ASP¼ò½é
ASPÈ«³ÆÎªActive Server Pages£¬ÊÇÒ»ÖÖÓÉ΢Èí(M1crosoft)¹«Ë¾¿ª·¢µÄ·þÎñÆ÷¶Ë½Å±¾ÓïÑÔÔËÐл·¾³£¬Ëü¿ÉÒÔ½áºÏHTMLÓïÑÔºÍActiveX×é¼þ½¨Á¢¶¯Ì¬¡¢½»»¥¡¢¸ßЧµÄWeb·þÎñÆ÷¶ËÓ¦ÓóÌÐò¡£µ±Ò»¸öÓû§ä¯ÀÀÆ÷´Óweb·þÎñÆ÷ÇëÇóÒ»¸öAsPÍøÒ³Ê±£¬web·þÎñÆ÷»á
½«Õâ¸öAsPÎļþ·¢Ë͸øweb·þÎñÆ÷µÄAsPÒýÇæ£¬AsPÒýÇæ½«¸ÃAsPÍøÒ³ÖÐËùÓеķþÎñÆ÷¶Ë½Å±¾(<%ºÍ%>Ö®¼äµÄ´úÂë)½øÐд¦Àí£¬²¢½«
Êä³ö½á¹ûת»»³ÉHTML´úÂ룬Ȼºó½«´¦ÀíºóµÄÍêÕûHTML´úÂë·¢Ë͸øÓû§ä¯ÀÀÆ÷¡£AsP³ÌÐòÖл¹¿ÉÒÔͨ¹ýActiveX Date Object¶ÔÏóʵ
ÏÖ¶ÔÊý¾Ý¿âµÄ·ÃÎÊ´¦Àí¡£
´ÓÈí¼þµÄ¼¼Êõ²ãÃæ¿´£¬AsPÓÐÈçÏÂÌØµã¡£
(1)ÎÞÐë±àÒë¡£AsP½Å±¾¼¯³ÉÓÚH¶¡MLµ±ÖУ¬ÎÞÐë±àÒë»òÁ´½Ó¼´¿ÉÖ±½Ó½âÊÍÖ´ÐС£
(2)Ò×ÓÚÉú³É¡£¿ÉÒÔʹÓ󣹿Îı¾±à¼Æ÷½øÐÐAsP³ÌÐò´úÂëµÄ±àд£¬Ò²¿ÉÒÔ±ãÓÃ
FrontPageºÍDrcamweaverµÈÍøÒ³ÖÆ×÷¹¤¾ß¡£
(3)¶ÀÁ¢ÓÚä¯ÀÀÆ÷¡£AsP½Å±¾ÔÚÕ¾µã·þÎñÆ÷¶ËÖ´ÐУ¬ÎÞÐëÓû§¶Ë°ÆÀÀÆ÷µÄÖ§³Ö¡£
(4)ÃæÏò¶ÔÏó¡£ÔÚAsP½Å±¾ÖпÉÒÔ·½±ãµØÒýÓÃϵͳ×é¼þºÍAsPµÄÄÚÖÃ×é¼þ£¬»¹ÄÜͨ
¹ý¶¨ÖÆActiveX·þÎñÆ÷×é¼þÀ´À©³ä¹¦ÄÜ¡£
(5)ÓëÈκÎActiveX scriptingÓïÑÔ¼æÈÝ¡£³ýÁË¿ÉʹÓÃVBScriptºÍJavaScriptÓïÑÔ½ø
ÐÐÉè¼ÆÍ⣬»¹¿Éͨ¹ýP1u8—inµÄ·½Ê½£¬Ê¹ÓÃÓɵÚÈý·½ËùÌṩµÄÆäËûscriptingÓïÑÔ¡£
(6)Ô´³ÌÐòÂë²»»áÍâ©¡£ÓÉÓÚAsPÔÚ·þÎñÆ÷¶Ë½âÊÍÖ´ÐУ¬ÔÚ¿Í»§¶ËµÄä¯ÀÀÆ÷ÉÏ¿´µ½
µÄÊÇÖ´ÐкóµÄ½á¹û£¬¿ª·¢ÕßÒ²²»Óõ£ÐıðÈËÏÂÔØ³ÌÐò´úÂ룬Ôö¼ÓÁËÍøÕ¾°²È«ÐÔ¡£
Ïà¹ØÎĵµ£º
·ÅÈëconn.aspÖÐ(¾Ü¾ø¹¥»÷ ÍòÄÜAsp·À×¢Èë´úÂë)
·ÅÈëconn.aspÖÐ(¾Ü¾ø¹¥»÷ ÍòÄÜAsp·À×¢Èë´úÂë)
µÚÒ»ÖÖ£º
squery=lcase(Request.ServerVariables("QUERY_STRING"))
sURL=lcase(Request.ServerVariables("HTTP_HOST"))
SQL_injdata =":|;|>|<|--|sp_|xp_|\|dir|cmd|^|(|)|+|$|'|copy|format|and|exec| ......
À¶ÑÀ»µµôÁË£¬ÕâÑùÒ»À´ ÊÖ»ú°²×°³ÌÐò±äµÃºÜ²»·½±ãÁË¡£Ò»¿ªÊ¼ÊÇÏȰÑÒª°²×°µÄ³ÌÐòÒÔ¸½¼þµÄÐÎʽ·¢µ½ÓÊÏä ÔÙÔÚÊÖ»úÉÏÅäÖÃÓÊÏä ÈúóÏÂÔØ¸½¼þ°²×°£¬ÕâÑùËäÈ»½â¾öÁËÎÊÌâ µ«ÊÇ»¹ÊÇÓкܶ಻·½±ãµÄµØ·½¡£ ÓÚÊÇ ×Ô¼ºÏë´î½¨Ò»¸ö·þÎñÆ÷ Ö±½ÓʵÏÖÔÚÏß°²×°¡£Ç°ÌáÊÇÊÖ»úÖ§³Öwifi£¬¾ÍÊÇ˵ÐèÒªÊÖ»ú·ÃÎÊÄÚÍøµØÖ·£¬·ñÔòµÃ»° ¾Í±È½Ï ......
ǰ¼¸ÌìÔÚ×Ô¼ºµÄ±Ê¼Ç±¾Éϰ²×°ÁËOFFICE2007¡£½ñÌì×öÁËÒ»¸ö°Ù¶ÈÓÑÇéÁ´½Ó¼ì²éµÄ¹¤¾ß£¬ ÔÚÁ¬½ÓACCESS2007Êý¾Ý¿âµÄʱºò£¬Ê¹ÓõÄÇý¶¯´úÂëΪ£º"provider=microsoft.jet.oledb.4.0;data source="&server.mappath("queryrecord.mdb") ¡£È··¢ÏÖÌáʾ£º
Microsoft JET Database Engine ´íÎó ''80004005''
²»¿Éʶ±ðµÄÊý¾Ý¿â¸ñʽ
µ« ......
<%
dim db
set db=Server.CreateObject("Adodb.Connection")
db.Open "Driver={Microsoft Access Driver (*.mdb)};Dbq=" & Server.Mappath("../mdb/count.mdb")
dim strSql,rs,visitNum
strSql="Select visitNum from counter "
SET rs=db.Execute(strSql)
if session("agai ......
Try
Dim Path As String = Server.MapPath("~/Download/") 'Îļþ·¾¶
Path = Path & "file.txt" 'ÎļþµÄÃû³Æ
......