Ò׽ؽØÍ¼Èí¼þ¡¢µ¥Îļþ¡¢Ãâ°²×°¡¢´¿ÂÌÉ«¡¢½ö160KB
ÈÈÃűêÇ©£º c c# c++ asp asp.net linux php jsp java vb Python Ruby mysql sql access Sqlite sqlserver delphi javascript Oracle ajax wap mssql html css flash flex dreamweaver xml
 ×îÐÂÎÄÕ : sql

ASP³ÌÐòÓëSQL´æ´¢¹ý³Ì½áºÏʹÓÃÏê½â

´æ´¢½ø³Ì¾ÍÊÇ×÷Ϊ¿ÉÖ´ÐжÔÏó´æ·ÅÔÚÊý¾Ý¿âÖеÄÒ»¸ö»ò¶à¸öSQLÃüÁî¡£
¶¨Òå×ÜÊǺܳéÏó¡£´æ´¢½ø³ÌÆäʵ¾ÍÊÇÄÜÍê³ÉÒ»¶¨²Ù×÷µÄÒ»×éSQLÓï¾ä£¬Ö»²»¹ýÕâ×éÓï¾äÊÇ·ÅÔÚÊý¾Ý¿âÖеÄ(ÕâÀïÎÒÃÇ̸ֻSQL SERVER)¡£Èç¹ûÎÒÃÇͨ¹ý´´½¨´æ´¢½ø³ÌÒÔ¼°ÔÚASPÖе÷Óô洢½ø³Ì£¬¾Í¿ÉÒÔ±ÜÃ⽫SQLÓï¾äͬASP´úÂë»ìÔÓÔÚÒ»Æð¡£ÕâÑù×öµÄºÃ´¦ÖÁÉÙÓÐÈý¸ö£º
µÚÒ»¡¢´ó´óÌá¸ßЧÂÊ¡£´æ´¢½ø³Ì±¾ÉíµÄÖ´ÐÐËٶȷdz£¿ì£¬¶øÇÒ£¬µ÷Óô洢½ø³Ì¿ÉÒÔ´ó´ó¼õÉÙͬÊý¾Ý¿âµÄ½»»¥´ÎÊý¡£
µÚ¶þ¡¢Ìá¸ß°²È«ÐÔ¡£¼ÙÈ罫SQLÓï¾ä»ìºÏÔÚASP´úÂëÖУ¬Ò»µ©´úÂëʧÃÜ£¬Í¬Ê±Ò²¾ÍÒâζ×Å¿â½á¹¹Ê§ÃÜ¡£
µÚÈý¡¢ÓÐÀûÓÚSQLÓï¾äµÄÖØÓá£
ÔÚASPÖУ¬Ò»°ãͨ¹ýCOMMAND¶ÔÏóµ÷Óô洢½ø³Ì£¬¸ù¾Ý²»Í¬Çé¿ö£¬±¾ÎÄÒ²½éÉÜÆäËüµ÷Ó÷½·¨¡£ÎªÁË·½±ã˵Ã÷£¬¸ù¾Ý´æ´¢½ø³ÌµÄÊäÈëÊä³ö£¬×÷ÒÔϼòµ¥·ÖÀࣺ
1. Ö»·µ»Øµ¥Ò»¼Ç¼¼¯µÄ´æ´¢½ø³Ì
¼ÙÉèÓÐÒÔÏ´洢½ø³Ì(±¾ÎĵÄÄ¿µÄ²»ÔÚÓÚ½²ÊöT-SQLÓï·¨£¬ËùÒÔ´æ´¢½ø³ÌÖ»¸ø³ö´úÂ룬²»×÷˵Ã÷)£º
/*SP1*/
CREATE PROCEDURE DBO.GETUSERLIST
AS
SET NOCOUNT ON
BEGIN
SELECT * from DBO.[USERINFO]
END
GO
ÒÔÉÏ´æ´¢½ø³ÌÈ¡µÃUSERINFO±íÖеÄËùÓмǼ£¬·µ»ØÒ»¸ö¼Ç¼¼¯¡£Í¨¹ýCOMMAND¶ÔÏóµ÷Óøô洢½ø³ÌµÄASP´úÂëÈçÏÂ:
'**ͨ¹ýCOMMAND¶ÔÏóµ ......

ASP³ÌÐòÓëSQL´æ´¢¹ý³Ì½áºÏʹÓÃÏê½â

´æ´¢½ø³Ì¾ÍÊÇ×÷Ϊ¿ÉÖ´ÐжÔÏó´æ·ÅÔÚÊý¾Ý¿âÖеÄÒ»¸ö»ò¶à¸öSQLÃüÁî¡£
¶¨Òå×ÜÊǺܳéÏó¡£´æ´¢½ø³ÌÆäʵ¾ÍÊÇÄÜÍê³ÉÒ»¶¨²Ù×÷µÄÒ»×éSQLÓï¾ä£¬Ö»²»¹ýÕâ×éÓï¾äÊÇ·ÅÔÚÊý¾Ý¿âÖеÄ(ÕâÀïÎÒÃÇ̸ֻSQL SERVER)¡£Èç¹ûÎÒÃÇͨ¹ý´´½¨´æ´¢½ø³ÌÒÔ¼°ÔÚASPÖе÷Óô洢½ø³Ì£¬¾Í¿ÉÒÔ±ÜÃ⽫SQLÓï¾äͬASP´úÂë»ìÔÓÔÚÒ»Æð¡£ÕâÑù×öµÄºÃ´¦ÖÁÉÙÓÐÈý¸ö£º
µÚÒ»¡¢´ó´óÌá¸ßЧÂÊ¡£´æ´¢½ø³Ì±¾ÉíµÄÖ´ÐÐËٶȷdz£¿ì£¬¶øÇÒ£¬µ÷Óô洢½ø³Ì¿ÉÒÔ´ó´ó¼õÉÙͬÊý¾Ý¿âµÄ½»»¥´ÎÊý¡£
µÚ¶þ¡¢Ìá¸ß°²È«ÐÔ¡£¼ÙÈ罫SQLÓï¾ä»ìºÏÔÚASP´úÂëÖУ¬Ò»µ©´úÂëʧÃÜ£¬Í¬Ê±Ò²¾ÍÒâζ×Å¿â½á¹¹Ê§ÃÜ¡£
µÚÈý¡¢ÓÐÀûÓÚSQLÓï¾äµÄÖØÓá£
ÔÚASPÖУ¬Ò»°ãͨ¹ýCOMMAND¶ÔÏóµ÷Óô洢½ø³Ì£¬¸ù¾Ý²»Í¬Çé¿ö£¬±¾ÎÄÒ²½éÉÜÆäËüµ÷Ó÷½·¨¡£ÎªÁË·½±ã˵Ã÷£¬¸ù¾Ý´æ´¢½ø³ÌµÄÊäÈëÊä³ö£¬×÷ÒÔϼòµ¥·ÖÀࣺ
1. Ö»·µ»Øµ¥Ò»¼Ç¼¼¯µÄ´æ´¢½ø³Ì
¼ÙÉèÓÐÒÔÏ´洢½ø³Ì(±¾ÎĵÄÄ¿µÄ²»ÔÚÓÚ½²ÊöT-SQLÓï·¨£¬ËùÒÔ´æ´¢½ø³ÌÖ»¸ø³ö´úÂ룬²»×÷˵Ã÷)£º
/*SP1*/
CREATE PROCEDURE DBO.GETUSERLIST
AS
SET NOCOUNT ON
BEGIN
SELECT * from DBO.[USERINFO]
END
GO
ÒÔÉÏ´æ´¢½ø³ÌÈ¡µÃUSERINFO±íÖеÄËùÓмǼ£¬·µ»ØÒ»¸ö¼Ç¼¼¯¡£Í¨¹ýCOMMAND¶ÔÏóµ÷Óøô洢½ø³ÌµÄASP´úÂëÈçÏÂ:
'**ͨ¹ýCOMMAND¶ÔÏóµ ......

asp.netÈçºÎÁ¬½Ósql server2000Êý¾Ý¿â

¡ïAsp.netÈçºÎÁ¬½ÓSQL Server2000Êý¾Ý¿â¡ï
 
´ó¼ÒºÃ,ÒÔÏÂÊÇÓйØASP.netÁ¬½ÓSQL Server2000Êý¾Ý¿âµÄÀý³Ì£¬
ÔÚÕâÀïºÍ´ó¼Ò·ÖÏíһϣº
Asp.netÁ¬½ÓSQL Server2000Êý¾Ý¿âÀý³ÌÏê½â: 
<%@ Import Namespace="System.Data" %> 
<%@ Import NameSpace="System.Data.SqlClient" %> 
<script laguage="VB" runat="server"> 
sub page_load(sender as Object,e as EventArgs) 
Dim myConnection As SqlConnection 
Dim myCommand As SqlCommand 
Dim ds as DataSet 
'1.connect to sql server 
myConnection = New SqlConnection( "server=localhost;database=Pubs;uid=ueytjdf;pwd=doekdf" ) 
myConnection.Open() 
la1.text="Connection Opened!" 
 
'2.Create a table 
myCommand = New SqlCo ......

asp.netÈçºÎÁ¬½Ósql server2000Êý¾Ý¿â

¡ïAsp.netÈçºÎÁ¬½ÓSQL Server2000Êý¾Ý¿â¡ï
 
´ó¼ÒºÃ,ÒÔÏÂÊÇÓйØASP.netÁ¬½ÓSQL Server2000Êý¾Ý¿âµÄÀý³Ì£¬
ÔÚÕâÀïºÍ´ó¼Ò·ÖÏíһϣº
Asp.netÁ¬½ÓSQL Server2000Êý¾Ý¿âÀý³ÌÏê½â: 
<%@ Import Namespace="System.Data" %> 
<%@ Import NameSpace="System.Data.SqlClient" %> 
<script laguage="VB" runat="server"> 
sub page_load(sender as Object,e as EventArgs) 
Dim myConnection As SqlConnection 
Dim myCommand As SqlCommand 
Dim ds as DataSet 
'1.connect to sql server 
myConnection = New SqlConnection( "server=localhost;database=Pubs;uid=ueytjdf;pwd=doekdf" ) 
myConnection.Open() 
la1.text="Connection Opened!" 
 
'2.Create a table 
myCommand = New SqlCo ......

ASP.NET·ÀSQL×¢Èë½Å±¾³ÌÐò v2.0

public class SqlCheck
{
public SqlCheck()
{
//
// TODO: ÔÚ´Ë´¦Ìí¼Ó¹¹Ô캯ÊýÂß¼­
//
}

public SqlConnection oconn()
{
SqlConnection conn = new SqlConnection();
conn.ConnectionString = ConfigurationManager.ConnectionStrings["StudyConnectionString"].ToString();
//µÚ1ÖÖµ÷Óõķ½·¨ JK1986_CheckSql();
JK1986_CheckSql();
if ( conn.State == ConnectionState.Closed )
{
conn.Open();
}
return conn;
}
public DataTable getsource(string getds)
{
SqlConnection conn = oconn();
SqlDataAdapter da = new SqlDataAdapter(getds, conn);
DataSet ds = new DataSet();
da.Fill(ds,"news" );
return ds.Tables["news"];
}

public static void JK1986_CheckSql()
{
string jk1986_sql = "exec↓select↓drop↓alter↓exists↓union↓and↓or↓xor↓order↓mid↓asc↓execute ......

ASP.NET·ÀSQL×¢Èë½Å±¾³ÌÐò v2.0

public class SqlCheck
{
public SqlCheck()
{
//
// TODO: ÔÚ´Ë´¦Ìí¼Ó¹¹Ô캯ÊýÂß¼­
//
}

public SqlConnection oconn()
{
SqlConnection conn = new SqlConnection();
conn.ConnectionString = ConfigurationManager.ConnectionStrings["StudyConnectionString"].ToString();
//µÚ1ÖÖµ÷Óõķ½·¨ JK1986_CheckSql();
JK1986_CheckSql();
if ( conn.State == ConnectionState.Closed )
{
conn.Open();
}
return conn;
}
public DataTable getsource(string getds)
{
SqlConnection conn = oconn();
SqlDataAdapter da = new SqlDataAdapter(getds, conn);
DataSet ds = new DataSet();
da.Fill(ds,"news" );
return ds.Tables["news"];
}

public static void JK1986_CheckSql()
{
string jk1986_sql = "exec↓select↓drop↓alter↓exists↓union↓and↓or↓xor↓order↓mid↓asc↓execute ......

SQLɾ³ýÖ¸¶¨×Ö¶ÎÎÊÌâ

¸üÐÂÏÂÎÊÌ⣺
񡜧TBL_Info
×ֶΣº
    infoId int
    title  varchar(20)
    Content  text
    byUser  varchar(20)
    createTime datetime
1¡¢ÈçºÎɾ³ý±íÖÐÊý¾ÝÏàͬµÄÊý¾ÝÄØ£¿£¨Ö÷¼ü³ýÍ⣩
2¡¢ÈçºÎɾ³ýÊý¾Ý±íÖÐij¸ö×Ö¶ÎÊý¾ÝÏàͬµÄÊý¾ÝÄØ(±ÈÈçtitle£ºÉ¾³ýËùÓÐtitleÏàͬµÄÊý¾Ý)£¿
3¡¢ÈçºÎͳ¼Æ±íÖÐtitleÏàͬÊý¾ÝµÄÊýÄ¿£¿
--1
--1.1Ïàͬʱ±£Áô×îСµÄinfoId
delete TBL_Info from TBL_Info t where infoId not in (select min(id) from infoId where title = t.title and Content = t.Content and byUser = t.byUser and createTime = t.createTime)
--1.1Ïàͬʱ±£Áô×î´óµÄinfoId
delete TBL_Info from TBL_Info t where infoId not in (select max(id) from infoId where title = t.title and Content = t.Content and byUser = t.byUser and createTime = t.createTime)
--2
delete from TBL_Info where title in (select title from TBL_Info group by title having count(1) > 1)
--3
select title , count(1) from TBL_Info group by title
select title , count( ......

¡¾×ªÔØ.SQL×¢ÈëÔ­Àí¡¿SQL×¢Èë·¨¹¥»÷Ò»ÈÕͨ

Ëæ×ÅB/SģʽӦÓÿª·¢µÄ·¢Õ¹£¬Ê¹ÓÃÕâÖÖģʽ±àдӦÓóÌÐòµÄ³ÌÐòÔ±Ò²Ô½À´Ô½¶à¡£µ«ÊÇÓÉÓÚ³ÌÐòÔ±µÄˮƽ¼°¾­ÑéÒ²²Î²î²»Æë£¬Ï൱´óÒ»²¿·Ö³ÌÐòÔ±ÔÚ±àд´úÂëµÄʱºò£¬Ã»ÓжÔÓû§ÊäÈëÊý¾ÝµÄºÏ·¨ÐÔ½øÐÐÅжϣ¬Ê¹Ó¦ÓóÌÐò´æÔÚ°²È«Òþ»¼¡£Óû§¿ÉÒÔÌá½»Ò»¶ÎÊý¾Ý¿â²éѯ´úÂ룬¸ù
¾Ý³ÌÐò·µ»ØµÄ½á¹û£¬»ñµÃijЩËûÏëµÃÖªµÄÊý¾Ý£¬Õâ¾ÍÊÇËùνµÄSQL Injection£¬¼´SQL×¢Èë¡£
SQL×¢ÈëÊÇ´ÓÕý³£µÄWWW¶Ë¿Ú·ÃÎÊ£¬¶øÇÒ±íÃæ¿´ÆðÀ´¸úÒ»°ãµÄWebÒ³Ãæ·ÃÎÊÃ»Ê²Ã´Çø±ð£¬ËùÒÔĿǰÊÐÃæµÄ·À»ðǽ¶¼²»»á¶ÔSQL×¢Èë·¢³ö¾¯±¨£¬Èç¹û¹ÜÀíԱû²é¿´IISÈÕÖ¾µÄϰ¹ß£¬¿ÉÄܱ»ÈëÇֺܳ¤Ê±¼ä¶¼²»»á·¢¾õ¡£µ«ÊÇ£¬SQL×¢ÈëµÄÊÖ·¨Ï൱Áé»î£¬ÔÚ×¢ÈëµÄʱºò»áÅöµ½ºÜ¶àÒâÍâµÄÇé¿ö¡£Äܲ»Äܸù¾Ý¾ßÌåÇé¿ö½øÐзÖÎö£¬¹¹ÔìÇÉÃîµÄSQLÓï¾ä£¬´Ó¶ø³É¹¦»ñÈ¡ÏëÒªµÄÊý¾Ý¡£
¾Ýͳ¼Æ£¬ÍøÕ¾ÓÃASP+Access»òSQLServerµÄÕ¼70%ÒÔÉÏ£¬PHP+MySQÕ¼L20%£¬ÆäËûµÄ²»×ã10%¡£ÔÚ±¾ÎÄ£¬ÒÔSQL-SERVER£«ASPÀý˵Ã÷SQL×¢ÈëµÄÔ­Àí¡¢·½·¨Óë¹ý³Ì¡££¨PHP×¢ÈëµÄÎÄÕÂÓÉNBÁªÃ˵ÄÁíһλÅóÓÑzwell׫дµÄÓйØÎÄÕ£©
SQL×¢Èë¹¥»÷µÄ×ÜÌå˼·ÊÇ£º
l ·¢ÏÖSQL×¢ÈëλÖã»
l ÅжϺǫ́Êý¾Ý¿âÀàÐÍ£»
l È·¶¨XP_CMDSHELL¿ÉÖ´ÐÐÇé¿ö
l ·¢ÏÖWEBÐéÄâĿ¼
l ......

¡¾×ªÔØ.SQL×¢ÈëÔ­Àí¡¿SQL×¢Èë©¶´È«½Ó´¥ ÈëÃÅÆª

Ëæ×ÅB/SģʽӦÓÿª·¢µÄ·¢Õ¹£¬Ê¹ÓÃÕâÖÖģʽ±àдӦÓóÌÐòµÄ³ÌÐòÔ±Ò²Ô½À´Ô½¶à¡£µ«ÊÇÓÉÓÚÕâ¸öÐÐÒµµÄÈëÃÅÃż÷²»¸ß£¬³ÌÐòÔ±µÄˮƽ¼°¾­ÑéÒ²²Î²î²»Æë£¬Ï൱´óÒ»²¿·Ö³ÌÐòÔ±ÔÚ±àд´úÂëµÄʱºò£¬Ã»ÓжÔÓû§ÊäÈëÊý¾ÝµÄºÏ·¨ÐÔ½øÐÐÅжϣ¬Ê¹Ó¦ÓóÌÐò´æÔÚ°²È«Òþ»¼¡£Óû§¿ÉÒÔÌá½»Ò»¶ÎÊý¾Ý¿â²éѯ´úÂ룬¸ù¾Ý³ÌÐò·µ»ØµÄ½á¹û£¬»ñµÃijЩËûÏëµÃÖªµÄÊý¾Ý£¬Õâ¾ÍÊÇËùνµÄSQL Injection£¬¼´SQL×¢Èë¡£     SQL×¢ÈëÊÇ´ÓÕý³£µÄWWW¶Ë¿Ú·ÃÎÊ£¬¶øÇÒ±íÃæ¿´ÆðÀ´¸úÒ»°ãµÄWebÒ³Ãæ·ÃÎÊÃ»Ê²Ã´Çø±ð£¬ËùÒÔĿǰÊÐÃæµÄ·À»ðǽ¶¼²»»á¶ÔSQL×¢Èë·¢³ö¾¯±¨£¬Èç¹û¹ÜÀíԱû²é¿´IISÈÕÖ¾µÄϰ¹ß£¬¿ÉÄܱ»ÈëÇֺܳ¤Ê±¼ä¶¼²»»á·¢¾õ¡£    µ«ÊÇ£¬SQL×¢ÈëµÄÊÖ·¨Ï൱Áé»î£¬ÔÚ×¢ÈëµÄʱºò»áÅöµ½ºÜ¶àÒâÍâµÄÇé¿ö¡£Äܲ»Äܸù¾Ý¾ßÌåÇé¿ö½øÐзÖÎö£¬¹¹ÔìÇÉÃîµÄSQLÓï¾ä£¬´Ó¶ø³É¹¦»ñÈ¡ÏëÒªµÄÊý¾Ý£¬ÊǸßÊÖÓë¡°²ËÄñ¡±µÄ¸ù±¾Çø±ð¡£    ¸ù¾Ý¹úÇ飬¹úÄÚµÄÍøÕ¾ÓÃASP+Access»òSQLServerµÄÕ¼70%ÒÔÉÏ£¬PHP+MySQÕ¼L20%£¬ÆäËûµÄ²»×ã10%¡£ÔÚ±¾ÎÄ£¬ÎÒÃÇ´Ó·ÖÈëÃÅ¡¢½ø½×ÖÁ¸ß¼¶½²½âÒ»ÏÂASP×¢ÈëµÄ·½·¨¼°¼¼ÇÉ£¬PHP×¢ÈëµÄÎÄÕÂÓÉNBÁªÃ˵ÄÁíһλÅóÓÑzwell׫д£¬Ï£Íû¶Ô°²È«¹¤×÷ÕߺͳÌÐòÔ±¶¼ÓÐÓô¦¡£Á˽âASP×¢ÈëµÄÅóÓÑÒ²Çë²»ÒªÌø¹ýÈëÃÅÆ ......
×ܼǼÊý:4346; ×ÜÒ³Êý:725; ÿҳ6 Ìõ; Ê×Ò³ ÉÏÒ»Ò³ [499] [500] [501] [502] 503 [504] [505] [506] [507] [508]  ÏÂÒ»Ò³ βҳ
© 2009 ej38.com All Rights Reserved. ¹ØÓÚE½¡ÍøÁªÏµÎÒÃÇ | Õ¾µãµØÍ¼ | ¸ÓICP±¸09004571ºÅ