ASP.NETÖÐÈçºÎ·À·¶SQL×¢Èëʽ¹¥»÷
1½«sqlÖÐʹÓõÄÒ»Ð©ÌØÊâ·ûºÅ£¬Èç' -- /* ; %µÈÓÃReplace()¹ýÂË£»
2ÏÞÖÆÎı¾¿òÊäÈë×Ö·ûµÄ³¤¶È£»
3¼ì²éÓû§ÊäÈëµÄºÏ·¨ÐÔ£»¿Í»§¶ËÓë·þÎñÆ÷¶Ë¶¼ÒªÖ´ÐУ¬¿ÉÒÔʹÓÃÕýÔò¡£
4ʹÓôø²ÎÊýµÄSQLÓï¾äÐÎʽ¡£
ASP.NETÖÐÈçºÎ·À·¶SQL×¢Èëʽ¹¥»÷
Ò»¡¢Ê²Ã´ÊÇSQL×¢Èëʽ¹¥»÷£¿
¡¡¡¡ËùνSQL×¢Èëʽ¹¥»÷£¬¾ÍÊǹ¥»÷Õß°ÑSQLÃüÁî²åÈëµ½Web±íµ¥µÄÊäÈëÓò»òÒ³ÃæÇëÇóµÄ²éѯ×Ö·û´®£¬ÆÛÆ·þÎñÆ÷Ö´ÐжñÒâµÄSQLÃüÁî¡£ÔÚijЩ±íµ¥ÖУ¬Óû§ÊäÈëµÄÄÚÈÝÖ±½ÓÓÃÀ´¹¹Ô죨»òÕßÓ°Ï죩¶¯Ì¬SQLÃüÁ»ò×÷Ϊ´æ´¢¹ý³ÌµÄÊäÈë²ÎÊý£¬ÕâÀà±íµ¥ÌرðÈÝÒ×Êܵ½SQL×¢Èëʽ¹¥»÷¡£³£¼ûµÄSQL×¢Èëʽ¹¥»÷¹ý³ÌÀàÈ磺
¡¡¡¡¢Å ij¸öASP.NET WebÓ¦ÓÃÓÐÒ»¸öµÇÂ¼Ò³Ãæ£¬Õâ¸öµÇÂ¼Ò³Ãæ¿ØÖÆ×ÅÓû§ÊÇ·ñÓÐȨ·ÃÎÊÓ¦Óã¬ËüÒªÇóÓû§ÊäÈëÒ»¸öÃû³ÆºÍÃÜÂë¡£
¡¡¡¡¢Æ µÇÂ¼Ò³ÃæÖÐÊäÈëµÄÄÚÈݽ«Ö±½ÓÓÃÀ´¹¹Ô춯̬µÄSQLÃüÁ»òÕßÖ±½ÓÓÃ×÷´æ´¢¹ý³ÌµÄ²ÎÊý¡£ÏÂÃæÊÇASP.NETÓ¦Óù¹Ôì²éѯµÄÒ»¸öÀý×Ó£º
System.Text.StringBuilder query = new System.Text.StringBuilder(
"SELECT * from Users WHERE login = '")
.Append(txtLogin.Text).Append("' AND password='")
.Append(txtPassword.Text).Append("'");
¡¡¡¡¢Ç ¹¥»÷ÕßÔÚÓû§Ãû×ÖºÍÃÜÂëÊäÈë¿òÖÐÊäÈë"'»ò'1'='1"Ö®ÀàµÄÄÚÈÝ¡£
¡¡¡¡¢È Óû§ÊäÈëµÄÄÚÈÝÌá½»¸ø·þÎñÆ÷Ö®ºó£¬·þÎñÆ÷ÔËÐÐÉÏÃæµÄASP.NET´úÂë¹¹Ôì³ö²éѯÓû§µÄSQLÃüÁµ«ÓÉÓÚ¹¥»÷ÕßÊäÈëµÄÄÚÈݷdz£ÌØÊ⣬ËùÒÔ×îºóµÃµ½µÄSQLÃüÁî±ä³É£ºSELECT * from Users WHERE login = '' or '1'='1' AND password = '' or '1'='1'¡£
¡¡¡¡¢É ·þÎñÆ÷Ö´Ðвéѯ»ò´æ´¢¹ý³Ì£¬½«Óû§ÊäÈëµÄÉí·ÝÐÅÏ¢ºÍ·þÎñÆ÷Öб£´æµÄÉí·ÝÐÅÏ¢½øÐжԱȡ£
¡¡¡¡¢Ê ÓÉÓÚSQLÃüÁîʵ¼ÊÉÏÒѱ»×¢Èëʽ¹¥»÷Ð޸ģ¬ÒѾ²»ÄÜÕæÕýÑéÖ¤Óû§Éí·Ý£¬ËùÒÔϵͳ»á´íÎóµØÊÚȨ¸ø¹¥»÷Õß¡£
¡¡¡¡Èç¹û¹¥»÷ÕßÖªµÀÓ¦ÓûὫ±íµ¥ÖÐÊäÈëµÄÄÚÈÝÖ±½ÓÓÃÓÚÑéÖ¤Éí·ÝµÄ²éѯ£¬Ëû¾Í»á³¢ÊÔÊäÈëÄ³Ð©ÌØÊâµÄSQL×Ö·û´®´Û¸Ä²éѯ¸Ä±äÆäÔÀ´µÄ¹¦ÄÜ£¬ÆÛÆÏµÍ³ÊÚÓè·ÃÎÊȨÏÞ¡£
¡¡¡¡ÏµÍ³»·¾³²»Í¬£¬¹¥»÷Õß¿ÉÄÜÔì³ÉµÄËðº¦Ò²²»Í¬£¬ÕâÖ÷ÒªÓÉÓ¦Ó÷ÃÎÊÊý¾Ý¿âµÄ°²È«È¨ÏÞ¾ö¶¨¡£Èç¹ûÓû§µÄÕÊ»§¾ßÓйÜÀíÔ±»òÆäËû±È½Ï¸ß¼¶µÄȨÏÞ£¬¹¥»÷Õ߾ͿÉÄܶÔÊý¾Ý¿âµÄ±íÖ´Ðи÷ÖÖËûÏëÒª×öµÄ²Ù×÷£¬°üÀ¨Ìí¼Ó¡¢É¾³ý»ò¸üÐÂÊý¾Ý£¬ÉõÖÁ¿ÉÄÜÖ±½Óɾ³ý±í¡£
¶þ¡¢ÈçºÎ·À·¶£¿
¡¡¡¡ºÃÔÚÒª·ÀÖ¹ASP.NETÓ¦Óñ»SQL×¢Èëʽ¹¥»÷´³Èë²¢²»ÊÇÒ»¼þÌØ±ðÀ§ÄѵÄÊÂÇ飬ֻҪÔÚÀûÓÃ±íµ¥ÊäÈëµÄÄÚÈݹ¹ÔìSQLÃüÁî֮ǰ£¬°ÑËùÓÐÊä
Ïà¹ØÎĵµ£º
¸üУºÐµĶ«Î÷´Ó×îеĸüн«ÊǺìÉ«µÄ¡£
This list will grow as I find new tools.Õâ·ÝÃûµ¥½«³É³¤ÎªÎÒÕÒµ½ÐµĹ¤¾ß¡£ So if you know of some not on this list do post them in the comments.ËùÒÔ£¬Èç¹ûÄãÖªµÀһЩ²»ÔÚ´ËÃûµ¥ÖеÄÒâ¼ûºó×öËûÃÇ¡£
SQL Server Management Studio Add-in's SQL Server¹ÜÀí¹¤×÷ÊÒÍâ½ÓµÄ
......
SELECT DISTINCT '['+user_name(b.uid)+'].['+b.name+']' AS ¶ÔÏóÃû,b.type AS ÀàÐÍ
from sysdepends a,sysobjects b
WHERE b.id=a.depid
AND a.id=OBJECT_ID('¹ý³ÌÃû');
EXEC SP_DEPENDS '¹ý³ÌÃû';
......
µÚÒ»Õ£ºÐÅÏ¢Ìåϵ½á¹¹ÔÔò
¸ù¾ÝÒÔÏÂ7¸öÏ໥ÒÀÀµµÄÊý¾Ý´æ´¢Ä¿±êÉè¼ÆºÍÆÀ¹ÀÈκÎÊý¾Ý´æ´¢£º
l ¼òµ¥ÐÔ£»
l ÓÐÓÃÐÔ
l Êý¾ÝÍêÕûÐÔ
l ÐÔÄÜ
l ¿ÉÓÃÐÔ
l ¿ÉÀ©Õ¹ÐÔ
l °²È«ÐÔ
¼Ü¹¹Éè¼ÆÔÔò
l ±ÜÃâ¹ýÓÚ¸´ÔÓ
l ¾«ÐÄÌôÑ¡¼ü
l Ê÷Á¢¿ÉÑ¡Êý¾Ý
l ÊµÏ ......
SQLÓï¾ä¼¯½õ
--Óï ¾ä ¹¦ ÄÜ
--Êý¾Ý²Ù×÷
SELECT --´ÓÊý¾Ý¿â±íÖмìË÷Êý¾ÝÐкÍÁÐ
INSERT& ......
¸ÕѧϰASP.NET AJAX¿ª·¢£¬½ñÌìÓöµ½Ò»¸öÆæ¹ÖµÄÎÊÌ⣬¿ÉÄÜÊÇ×Ô¼º²»ÊìµÄÔÒò£¡£¡
ÔÚvs2005Æô¶¯µÄʱºò£¬ÔÚasmxÎļþÖУ¬Ìí¼Ó¶Ïµã£¬Æô¶¯µ÷ÊÔÄÜÕý³£½øÈëµ½µ÷ÊÔÒ³Ãæ£¬È»ºóÐÞ¸ÄasmxÒ³ÃæÒÔºó£¬
ÖØÐÂÆô¶¯µ÷ÊÔ£¬¾Í²»ÄÜÕý³£½øÈëµ½asmxÎļþÖеĶϵ㣬¶øÇÒÎļþÐ޸ĵĵط½£¬¶ÔÓÚÒ³Ãæµ÷ÓÃÖ±½ÓÎÞЧ£¬ÏÔʾЧ¹ûʼÖÕÊÇÐÞ¸ÄǰµÄЧ¹û£¡£¡
......