Ò׽ؽØͼÈí¼þ¡¢µ¥Îļþ¡¢Ãâ°²×°¡¢´¿ÂÌÉ«¡¢½ö160KB

ASP.NET³£¼û°²È«ÎÊÌâ

ASP.NET³£¼û°²È«ÎÊÌâ
Ò»¡¢SQLÓï¾ä©¶´
Ðí¶à³ÌÐòÔ±ÔÚÓÃsqlÓï¾ä½øÐÐÓû§ÃÜÂëÑé֤ʱÊÇͨ¹ýÒ»¸öÀàËÆÕâÑùµÄÓï¾äÀ´ÊµÏֵģº 
Sql="Select * from Óû§±í where ÐÕÃû = '" + name + "' and ÃÜÂë = '" + password + "'" 
ͨ¹ý·ÖÎö¿ÉÒÔ·¢ÏÖ£¬ÉÏÊöÓï¾ä´æÔÚ×ÅÖÂÃüµÄ©¶´¡£µ±ÎÒÃÇÔÚÓû§Ãû³ÆÖÐÊäÈëÏÂÃæµÄ×Ö·û´®Ê±£ºtest' or '1' = '1£¬È»ºó¿ÚÁîËæ±ãÊäÈ룬ÎÒÃÇÉèΪaaa¡£±äÁ¿´ú»»ºó£¬sqlÓï¾ä¾Í±ä³ÉÁËÏÂÃæµÄ×Ö·û´®£º 
Sql="Select * from Óû§±í where ÐÕÃû='test' or '1' = '1' and ÃÜÂë = 'aaa' 
ÎÒÃǶ¼ÖªµÀselectÓï¾äÔÚÅжϲéѯÌõ¼þʱ£¬Óöµ½»ò£¨or£©²Ù×÷¾Í»áºöÂÔÏÂÃæµÄÓ루and£©²Ù×÷£¬¶øÔÚÉÏÃæµÄÓï¾äÖÐ1=1µÄÖµÓÀԶΪtrue£¬ÕâÒâζ×ÅÎÞÂÛÔÚÃÜÂëÖÐÊäÈëʲôֵ£¬¾ùÄÜͨ¹ýÉÏÊöµÄÃÜÂëÑéÖ¤£¡
Select * from Óû§±í where ÐÕÃû = 'ºÏ·¨µÄÐÕÃû' or '1' = '1' and ÃÜÂë = ''  //ÎÞÐèÃÜÂë 
Select * from Óû§±í where ÐÕÃû = '' or '1'='1' and ÃÜÂë = '' or '1'='1' //ÎÞÐèÓû§ÃûºÍÃÜÂë
Select * from Óû§±í where ÐÕÃû = 'ºÏ·¨µÄÐÕÃû' --' and ÃÜÂë = ''  //ÎÞÐèÃÜÂë
½â¾ö·½·¨£º 
·ÀÖ¹ASP.NETÓ¦Óñ»SQL×¢Èëʽ¹¥»÷´³Èë²¢²»ÊÇÒ»¼þÌرðÀ§ÄѵÄÊÂÇ飬ֻҪÔÚÀûÓÃ±íµ¥ÊäÈëµÄÄÚÈݹ¹ÔìSQLÃüÁî֮ǰ£¬°ÑËùÓÐÊäÈëÄÚÈݹýÂËÒ»·¬¾Í¿ÉÒÔÁË¡£¹ýÂËÊäÈëÄÚÈÝ¿ÉÒÔ°´¶àÖÖ·½Ê½½øÐУº
1¡¢¼ì²éÓû§ÊäÈëµÄºÏ·¨ÐÔ£¬È·ÐÅÊäÈëµÄÄÚÈÝÖ»°üº¬ºÏ·¨µÄÊý¾Ý¡£Êý¾Ý¼ì²éÓ¦µ±ÔÚ¿Í»§¶ËºÍ·þÎñÆ÷¶Ë¶¼Ö´ÐЗ—Ö®ËùÒÔÒªÖ´ÐзþÎñÆ÷¶ËÑéÖ¤£¬ÊÇΪÁËÃÖ²¹¿Í»§¶ËÑéÖ¤»úÖÆ´àÈõµÄ°²È«ÐÔ¡£ÔÚ¿Í»§¶Ë£¬¹¥»÷ÕßÍêÈ«ÓпÉÄÜ»ñµÃÍøÒ³µÄÔ´´úÂ룬ÐÞ¸ÄÑéÖ¤ºÏ·¨ÐԵĽű¾£¨»òÕßÖ±½Óɾ³ý½Å±¾£©£¬È»ºó½«·Ç·¨ÄÚÈÝͨ¹ýÐ޸ĺóµÄ±íµ¥Ìá½»¸ø·þÎñÆ÷¡£
2¡¢¶ÔÓÚ¶¯Ì¬¹¹ÔìSQL²éѯµÄ³¡ºÏ£¬¿ÉÒÔʹÓÃÏÂÃæµÄ¼¼Êõ£º
  µÚÒ»£ºÌæ»»µ¥ÒýºÅ£¬¼´°ÑËùÓе¥¶À³öÏֵĵ¥ÒýºÅ¸Ä³ÉÁ½¸öµ¥ÒýºÅ¡£
µÚ¶þ£ºÉ¾³ýÓû§ÊäÈëÄÚÈÝÖеÄËùÓÐÁ¬×Ö·û¡£
µÚÈý£º¶ÔÓÚÓÃÀ´Ö´ÐвéѯµÄÊý¾Ý¿âÕÊ»§£¬ÏÞÖÆÆäȨÏÞ¡£Óò»Í¬µÄÓû§ÕÊ»§Ö´Ðвéѯ¡¢²åÈë¡¢¸üС¢É¾³ý²Ù×÷¡£ÓÉÓÚ¸ôÀëÁ˲»Í¬ÕÊ»§¿ÉÖ´ÐеIJÙ×÷£¬Òò¶øÒ²¾Í·ÀÖ¹ÁËÔ­±¾ÓÃÓÚÖ´ÐÐSELECTÃüÁîµÄµØ·½È´±»ÓÃÓÚÖ´ÐÐINSERT¡¢UPDATE»òDELETEÃüÁî¡£
3¡¢Óô洢¹ý³ÌÀ´Ö´ÐÐËùÓеIJéѯ¡£SQL²ÎÊýµÄ´«µÝ·½Ê½½«·ÀÖ¹¹¥»÷ÕßÀûÓõ¥ÒýºÅºÍÁ¬×Ö·ûʵʩ¹¥»÷¡£´ËÍ⣬Ëü»¹Ê¹µÃÊý¾Ý¿âȨÏÞ¿ÉÒÔÏÞÖƵ½Ö»ÔÊÐíÌض¨µÄ´æ´¢¹ý³ÌÖ´ÐУ¬ËùÓеÄÓû§ÊäÈë±ØÐë×ñ´Ó±»µ÷ÓõĴ洢¹ý³ÌµÄ°²È«ÉÏÏÂÎÄ£¬ÕâÑ


Ïà¹ØÎĵµ£º

jQuery Ajax ·½·¨µ÷Óà Asp.Net WebService µÄÏêϸÀý×Ó

http://www.cnblogs.com/TerryFeng/archive/2009/02/01/1382123.html
ÕâºÜ³£Óã¬ËÑË÷ÁËһϲ©¿ÍÔ°µÄ“ÕÒÕÒ¿´”ºÍ¹È¸è£¬¿´µ½´ó²¿·Ö¶¼ÊÇתÔØÓÚÒ»Á½ÆªÎÄÕ£¨¶øÇÒÀ´Ô´»¹²»ÊDz©¿ÍÔ°£©£¬ÓеÄÊǼòµ¥µÄ˵һµãÎÞ·¨ÔËÐУ¬¸ø³õѧÕߵĵ÷ÊÔºÍѧϰ´øÀ´²»·½±ã£¬ÎÒÔÚÕâÀォjQuery Ajax µ÷ÓÃAspx.Net WebService µÄ¼¸¸ö³£Óõķ½·¨ ......

ASP.NET ³ÌÐòÔ±µÄÐÞÁ¶Ö®Â·

³õ¼¶µÄ³ÌÐòÔ±»ò¾­Ñé²»×ãµÄ³ÌÐòÔ±ÍùÍùÖ»Òâʶµ½×Ô¼ºµÄ³ÌÐòÊÇд¸ø¼ÆËã»úµÄ£¬¶ø²»»áÔÚÒâ³ÌÐòÆäʵҲÊÇд¸øÈ˵ģ¬»òÔÚÒâµÃ²»¹»¡¢²»È«Ãæ¡£
д¸ø»úÆ÷µÄ³ÌÐò£¬ÍùÍù×·ÇóµÄÊÇÔËÐÐÕýÈ·¡¢Ö´ÐÐЧÂÊÄÜÂú×ãÒªÇó¡£µ«³ÌÐòÔ±µÄÈÎÎñ½ö½ö¾ÍÊÇ°ÑÒµÎñÂß¼­×ª³É»úÆ÷ÄܱàÒëµÄ¼ÆËã»úÓïÑÔÂð?
Æäʵ£¬³ÌÐòÊ×ÏÈ(×¢Ò⣬ÊÇÊ×ÏÈ)ÊÇд¸øÈ˵ġ£µÚÒ»£¬³ÌÐòÊÇд¸ ......

ÔÚ Linux ÏÂÔËÐÐ ASP.NET 2.0

µ¥Î»ÓÐһ̨ÏÐÖÃµÄ¾É IBM Netfinity 7000 µÄ·þÎñÆ÷£¬Ë« Pentium Pro 200 MHz CPU£¬512 MB Äڴ棬һ¸ö 9.1 GB ºÍÎå¸ö 4.5 GB µÄ SCSI Ó²ÅÌ¡£ÎÒÏ뽫Æä·ÏÎïÀûÓÃһϣ¬ÓÚÊÇ£º
1. µ½ http://tw.releases.ubuntu.com/edgy/ ÏÂÔØ  PC (Intel x86) server install CD £¬½«ÏÂÔصõ½µÄ ubuntu-6.10-server-i386.iso Îļþ¿Ì¼һÕÅ ......

asp.net jquery Èý¼¶Áª¶¯

 var j = jQuery.noConflict();
var prov="";
var city="";
var area="";
j(function(){
    j.get("/Js/Message/address.xml",function(xml){
            j("body").data("xml",xml);
  ......

°ÑASP.NETÍøҳתÒƵ½SharePointÍøÒ³µÄ·½·¨

¹«Ë¾Ô­ÓÐÒ»¸ö¾ÖÓòÍø£¬¾­¹ý¶àÄêµÄÐÞÐÞ²¹²¹£¬ÒѾ­´´½¨Á˲»ÉÙµÄÄÚÈÝ£¬°üÀ¨Ò»Ð©Êý¾Ý¿â²éѯ±¨±í¡¢¹¤×÷Á÷µÈÍøÕ¾£¬ÕâЩÍøÕ¾ÓÐһЩÊÇÓÃASP.NETÀ´¿ª·¢µÄ£¬²¢ÇÒÓÃÁ˺ܶàÄ꣬»ýÀÛÁ˺ܶàÒµÎñÊý¾Ý£»ÏÖÔÚ¹«Ë¾Ïë°Ñ¾ÖÓòÍøÓÃWSS3.0À´¼ÜÉ裬Õâ¾ÍÃæÁÙµ½Ò»¸öºÜ¼¬ÊÖµÄÎÊÌ⣬¾ÍÊÇÔõÑùÀ´´¦ÀíÕâЩ¾ÉµÄÍøÒ³¡£Èç¹ûÍƵ¹ÖØÀ´£¬ÄÇô¹¤×÷Á¿½«ÊǷdz£ÏÅÈ˵ģ ......
© 2009 ej38.com All Rights Reserved. ¹ØÓÚE½¡ÍøÁªÏµÎÒÃÇ | Õ¾µãµØͼ | ¸ÓICP±¸09004571ºÅ