jspÈçºÎ·À·¶sql×¢Èë¹¥»÷
ÉÏÖܸø±ðÈË×öÁ˸öÍøÕ¾£¬ÎÞÒâ¼ä·¢ÏÖ×Ô¼ºµÄ×÷Æ·Óкܶà©¶´£¬Ôڶ̶̵Ä20Ãë¾Í±»×Ô¼ºÓÃsql×¢Èë·¨¸ø¸ÉÁË¡£ËùÒÔ²éÁËÒ»µã¹ØÓÚsql×¢ÈëµÄ×ÊÁÏ£¬²¢ÇÒÓеã¸ÐÎò£¬Ï£ÍûÄÜÓëÐÂÊÖÃÇ·ÖÏíһϡ£¸ßÊÖÃǼûЦÁË£¡
sql×¢Èë¹¥»÷µÄ×ÜÌå˼·£º
·¢ÏÖsql×¢ÈëλÖã»
ÅжϷþÎñÆ÷ÀàÐͺͺǫ́Êý¾Ý¿âÀàÐÍ£»
È·¶¨¿ÉÖ´ÐÐÇé¿ö
¶ÔÓÚÓÐЩ¹¥»÷Õß¶øÑÔ£¬Ò»°ã»á²ÉÈ¡sql×¢Èë·¨¡£ÏÂÃæÎÒҲ̸һÏÂ×Ô¼º¹ØÓÚsql×¢Èë·¨µÄ¸ÐÎò¡£
×¢Èë·¨£º
´ÓÀíÂÛÉÏ˵£¬ÈÏÖ¤ÍøÒ³ÖлáÓÐÐÍÈ磺
select from admin where username=' xxx' and password=' yyy' µÄÓï¾ä£¬ÈôÔÚÕýʽÔËÐд˾ä֮ǰ£¬Èç¹ûûÓнøÐбØÒªµÄ×Ö·û¹ýÂË£¬ÔòºÜÈÝÒ×ʵʩsql×¢Èë¡£
ÈçÔÚÓû§ÃûÎı¾¿òÄÚÊäÈ룺abc’ or 1=1-- ÔÚÃÜÂë¿òÄÚÊäÈ룺123 ÔòsqlÓï¾ä±ä³É£º
select from admin where username=' abc’ or 1=1 and password=' 123’ ²»¹ÜÓû§ÊäÈëÈκÎÓû§ÃûÓëÃÜÂ룬´ËÓï¾äÓÀÔ¶¶¼ÄÜÕýÈ·Ö´ÐУ¬Óû§ÇáÒׯ¹ýϵͳ£¬»ñÈ¡ºÏ·¨Éí·Ý¡£
²Â½â·¨£º
»ù±¾Ë¼Â·ÊÇ£º²Â½âËùÓÐÊý¾Ý¿âÃû³Æ£¬²Â³ö¿âÖеÄÿÕűíÃû£¬·ÖÎö¿ÉÄÜÊÇ´æ·ÅÓû§ÃûÓëÃÜÂëµÄ±íÃû£¬²Â³ö±íÖеÄÿ¸ö×Ö¶ÎÃû£¬²Â³ö±íÖеÄÿÌõ¼Ç¼ÄÚÈÝ¡£
»¹ÓÐÒ»ÖÖ·½Ê½¿ÉÒÔ»ñµÃÄãµÄÊý¾Ý¿âÃûºÍÿÕűíµÄÃû¡£
¾ÍÊÇͨ¹ýÔÚÐÎÈ磺http://www. .cn/news?id=10' µÄ·½Ê½À´Í¨¹ý±¨´í»ñµÃÄãµÄÊý¾Ý¿âÃûºÍ±íÃû£¡
¶ÔÓÚjsp¶øÑÔÎÒÃÇÒ»°ã²ÉȡһϲßÂÔÀ´Ó¦¶Ô£º
1¡¢preparedstatement
Èç¹ûÄãÒѾÊÇÉÔÓÐˮƽ¿ª·¢Õß Äã¾ÍÓ¦¸ÃʼÖÕÒÔpreparedstatement´úÌæstatement.
ÒÔÏÂÊǼ¸µãÔÒò
1¡¢´úÂëµÄ¿É¶ÁÐԺͿÉά»¤ÐÔ.
2¡¢preparedstatement¾¡×î´ó¿ÉÄÜÌá¸ßÐÔÄÜ.
3¡¢×îÖØÒªµÄÒ»µãÊǼ«´óµØÌá¸ßÁ˰²È«ÐÔ.
µ½Ä¿Ç°ÎªÖ¹£¬ÓÐһЩÈË£¨°üÀ¨±¾ÈË£©Á¬»ù±¾µÄ¶ñÒåsqlÓï·¨¶¼²»ÖªµÀ.
string sql = " select from tb_name where name= ' " +varname+" ' and passwd=' " +varpasswd+" ' "
Èç¹ûÎÒÃǰÑ[' or ' 1' = ' 1]×÷Ϊname´«È
Ïà¹ØÎĵµ£º
<%@ page language="java" import="kg.TestBean2;" %>
<%@ page contentType="text/html;charset=gb2312" %>
<html>
<head>
<title>HelloBean</title>
</head>
<body>
<%--
<%
kg.TestBean2 testbean=(kg.TestBean2)session.setAttribute("testbean");
if ......
javascriptдjavaû¹ØÏµ,ÖÁÓÚΪʲôÃû×ÖÕâôÏà½ü,¿ÉÄÜÊÇÒòΪjavaºÜÓÐÃûÆøËùÒÔ°ÑÃû×ÖÈ¡³É²î²»¶àµÄ,Ò»ÖÖÐÂÓïÑÔ¸Õ³öÀ´µÄʱºòÒªµãÃûÆøÀ´³öÃû°É~~
javascriptËãÊÇÒ»ÖÖhtml½Å±¾ÄÜÖ±½ÓÖ´ÐеÄÓïÑÔ°É,jspÒª±àÒë²ÅÄÜÖ´ÐÐ,Äã×Ô¼ºÐ´¸öJSP²»¿ªtomcatÖ®ÀàµÄÊÇÎÞ·¨Ö´ÐеÄ.JSPºÍJAVAµÄÇø±ð,JSPËãÊÇJAVAÒ»ÖÖ¼¼Êõ°É,ÓÃÔÚÍøÒ³±à³ÌÉÏ,ÒòΪJAVA² ......
Ò»¡¢
ÎÊ£ºorg.postgresql.util.PSQLException: FATAL: no pg_hba.conf entry for host "192.168.254.103", user "postgres",database "postgres", SSL off
´ð£ºPostgreSQÊý¾Ý¿âΪÁ˰²È«£¬Ëü²»»á¼àÌý³ý±¾µØÒÔÍâµÄËùÓÐÁ¬½ÓÇëÇ󣬵±Óû§Í¨¹ýJDBC·ÃÎÊÊÇ£¬¾Í»á±¨Ò»Ð©ÒÔÉϵÄÒì³£¡£Òª½â¾öÕâ¸öÎÊÌâ ......
ÒÔǰÓÐÌáµ½¹ýÂÒÂëÎÊÌ⣬×î½üÔÚʹÓÃwindow.openʱÓÖ³öÏÖ´ËÀàÎÊÌ⣬ÏÖ½â¾öÈçÏ£º
1£ºÊ¹ÓÃencodeURIComponentº¯Êý¶Ô²ÎÊý½øÐд¦Àí£¬ÀýÈ磺window.open("html.jsp?name=" + encodeUrlComponent(value)));
2£ºÐÞ¸Ätomcat·þÎñÆ÷µÄserver.xmlÎļþÌí¼Ó£ºuseBodyEncodingForURI="true"»òÕß
URIEncoding=" ......
struts-config:
<action path="/articleManage" name="articleManageForm" scope="request" type="auction.action.ArticleManageAction" validate="false">
<forward name="atriclesList" path="/WEB-INF/publish/articleManage/atriclesList.jsp"/>
<forward ......