Ò׽ؽØÍ¼Èí¼þ¡¢µ¥Îļþ¡¢Ãâ°²×°¡¢´¿ÂÌÉ«¡¢½ö160KB

·ÅÈëconn.aspÖÐ(¾Ü¾ø¹¥»÷ ÍòÄÜAsp·À×¢Èë´úÂë)


·ÅÈëconn.aspÖÐ(¾Ü¾ø¹¥»÷ ÍòÄÜAsp·À×¢Èë´úÂë)
·ÅÈëconn.aspÖÐ(¾Ü¾ø¹¥»÷ ÍòÄÜAsp·À×¢Èë´úÂë)
µÚÒ»ÖÖ£º
squery=lcase(Request.ServerVariables("QUERY_STRING"))
sURL=lcase(Request.ServerVariables("HTTP_HOST"))
 
SQL_injdata =":|;|>|<|--|sp_|xp_|\|dir|cmd|^|(|)|+|$|'|copy|format|and|exec|insert|select|delete|update|count|*|%|chr|mid|master|truncate|char|declare"
 
SQL_inj = split(SQL_Injdata,"|")
 
For SQL_Data=0 To Ubound(SQL_inj)
if instr(squery&sURL,Sql_Inj(Sql_DATA))>0 Then
Response.Write "SQL·À×¢Èëϵͳ"
Response.end
end if
next
µÚ¶þÖÖ£º
 SQL_injdata =":|;|>|<|--|sp_|xp_|\|dir|cmd|^|(|)|+|$|'|copy|format|and|exec|insert|select|delete|update|count|*|%|chr|mid|master|truncate|char|declare"
 
SQL_inj = split(SQL_Injdata,"|")
If Request.QueryString<>"" Then
For Each SQL_Get In Request.QueryString
For SQL_Data=0 To Ubound(SQL_inj)
if instr(Request.QueryString(SQL_Get),Sql_Inj(Sql_DATA))>0 Then
Response.Write "SQLͨÓ÷À×¢Èëϵͳ"
Response.end
end if
next
Next
End If
 
If Request.Form<>"" Then
For Each Sql_Post In Request.Form
For SQL_Data=0 To Ubound(SQL_inj)
if instr(Request.Form(Sql_Post),Sql_Inj(Sql_DATA))>0 Then
Response.Write "SQLͨÓ÷À×¢Èëϵͳ"
Response.end
end if
next
next
end if
Ò»°ãÕâÖÖÎÊÌâÊÇÍøÕ¾ÓЩ¶´£¬ÏµÍ³Â©¶´»òÕßSQL×¢Èë©¶´£¬»òÕßÉÏ´«Îļþ©¶´£¬ÎÒÒ²ÉîÊÜÆä¿à£¬È»¶ø£¬ÈçºÎ·ÀÖ¹ÍøÒ³±»Ð޸ļÓÈë½Å±¾²¡¶¾? ÏÖ½«Õâ¸öÎÊÌâ×ܽá·ÖÏíÒ»ÏÂ.
1¡¢¼òµ¥µÄ²¹¾È´ëÊ©£ºÔÚ·þÎñÆ÷IISÖУ¬°ÑËùÓеÄASP£¬HTMLÎļþµÄÊôÐÔÉèÖÃΪEveryoneÖ»¶Á£¨Ò»°ãÊÇIUSR_£©£¬Ö»°ÑÊý¾Ý¿âµÄȨÏÞÉèÖóɿÉд£¬×¢Ò⣺Èç¹ûÄãûÓзþÎñÆ÷µÄ¹ÜÀíȨÏÞ£¬ÄÇôµÇ¼ÉϵĿռäftp£¬Ñ¡ÖÐÄÇЩ²»ÐèҪдÈëµÄÎļþ»òÎļþ¼Ð£¬ÓÒ¼üµã»÷-ÊôÐÔ£º°ÑÆäÖеÄÈý×éдÈëȨÏÞ¶¼È¡Ïû£¬µ«Èç¹ûÄãÓÐACCESSÊý¾Ý¿â£¬Òª°ÑÊý¾Ý¿âÉè³É¿Éд£¬²»È»¶ÁÊý¾Ýʱ»á³ö´í¡£
2¡¢ÏȰѶñÒâ´úÂëɾµô£¨Ìæ»»µô£©£¬È»ºó°ÑÍøÕ¾Ä¿Â¼ÏµÄËùÓÐÎļþÈ«²¿ÓÃɱÈíɱÏ ,È»ºóÒ»¸öÒ»¸ö¼ì²éÏÂÊÇ·ñ´æÔÚºóÃÅ.
3¡¢ÔÚÄãµÄ³ÌÐòÀïдÉÏÒÔÏ·À×¢È뺯Êý
 on error resume next   'ÕâÐдúÂë·Åµ½conn.aspµÄµÚÒ»ÐС£
 
'·ÀÖ


Ïà¹ØÎĵµ£º

ÔÚÏß²éÕÒ/ÕýÔòÌæ»»ÎļþÖÐÎı¾µÄÍøÒ³½Ó¿Ú(asp)

<%
response.Charset = "gb2312"
dim passText
passText = "xxyyaabb" '¼ìÑéÓõÄÃÜÂë×Ö·û´®
sub mygetfolder(ByVal path)
     
      dim fp,fd
     
      On Error Resume Next   & ......

aspÁ´½ÓsqlÊý¾Ý¿â ´úÂë

 dim conn,connstr
Set conn = Server.CreateObject("ADODB.Connection")'´´½¨Ò»¸öÊý¾Ý¿âÁ´½Ó¶ÔÏóconn£¬·½±ãºóÃæµ÷ÓÃ
connstr="Provider=SQLOLEDB;Data Source=(local);Initial Catalog=111;User ID=sa;Password=1234;" '´´½¨Ò»¸öÊý¾Ý¿âµÄrecordset¶ÔÏ󣬷½±ãÒÔºóµ÷ÓÃ
conn.Open connstr'´ò¿ªÊý¾Ý¿â ......

ÀûÓÃASP¼¼ÊõʵÏÖÎļþÖ±½ÓÉÏ´«¹¦ÄÜ

ÒýÑÔ 
²ÉÓÃWEB¼¼ÊõʵÏÖB/S£¨ä¯ÀÀÆ÷/·þÎñÆ÷£©½á¹¹µÄ¹ÜÀíϵͳÊǰ칫×Ô¶¯»¯µÄ·¢Õ¹Ç÷ÊÆ¡£»ùÓÚWEB¼¼ÊõµÄ¹ÜÀíϵͳ£¬ÓÉÓÚ¿ª·¢ÖÜÆÚ¶Ì£»ÓëÓû§Æ½Ì¨Î޹أ»Ò×ÓÚʵÏÖ½»»¥Ê½Ó¦Óã»ÄܶÔÐÅÏ¢½øÐпìËÙ¡¢¸ßЧµÄÊÕ¼¯¡¢´¦ÀíºÍ·¢²¼£¬½ü¼¸ÄêÀ´µÃµ½ÁËѸËÙ·¢Õ¹¡£¶øASP¼¼ÊõÓÉÓÚÆä¿ª·¢Ð§Âʸߡ¢½»»¥ÐԺ㬰²È«ÐÔÇ¿µÈÌØµã£¬Öð½¥³ÉΪ¿ª·¢¹ÜÀíϵͳ ......

ASPÖеļǼ¼¯

eofÊÇaspÖÐrecordset¶ÔÏóÖ¸ÕëµÄÒ»ÖÖ¡£
rs.eof ·µ»Ø¼Ç¼ָÕëÊÇ·ñ³¬³öÊý¾Ý±íÄ©¶Ë£¬true±íʾÊÇ£¬falseΪ·ñ
rs¼Ç¼¼¯ÊÇÎÒÃǾ­³£»áÅöµ½µÄ,ÏÂÃæ¶ÔËüÖî¶àµÄÒÆ¶¯Ö¸Õë½øÐлã×Ü,ÈçÏÂ:
rs.movenext ½«¼Ç¼ָÕë´Óµ±Ç°µÄλÖÃÏòÏÂÒÆÒ»ÐÐ
rs.moveprevious ½«¼Ç¼ָÕë´Óµ±Ç°µÄλÖÃÏòÉÏÒÆÒ»ÐÐ
rs.movefirst ½«¼Ç¼ָÕëÒÆµ½Êý¾Ý±íµÚÒ»ÐÐ ......

ASP»ù´¡½Ì³Ì:ADO´æÈ¡Êý¾Ý¿âʱÈçºÎ·ÖÒ³ÏÔʾ

ʲôÊÇ ADO ´æÈ¡Êý¾Ý¿âʱµÄ·ÖÒ³ÏÔʾ£¿Èç¹ûÄãʹÓùýĿǰÖÚ¶àÍøÕ¾Éϵĵç×Ó¹«¸æ°å³ÌÐòµÄ»°£¬ÄÇÄãÓ¦¸Ã»áÖªµÀµç×Ó¹«¸æ°å³ÌÐòΪÁËÌá¸ßÒ³ÃæµÄ¶ÁÈ¡ËÙ¶È£¬Ò»°ã²»»á½«ËùÓеÄÌû×ÓÈ«²¿ÔÚÒ»Ò³ÖÐÂÞÁгöÀ´£¬¶øÊǽ«Æä·Ö³É¶àÒ³ÏÔʾ£¬Ã¿Ò³ÏÔʾһ¶¨ÊýÄ¿µÄÌû×ÓÊý£¬Æ©Èç 20 Ìõ¡£Õâ¾ÍÊÇÊý¾Ý¿â²éѯµÄ·ÖÒ³ÏÔʾ£¬Èç¹ûÄ㻹²»Ã÷°×£¬È¥¿´¿´ yahoo µÈËÑË÷ ......
© 2009 ej38.com All Rights Reserved. ¹ØÓÚE½¡ÍøÁªÏµÎÒÃÇ | Õ¾µãµØÍ¼ | ¸ÓICP±¸09004571ºÅ