Ò»Ì×»ùÓÚasp.netµÄ°²È«Ð£Ñé»úÖÆÓ¦ÓÃÄ£ÐÍ £¡
using System;
using System.Data;
using System.Configuration;
using System.Linq;
using System.Web;
using System.Web.Security;
using System.Web.UI;
using System.Web.UI.HtmlControls;
using System.Web.UI.WebControls;
using System.Web.UI.WebControls.WebParts;
using System.Xml.Linq;
using System.IO;
using System.Text;
using System.Web.UI.MobileControls;
using System.Collections.Generic;
/// <summary>
///SQLFilter µÄժҪ˵Ã÷
/// </summary>
public static class SQLFilter
{
#region SQL×¢Èë¹ýÂË
/// <summary>
/// SQL×¢Èë¹ýÂË
/// </summary>
/// <param name="sqlParems">Òª¹ýÂ˵IJÎÊýÊý×é</param>
/// <returns>Èç¹û²ÎÊý´æÔÚ²»°²È«×Ö·û£¬Ôò·µ»Øfalse</returns>
// Ó¦ÓÃʾÀý
// if(TheManagerUtils.SqlFilter(new string[] { "ss","kk" }, this.Page) == false)
// {
// //Ö±½ÓÌø×ªµ½ÏàÓ¦µÄ´íÎóÒ³Ãæ
// Response.Redirect("WelfarePage.aspx");
// return;
// }
public static bool SqlFilter(string[] sqlParems, Page p)
{
StringBuilder parems = new StringBuilder();
#region ÓйطǷ¨Êý¾ÝµÄÏà¹ØÎ¬»¤
//³£ÓõÄSQL¶ñÒâ×Ö·ûÆÁ±Î
string sql = "insert|delete|update|select|exec|script";
try
{
//»ñÈ¡ÅäÖÃÔÚWeb.configÖÐ×îеÄSQL¶ñÒâ×Ö·ûÆÁ±Î
sql = System.Configuration.ConfigurationSettings.AppSettings["
Ïà¹ØÎĵµ£º
1. C#ÓïÑÔ·½Ãæ
1.1 À¬»ø»ØÊÕ
¡¡À¬»ø»ØÊÕ½â·ÅÁËÊÖ¹¤¹ÜÀí¶ÔÏóµÄ¹¤×÷£¬Ìá¸ßÁ˳ÌÐòµÄ½¡×³ÐÔ£¬µ«¸±×÷ÓþÍÊdzÌÐò´úÂë¿ÉÄܶÔÓÚ¶ÔÏó´´½¨±äµÃËæÒâ¡£
¡¡1.1.1 ±ÜÃâ²»±ØÒªµÄ¶ÔÏó´´½¨
¡¡ÓÉÓÚÀ¬»ø»ØÊյĴú¼Û½Ï¸ß£¬ËùÒÔC#³ÌÐò¿ª·¢Òª×ñѵÄÒ»¸ö»ù±¾ÔÔò¾ÍÊDZÜÃâ²»±ØÒªµÄ¶ÔÏó´´½¨¡£ÒÔÏÂÁоÙһЩ³£¼ûµÄÇéÐΡ£
¡¡1.1.1.1 ±ÜÃâÑ»·´´½¨¶ÔÏ ......
1.<a href=”test.aspx”></a>
2.ÕâÊÇ×î³£¼ûµÄÒ»ÖÖתÏò·½·¨;
HyperLink¿Ø¼þ
1.Asp.net ·þÎñÆ÷¶Ë¿Ø¼þ ÊôÐÔNavigateUrlÖ¸¶¨ÒªÌø×ªµ½µÄUrlµØÖ·
2.NavigateUrlÊÇ¿ÉÒÔÔÚ·þÎñÆ÷¶ËʹÓôúÂëÐ޸ģ¬Õâ¸öÇø±ðÓÚ<a>
3.ÓÉÓÚHyperLink±¾ÉíûÓÐʼþËùÒÔÒªÔÚ·þÎñÆ÷¶ËÆäËüʼþÖÐÉèÖÃNavigateUrl
4.´ ......
¹ØÓÚÒ³Ãæ´«ÖµµÄ·½·¨£¬Òý·¢Á˺ܶàÌÖÂÛ¡£¿´À´ÓкܶàÈ˹Ø×¢Õâ¸ö£¬ÎÒ¾ÍÎÒ¸öÈ˹۵ã×öÁËЩ×ܽᣬϣÍû¶Ô´ó¼ÒÓÐËù°ïÖú¡£
1. ʹÓÃQueryString±äÁ¿
QueryStringÊÇÒ»Öַdz£¼òµ¥µÄ´«Öµ·½Ê½£¬Ëû¿ÉÒÔ½«´«Ë͵ÄÖµÏÔʾÔÚä¯ÀÀÆ÷µÄµØÖ·À¸ÖС£Èç¹ûÊÇ´«µÝÒ»¸ö»ò¶à¸ö°²È«ÐÔÒªÇ󲻸߻òÊǽṹ¼òµ¥µÄÊýֵʱ£¬¿ÉÒÔʹÓÃÕâ¸ö·½·¨¡£µ«ÊǶÔÓÚ´«µ ......
ÓÐʱ»áÅöµ½
System.IO.Directory.Exists("\\server11\jqb")
×ÜÊÇ·µ»Øfalse,˵·¾¶²»´æÔÚ£¬ÊÂʵÉÏËüÊÇ´æÔڵģ¬ÒýÆðÕâ¸öÎÊÌâµÄÔÒòÊÇÓÉÓÚwindowµÄȨÏÞÎÊÌâ
¡£
½â¾ö·½°¸ÈçÏ£º
1¡£ÔÚaspx±¾»úºÍÓû·ÃÎʵÄÔ¶³ÌÖ÷»ú£¨Èç server11£©·Ö±ð½¨Ò»¸öÃû³Æ£¨Èç jqbsystem£©ºÍÃÜÂ루Èç
1234£©Ò»Ä£Ò»ÑùµÄwindowsÕʺÅ
2¡£ÔÚweb.configÖ ......
--aspxÎļþ
<%@ Page Language="C#" AutoEventWireup="true" CodeFile="NetWork.aspx.cs" Inherits="NetWork" %>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<he ......