ÈçºÎÓ¦¶ÔWinformsÖÐSQLµÄ×¢Èëʽ¹¥»÷
SqlÓï¾ä×÷Ϊ¹ú¼Ê±ê×¼µÄÊý¾Ý¿â²éѯÓï¾ä£¬±±¾©°á¼Ò¹«Ë¾ ±±¾©Êèͨ¹«Ë¾ÔÚ¸÷ÖÖ±à³Ì»·¾³Öеõ½Á˹㷺µÄÓ¦Óá£×÷Ϊһ¸ö³ÉÊì¡¢Îȶ¨µÄϵͳ£¬Óû§µÇ½ºÍÃÜÂëÑéÖ¤ÊDZز»¿ÉÉٵġ£ÔÚÆ½Ê±µÄ±à³Ì¹¤×÷ÖÐÐí¶à³ÌÐòÔ±ÔÚÓÃsqlÓï¾ä½øÐÐÓû§ÃÜÂëÑé֤ʱÊÇͨ¹ýÒ»¸öÀàËÆÕâÑùµÄÓï¾äÀ´ÊµÏֵģº
strSel = " Select * from Óû§±í where ÐÕÃû= '" + name + "' and ÃÜÂë = '" + password + "'";
ÆäÖÐnameºÍpasswordÊÇ´æ·ÅÓû§ÊäÈëµÄÓû§ÃûºÍ¿ÚÁͨ¹ýÖ´ÐÐÉÏÊöÓï¾äÀ´ÑéÖ¤Óû§ºÍÃÜÂëÊÇ·ñºÏ·¨ÓÐЧ¡£µ«ÊÇͨ¹ý·ÖÎö¿ÉÒÔ·¢ÏÖ£¬ÉÏÊöÓï¾äÈ´´æÔÚ×ÅÖÂÃüµÄ©¶´¡£µ±ÎÒÃÇÔÚÓû§Ãû³ÆÖÐÊäÈëÏÂÃæµÄ×Ö·û´®Ê±£º111 ' or '1 = 1£¬È»ºó¿ÚÁîÒ²ÒÔÀàËÆ·½·¨ÊäÈ룬ÎÒÃǼÙÉèÃÜÂëΪaaaa¡£±äÁ¿´ú»»ºó£¬sqlÓï¾ä¾Í±ä³ÉÁËÏÂÃæµÄ×Ö·û´®£º Sql="Select * from Óû§±í where ÐÕÃû = '111' or '1' = '1' and ÃÜÂë = 'aaaa'
ÎÒÃǶ¼ÖªµÀselectÓï¾äÔÚÅжϲéѯÌõ¼þʱ£¬Óöµ½»ò£¨or£©²Ù×÷¾Í»áºöÂÔÏÂÃæµÄÓ루and£©²Ù×÷£¬¶øÔÚÉÏÃæµÄÓï¾äÖÐ1=1µÄÖµÓÀԶΪtrue£¬ÕâÒâζ×ÅÎÞÂÛÔÚÃÜÂëÖÐÊäÈëʲôֵ£¬¾ùÄÜͨ¹ýÉÏÊöµÄÃÜÂëÑéÖ¤£¡Õâ¸öÎÊÌâµÄ½â¾öºÜ¼òµ¥£¬·½·¨Ò²ºÜ¶à£¬×î³£ÓõÄÊÇÔÚÖ´ÐÐÑé֤֮ǰ£¬¶ÔÓû§ÊäÈëµÄÓû§ºÍÃÜÂë½øÐкϷ¨ÐÔÅжϣ¬±±¾©°á¼Ò¹«Ë¾ ±±¾©Êèͨ¹«Ë¾²»ÔÊÐíÊäÈëµ¥ÒýºÅ¡¢µÈºÅµÈÌØÊâ×Ö·û¡£
ÉÏÊöÎÊÌâËäÈ»¿´ÆðÀ´¼òµ¥£¬µ«È·ÊµÊÇ´æÔڵġ£ÀýÈçÔÚ»¥ÁªÍøÉϺÜÓÐÃûÆøµÄÍøÂçÓÎÏ·"Ц°Á½ºþ"µÄÔçÆÚ°æ±¾¾Í´æÔÚ×ÅÕâÑùµÄÎÊÌ⣬ÕâȷʵӦ¸ÃÒýÆðÎÒÃǵÄ×¢Òâ¡£ÕâÒ²±©Â¶³öÄêÇá³ÌÐòÔ±ÔÚ±à³Ì¾ÑéºÍ°²È«ÒâʶÉϵIJ»×㡣ͬʱҲÌáÐÑÎÒÃDZà³Ì¹¤×÷ÕßÔÚ³ÌÐòÉè¼ÆÊ±Ó¦µ±³ä·Ö¿¼ÂdzÌÐòµÄ°²È«ÐÔ£¬²»¿ÉÓаëµãÂí»¢£¬Ò»¸ö¿´ËƺÜСµÄÊè©¿ÉÄܾͻáÔì³ÉºÜÑÏÖØµÄºó¹û¡£ ÔÚWinforms±à³ÌÖпÉÒÔ²ÉÈ¡ÒÔÏ·½·¨½â¾ö£¬¿ÉÒÔÓÃÎı¾¿òµÄKeyPressʼþÖÐÌí¼ÓÒÔÏ´úÂë
if(e.KeyChar == ' \' ') {
MessageBox.Show("²»¿ÉÒÔÊäÈë‘£¡");
e.Handled = true;
}±±¾©°á¼Ò¹«Ë¾ ±±¾©Êèͨ¹«Ë¾
´Ë´¦µÄeÊǸÃʼþÌṩµÄ²ÎÊý¶ÔÏó£¬KeyCharÊDZíʾËù°´¼üµÄASCIIÂ룬\'±íʾµ¥ÒýºÅ£¬Ìõ¼
Ïà¹ØÎĵµ£º
ÔÚÆ½Ê±µÄ¹¤×÷¹ý³ÌÖУ¬×÷ΪDBA½ÇÉ«¹ÜÀíÊý¾Ý¿â£¬Í·ÄÔÖеÄÓ¡ÏóÍùÍùÊÇÊý¾Ý¿âʵÀýÃû³Æ£¬¶ø²»»áÈ¥¹ØÐÄServerµÄIP£¬¶ø×÷ΪDeveloperµÄ½ÇÉ«£¬ËûÃÇÍùÍùÏëÖªµÀÖªµÀServer IpºÍ¶Ë¿ÚºÅ¡£ËùÒÔ£¬DBA»á¾³£±»Îʼ°µ½£ºXXXʵÀýµÄIPºÍ¶Ë¿ÚºÅÊÇʲô£¿
Õâ¸öÎÊÌ⣬µ±È»ÎÒÃÇ¿ÉÒÔLoginµ½OS²é¿´IP¡¢Ê¹ÓÃÅäÖÆ¹ÜÀí¹¤¾ß»ñÈ¡µ½¶Ë¿ÚºÅ¡£µ«ÊÇ£¬Õâ¸ö·½·¨·Ç ......
public List<FirmAttachmentModel> LoadFirmAttachmentByFirmId(int FirmId, int pageIndex, int pageSize)
{
List<FirmAttachmentModel> result = new List<FirmAtt ......
µÚÒ»ÖÖ£º
select b.* from
( select a.*, rownum row_num from
(select t.* from A05_ORGANIZATION t order by org_name_en asc) a
) b
where b.row_num between 1 and 5 order by b.row_num asc
µÚ¶þÖÖ£¨¸ü¸ßЧ£©£º
select b.* from
( select a.*, rown ......
ÉùÃ÷×Ö¶ÎÓ³Éä
@Target(ElementType.FIELD)
@Retention(RetentionPolicy.RUNTIME)
public @interface FiledRef
{
String fieldName();
}
ÉùÃ÷±íÓ³Éä
@Target(ElementType.TYPE)
@Retention(RetentionPolicy.RUNTIME)
public @interface TableRef
{
& ......
¡¡Microsoft SQL server2000ÓÉһϵÁÐÏ໥Ð×÷µÄ×é¼þ¹¹³É¡£ÄÜÂú×ã×î´óµÄWEBÕ¾µãºÍÆóÒµÊý¾Ý´¦Àíϵͳ´æ´¢ºÍ·ÖÎöÊý¾ÝµÄÐèÒª¡£±¾ÎÄ´øÀ´µÄ¾ÍÊÇÔÚwindows»·¾³ÏÂSQL2000µÄ°²×°¹ý³Ì¡£
¡¡¡¡
¡¡¡¡ÏµÍ³ÐèÇó
¡¡¡¡
¡¡¡¡ÕâÀïÒÔÆäËĺÏÒ»°æ±¾ÎªÀý£¬ÒÔϰ²×°¹ý³ÌͬÀí¡£Microsoft SQL Server 2000 ¿ÉÔÚÔËÐÐ Intel»ò¼æÈÝµÄ Pentium¡¢Pentium ......