¹«Ë¾ÔÓÐÒ»¸ö¾ÖÓòÍø£¬¾¹ý¶àÄêµÄÐÞÐÞ²¹²¹£¬ÒѾ´´½¨Á˲»ÉÙµÄÄÚÈÝ£¬°üÀ¨Ò»Ð©Êý¾Ý¿â²éѯ±¨±í¡¢¹¤×÷Á÷µÈÍøÕ¾£¬ÕâЩÍøÕ¾ÓÐһЩÊÇÓÃASP.NETÀ´¿ª·¢µÄ£¬²¢ÇÒÓÃÁ˺ܶàÄ꣬»ýÀÛÁ˺ܶàÒµÎñÊý¾Ý£»ÏÖÔÚ¹«Ë¾Ïë°Ñ¾ÖÓòÍøÓÃWSS3.0À´¼ÜÉ裬Õâ¾ÍÃæÁÙµ½Ò»¸öºÜ¼¬ÊÖµÄÎÊÌ⣬¾ÍÊÇÔõÑùÀ´´¦ÀíÕâЩ¾ÉµÄÍøÒ³¡£Èç¹ûÍƵ¹ÖØÀ´£¬ÄÇô¹¤×÷Á¿½«ÊǷdz£ÏÅÈ˵ģ¬Ã»ÓиöÁ½¡¢ÈýÄêÊÇÍê²»³ÉµÄ£»Èç¹û¼ÌÐø±£Áô£¬Ð¾ÉÍøվͬʱ²¢´æ£¬ÄÇôÃÅ»§ÍøÕ¾½«³ÉΪһ¸ö±ðŤµÄ»ìѪ¶ù£¬»á¸ü¼ÓµÄ»ìÂÒ²»¿°¡£¶ÔÓÚһЩ¼òµ¥µÄASP.NETÍøÕ¾£¬ÎÒÃDzÉÓÃÒÔϵķ½·¨£¬°ÑËüÃÇת³É¿ÉÒÔÔÚWSS3.0ƽ̨ÉÏÃæÔËÐеÄÍøÕ¾£¬ÕâÑùÎÒÃǾ¡Á¿²»È¥¸Ä¶¯ÔÓÐϵͳÀïÃæµÄÂß¼£¬Ö»ÊǼòµ¥µÄ°üװһϣ¬¹¤×÷Á¿»áÉٺܶࡣÏÂÃæµÄ²½ÖèÔËÓÃÒ»¸ö×î¼òµ¥µÄHelloWorldÍøÒ³×÷ΪÀý×Ó£¬¼Ç¼һÏÂת»¯µÄ²½ÖèºÍ×¢ÒâÊÂÏî¡£
1¡¢¼ÙÈçÓÐÒ»¸öASP.NETµÄÍøÒ³£¬ËüÓÐÒ»¸öMyWebForm.aspxµÄÒ³Ã棬°´Ò»ÏÂHello°´Å¥£¬È»ºóÔÚÎı¾¿òÀïÃæÏÔʾ“Hello World”£¬ËüµÄ¹¤³ÌÎļþÈçÏÂͼ£º
ËüµÄCodeBehind´úÂëÈçÏ£º
2¡¢ÎÒÏÈÔÚWSSÍøÕ¾ÉÏÃæ´´½¨Ò»¸ö“Pages”µÄÎļþ¼Ð£¬È»ºó°ÑÕâ¸öMyWebForm.aspx¿½±´µ½PagesÎļþ¼ÐÀïÃ棬¿´Äܲ»ÄÜÔÚIEÀïÃæä¯ÀÀËü£»
3¡¢½á¹ûä¯ÀÀÆ÷±¨¸æÒÔÏ´íÎó£ ......
ʹÓÃASP.NETÉú³É¾²Ì¬Ò³ÃæµÄ·½·¨ÓÐÁ½ÖÖ£¬µÚÒ»ÖÖÊÇʹÓÃC#ÔÚºǫ́Ӳ±àÂ룬µÚ¶þÖÖÊǶÁÈ¡Ä£°åÎļþ£¬Ê¹ÓÃ×Ö·û´®Ìæ»»µÄ·½·¨¡£µÚÒ»ÖÖ·½·¨±àÂëÁ¿´ó£¬
¶øÇÒά»¤±È½ÏÀ§ÄÑ¡£ÎÒÖص㽲½âµÚ¶þÖÖ·½·¨¡£µÚ¶þÖÖ·½·¨µÄ»ù±¾Ë¼Â·ÊÇ£ºÊ¹ÓÃDWÖ®ÀàµÄ¹¤¾ßÉú³ÉÒ»¸ö¾²Ì¬Ò³ÃæÄ£°å¡£¶ÁÈ¡¸ÃÄ£°åÎļþ£¬È»ºó¶ÔÀïÃæµÄÌØÊâ±ê¼ÇʹÓÃ
ÕæʵµÄÊý¾ÝÌæ»»µô£¬²¢Éú³ÉÒ»¸öHTMLÎļþ
Çë¿´´úÂë
1.C#
1
using
System;
2
using
System.Collections.Generic;
3
using
System.Text;
4
using
System.Xml;
5
using
System.IO;
6
7
namespace
htmlWeb
8
{
9
public
class
CreateHtm
10
{
11
12
13
private
string
fileName;
14
15
public
String FileName
16
{
17
  ......
ASP.NET³£¼û°²È«ÎÊÌâ
Ò»¡¢SQLÓï¾ä©¶´
Ðí¶à³ÌÐòÔ±ÔÚÓÃsqlÓï¾ä½øÐÐÓû§ÃÜÂëÑé֤ʱÊÇͨ¹ýÒ»¸öÀàËÆÕâÑùµÄÓï¾äÀ´ÊµÏֵģº
Sql="Select * from Óû§±í where ÐÕÃû = '" + name + "' and ÃÜÂë = '" + password + "'"
ͨ¹ý·ÖÎö¿ÉÒÔ·¢ÏÖ£¬ÉÏÊöÓï¾ä´æÔÚ×ÅÖÂÃüµÄ©¶´¡£µ±ÎÒÃÇÔÚÓû§Ãû³ÆÖÐÊäÈëÏÂÃæµÄ×Ö·û´®Ê±£ºtest' or '1' = '1£¬È»ºó¿ÚÁîËæ±ãÊäÈ룬ÎÒÃÇÉèΪaaa¡£±äÁ¿´ú»»ºó£¬sqlÓï¾ä¾Í±ä³ÉÁËÏÂÃæµÄ×Ö·û´®£º
Sql="Select * from Óû§±í where ÐÕÃû='test' or '1' = '1' and ÃÜÂë = 'aaa'
ÎÒÃǶ¼ÖªµÀselectÓï¾äÔÚÅжϲéѯÌõ¼þʱ£¬Óöµ½»ò£¨or£©²Ù×÷¾Í»áºöÂÔÏÂÃæµÄÓ루and£©²Ù×÷£¬¶øÔÚÉÏÃæµÄÓï¾äÖÐ1=1µÄÖµÓÀԶΪtrue£¬ÕâÒâζ×ÅÎÞÂÛÔÚÃÜÂëÖÐÊäÈëʲôֵ£¬¾ùÄÜͨ¹ýÉÏÊöµÄÃÜÂëÑéÖ¤£¡
Select * from Óû§±í where ÐÕÃû = 'ºÏ·¨µÄÐÕÃû' or '1' = '1' and ÃÜÂë = '' //ÎÞÐèÃÜÂë
Select * from Óû§±í where ÐÕÃû = '' or '1'='1' and ÃÜÂë = '' or '1'='1' //ÎÞÐèÓû§ÃûºÍÃÜÂë
Select * from Óû§±í where ÐÕÃû = 'ºÏ·¨µÄÐÕÃû' --' and ÃÜÂë = '' //ÎÞÐèÃÜÂë
½â¾ö·½·¨£º
·ÀÖ¹ASP.NETÓ¦Óñ»SQL×¢Èëʽ¹¥»÷´³Èë²¢²»ÊÇÒ»¼þÌرð ......
C#:³ÉÔ±±äÁ¿Ê××Öĸ´óд¶øÇÒÇ°Ãæ¼ÓÏ»®Ïß
1.Á¬½Ó¶ÔÏó¾²Ì¬Óë·Ç¾²Ì¬ÎÊÌâ
2.Êý¾Ý·ÃÎÊÀàΪʲô²»ÄÜÅÉÉúÓëDBConnection
3.CatchµÄ×÷Óã¬ÒÔ¼°ÎªÊ²Ã´¿ÉÒÔÔÚÕâÀïÊ¡µô
4.ÔÚÊý¾Ý·ÃÎÊ·½·¨ÖУ¬ÎªÊ²Ã´²»Ö±½ÓʵÀý»¯ List<NationData> list;
5.Ö´ÐÐÔöɾ¸ÄΪʲô²»ÄÜ´«ÈëSqlÓï¾ä½øÐвÙ×÷
6.ÔÚInfoDAÀàÖУ¬É¾³ýinfo±íµÄʱºòΪʲô²»ÏÈ É¾³ýwork family±íÖеÄÏà¹ØÄÚÈÝ
Web¿ª·¢
web·þÎñÆ÷µÄ×÷Óãº
request ½ÓÊÕÇëÇó
response ·¢ËÍÇëÇó
1.Á½ÖÖweb·þÎñÆ÷
IIS
ASP.NET Development Server
2.·¢²¼Õ¾µã
XCOPY
¸´ÖÆÍøÕ¾
·¢²¼ÍøÕ¾
3.ÏîÄ¿ÖеĽâ¾ö·½°¸
½â¾ö·½°¸£º WorSpace ¹ÜÀíÏîÄ¿
ÏîÄ¿£º Project Ï൱ÓÚjavaÖеŤ³Ì ¹ÜÀíÎļþ
web.config:ÏîÄ¿ÖеÄÅäÖÃÎļþ Ï൱ÓÚjavaÖеĺó ׺ΪxmlµÄÎļþ
.aspx: Ò³ÃæÎļþ Ï൱ÓÚjavaÖеÄjsp
.aspx.cs: Ò³Ãæ´úÂëÎļþ Ï൱ÓÚjavaÖÐjspǶ ......
<httpHandlers>
<remove verb="*" path="*.asmx"/>
<!--
<add verb="*" path="*.asmx" validate="false" type="Microsoft.Web.Script.Services.ScriptHandlerFactory, Microsoft.Web.Extensions, Version=1.0.61025.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35"/>
<add verb="GET" path="ScriptResource.axd" type="Microsoft.Web.Handlers.ScriptResourceHandler" validate="false"/>
-->
<!--°ÑÉÏÃæµÄ¸ÄΪÈçÏÂ,1.0 rc°æ,ÒѾ°ÑÃüÃû¿Õ¼ä¸ÄΪÁËsystem-->
<add verb="*" path="*.asmx" validate="false" type="System.Web.Script.Services.ScriptHandlerFactory, System.Web.Extensions, Version=1.0.61025.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35"/>
<add verb="GET" path="ScriptResource.axd" type="System.Web.Handlers.ScriptResourceHandler" valid ......
Ò»¡¢Ä¿Ç°ÔÚASP.NETÖÐÒ³Ãæ´«Öµ¹²ÓÐÕâô¼¸ÖÖ·½Ê½£º
µÚÒ»ÖÖ·½·¨£º
¡¡¡¡Í¨¹ýURLÁ´½ÓµØÖ·´«µÝ
send.aspx:
protected void Button1_Click(object sender, EventArgs e)
{
Request.Redirect("Default2.aspx?username=honge");
}
receive.aspx:
string username = Request.QueryString["username"];//ÕâÑù¿ÉÒԵõ½²ÎÊýÖµ¡£
µÚ¶þÖÖ·½·¨£º
¡¡¡¡Í¨¹ýpost·½Ê½
send.aspx receive.aspxstring username = Ruquest.Form["receive"];
¡¡¡¡µÚÈýÖÖ·½·¨£º
ͨ¹ýsession
send.aspx:
protected void Button1_Click(object sender, EventArgs e)
{
Session["username"] = "honge";
Request.Redirect("Default2.aspx");
}
receive.aspx:
string username = Session["username"];ÕâÑù¿ÉÒ ......