Ò׽ؽØͼÈí¼þ¡¢µ¥Îļþ¡¢Ãâ°²×°¡¢´¿ÂÌÉ«¡¢½ö160KB

ASP.NET·ÀSQL×¢Èë½Å±¾³ÌÐò v2.0

public class SqlCheck
{
public SqlCheck()
{
//
// TODO: ÔÚ´Ë´¦Ìí¼Ó¹¹Ô캯ÊýÂß¼­
//
}

public SqlConnection oconn()
{
SqlConnection conn = new SqlConnection();
conn.ConnectionString = ConfigurationManager.ConnectionStrings["StudyConnectionString"].ToString();
//µÚ1ÖÖµ÷Óõķ½·¨ JK1986_CheckSql();
JK1986_CheckSql();
if ( conn.State == ConnectionState.Closed )
{
conn.Open();
}
return conn;
}
public DataTable getsource(string getds)
{
SqlConnection conn = oconn();
SqlDataAdapter da = new SqlDataAdapter(getds, conn);
DataSet ds = new DataSet();
da.Fill(ds,"news" );
return ds.Tables["news"];
}

public static void JK1986_CheckSql()
{
string jk1986_sql = "exec↓select↓drop↓alter↓exists↓union↓and↓or↓xor↓order↓mid↓asc↓execute↓xp_cmdshell↓insert↓update↓delete↓join↓declare↓char↓sp_oacreate↓wscript.shell↓xp_regwrite↓'↓;↓--";
string[] jk_sql = jk1986_sql.Split('↓');
foreach (string jk in jk_sql)
{
// -----------------------·À Post ×¢Èë-----------------------
if ( System.Web.HttpContext.Current.Request.Form != null)
{
for (int k = 0; k < System.Web.HttpContext.Current.Request.Form.Count; k++)
{
string getsqlkey = System.Web.HttpContext.Current.Request.Form.Keys[k];
string getip;
if (System.Web.HttpContext.Current.Request.Form[getsqlkey].ToLower().Contains(jk) == true)
{
System.Web.HttpContext.Current.Response.Write("<script Language=JavaScript>alert('ASP.NET( C#°æ±¾ )·À×¢Èë³ÌÐòÌáʾÄú£¬ÇëÎðÌá½»·Ç·¨×Ö·û£¡↓\\n\\nBlog:http://hi.


Ïà¹ØÎĵµ£º

ASP.NET ½«±í¸ñ¿Ø¼þ°ó¶¨µ½ XmlDataSource ¿Ø¼þ


      XmlDataSource ¿Ø¼þÖ÷ÒªÓÃÓÚ½«·Ö²ãµÄ XML Êý¾Ý¹«¿ª¸øÖîÈç TreeView »ò Menu ¿Ø¼þµÈ°ó¶¨¿Ø¼þ¡£»¹¿ÉÒÔ½« GridView »ò DataList ¿Ø¼þµÈ±í¸ñÊý¾Ý°ó¶¨¿Ø¼þ°ó¶¨µ½ XmlDataSource ¿Ø¼þ¡£
 
Ò»¡¢°ó¶¨µ½ XML Êý¾ÝÖеÄ×Ö¶Î
ÔÚ½«±í¸ñÊý¾Ý°ó¶¨¿Ø¼þ°ó¶¨µ½ XmlDataSource ¿Ø¼þʱ£¬¸Ã¿Ø¼þ½ö³ÊÏÖ ......

ASP.NET—fromÑéÖ¤

Step 1£ºÐ½¨Êý¾Ý¿â(¿â£ºMyForms £»±í£ºusers £»×ֶΣºID£¬userName, userPwd)£»
Step 2£ºÐ½¨ÍøÕ¾£¬web.config µÄÎļþÈ«²¿´úÂëÈçÏ£º
web.config µÄÈ«²¿´úÂë
<?xml version="1.0"?>
<configuration>
    <appSettings/>
    <connectionStrings/>
  ......

asp.netµÄ¼¸ÖÖÒ³Ãæ´«Öµ·½·¨

1. ʹÓÃQueryString±äÁ¿
¡¡¡¡QueryStringÊÇÒ»Öַdz£¼òµ¥µÄ´«Öµ·½Ê½£¬Ëû¿ÉÒÔ½«´«Ë͵ÄÖµÏÔʾÔÚä¯ÀÀÆ÷µÄµØÖ·À¸ÖС£Èç¹ûÊÇ´«µÝÒ»¸ö»ò¶à¸ö°²È«ÐÔÒªÇ󲻸߻òÊǽṹ¼òµ¥µÄÊýֵʱ£¬¿ÉÒÔʹÓÃÕâ¸ö·½·¨¡£µ«ÊǶÔÓÚ´«µÝÊý×é»ò¶ÔÏóµÄ»°£¬¾Í²»ÄÜÓÃÕâ¸ö·½·¨ÁË¡£ÏÂÃæÊÇÒ»¸öÀý×Ó£º
a.aspxµÄC#´úÂë
private void Button1_Click(object sende ......

asp.netÂÒÂë´¦Àí

ÔÚWeb.ConfigÎļþÀïÃæ
<system.web>
   ¼ÓÈëÒ»ÏÂÕâ¶Î´úÂë
</system.web>
<globalization requestEncoding="GB2312" responseEncoding ="GB2312"/>
˳±ã˵һÏÂUrlencodeµÄ±àÂë¼¼ÇÉ¡£
System.Web.HttpUtility.UrlEncode(str, Encoding.GetEncoding("GB2312"));
¿ÉÒÔ¸ù¾ÝÐèҪȥ¸ñʽ»¯UrlµÄ ......

ASP.NET Ò³Ãæ¼äÊý¾Ý´«µÝ·½·¨

0¡¢ÒýÑÔ
    Web Ò³ÃæÊÇÎÞ״̬µÄ£¬ ·þÎñÆ÷¶Ôÿһ´ÎÇëÇó¶¼ÈÏΪÀ´×Ô²»Í¬Óû§£¬Òò´Ë£¬±äÁ¿µÄ״̬ÔÚÁ¬Ðø¶ÔͬһҳÃæµÄ¶à´ÎÇëÇóÖ®¼ä»òÔÚÒ³ÃæÌøתʱ²»»á±»±£Áô¡£ÔÚÓÃAsp.NET Éè¼Æ¿ª·¢Ò»¸öWebϵͳʱ£¬ Óöµ½Ò»¸öÖØÒªµÄÎÊÌâÊÇÈçºÎ±£Ö¤Êý¾ÝÔÚÒ³Ãæ¼ä½øÐÐÕýÈ·¡¢°²È«ºÍ¸ßЧµØ´«ËÍ£¬Asp.net ÌṩÁË״̬¹ÜÀíµÈ¶àÖÖ¼¼ÊõÀ´½â¾ ......
© 2009 ej38.com All Rights Reserved. ¹ØÓÚE½¡ÍøÁªÏµÎÒÃÇ | Õ¾µãµØͼ | ¸ÓICP±¸09004571ºÅ