SQL ·À×¢Èëʽ¹¥»÷
1¡¢¼ì²éÊÇ·ñÓзǷ¨×Ö·û
public static boolean sql_inj(String str)
{
String inj_str = "'|and|exec|insert|select|delete|update|
count|*|%|chr|mid|master|truncate|char|declare|;|or|-|+|,";
//ÕâÀïµÄ¶«Î÷»¹¿ÉÒÔ×Ô¼ºÌí¼Ó
String[] inj_stra=inj_str.split("\\|");
for (int i=0 ; i <; inj_stra.length ; i++ )
{
if (str.indexOf(inj_stra[i])<=0)
{
return true;
}
}
return false;
}
2¡¢¹ýÂË·Ç·¨×Ö·û
public static String TransactSQLInjection(String str)
{
return str.replaceAll(".*([';]+|(--)+).*", " ");
}
Ïà¹ØÎĵµ£º
-- ±íµÄ½á¹¹ area
DROP TABLE area;
CREATE TABLE area (
id int NOT NULL ,
areaID int NOT NULL,
area varchar(200) NOT NULL,
fatherID int NOT NULL,
PRIMARY KEY (id)
)
DROP TABLE city;
CREATE TABLE city select
id int NOT NULL ......
ÔÚÈëÃÅƪ£¬ÎÒÃÇѧ»áÁˣӣѣÌ×¢ÈëµÄÅжϷ½·¨£¬µ«ÕæÕýÒªÄõ½ÍøÕ¾µÄ±£ÃÜÄÚÈÝ£¬ÊÇÔ¶Ô¶²»¹»µÄ¡£½ÓÏÂÀ´£¬ÎÒÃǾͼÌÐøѧϰÈçºÎ´ÓÊý¾Ý¿âÖлñÈ¡ÏëÒª»ñµÃµÄÄÚÈÝ£¬Ê×ÏÈ£¬ÎÒÃÇÏÈ¿´¿´£Ó£Ñ£Ì×¢ÈëµÄÒ»°ã²½Ö裺
µÚÒ»½Ú¡¢£Ó£Ñ£Ì×¢ÈëµÄÒ»°ã²½Öè
¡¡¡¡Ê×ÏÈ£¬Åжϻ·¾³£¬Ñ°ÕÒ×¢Èëµã£¬ÅжÏÊý¾Ý¿âÀàÐÍ£¬ÕâÔÚÈëÃÅƪÒѾ½²¹ýÁË¡£
¡¡¡¡Æä´Î£¬¸ù¾Ý×¢Èë ......
À´Ô´:http://hi.baidu.com/czgblog/blog/item/3abd5aa911d51ff51f17a292.html
function OnFirstUIAfter()
STRING szTitle, szMsg1, szMsg2, szOpt1, szOpt2;
NUMBER bvOpt1, bvOpt2;
NUMBER bShowUpdateServiceDlg;
......
--µ±Á½¸ö»òÁ½ÒÔÉϵIJÙ×÷Ҫô¶¼Ö´ÐУ¬ÒªÃ´¶¼²»Ö´ÐÐʱҪÓÃÊÂÎñ¡£
1. Sqlд·¨(ÊÂÎï+Óαê)
--¿ªÊ¼ÊÂÎñ
BEGIN TRAN
--²»ÏÔʾ¼ÆÊýÐÅÏ¢
SET NOCOUNT ON
DECLARE @ProjNo varchar(50),@CusNo varchar(50)
--ÉùÃ÷Óαê
DECLARE CRMPSContact_cursor CURSOR FOR
SEL ......
1.²éѯµÄÄ£ºýÆ¥Åä
¾¡Á¿±ÜÃâÔÚÒ»¸ö¸´ÔÓ²éѯÀïÃæʹÓà LIKE '%parm1%'—— ºìÉ«±êʶλÖõİٷֺŻᵼÖÂÏà¹ØÁеÄË÷ÒýÎÞ·¨Ê¹Óã¬×îºÃ²»ÒªÓÃ.
½â¾ö°ì·¨:
ÆäʵֻÐèÒª¶Ô¸Ã½Å±¾ÂÔ×ö¸Ä½ø£¬²éѯËٶȱã»áÌá¸ß½ü°Ù±¶¡£¸Ä½ø·½·¨ÈçÏ£º
a¡¢ÐÞ¸Äǰ̨³ÌÐò——°Ñ²éѯÌõ¼þµÄ¹©Ó¦ÉÌÃû³ÆÒ»À¸ÓÉÔÀ´µÄÎı¾ÊäÈë¸ÄΪÏÂÀÁб ......