×öÏîĿҲÓÐÒ»¶Îʱ¼äÁË£¬ÔÚ³ÌÐòÖÐÒ²Óöµ½ºÜ¶à°²È«·½ÃæµÄÎÊÌâ¡£Ò²¸Ã×ܽáÒ»ÏÂÁË¡£Õâ¸öÏîÄ¿ÊÇÒ»¸ö CMS ϵͳ¡£ÏµÍ³ÊÇÓà ASP.NET ×öµÄ¡£¿ª·¢µÄʱºò·¢ÏÖ΢Èí×öÁ˺ܶలȫ´ëÊ©£¬Ö»ÊÇÓÐЩÐÂÊÖ³ÌÐòÔ±²»ÖªµÀÔõô¿ªÆô¡£ÏÂÃæÎÒͨ¹ý¼¸¸ö·½Ãæ¼òµ¥½éÉÜ£º
¡¡¡¡1£ºSQL ×¢Èë
¡¡¡¡2£ºXSS
¡¡¡¡3£ºCSRF
¡¡¡¡4£ºÎļþÉÏ´«
SQL ×¢Èë
¡¡¡¡ÒýÆðÔÒò£ºÆäʵÏÖÔںܶàÍøÕ¾Öж¼´æÔÚÕâÖÖÎÊÌâ¡£¾ÍÊdzÌÐòÖÐÖ±½Ó½øÐÐ SQL Óï¾äÆ´½Ó¡£¿ÉÄÜÓÐЩ¶ÁÕß²»Ì«Ã÷°×¡£ÏÂÃæÍ¨¹ýÒ»¸öµÇ¼ʱ¶ÔÓû§ÑéÖ¤À´ËµÃ÷£º
¡¡¡¡Ñé֤ʱµÄ SQL Óï¾ä£º
µÇ¼ÑéÖ¤ SQL Óï¾ä(Ôʼ)
Select * from Where user = '" + txtUsername.Text + "' AND pwd = '" + txtPwd.Text + "'
¡¡¡¡ÕâÊÇÒ»¶Î´ÓÊý¾Ý¿âÖвéѯÓû§£¬¶ÔÓû§Ãû£¬ÃÜÂëÑéÖ¤¡£
¡¡¡¡¿´ÉÏÈ¥ºÃÏóûÓÐʲôÎÊÌ⣬µ«ÊÇʵ¼ÊÕâÀïÃæÇ³²Ø×ÅÎÊÌ⣬Óû§Ãû£ºadmin ÃÜÂ룺admin
µÇ¼ÑéÖ¤ SQL Óï¾ä(ÕæÊµ)
Select * from Where user = 'admin' AND pwd = 'admin'
¡¡¡¡Èç¹ûÓû§ºÍÃÜÂëÕýÈ·¾Í¿ÉͨÑéÖ¤¡£Èç¹ûÎÒÓû§Ãû£ºasdf' OR 1 = 1 ......
asp.netÖеÄÓû§¿Ø¼þÎÞÒÉÊÇ´úÂëÖØÓõÄÁ¼ºÃ;¾¶£¬²»µ«µ÷Ó÷½±ã£¬Éè¼ÆÆðÀ´Ò²·Ç³£Ö±¹Û£¬±¾Éí¾Í¼¸ºõ¿ÉÒÔ×öΪÆÕͨҳÀ´¶Ô´ý¡£
ÔÚµ÷ÓÃÒ³ÖУ¬ÈçºÎ¿ØÖÆÓû§¿ØÖÆÖеĿؼþÄØ£¿ÎÒÏëasp.netµÄÉè¼ÆÕߣ¬ÔÚÉè¼ÆÖ®³õ£¬Ôç¾ÍÒѾ¿¼Âǵ½ÁËÕâÒ»µãÁ˰ɣ¡¼ÈÈ»Óû§¿ØÖÆÔÚµ÷ÓÃÒ³ÃæÖÐÓÐΨһµÄID±êʶ£¬ÄÇôÆäÏà¹ØµÄ²Ù×÷£¬¿Ï¶¨Ò²ÊÇͨ¹ýÕâ¸öid±êʶÀ´ÊµÏֵġ£
ͨ¹ý³¢ÊÔ£¬·¢ÏÖÓÐÒ»¸öFindControl(string name)·½·¨¿ÉÓã¬Ö»ÐèÒªÕÒ³öËùÐèµÄcontrolÖ®ºó£¬ÔÙ½øÐÐÀàÐÍת»»¼´¿Éµ÷ÓúͲÙ×÷ÁË¡£ÀýÈçÒѾÓû§¿Ø¼þÖÐÓÐÒ»¸öLiteral¿Ø¼þ£¬Ãû³ÆÎªltPosition£¬ÆäËùÔÚµÄÓû§¿Ø¼þidΪctl1£¬ÄÇô¿ÉÒÔÕâÑùÕÒµ½Ëü£º
(Literal)(ctl1.FindControl("ltPosition"))
Ö®ºó£¬¾Í¿ÉÒÔÏñ²Ù×÷ÆÕͨµÄLiteral¿Ø¼þÒ»Ñù²Ù×÷ËüÁË¡£ÕæµÄͦ·½±ãµÄŶ¡£ ......
ÔÚweb.configÖÐÐÞ¸ÄÐÞ¸ÄÊôÐÔ
1£º<configSections><configSections>ÖмÓÏÂÃæ´úÂë
<configSections>
<sectionGroup name="system.web.extensions" type="System.Web.Configuration.SystemWebExtensionsSectionGroup, System.Web.Extensions, Version=1.0.61025.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35">
<sectionGroup name="scripting" type="System.Web.Configuration.ScriptingSectionGroup, System.Web.Extensions, Version=1.0.61025.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35">
<section name="scriptResourceHandler" type="System.Web.Configuration.ScriptingScriptResourceHandlerSection, System.Web.Extensions, Version=1.0.61025.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35" requirePermission="false" allowDefinition="MachineToApplication"/>
<sectionGroup name="webServices" type="System.Web.Configuration.ScriptingWebServicesSectionGroup, System.Web.Extensions, Version ......
ÔÚweb.configÖÐÐÞ¸ÄÐÞ¸ÄÊôÐÔ
1£º<configSections><configSections>ÖмÓÏÂÃæ´úÂë
<configSections>
<sectionGroup name="system.web.extensions" type="System.Web.Configuration.SystemWebExtensionsSectionGroup, System.Web.Extensions, Version=1.0.61025.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35">
<sectionGroup name="scripting" type="System.Web.Configuration.ScriptingSectionGroup, System.Web.Extensions, Version=1.0.61025.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35">
<section name="scriptResourceHandler" type="System.Web.Configuration.ScriptingScriptResourceHandlerSection, System.Web.Extensions, Version=1.0.61025.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35" requirePermission="false" allowDefinition="MachineToApplication"/>
<sectionGroup name="webServices" type="System.Web.Configuration.ScriptingWebServicesSectionGroup, System.Web.Extensions, Version ......
dz̸ASP.NETÖеÄÈýÖֻỰ״̬
³£ÓõÄASP.NETµÄ»á»°×´Ì¬ÖÐÓÐÈýÖÖ.·ÖΪ½ø³ÌÄڻỰ״̬¡¢×´Ì¬·þÎñÆ÷»á»°×´Ì¬¡¢SQL Server »á»°×´Ì¬
ÏÈ̸̸½ø³ÌÄڻỰ״̬£¨Inprocess£©ÕâÊÇÒ»ÖÖĬÈϵÄģʽ£¬µ«ÊÇÖ»ÒªÔÚWeb.configÖнøÐмòµ¥µÄÅäÖþͿɽøÐиü¸Ä£¬¾ßÌåÄÚÈÝÏÂÃæ»á½øÐÐ˵Ã÷¡£½ø³ÌÄڻỰ״̬ÊÇÒ»ÖÖ×î¿ì£¬µ«ÊÇ×î²»Îȶ¨µÄÒ»ÖÖģʽ¡£Èç¹ûÖØÆôIIS»ò·þÎñÆ÷µÄ»°£¬»á»°×´Ì¬½«»áÏûʧ¡£ÕâÖÖÇé¿öÊʺÏÔÚһ̨·þÎñÆ÷ÖлòÕâûÓÐWEB³¡µÄÇé¿öÖС£Èç¹ûÄã¹Ø×¢µÄËٶȶø²»ÊÇÎȶ¨ÏཨÒéÄãÑ¡ÔñÕâÖÖ·½Ê½¡£
ÉèÖÃÈçÏ <SessionState .... mode="InProc">
״̬·þÎñÆ÷»á»°¾ÖģʽÊÇASP.NETÖеÄÐÂģʽ£¬µ«ÊÇËüµÄËٶȱȽø³ÌÄڻỰÂý£¬Ó¦Îª´Ó»á»°×´Ì¬µ½ÁíÒ»ÖֻỰ״̬Ҫ´©Ô½²»Í¬µÄ·þÎñÆ÷ºÍ±ß½ç£¬Òò´Ë»á¼õÂýÆä·ÃÎʵÄËÙ¶È¡£Êµ¼ÊÉϻỰ״̬ÊÇ´æ´¢ÔÚÒ»¸öÃûΪASP.NETµÄµ¥¶À½ø³ÌÖУ¬Ê¹Óøýø³ÌµÄ»°ÐèÒª½«×´Ì¬·þÎñÆ÷ÉèΪÆô¶¯¡£
ASP.NET״̬·þÎñÆ÷½ø³ÌÊǵ¥¶ÀÓëASP¸¨Öú½ø³ÌºÍIISÓ¦ÓóÌÐò³ØµÄµ¥¶À½ø½ø³Ì£¬Èç¹û¼Ó´Ë½ø³ÌÔËÐÐÔÚÁíһ̨·þÎñÆ÷Éϵϰ£¬ÉõÖÁ¿ÉÒÔÔÚIIS»ò·þÎñÆ÷ÖØÆôµÄʱºò±£Áô» ......
×î½üÔÚºÍÒ»¸öͬѧ±àдһ¸ö¹ÜÀíϵͳµÄʱºò£¬ÒªÓõ½GridView¿Ø¼þ£¬½á¹ûÔÚCSDNÀïÃæÕÒµ½Ò»¸ö²©¿Í£¬ÕâЩ½²µÃºÜÏêϸ£¬Ìṩһ¸öµØÖ·¸ø´ó¼Ò²Î¿¼°É
http://blog.csdn.net/21aspnet/archive/2007/03/25/1540301.aspx
»¹ÓÐÒ»¸ö¾ÍÊǰٶȿռäÀïÃæµÄ:http://hi.baidu.com/%BA%AB%C7%EC%D5%EA/blog/item/c0b717daa312fb3f33fa1c91.html ......
ÓÉÓÚÏîÄ¿µÄÐèÇóͼ±íÏÔʾÊý¾Ý,½ñÌìÔÚÍøÉÏÕÒÁËÒ»Ìì,ÖÕÓÚÕÒµ½Ò»¸ö²»´íµÄ¿Ø¼þ----ZedGraph,ËüÖ§³Öasp,asp.net,vc.
ÏÖÔÚ×îеİ汾ÊÇ5.0,Щ°æ±¾Ö§³Ö .NET 2.0.5.0°æ±¾ÒÔϵÄÖ§³Ö.NET 1.1
ÎÒÃÇÏÖÔÚµÄÏîÄ¿ÊÇ.NET1.1¿ª·¢µÄ.ÎÒÔÚÍøÉÏÕÒÁËÒ»ÌìҲûÓз¢ÏÖÒ»¸öÀý×Ó,ÏÂÃæÎÒ½«½éÉÜÏÂÆäÔÚASP.NETϵÄÓÃ×öWEB¿Ø¼þµÄÓ÷¨
1.ÏȽ«ËüÌṩµÄÁ½¸öDLLÎļþÌí¼ÓÒýÓÃ
2.н¨Ò»¸öASPXÒ³ÃæZedGraph.aspx,ÒýÓÃZedGraphÓû§¿Ø¼þ
ZedGraph.aspxÒ³Ãæ´úÂë
ZedGraph.aspx.cs´úÂë
1
using
System;
2
using
System.Collections;
3
using
System.ComponentModel;
4
using
System.Data;
5
using
System.Drawing;
6
using
System.Web;
7
using
System.Web.SessionState;
8
using
System.Web.UI;
9
using
System.Web.UI.WebControls;
10
using
System.Web.UI.HtmlControls;
11
using
ZedGraph;
12
......