½â¾öSQL Injection©¶´µÄÒ»¸öº¯Êý
http://blog.csdn.net/cncco/archive/2006/04/07/654254.aspx
º¯Êý
<%
Function CheckInput(str,strType)
'º¯Êý¹¦ÄÜ£º¹ýÂË×Ö·û²ÎÊýÖеĵ¥ÒýºÅ£¬¶ÔÓÚÊý×Ö²ÎÊý½øÐÐÅжϣ¬Èç¹û²»ÊÇÊýÖµÀàÐÍ£¬Ôò¸³Öµ0
'²ÎÊýÒâÒ壺 str ---- Òª¹ýÂ˵IJÎÊý
' strType ---- ²ÎÊýÀàÐÍ£¬·ÖΪ×Ö·ûÐͺÍÊý×ÖÐÍ£¬×Ö·ûÐÍΪ"s"£¬Êý×ÖÐÍΪ"i"
Dim strTmp
strTmp = ""
If strType ="s" Then
strTmp = Replace(Trim(str),"'","'")
ElseIf strType="i" Then
If isNumeric(str)=False Then str="0"
strTmp = str
Else
strTmp = str
End If
CheckInput = strTmp
End Function
%>
Õâ¸öº¯ÊýºÜ¼òµ¥£¬ Ö÷ÒªÊÇÕë¶Ô×Ö·û´®ºÍÊý×ÖÁ½ÖÖÀàÐ͵Ĵ«ÈëÊý¾Ý·Ö±ð½øÐÐÁË´¦Àí£¬¾ßÌåÓ÷¨£º
×Ö·ûÀàÐ͵Ä
strUsername = CheckInput(Request(“username“),“s ......
SQLÈßÓà×ֶεIJßÂԺ͹ÜÀí
http://www.examda.com/ncre/three/db/fudao/20091203/093528816.html
ÈßÓà×ֶεÄʹÓÃÔÚ¶à±íÁªºÏ²éѯ¶¼ÊÇ´óÊý¾ÝÁ¿µÄ±íµÄÇé¿öÏ£¬È·ÊµÊǸö²»´íµÄÑ¡Ôñ£¬ÓÐЧµÄ¼õÉÙÁËIO²Ù×÷¡£µ«½áºÏÒÑÓеÄÏîÄ¿²úÆ·À´¿´£¬ÈßÓà×Ö¶ÎȷʵÊÇË«Èн£¡£ÓÈÆäÊÇ´óÏîÄ¿µÄ¿ª·¢£¬Èç¹ûºöÂÔij¸ö±íµÄÈßÓà×ֶεĸüУ¬ÄÇôºó¹ûÊÇÔÖÄÑÐԵġ£ÈçºÎÓÐЧµÄ¹ÜÀíÈßÓà×Ö¶ÎÊÇ¿ª·¢×éÄÚ±ØÐë½â¾öµÄÎÊÌâ¡£ÎҵĽâ¾ö·½°¸ÊÇ£ºÊ¹ÓÃרÃŵıíÀ´¹ÜÀíÈßÓà×ֶΡ£ÀýÈçarticle±íÓÐÒÔÏÂÈßÓà×Ö¶Î
¡¡¡¡fromUserName,toUserName
¡¡¡¡ÈçºÎ¹ÜÀíÕâÁ½¸ö×Ö¶ÎÄØ£¿Í¨¹ý½¨Á¢Ò»¸ö±í£¬±í½á¹¹ÈçÏÂ
¡¡¡¡id,objTable,objName,sourceTable, sourceId,level£¬isUpdate
¡¡¡¡ÆäÖÐobjTable=Ä¿±ê±í£¬objName= Ä¿±ê×ֶΣ¬sourceTable=Ô´±í,sourceId=Ô´±íID,level=ÊÇ·ñÐèÒªÁ¢¼´¸üÐÂ,isUpdate=ÊÇ·ñÒѸüÐÂ
¡¡¡¡ÆäÖУ¬level×ֶκÜÓбØÒª£¬ÓÐЩÈßÓà×ֶβ¢²»ÐèÒªÔÚÔ´±íÐ޸ĺóÁ¢¼´¸üУ¬ÄÇô¿ÉÒÔͨ¹ýÒ»¸ö¶¨ÆÚ¸üвßÂÔÀ´¸üС£
¡¡¡¡Í¨¹ý¿â±íµÄ¹ÜÀí£¬ÅäºÏÒ»¸öºÏÀíµÄ´æ´¢¹ý³Ì£¬ÈßÓà×ֶεÄʹÓý«²»ÔÙÊÇÄÑÌâ¡£
¡¡¡¡¾ÙÀý£¬Èç¹ûÉÏÃæÁ½¸ö×ֶη¢Éú±ä»¯£¬ÔòʹÓô¥·¢Æ÷»òÕßµ÷ÓÃÕâ¸ö´æ´¢¹ý³ÌÀ´¼ì²éÊÇ·ñÓÐÐèÒªÁ¢¼´¸üеÄÈßÓà×ֶΣ¬ÐèÒªÔòÁ¢¼´¸üУ¬² ......
v$sqltext
´æ´¢µÄÊÇÍêÕûµÄSQL
v$sqlarea
´æ´¢µÄSQL ºÍһЩÏà¹ØµÄÐÅÏ¢£¬±ÈÈçÀۼƵÄÖ´ÐдÎÊý£¬Âß¼¶Á£¬ÎïÀí¶ÁµÈͳ¼ÆÐÅÏ¢
v$sql
´æ´¢µÄÊǾßÌåµÄSQL ºÍÖ´Ðмƻ®Ïà¹ØÐÅÏ¢£¬Êµ¼ÊÉÏ£¬v$sqlarea ¿ÉÒÔ¿´×ö v$sql ¸ù¾Ý sqltext µÈ ×öÁË group by Ö®ºóµÄÐÅÏ¢ ......
±íjh03ÓÐÏÂÁÐÊý¾Ý£º
name¡¡score
aa¡¡¡¡99
bb¡¡¡¡56
cc¡¡¡¡56
dd¡¡¡¡77
ee¡¡¡¡78
ff¡¡¡¡76
gg¡¡¡¡78
ff¡¡¡¡50
1. Ãû´ÎÉú³É·½Ê½1,ScoreÖØ¸´Ê±ºÏ²¢Ãû´Î
SELECT *¡¡,¡¡Place=(SELECT COUNT(DISTINCT Score) from jh03 WHERE Score >= a.Score)
from jh03 a
ORDER BY Place
½á¹û
Name Score Place
---------------- ----------------- -----------
aa 99.00 1
ee 78.00 2
gg 78.00 2
dd 77.00 3
ff 76.00 4
bb 56.00 5
cc 56.00 5
ff 50.00 6
2. Ãû´ÎÉú³É·½Ê½2 , ScoreÖØ¸´Ê±±£ÁôÃû´Î¿Õȱ
SELECT * , Place=(SELECT COUNT(Score) from jh03 WHERE Score > a.Score) + 1
from jh03 a
ORDER BY Place
½á¹û
Name Score Place
--------------- ----------------- -----------
aa 99.00 1
ee 78.00 2
gg 78.00 2
dd 77.00 4
ff 76.00 5
bb 56.00 6
cc 56.00 6
ff ......
½ñÌìÐÞ¸ÄÁËÊý¾Ý¿â£¬ÓÚÊǽøÐÐÖØÐ·¢²¼ºÍ¶©ÔÄ£¬Í»È»³öÏÖÁËÒÔÏÂÒì³£
½ø³ÌδÄÜ´óÈÝÁ¿¸´ÖƵ½±í"XS_DDML"ÖÐ
´íÎóÏêϸÐÅÏ¢£º
ÔÚ BCP Êý¾ÝÎļþÖÐÓöµ½µÄÒâÍâµÄ EOF
(Ô´: ODBC SQL Server Driver (ODBC); ´íÎó´úÂë: S1000)
ÓÚÊDzé°ïÖú£¬²éGoogle,ºÇºÇ£¬Google»¹ÕæÊǸöºÃµØ·½£¬ÕÒµ½ÁËÒÔÏÂSQL£¬¾Ý˵¿ÉÒÔ½â¾ö¸ÃÎÊÌâ
sp_configure 'max text repl size (B)',2147483647
GO
RECONFIGURE WITH OVERRIDE
GO
¿ÉÒÔÌì²»´ÓÈËÔ¸°¡£¬¼ÌÐø³öÏÖÕâ¸öÒì³££¬ÓÚÊÇ»ØÏëÉϴεijöÏÖ£¬¹þ¹þ£¬Ìø¹ýÕâ¸ö´¦Àí¡£
²ÉÓÃDTSµ¼Èëµ¼³öÊý¾Ý¹¦Äܰѷ¢²¼Êý¾Ý¿âÈ«²¿¸´ÖƵ½¶©ÔÄÊý¾Ý¿â£¬È»ºóÖØÐ´´½¨¶©ÔÄ£¬Ñ¡Ôñ¶©ÔÄÊý¾Ý¿âÒѾÓнṹºÍÊý¾Ý¡£
Ð޸ķ¢²¼ÖеÄÊý¾Ý½øÐвâÊÔ£¬Ò»ÇÐÕý³£¡£
ºÇºÇ£¬×ÜËã²»ÓòÉÓÃGoogleÖв鵽µÄ½¨Ò飬varcharµÈµÈÈ«²¿ÐÞ¸ÄΪnvarchar,textÐÞ¸ÄΪntextÕâÑùÐèÒªµÄ¹¤³ÌÌ«´óÁË¡£
......
ÊéÇ©£ºÇå³ýËùÓÐÊéÇ©¡£ CTRL-SHIFT-F2
ÊéÇ©£º²åÈë»òɾ³ýÊéÇ©(Çл»)¡£ CTRL+F2
ÊéÇ©£ºÒƶ¯µ½ÏÂÒ»¸öÊéÇ©¡£ F2 ¹¦Äܼü
ÊéÇ©£ºÒƶ¯µ½ÉÏÒ»¸öÊéÇ©¡£ SHIFT+F2
È¡Ïû²éѯ¡£ ALT+BREAK
Á¬½Ó£ºÁ¬½Ó¡£ CTRL+O
Á¬½Ó£º¶Ï¿ªÁ¬½Ó¡£ CTRL+F4
Á¬½Ó£º¶Ï¿ªÁ¬½Ó²¢¹Ø±Õ×Ó´°¿Ú¡£ CTRL+F4
Êý¾Ý¿â¶ÔÏóÐÅÏ¢¡£ ALT+F1
±à¼£ºÇå³ý»î¶¯µÄ±à¼Æ÷´°¸ñ¡£ CTRL+SHIFT+DEL
±à¼£º×¢ÊÍ´úÂë¡£ CTRL+SHIFT+C
±à¼£ºÉ¾³ý×¢ÊÍ¡£ CTRL+SHIFT+R
±à¼£º¸´ÖÆ¡£»¹¿ÉÒÔʹÓà CTRL+INSERT¡£ CTRL+C
±à¼£º¼ôÇС£»¹¿ÉÒÔʹÓà SHIFT+DEL¡£ CTRL+X
±à¼£º¼õСËõ½ø¡£ SHIFT+TAB
±à¼£ºÔÚ±à¼Æ÷´°¸ñÖÐɾ³ýÖÁÐÐβ¡£ CTRL+DEL
±à¼£º²éÕÒ¡£ CTRL+F
±à¼£º×ªµ½Ðкš£ CTRL+G
±à¼£ºÔö´óËõ½ø¡£ TAB
±à¼£ºÊ¹Ñ¡¶¨ÄÚÈÝΪСд¡£ CTRL+SHIFT+L
±à¼£ºÊ¹Ñ¡¶¨ÄÚÈÝΪ´óд¡£ CTRL+SHIFT+U
±à¼£ºÕ³Ìù¡£»¹¿ÉÒÔʹÓà SHIFT+INSERT¡£ CTRL+V
±à¼£ºÖظ´ÉÏ´ÎËÑË÷»ò²éÕÒÏÂÒ»¸ö¡£ F3 ¹¦Äܼü
±à¼£ºÌæ»»¡£ CTRL+H
±à¼£ºÈ«Ñ¡¡£ CTRL+A
±à¼£º³·Ïû¡£ CTRL+Z
Ö´Ðвéѯ¡£»¹¿ÉÒÔʹÓà CTRL+E (Õë¶ÔÏòºó¼æÈÝÐÔ)¡£ F5 ¹¦Äܼü
SQL ²éѯ·ÖÎöÆ÷°ïÖú¡£ F1 ¹¦Äܼü
¶ÔËùÑ¡ Transact-SQL Óï¾äµÄ°ïÖú¡£ SHIFT+F ......