asp²É¼¯³ÌÐò
<%
Function getHTTPPage(url)
On Error Resume Next
dim http
set http=Server.createobject("Microsoft.XMLHTTP")
Http.open "GET",url,false
Http.send()
if Http.readystate<>4 then
exit function
end if
getHTTPPage=bytesToBSTR(Http.responseBody,"GB2312")
set http=nothing
If Err.number<>0 then
Response.Write "<p align=’center’><font color=’red’><b>·þÎñÆ÷»ñÈ¡ÎļþÄÚÈݳö´í</b></font></p>"
Err.Clear
End If
End Function
Function BytesToBstr(body,Cset)
dim objstream
set objstream = Server.CreateObject("adodb.stream")
objstream.Type = 1
objstream.Mode =3
objstream.Open
objstream.Write body
objstream.Position = 0
objstream.Type = 2
objstream.Charset = Cset
BytesToBstr = objstream.ReadText
objstream.Close
set objstream = nothing
End Function
'½ØÈ¡×Ö·û´®,1.°üÀ¨ÆðʼºÍÖÕÖ¹×Ö·û£¬2.²»°üÀ¨
Function strCut(strContent,StartStr,EndStr,CutType)
Dim strHtml,S1,S2
strHtml = strContent
On Error Resume Next
Select Case CutType
Case 1
S1 = InStr(strHtml,StartStr)
S2 = InStr(S1,strHtml,EndStr)+Len(EndStr)
Case 2
S1 = InStr(strHtml,StartStr)+Len(StartStr)
S2 = InStr(S1,strHtml,EndStr)
End Select
If Err Then
strCute = "<p align=’center’>ûÓÐÕÒµ½ÐèÒªµÄÄÚÈÝ¡£</p>"
Err.Clear
Exit Function
Else
strCut = Mid(strHtml,S1,S2-S1)
End If
End Function
'¹¦ÄÜ£ºasp²É¼¯´úÂë
'×÷Õߣºwangsdong
'±¸×¢£ºÖ§³ÖÔ´´³ÌÐò£¬Çë±£Áô´ËÐÅÏ¢£¬Ð»Ð»
url="http://sports.sina.com.cn/k/2008-09-15/04593948756.shtml"
str=getHTTPPage(url)
title=strcut(str,"<h1 id=""artibodyTitle"" style=""color:#03005C;"">","</h1>",2)
content=strcut(str,"<!-- ÕýÎÄÄÚÈÝ begin -->","<!-- ÕýÎÄÄÚÈÝ end -->",2)
response.write "ÐÂÎűêÌâ<br><b>"&title&"</b><br><br><br>ÐÂÎÅÄÚÈÝ:<br>"&content
%>
Ïà¹ØÎĵµ£º
·ÅÈëconn.aspÖÐ(¾Ü¾ø¹¥»÷ ÍòÄÜAsp·À×¢Èë´úÂë)
·ÅÈëconn.aspÖÐ(¾Ü¾ø¹¥»÷ ÍòÄÜAsp·À×¢Èë´úÂë)
µÚÒ»ÖÖ£º
squery=lcase(Request.ServerVariables("QUERY_STRING"))
sURL=lcase(Request.ServerVariables("HTTP_HOST"))
SQL_injdata =":|;|>|<|--|sp_|xp_|\|dir|cmd|^|(|)|+|$|'|copy|format|and|exec| ......
4.1 ³£ÓõÄHTML¿Ø¼þ
4.1.1 ±íµ¥¿Ø¼þ
ÓÃÓÚ½ÓÊÕ¿Í»§¶ËµÄÊäÈ룬²¢½«ÊäÈëµÄ½á¹ûÌá½»¸ø·þÎñÆ÷´¦Àí
1.HtmlForm¿Ø¼þ
ËùÓеÄWeb Form¿Ø¼þ±ØÐë°üº¬ÔÚÒ»¶ÔHtmlForm¿Ø¼þ±êÇ©ÖÐ
<Form
Id = "¿Ø¼þ±êʶ"
Runat = "Server"
Method = "Post | Get"
Action = "ÒªÖ´ÐÐ ......
ǰ¼¸ÌìÔÚ×Ô¼ºµÄ±Ê¼Ç±¾Éϰ²×°ÁËOFFICE2007¡£½ñÌì×öÁËÒ»¸ö°Ù¶ÈÓÑÇéÁ´½Ó¼ì²éµÄ¹¤¾ß£¬ ÔÚÁ¬½ÓACCESS2007Êý¾Ý¿âµÄʱºò£¬Ê¹ÓõÄÇý¶¯´úÂëΪ£º"provider=microsoft.jet.oledb.4.0;data source="&server.mappath("queryrecord.mdb") ¡£È··¢ÏÖÌáʾ£º
Microsoft JET Database Engine ´íÎó ''80004005''
²»¿Éʶ±ðµÄÊý¾Ý¿â¸ñʽ
µ« ......
VBSÀ³¬³öIntegerÀàÐ͵Äȡֵ·¶Î§£¬¸ÃÀàÐ͵Äȡֵ·¶Î§Îª-32,768 µ½ 32,767 Ö®¼äµÄÕûÊý¡£
³ö´íµÄ¸ùÔ´£º
ÔÚASPÀÓÐʱºòΪÁË·ÂÖ¹×¢È룬ËùÒÔÔÚ½ÓÊÕ²ÎÊýµÄʱºòÖ±½ÓʹÓÃCintº¯Êý°Ñ½Ó¹ýÀ´µÄ²ÎÊýת»»ÎªInteger£¨Êý×Ö£©ÀàÐÍ£¬Õâ¾Í´æÔÚÒ»¸öDZÔÚÎÊÌ⣬µ±Ò³Ãæ½ÓÊÕµÄij¸ö²ÎÊý£¨Request("xxx")£©³¬¹ýȡֵ·¶Î§Ê±£¨¿É¼òµ¥Àí½âΪ5λÊý×Ö£ ......