ASP.NET³£¼û°²È«ÎÊÌâ
ASP.NET³£¼û°²È«ÎÊÌâ
Ò»¡¢SQLÓï¾ä©¶´
Ðí¶à³ÌÐòÔ±ÔÚÓÃsqlÓï¾ä½øÐÐÓû§ÃÜÂëÑé֤ʱÊÇͨ¹ýÒ»¸öÀàËÆÕâÑùµÄÓï¾äÀ´ÊµÏֵģº
Sql="Select * from Óû§±í where ÐÕÃû = '" + name + "' and ÃÜÂë = '" + password + "'"
ͨ¹ý·ÖÎö¿ÉÒÔ·¢ÏÖ£¬ÉÏÊöÓï¾ä´æÔÚ×ÅÖÂÃüµÄ©¶´¡£µ±ÎÒÃÇÔÚÓû§Ãû³ÆÖÐÊäÈëÏÂÃæµÄ×Ö·û´®Ê±£ºtest' or '1' = '1£¬È»ºó¿ÚÁîËæ±ãÊäÈ룬ÎÒÃÇÉèΪaaa¡£±äÁ¿´ú»»ºó£¬sqlÓï¾ä¾Í±ä³ÉÁËÏÂÃæµÄ×Ö·û´®£º
Sql="Select * from Óû§±í where ÐÕÃû='test' or '1' = '1' and ÃÜÂë = 'aaa'
ÎÒÃǶ¼ÖªµÀselectÓï¾äÔÚÅжϲéѯÌõ¼þʱ£¬Óöµ½»ò£¨or£©²Ù×÷¾Í»áºöÂÔÏÂÃæµÄÓ루and£©²Ù×÷£¬¶øÔÚÉÏÃæµÄÓï¾äÖÐ1=1µÄÖµÓÀԶΪtrue£¬ÕâÒâζ×ÅÎÞÂÛÔÚÃÜÂëÖÐÊäÈëʲôֵ£¬¾ùÄÜͨ¹ýÉÏÊöµÄÃÜÂëÑéÖ¤£¡
Select * from Óû§±í where ÐÕÃû = 'ºÏ·¨µÄÐÕÃû' or '1' = '1' and ÃÜÂë = '' //ÎÞÐèÃÜÂë
Select * from Óû§±í where ÐÕÃû = '' or '1'='1' and ÃÜÂë = '' or '1'='1' //ÎÞÐèÓû§ÃûºÍÃÜÂë
Select * from Óû§±í where ÐÕÃû = 'ºÏ·¨µÄÐÕÃû' --' and ÃÜÂë = '' //ÎÞÐèÃÜÂë
½â¾ö·½·¨£º
·ÀÖ¹ASP.NETÓ¦Óñ»SQL×¢Èëʽ¹¥»÷´³Èë²¢²»ÊÇÒ»¼þÌØ±ðÀ§ÄѵÄÊÂÇ飬ֻҪÔÚÀûÓÃ±íµ¥ÊäÈëµÄÄÚÈݹ¹ÔìSQLÃüÁî֮ǰ£¬°ÑËùÓÐÊäÈëÄÚÈݹýÂËÒ»·¬¾Í¿ÉÒÔÁË¡£¹ýÂËÊäÈëÄÚÈÝ¿ÉÒÔ°´¶àÖÖ·½Ê½½øÐУº
1¡¢¼ì²éÓû§ÊäÈëµÄºÏ·¨ÐÔ£¬È·ÐÅÊäÈëµÄÄÚÈÝÖ»°üº¬ºÏ·¨µÄÊý¾Ý¡£Êý¾Ý¼ì²éÓ¦µ±ÔÚ¿Í»§¶ËºÍ·þÎñÆ÷¶Ë¶¼Ö´ÐЗ—Ö®ËùÒÔÒªÖ´ÐзþÎñÆ÷¶ËÑéÖ¤£¬ÊÇΪÁËÃÖ²¹¿Í»§¶ËÑéÖ¤»úÖÆ´àÈõµÄ°²È«ÐÔ¡£ÔÚ¿Í»§¶Ë£¬¹¥»÷ÕßÍêÈ«ÓпÉÄÜ»ñµÃÍøÒ³µÄÔ´´úÂ룬ÐÞ¸ÄÑéÖ¤ºÏ·¨ÐԵĽű¾£¨»òÕßÖ±½Óɾ³ý½Å±¾£©£¬È»ºó½«·Ç·¨ÄÚÈÝͨ¹ýÐ޸ĺóµÄ±íµ¥Ìá½»¸ø·þÎñÆ÷¡£
2¡¢¶ÔÓÚ¶¯Ì¬¹¹ÔìSQL²éѯµÄ³¡ºÏ£¬¿ÉÒÔʹÓÃÏÂÃæµÄ¼¼Êõ£º
µÚÒ»£ºÌæ»»µ¥ÒýºÅ£¬¼´°ÑËùÓе¥¶À³öÏֵĵ¥ÒýºÅ¸Ä³ÉÁ½¸öµ¥ÒýºÅ¡£
µÚ¶þ£ºÉ¾³ýÓû§ÊäÈëÄÚÈÝÖеÄËùÓÐÁ¬×Ö·û¡£
µÚÈý£º¶ÔÓÚÓÃÀ´Ö´ÐвéѯµÄÊý¾Ý¿âÕÊ»§£¬ÏÞÖÆÆäȨÏÞ¡£Óò»Í¬µÄÓû§ÕÊ»§Ö´Ðвéѯ¡¢²åÈë¡¢¸üС¢É¾³ý²Ù×÷¡£ÓÉÓÚ¸ôÀëÁ˲»Í¬ÕÊ»§¿ÉÖ´ÐеIJÙ×÷£¬Òò¶øÒ²¾Í·ÀÖ¹ÁËÔ±¾ÓÃÓÚÖ´ÐÐSELECTÃüÁîµÄµØ·½È´±»ÓÃÓÚÖ´ÐÐINSERT¡¢UPDATE»òDELETEÃüÁî¡£
3¡¢Óô洢¹ý³ÌÀ´Ö´ÐÐËùÓеIJéѯ¡£SQL²ÎÊýµÄ´«µÝ·½Ê½½«·ÀÖ¹¹¥»÷ÕßÀûÓõ¥ÒýºÅºÍÁ¬×Ö·ûʵʩ¹¥»÷¡£´ËÍ⣬Ëü»¹Ê¹µÃÊý¾Ý¿âȨÏÞ¿ÉÒÔÏÞÖÆµ½Ö»ÔÊÐíÌØ¶¨µÄ´æ´¢¹ý³ÌÖ´ÐУ¬ËùÓеÄÓû§ÊäÈë±ØÐë×ñ´Ó±»µ÷ÓõĴ洢¹ý³ÌµÄ°²È«ÉÏÏÂÎÄ£¬ÕâÑ
Ïà¹ØÎĵµ£º
¹ØÓڿؼþͼ±êµÄÊ£¬¿ÉûÉÙϹÕÛÌÚ£¬´ÓǰÄêÏëÈëÊÖÕâ·½Ãæ¿ªÊ¼£¬¾Íû¸ã¶¨¹ý¡£N¶à´óϺµÄÌù×Ó¶¼·ÀÃÁË£¬Ò²Ã»ÕÒ³ö¸öÍ·Ð÷À´¡£Æäʵ×ʼÓдÎÕæ¸øÃɳöÀ´ÁË£¡²»¹ýºóÀ´¸Ä¿Ø¼þ£¬Ò²²»ÖªµÀ¸ÄÄÄÁË¡£Ã»ÁË£¡ÓÚÊÇÂúÊÀ½çµÄCSDN¡¢MSDN¡£¡£¡£¡£NBµÄÈË£¬NBµÄÎÄÕ¿´ÁËÑÛÔΣ¬´òËÀҲûÓÐŪ³öÀ´¡£×òÌìÏîÄ¿ÖÐÓöµ½ÎÊÌ⣬¿´ÁËÒ»¸çÃǵĿؼþ£¨WEBABCD£ºÖÁ½ñ ......
ÓÉÓÚÏîÄ¿ÖжദÐèÒª¶ÔÅäÖÃÎļþ½øÐвÙ×÷£¬ÈçÅäÖÃÐÅÏ¢µÄ¶ÁÈ¡¡¢¸ü¸ÄºÍдÈ룬ÐèÒªÒ»¸öͨÓõÄÀàÀ´¶ÔÆä½øÐвÙ×÷ºÍ´¦Àí¡£Õâ´ÎµÄÈÎÎñ¾ÍÊÇÅäÖýڵÄһЩÓ÷¨¡£
Õâ´ÎÉý¼¶ºóµÄ¿ª·¢¹¤¾ßÊÇ»ùÓÚVS2005µÄ£¬·ÖÎöÁËVS2005 ÐÂÔöµÄһЩ¹¦ÄÜ£¬Ëü×Ô´øÁËÒ»Ì×ÅäÖÃÎļþÖнáµãµÈµÄÅäÖá£Ä¿Ç°µÄÏîÄ¿ÓõÄÅä ......
ÔÎÄ http://www.886s.com/blog/?p=96
Ëæ×ÅAjaxµÄÊ¢ÐУ¬´ó¼Ò¶¼È¥´ÕÈÈÄÖ£¬ÎÒÃǵÄÏîĿҲ²»ÀýÍâ¡£
¿´ÁËÒ»ÏÂÏÖÓеĴúÂ룬¶ÔÓÚÒ»¸ö²Ù×÷³éȡһ¸öµÄÒ³Ãæ£¬°Ñ²ÎÊý½ÓÊÕ£¬µ÷ÓÃÂß¼²ãµÄÏà¹Øº¯Êý²¢·µ»ØÏàÓ¦µÄJson»òÕßXml£¬ËÑË÷ÁËһϣ¬¹¤³ÌÖо¹È»ÓÐÁË360+¸öÕâÖÖÒ³Ãæ£¬ÕâÕæÊÇÒ»ÖÖÀË·Ñ£¡Èç¹ûÓ÷´É䣬һ¸öÒ³Ãæ¾Í¿ÉÒԸ㶨£¡½ÚÊ¡Á˶àÉ ......
1. Êý¾Ý¿â·ÃÎÊÐÔÄÜÓÅ»¯¡¡
¡¡
Êý¾Ý¿âµÄÁ¬½ÓºÍ¹Ø±Õ
·ÃÎÊÊý¾Ý¿â×ÊÔ´ÐèÒª´´½¨Á¬½Ó¡¢´ò¿ªÁ¬½ÓºÍ¹Ø±ÕÁ¬½Ó¼¸¸ö²Ù×÷¡£ÕâЩ¹ý³ÌÐèÒª¶à´ÎÓëÊý¾Ý¿â½»»»ÐÅÏ¢ÒÔͨ¹ýÉí·ÝÑéÖ¤£¬±È½ÏºÄ·Ñ·þÎñÆ÷×ÊÔ´¡£ASP.NETÖÐÌṩÁËÁ¬½Ó³Ø(Connection Pool)¸ÄÉÆ´ò¿ªºÍ¹Ø±ÕÊý¾Ý¿â¶ÔÐÔÄܵÄÓ°Ï졣ϵͳ½«Óû§µÄÊý¾Ý¿âÁ¬½Ó·ÅÔÚÁ¬½Ó³ØÖУ¬ÐèҪʱȡ³ö£¬¹Ø±ÕÊ±Ê ......
ʹÓÃASP.NETÉú³É¾²Ì¬Ò³ÃæµÄ·½·¨ÓÐÁ½ÖÖ£¬µÚÒ»ÖÖÊÇʹÓÃC#ÔÚºǫ́Ӳ±àÂ룬µÚ¶þÖÖÊǶÁȡģ°åÎļþ£¬Ê¹ÓÃ×Ö·û´®Ìæ»»µÄ·½·¨¡£µÚÒ»ÖÖ·½·¨±àÂëÁ¿´ó£¬
¶øÇÒά»¤±È½ÏÀ§ÄÑ¡£ÎÒÖØµã½²½âµÚ¶þÖÖ·½·¨¡£µÚ¶þÖÖ·½·¨µÄ»ù±¾Ë¼Â·ÊÇ£ºÊ¹ÓÃDWÖ®ÀàµÄ¹¤¾ßÉú³ÉÒ»¸ö¾²Ì¬Ò³ÃæÄ£°å¡£¶ÁÈ¡¸ÃÄ£°åÎļþ£¬È»ºó¶ÔÀïÃæµÄÌØÊâ±ê¼ÇʹÓÃ
ÕæÊµµÄÊý¾ÝÌæ»»µô£¬²¢Éú³ÉÒ ......