·ÅÈëconn.aspÖÐ(¾Ü¾ø¹¥»÷ ÍòÄÜAsp·À×¢Èë´úÂë)
·ÅÈëconn.aspÖÐ(¾Ü¾ø¹¥»÷ ÍòÄÜAsp·À×¢Èë´úÂë)
·ÅÈëconn.aspÖÐ(¾Ü¾ø¹¥»÷ ÍòÄÜAsp·À×¢Èë´úÂë)
µÚÒ»ÖÖ£º
squery=lcase(Request.ServerVariables("QUERY_STRING"))
sURL=lcase(Request.ServerVariables("HTTP_HOST"))
SQL_injdata =":|;|>|<|--|sp_|xp_|\|dir|cmd|^|(|)|+|$|'|copy|format|and|exec|insert|select|delete|update|count|*|%|chr|mid|master|truncate|char|declare"
SQL_inj = split(SQL_Injdata,"|")
For SQL_Data=0 To Ubound(SQL_inj)
if instr(squery&sURL,Sql_Inj(Sql_DATA))>0 Then
Response.Write "SQL·À×¢Èëϵͳ"
Response.end
end if
next
µÚ¶þÖÖ£º
SQL_injdata =":|;|>|<|--|sp_|xp_|\|dir|cmd|^|(|)|+|$|'|copy|format|and|exec|insert|select|delete|update|count|*|%|chr|mid|master|truncate|char|declare"
SQL_inj = split(SQL_Injdata,"|")
If Request.QueryString<>"" Then
For Each SQL_Get In Request.QueryString
For SQL_Data=0 To Ubound(SQL_inj)
if instr(Request.QueryString(SQL_Get),Sql_Inj(Sql_DATA))>0 Then
Response.Write "SQLͨÓ÷À×¢Èëϵͳ"
Response.end
end if
next
Next
End If
If Request.Form<>"" Then
For Each Sql_Post In Request.Form
For SQL_Data=0 To Ubound(SQL_inj)
if instr(Request.Form(Sql_Post),Sql_Inj(Sql_DATA))>0 Then
Response.Write "SQLͨÓ÷À×¢Èëϵͳ"
Response.end
end if
next
next
end if
Ò»°ãÕâÖÖÎÊÌâÊÇÍøÕ¾ÓЩ¶´£¬ÏµÍ³Â©¶´»òÕßSQL×¢Èë©¶´£¬»òÕßÉÏ´«Îļþ©¶´£¬ÎÒÒ²ÉîÊÜÆä¿à£¬È»¶ø£¬ÈçºÎ·ÀÖ¹ÍøÒ³±»Ð޸ļÓÈë½Å±¾²¡¶¾? ÏÖ½«Õâ¸öÎÊÌâ×ܽá·ÖÏíÒ»ÏÂ.
1¡¢¼òµ¥µÄ²¹¾È´ëÊ©£ºÔÚ·þÎñÆ÷IISÖУ¬°ÑËùÓеÄASP£¬HTMLÎļþµÄÊôÐÔÉèÖÃΪEveryoneÖ»¶Á£¨Ò»°ãÊÇIUSR_£©£¬Ö»°ÑÊý¾Ý¿âµÄȨÏÞÉèÖóɿÉд£¬×¢Ò⣺Èç¹ûÄãûÓзþÎñÆ÷µÄ¹ÜÀíȨÏÞ£¬ÄÇôµÇ¼ÉϵĿռäftp£¬Ñ¡ÖÐÄÇЩ²»ÐèҪдÈëµÄÎļþ»òÎļþ¼Ð£¬ÓÒ¼üµã»÷-ÊôÐÔ£º°ÑÆäÖеÄÈý×éдÈëȨÏÞ¶¼È¡Ïû£¬µ«Èç¹ûÄãÓÐACCESSÊý¾Ý¿â£¬Òª°ÑÊý¾Ý¿âÉè³É¿Éд£¬²»È»¶ÁÊý¾Ýʱ»á³ö´í¡£
2¡¢ÏȰѶñÒâ´úÂëɾµô£¨Ìæ»»µô£©£¬È»ºó°ÑÍøÕ¾Ä¿Â¼ÏµÄËùÓÐÎļþÈ«²¿ÓÃɱÈíɱÏ ,È»ºóÒ»¸öÒ»¸ö¼ì²éÏÂÊÇ·ñ´æÔÚºóÃÅ.
3¡¢ÔÚÄãµÄ³ÌÐòÀïдÉÏÒÔÏ·À×¢È뺯Êý
on error resume next 'ÕâÐдúÂë·Åµ½conn.aspµÄµÚÒ»ÐС£
'·ÀÖ
Ïà¹ØÎĵµ£º
»·¾³£ºÊý¾Ý¿â oracle 64bit ϵͳ win2008 64bit IIS7 ÔÚasp ÍøÒ³ÖÐʹÓÃadoÁ¬½ÓÊý¾Ý¿â ODBCÓõÄÊÇMicrosft ODBC for oracle
Çé¿ö£ºÔÚÍøÒ³µÄ²éѯÓï¾äÖв»º¬ÖÐÎĵĿÉÒÔ£¬Ö»ÒªÓï¾äÖк¬ÓÐÖÐÎľͻ᷵»Ø´íÎó½á¹û¡£
Èç:select 'Ò»¶þÈý' from dual;ÕâÑùµÄÓï¾ä ·µ»Ø»ØÀ´¾ÍÊÇ£¿£¿£¿
»¹ÒªËµÃ÷µÄÊÇoracleµÄ×Ö·û¼¯ÊÇAMERICAN_AMERICA.U ......
¸Õ¸Õ ¿´µ½Õâôһ¸öÎÊÌ⣬ÕâÀïÒ²×ö¸ö±ê¼Ç£ºhttp://topic.csdn.net/u/20080411/14/7b0f9da5-0413-4149-91e9-72c3df3018a3.html?seed=327251592
µÚÒ»ÖÖ·½Ê½£º
//ÔÚVisual Studio 2008Öе÷ÊÔͨ¹ý
testPop_Page.aspx:Ö÷Ò³ÃæASPX´úÂë
<html xmlns="http://www.w3.org/1999/xhtml">
<head runat="server">
  ......
<%
response.Charset = "gb2312"
if request("test") <> "" then
On Error Resume Next
dim fso
set fso = server.createObject("Scripting.FileSystemObject")
if Err.Number > 0 then
  ......
ÒýÑÔ
²ÉÓÃWEB¼¼ÊõʵÏÖB/S£¨ä¯ÀÀÆ÷/·þÎñÆ÷£©½á¹¹µÄ¹ÜÀíϵͳÊǰ칫×Ô¶¯»¯µÄ·¢Õ¹Ç÷ÊÆ¡£»ùÓÚWEB¼¼ÊõµÄ¹ÜÀíϵͳ£¬ÓÉÓÚ¿ª·¢ÖÜÆÚ¶Ì£»ÓëÓû§Æ½Ì¨Î޹أ»Ò×ÓÚʵÏÖ½»»¥Ê½Ó¦Óã»ÄܶÔÐÅÏ¢½øÐпìËÙ¡¢¸ßЧµÄÊÕ¼¯¡¢´¦ÀíºÍ·¢²¼£¬½ü¼¸ÄêÀ´µÃµ½ÁËѸËÙ·¢Õ¹¡£¶øASP¼¼ÊõÓÉÓÚÆä¿ª·¢Ð§Âʸߡ¢½»»¥ÐԺ㬰²È«ÐÔÇ¿µÈÌØµã£¬Öð½¥³ÉΪ¿ª·¢¹ÜÀíϵͳ ......
º¯Êý Óï·¨ ¹¦ÄÜ
Len Len(string|varname) ·µ»Ø×Ö·û´®ÄÚ×Ö·ûµÄÊýÄ¿£¬»òÊÇ´æ´¢Ò»±äÁ¿ËùÐèµÄ×Ö½ÚÊý¡£
Trim Trim(string) ½«×Ö·û´®Ç°ºóµÄ¿Õ¸ñÈ¥µô
Ltrim Ltrim(string) ½«×Ö·û´®Ç°ÃæµÄ¿Õ¸ñÈ¥µô
Rtrim Rtrim(string) ½«×Ö·û´®ºóÃæµÄ¿Õ¸ñÈ¥µô
Mid Mid(string,start,length) ´Óstring×Ö·û´®µÄstart×Ö·û¿ªÊ¼È¡µÃlength³¤¶ ......