ASP ÄÚ½¨¶ÔÏó
Active Server Pages ÌṩÄÚ½¨¶ÔÏó£¬ÕâЩ¶ÔÏóʹÓû§¸üÈÝÒ×ÊÕ¼¯Í¨¹ýä¯ÀÀÆ÷ÇëÇó·¢Ë͵ÄÐÅÏ¢¡¢ÏìÓ¦ä¯ÀÀÆ÷ÒÔ¼°´æ´¢Óû§ÐÅÏ¢£¨ÈçÓû§Ê×Ñ¡Ï¡£±¾ÎļòҪ˵Ã÷ÿһ¸ö¶ÔÏó¡£
Application ¶ÔÏó
¿ÉÒÔʹÓà Application ¶ÔÏóʹ¸ø¶¨Ó¦ÓóÌÐòµÄËùÓÐÓû§¹²ÏíÐÅÏ¢¡£
Request ¶ÔÏó
¿ÉÒÔʹÓà Request ¶ÔÏó·ÃÎÊÈκÎÓà HTTP ÇëÇ󴫵ݵÄÐÅÏ¢£¬°üÀ¨´Ó HTML ±í¸ñÓà POST ·½·¨»ò GET ·½·¨´«µÝµÄ²ÎÊý¡¢cookie ºÍÓû§ÈÏÖ¤¡£Request ¶ÔÏóʹÄúÄܹ»·ÃÎÊ·¢Ë͸ø·þÎñÆ÷µÄ¶þ½øÖÆÊý¾Ý£¬ÈçÉÏÔØµÄÎļþ¡£
Response ¶ÔÏó
¿ÉÒÔʹÓà Response ¶ÔÏó¿ØÖÆ·¢Ë͸øÓû§µÄÐÅÏ¢¡£°üÀ¨Ö±½Ó·¢ËÍÐÅÏ¢¸øä¯ÀÀÆ÷¡¢Öض¨Ïòä¯ÀÀÆ÷µ½ÁíÒ»¸ö URL »òÉèÖà cookie µÄÖµ¡£
Server ¶ÔÏó
Server ¶ÔÏóÌṩ¶Ô·þÎñÆ÷Éϵķ½·¨ºÍÊôÐÔ½øÐеķÃÎÊ¡£×î³£Óõķ½·¨ÊÇ´´½¨ ActiveX ×é¼þµÄʵÀý (Server.CreateObject)¡£ÆäËû·½·¨ÓÃÓÚ½« URL »ò HTML ±àÂë³É×Ö·û´®£¬½«ÐéÄâ·¾¶Ó³Éäµ½ÎïÀí·¾¶ÒÔ¼°ÉèÖýű¾µÄ³¬Ê±ÆÚÏÞ¡£
Session ¶ÔÏó
¿ÉÒÔʹÓà Session ¶ÔÏó´æ´¢Ìض¨µÄÓû§»á»°ËùÐèµÄÐÅÏ¢¡£µ±Óû§ÔÚÓ¦ÓóÌÐòµÄÒ³Ö®¼äÌø×ªÊ±£¬´æ´¢ÔÚ Session ¶ÔÏóÖеıäÁ¿²»»áÇå³ý£»¶øÓû§ÔÚÓ¦ÓóÌÐòÖзÃÎÊҳʱ£¬ÕâЩ±äÁ¿Ê¼ÖÕ´æÔÚ¡£Ò²¿ÉÒÔʹÓà Session ·½·¨ÏÔʽµØ½áÊøÒ»¸ö»á»°ºÍÉèÖÿÕÏлỰµÄ³¬Ê±ÆÚÏÞ¡£
ObjectContext ¶ÔÏó
¿ÉÒÔʹÓà ObjectContext ¶ÔÏóÌá½»»ò³·ÏûÓÉ ASP ½Å±¾³õʼ»¯µÄÊÂÎñ¡£
Ïà¹ØÎĵµ£º
FormatDateTime
·µ»Ø±í´ïʽ£¬´Ë±í´ïʽÒѱ»¸ñʽ»¯ÎªÈÕÆÚ»òʱ¼ä¡£
FormatDateTime(Date[, NamedFormat])
²ÎÊý
Date
±ØÑ¡Ïî¡£Òª±»¸ñʽ»¯µÄÈÕÆÚ±í´ïʽ¡£
NamedFormat
¿ÉÑ¡ÏָʾËùʹÓõÄÈÕÆÚ/ʱ¼ä¸ñʽµÄÊýÖµ£¬Èç¹ûÊ¡ÂÔ£¬ÔòʹÓà vbGeneralDate¡£
ÉèÖÃ
NamedFormat ²ÎÊý¿ÉÒÔÓÐÒÔÏÂÖµ£º
³£Êý Öµ ÃèÊö
vbGeneralDate ......
Javascript »ù±¾½á¹¹ºÍÓï·¨
ÓëVBScriptÏàͬ£¬Ò²ÊÇдÔÚ <% %> Ö®¼ä¡£
Óà var ÉùÃ÷±äÁ¿£¬Óï¾äµÄĩβÓÓ;”¸ô¿ª¡£
ÒÔÏÂΪÒýÓÃÄÚÈÝ£º
<%@LANGUAGE="JSCRIPT" CODEPAGE="65001"%>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml ......
1£ºSQL ×¢È룺
½â¾ö·½°¸£º
a. Õâ¸öÎÊÌâÖ÷ÒªÊÇÓÉÓÚ´«ÈëÌØÊâ×Ö·ûÒýÆðµÄÎÒÃÇ¿ÉÒÔÔÚ¶ÔÊäÈëµÄÓû§ÃûÃÜÂë½øÈë¹ýÂËÌØÊâ×Ö·û´¦Àí¡£
b. ʹÓô洢¹ý³Ìͨ¹ý´«Èë²ÎÊýµÄ·½·¨¿É½â¾ö´ËÀàÎÊÌ⣨עÒ⣺ÔÚ´æ´¢¹ý³ÌÖв»¿ÉʹÓÃÆ´½ÓʵÏÖ£¬²»È»ºÍûÓô洢¹ýºÍÊÇÒ»ÑùµÄ£©¡£
2. XSS£¨¿çÕ¾½Å±¾¹¥»÷£©£º
½â¾ö·½°¸£º
¡¡¡¡a. ͨ¹ýÔÚ Page Ö¸Áî»ò Å ......
ÔÚÍøÉÏ¿´µ½ºÜ¶àÕâ·½ÃæµÄ´úÂ룬µ«ÊÇÓÐЩÊDz»ÄÜÓã¬ÓÐЩÊÇÀ¬»ø´úÂëÌ«¶à£¬ÎÒ¼òµ¥µÄÐÞ¸ÄÁËÒ»ÏÂÏÖÔÚÓë´ó¼Ò¹²Ïíһϡ£
<%
Option Explicit
dim databasename '¶¨ÒåÊý¾Ý¿âÃû³Æ
databasename="database.mdb" 'Êý¾Ý¿âÃû³Æ
dim databasepath '¶¨ÒåÊý¾Ý¿â´æ·Å·¾¶
......
1.ÈçºÎÓÃAspÅжÏÄãµÄÍøÕ¾µÄÐéÄâÎïÀí·¾¶
´ð£ºÊ¹ÓÃMappath·½·¨
< p align="center" >< font size="4" face="Arial" >< b >
The Physical path to this virtual website is:
< /b >< /font >
< font color="#FF0000" size="6" face="Arial" >
< %= Server.MapPath("\")% >
......