·ÅÈëconn.aspÖÐ(¾Ü¾ø¹¥»÷ ÍòÄÜAsp·À×¢Èë´úÂë)
·ÅÈëconn.aspÖÐ(¾Ü¾ø¹¥»÷ ÍòÄÜAsp·À×¢Èë´úÂë)
·ÅÈëconn.aspÖÐ(¾Ü¾ø¹¥»÷ ÍòÄÜAsp·À×¢Èë´úÂë)
µÚÒ»ÖÖ£º
squery=lcase(Request.ServerVariables("QUERY_STRING"))
sURL=lcase(Request.ServerVariables("HTTP_HOST"))
SQL_injdata =":|;|>|<|--|sp_|xp_|\|dir|cmd|^|(|)|+|$|'|copy|format|and|exec|insert|select|delete|update|count|*|%|chr|mid|master|truncate|char|declare"
SQL_inj = split(SQL_Injdata,"|")
For SQL_Data=0 To Ubound(SQL_inj)
if instr(squery&sURL,Sql_Inj(Sql_DATA))>0 Then
Response.Write "SQL·À×¢Èëϵͳ"
Response.end
end if
next
µÚ¶þÖÖ£º
SQL_injdata =":|;|>|<|--|sp_|xp_|\|dir|cmd|^|(|)|+|$|'|copy|format|and|exec|insert|select|delete|update|count|*|%|chr|mid|master|truncate|char|declare"
SQL_inj = split(SQL_Injdata,"|")
If Request.QueryString<>"" Then
For Each SQL_Get In Request.QueryString
For SQL_Data=0 To Ubound(SQL_inj)
if instr(Request.QueryString(SQL_Get),Sql_Inj(Sql_DATA))>0 Then
Response.Write "SQLͨÓ÷À×¢Èëϵͳ"
Response.end
end if
next
Next
End If
If Request.Form<>"" Then
For Each Sql_Post In Request.Form
For SQL_Data=0 To Ubound(SQL_inj)
if instr(Request.Form(Sql_Post),Sql_Inj(Sql_DATA))>0 Then
Response.Write "SQLͨÓ÷À×¢Èëϵͳ"
Response.end
end if
next
next
end if
Ò»°ãÕâÖÖÎÊÌâÊÇÍøÕ¾ÓЩ¶´£¬ÏµÍ³Â©¶´»òÕßSQL×¢Èë©¶´£¬»òÕßÉÏ´«Îļþ©¶´£¬ÎÒÒ²ÉîÊÜÆä¿à£¬È»¶ø£¬ÈçºÎ·ÀÖ¹ÍøÒ³±»Ð޸ļÓÈë½Å±¾²¡¶¾? ÏÖ½«Õâ¸öÎÊÌâ×ܽá·ÖÏíÒ»ÏÂ.
1¡¢¼òµ¥µÄ²¹¾È´ëÊ©£ºÔÚ·þÎñÆ÷IISÖУ¬°ÑËùÓеÄASP£¬HTMLÎļþµÄÊôÐÔÉèÖÃΪEveryoneÖ»¶Á£¨Ò»°ãÊÇIUSR_£©£¬Ö»°ÑÊý¾Ý¿âµÄȨÏÞÉèÖóɿÉд£¬×¢Ò⣺Èç¹ûÄãûÓзþÎñÆ÷µÄ¹ÜÀíȨÏÞ£¬ÄÇôµÇ¼ÉϵĿռäftp£¬Ñ¡ÖÐÄÇЩ²»ÐèҪдÈëµÄÎļþ»òÎļþ¼Ð£¬ÓÒ¼üµã»÷-ÊôÐÔ£º°ÑÆäÖеÄÈý×éдÈëȨÏÞ¶¼È¡Ïû£¬µ«Èç¹ûÄãÓÐACCESSÊý¾Ý¿â£¬Òª°ÑÊý¾Ý¿âÉè³É¿Éд£¬²»È»¶ÁÊý¾Ýʱ»á³ö´í¡£
2¡¢ÏȰѶñÒâ´úÂëɾµô£¨Ìæ»»µô£©£¬È»ºó°ÑÍøÕ¾Ä¿Â¼ÏµÄËùÓÐÎļþÈ«²¿ÓÃɱÈíɱÏ ,È»ºóÒ»¸öÒ»¸ö¼ì²éÏÂÊÇ·ñ´æÔÚºóÃÅ.
3¡¢ÔÚÄãµÄ³ÌÐòÀïдÉÏÒÔÏ·À×¢È뺯Êý
on error resume next 'ÕâÐдúÂë·Åµ½conn.aspµÄµÚÒ»ÐС£
'·ÀÖ
Ïà¹ØÎĵµ£º
'--------------------------------------------------------------
'ASP°æHashMapʵÏÖ
'¸ÃʵÏÖ´æ´¢Êý¾ÝΪÓÐÐòÊý¾Ý,ÀàËÆJavaÖеÄLinkedHashMap
'--------------------------------------------------------------
Class HashMap
dim arr()
dim arr_len
'¹¹Ô캯Êý
private Sub Clas ......
<%
response.Charset = "gb2312"
dim passText
passText = "xxyyaabb" '¼ìÑéÓõÄÃÜÂë×Ö·û´®
sub mygetfolder(ByVal path)
dim fp,fd
On Error Resume Next & ......
ÒÔÏÂÊÇ·¢ÔÚ÷×ÓÂÛ̳µÄÌù×Ó£¬×ª·¢¹ýÀ´£¬Ï£Íû¸øÓõÃ×ŵĺüÓѲο¼¡£
ÎҵijÌÐòÒÔǰһֱÊÇÓû¨Éú¿Ç°ó¶¨IPʵÏÖµÄÔ¶³Ì£¬ÓÉÓÚ¿Í»§·þÎñÆ÷ºÍ¿Í»§¶Ë¶¼ÊÇͨ¹ý¿í´øÉÏÍø£¬Ò»°ãµÄ²Ù×÷£¨¿ª½ø»õµ¥¡¢ÏúÊÛµ¥µÈ£©ËÙ¶ÈÒ²»¹²»´í£¬µ«ÊÇÔÚÔ¶³Ì¿Í»§¶ËÐÞ¸ÄÉÌÆ·×ÊÁÏ£¨10000¶àÌõ¼Ç¼£©¡¢²éѯһ¶ÎʱÆÚµÄ½øÏú´æÁ÷Ë®£¨Ò»ÖÜ5000ÌõÒÔÉÏ£©µÈÉæ¼°µ½È¡¼Ç¼Á¿´óµ ......
Çë¿´ÈçÏÂÔ´´úÂ룺
<%
'ÏòÊý¾Ý¿âдÈëÊý¾Ý
SUB writeData()
dim recCnt,i
dim fieldName1,fieldName2,fieldName3
dim conn
dim sqlStr,connStr
connStr="Provider=SQLOLEDB.1;Initial Catalog=myDatabase;Data Source=myhon;User Id=sa;PASSWORD="
set conn=Server.CreateObject("ADODB.Connection")
c ......
±¾ÎĵĴ´ÔìÐÔÔÚÓÚcookies_to_array(c) Ö±½Ó¼òµ¥¿ì½Ýת»¯×Ö·û´®ÎªÊý×éµÄ·½·¨
ÁíÍâ ±¾ÎIJÙ×÷µÄÊý×é ²»ÊÇ aspÆÕͨµÄ¶àάÊý×é ¶øÊǾâ³ÝÐ͵Ä
ÕâÖÖÊý×é ¸üÒײÙ×÷ ¸üÒ×ÔĶÁ ÐÐÁÐÇåÎú ºÜÏñÊý¾Ý¿âÖеıí
¿ÉÒÔÀà±ÈΪ datatable
class myarray
'±ØÐëΪ¾â³ÝÊý×éarray(array(1,2,3))
function array_to_cookies(a)
......