using System;
using System.Text.RegularExpressions;
using System.Web;
namespace FSqlKeyWord
......{
/**//**//**//// <summary>
/// SqlKey µÄժҪ˵Ã÷¡£
/// </summary>
public class SqlKey
......{
private HttpRequest request;
private const string StrKeyWord = @"select|insert|delete|from|count(|drop table|update|truncate|asc(|mid(|char(|xp_cmdshell|exec master|netlocalgroup administrators|:|net user|""|or|and";
private const string StrRegex = @"[-|;|,|/|(|)|[|]|}|{|%|@|*|!|']";
public SqlKey(System.Web.HttpRequest _request)
......{
//
  ......
using System;
using System.Text.RegularExpressions;
using System.Web;
namespace FSqlKeyWord
......{
/**//**//**//// <summary>
/// SqlKey µÄժҪ˵Ã÷¡£
/// </summary>
public class SqlKey
......{
private HttpRequest request;
private const string StrKeyWord = @"select|insert|delete|from|count(|drop table|update|truncate|asc(|mid(|char(|xp_cmdshell|exec master|netlocalgroup administrators|:|net user|""|or|and";
private const string StrRegex = @"[-|;|,|/|(|)|[|]|}|{|%|@|*|!|']";
public SqlKey(System.Web.HttpRequest _request)
......{
//
  ......
//¿ª·¢»·¾³£ºWindow 2000¡¢SQLServer2000¡¢.Net Framework SDKÕýʽ°æ
//¿ª·¢ÓïÑÔ£ºC#¡¢ASP.Net
//¼ò½é£ºÊý¾Ý¿âÖÐͼƬ´æÐî¼°¶ÁÈ¡
//×÷Õߣºengine
/*
˵Ã÷£ºÔÚASPÖУ¬ÎÒÃÇÓÃRequest.TotalBytes¡¢Request.BinaryRead()À´ÉÏ´«Í¼Æ¬£¬Õâ¸ö¿É¶ñµÄBinaryRead()·½·¨·Ç³£±¿£¬µ¥¸öÎļþÉÏ´«µ¹Ã»Ê²Ã´´óÊ£¬µ¥Èç¹û¶à¸öͼƬÉÏר¿É¾Í»¨´óÆøÁ¦ÁË…£¡¶øÏÖÔÚASP.NetÖн«»á°Ñ½â¾öÒÔǰASPÖÐÎļþÉÏ´«µÄÖÖÖÖÎÊÌ⣬ʹÄãÔÚASP.NetÖÐÇáÇáËÉËÉ¿ª·¢³ö¹¦ÄÜÇ¿´óµÄÉÏ´«³ÌÐò£¬ÏÂÃæ´ó¼Ò¿´¿´Àý×ÓÀ²¡£
*/
//×¢Ò⣺ÓÉÓÚ×÷ÕßˮƽÓÐÏÞ£¬´íÎóÊÇÄÑÃâµÄ£¬Èç·¢ÏÖ´íÎóÇëÖ¸½Ì
/*
Ê×ÏÈÔÚSQL ServerÖн¨Á¢Ò»¸öͼƬ´æ´¢µÄÊý¿â±í£¬ImageData ColumnΪͼÏó¶þ½øÖÆÊý¾Ý´¢´æ×ֶΣ¬ImageContentType ColumnΪͼÏóÎļþÀàÐͼǼ×ֶΣ¬ImageDescription ColumnΪ´¢ÐîͼÏóÎļþ˵Ã÷×Ö¶Î,ImageSize ColumnΪ´¢´æÍ¼ÏóÎļþ³¤¶È×ֶΣ¬½á¹¹ÈçÏ£º
CREATE TABLE (
IDENTITY (1, 1) NOT NULL ,
NULL ,
& ......
µÚÒ»Õ¡¢ Asp.net ÖзþÎñ¶Ë¿Ø¼þʼþÊÇÈçºÎ´¥·¢µÄ
Asp.net ÖÐÔÚ¿Í»§¶Ë´¥·¢·þÎñ¶Ëʼþ·ÖΪÁ½ÖÖÇé¿ö£º
¡¡¡¡
¡¡¡¡Ò».¡¡¡¡ WebControls ÖÐµÄ Button ºÍ HtmlControls ÖÐµÄ Type Ϊ submit µÄ HtmlInputButton
¡¡¡¡
¡¡¡¡ÕâÁ½ÖÖ°´Å¥×îÖÕµ½¿Í»§¶ËµÄ±íÏÖÐÎʽΪ£º <input name="Submit1" id="Submit1" type="submit" value=”Submit”>£¬ÕâÊÇ Form ±íµ¥µÄÌá½»°´Å¥£¬µã»÷ÒÔºó»á×÷Ϊ²ÎÊý·¢Ë͵½·þÎñ¶Ë£¬²ÎÊýÊÇÕâÑùµÄ£º ¿Ø¼þµÄ name ÊôÐÔ=¿Ø¼þµÄ value Öµ£¬¶ÔÓ¦ÉÏÃæµÄÀý×Ó¾ÍÊÇ£ºSubmit1= Submit¡£ ·þÎñ¶Ë»á¸ù¾Ý½ÓÊÕµ½µÄ¿Ø¼þµÄ name ÊôÐÔµÄÕâ¸ö key À´µÃÖªÊÇÕâ¸ö°´Å¥±»µã»÷ÁË£¬´Ó¶øÔÚ·þÎñ¶Ë´¥·¢Õâ¸ö°´Å¥µÄµã»÷ʼþ¡£
¡¡¡¡
¡¡¡¡¶þ.¡¡¡¡ HtmlControls ÖÐµÄ Type Ϊ button µÄ HtmlInputButton ºÍÆäËüËùÓеĿؼþʼþ£¬±ÈÈç LinkButton µã»÷£¬TextBox µÄ Change ʼþµÈµÈ£º
¡¡¡¡
¡¡¡¡ÕâЩʼþÔÚ¿Í»§¶Ë²úÉúºó»á¾¹ýÒ»¸öͳһµÄ»úÖÆ·¢Ë͵½·þÎñ¶Ë¡£
¡¡¡ ......
ת£ºhttp://www.cnblogs.com/xiaozhuang/archive/2008/08/15/1268907.html
Õ⼸ÌìÔ°×ÓÀï¹ØÓÚÈí¼þ¼Ü¹¹µÄÌÖÂÛ»¹ÊÇÏ൱¼¤ÁÒ£¬´ó¼Ò¶¼ÏëÒªÒ»ÖÖÄÜ×î´óÏ޶ȵĽµµÍ¸÷²ãÖ®¼äÒÀÀµ¹ØÏµµÄµÄ¼Ü¹¹À´ÊÊÓ¦±ä»¯µÄÐèÇó£¬Ë¶¼²»Ï²»¶¸ÄÒ»µã¶ø¶¯È«Éí£¬¾¡Á¿½µµÍ¸÷²ãµÄ¸Ä¶¯²úÉúµÄÏ໥ӰÏì¡£
±¾ÆªÎÒÒÔÀíÂÛºÍʵ¼ù£¨Ô´´úÂ룩Á½¸ö·½ÃæºÍ´ó¼Ò̽ÌÖÒ»ÏÂÎҵķ½°¸£¬Ï£Íû´ó¼Ò¶àÌᱦ¹óÒâ¼û¡£
Ò»¡¢Èí¼þ¼Ü¹¹µÄ¸ÅÄîÎÊÌ⣬ʲôÊÇÈí¼þµÄ¼Ü¹¹?ÎÒµÄÀí½âÊÇ£ºÈí¼þµÄ¼Ü¹¹°üÀ¨Á½¸ö·½ÃæµÄÄÚÈÝ£¬Ò»¸öÊÇÈí¼þµÄ¿ª·¢¼Ü¹¹£¬Ò»¸öÊÇÈí¼þµÄ²¿Êð¼Ü¹¹£¬Ëùν²¿Êð¼Ü¹¹¾ÍÊÇÖ¸²¿ÊðʱµÄ·Ö²¼Ê½£¬¼¯ÈºµÈÉè¼ÆÎÊÌ⣻¿ª·¢¼Ü¹¹¾ÍÊÇÎÒÃÇÆ½³£ËµµÄÈí¼þ·Ö²ãÉè¼ÆÎÊÌ⣬Ҳ¾ÍÊÇÎÒÃǽñÌìҪ̸µÄÎÊÌâ¡£
¶þ¡¢ºÎν·Ö²ã£¿·Ö²ãµÄ·½Ê½Óм¸ÖÖ£¿·Ö²ãÒ²¾ÍÊǰÑÒ»¸ö´óµÄÈí¼þ½â¾ö·½°¸·Ö³É¶à¸öÏîÄ¿½øÐпª·¢£¬·ÖΪÈýÖÖ£¬Ò»ÖÖÊǰ´ÕÕ´úÂëµÄ¹¦Äܲã´Î½øÐзֲ㣬·ÖΪÊý¾Ý¿â·ÃÎʲ㣬ҵÎñÂß¼²ã£¬UI²ãµÈ£¬Ò»ÖÖÊǰ´ÕÕҪʵÏֵŦÄÜÄ£¿é½øÐзֲ㣬ÀýÈçÐÂÎŹÜÀí²ã£¬²©¿Í¹ÜÀí²ãµÈ£¬µÚÈýÖÖ¾ÍÊǰÑǰÁ½Õß½áºÏÆðÀ´½øÐзֲ㣺ÏȰ´ÕÕ´úÂ빦ÄÜ»®·ÖºÃ²ã´Î£¬È»ºóÔÙÔÚÿһ²ãÖзֲã³É¸÷¸ö¹¦ÄÜÄ£¿é¡£
Èý¡¢ÃæÏò½Ó¿ÚÄܹ»½µµÍ¸÷²ãÖ®¼äµÄÒÀÀµ¹ØÏµÂ𣿻¹ÐèҪʲô£¿ÃæÏò½Ó¿ÚÖ»ÊǰѶԶÔÏóµÄÖ± ......
Iframe±ê¼Ç£¬Óֽи¡¶¯Ö¡±ê¼Ç£¬Äã¿ÉÒÔÓÃËü½«Ò»¸öHTMLÎĵµÇ¶ÈëÔÚÒ»¸öHTMLÖÐÏÔʾ¡£Ëü²»Í¬ÓÚFrame±ê¼Ç×î´óµÄÌØÕ÷¼´Õâ¸ö±ê¼ÇËùÒýÓõÄHTMLÎļþ²»ÊÇÓëÁíÍâµÄHTMLÎļþÏ໥¶ÀÁ¢ÏÔʾ£¬¶øÊÇ¿ÉÒÔÖ±½ÓǶÈëÔÚÒ»¸öHTMLÎļþÖУ¬ÓëÕâ¸öHTMLÎļþÄÚÈÝÏ໥Èںϣ¬³ÉΪһ¸öÕûÌ壬ÁíÍ⣬»¹¿ÉÒÔ¶à´ÎÔÚÒ»¸öÒ³ÃæÄÚÏÔʾͬһÄÚÈÝ£¬¶ø²»±ØÖظ´Ð´ÄÚÈÝ£¬Ò»¸öÐÎÏóµÄ±ÈÓ÷¼´“»Öл“µçÊÓ¡£¼´°ÑһЩ±ä»¯±È½Ï¶àµÄÄÚÈÝ·ÅÔÚIframeËùµ÷ÓõÄÒ³ÃæÖУ¬²»Ôõô±ä»¯µÄ·ÅÔÚiframeÍâÃæ¡£
<%--<iframe style="width:600px; height:400px; border:10px" frameborder="0" scrolling="auto" marginheight="0" src="ChatInfo.aspx">
</iframe>--%>
ChatInfo.aspxÒ³ÃæÖеĴúÂ룺
<head id="Head1" runat="server">
<title>ÎÞ±êÌâÒ³</title>
¸Ã×ÓÒ³ÃæÃ¿¸ô2ÃëË¢ÐÂÒ»´Î£¬¼´£º
<meta http-equiv="refresh" content="2"/>
</head>
<body>
<form id="form1" runat="server">
<div>
& ......
<%-- ʹÓÃAjax¹Ì¶¨¿Ø¼þʵÏÖ¾Ö²¿Ò³ÃæµÄË¢ÐÂ--%>
<asp:ScriptManager ID="ScriptManager1" runat="server">
</asp:ScriptManager>
<asp:UpdatePanel ID="UpdatePanel1" runat="server">
<ContentTemplate> ÀïÃæ´æ·Åʱ¿ÌÐèÒª¸üеÄÄÚÈÝ
<div style="width:600px; height:400px; border-width:50px; border-color:#A0522D" align="left">
<asp:DataList ID="AllChatInfo" runat="server">
<ItemTemplate>
& ......
<%-- ʹÓÃAjax¹Ì¶¨¿Ø¼þʵÏÖ¾Ö²¿Ò³ÃæµÄË¢ÐÂ--%>
<asp:ScriptManager ID="ScriptManager1" runat="server">
</asp:ScriptManager>
<asp:UpdatePanel ID="UpdatePanel1" runat="server">
<ContentTemplate> ÀïÃæ´æ·Åʱ¿ÌÐèÒª¸üеÄÄÚÈÝ
<div style="width:600px; height:400px; border-width:50px; border-color:#A0522D" align="left">
<asp:DataList ID="AllChatInfo" runat="server">
<ItemTemplate>
& ......