[MySQLÓÅ»¯] ÈçºÎ²éÕÒSQLЧÂʵØÏµÄÔÒò
[MySQLÓÅ»¯] -- ÈçºÎ²éÕÒSQLЧÂʵØÏµÄÔÒò
ʱ¼ä:2010-2-28À´Ô´:HaCMS¿ªÔ´ÉçÇø ×÷Õß:chusong
²éѯµ½Ð§ÂÊµÍµÄ SQL Óï¾ä ºó£¬¿ÉÒÔͨ¹ý EXPLAIN »òÕß DESC ÃüÁî»ñÈ¡ MySQL ÈçºÎÖ´ÐÐ SELECT Óï¾äµÄÐÅÏ¢£¬°üÀ¨ÔÚ SELECT Óï¾äÖ´Ðйý³ÌÖбíÈçºÎÁ¬½ÓºÍÁ¬½ÓµÄ˳Ðò£¬±ÈÈçÎÒÃÇÏë¼ÆËã 2006 ÄêËùÓй«Ë¾µÄÏúÊ۶ÐèÒª¹ØÁª sales ±íºÍ company ±í£¬²¢ÇÒ¶Ô profit ×Ö¶Î×öÇóºÍ£¨ s ...
²éѯµ½Ð§ÂÊµÍµÄ SQL Óï¾ä ºó£¬¿ÉÒÔͨ¹ý EXPLAIN »òÕß DESC ÃüÁî»ñÈ¡ MySQL ÈçºÎÖ´ÐÐ SELECT Óï¾äµÄÐÅÏ¢£¬°üÀ¨ÔÚ SELECT Óï¾äÖ´Ðйý³ÌÖбíÈçºÎÁ¬½ÓºÍÁ¬½ÓµÄ˳Ðò£¬±ÈÈçÎÒÃÇÏë¼ÆËã 2006 ÄêËùÓй«Ë¾µÄÏúÊ۶ÐèÒª¹ØÁª sales ±íºÍ company ±í£¬²¢ÇÒ¶Ô profit ×Ö¶Î×öÇóºÍ£¨ sum £©²Ù×÷£¬ÏàÓ¦ SQL µÄÖ´Ðмƻ®ÈçÏ£º
mysql> explain select sum(profit) from sales a,company b where a.company_id = b.id and a.year = 2006\G;
*************************** 1. row ***************************
id: 1
select_type: SIMPLE
table: a
type: ALL
possible_keys: NULL
key: NULL
key_len: NULL
ref: NULL
rows: 12
Extra: Using where
*************************** 2. row ***************************
id: 1
select_type: SIMPLE
table: b
type: ALL
possible_keys: NULL
key: NULL
key_len: NULL
ref: NULL
rows: 12
Extra: Using where
2 rows in set (0.00 sec)
ÿ¸öÁеĽâÊÍÈçÏ£º
Extra £ºÖ´ÐÐÇé¿öµÄ˵Ã÷ºÍÃèÊö¡£
ÔÚÉÏÃæµÄÀý×ÓÖУ¬ÒѾ¿ÉÒÔÈ·ÈÏÊÇ ¶Ô a ±íµÄÈ«±íɨÃèµ¼ÖÂЧÂʵIJ»ÀíÏ룬ÄÇô ¶Ô a ±íµÄ year ×ֶδ´½¨Ë÷Òý£¬¾ßÌåÈçÏ£º
mysql> create index idx_sales_year on sales(year);
Query OK, 12 rows affected (0.01 sec)
Records: 12 Duplicates: 0 Warnings: 0
´´½¨Ë÷Òýºó£¬ÕâÌõÓï¾äµÄÖ´Ðмƻ®ÈçÏ£º
mysql> explain select sum(profit) from sales a,company b where a.company_id = b.id and a.year = 2006\G;
*************************** 1. row ***************************
id: 1
select_type: SIMPLE
table: a
type: ref
possible_keys: idx_sales_year
key: idx_sales_
Ïà¹ØÎĵµ£º
<!--MySql Çý¶¯³ÌÐò eg. mysql-connector-java-5.0.4-bin.jar-->
<property name="dialect">org.hibernate.dialect.MySQLDialect</property>
<property name="connection.driver_class">com.mysql.jdbc.Driver</property>
<!-- JDBC URL -->
......
¸ù¾ÝÄãµÄʹÓÃÄ¿µÄÎÒ¾õµÃÕâ¸öº¯ÊýÓÐÁ½·½ÃæµÄÓÃ;£º
·ÀÖ¹SQL Injection¹¥»÷£¬Ò²¾ÍÊÇÄã±ØÐëÑéÖ¤Óû§µÄÊäÈë
²Ù×÷Êý¾ÝµÄʱºò±ÜÃâ²»±ØÒªµÄ×Ö·ûµ¼Ö´íÎó
mysql_real_escape_string() º¯ÊýתÒå SQL Óï¾äÖÐʹÓõÄ×Ö·û´®ÖеÄÌØÊâ×Ö·û¡£
ÏÂÁÐ×Ö·ûÊÜÓ°Ï죺
\x00
\n
\r
\
'
"
\x1a
Èç¹û³É¹¦£¬Ôò¸Ãº¯Êý·µ»Ø±»×ªÒåµÄ×Ö·û´ ......
1. ¿ÉÒÔÓýű¾±¸·Ý
¡¡¡¡manger studio--ÓÒ¼üÄãµÄÊý¾Ý¿â--ÈÎÎñ--Éú³É½Å±¾
¡¡¡¡Ôڽű¾Éú³ÉÏòµ¼µÄ"Ñ¡Ôñ¶ÔÏóÀàÐÍ"²½ÖèÖÐ, ½«"´æ´¢¹ý³Ì"Ñ¡ÉÏ, ÔÚ½ÓÏÂÀ´µÄ"Ñ¡Ôñ´æ´¢¹ý³Ì"µÄ²½ÖèÖÐ, Ñ¡ÔñËùÓеĴ洢¹ý³Ì(»òÕßÄãÒª¸´ÖƵĴ洢¹ý³Ì)
¡¡¡¡Íê³Éºó, ËùÓд洢¹ý³ÌµÄ½Å±¾»áÉú³ÉÔÚÒ»¸öеIJéѯ´°¿ÚÖÐ, ¹ØµôÉú³É½Å±¾Ïòµ¼, ÔÚÉú³ÉµÄ´æ´¢¹ý³Ì ......
Ê×ÏÈ˵Ã÷Ò»µã£ºVC³ÌÐòÖÐÓÃADOÁ¬½ÓSQL Server 2005 ºÍÁ¬½Ó SQL Server 2000µÄÓï¾äºÍÁ¬½Ó×Ö·û´®ÊÇÍêȫһÑùµÄ£¬ÏÂÃæµÄ´úÂëÊÊÓÃÓÚÁ½¸öÊý¾Ý¿âµÄÁ¬½Ó¡£
ÁíÒ»µã˵Ã÷£ºÈç¹ûÄãÒÔǰ°²×°¹ýSQL Server 2000£¬ºóÔÚûÓÐÐ¶ÔØµÄÇé¿öÏÂÓÖ°²×°ÁË2005£¬ÄÇôÄã֮ǰÔÚ2000ÖÐÉèÖõÄÓû§ÃûºÍÃÜÂëÔÚ2005Öлᱣ³Ö£¬¼´Ê¹Äã°²×°2005ʱδÉèÖÃÈκÎÓû§Ãû ......