aspÖÐÈÝ´íÓï¾äµÄʹÓÃ
ÈçÏ´úÂ룺
On Error Resume Next
1=1-1
On Error GoTo 0
Response.Write("³ÌÐò³ö´íÀ²£¡£¡")
On Error Resume Next ÈÝ´íÓï¾ä£¬Ö»Ê¹ÓÃÕâÒ»¾ä»°±¾Ò³Ã潫²»»á³öÏÖ´íÎó¡£
On Error GoTo 0 Èç¹û³öÏÖÁË´íÎó£¬ÔòÔËÐдËÓï¾äϵĵÚ1ÐС£
Err.Description ³ö´íÄÚÈÝ
Err.Number ³ö´íÊýÄ¿
Err.Clear Çå³ý´íÎó
Ó¦Ó㺿ÉÒÔʹÓÃÈÝ´í£«Êý¾Ý¿âÔ¼ÊøµÄ·½·¨£¬´ïµ½±£³ÖÊý¾ÝÍêÕûÐÔµÄÄ¿µÄ¡££¨ÔÚ×î½üµÄOA°ì¹«ÏµÍ³ÖÐʹÓóɹ¦¡££©
ÏêϸÀý×Ó
1¡¢×î»ù±¾µÄ´íÎóÌáʾ
dim i
i = 1/0
½á¹û£º
Microsoft VBScript ÔËÐÐʱ´íÎó ´íÎó '800a000b'
±»Áã³ý
/try.asp£¬ÐÐ 3
2¡¢·ÀֹϵͳµÄ´íÎóÌáʾ
ʹÓÃon error resume next£¬¿ÉÒÔ·ÅÖÃϵͳÌáʾ´íÎ󣬲¢ÇÒºÃÏñʲô¶¼Ã»Óз¢ÉúÒ»Ñù£¬³ÁĬµÄÔËÐÐÏÂÈ¥
on error resume next
dim i
i = 1/0
ÔËÐнá¹û£º
¿Õ
3¡¢¼ì²éϵͳµÄ´íÎó
ʹÓÃÁËon error resume nextÖ®ºó£¬Èç¹û³ö´íErr¶ÔÏóÖн«·ÅÖÃ×î½üÒ»´Î³ö´íµÄÐÅÏ¢¡£Err¶ÔÏóÖØÒªµÄÊôÐÔÓÐÈý¸ö£ºNumber, Source, Description¡£·Ö±ðÊÇ´íÎóºÅ£¬´íÎóÀ´Ô´£¬´íÎóÃèÊö¡£ÄãÄܲ¶»ñµÄ¶¼ÊÇÔËÐÐʱ´íÎ󣬶øÇÒIf Err thenÕâÑùµÄд·¨µÈ¼ÛÓÚIf Err.Number then
on error resume next
dim i
i = 1/0
execute "test"
Response.Write Err.Description
ÔËÐнá¹û£º
ÀàÐͲ»Æ¥Åä
¿ÉÒÔ¿´µ½£¬ÌáʾµÄ²¢²»ÊDZ»Áã³ý
4¡¢ÈÃÏµÍ³ÖØÐ½ӹܴíÎóµÄ´¦Àí
on error goto 0 £¬Ê¹ÓÃÕâÌõÓï¾ä»áÈÃϵͳ²»ÔÙ³ÁĬ£¬Ò»µ©ÓдíÎó·¢Éú¾Í»áÌáʾ´íÎ󣬲¢½áÊø½Å±¾Ö´ÐС£
on error resume next
dim i
i = 1/0
Response.Write "1"
on error goto 0
i = 1/0
Response.Write "2"
ÔËÐнá¹û£º
1
Microsoft VBScript ÔËÐÐʱ´íÎó ´íÎó '800a000b'
±»Áã³ý
/try.asp£¬ÐÐ 7
¿ÉÒÔ¿´µ½£¬µÚÒ»¸ö1Êä³öÁË£¬µÚ¶þ¸öûÓС£
5¡¢on error resume next¶Ô×Ó³ÌÐòµÄÓ°Ïì
ÏÈ¿´Àý×Ó
sub test()
dim i
i = 1/0
Response.Write "ok"
end sub
sub test1()
test
Response.Write "ok"
end sub
on error resume next
test1
ÔËÐнá¹
Ïà¹ØÎĵµ£º
ÔÚASPÖÐʹÓà Request.ServerVariables("REMOTE_ADDR") À´È¡µÃ¿Í»§¶ËµÄIPµØÖ·£¬µ«Èç¹û¿Í»§¶ËÊÇʹÓôúÀí·þÎñÆ÷À´·ÃÎÊ£¬ÄÇÈ¡µ½µÄ¾ÍÊÇ´úÀí·þÎñÆ÷µÄIPµØÖ·£¬¶ø²»ÊÇÕæÕýµÄ¿Í»§¶ËIPµØÖ·¡£ÒªÏë͸¹ý´úÀí·þÎñÆ÷È¡µÃ¿Í»§¶ËµÄÕæÊµIPµØÖ·£¬¾ÍҪʹÓà Request.ServerVariables("HTTP_X_FORWARDED_FOR") À´¶ÁÈ¡¡£²»¹ýҪעÒâµÄÊ£¬²¢²»ÊÇÿ¸ö ......
Ò»¡¢ÐÞ¸ÄIISÉèÖã¬ÔÊÐíÖ±½Ó±à¼ÅäÖÃÊý¾Ý¿â
¶þ¡¢ÏÈÔÚ·þÎñÀï¹Ø±Õiis admin service·þÎñ
ÕÒµ½windows\system32\inetsrv\ϵÄmetabase.xml,
´ò¿ª£¬ÕÒµ½ASPMaxRequestEntityAllowed °ÑËûÐÞ¸ÄΪÐèÒªµÄÖµ£¬Ä¬ÈÏΪ204800£¬¼´200K °ÑËüÐÞ¸ÄΪÄãËùÐèµÄ´óС¼´¿É¡£È磺512000£¨500k£©
È»ºóÖØÆôiis admin service·þÎñ¡£ ......
ÎÒÏëÓÃC#ʵÏÖÏóASPÖеÄ
rs.addnew
rs( "a ") = "aaa "
rs( "b ") = 123
rs.update
ÕâÑù·½·¨Ìí¼ÓÊý¾Ý£¬ÎÊһϣ¬ÒªÔõô×ö°¡£¿
¾ßÌå·½·¨ÈçÏÂ
string dbPath = "../App_data/We ......
<%
Dim Fy_Url,Fy_a,Fy_x,Fy_Cs(),Fy_Cl,Fy_Ts,Fy_Zx
'---¶¨Ò岿·Ý Í·------
Fy_Cl = 1 '´¦Àí·½Ê½£º1=ÌáʾÐÅÏ¢,2=תÏòÒ³Ãæ,3=ÏÈÌáʾÔÙתÏò
Fy_Zx = "Error.Asp" '³ö´íʱתÏòµÄÒ³Ãæ
'---¶¨Ò岿·Ý β------
On Error Resume Next
Fy_Url=Request.ServerVariables("QUER ......
ÏÖÔڱȽÏÁ÷ÐеÄSQL×¢È빤¾ßµÄ¹¤×÷·½Ê½ÊÇͨ¹ýGETºÍPOSTÀ´Íê³É¾ßÌåµÄ×¢Èë¡£ÎÒÃÇ¿ÉÒÔ½«×¢ÈëʱËùÓõ½µÄÒ»ÇзûºÅ¹ýÂ˵ô¡£ÄÇôÎÒÃÇ¿ÉÒÔͨ¹ý¼òµ¥µÄÅжÏÓï¾äÀ´´ïµ½Ä¿µÄ¡£ÎÒÃÇÏÈÀ´¹ýÂËGET°É¡£
´úÂëÈçÏ£º
dim sql_injdata SQL_inj SQL_Get
SQL_injdata = "’|and|exec|insert|select|delete|update|count|*|%|chr|mid|mast ......