LBound() º¯Êý: ·µ»ØÖ¸¶¨µÄÊý×éά¿ÉÓõÄ×îСϱꡣ
UBound() º¯Êý: ·µ»ØÖ¸¶¨µÄÊý×éά¿ÉÓõÄ×î´óϱꡣ
InStr([start, ]string1, string2[, compare]) ·µ»Ø×Ö·û»ò×Ö·û´®ÔÚÁíÒ»¸ö×Ö·û´®ÖеÚÒ»´Î³öÏÖµÄλÖÃ
InStrRev()º¯Êý ·µ»ØÄ³×Ö·û´®ÔÚÁíÒ»¸ö×Ö·û´®ÖÐ×îºó³öÏÖµÄλÖÃ
CDate() º¯Êý¿É°ÑÒ»¸öºÏ·¨µÄÈÕÆÚºÍʱ¼ä±í´ïʽת»»Îª Date ÀàÐÍ£¬²¢·µ»Ø½á¹û¡£
cstr()º¯Êý½«À¨ºÅÖеÄÄÚÈÝת»»Îª×Ö·û´®
clng()Êǽ«Êý×Öת»»³ÉLong¸ñʽµÄÊý×ÖÀàÐÍ£¬ÕâÑù²ÅÄܽøÐмÆËã
CInt() ·µ»ØËÄÉáÎåÈëµÄÕûÊý£¬µ±·ÖÊý²¿·ÖÇ¡ºÃΪ 0.5 ʱ£¬CInt º¯Êýͨ³£½«ÆäËÄÉáÎåÈëΪ×î½Ó½üµÄżÊý
Fix() ºÍ Int() ½«Êý×ֵķÖÊý²¿·Ö½ØÎ²È¡Õû£¬¶ø²»ÊÇËÄÉáÎåÈë¡£
IsNumeric() ·µ»Øboolean ÅжÏΪÊý×ÖÇÒ²»Îª¿Õ
Trim() ¹¦ÄÜɾ³ý×Ö·û´®Êײ¿ºÍβ²¿µÄ¿Õ¸ñ¡£
LCase UCaseº¯Êý ·µ»Ø×Ö·û´®µÄСдÐÎʽ¡£½ö´óд×Öĸת»»³ÉСд×Öĸ£»ËùÓÐСд×ÖĸºÍ·Ç×Öĸ×Ö·û±£³Ö²»±ä¡£
Mid(string, start[, length]) ËüµÄÖ÷Òª×÷ÓÃÊÇ´Ó×Ö·û´®Öзµ»ØÖ¸¶¨ÊýÄ¿µÄ×Ö·û¡£
Asc() ·µ»Ø×Ö·ûµÄANSIÖµ¡£
replace(string,"1","A")º¯Êý ÈôÒª°Ñ×Ö·û´® string ÀïÃæµÄ 1 ת»¯ÎªA¡£
timer() ¾ÍÊÇ´ÓÁãµã¿ªÊ¼½ñÌì¹ýÈ¥µÄÃëÊý
TypeName()º¯Êý ·µ»ØÓйرäÁ¿µ ......
Array()
¡¡¡¡FUNCTION: ·µ»ØÒ»¸öÊý×é
¡¡¡¡SYNTAX: Array(list)
¡¡¡¡ARGUMENTS: ×Ö·û£¬Êý×Ö¾ù¿É
¡¡¡¡EXAMPLE: <%
¡¡¡¡Dim myArray()
¡¡¡¡For i = 1 to 7
¡¡¡¡Redim Preserve myArray(i)
¡¡¡¡myArray(i) = WeekdayName(i)
¡¡¡¡Next
¡¡¡¡%[/IMG]
¡¡¡¡RESULT: ½¨Á¢ÁËÒ»¸ö°üº¬7¸öÔªËØµÄÊý×émyArray
¡¡¡¡myArray("Sunday","Monday", ... ... "Saturday")
CInt()
¡¡¡¡FUNCTION: ½«Ò»¸ö±í´ïʽת»¯ÎªÊý×ÖÀàÐÍ
¡¡¡¡SYNTAX: CInt(expression)
¡¡¡¡ARGUMENTS: ÈκÎÓÐЧµÄ×Ö·û¾ù¿É
¡¡¡¡EXAMPLE: <%
¡¡¡¡f = "234"
¡¡¡¡response.write cINT(f) + 2
¡¡¡¡%[/IMG]
¡¡¡¡RESULT: 236
¡¡¡¡×ª»¯×Ö·û"234"ΪÊý×Ö"234"£¬Èç¹û×Ö·û´®Îª¿Õ£¬Ôò·µ»Ø0Öµ
CreateObject()
¡¡¡¡FUNCTION: ½¨Á¢ºÍ·µ»ØÒ»¸öÒÑ×¢²áµÄACTIVEX×é¼þµÄʵÀý¡£
¡¡¡¡SYNTAX: CreateObject(objName)
¡¡¡¡ARGUMENTS: objName ÊÇÈκÎÒ»¸öÓÐЧ¡¢ÒÑ×¢²áµÄACTIVEX×é¼þµÄÃû×Ö.
¡¡¡¡EXAMPLE: <%
¡¡¡¡Set con = Server.CreateObject("ADODB.Connection")
¡¡¡¡%[/IMG]
¡¡¡¡RESULT:
CStr()
¡¡¡¡FUNCTION: ת»¯Ò»¸ö±í´ïʽΪ×Ö·û´®.
¡¡¡¡SYNTAX: CStr(expression)
¡¡¡¡A ......
1. DotNetNuke(ASP.NET 2.0) ¸öÈËÍÆ¼öÉîÈëÑо¿
DotNetNukeÊÇÒ»¸öWebÓ¦Óÿò¼ÜµÄÀíÏë,Ϊ´´½¨ºÍ²¿ÊðµÄÏîÄ¿,ÈçÉÌÒµÍøÕ¾,ÆóÒµÄÚÁªÍøºÍÍâÁªÍø,ÔÚÍøÉϳö°æÃÅ»§,²¢¶¨ÖÆ´¹Ö±Ó¦ÓÃÈí¼þ¡£ ·½±ãÓû§-DotNetNukeÖ¼ÔÚʹÓû§¿ÉÒÔ¸üÇáËɵعÜÀíËùÓз½ÃæµÄÏîÄ¿¡£
ÏÂÔØÍøÖ·:http://www.dotnetnuke.com/
2¡¢Ludico
LudicoÊÇC#±àдµÄ¾ÓÓÚASP.NET 2.0µÄPortal/CMSϵͳ¡£ËüµÄÄ£¿é»¯Éè¼ÆÊÇÄã¿ÉÒÔ°´ÕÕÄãÏ£ÍûµÄʹÓûò¿ª·¢ÍøÕ¾¹¦ÄÜ¡£ËüÀïÃæÓи߼¶µÄÓû§¹ÜÀí£¬Ò»¸öËù¼û¼´ËùµÄ(WYSIWYG)µÄ±à¼Æ÷µÈ¡£
ÏÂÔØµØÖ·£ºhttp://sourceforge.net/projects/ludico/
3¡¢umbraco
UmbracoÊÇÒ»¿îÔÚ.netƽ̨ÏÂC#¿ª·¢µÄ¿ªÔ´ÄÚÈݹÜÀíϵͳ£¬¸ÃϵͳЧÂÊ£¬Áé»î£¬Óû§½çÃæ¶¼²»´í¡£
ÏÂÔØµØÖ·£ºhttp://umbraco.org/
4¡¢mojoPortal
mojoPortalÊÇÒ»¿îC#¿ª·¢µÄÃæÏà¶ÔÏóÍøÕ¾¿ò¼Ü£¬Ëü¿ÉÒÔÔËÐÐÓÚWindowsµÄASP.NET ºÍGNU/Linux »òMac OS XµÄMonoµÄƽ̨ÉÏ¡£
ÏÂÔØµØÖ·£ºhttp://www.mojoportal.com/
5¡¢Kodai CMS
Kodai CMSÊÇ.NETƽ̨ϵÄÒ»¿î¹¦ÄÜÆëÈ«µÄÄÚÈݹÜÀíϵͳ¡£
ÏÂÔØµØÖ·£ºhttp://www.gotdotnet.com/workspaces/workspace.aspx?id=070f30c3-6089-4a75-b84c-fac654a7ec08
6¡¢nkCMS
NkCMSÊÇʹÓÃASP.netºÍSql server 2000 ......
WSDL£ºÊÇÒ»¸öÓÃÀ´ÃèÊöWeb·þÎñºÍ˵Ã÷ÈçºÎÓëWeb·þÎñͨÐŵÄXMLÓïÑÔ¡£ ÔõÑùÏò±ðÈ˽éÉÜÄãµÄWeb serviceÓÐʲô¹¦ÄÜ£¬ÒÔ¼°Ã¿¸öº¯Êýµ÷ÓÃʱµÄ²ÎÊýµÈµÈ¡£
web·þÎñ£º½øÐÐwebÉÏÊý¾Ý½»»»µÄ·½·¨¡£Äܹ»ÒÔ´¿xml·½Ê½Í¨ÐÅ¡£
SOAP£º¼òµ¥¶ÔÏó´æÈ¡ÐÒé¡£¿É¿´×öxml·½ÑÔ£» ÒÔSOAPÐÅ·âÀ´´«µÝºÍÏìÓ¦Îı¾£¨°üº¬£ºÊײ¿¡¢Ö÷Ì壩HTTP POST
VSÖн¨Á¢web·þÎñÏîÄ¿ £¨vs×Ô¶¯Éú³ÉsoapÐŷ⣩
Ö÷ÎļþService.cs ÈçÏ£º
using System;
using System.Web;
using System.Web.Services;
using System.Web.Services.Protocols;
[WebService(Namespace = "http://tempuri.org/")]
[WebServiceBinding(ConformsTo = WsiProfiles.BasicProfile1_1)]
public class Service : System.Web.Services.WebService
{
public Service () {
//Èç¹ûʹÓÃÉè¼ÆµÄ×é¼þ£¬ÇëÈ¡Ïû×¢ÊÍÒÔÏÂÐÐ
//InitializeComponent();
}
[WebMethod]
public string HelloWorld(string name) {
return "Hello World!"+name;
}
}
ÔËÐÐÏîÄ¿·µ»ØxmlÊý¾Ý£º
<?xml version="1.0" encoding="utf-8" ?>
<string xmlns="http://tempur ......
ÔÚASP.NETÖÐÎÒÃǾ³£ÐèÒªÊä³öһЩJS½Å±¾£¬±ÈÈ絯³öÒ»¸ö¾¯¸æ´°¿Ú£¬·µ»Øµ½ÀúÊ·Ò³ÃæµÈJS¹¦ÄÜ£¬ÎÒ¿´µ½ÍøÉϺöàÕâ·½ÃæµÄ´úÂ룬ÒÔÏ´úÂëÊÇÆäÖÐÖ®Ò»¡£
Õû¸ö³ÌÐòµÄ´úÂëÈçÏ£º
¸´ÖÆ´úÂë ´úÂëÈçÏÂ:
using System;
using System.Collections.Generic;
using System.Text;
using System.Web;
using System.Web.UI;
/// <summary>
/// µ¯³öJavaScriptС´°¿Ú
/// </summary>
/// <param name="js">´°¿ÚÐÅÏ¢</param>
public static void Alert(string message, Page page)
{
#region
string js = @"<Script language='JavaScript'>
alert('" + message + "');</Script>";
//HttpContext.Current.Response.Write(js);
if (!page.ClientScript.IsStartupScriptRegistered(page.GetType(), "alert"))
{
page.ClientScript.RegisterStartupScript(page.GetType(), "alert", js);
}
#endregion
}
/// <summary>
/// µ¯³öÏûÏ¢¿ò²¢ÇÒתÏòµ½ÐµÄURL
/// </summary>
/// <param name="message">ÏûÏ¢ÄÚÈÝ</param>
/// <param name="toURL">Á¬½ÓµØÖ·</param>
public ......
ÔÚÍøÂç¾³£¿´µ½ÍøÕ¾±»¹ÒÂí¡¢Ö÷Ò³±»Ð޸ĵÄÐÂÎÅ£¬ÆäʵÕâЩÎÊÌâ¿ÉÄÜÊÇ¶à·½ÃæµÄ£¬·þÎñÆ÷£¬ÍøÕ¾³ÌÐòµÈµÈ¡£¡£¡£µ«ÊÇÏÖÔÚÒç³öÒѾ±»ÈËÃÇÖØÊӺͷþÎñÆ÷µÄ²»¶ÏÍêÉÆ£¬·þÎñÆ÷ϵͳ©¶´Ò²²»ÊÇÄÇôÈÝÒ×·¢¾ò£¬µ±È»Ò²Òª±£Ö¤µÚÈý·½µÄÈí¼þ°²È«¡£
×öÏîĿҲÓÐÒ»¶Îʱ¼äÁË¡£ÔÚ³ÌÐòÖÐÒ²Óöµ½ºÜ¶à°²È«·½ÃæµÄÎÊÌâ¡£Ò²¸Ã×ܽáÒ»ÏÂÁË¡£Õâ¸öÏîÄ¿ÊÇÒ»¸öCMSϵͳ¡£ÏµÍ³ÊÇÓÃASP.NET×öµÄ¡£¿ª·¢µÄʱºò·¢ÏÖ΢Èí×öÁ˺ܶలȫ´ëÊ©£¬Ö»ÊÇÓÐЩÐÂÊÖ³ÌÐòÔ±²»ÖªµÀÔõô¿ªÆô¡£ÏÂÃæÎÒͨ¹ý¼¸¸ö·½Ãæ¼òµ¥½éÉÜ£º
£±£ºSQL ×¢Èë
£²£ºXSS
£³£ºCSRF
£´£ºÎļþÉÏ´«
£±£ºSQL ×¢Èë
ÒýÆðÔÒò£º
ÆäʵÏÖÔںܶàÍøÕ¾Öж¼´æÔÚÕâÖÖÎÊÌâ¡£¾ÍÊdzÌÐòÖÐÖ±½Ó½øÐÐSQLÓï¾äÆ´½Ó¡£¿ÉÄÜÓÐЩ¶ÁÕß²»Ì«Ã÷°×¡£ÏÂÃæÍ¨¹ýÒ»¸öµÇ¼ʱ¶ÔÓû§ÑéÖ¤À´ËµÃ÷£º
code:
Ñé֤ʱµÄsqlÓï¾ä: select * from where user='"+txtUsername.Text+"' and pwd='"+txtPwd.Text+"'
ÕâÊÇÒ»¶Î´ÓÊý¾Ý¿âÖвéѯÓû§£¬¶ÔÓû§Ãû£¬ÃÜÂëÑéÖ¤¡£
¿´ÉÏÈ¥ºÃÏóûÓÐʲôÎÊÌ⣬µ«ÊÇʵ¼ÊÕâÀïÃæÇ³²Ø×ÅÎÊÌ⣬Óû§Ãû£ºadmin ÃÜÂ룺 admin£¬
select * from where user='admin' and pwd='admin'
Èç¹ûÓû§ºÍÃÜÂëÕýÈ·¾Í¿ÉͨÑéÖ¤¡£Èç¹ûÎÒÓû§Ãû£ºasdf' or 1=1 -- ÃÜÂë£ºËæÒâÊ ......