Ò׽ؽØÍ¼Èí¼þ¡¢µ¥Îļþ¡¢Ãâ°²×°¡¢´¿ÂÌÉ«¡¢½ö160KB

·Àsql×¢ÈëÀà

 using System;
using System.Text.RegularExpressions;
using System.Web;
namespace FSqlKeyWord
{
/**//**//**//// <summary>
/// SqlKey µÄժҪ˵Ã÷¡£
/// </summary>
public class SqlKey
{
private HttpRequest request;
//private const string StrKeyWord = @"select|insert|delete|from|count(|drop table|update|truncate|asc(|mid(|char(|xp_cmdshell|exec master|netlocalgroup administrators|:|net user|""|or|and";

//string StrKeyWord1 = @"(like|and|exec|insert|select|delete|update|chr|mid|master|or|truncate|char|declare|join)".Replace("|",")|(");
private const string StrKeyWord = @"( like | and | exec |insert|select|delete|update|chr|mid|master| or |truncate|char|declare|join|exec master|xp_cmdshell|net user|systypes|sysobjects)";
//private const string StrRegex = @"([-|;|,|/|(|)|[|]|}|{|%|@|*|!|'])";
private const string StrRegex = @"--|'|@|!";
public SqlKey(System.Web.HttpRequest _request)
{
//
// TODO: ÔÚ´Ë´¦Ìí¼Ó¹¹Ô캯ÊýÂß¼­
//
this.request = _request;
}
public SqlKey()
{
//
// TODO: ÔÚ´Ë´¦Ìí¼Ó¹¹Ô캯ÊýÂß¼­
//
//this.request = _request;
}
/**//**//**//// <summary>
/// Ö»¶ÁÊôÐÔ SQL¹Ø¼ü×Ö
/// </summary>
public static string KeyWord
{
get
{
return StrKeyWord;
}
}
/**//**//**//// <summary>
/// Ö»¶ÁÊôÐÔ¹ýÂËÌØÊâ×Ö·û
/// </summary>
public static string RegexString
{
get
{
return StrRegex;
}
}
/**//**//**//// <summary>
/// ¼ì²éURL²ÎÊýÖÐÊÇ·ñ´øÓÐSQL×¢Èë¿ÉÄܹؼü×Ö¡£
/// </summary>
/// <param na


Ïà¹ØÎĵµ£º

±àдSQL²éѯµÄ¹Ø¼ü—SQLÓï¾äµÄÖ´ÐÐ˳Ðò


¡¾ÎÄÕ±êÌâ¡¿±àд
SQL
²éѯµÄ¹Ø¼ü—
SQL
Óï¾äµÄÖ´ÐÐ˳Ðò
¡¾ÎÄÕÂ×÷Õß¡¿Ôø½¡Éú
¡¾×÷ÕßÓÊÏä¡¿
zengjiansheng1@126.com
¡¾×÷Õß
QQ
¡¿
190678908
¡¾×÷Õß
MSN
¡¿
zengjiansheng1@hotmail.com
¡¾×÷Õß²©¿Í¡¿
blog.csdn.net/newjueqi
 
*********************************************************** ......

pl/sql´Ê»ãµ¥Ôª

 
2±êʶ·û¹æÔò
µ±Ê¹Óñêʶ·û¶¨Òå±äÁ¿ ³£Á¿Ê±£¬Ã¿ÐÐÖ»ÄܵÚÒ»Ò»¸ö±êʶ·û
µ±Ê¹Óñêʶ·û¶¨Òå±äÁ¿£¬³£Á¿Ê±£¬±êʶ·ûÃû³Æ±ØÐëÒªÒÔ°¢À­²®×Ö·û£¨A~Z,a~z£©¿ªÊ¼£¬²¢ÇÒ×î´ó³¤¶ÈΪ30¸ö×Ö·û¡£Èç¹ûÒÔÆäËû×Ö·û¿ªÊ¼£¬ÄÇô±ØÐëҪʹÓÃË«ÒýºÅÒýס¡£
µ±Ê¹Óñêʶ·û¶¨Òå±äÁ¿³£Á¿Ê±£¬±êʶ·ûÃû³ÆÖ»ÄÜʹÓ÷ûºÅA~Z,a~z£¬0~9£¬_,$ºÍ#¡£Èç¹ûÊ¹Ó ......

SQL ServerÃæÊÔÌâÕûºÏ

 3¡£±íÄÚÈÝÈçÏÂ
-----------------------------
ID            LogTime
1            2008/10/10 10:00:00
1            2008/10/1 ......

¾­µäsqlÓï¾ä

Ò»¡¢Ñ­»·
create table tb(
   col1 varchar(1),
   col2 varchar(2)

insert tb(col1,col2)values('0','0')
 go 10000000
¶þ¡¢Êý¾ÝºÏ²¢
if object_id('[order]') is not null drop table [order]
go
create table [order]([orderid] int,[ordertype] varchar(1))
insert [ord ......
© 2009 ej38.com All Rights Reserved. ¹ØÓÚE½¡ÍøÁªÏµÎÒÃÇ | Õ¾µãµØÍ¼ | ¸ÓICP±¸09004571ºÅ