ASP.NET·ÀSQL×¢Èë½Å±¾³ÌÐò v2.0
public class SqlCheck
{
public SqlCheck()
{
//
// TODO: ÔÚ´Ë´¦Ìí¼Ó¹¹Ô캯ÊýÂß¼
//
}
public SqlConnection oconn()
{
SqlConnection conn = new SqlConnection();
conn.ConnectionString = ConfigurationManager.ConnectionStrings["StudyConnectionString"].ToString();
//µÚ1ÖÖµ÷Óõķ½·¨ JK1986_CheckSql();
JK1986_CheckSql();
if ( conn.State == ConnectionState.Closed )
{
conn.Open();
}
return conn;
}
public DataTable getsource(string getds)
{
SqlConnection conn = oconn();
SqlDataAdapter da = new SqlDataAdapter(getds, conn);
DataSet ds = new DataSet();
da.Fill(ds,"news" );
return ds.Tables["news"];
}
public static void JK1986_CheckSql()
{
string jk1986_sql = "exec↓select↓drop↓alter↓exists↓union↓and↓or↓xor↓order↓mid↓asc↓execute↓xp_cmdshell↓insert↓update↓delete↓join↓declare↓char↓sp_oacreate↓wscript.shell↓xp_regwrite↓'↓;↓--";
string[] jk_sql = jk1986_sql.Split('↓');
foreach (string jk in jk_sql)
{
// -----------------------·À Post ×¢Èë-----------------------
if ( System.Web.HttpContext.Current.Request.Form != null)
{
for (int k = 0; k < System.Web.HttpContext.Current.Request.Form.Count; k++)
{
string getsqlkey = System.Web.HttpContext.Current.Request.Form.Keys[k];
string getip;
if (System.Web.HttpContext.Current.Request.Form[getsqlkey].ToLower().Contains(jk) == true)
{
System.Web.HttpContext.Current.Response.Write("<script Language=JavaScript>alert('ASP.NET( C#°æ±¾ )·À×¢Èë³ÌÐòÌáʾÄú£¬ÇëÎðÌá½»·Ç·¨×Ö·û£¡↓\\n\\nBlog:http://hi.
Ïà¹ØÎĵµ£º
ÔÚWeb±à³Ì¹ý³ÌÖУ¬´æÔÚןܶలȫÒþ»¼¡£±ÈÈçÔÚÒÔÇ°µÄASP°æ±¾ÖУ¬CookieΪ·ÃÎÊÕߺͱà³ÌÕ߶¼ÌṩÁË·½±ã£¬²¢Ã»ÓÐÌṩ¼ÓÃܵŦÄÜ¡£´ò¿ªIEä¯ÀÀÆ÷£¬Ñ¡Ôñ“¹¤¾ß”²Ëµ¥ÀïµÄ“InternetÑ¡Ï¬È»ºóÔÚµ¯³öµÄ¶Ô»°¿òÀïµ¥»÷“ÉèÖÔ°´Å¥£¬Ñ¡Ôñ“²é¿´Îļþ”°´Å¥£¬ÔÚµ¯³öµÄ´°¿ÚÖУ¬¾Í»áÏÔʾӲÅÌÀï ......
create PROCEDURE pagelist
@tablename nvarchar(50),
@fieldname nvarchar(50)='*',
@pagesize int output,--ÿҳÏÔʾ¼Ç¼ÌõÊý
@currentpage int output,--µÚ¼¸Ò³
@orderid nvarchar(50),--Ö÷¼üÅÅÐò
@sort int,--ÅÅÐò·½Ê½£¬1±íʾÉýÐò£¬0±íʾ½µÐòÅÅÁÐ
......
¡ïAsp.netÈçºÎÁ¬½ÓSQL Server2000Êý¾Ý¿â¡ï
´ó¼ÒºÃ,ÒÔÏÂÊÇÓйØASP.netÁ¬½ÓSQL Server2000Êý¾Ý¿âµÄÀý³Ì£¬
ÔÚÕâÀïºÍ´ó¼Ò·ÖÏíһϣº
Asp.netÁ¬½ÓSQL Server2000Êý¾Ý¿âÀý³ÌÏê½â:
<%@ Import Namespace="System.Data" %>
<%@ Import NameSp ......
Asp.netÉè¼Æʱ¾³£ÒªÔÚ.aspx.cs´úÂëÖÐдһЩ½Å±¾,ÿ´Î¶¼ÖØÐÂд±È½ÏÂé·³,ËùÒ԰Ѿ³£ÓõÄÕûÀíÁËÒ»ÏÂ,д³ÉÒ»¸ö¹«¹²Àà,ÒÔ±ãÒÔºóµ÷ÓÃ.
using System.Text;
using System.Web;
using System.Web.UI; namespace Lmsoft.Net.Web
{
/**//// <summary>
/// ÎļþÃû: Js.cs ......
ͨ¹ýʹÓÃÑéÖ¤¿Ø¼þ£¬¿ÉÒÔÏò ASP.NET ÍøÒ³ÖÐÌí¼ÓÊäÈëÑéÖ¤¡£ÑéÖ¤¿Ø¼þΪËùÓг£Óõıê×¼ÑéÖ¤ÀàÐÍ£¨ÀýÈ磬²âÊÔij·¶Î§ÄÚµÄÓÐЧÈÕÆÚ»òÖµ£©ÌṩÁËÒ»ÖÖÒ×ÓÚʹÓõĻúÖÆ£¬ÒÔ¼°×Ô¶¨Òå±àдÑéÖ¤µÄ·½·¨¡£´ËÍ⣬ÑéÖ¤¿Ø¼þ»¹ÔÊÐí×Ô¶¨ÒåÏòÓû§ÏÔʾ´íÎóÐÅÏ¢µÄ·½·¨¡£ÑéÖ¤¿Ø¼þ¿ÉÓë ASP.NET ÍøÒ³ÉϵÄÈκοؼ ......