ÕßÕßÈí¼þ ASPÈçºÎ»ñÈ¡ÕæÊµIPµØÖ·
ÔÚ ASP ÖÐʹÓà Request.ServerVariables("REMOTE_ADDR") À´È¡µÃ¿Í»§¶ËµÄ IP µØÖ·£¬µ«Èç¹û¿Í»§¶ËÊÇʹÓôúÀí·þÎñ
Æ÷À´·ÃÎÊ£¬ÄÇÈ¡µ½µÄ¾ÍÊÇ´úÀí·þÎñÆ÷µÄ IP µØÖ·£¬¶ø²»ÊÇÕæÕýµÄ¿Í»§¶Ë IP µØÖ·¡£ÒªÏë͸¹ý´úÀí·þÎñÆ÷È¡µÃ¿Í»§¶ËµÄÕæÊµ
IP µØÖ·£¬¾ÍҪʹÓà Request.ServerVariables("HTTP_X_FORWARDED_FOR") À´¶ÁÈ¡¡£
¡¡¡¡²»¹ýҪעÒâµÄÊ£¬²¢²»ÊÇÿ¸ö´úÀí·þÎñÆ÷¶¼ÄÜÓà Request.ServerVariables("HTTP_X_FORWARDED_FOR") À´¶ÁÈ¡¿Í»§¶Ë
µÄÕæÊµ IP£¬ÓÐЩÓô˷½·¨¶ÁÈ¡µ½µÄÈÔÈ»ÊÇ´úÀí·þÎñÆ÷µÄ IP¡£
¡¡¡¡»¹ÓÐÒ»µãÐèҪעÒâµÄÊÇ£ºÈç¹û¿Í»§¶ËûÓÐͨ¹ý´úÀí·þÎñÆ÷À´·ÃÎÊ£¬ÄÇôÓà Request.ServerVariables
("HTTP_X_FORWARDED_FOR") È¡µ½µÄÖµ½«Êǿյġ£Òò´Ë£¬Èç¹ûÒªÔÚ³ÌÐòÖÐʹÓô˷½·¨£¬¿ÉÒÔÕâÑù´¦Àí£º
......
userip = Request.ServerVariables("HTTP_X_FORWARDED_FOR")
If userip = "" Then userip = Request.ServerVariables("REMOTE_ADDR")
......
¡¡¡¡¼´£ºÈç¹û¿Í»§¶Ëͨ¹ý´úÀí·þÎñÆ÷£¬ÔòÈ¡ HTTP_X_FORWARDED_FOR µÄÖµ£¬Èç¹ûûͨ¹ý´úÀí·þÎñÆ÷£¬¾ÍÈ¡ REMOTE_ADDR µÄÖµ¡£
Ïà¹ØÎĵµ£º
¼ÇµÃÔÚ½¨Á¢Ò»¸öÎļþ¼Ð"updata"
saveannounce_upload.asp ÉÏ´«Ò³
------------------------------------
<html>
<head>
<style type="text/css
">
body {font-size:9pt;}
input {font-size:9pt;}
</style>
<title>ÎļþÉÏ´«</title>
</head& ......
Ö»ÄÜÊäÈë1¸öÊý×Ö
±í´ïʽ ^\d$
ÃèÊö Æ¥ÅäÒ»¸öÊý×Ö
Æ¥ÅäµÄÀý×Ó 0,1,2,3
²»Æ¥ÅäµÄÀý×Ó
Ö»ÄÜÊäÈën¸öÊý×Ö
±í´ïʽ ^\d{n}$ ÀýÈç^\d{8}$
ÃèÊö Æ¥Åä8¸öÊý×Ö
Æ¥ÅäµÄÀý×Ó 12345678,22223334,12344321
²»Æ¥ÅäµÄÀý×Ó
Ö»ÄÜÊäÈëÖÁÉÙn¸öÊý×Ö
±í´ïʽ ^\d{n,}$ ÀýÈç^\d{8, ......
ActiveConnection ÉèÖûò·µ»ØCommand¶ÔÏóµÄÁ¬½ÓÐÅÏ¢£¬¸ÃÊôÐÔ¿ÉÒÔÊÇÒ»¸öConnection¶ÔÏó»òÁ¬½Ó×Ö·û´®¡£
CommandText ÉèÖûò·µ»Ø¶ÔÊý¾ÝÔ´µÄÃüÁî´®£¬Õâ¸ö´®¿ÉÒÔÊÇSQLÓï¾ä¡¢±í¡¢´¢´æ¹ý³Ì»òÊý¾ÝÌṩÕßÖ§³ÖµÄÈÎ ºÎÌØÊâÓÐЧµÄÃüÁîÎı¾¡£
Prepared Ìá³öÔÚµ÷ÓÃCommand¶ÔÏóµÄExecute·½·¨Ê±£¬ÊÇ·ñ½«²éѯµÄ±àÒë½á¹û´¢´æÏÂÀ´¡£Èç¹û½«¸ ......
ºÜ¶àʱºò,ÎÒÃDzÉÓÃÔʼµÄ·½·¨À´½â¾öÒ»ÐÐÄÚÑ»·3ÕÅͼƬ,Èç¹ûÉÏ´«ÕßÖ»ÉÏ´«ÁË2ÕÅͼƬ,ÄÇô2ÕÅͼƬ¼äµÄ¾àÀë»áºÜ´ó,ÒòΪȱÉÙÁËÒ»¸ö<td> </td>.
<table border="0" cellpadding="0" cellspacing="0">
<%
dim rs,sqltext
set rs = Server.CreateObject("adodb.recordset")
sqltext="sel ......
set conn=server.createobject("adodb.connection")
conn.open "driver={microsoft access driver (*.mdb)};dbq=F:\\ajaxpro\\App_Data\\server.mdb"
Dim StrSQL,RS
StrSQL="SELECT*from Manager WHERE ID='"&username&"'"
StrSQL=StrSQL&"AND Pin='"&passwor ......