aspµ¥Ò³Éú³É¾²Ì¬Ò³
½ñÌìÔÚÍøÉÏÕÒÁ˺þùØÓÚASPÉú³É¾²Ì¬Ò³µÄ´úÂë ×î¶àµÄ¾ÍÊÇ FSO·½·¨£¬Ä£°å·½·¨£¬µ«²»ÖªµÀ£¬ÎÒ°Ñ´úÂëÄÃÀ´Ö®ºó¶¼²»ºÃÓ㬾ÍÊÇÌṩÏÂÔصÄѹËõ°üÀïÃæдºÃµÄÎÒÔËÐж¼ÊÇÓдíÎ󡣡£
²»¹ý»ÆÌì²»¸ºÓÐÐÄÈË£¬ÎÒÖÕÓÚÕÒµ½Ò»¸öµ¥Ò³Éú³É¾²Ì¬µÄ·½·¨£¬ÄóöÀ´¸ø´ó¼Ò·ÖÏí
<!-- ======================== Éú³É¾²Ì¬·½·¨ ====================== -->
<%
Function GetPage(url)
'»ñµÃÎļþÄÚÈÝ
dim Retrieval
Set Retrieval = CreateObject("Microsoft.XMLHTTP")
With Retrieval
.Open "Get", url, False ', "", ""
.Send
GetPage = BytesToBstr(.ResponseBody)
End With
Set Retrieval = Nothing
End Function
Function BytesToBstr(body)
dim objstream
set objstream = Server.CreateObject("adodb.stream")
objstream.Type = 1
objstream.Mode =3
objstream.Open
objstream.Write body
objstream.Position = 0
objstream.Type = 2
objstream.Charset = "GB2312"
BytesToBstr = objstream.ReadText
objstream.Close
set objstream = nothing
End Function
on error resume next
Url=" http://www.ent-wangchong.cn/index.asp"'Òª¶ÁÈ¡µÄÒ³ÃæµØÖ·
response.write "¿ªÊ¼¸üÐÂÊ×Ò³..."
wstr = GetPage(Url)
'response.write(wstr)
Set fs=Server.CreateObject("Scripting.FileSystemObject")
'if not MyFile.FolderExists(server.MapPath("/html/")) then
'MyFile.CreateFolder(server.MapPath("/html/"))'
'end if
'Òª´æ·ÅµÄÒ³ÃæµØÖ·
dizhi=server.MapPath("index.html")
If (fs.FileExists(dizhi)) Then
fs.DeleteFile(dizhi)
End If
Set CrFi=fs.CreateTextFile(dizhi)
Crfi.Writeline(wstr)
set CrFi=nothing
set fs=nothing
response.write "¸üÐÂÍê³É£¡"
response.End()
%>
±£´æΪasp¾ÍÐУ¬ÐèÒªÉú³É£¬Ö´ÐÐÒ»ÏÂÕâ¸öÎļþ£¡
Ïà¹ØÎĵµ£º
´´½¨Ò»¸ö¼òµ¥µÄASPÒ³Ãæ
ÔÚ·þÎñÆ÷¶Ë±àдµÄÎļþ index.asp £º
ÒÔÏÂΪÒýÓÃÄÚÈÝ£º
<%@LANGUAGE="JSCRIPT" CODEPAGE="65001"%>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"&g ......
³£ÓõĽű¾ÓïÑÔÓÐ Javascript ºÍ VBscript ¡£
ʹÓÃÄÄÖÖÓïÑÔÐèÏÈÉ趨¡£ÈçÉϽڴúÂëÖеÄ<%@ LANGUAGE="JSCRIPT" ... %>¡£
Èç¹ûûÓÐÖ¸¶¨£¬ÏµÍ³¾Í»áʹÓà IIS ³ÌÐòÖ¸¶¨µÄ½Å±¾ÓïÑÔ¡£
VBscript Ó÷¨
VBscript Ò»°ã·ÅÔÚ <head> Óë </head> ÄÚµÄ <% ºÍ %> Ö®¼ä¡£
´ú ......
VBSCRIPT µÄÊý¾ÝÀàÐÍ
VBSCRIPT Ö»ÓÐÒ»ÖÖÊý¾ÝÀàÐÍ£ºvariant £¬³ÌÐò¸ù¾ÝÉÏÏÂÎÄÀ´ÅÐ¶Ï variant ΪÊý×ÖÀàÐÍ»¹ÊÇ×Ö·û´®ÀàÐÍ¡£
ÒýºÅÄÚµÄÊý×Ö±»¿´³É×Ö·û´®£¬È磺a="12" £»
²»´øÒýºÅµ±È»¾ÍÊÇÊý×Ö£¬È磺b=13 ¡£
ʵÀý£º
ÒÔÏÂΪÒýÓÃÄÚÈÝ£º
<%@LANGUAGE="VBSCRIPT" CODEPAGE="65001"%>
<!DOCTYPE html PUBLIC "-//W3C// ......
Á÷³Ì¿ØÖÆÓï¾ä
ÒÔÏÂÓÃʵÀýÀ´ÑÝʾÁ÷³Ì¿ØÖÆÓï¾äÖеÄÑ»·Óï¾äÓëÌõ¼þÓï¾ä£º
Ìõ¼þÓï¾ä£ºif ...else
ÒÔÏÂΪÒýÓÃÄÚÈÝ£º
<%@LANGUAGE="VBSCRIPT" CODEPAGE="65001"%>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns ......
1£ºSQL ×¢È룺
½â¾ö·½°¸£º
a. Õâ¸öÎÊÌâÖ÷ÒªÊÇÓÉÓÚ´«ÈëÌØÊâ×Ö·ûÒýÆðµÄÎÒÃÇ¿ÉÒÔÔÚ¶ÔÊäÈëµÄÓû§ÃûÃÜÂë½øÈë¹ýÂËÌØÊâ×Ö·û´¦Àí¡£
b. ʹÓô洢¹ý³Ìͨ¹ý´«Èë²ÎÊýµÄ·½·¨¿É½â¾ö´ËÀàÎÊÌ⣨עÒ⣺ÔÚ´æ´¢¹ý³ÌÖв»¿ÉʹÓÃÆ´½ÓʵÏÖ£¬²»È»ºÍûÓô洢¹ýºÍÊÇÒ»ÑùµÄ£©¡£
2. XSS£¨¿çÕ¾½Å±¾¹¥»÷£©£º
½â¾ö·½°¸£º
¡¡¡¡a. ͨ¹ýÔÚ Page Ö¸Áî»ò Å ......