ASP.NET SQL ×¢ÈëÃâ·Ñ½â¾ö·½°¸
UrlScanµÄ3.1ÊÇÒ»¸ö°²È«µÄ¹¤¾ß£¬ÏÞÖÆÁËIISµÄHTTPÇëÇ󽫴¦ÀíÀàÐÍ¡£ ͨ¹ý×èÖ¹ÌØ¶¨µÄHTTPÇëÇó£¬ÔÚURLScan 3.1°²È«¹¤¾ßÓÐÖúÓÚ·ÀÖ¹¶Ô·þÎñÆ÷Ó¦ÓóÌÐò¿ÉÄÜÓꦵÄÇëÇó¡£ UrlScanµÄ3.1ÊÇURLScan 2.5µÄ¸üа汾¡£Ö§³ÖIIS 5.1ÖУ¬IIS 6.0ºÍIIS 7.0ÔÚWindows VistaºÍWindows Server 2008¡£ÏÂÔØµØÖ·http://download.csdn.net/source/2057125
×èÖ¹¶ÔWebÓ¦ÓóÌÐò¿ÉÄÜÓꦵÄÇëÇó
UrlScan3.1¸ù¾Ý¹ÜÀíÔ±ÉèÖõĹæÔò¹ýÂËËùÓд«Èëµ½·þÎñÆ÷µÄÇëÇó¡£Ö»ÒªÇëÇóͨ¹ý¹ýÂË£¬²ÅÄܵõ½·þÎñÆ÷µÄ´¦Àí¡£
¼õÇáSQL×¢Èë¹¥»÷
ͨ¹ý UrlScan3.1µÄ¿ÉÅäÖÿÉÒÔ¹ýÂËHTTP²éѯ×Ö·û´®ÖµºÍÆäËûµÄHTTP±êÍ·£¬ÒÔ¼õÇáSQL×¢Èë¹¥»÷£¬´Ó¶ø¹®¹ÌÓ¦ÓóÌÐòµÄ°²È«¡£
·ÖÎöÈÕÖ¾Îļþ
UrlScan3.1ÌṩÁËW3C¸ñʽµÄÈÕÖ¾Îļþ·ÖÎöÎļþ£¬×ñÑ΢ÈíÈÕÖ¾·ÖÎöÆ÷2.2·ÖÎö½â¾ö·½°¸¡£
ÌØÕ÷
еÄURLScan 3.1°æ±¾¿ÉÒÔ°²×°ÔÚIIS 5.1£¬IIS 6.0ºÍIIS 7.0 ÉÏ
´´½¨¶ÀÌØµÄ“¾Ü¾ø”¹æÔòÓÃÓÚ¼ì²â²éѯ×Ö·û´®£¬ËùÓбêÌ⣬»òÌØ¶¨Í·¡£
ÔÚÒ»¸öÈ«¾ÖµÄDenyQueryStringÅäÖýÚÖУ¬Äú¿ÉÒÔ×Ô¶¨ÒåÇëÇó¹æÔò
ÔÚÒ»¸öÈ«¾ÖµÄAlwaysAllowedUrlsÅäÖýڲ¿·ÖÔÊÐíÄúÖ¸¶¨°²È«µÄÍøÖ·£¬´Ó¶øÍ¨¹ýURLµÄ¼ì²é¡£
ÔÚÒ»¸öÈ«¾ÖµÄAlwaysAllowedQueryStringsÅäÖýÚÖУ¬¿ÉÒÔÖ¸¶¨²éѯ×Ö·û´®µÄ°²È«£¬½«Í¨¹ýËùÓеIJéѯ×Ö·û´®¼ì²é¡£
תÒåÐòÁУ¨È磥0D£¥£©£¬¿ÉÓÃÓÚ·ñÈϹæÔò£¬ËùÒÔ¿ÉÒÔ·ñ¶¨µÄCRLFºÍÉæ¼°·Ç´òÓ¡×Ö·ûµÄÆäËûÐòÁС£
UrlScanµÄ¶à¸öʵÀý¿ÉÒÔΪվµã°²×°¹ýÂËÆ÷£¬Æä×Ô¼ºµÄÅäÖú͹æÔò£¨Urlscan.iniµÄ£©Ã¿¸ö¡£
¸ü¸Ä֪ͨ»á´«²¥µ½IIS¹¤×÷½ø³Ì¡£
ÔöÇ¿µÄW3C¸ñʽµÄÅäÖôíÎó¸ñʽ¼Ç¼ÔÚ±¸×¢Ê¹Í·ÖС£
Ïà¹ØÎĵµ£º
SQL³£Ó÷ÖÒ³µÄ°ì·¨:
±íÖÐÖ÷¼ü±ØÐëΪ±êʶÁУ¬[ID] int IDENTITY (1,1)
1.·ÖÒ³·½°¸Ò»£º(ÀûÓÃNot InºÍSELECT TOP·ÖÒ³)
Óï¾äÐÎʽ£º
SELECT TOP Ò³¼Ç¼ÊýÁ¿ *
from ±íÃû
WHERE (ID NOT IN
(SELECT TOP (ÿҳÐÐÊý*(Ò³Êý-1)) ID
from ±íÃû
ORDER BY ID))
ORDER BY ID
//×Ô ......
1¡¢ÔÚÊý¾Ý¿â½¨±íµÄʱºò×Ö¶ÎÖ±½ÓÉèÖÃΪDATETIMEÀàÐÍ£»
2¡¢Ö´ÐвåÈëµÄʱºòʹÓÃÈçÏÂÓï¾ä£º
PreparedStatement pstmt = conn.prepareStatement("insert into guestbook(gst_user,gst_title,gst_content,gst_ip,gst_time) values(?,?,?,?,getdate())");
3¡¢Òª°ÑÈÕÆÚ´ÓÊý¾Ý¿âÖÐÈ¡³ö£¬Ö´ÐÐÈçÏÂÓï¾ä£º
......
MS SQL Server2000 Êý¾ÝÔ´ÅäÖÃ
£¨×¢£ºsqljdbc.jarÏÂÔØ²»µ½µÄ»°£¬ÕÒÎÒË÷È¡pengqinghui110@126.com)
1¡¢ÔÚÏîÄ¿µÄWebRootϵÄMETA-INFÖÐн¨context.xmlÎļþ¡£ÄÚÈÝÈçÏ£º
<?xml version="1.0" encoding="UTF-8"?>
<Context>
<Resource name="jdbc/sqlserver"
&nbs ......
1 ÓÃUNIONÌæ»»OR (ÊÊÓÃÓÚË÷ÒýÁÐ)
ͨ³£Çé¿öÏÂ, ÓÃUNIONÌæ»»WHERE×Ó¾äÖеÄOR½«»áÆðµ½½ÏºÃµÄЧ¹û. ¶ÔË÷ÒýÁÐʹÓÃOR½«Ôì³ÉÈ«±íɨÃè. ×¢Òâ, ÒÔÉϹæÔòÖ»Õë¶Ô¶à¸öË÷ÒýÁÐÓÐЧ.
Èç¹ûÓÐcolumnûÓб»Ë÷Òý, ²éѯЧÂÊ¿ÉÄÜ»áÒòΪÄãûÓÐÑ¡ÔñOR¶ø½µµÍ. ÔÚÏÂÃæµÄÀý×ÓÖÐ, LOC_ID ºÍREGIONÉ϶¼½¨ÓÐË÷Òý.
¸ßЧ: SELECT LOC_ID , LOC_DESC , ......
Êý¾Ý¿âµÄÐÔÄܲâÊÔ¿ÉÒÔ°ïÖúÄãÌáǰ֪µÀÄãµÄϵͳµÄ¸ºÔØÄÜÁ¦£¬¿ÉÒÔ°ïÖúÄã¸Ä½øÏµÍ³µÄʵʩ»òÉè¼Æ£¬¿ÉÒÔ°ïÖúÄãÈ·¶¨Ò»Ð©Éè¼ÆºÍ±à³ÌÔÔò. µ«ÊÇ£¬ÕâÀïÃæÒ²ÓÐÏÝÚå. Èç¹û²»Ð¡ÐÄ£¬Äã»á×Ô¼º°Ñ×Ô¼ºÏݽøÈ¥£¬È´×îÖÕ²»Ã÷°×ÊÇʲôÔÒò. ÕâÀÎÒÄÃһλÏÈÉúΪÀý£¬À´¿´¿´ËûÔõô×Ô¼º°Ñ×Ô¼º¸ãºýÍ¿µÄ.
×î½ü, ÏëÆðÔÚ´æ´¢¹ý³ÌÖо¿¾¹ÊÇʹÓÃÁÙʱ±í»¹ÊÇÊ ......