·¢Ò»¸ö×Ô¼º·â×°µÄAsp DllÎļþ
µ÷ÊÔ³ÌÐòºÍ×ö³ÌÐòµÄʱºò£¬ºÃ¶àÖظ´µÄ´úÂëÒ»Ö±ÊäÈëºÜÂé·³£¬Ò²ºÜûÓÐЧÂÊ£¬·â×°Ò»¸ö×Ô¼ºµÄAsp°ü°ü£¬Í¦ÓÐÓеÄ
ÏÂÔظö¾«¼ò°æµÄVB6.0£¬Ð½¨ ActiveX dll£¬ÒÔÏÂÊÇ·â×°µÄ´úÂ룬ÖØÒª²¿·Ö¶¼ÓÐ×¢ÊÍ£¬²»¶®¿ÉÒÔ¸úÌû
Option Explicit
Public Resp As Response, Requ As Request, Appl As Application, Serv As Server, Sess As Session 'ÄÚÖöÔÏóµÄ±äÁ¿ÉùÃ÷
Public ObjConn As Object, StrSql As String, ObjRs As Object, ObjFso As Object 'È«¾Ö¼¶±äÁ¿
'=============================Md5²¿·ÖÉùÃ÷=============================
Private Const BITS_TO_A_BYTE = 8
Private Const BYTES_TO_A_WORD = 4
Private Const BITS_TO_A_WORD = 32
Private m_lOnBits(30), m_l2Power(30) 'Êý×éÉùÃ÷
'=====================================================================
Public Sub OnStartPage(MyObj As ScriptingContext)
Set Resp = MyObj.Response
Set Requ = MyObj.Request
Set Serv = MyObj.Server
Set Appl = MyObj.Application
Set Sess = MyObj.Session
Sess.Timeout = 30
End Sub
Public Sub OnEndPage()
Set Resp = Nothing
Set Requ = Nothing
Set Serv = Nothing
Set Appl = Nothing
Set Sess = Nothing
End Sub
'----------------------------------------------------------------------------------
'----------------------------------------------------------------------------------
'---------- º¯Êý±í ·½·¨ ÓëÍâÀ´²ÎÊý´«µÝ -----------
'----------------------------------------------------------------------------------
'----------------------------------------------------------------------------------
'W ·½·¨ Èë¿ÚÖµ£ºStrWords As String ·µ»ØÖµ£ºÖ±½ÓÊä³ö
'R ·½·¨ Èë¿ÚÖµ£ºStrUrl As Strin
Ïà¹ØÎĵµ£º
VBSCRIPT µÄÊý¾ÝÀàÐÍ
VBSCRIPT Ö»ÓÐÒ»ÖÖÊý¾ÝÀàÐÍ£ºvariant £¬³ÌÐò¸ù¾ÝÉÏÏÂÎÄÀ´ÅÐ¶Ï variant ΪÊý×ÖÀàÐÍ»¹ÊÇ×Ö·û´®ÀàÐÍ¡£
ÒýºÅÄÚµÄÊý×Ö±»¿´³É×Ö·û´®£¬È磺a="12" £»
²»´øÒýºÅµ±È»¾ÍÊÇÊý×Ö£¬È磺b=13 ¡£
ʵÀý£º
ÒÔÏÂΪÒýÓÃÄÚÈÝ£º
<%@LANGUAGE="VBSCRIPT" CODEPAGE="65001"%>
<!DOCTYPE html PUBLIC "-//W3C// ......
±äÁ¿ÉêÃ÷£¬ÃüÃû¹æÔòÓëÔËËã·û
1£¬ÓÃÈýÖÖÓï¾äÀ´ÉùÃ÷±äÁ¿£ºdim £¬public Óë private £¬±È½Ï³£ÓõĻ¹ÊÇ dim ¡£
È磺<% dim a %> £»<% dim a , b , c %>
2£¬ÃüÃû¹æÔò£º
<1> ±äÁ¿µÄµÚÒ»¸ö×Ö·û±ØÐëÊÇ×Öĸ£¬Êý×ֺͷûºÅ¶¼²»ÐС£
<2> ²»ÄÜǶÈë¾äµã¡£
<3> ³¤¶È²»Äܳ¬¹ý255¸ö×Ö·û¡£
<4> ......
Á÷³Ì¿ØÖÆÓï¾ä
ÒÔÏÂÓÃʵÀýÀ´ÑÝʾÁ÷³Ì¿ØÖÆÓï¾äÖеÄÑ»·Óï¾äÓëÌõ¼þÓï¾ä£º
Ìõ¼þÓï¾ä£ºif ...else
ÒÔÏÂΪÒýÓÃÄÚÈÝ£º
<%@LANGUAGE="VBSCRIPT" CODEPAGE="65001"%>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns ......
1£ºSQL ×¢È룺
½â¾ö·½°¸£º
a. Õâ¸öÎÊÌâÖ÷ÒªÊÇÓÉÓÚ´«ÈëÌØÊâ×Ö·ûÒýÆðµÄÎÒÃÇ¿ÉÒÔÔÚ¶ÔÊäÈëµÄÓû§ÃûÃÜÂë½øÈë¹ýÂËÌØÊâ×Ö·û´¦Àí¡£
b. ʹÓô洢¹ý³Ìͨ¹ý´«Èë²ÎÊýµÄ·½·¨¿É½â¾ö´ËÀàÎÊÌ⣨עÒ⣺ÔÚ´æ´¢¹ý³ÌÖв»¿ÉʹÓÃÆ´½ÓʵÏÖ£¬²»È»ºÍûÓô洢¹ýºÍÊÇÒ»ÑùµÄ£©¡£
2. XSS£¨¿çÕ¾½Å±¾¹¥»÷£©£º
½â¾ö·½°¸£º
¡¡¡¡a. ͨ¹ýÔÚ Page Ö¸Áî»ò Å ......
<html xmlns="http://www.w3.org/1999/xhtml" >
<HEAD>
<title>¶àÎļþÉÏ´« </title>
<script language="JavaScript">
function addFile()
{
var str = ' <br / ......