¿Í»§¶Ëµ÷Óá£
4.½«myfll.fll¸´ÖƵ½WINDOWSϵͳÎļþ¼Ð£¬ÕâÒ»µã·Ç³£ÖØÒª£¬·ñÔòÖ´ÐÐasp½«ÌáʾÕÒ²»µ½A ......
dim conn,connstr
Set conn = Server.CreateObject("ADODB.Connection")'´´½¨Ò»¸öÊý¾Ý¿âÁ´½Ó¶ÔÏóconn£¬·½±ãºóÃæµ÷ÓÃ
connstr="Provider=SQLOLEDB;Data Source=(local);Initial Catalog=111;User ID=sa;Password=1234;" '´´½¨Ò»¸öÊý¾Ý¿âµÄrecordset¶ÔÏ󣬷½±ãÒÔºóµ÷ÓÃ
conn.Open connstr'´ò¿ªÊý¾Ý¿â ......
dim conn,connstr
Set conn = Server.CreateObject("ADODB.Connection")'´´½¨Ò»¸öÊý¾Ý¿âÁ´½Ó¶ÔÏóconn£¬·½±ãºóÃæµ÷ÓÃ
connstr="Provider=SQLOLEDB;Data Source=(local);Initial Catalog=111;User ID=sa;Password=1234;" '´´½¨Ò»¸öÊý¾Ý¿âµÄrecordset¶ÔÏ󣬷½±ãÒÔºóµ÷ÓÃ
conn.Open connstr'´ò¿ªÊý¾Ý¿â ......
ÒýÑÔ
²ÉÓÃWEB¼¼ÊõʵÏÖB/S£¨ä¯ÀÀÆ÷/·þÎñÆ÷£©½á¹¹µÄ¹ÜÀíϵͳÊǰ칫×Ô¶¯»¯µÄ·¢Õ¹Ç÷ÊÆ¡£»ùÓÚWEB¼¼ÊõµÄ¹ÜÀíϵͳ£¬ÓÉÓÚ¿ª·¢ÖÜÆڶ̣»ÓëÓû§Æ½Ì¨Î޹أ»Ò×ÓÚʵÏÖ½»»¥Ê½Ó¦Óã»ÄܶÔÐÅÏ¢½øÐпìËÙ¡¢¸ßЧµÄÊÕ¼¯¡¢´¦ÀíºÍ·¢²¼£¬½ü¼¸ÄêÀ´µÃµ½ÁËѸËÙ·¢Õ¹¡£¶øASP¼¼ÊõÓÉÓÚÆ俪·¢Ð§Âʸߡ¢½»»¥ÐԺ㬰²È«ÐÔÇ¿µÈÌص㣬Öð½¥³ÉΪ¿ª·¢¹ÜÀíϵͳµÄÊ×Ñ¡¹¤¾ß¡£
Ðí¶à»ùÓÚWEBµÄÓ¦Óö¼Éæ¼°ÎļþÉÏ´«²Ù×÷¡£³£¼ûµÄÎļþÉÏ´«¼¼ÊõÓУº»ùÓÚHTTPÐÒéµÄ£»»ùÓÚVB£¨»òDELPHIµÈ±à³ÌÓïÑÔ£©¿ª·¢µÄÎļþÉÏ´«×é¼þµÄ£»»ùÓÚÊý¾Ý¿â¼¼ÊõµÄµÈµÈ¡£ÕâЩ·½·¨Ò»°ã¶¼ÐèÒª±à³ÌÕßÄÜͬʱÕÆÎÕWEB¼¼Êõ¡¢Êý¾Ý¿â¼¼Êõ»òCGI¼¼Êõ»ò×é¼þ¼¼Êõ£¬¶Ô±à³ÌÕßµÄÒªÇó½Ï¸ß¡£¶ø±¾ÎĽ«½éÉܵÄÀûÓÃASP¼¼ÊõÖ±½ÓʵÏÖÎļþÉÏ´«¹¦ÄÜÔòÖ»Ðè±à³ÌÕßÕÆÎÕµ¥Ò»µÄASP¼¼Êõ¼´¿É£¬´ó´ó½µµÍÁ˱à³ÌÄѶȡ£
¼¸ÖÖÎļþÉÏ´«¼¼ÊõµÄ±È½Ï
1¡¢»ùÓÚHTTPÐÒé
¸Ã·½·¨ÐèÒª±à³ÌÕßÀûÓõÚÈý·½Èí¼þ£¬ÈçDELPHI¡¢VBµÈ£¬ÔÚÓ¦ÓóÌÐòÖÐÏȽøÐÐHTTPÐÒé±à³Ì£¬È»ºó½«´ýÉÏ´«ÎļþÄÚÈÝ°´HTTPÐÒéµÄ¸ñʽ´ò°ü£¬×îºóÏòWEB·þÎñÆ÷·¢ËÍÉÏ´«µÄÇëÇó±¨ÎÄ£¬´Ó¶øʵÏÖÎļþµÄÉÏ´«¡£ÒòΪDELPHIºÍVB²»ÄܱàдÍêÕûµÄWEBÍøÂç³ÌÐò£¬Ö»ÄܱàдWEBСӦÓóÌÐò£¬Òò´Ë£¬¸Ã·½·¨Ö»ÓÃÓÚ¹¦ÄÜÊÜÏÞµÄÍøÂçÓ ......