·ÀSQLÊý×Ö×¢È뺯Êý
http://blog.csdn.net/cncco/archive/2007/10/03/1810540.aspx
·ÀSQL×¢È뺯Êý
³ÌÐò´úÂ룺
º¯Êý²¿·Ö========================================================================
'------------------------------------------------
'ÓÃ;:¼ì²éÊÇ·ñΪÊý×Ö,ÒÔ¼°Êý×ÖÊÇ·ñ³¬³ö·¶Î§
'ÊäÈë:¼ì²é×Ö·û,´«Öµ·½Ê½(0Ö±½Ó´«,1È¡Form,2È¡QueryString,3È¡cookies,4Ö±½ÓReqeust),¿ªÊ¼Êý×Ö(ĬÈÏÊý×Ö),½áÊøÊý×Ö(Ϊ-1Ôò²»¼ì²é´óС)
Function CheckNum(str_str,int_quest,int_startnum,int_endnum)
mystr=Trim(str_str)
Select Case int_quest
Case 1
istr=Request.Form(mystr)
Case 2
istr=Request.QueryString(mystr)
Case 3
istr=Request.Cookies(mystr)
Case 4
istr=Request(mystr)
Case Else
istr=mystr
End Select
istr=Left(istr,32)
If IsNumeric(istr) Then
iNum=CDbl(istr)
Else
iNum=int_startnum
End If
If int_endnum>-1Then
If iNum If iNum>int_endnum Then iNum=int_endnum
End If
CheckNum=iNum
End Function
'------------------------------------------------
'ÓÃ;:¼ì²é¹ýÂË×Ö·û´®
'ÊäÈë:×Ö·û´®,´«Öµ·½Ê½(0 ......
·ÀSQL×¢È뺯Êý
³ÌÐò´úÂ룺
º¯Êý²¿·Ö========================================================================
'------------------------------------------------
'ÓÃ;:¼ì²éÊÇ·ñΪÊý×Ö,ÒÔ¼°Êý×ÖÊÇ·ñ³¬³ö·¶Î§
'ÊäÈë:¼ì²é×Ö·û,´«Öµ·½Ê½(0Ö±½Ó´«,1È¡Form,2È¡QueryString,3È¡cookies,4Ö±½ÓReqeust),¿ªÊ¼Êý×Ö(ĬÈÏÊý×Ö),½áÊøÊý×Ö(Ϊ-1Ôò²»¼ì²é´óС)
Function CheckNum(str_str,int_quest,int_startnum,int_endnum)
mystr=Trim(str_str)
Select Case int_quest
Case 1
istr=Request.Form(mystr)
Case 2
istr=Request.QueryString(mystr)
Case 3
istr=Request.Cookies(mystr)
Case 4
istr=Request(mystr)
Case Else
istr=mystr
End Select
istr=Left(istr,32)
If IsNumeric(istr) Then
iNum=CDbl(istr)
Else
iNum=int_startnum
End If
If int_endnum>-1Then
If iNum If iNum>int_endnum Then iNum=int_endnum
End If
CheckNum=iNum
End Function
'------------------------------------------------
'ÓÃ;:¼ì²é¹ýÂË× ......
'*************************************************************************
'**Ä£ ¿é Ãû£ºfBackupDatabase_a
'**Ãè Êö£º±¸·ÝÊý¾Ý¿â,·µ»Ø³ö´íÐÅÏ¢,Õý³£»Ö¸´,·µ»Ø""
'**µ÷ ÓãºfBackupDatabase_a "±¸·ÝÎļþÃû","Êý¾Ý¿âÃû"
'**²ÎÊý˵Ã÷£º
'** sBackUpfileName »Ö¸´ºóµÄÊý¾Ý¿â´æ·ÅĿ¼
'** sDataBaseName ±¸·ÝµÄÊý¾ÝÃû
'** sIsAddBackup ÊÇ·ñ×·¼Óµ½±¸·ÝÎļþÖÐ
'**˵ Ã÷£ºÒýÓÃMicrosoft ActiveX Data Objects 2.x Library
'**´´ ½¨ ÈË£º×Þ½¨
'**ÈÕ ÆÚ£º2003Äê12ÔÂ09ÈÕ
'*************************************************************************
Public Function fBackupDatabase_a(ByVal sBac ......
'*************************************************************************
'**Ä£ ¿é Ãû£ºfBackupDatabase_a
'**Ãè Êö£º±¸·ÝÊý¾Ý¿â,·µ»Ø³ö´íÐÅÏ¢,Õý³£»Ö¸´,·µ»Ø""
'**µ÷ ÓãºfBackupDatabase_a "±¸·ÝÎļþÃû","Êý¾Ý¿âÃû"
'**²ÎÊý˵Ã÷£º
'** sBackUpfileName »Ö¸´ºóµÄÊý¾Ý¿â´æ·ÅĿ¼
'** sDataBaseName ±¸·ÝµÄÊý¾ÝÃû
'** sIsAddBackup ÊÇ·ñ×·¼Óµ½±¸·ÝÎļþÖÐ
'**˵ Ã÷£ºÒýÓÃMicrosoft ActiveX Data Objects 2.x Library
'**´´ ½¨ ÈË£º×Þ½¨
'**ÈÕ ÆÚ£º2003Äê12ÔÂ09ÈÕ
'*************************************************************************
Public Function fBackupDatabase_a(ByVal sBac ......
½â¾öSQL Injection©¶´µÄÒ»¸öº¯Êý
http://blog.csdn.net/cncco/archive/2006/04/07/654254.aspx
º¯Êý
<%
Function CheckInput(str,strType)
'º¯Êý¹¦ÄÜ£º¹ýÂË×Ö·û²ÎÊýÖеĵ¥ÒýºÅ£¬¶ÔÓÚÊý×Ö²ÎÊý½øÐÐÅжϣ¬Èç¹û²»ÊÇÊýÖµÀàÐÍ£¬Ôò¸³Öµ0
'²ÎÊýÒâÒ壺 str ---- Òª¹ýÂ˵IJÎÊý
' strType ---- ²ÎÊýÀàÐÍ£¬·ÖΪ×Ö·ûÐͺÍÊý×ÖÐÍ£¬×Ö·ûÐÍΪ"s"£¬Êý×ÖÐÍΪ"i"
Dim strTmp
strTmp = ""
If strType ="s" Then
strTmp = Replace(Trim(str),"'","'")
ElseIf strType="i" Then
If isNumeric(str)=False Then str="0"
strTmp = str
Else
strTmp = str
End If
CheckInput = strTmp
End Function
%>
Õâ¸öº¯ÊýºÜ¼òµ¥£¬ Ö÷ÒªÊÇÕë¶Ô×Ö·û´®ºÍÊý×ÖÁ½ÖÖÀàÐ͵Ĵ«ÈëÊý¾Ý·Ö±ð½øÐÐÁË´¦Àí£¬¾ßÌåÓ÷¨£º
×Ö·ûÀàÐ͵Ä
strUsername = CheckInput(Request(“username“),“s ......
SQLÈßÓà×ֶεIJßÂԺ͹ÜÀí
http://www.examda.com/ncre/three/db/fudao/20091203/093528816.html
ÈßÓà×ֶεÄʹÓÃÔÚ¶à±íÁªºÏ²éѯ¶¼ÊÇ´óÊý¾ÝÁ¿µÄ±íµÄÇé¿öÏ£¬È·ÊµÊǸö²»´íµÄÑ¡Ôñ£¬ÓÐЧµÄ¼õÉÙÁËIO²Ù×÷¡£µ«½áºÏÒÑÓеÄÏîÄ¿²úÆ·À´¿´£¬ÈßÓà×Ö¶ÎȷʵÊÇË«Èн£¡£ÓÈÆäÊÇ´óÏîÄ¿µÄ¿ª·¢£¬Èç¹ûºöÂÔij¸ö±íµÄÈßÓà×ֶεĸüУ¬ÄÇôºó¹ûÊÇÔÖÄÑÐԵġ£ÈçºÎÓÐЧµÄ¹ÜÀíÈßÓà×Ö¶ÎÊÇ¿ª·¢×éÄÚ±ØÐë½â¾öµÄÎÊÌâ¡£ÎҵĽâ¾ö·½°¸ÊÇ£ºÊ¹ÓÃרÃŵıíÀ´¹ÜÀíÈßÓà×ֶΡ£ÀýÈçarticle±íÓÐÒÔÏÂÈßÓà×Ö¶Î
¡¡¡¡fromUserName,toUserName
¡¡¡¡ÈçºÎ¹ÜÀíÕâÁ½¸ö×Ö¶ÎÄØ£¿Í¨¹ý½¨Á¢Ò»¸ö±í£¬±í½á¹¹ÈçÏÂ
¡¡¡¡id,objTable,objName,sourceTable, sourceId,level£¬isUpdate
¡¡¡¡ÆäÖÐobjTable=Ä¿±ê±í£¬objName= Ä¿±ê×ֶΣ¬sourceTable=Ô´±í,sourceId=Ô´±íID,level=ÊÇ·ñÐèÒªÁ¢¼´¸üÐÂ,isUpdate=ÊÇ·ñÒѸüÐÂ
¡¡¡¡ÆäÖУ¬level×ֶκÜÓбØÒª£¬ÓÐЩÈßÓà×ֶβ¢²»ÐèÒªÔÚÔ´±íÐ޸ĺóÁ¢¼´¸üУ¬ÄÇô¿ÉÒÔͨ¹ýÒ»¸ö¶¨ÆÚ¸üвßÂÔÀ´¸üС£
¡¡¡¡Í¨¹ý¿â±íµÄ¹ÜÀí£¬ÅäºÏÒ»¸öºÏÀíµÄ´æ´¢¹ý³Ì£¬ÈßÓà×ֶεÄʹÓý«²»ÔÙÊÇÄÑÌâ¡£
¡¡¡¡¾ÙÀý£¬Èç¹ûÉÏÃæÁ½¸ö×ֶη¢Éú±ä»¯£¬ÔòʹÓô¥·¢Æ÷»òÕßµ÷ÓÃÕâ¸ö´æ´¢¹ý³ÌÀ´¼ì²éÊÇ·ñÓÐÐèÒªÁ¢¼´¸üеÄÈßÓà×ֶΣ¬ÐèÒªÔòÁ¢¼´¸üУ¬² ......
v$sqltext
´æ´¢µÄÊÇÍêÕûµÄSQL
v$sqlarea
´æ´¢µÄSQL ºÍһЩÏà¹ØµÄÐÅÏ¢£¬±ÈÈçÀۼƵÄÖ´ÐдÎÊý£¬Âß¼¶Á£¬ÎïÀí¶ÁµÈͳ¼ÆÐÅÏ¢
v$sql
´æ´¢µÄÊǾßÌåµÄSQL ºÍÖ´Ðмƻ®Ïà¹ØÐÅÏ¢£¬Êµ¼ÊÉÏ£¬v$sqlarea ¿ÉÒÔ¿´×ö v$sql ¸ù¾Ý sqltext µÈ ×öÁË group by Ö®ºóµÄÐÅÏ¢ ......