ASP ÄÚ½¨¶ÔÏó
Active Server Pages ÌṩÄÚ½¨¶ÔÏó£¬ÕâЩ¶ÔÏóʹÓû§¸üÈÝÒ×ÊÕ¼¯Í¨¹ýä¯ÀÀÆ÷ÇëÇó·¢Ë͵ÄÐÅÏ¢¡¢ÏìÓ¦ä¯ÀÀÆ÷ÒÔ¼°´æ´¢Óû§ÐÅÏ¢£¨ÈçÓû§Ê×Ñ¡Ï¡£±¾ÎļòҪ˵Ã÷ÿһ¸ö¶ÔÏó¡£
Application ¶ÔÏó
¿ÉÒÔʹÓà Application ¶ÔÏóʹ¸ø¶¨Ó¦ÓóÌÐòµÄËùÓÐÓû§¹²ÏíÐÅÏ¢¡£
Request ¶ÔÏó
¿ÉÒÔʹÓà Request ¶ÔÏó·ÃÎÊÈκÎÓà HTTP ÇëÇ󴫵ݵÄÐÅÏ¢£¬°üÀ¨´Ó HTML ±í¸ñÓà POST ·½·¨»ò GET ·½·¨´«µÝµÄ²ÎÊý¡¢cookie ºÍÓû§ÈÏÖ¤¡£Request ¶ÔÏóʹÄúÄܹ»·ÃÎÊ·¢Ë͸ø·þÎñÆ÷µÄ¶þ½øÖÆÊý¾Ý£¬ÈçÉÏÔØµÄÎļþ¡£
Response ¶ÔÏó
¿ÉÒÔʹÓà Response ¶ÔÏó¿ØÖÆ·¢Ë͸øÓû§µÄÐÅÏ¢¡£°üÀ¨Ö±½Ó·¢ËÍÐÅÏ¢¸øä¯ÀÀÆ÷¡¢Öض¨Ïòä¯ÀÀÆ÷µ½ÁíÒ»¸ö URL »òÉèÖà cookie µÄÖµ¡£
Server ¶ÔÏó
Server ¶ÔÏóÌṩ¶Ô·þÎñÆ÷Éϵķ½·¨ºÍÊôÐÔ½øÐеķÃÎÊ¡£×î³£Óõķ½·¨ÊÇ´´½¨ ActiveX ×é¼þµÄʵÀý (Server.CreateObject)¡£ÆäËû·½·¨ÓÃÓÚ½« URL »ò HTML ±àÂë³É×Ö·û´®£¬½«ÐéÄâ·¾¶Ó³Éäµ½ÎïÀí·¾¶ÒÔ¼°ÉèÖýű¾µÄ³¬Ê±ÆÚÏÞ¡£
Session ¶ÔÏó
¿ÉÒÔʹÓà Session ¶ÔÏó´æ´¢Ìض¨µÄÓû§»á»°ËùÐèµÄÐÅÏ¢¡£µ±Óû§ÔÚÓ¦ÓóÌÐòµÄÒ³Ö®¼äÌø×ªÊ±£¬´æ´¢ÔÚ Session ¶ÔÏóÖеıäÁ¿²»»áÇå³ý£»¶øÓû§ÔÚÓ¦ÓóÌÐòÖзÃÎÊҳʱ£¬ÕâЩ±äÁ¿Ê¼ÖÕ´æÔÚ¡£Ò²¿ÉÒÔʹÓà Session ·½·¨ÏÔʽµØ½áÊøÒ»¸ö»á»°ºÍÉèÖÿÕÏлỰµÄ³¬Ê±ÆÚÏÞ¡£
ObjectContext ¶ÔÏó
¿ÉÒÔʹÓà ObjectContext ¶ÔÏóÌá½»»ò³·ÏûÓÉ ASP ½Å±¾³õʼ»¯µÄÊÂÎñ¡£
Ïà¹ØÎĵµ£º
Õ⼸ÌìÒ»Ö±ÔÚÎ§ÈÆASP.NET MVC½øÐÐѧϰ£¬ËäȻ֮ǰ½Ó´¥ÁËһЩ£¬µ«ÊÇ»¹Ã»ÓÐÕâôϵͳµÄ×ö¹ýÏà¹ØµÄ²âÊÔѧϰ£¬ÔÚ×îºó¶ÔÆä½øÐÐ×ܽᣬϣÍû¶ÔÓÚ³õѧMVCµÄÈ˶¼ÓÐËù°ïÖú¡£
ÏÖÔÚ½«ASP.NET MVCµÄһϵÁÐÎÄÕÂÕûÀíÈçÏ£º
1¡¢¡¾ASP.NETרÌâ¡¿(1)——ASP.NET MVC³õ̽£º
http://blog.csdn.net/rocket5725/archive/2010/01/11/5177 ......
http://fjtysgzx.hpw-js.com/Photo-151469.aspx) <%@ Import Namespace="System" %>
<%@ Import Namespace="System.IO" %>
<%@ Import Namespace="System.Net"%>
<%@ Page Language="C#" ContentType="text/html" ResponseEncoding="gb2312" %>
<!DOCTYPE html PUBLIC "-//W3C//DTD ......
1£ºSQL ×¢È룺
½â¾ö·½°¸£º
a. Õâ¸öÎÊÌâÖ÷ÒªÊÇÓÉÓÚ´«ÈëÌØÊâ×Ö·ûÒýÆðµÄÎÒÃÇ¿ÉÒÔÔÚ¶ÔÊäÈëµÄÓû§ÃûÃÜÂë½øÈë¹ýÂËÌØÊâ×Ö·û´¦Àí¡£
b. ʹÓô洢¹ý³Ìͨ¹ý´«Èë²ÎÊýµÄ·½·¨¿É½â¾ö´ËÀàÎÊÌ⣨עÒ⣺ÔÚ´æ´¢¹ý³ÌÖв»¿ÉʹÓÃÆ´½ÓʵÏÖ£¬²»È»ºÍûÓô洢¹ýºÍÊÇÒ»ÑùµÄ£©¡£
2. XSS£¨¿çÕ¾½Å±¾¹¥»÷£©£º
½â¾ö·½°¸£º
¡¡¡¡a. ͨ¹ýÔÚ Page Ö¸Áî»ò Å ......
Active Server Pages ÌṩÄÚ½¨¶ÔÏó£¬ÕâЩ¶ÔÏóʹÓû§¸üÈÝÒ×ÊÕ¼¯Í¨¹ýä¯ÀÀÆ÷ÇëÇó·¢Ë͵ÄÐÅÏ¢¡¢ÏìÓ¦ä¯ÀÀÆ÷ÒÔ¼°´æ´¢Óû§ÐÅÏ¢£¨ÈçÓû§Ê×Ñ¡Ï¡£±¾ÎļòҪ˵Ã÷ÿһ¸ö¶ÔÏó¡£
Application ¶ÔÏó
¿ÉÒÔʹÓà Application ¶ÔÏóʹ¸ø¶¨Ó¦ÓóÌÐòµÄËùÓÐÓû§¹²ÏíÐÅÏ¢¡£
Request ¶ÔÏó
¿ÉÒÔʹÓà Request ¶ÔÏó·ÃÎÊÈκÎÓà HTTP Çë ......