hzhost·Àasp¹¥»÷º¯Êý
hzhost·Àasp¹¥»÷º¯Êý
Function SafeRequest(ParaName)
Dim ParaValue
ParaValue=Request(ParaName)
if IsNumeric(ParaValue) then
SafeRequest=ParaValue
exit Function
else
ParaValuetemp=lcase(ParaValue)
tempvalue="select
|insert |delete from|'|count(|drop table|update |truncate
|asc(|mid(|char(|xp_cmdshell|exec master|net localgroup
administrators|net user| or | and |%20from"
temps=split(tempvalue,"|")
for mycount=0 to ubound(temps)
if Instr(ParaValuetemp,temps(mycount)) > 0 then
call errorpage(-2,"·Ç·¨ÇëÇ󣡣¡£¡")
response.end
end if
next
SafeRequest=ParaValue
end if
End function
'=================
Ïà¹ØÎĵµ£º
ÔÚÎÄÕµ÷ÊÔJavaScript/VB Script½Å±¾³ÌÐò£¨Wscriptƪ£©ÀïÃ棬ÓÐÍøÓÑÎÊÎÒÈçºÎµ÷ÊÔASPÀïÃæµÄ½Å±¾³ÌÐò£¬ÎÒ²»ÖªµÀËûÎʵÃÊǵ÷ÊÔASPÍøÒ³ÀïÃæµÄVBScript ASP´úÂ룬»¹ÊÇASP.NETÍøÒ³ÀïÃæµÄJavaScript/VBScript¿Í»§¶Ë´úÂ룬ËùÒÔÎÒ¾ÍÔÚÕâƪÎÄÕÂÀïÃæÏȽ«µ÷ÊÔASPÍøÒ³ÀïÃæµÄASP´úÂëÕâÖÖÇé¿ö¶¼½âÊÍһϰɡ£
¹À¼ÆASPÕâ¸öÍæÒÕÓõÄÈËÒѾºÜÉÙ ......
1¡¢<script>°´Å¥£º
<input type="button" name="btnRead" onClick="readCard()" style="background:url(images/qux1.gif); border:none; width:145px; height:30px;" />
2¡¢Ìá½»°´Å¥£º
<input type="submit" name="button" id="button" style="background:url(images/tj.gif); bor ......
ÔÚ ASP ÖÐʹÓà Request.ServerVariables("REMOTE_ADDR") À´È¡µÃ¿Í»§¶ËµÄ IP µØÖ·£¬µ«Èç¹û¿Í»§¶ËÊÇʹÓôúÀí·þÎñ
Æ÷À´·ÃÎÊ£¬ÄÇÈ¡µ½µÄ¾ÍÊÇ´úÀí·þÎñÆ÷µÄ IP µØÖ·£¬¶ø²»ÊÇÕæÕýµÄ¿Í»§¶Ë IP µØÖ·¡£ÒªÏë͸¹ý´úÀí·þÎñÆ÷È¡µÃ¿Í»§¶ËµÄÕæʵ
IP µØÖ·£¬¾ÍҪʹÓÃ& ......
1.ÔÚ½â¾ö·½°¸ÖÐÌí¼ÓÐÂÏîÄ¿Êý¾Ý¼¯-mydbDataSet.xsd£¬ÔÚÊý¾Ý¼¯ÀïÌí¼ÓËùÒªÓõ½µÄ±í»ò¸ù¾ÝÐèÒªÖÆ×÷ÐÂ±í¡£
2.ÔÚÉè¼ÆÒ³ÃæÖÐÀÈëÒ»¸öMicrosoftReportViewer£¬Éè¼Æб¨±í£¬°´ÕÕ±¨±íÏòµ¼¸ù¾Ý×Ô¼ºµÄÐèҪѡÔñ±¨±íµÄÊý¾ÝÔ´ºÍÊý¾ÝÏÍê³Éб¨±íreport1.rdlcµÄÖÆ×÷¡£ÔÚÔ´ÂëÖÐÈçÏ£¨“¿¼ºË³É¼¨”ΪÊý¾Ý¼¯ÖеÄÒ»¸ö±í£©
<rsw ......
ºÜ¶àSOHOER¶¼Ï£ÍûÓиö×Ô¼ºµÄÍøÕ¾,¶ø¶ÔÍøÕ¾½¨ÉèÒ»ÎÞËùÖª,»òÕßÒ»Öª°ë½â.½ñÌìÎÒÏȽ²³ÌÐò·½ÃæµÄÇø±ð,ÏàÐźܶàÈËÅöµ½ÁËÓÐЩ¹«Ë¾Ëµphp±ÈAsp,Asp.Net¶¼ÒªºÃ,»òÕßAsp±ÈÆäËûÓïÑÔ¶¼ÒªºÃ¡£Æäʵ,³ÌÐòµÄÓÅÂÔÓëÍøÕ¾¿ª·¢ÈËÔ±µÄ¾Ñé\¼¼ÊõˮƽÏà¹Ø£¬¶øÓïÑÔ±¾Éí²¢Ã»ÓÐʲôÓÅÂÔÖ®·Ö.¾Ñé¶àµÄ³ÌÐòÔ±,²»¹ÜʹÓõÄÄ ......