ASP.NET SQL ×¢Èë½â¾ö·½°¸
ÈκÎÒ»ÖÖʹÓÃÊý¾Ý¿âweb³ÌÐò£¨µ±È»£¬Ò²°üÀ¨×ÀÃæ³ÌÐò£©¶¼Óб»SQL×¢ÈëµÄ·çÏÕ¡£·ÀÖ¹±»SQL×¢È룬×î»ù±¾µÄ·½·¨ÊÇÔÚ´úÂë¼¶±ð¾ÍÒª×èÖ¹ÕâÖÖ¿ÉÄÜ£¬Õâ¸öÍøÉϽ²µÄºÜ¶à£¬ÎҾͲ»¶à˵ÁË¡£²»¹ýÈç¹ûÄãÄõ½µÄÊÇÒ»¸öÒѾÍ깤µÄ²úÆ·£¬Õâ¸öʱºò¸ÃÈçºÎ½â¾öÄØ£¿ÎÒ½éÉܼ¸ÖÖ¶ÔÓÚASPºÍASP.NETÓÐЧµÄ·ÀÖ¹SQL×¢ÈëµÄ·½°¸£¬¶øÇÒÊÇÃâ·ÑµÄ¡£
UrlScan 3.1
UrlScan 3.1ÊÇÒ»¸ö°²È«·½ÃæµÄ¹¤¾ß£¬Î¢Èí¹Ù·½µÄ¶«Î÷¡£Ëü»á¼ì²éËùÓÐIIS´¦ÀíµÄHTTPÇëÇó¡£UrlScan ¿ÉÒÔÔÚÓа²È«ÎÊÌâµÄHTTPÇëÇóµ½´ïÓ¦ÓóÌÐò֮ǰ¾Í×èÖ¹Õâ¸öÇëÇó¡£UrlScan 3.1 ÊÇUrlScan 2.5µÄÒ»¸öÉý¼¶°æ±¾£¬Ö§³ÖWindows Vista ºÍWindows Server 2008ϵͳ֮ÉϵÄIIS 5.1, IIS 6.0 ºÍ IIS 7.0¡£
Á´½ÓµØÖ·£ºhttp://www.iis.net/expand/UrlScan ÕâÀﻹÓкܶà·Ç³£ÓÐÓõÄIISÀ©Õ¹£¬¿ÉÒÔ¿´¿´¡£
IIS 6 SQL Injection Sanitation ISAPI Wildcard
Õâ¸öISAPI dll Ò²ÊÇͨ¹ý¼ì²éHTTPÇëÇó±ÜÃâSQL×¢Èë¡£Ö»¼æÈÝwindows 2003É쵀 IIS 6.0¡£¶ÔÓÚWindows XP É쵀 IIS 5 ²»Ö§³Ö¡£
ÕâÊÇÒ»¸ö¿ªÔ´ÏîÄ¿£ºhttp://www.codeplex.com/IIS6SQLInjection
ת×Ô:http://www.cnblogs.com/DotNetNuke/archive/2009/12/30/1635758.html
Ïà¹ØÎĵµ£º
ϵͳ»·¾³£ºWindows 7
Èí¼þ»·¾³£ºVisual C++ 2008 SP1 +SQL Server 2005
±¾´ÎÄ¿µÄ£º±àдһ¸öº½¿Õ¹ÜÀíϵͳ
ÕâÊÇÊý¾Ý¿â¿Î³ÌÉè¼ÆµÄ³É¹û£¬ËäÈ»³É¼¨²»¼Ñ£¬µ«ÊÇ×÷ΪÎÒÓÃVC++ ÒÔÀ´±àдµÄ×î´ó³ÌÐò»¹ÊÇ´«µ½ÍøÉÏ£¬ÒÔ¹©²Î¿¼¡£ÓÃVC++ ×öÊý¾Ý¿âÉè¼Æ²¢²»ÈÝÒ×£¬µ«Ò²²»ÊDz»¿ÉÄÜ¡£ÒÔÏÂÊÇÎҵijÌÐò½çÃæ£¬ºóÃæ ......
PL/SQL¿é
declare
begin
--SQLÓï¾ä
--Ö±½ÓдµÄSQLÓï¾ä(DML/TCL)
--¼ä½Óдexecute immediate <DDL/DCLÃüÁî×Ö·û´®>
--select Óï¾ä
<1>±ØÐë´øÓÐinto×Ó¾ä
......
±ÈÈçÔÚNorthwindÊý¾Ý¿âÖÐ
ÓÐÒ»¸ö²éѯΪ
SELECT c.CustomerId, CompanyName
from Customers c
WHERE EXISTS(
SELECT OrderID from Orders o
WHERE o.CustomerID = cu.CustomerID)
ÕâÀïÃæµÄEXISTSÊÇÈçºÎÔË×÷ÄØ£¿×Ó²éѯ·µ»ØµÄÊÇOrderId×ֶΣ¬¿ÉÊÇÍâÃæµÄ²éѯҪÕÒµÄÊÇCustomerIDºÍCompanyName×ֶΣ¬ÕâÁ½¸ö×Ö¶Î¿Ï ......
ORACLE SQLÐÔÄÜÓÅ»¯ÏµÁÐ
1. ·ÃÎÊTableµÄ·½Ê½
ORACLE ²ÉÓÃÁ½ÖÖ·ÃÎʱíÖмǼµÄ·½Ê½:
a. È«±íɨÃè
È«±íɨÃè¾ÍÊÇ˳ÐòµØ·ÃÎʱíÖÐÿÌõ¼Ç¼. ORACLE²ÉÓÃÒ»´Î¶ÁÈë¶à¸öÊý¾Ý¿é(database block)µÄ·½Ê½ÓÅ»¯È«±íɨÃè.
b. ͨ¹ýROWID·ÃÎʱí
Äã¿ÉÒÔ²ÉÓûùÓÚROWIDµÄ·ÃÎÊ·½Ê½Çé¿ö,Ìá¸ß·ÃÎʱíµÄЧÂÊ, , ROWID°üº¬Á˱íÖмǼµ ......
ÏÈÀ´Ò»¶Î´úÂ룺
WITH OrderedOrders AS
(SELECT *,
ROW_NUMBER() OVER (order by [id])as RowNumber¡¡¡¡--idÊÇÓÃÀ´ÅÅÐòµÄÁÐ
from table_info ) --table_infoÊDZíÃû
SELECT *
from OrderedOrders
WHERE RowNumber between 50 and 60;
ÔÚwindows server 2003, sql server 2005 CTP,P4 2.66GHZ,1GB ÄÚ´æÏ²âÊÔ£¬Ö´ÐÐʱ ......