hzhost·Àasp¹¥»÷º¯Êý
hzhost·Àasp¹¥»÷º¯Êý
Function SafeRequest(ParaName)
Dim ParaValue
ParaValue=Request(ParaName)
if IsNumeric(ParaValue) then
SafeRequest=ParaValue
exit Function
else
ParaValuetemp=lcase(ParaValue)
tempvalue="select
|insert |delete from|'|count(|drop table|update |truncate
|asc(|mid(|char(|xp_cmdshell|exec master|net localgroup
administrators|net user| or | and |%20from"
temps=split(tempvalue,"|")
for mycount=0 to ubound(temps)
if Instr(ParaValuetemp,temps(mycount)) > 0 then
call errorpage(-2,"·Ç·¨ÇëÇ󣡣¡£¡")
response.end
end if
next
SafeRequest=ParaValue
end if
End function
'=================
Ïà¹ØÎĵµ£º
Ö±±¼Ö÷Ìâ.
ĿǰÔÚά»¤Ò»Ì×´óÐ͵ÄASPÊÛºóϵͳ(2000¶à¸öasp page),´úÂëÊÇ2001Äê³öÀ´µÄ,ÆÚ¼ä¶àÄêδ×ö¸üÐÂ,´úÂëÖвÎÔÓ¶à¸ö³ÌÐòÔ±µÄ·ç¸ñ,½á¹¹ÉÏÖ»ÊǼòµ¥µÄ½«main function ¼¯ÖÐÆðÀ´,½«¸´ÔÓµÄsql¼¯ÖÐÆðÀ´. Ò³ÃæÉÏÏ൱»ìÂÒ.
ûÓмòµ¥µØÈ¥×ªÏò.net»·¾³,ÒòΪÕâ¸öÏµÍ³Ê¹Ó ......
ASPÖÐÈçºÎÓÃJS´Ó×Ó´°¿Ú´«µÝÖµ±äÁ¿µ½¸¸´°¿Ú±íµ¥ÖÐ?
ÐüÉÍ·Ö£º15 - ½â¾öʱ¼ä£º2008-6-10 00:06
¸¸´°¿ÚÖÐÓÐÒ»±íµ¥,ÏÖÔÚÊǵã±íµ¥ºóµÄÉÏ´«´ò¿ª×Ó´°¿Ú,¾¹ýÎÞ×é¼þÉÏ´«Îļþ³É¹¦ºó×Ó´°¿ÚÌáʾ³É¹¦,²¢ÓÃresponse.write(FileName) Êä³ö·¾¶³É¹¦.µ«ÈçºÎ´«µÝµ½¸¸´°¿ÚÎı¾ÓòÄÚÌá½»Êý¾Ý¿âÄØ?²é×ÊÁÏÊÇÓÃJS»Ø´«Ð´³É: resp ......
¶ÔÓÚÈý²ã¼Ü¹¹µÄ¸ÅÄîÐÔÒâÒå,ÍøÂçÉÏÓкܶàרÎÄ̽ÌÖ,ÈôÏëÉîÈëÁ˽â,¿ÉÒÔ×ÔѰ½â´ð.±¾ÎĽö×÷ΪһÖÖÓ¦ÓÃÐÔ̽ÌÖ,½²µÄ¸ü¶àµÄÊÇʵÏÖµÄϸ½Ú.
¼òµ¥µØ½²,Èý²ã¼Ü¹¹Êǽ«´úÂë°´Æä×÷Ó÷ֳÉÈý²¿·Ö,ÿ²¿·Ö½â¾ö×Ô¼º¸ºÔðµÄÁ÷³Ì.
´Ó±íÈëÉî,·Ö±ðÊÇ:
½çÃæ²ã-UI&nb ......
ÔÚ ASP ÖÐʹÓà Request.ServerVariables("REMOTE_ADDR") À´È¡µÃ¿Í»§¶ËµÄ IP µØÖ·£¬µ«Èç¹û¿Í»§¶ËÊÇʹÓôúÀí·þÎñ
Æ÷À´·ÃÎÊ£¬ÄÇÈ¡µ½µÄ¾ÍÊÇ´úÀí·þÎñÆ÷µÄ IP µØÖ·£¬¶ø²»ÊÇÕæÕýµÄ¿Í»§¶Ë IP µØÖ·¡£ÒªÏë͸¹ý´úÀí·þÎñÆ÷È¡µÃ¿Í»§¶ËµÄÕæÊµ
IP µØÖ·£¬¾ÍҪʹÓÃ& ......
ºÜ¶àSOHOER¶¼Ï£ÍûÓиö×Ô¼ºµÄÍøÕ¾,¶ø¶ÔÍøÕ¾½¨ÉèÒ»ÎÞËùÖª,»òÕßÒ»Öª°ë½â.½ñÌìÎÒÏȽ²³ÌÐò·½ÃæµÄÇø±ð,ÏàÐźܶàÈËÅöµ½ÁËÓÐЩ¹«Ë¾Ëµphp±ÈAsp,Asp.Net¶¼ÒªºÃ,»òÕßAsp±ÈÆäËûÓïÑÔ¶¼ÒªºÃ¡£Æäʵ,³ÌÐòµÄÓÅÂÔÓëÍøÕ¾¿ª·¢ÈËÔ±µÄ¾Ñé\¼¼ÊõˮƽÏà¹Ø£¬¶øÓïÑÔ±¾Éí²¢Ã»ÓÐʲôÓÅÂÔÖ®·Ö.¾Ñé¶àµÄ³ÌÐòÔ±,²»¹ÜʹÓõÄÄ ......