Ò׽ؽØÍ¼Èí¼þ¡¢µ¥Îļþ¡¢Ãâ°²×°¡¢´¿ÂÌÉ«¡¢½ö160KB

´î½¨¼òÒ×µÄasp·þÎñÆ÷ ÓÃÓÚÊÖ»ú°²×°²âÊÔ³ÌÐò

À¶ÑÀ»µµôÁË£¬ÕâÑùÒ»À´ ÊÖ»ú°²×°³ÌÐò±äµÃºÜ²»·½±ãÁË¡£Ò»¿ªÊ¼ÊÇÏȰÑÒª°²×°µÄ³ÌÐòÒÔ¸½¼þµÄÐÎʽ·¢µ½ÓÊÏä ÔÙÔÚÊÖ»úÉÏÅäÖÃÓÊÏä ÈúóÏÂÔØ¸½¼þ°²×°£¬ÕâÑùËäÈ»½â¾öÁËÎÊÌâ  µ«ÊÇ»¹ÊÇÓкܶ಻·½±ãµÄµØ·½¡£ ÓÚÊÇ  ×Ô¼ºÏë´î½¨Ò»¸ö·þÎñÆ÷ Ö±½ÓʵÏÖÔÚÏß°²×°¡£Ç°ÌáÊÇÊÖ»úÖ§³Öwifi£¬¾ÍÊÇ˵ÐèÒªÊÖ»ú·ÃÎÊÄÚÍøµØÖ·£¬·ñÔòµÃ»° ¾Í±È½ÏÂé·³ÁË ÄãµÄÖ÷»ú±ØÐëÒªÔÚÍâÍøÉÏÄܱ»·ÃÎʵ½¡£
ÉÏÍøËÑË÷×ÊÁÏ£¬×¼±¸Ê¹ÓÃiis£¬µ«ÊÇÎÒµÄϵͳûÓа²×°iis ÔÙÕÒÒ²±È½ÏÂé·³ÁË  ¶øÇÒ¾õµÃÅäÖÃÒ²±È½ÏÂé·³ ¡£ËùÒÔÔÚÍøÉÏÕÒÁËÒ»¸ö¼òÒ×µÄasp·þÎñÆ÷Èí¼þ AWS£¨asp web server£©¡£ÊÇÒ»¸öºÜɵ¹ÏµÄÈí¼þ£¬ÊʺÏÎÒÃÇÕâÖÖ·ÇרҵÈËÊ¿µÄһЩ¼òµ¥µÄÐèÇó¡£
ÔÚpcµÄÈÎÒâλÖà ½¨Á¢Ò»¸öÎļþ¼Ð ÓÃ×÷ÄãµÄasp¸ùĿ¼¡£È»ºó°ÑÕâ¸öaws·Åµ½ÀïÃæ ÂÌÉ«µÄ ²»Óð²×°¡£È»ºóÔÚ¸ùĿ¼Ï´´½¨Ò»¸öaspÒ³ÃæÎļþ  ÎÒµÄÊÇindex.asp,Ã²ËÆºÃ¶àĬÈϵͼÊÇÕâ¸öÃû×Ö¡£
È»ºó±à¼­¸ÃÒ³Ãæ  ÎÒÒ²²»¶®ÖÆ×÷ÍøÒ³ ¾ÍÔÚÍøÒ³ÀïдÁËÒ»¾ä
<a href="/YourSoftWare.sisx">DownLoadSis</a>±íʾһ¸öÁ¬½Ó ¡£YourSoftWare.sisx£¨Í¬Àíjar ʲôµÄ¶¼ÀàËÆ°É£© ÊÇÄã×¼±¸°²×°µÄÈí¼þ ·ÅÔÚºÍindex.aspͬ¼¶µÄĿ¼Ï¾ÍOKÁË¡£´ò¿ªaws£¬Ëû»á×Ô¶¯´ò¿ªindex.aspÒ³Ãæ£¬Ò³ÃæÉÏÏÔʾDownLoadSisÕâ¸öÁ´½Ó¡£µã»÷Õâ¸öÁ´½Ó  ¾ÍÌáʾÏÂÔØsisxÁË¡£Õâ˵Ã÷·þÎñÆ÷´î½¨³É¹¦ÁË£¡
½ÓÏÂÀ´£¬Äã¿ÉÒÔʹÓÃÊÖ»ú°²×°ÁË£¬ÔÚÊÖ»úµÄä¯ÀÀÆ÷µØÖ·À¸Àï¼üÈëpcÉϵØÖ·À¸ÀïµÄÄÚÈݼ´ÄãpcµÄipºÍ¶Ë¿ÚºÅ¡£È»ºóÊÖ»úä¯ÀÀÆ÷Àï¾Í»áÏÔʾindex.aspÒ³ÃæÁË£¬µã½âÒ³ÃæÉϵÄÁ´½Ó ¾ÍÄܰ²×°ÁË¡£


Ïà¹ØÎĵµ£º

ͨÓÃasp·À×¢Èë³ÌÐò

‘·À×¢Èë°ÑËü¼Óµ½connÀïÕâÑù¾ÍokÁË
dim sql_injdata
SQL_injdata = "’|and|exec|insert|select|delete|update|count|*|%|chr|mid|master|truncate|char|declare"
SQL_inj = split(SQL_Injdata,"|")
If Request.QueryString<>"" Then
For Each SQL_Get In Request.QueryString
For SQL_Data=0 To Ubo ......

aspÁ´½ÓsqlÊý¾Ý¿â ´úÂë

 dim conn,connstr
Set conn = Server.CreateObject("ADODB.Connection")'´´½¨Ò»¸öÊý¾Ý¿âÁ´½Ó¶ÔÏóconn£¬·½±ãºóÃæµ÷ÓÃ
connstr="Provider=SQLOLEDB;Data Source=(local);Initial Catalog=111;User ID=sa;Password=1234;" '´´½¨Ò»¸öÊý¾Ý¿âµÄrecordset¶ÔÏ󣬷½±ãÒÔºóµ÷ÓÃ
conn.Open connstr'´ò¿ªÊý¾Ý¿â ......

ASP»ù´¡½Ì³Ì:ADO´æÈ¡Êý¾Ý¿âʱÈçºÎ·ÖÒ³ÏÔʾ

ʲôÊÇ ADO ´æÈ¡Êý¾Ý¿âʱµÄ·ÖÒ³ÏÔʾ£¿Èç¹ûÄãʹÓùýĿǰÖÚ¶àÍøÕ¾Éϵĵç×Ó¹«¸æ°å³ÌÐòµÄ»°£¬ÄÇÄãÓ¦¸Ã»áÖªµÀµç×Ó¹«¸æ°å³ÌÐòΪÁËÌá¸ßÒ³ÃæµÄ¶ÁÈ¡ËÙ¶È£¬Ò»°ã²»»á½«ËùÓеÄÌû×ÓÈ«²¿ÔÚÒ»Ò³ÖÐÂÞÁгöÀ´£¬¶øÊǽ«Æä·Ö³É¶àÒ³ÏÔʾ£¬Ã¿Ò³ÏÔʾһ¶¨ÊýÄ¿µÄÌû×ÓÊý£¬Æ©Èç 20 Ìõ¡£Õâ¾ÍÊÇÊý¾Ý¿â²éѯµÄ·ÖÒ³ÏÔʾ£¬Èç¹ûÄ㻹²»Ã÷°×£¬È¥¿´¿´ yahoo µÈËÑË÷ ......

ASP×Ö·û´®º¯Êý´óÈ«

º¯Êý Óï·¨ ¹¦ÄÜ
Len Len(string|varname) ·µ»Ø×Ö·û´®ÄÚ×Ö·ûµÄÊýÄ¿£¬»òÊÇ´æ´¢Ò»±äÁ¿ËùÐèµÄ×Ö½ÚÊý¡£
Trim Trim(string) ½«×Ö·û´®Ç°ºóµÄ¿Õ¸ñÈ¥µô
Ltrim Ltrim(string) ½«×Ö·û´®Ç°ÃæµÄ¿Õ¸ñÈ¥µô
Rtrim Rtrim(string) ½«×Ö·û´®ºóÃæµÄ¿Õ¸ñÈ¥µô
Mid Mid(string,start,length) ´Óstring×Ö·û´®µÄstart×Ö·û¿ªÊ¼È¡µÃlength³¤¶ ......

·ÅÈëconn.aspÖÐ(¾Ü¾ø¹¥»÷ ÍòÄÜAsp·À×¢Èë´úÂë)


·ÅÈëconn.aspÖÐ(¾Ü¾ø¹¥»÷ ÍòÄÜAsp·À×¢Èë´úÂë)
·ÅÈëconn.aspÖÐ(¾Ü¾ø¹¥»÷ ÍòÄÜAsp·À×¢Èë´úÂë)
µÚÒ»ÖÖ£º
squery=lcase(Request.ServerVariables("QUERY_STRING"))
sURL=lcase(Request.ServerVariables("HTTP_HOST"))
 
SQL_injdata =":|;|>|<|--|sp_|xp_|\|dir|cmd|^|(|)|+|$|'|copy|format|and|exec| ......
© 2009 ej38.com All Rights Reserved. ¹ØÓÚE½¡ÍøÁªÏµÎÒÃÇ | Õ¾µãµØÍ¼ | ¸ÓICP±¸09004571ºÅ