Ò׽ؽØͼÈí¼þ¡¢µ¥Îļþ¡¢Ãâ°²×°¡¢´¿ÂÌÉ«¡¢½ö160KB

SQLÊÖ¹¤×¢ÉäÔ­Àí

     ¹ØÓÚSQL×¢Èë(SQL Injection)µÄ·½·¨Æäʵ¶¼ºÜÆÕ±éºÍʹÓ㬹éÄÉÆðÀ´Ò²ºÜ·½±ã¡£Ò»°ã“ºÚ¿Í”ʹÓõÄÊÇÏֳɵŤ¾ßÈç“WEBÅÔ×¢¡¢°¢DÍøÂ繤¾ß°ü¡¢½ÌÖ÷XXX”µÈÕâЩ¶¼ÊǼ¯³ÉÁË
һЩ³£ÓõÄsql×¢ÈëÓï¾ä¡£ÏÂÃæÎÒ½«½éÉÜÈçºÎʹÓÃÊÖ¹¤×¢ÈëMYSQL,MSSQLÊý¾Ý¿â.
    Ò»°ã©¶´²úÉúµÄÔ­Òò : ³ÌÐòÖ´ÐÐÖÐδ¶ÔÃô¸Ð×Ö·û½øÐйýÂË,ʹµÃ¹¥»÷Õß´«Èë¶ñÒâ×Ö·û´®Óë½á¹¹»¯Êý¾Ý²éѯÓï¾äºÏ²¢,²¢ÇÒÖ´ÐжñÒâ´úÂë.
´´½¨textÊý¾Ý±íMYSQL´úÂë:
create database if not exists `test`;
USE `test`;
/*Êý¾Ý±í `account` µÄ±í½á¹¹*/
DROP TABLE IF EXISTS `account`;
CREATE TABLE `account` (
  `accountId` bigint(20) NOT NULL auto_increment,
  `accountName` varchar(32) default NULL,
  `accountPass` varchar(32) default NULL,
  PRIMARY KEY  (`accountId`)
) ENGINE=InnoDB DEFAULT CHARSET=latin1;
/*Êý¾Ý±í `account` µÄÊý¾Ý*/
insert into `account` values  
(1,'account1','account1');
/*Êý¾Ý±í `admin` µÄ±í½á¹¹*/
DROP TABLE IF EXISTS `admin`;
CREATE TABLE `admin` (
  `adminId` bigint(20) NOT NULL auto_increment,
  `adminName` varchar(32) default NULL,
  `adminPass` varchar(32) default NULL,
  PRIMARY KEY  (`adminId`)
) ENGINE=InnoDB DEFAULT CHARSET=latin1;
/*°ÑÊý¾Ý²åÈëÊý¾Ý±í `admin` µÄÊý¾Ý*/
insert into `admin` values  
(1,'admin','admin');
2.©¶´µÄÀûÓÃ
Õâ¸ö¾ÍÊÇÊý¾Ý¿âÀïµÄ¼Ç¼ÁË.ÒÔºó»ÆɫΪ¹Ø¼üÓï¾ä,ºìɫΪÊäÈëµÄ²¿·Ö.
    ´ó¼Ò×¢Òâ¿´resultSet = statment.executeQuery("select * from account where accountId = '"+ request.getParameter("id") +"'");
ÕâÀïµÄrequest.getParameter("id") ÊÇ»ñÈ¡GET´«²ÎµÄid ²ÎÊý,Ò²¾ÍÊÇmysqlInject.jsp?id=1 ÕâÀïµÄid. ÕâÑùÕâ¸öSQLÓï¾ä¾Í±ä³ÉÁËselect * from account where accountId = 
'1' ÁË.Èç¹û¼ÓÒԱ任ÄØ?
2.1©¶´µÄ¼ì²â
    ÎÒÃÇ°Ñid д³ÉmysqlInject.jsp?id=1' ÄÇôSQL Óï¾ä¾Í±ä³Éselect * from account where accountId = '1'' ÁË,ÕâÑùµÄ»°SQLÓï¾ä¾Í»á±¨´í,ÒòΪSQLÓï¾äµÄÖµÊÇÐèÒª2¸ö°üº¬
·ûºÅ,±ÈÈ璺͔Èç¹ûÖ»ÊÇÊý×Ö¿ÉÒÔʲô¶¼²»Ð´.Èç¹û


Ïà¹ØÎĵµ£º

SQL ServerʵÏÖÊý¾Ý¿â¶¨Ê±×Ô¶¯±¸·Ý

ÔÚSQL ServerÖгöÓÚÊý¾Ý°²È«µÄ¿¼ÂÇ£¬ËùÒÔÐèÒª¶¨Æڵı¸·ÝÊý¾Ý¿â¡£¶ø±¸·ÝÊý¾Ý¿âÒ»°ãÓÖÊÇÔÚÁ賿ʱ¼ä»ù±¾Ã»ÓÐÊý¾Ý¿â²Ù×÷µÄʱºò½øÐУ¬ËùÒÔÎÒÃDz»¿ÉÄÜÒªÇó¹ÜÀíԱÿÌìÊص½ÍíÉÏ1µãÈ¥±¸·ÝÊý¾Ý¿â¡£ÒªÊµÏÖÊý¾Ý¿âµÄ¶¨Ê±×Ô¶¯±¸·Ý£¬×î³£Óõķ½Ê½¾ÍÊÇʹÓÃSQL Server´úÀíÖеÄ×÷Òµ¡£Æô¶¯SQL Server Agent·þÎñ£¬È»ºóÔÚÆäÖÐн¨×÷Òµ£¬×÷ÒµÖÐÌí¼ ......

ASP³ÌÐòÓëSQL´æ´¢¹ý³ÌÏê½â

  ´æ´¢½ø³Ì¾ÍÊÇ×÷Ϊ¿ÉÖ´ÐжÔÏó´æ·ÅÔÚÊý¾Ý¿âÖеÄÒ»¸ö»ò¶à¸öSQLÃüÁî¡£
    ¶¨Òå×ÜÊǺܳéÏó¡£´æ´¢½ø³ÌÆäʵ¾ÍÊÇÄÜÍê³ÉÒ»¶¨²Ù×÷µÄÒ»×éSQLÓï¾ä£¬Ö»²»¹ýÕâ×éÓï¾äÊÇ·ÅÔÚÊý¾Ý¿âÖеÄ(ÕâÀïÎÒÃÇ̸ֻSQL SERVER)¡£Èç¹ûÎÒÃÇͨ¹ý´´½¨´æ´¢½ø³ÌÒÔ¼°ÔÚASPÖе÷Óô洢½ø³Ì£¬¾Í¿ÉÒÔ±ÜÃ⽫SQLÓï¾äͬASP´úÂë»ìÔÓÔÚÒ ......

sql´æ´¢¹ý³Ì

 ÔÚASP.NetÏîÄ¿ÖÐʹÓô洢¹ý³Ì,Ê×ÏÈ¿ÉÒÔÌá¸ßÊý¾Ý¿âµÄ°²È«ÐÔ£¬Æä´Î¿ÉÒÔÌá¸ßÔËÐÐSQL´úÂëÔËÐеÄËٶȣ¬ÔÚ´óÐÍÏîÄ¿ÖÐÒ»°ãÊDZز»¿ÉÉٵġ£Visual Studio.NetΪSQLµÄ´æ´¢¹ý³ÌÌṩÁËÇ¿´óµÄÖ§³Ö£¬Äú¼È¿ÉÒÔͨ¹ývisual studio.netÀ´Ð½¨´æ´¢¹ý³Ì£¬Ò²¿ÉÒÔÖ±½ÓÔÚSql ServerµÄ²éѯ·ÖÎöÆ÷ÖÐÔËÐУ¬»¹¿ÉÒÔͨ¹ýÆóÒµ¹ÜÀíÆ÷´´½¨£¬Ê¹ÓÃÆðÀ´Ò² ......

sql serverµÄtinyintÀàÐÍÓë.netÖеÄË­¶ÔÓ¦

 .NETÖÐC#µÄbyte¹Ø¼ü×ÖÓ³Éä.NETµÄByte½á¹¹£º±íʾһ¸ö 8 λÎÞ·ûºÅÕûÊý¡£Byte ÖµÀàÐͱíʾֵ½éÓÚ 0 ºÍ 255 Ö®¼äµÄÎÞ·ûºÅÕûÊý¡£
.NETÖÐC#µÄshort¹Ø¼ü×ÖÓ³Éä.NETÖеÄInt16£ºÓзûºÅ 16 λÕûÊý£¬-32,768 µ½ 32,767¡£
SQL SERVERÖеÄtinyint:´Ó 0 µ½ 255 µÄÕûÐÍÊý¾Ý¡£´æ´¢´óСΪ 1 ×Ö½Ú¡£
sbyte£º´æ´¢8λ´ø·ûºÅÕûÊý¡£sbyt ......

IISÓëSQL·þÎñÆ÷°²È«¼Ó¹ÌÏê½â(ת)

 
IIS Web·þÎñÆ÷°²È«¼Ó¹Ì²½Ö裺
²½Öè¡¡°²×°ºÍÅäÖà Windows Server 2003¡£
×¢Ò⣺
1.½«\System32\cmd.exeתÒƵ½ÆäËûĿ¼»ò¸üÃû£»
2.ϵͳÕʺž¡Á¿ÉÙ£¬¸ü¸ÄĬÈÏÕÊ»§Ãû£¨ÈçAdministrator£©ºÍÃèÊö£¬ÃÜÂ뾡Á¿¸´ÔÓ£»
3.¾Ü¾øͨ¹ýÍøÂç·ÃÎʸüÆËã»ú£¨ÄäÃûµÇ¼£»ÄÚÖùÜÀíÔ±ÕÊ»§£»Support_388945a0£»Guest£»ËùÓзDzÙ×÷ϵͳ·þ ......
© 2009 ej38.com All Rights Reserved. ¹ØÓÚE½¡ÍøÁªÏµÎÒÃÇ | Õ¾µãµØͼ | ¸ÓICP±¸09004571ºÅ