asp.netʵÏÖα¾²Ì¬
Ò»¡¢Î±¾²Ì¬µÄÓô¦
ÓÐЩÓû§
¾õµÃ£¬Î±¾²Ì¬ºÍÕæ¾²Ì¬Êµ¼Ê±»ÊÕ¼Á¿»áÏà²îºÜ´ó£¬Æäʵ²»È»£¬´ÓÄã¸öÈ˽Ƕȣ¬Äã
È¥ÅжÏÒ»ÏÂÒ»¸öÌû×Óµ½µ×ÊÇÕæ¾²Ì¬»¹ÊÇα¾²Ì¬£¿¹À¼ÆºÜÄÑ¿´µÃ³ö£¬ÒòΪËùν¾²Ì¬µÄÒâ˼£¬¾ÍÊǵØÖ·Öв»´øÎʺţ¬²»´øÎʺŵľÍÊǾ²Ì¬£¬¹ÜËûÊÇÕæµÄ»¹ÊÇαµÄ£¿ËÑË÷Òý
Çæ¿´µÃ³öÂð£¿ËùÒÔ˵£¬Æäʵ²»ÂÛÊÇÕæµÄ»¹ÊÇαµÄ£¬Æäʵ¶ÔÓÚËÑË÷ÒýÇæÀ´Ëµ¶¼ÊÇÒ»ÑùµÄ£¬ËÑË÷ÒýÇæÃ»ÓÐ˵£¬ÄãÕâ¸öÊÇαµÄ£¬ÎÒ²»ÊÕ¼Äã¡£
×·¸ù¾¿µ×À´Ëµ£¬ÎªÊ²Ã´ËÑË÷ÒýÇæ»á²»ÊÕ¼´øÎʺŵÄÍøÖ·£¿ÒòΪËÑË÷ÒýÇæÅÂÓÉÓÚÎʺŶø½øÈëËÀÑ»·£¬³ÆÎª“ËÑË÷»úÆ÷ÈËÏÝÚ壨Spidertraps£©”£¨ÒÔǰ¶¯Íø
¾ÍÓÐÕâÑùÒ»¸ö©¶´£¬Ö©Öë½øÈ¥³ö²»À´ÁË£©£¬ËùÒԺܶàʱºò´øÎʺŵĵØÖ·ËÑË÷ÒýÇæÊDz»»á½øÈ¥µÄ£¬Î±¾²Ì¬¶ÔÓÚËÑË÷ÒýÇæÀ´Ëµ£¬Æäʵ¾ÍÊǾ²Ì¬£¬ÒòΪµØÖ·ÖÐûÓдøÎʺţ¬
ËùÒÔûÓÐÕæ¾²Ì¬±Èα¾²Ì¬ÊÕ¼µÃ¶àµÄ˵·¨¡£
¶þ¡¢ÎªÊ²Ã´Ñ¡Ôñα¾²Ì¬£¿
ÓкܶàÓû§Ëµ£ºÕ澲̬²»ºÃÂð£¿ÎªÊ²Ã´²»ÓÃÕæ¾²Ì¬£¿·ÃÎÊÆðÀ´²»ÊǸü¿ìÂ𣿸ºÔز»ÊǸüºÃÂ𣿵ȵȵȵȡ£¡£¡£¡£¡£¡£
ÔÚÕâÀÆäʵֻÓÃÒ»¸öÎÊÌâÀ´»Ø´ð£ºÎªÊ²Ã´Ñ¡ÔñMYSQL£¿ºÜ¶àÓû§´ó¸Å²»Ã÷°×ΪʲôÄÇô¶à´óÐÍÂÛ̳¶¼Ñ¡ÔñÁËMYSQLÊý¾Ý¿â×÷Ϊ´¢´æ»úÖÆ£¬´ó¸Å´ó²¿·Ö¶¼ÊÇÏ룺“Ò ......
Ò»¡¢Ê²Ã´ÊÇSQL×¢Èëʽ¹¥»÷?
¡¡¡¡ËùνSQL×¢Èëʽ¹¥»÷£¬¾ÍÊǹ¥»÷Õß°ÑSQLÃüÁî²åÈëµ½Web±íµ¥µÄÊäÈëÓò»òÒ³ÃæÇëÇóµÄ²éѯ×Ö·û´®£¬ÆÛÆ·þÎñÆ÷Ö´ÐжñÒâµÄSQLÃüÁî¡£ÔÚijЩ±í
µ¥ÖУ¬Óû§ÊäÈëµÄÄÚÈÝÖ±½ÓÓÃÀ´¹¹Ôì(»òÕßÓ°Ïì)¶¯Ì¬SQLÃüÁ»ò×÷Ϊ´æ´¢¹ý³ÌµÄÊäÈë²ÎÊý£¬ÕâÀà±íµ¥ÌرðÈÝÒ×Êܵ½SQL×¢Èëʽ¹¥»÷¡£³£¼ûµÄSQL×¢Èëʽ¹¥
»÷¹ý³ÌÀàÈ磺
¡¡¡¡¢Å ij¸öASP.NET WebÓ¦ÓÃÓÐÒ»¸öµÇÂ¼Ò³Ãæ£¬Õâ¸öµÇÂ¼Ò³Ãæ¿ØÖÆ×ÅÓû§ÊÇ·ñÓÐȨ·ÃÎÊÓ¦Óã¬ËüÒªÇóÓû§ÊäÈëÒ»¸öÃû³ÆºÍÃÜÂë¡£
¡¡¡¡¢Æ µÇÂ¼Ò³ÃæÖÐÊäÈëµÄÄÚÈݽ«Ö±½ÓÓÃÀ´¹¹Ô춯̬µÄSQLÃüÁ»òÕßÖ±½ÓÓÃ×÷´æ´¢¹ý³ÌµÄ²ÎÊý¡£ÏÂÃæÊÇASP.NETÓ¦Óù¹Ôì²éѯµÄÒ»¸öÀý×Ó£º
¡¡¡¡
System.Text.StringBuilder query = new System.Text.StringBuilder("SELECT * from Users WHERE login = '")¡£
Append(txtLogin.Text)¡£Append("' AND password='")¡£
Append(txtPassword.Text)¡£Append("'");
¡¡¡¡¢Ç ¹¥»÷ÕßÔÚÓû§Ãû×ÖºÍÃÜÂëÊäÈë¿òÖÐÊäÈë"'»ò'1'='1"Ö®ÀàµÄÄÚÈÝ¡£
¡¡¡¡¢È Óû§ÊäÈëµÄÄÚÈÝÌá½»¸ø·þÎñÆ÷Ö®ºó£¬·þÎñÆ÷ÔËÐÐÉÏÃæµÄASP.NE ......
Ò»¡¢Ê²Ã´ÊÇSQL×¢Èëʽ¹¥»÷?
¡¡¡¡ËùνSQL×¢Èëʽ¹¥»÷£¬¾ÍÊǹ¥»÷Õß°ÑSQLÃüÁî²åÈëµ½Web±íµ¥µÄÊäÈëÓò»òÒ³ÃæÇëÇóµÄ²éѯ×Ö·û´®£¬ÆÛÆ·þÎñÆ÷Ö´ÐжñÒâµÄSQLÃüÁî¡£ÔÚijЩ±í
µ¥ÖУ¬Óû§ÊäÈëµÄÄÚÈÝÖ±½ÓÓÃÀ´¹¹Ôì(»òÕßÓ°Ïì)¶¯Ì¬SQLÃüÁ»ò×÷Ϊ´æ´¢¹ý³ÌµÄÊäÈë²ÎÊý£¬ÕâÀà±íµ¥ÌرðÈÝÒ×Êܵ½SQL×¢Èëʽ¹¥»÷¡£³£¼ûµÄSQL×¢Èëʽ¹¥
»÷¹ý³ÌÀàÈ磺
¡¡¡¡¢Å ij¸öASP.NET WebÓ¦ÓÃÓÐÒ»¸öµÇÂ¼Ò³Ãæ£¬Õâ¸öµÇÂ¼Ò³Ãæ¿ØÖÆ×ÅÓû§ÊÇ·ñÓÐȨ·ÃÎÊÓ¦Óã¬ËüÒªÇóÓû§ÊäÈëÒ»¸öÃû³ÆºÍÃÜÂë¡£
¡¡¡¡¢Æ µÇÂ¼Ò³ÃæÖÐÊäÈëµÄÄÚÈݽ«Ö±½ÓÓÃÀ´¹¹Ô춯̬µÄSQLÃüÁ»òÕßÖ±½ÓÓÃ×÷´æ´¢¹ý³ÌµÄ²ÎÊý¡£ÏÂÃæÊÇASP.NETÓ¦Óù¹Ôì²éѯµÄÒ»¸öÀý×Ó£º
¡¡¡¡
System.Text.StringBuilder query = new System.Text.StringBuilder("SELECT * from Users WHERE login = '")¡£
Append(txtLogin.Text)¡£Append("' AND password='")¡£
Append(txtPassword.Text)¡£Append("'");
¡¡¡¡¢Ç ¹¥»÷ÕßÔÚÓû§Ãû×ÖºÍÃÜÂëÊäÈë¿òÖÐÊäÈë"'»ò'1'='1"Ö®ÀàµÄÄÚÈÝ¡£
¡¡¡¡¢È Óû§ÊäÈëµÄÄÚÈÝÌá½»¸ø·þÎñÆ÷Ö®ºó£¬·þÎñÆ÷ÔËÐÐÉÏÃæµÄASP.NE ......
֮ǰҲÊÇÔÚÍøÉÏÕÒµÄdotMsn¿ÉÒÔ»ñÈ¡ÁË£¬Ö®ºóÓÖÔÚÍøÉÏ¿´µ½ËµÊÇmsnÉý¼¶ÁËdotMsn»ñÈ¡²»µ½ÁË£¬Ôõô°ìÄÇ£¬ÎÒÏÖÔÚÔÚ×öÒ»¸öÉçÇøÍø£¬ÀïÃæÓÐÑûÇëºÃÓѼÓÈëµÄ¹¦ÄÜ£¬ÐèÒª»ñÈ¡µ½msnµÄÁªÏµÈË£¬Èç¹ûÓÐÄÄλ¸ßÊÖÖªµÀµÄ£¬Âé·³¸øÎÒ·¢Ò»·Ý£¬ÏÈллÁË£¡msn:gongchuanbo@live.cn ,qq:476759761 ......
ÔÚwindows 2003ÏÂ,ÔÚÔËÐÐwebÓ¦ÓóÌÐòµÄʱºò³öÏÖһϴíÎó:
·þÎñÆ÷ÎÞ·¨´¦ÀíÇëÇ󣬣££¾¶Ô·¾¶“C:\temp\mytest.txt”µÄ·ÃÎʾܾø
˵Ã÷: Ö´Ðе±Ç° Web ÇëÇóÆÚ¼ä£¬³öÏÖδ´¦ÀíµÄÒì³£¡£Çë¼ì²é¶ÑÕ»¸ú×ÙÐÅÏ¢£¬ÒÔÁ˽âÓйظôíÎóÒÔ¼°´úÂëÖе¼Ö´íÎóµÄ³ö´¦µÄÏêϸÐÅÏ¢¡£
Òì³£ÏêϸÐÅÏ¢: System.UnauthorizedAccessException: ¶Ô·¾¶“D:\temp1\MyTest.txt”µÄ·ÃÎʱ»¾Ü¾ø¡£
½â¾ö·½°¸Ò»
ÔÚÐèÒª½øÐжÁд²Ù×÷µÄĿ¼ÏÂÌí¼ÓNetwork ServiceÕâ¸öÕʺţ¬ÓÉÓÚÔÚiis 6.0ÖУ¬Ä¬ÈϵÄÓ¦ÓóÌÐò³ØÖеıêʾÓõÄÊÇNetwork Service£¬ËùÒÔÔÚ½ø³ÌÖÐÊÇʹÓÃNetwork ServiceÕâ¸öÕʺÅÔËÐÐÀ´ÔËÐÐw3wp.exe½ø³Ì£¬¶øµ±ÎÒÃÇÔÚÔËÐÐVS 2003µÄʱºòÐèÒª¶Ôijһ¸öĿ¼Ï½øÐжÁд²Ù×÷£¬¿´ÁËһϸÃÎļþ¼Ð£¬·¢ÏÖûÓÐNetwork Service£¬Ìí¼ÓÉϸÃÕ˺ţ¬Í¬Ê±Ñ¡ÉÏFULL CONTROL£¬ÎÊÌâ½â¾ö¡£
¡¡¡¡¡¡¡¡¾ßÌå¹ý³Ì£º¶Ô¸ÃÎļþ¼Ð°´ÓÒ¼ü££ÊôÐÔ££°²È«££Ìí¼Ó££¸ß¼¶££Á¢¼´²éÕÒ££ÔÚ“ËÑË÷½á¹û”ÏÂÑ¡“NETWORK¡¡SERVICE”££È·¶¨££È·¶¨££È·¶¨
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
½â¾ö·½°¸ ......
´ò¿ªÒ»¸öÍøÒ³£¬ÉÏÃæÏÔʾ5ÃëÖÓÒÔºóÌø×ªµ½ÆäËûÍøÒ³£¬Ã¿¹ýÒ»Ã룬Ëü¾Í»á¸Ä±ä£¨4ÃëÖÓÒÔºóÌø×ª£¬3ÃëÖÓÒÔºóÌø×ª¡£¡£¡££©
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" >
<head>
<title>Demo</title>
<script type="text/javascript">
var intervalID = 0;
var leftSeconds = 5;
function beginTimer()
{
loopTimerId = setInterval( timerStep, 1000 );
}
function timerStep()
{
if( leftSeconds > 1 )
{
leftSeconds --;
document.getElementById( "spTest" ).innerHTML = leftSeconds.toString() + "ÃëÖÓÒÔºóÌø×ªµ½ÆäËûÍøÒ³";
}
else
{
clearInterval( intervalID );
window.location.href = "newPage.aspx";
}
}
</script>
</head>
<body onload="beginTimer()">
<div>
<span id="spTest">5ÃëÖÓÒÔºóÌø×ªµ½ÆäËûÍøÒ³</span>
</div>
</body>
</html> ......
´ò¿ªÒ»¸öÍøÒ³£¬ÉÏÃæÏÔʾ5ÃëÖÓÒÔºóÌø×ªµ½ÆäËûÍøÒ³£¬Ã¿¹ýÒ»Ã룬Ëü¾Í»á¸Ä±ä£¨4ÃëÖÓÒÔºóÌø×ª£¬3ÃëÖÓÒÔºóÌø×ª¡£¡£¡££©
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" >
<head>
<title>Demo</title>
<script type="text/javascript">
var intervalID = 0;
var leftSeconds = 5;
function beginTimer()
{
loopTimerId = setInterval( timerStep, 1000 );
}
function timerStep()
{
if( leftSeconds > 1 )
{
leftSeconds --;
document.getElementById( "spTest" ).innerHTML = leftSeconds.toString() + "ÃëÖÓÒÔºóÌø×ªµ½ÆäËûÍøÒ³";
}
else
{
clearInterval( intervalID );
window.location.href = "newPage.aspx";
}
}
</script>
</head>
<body onload="beginTimer()">
<div>
<span id="spTest">5ÃëÖÓÒÔºóÌø×ªµ½ÆäËûÍøÒ³</span>
</div>
</body>
</html> ......