ASP ±à³ÌÖÐ 20 ¸ö·Ç³£ÓÐÓõÄÀý×Ó
1.ÈçºÎÓÃAspÅжÏÄãµÄÍøÕ¾µÄÐéÄâÎïÀí·¾¶
´ð£ºÊ¹ÓÃMappath·½·¨
< p align="center" >< font size="4" face="Arial" >< b >
The Physical path to this virtual website is:
< /b >< /font >
< font color="#FF0000" size="6" face="Arial" >
< %= Server.MapPath("\")% >
< /font >< /p >
2.ÎÒÈçºÎÖªµÀʹÓÃÕßËùÓõÄä¯ÀÀÆ÷?
´ð£ºÊ¹ÓÃthe Request object·½·¨
strBrowser=Request.ServerVariables("HTTP_USER_AGENT")
If Instr(strBrowser,"MSIE") < > 0 Then
Response.redirect("ForMSIEOnly.htm")
Else
Response.redirect("ForAll.htm")
End If
3.ÈçºÎ¼ÆËãÿÌìµÄƽ¾ù·´¸´·ÃÎÊÈËÊý
´ð£º½â¾ö·½·¨
< % startdate=DateDiff("d",Now,"01/01/1990")
if strdate< 0 then startdate=startdate*-1
avgvpd=Int((usercnt)/startdate) % >
ÏÔʾ½á¹û
< % response.write(avgvpd) % >
that is it.this page have been viewed since November 10,1998
4.ÈçºÎÏÔÊ¾Ëæ»úͼÏó
< % dim p,ppic,dpic
ppic=12
randomize
p=Int((ppic*rnd)+1)
dpic="graphix/randompics/"&p&".gif"
% >
ÏÔʾ
< img src="< %=dpic% >" >
5.ÈçºÎ»Øµ½ÏÈǰµÄÒ³Ãæ
´ð£º< a href="< %=request.serverVariables("Http_REFERER")% >" >preivous page< /a >
»òÓÃͼƬÈ磺< img src="arrowback.gif" alt="< %=request.serverVariables("HTTP_REFERER")% >" >
6.ÈçºÎÈ·¶¨¶Ô·½µÄIPµØÖ·
´ð£º< %=Request.serverVariables("REMOTE_ADDR)% >
7.ÈçºÎÁ´½áµ½Ò»¸±Í¼Æ¬ÉÏ
´ð£º< % @Languages=vbscript % >
< % response.expires=0
strimagename="graphix/errors/erroriamge.gif"
response.redirect(strimagename)
% >
8.Ç¿ÆÈÊäÈëÃÜÂë¶Ô»°¿ò
´ð£º°ÑÕâ¾ä»°·ÅÔØÒ³ÃæµÄ¿ªÍ·
< % response.status="401 not Authorized"
response.end
% >
9.ÈçºÎ´«µÝ±äÁ¿´ÓÒ»Ò³µ½ÁíÒ»Ò³
´ð£ºÓà HIDDEN ÀàÐÍÀ´´«µÝ±äÁ¿
< % form method="post" action="mynextpage.asp" >
< % for each item in request.form % >
< input namee="< %=item% >" type="HIDDEN"
value="< %=server.HTMLEncode(Request.form(item)) % >" >
< % next % >
< /form >
10.ΪºÎÎÒÔÚ asp ³ÌÐòÄÚʹ
Ïà¹ØÎĵµ£º
VBSCRIPT µÄÊý¾ÝÀàÐÍ
VBSCRIPT Ö»ÓÐÒ»ÖÖÊý¾ÝÀàÐÍ£ºvariant £¬³ÌÐò¸ù¾ÝÉÏÏÂÎÄÀ´ÅÐ¶Ï variant ΪÊý×ÖÀàÐÍ»¹ÊÇ×Ö·û´®ÀàÐÍ¡£
ÒýºÅÄÚµÄÊý×Ö±»¿´³É×Ö·û´®£¬È磺a="12" £»
²»´øÒýºÅµ±È»¾ÍÊÇÊý×Ö£¬È磺b=13 ¡£
ʵÀý£º
ÒÔÏÂΪÒýÓÃÄÚÈÝ£º
<%@LANGUAGE="VBSCRIPT" CODEPAGE="65001"%>
<!DOCTYPE html PUBLIC "-//W3C// ......
°ÑFCKeditorǶÈëµ½ASPµ±ÖÐÓÃÀ´´æÈ¡Êý¾ÝºÍÉÏ´«Îļþʱ³öÏÖÁËÂÒÂëÎÊÌâ£¬ÍøÉϲéÁËϲÅÖªµÀ×Ô¼º×öASPÊÇgb2312µÄ±àÂ룬¶øfckeditorĬÈϵıàÂëÊÇutf-8,Òò´Ë³öÏÖÁËÂÒÂëÎÊÌâ¡£
ÍøÉÏÕÒÁËһЩһЩ½â¾ö°ì·¨£¬×îÖÕÓÐÓõÄÄÃÀ´°É¡£ÔÚFCKeditor/editor/filemanager/connector/aspĿ¼ÏÂÓÐÁ½¸ö ......
Ò»¡¢Ä¾ÂíÉú³É
aspľÂí´úÂë¼ÓÃÜ£¬Í¼Æ¬ºÏ²¢£¬Îļþʱ¼äÐ޸쬻¹ÓÐÒªÃüµÄϵͳ©¶´ÀûÓÃ
ͼƬºÍľÂíºÏ²¢ÃüÁ
copy 1.gif /b + asp.asp /a asp.gif
¶þ¡¢Ä¾ÂíÉÏ´«
Èç¹ûºǫ́ûÓÐÀàËÆÊý¾Ý¿â±¸·Ý¹¦ÄÜ£¬¿ÉÒÔÉú³ÉÐÂÎļþ£¬»òÕßÖ±½ÓÐÞ¸ÄÎļþ¡£ÄÇôºÜÄÑÖ±½ÓÈÃľÂíÔËÐУ¬²»¹ý»¹ÊÇÓÐһЩ·½·¨£¬¿ÉÒÔ¿¼ÂÇ¡£
1¡¢Èç¹ ......
1£ºSQL ×¢È룺
½â¾ö·½°¸£º
a. Õâ¸öÎÊÌâÖ÷ÒªÊÇÓÉÓÚ´«ÈëÌØÊâ×Ö·ûÒýÆðµÄÎÒÃÇ¿ÉÒÔÔÚ¶ÔÊäÈëµÄÓû§ÃûÃÜÂë½øÈë¹ýÂËÌØÊâ×Ö·û´¦Àí¡£
b. ʹÓô洢¹ý³Ìͨ¹ý´«Èë²ÎÊýµÄ·½·¨¿É½â¾ö´ËÀàÎÊÌ⣨עÒ⣺ÔÚ´æ´¢¹ý³ÌÖв»¿ÉʹÓÃÆ´½ÓʵÏÖ£¬²»È»ºÍûÓô洢¹ýºÍÊÇÒ»ÑùµÄ£©¡£
2. XSS£¨¿çÕ¾½Å±¾¹¥»÷£©£º
½â¾ö·½°¸£º
¡¡¡¡a. ͨ¹ýÔÚ Page Ö¸Áî»ò Å ......
ÏÖÔÚÖ÷Á÷µÄÍøÕ¾¿ª·¢ÓïÑÔÎÞÍâºõasp¡¢php¡¢asp.net¡¢jspµÈ¡£
ÍøÒ³´Ó¿ªÊ¼¼òµ¥µÄhmtlµ½¸´ÔӵķþÎñÓïÑÔ£¬×ß¹ýÁË10¶à¸öÄêÍ·£¬¸÷ÖÖ¼¼Êõ²ã³ö²»Çµ¥¸öµÄÖ÷Á÷¼¼ÊõÒ²ÔÚ²»¶Ï·Ðµİ汾£¬ÏÖÔÚ·ÖÎöϸ÷ÖÖÓïÑÔµÄÇø±ð¡¢ÓÅÊÆ¡¢ÁÓÊÆ¡¢¿ª·¢×¢ÒâÊÂÏ
......