Ò׽ؽØÍ¼Èí¼þ¡¢µ¥Îļþ¡¢Ãâ°²×°¡¢´¿ÂÌÉ«¡¢½ö160KB

·ÅÈëconn.aspÖÐ(¾Ü¾ø¹¥»÷ ÍòÄÜAsp·À×¢Èë´úÂë)


·ÅÈëconn.aspÖÐ(¾Ü¾ø¹¥»÷ ÍòÄÜAsp·À×¢Èë´úÂë)
·ÅÈëconn.aspÖÐ(¾Ü¾ø¹¥»÷ ÍòÄÜAsp·À×¢Èë´úÂë)
µÚÒ»ÖÖ£º
squery=lcase(Request.ServerVariables("QUERY_STRING"))
sURL=lcase(Request.ServerVariables("HTTP_HOST"))
 
SQL_injdata =":|;|>|<|--|sp_|xp_|\|dir|cmd|^|(|)|+|$|'|copy|format|and|exec|insert|select|delete|update|count|*|%|chr|mid|master|truncate|char|declare"
 
SQL_inj = split(SQL_Injdata,"|")
 
For SQL_Data=0 To Ubound(SQL_inj)
if instr(squery&sURL,Sql_Inj(Sql_DATA))>0 Then
Response.Write "SQL·À×¢Èëϵͳ"
Response.end
end if
next
µÚ¶þÖÖ£º
 SQL_injdata =":|;|>|<|--|sp_|xp_|\|dir|cmd|^|(|)|+|$|'|copy|format|and|exec|insert|select|delete|update|count|*|%|chr|mid|master|truncate|char|declare"
 
SQL_inj = split(SQL_Injdata,"|")
If Request.QueryString<>"" Then
For Each SQL_Get In Request.QueryString
For SQL_Data=0 To Ubound(SQL_inj)
if instr(Request.QueryString(SQL_Get),Sql_Inj(Sql_DATA))>0 Then
Response.Write "SQLͨÓ÷À×¢Èëϵͳ"
Response.end
end if
next
Next
End If
 
If Request.Form<>"" Then
For Each Sql_Post In Request.Form
For SQL_Data=0 To Ubound(SQL_inj)
if instr(Request.Form(Sql_Post),Sql_Inj(Sql_DATA))>0 Then
Response.Write "SQLͨÓ÷À×¢Èëϵͳ"
Response.end
end if
next
next
end if
Ò»°ãÕâÖÖÎÊÌâÊÇÍøÕ¾ÓЩ¶´£¬ÏµÍ³Â©¶´»òÕßSQL×¢Èë©¶´£¬»òÕßÉÏ´«Îļþ©¶´£¬ÎÒÒ²ÉîÊÜÆä¿à£¬È»¶ø£¬ÈçºÎ·ÀÖ¹ÍøÒ³±»Ð޸ļÓÈë½Å±¾²¡¶¾? ÏÖ½«Õâ¸öÎÊÌâ×ܽá·ÖÏíÒ»ÏÂ.
1¡¢¼òµ¥µÄ²¹¾È´ëÊ©£ºÔÚ·þÎñÆ÷IISÖУ¬°ÑËùÓеÄASP£¬HTMLÎļþµÄÊôÐÔÉèÖÃΪEveryoneÖ»¶Á£¨Ò»°ãÊÇIUSR_£©£¬Ö»°ÑÊý¾Ý¿âµÄȨÏÞÉèÖóɿÉд£¬×¢Ò⣺Èç¹ûÄãûÓзþÎñÆ÷µÄ¹ÜÀíȨÏÞ£¬ÄÇôµÇ¼ÉϵĿռäftp£¬Ñ¡ÖÐÄÇЩ²»ÐèҪдÈëµÄÎļþ»òÎļþ¼Ð£¬ÓÒ¼üµã»÷-ÊôÐÔ£º°ÑÆäÖеÄÈý×éдÈëȨÏÞ¶¼È¡Ïû£¬µ«Èç¹ûÄãÓÐACCESSÊý¾Ý¿â£¬Òª°ÑÊý¾Ý¿âÉè³É¿Éд£¬²»È»¶ÁÊý¾Ýʱ»á³ö´í¡£
2¡¢ÏȰѶñÒâ´úÂëɾµô£¨Ìæ»»µô£©£¬È»ºó°ÑÍøÕ¾Ä¿Â¼ÏµÄËùÓÐÎļþÈ«²¿ÓÃɱÈíɱÏ ,È»ºóÒ»¸öÒ»¸ö¼ì²éÏÂÊÇ·ñ´æÔÚºóÃÅ.
3¡¢ÔÚÄãµÄ³ÌÐòÀïдÉÏÒÔÏ·À×¢È뺯Êý
 on error resume next   'ÕâÐдúÂë·Åµ½conn.aspµÄµÚÒ»ÐС£
 
'·ÀÖ


Ïà¹ØÎĵµ£º

ÔÚÏß²éÕÒ/ÕýÔòÌæ»»ÎļþÖÐÎı¾µÄÍøÒ³½Ó¿Ú(asp)

<%
response.Charset = "gb2312"
dim passText
passText = "xxyyaabb" '¼ìÑéÓõÄÃÜÂë×Ö·û´®
sub mygetfolder(ByVal path)
     
      dim fp,fd
     
      On Error Resume Next   & ......

asp¼°asp.netµÄurlencodeÎÊÌâ

ÎÒÏëÔÚaspÖмÓÒ»¸öÁ´½Ó£¬Ö¸Ïòasp.netÍøÒ³£¬µ«asp.netµÄÍøÖ·ÊǾ­¹ýHttpUtility.UrlEncode±äÐκÍHttpUtility.UrlDecode±ä»ØµÄ£¬¶øaspµÄserver.urlencodeÈ´²úÉú²»Á˺ÍHttpUtility.UrlEncodeÒ»ÑùµÄ±àÂ룬ÇëÎÊÓÐûÓнâ¾ö°ì·¨
²¹³ä£ºÔ­À´asp.netµÄÊÇ"web.aspx?str="+HttpUtility.UrlEncode(str)
ºÍHttpUtility.UrlDecode(Requ ......

ͨÓÃasp·À×¢Èë³ÌÐò

‘·À×¢Èë°ÑËü¼Óµ½connÀïÕâÑù¾ÍokÁË
dim sql_injdata
SQL_injdata = "’|and|exec|insert|select|delete|update|count|*|%|chr|mid|master|truncate|char|declare"
SQL_inj = split(SQL_Injdata,"|")
If Request.QueryString<>"" Then
For Each SQL_Get In Request.QueryString
For SQL_Data=0 To Ubo ......

aspµÄÐĵÃ

    ASP²¿·Ö½²Êö£º   ¶ÔÓÚASPÀ´ËµÏàÐÅ´ó¼Ò¶¼²¢²»Ä°Éú£¬ÔÚÕâÀïÎҾͲ»ÀË·ÑÌ«¶àµÄʱ¼äÀ´½øÐвûÊöÁË¡£
       ÎÒÕâÀïÖ÷ÒªÊǼǼÁËÎÒÔÚ¶ÁASPʱµÄһЩÐĵúÍÎÒ×Ô¼ºÈÏΪӦ¸Ã×¢ÒâµÄµØ·½£¬Ï£ÍûÕâЩµãµãµÎµÎÄܹ»ÎªÄÇЩ³õѧµÄÅóÓÑÓÐÒ»¶¨µÄ°ïÖú£¬Í¬Ê±Ò²Ï£ÍûºÍÒѾ­ÓкÜÉî¾­ÑéºÍ ......

ʹÓÃVB½«ASP´úÂë·â×°µ½DLLÎļþÍêÕûʵÀý

ʹÓÃVB½«ASP´úÂë·â×°µ½DLLÎļþÍêÕûʵÀý
http://blog.csdn.net/cncco/archive/2007/10/20/1834865.aspx
ÓÃVB·â×°ASP£¬½¨Á¢SayHello²âÊÔ³ÌÐò
1¡¢´ò¿ªVB6£¬Ð½¨ActiveX DLL
2¡¢ÔÚ¹¤³ÌÒýÓÃÖмÓÈëMicrosoft Active Server Pages Object LibraryÑ¡Ôñ
3¡¢Ìî¼Ó´úÂëÈçÏ£º
'Code Start
'ÉùÃ÷²¿·Ö
Private MyScriptingContext ......
© 2009 ej38.com All Rights Reserved. ¹ØÓÚE½¡ÍøÁªÏµÎÒÃÇ | Õ¾µãµØÍ¼ | ¸ÓICP±¸09004571ºÅ