SQLÎÞÏÞ·Ö¼¶½á¹¹
×î½ü£¬ÒòΪÏîÄ¿µÄÔÒò£¬ÐèÒªÉè¼ÆÒ»¸öÊý¾Ý¿â£¬¸ÃÊý¾Ý¿âµÄ¹¦ÄÜÖ÷ÒªÊÇÃèÊöÎļþϵͳµÄ½á¹¹ºÍÎļþÐÅÏ¢£¬ÔÚÍøÉÏÕÒÁ˺ܶàµÄ×ÊÁÏ£¬µ«ÊÇÐí¶àÉè¼ÆÒªÃ´Õë¶Ô²éѯÁ¿±È½Ï¶àµÄÀ´×ö£¬ÒªÃ´Õë¶ÔÐ޸ġ¢²åÈëÁ¿±È½Ï¶àµÄÀ´×ö£¬¶ø¶ÔÓÚÎļþϵͳ¶øÑÔ£¬ËüµÄ²éѯ¡¢²åÈë¡¢Ð޸ͼÊÇÏ൱Ƶ·±µÄ£¬Òò´Ë£¬Êý¾Ý¿âµÄÉè¼Æ¼«ÆäÖØÒª,ÏÖ½«×Ô¼ºµÄÒ»µãÏ뷨˵˵£¬Ï£Íû´ó¼ÒÄܹ»¸øÒ»µãÒâ¼û°¡£¡£¡
Ò»¿ªÊ¼£¬ÎªÁ˾¡¿ìÀ³öÔÐÍϵͳ£¬ÎÒ²ÉÓÃÁËname£¨±¾½áµã£©£¬parent£¨¸¸½Úµã£©£¬ancestor£¨×æÏȽáµã£© À´ÃèÊöÆä½á¹¹£¬È»ºó²ÉÓõݹéË㷨ȥ¶ÔÊý¾Ý¿â½øÐвÙ×÷£¬ÕâÑù£¬¹¦ÄÜ»ù±¾¿ÉÒÔÍê³É£¬µ«ÊÇ£¬ÊµÔÚµ£ÐÄÔÚÎļþ¼ÐÉî¶È¹ý¸ßʱÊý¾Ý¿â³ÐÊܲ»ÁËÕâÑùµÄ¸ºµ££¬ÓÚÊÇ£¬ÔÚѰÕÒ½â¾ö°ì·¨¡£
µÚÒ»ÖÖ·½·¨£¬¸Ä½øSQLÓï¾äÂß¼£ºÕâÖÖ·½·¨¶ÔÓÚÏÖÓÐÊý¾Ý¿âÉè¼ÆºÍ³ÌÐòÉè¼Æ¶øÑÔ£¬Ó¦¸Ã˵ÓÅ»¯¹¤×÷Á¿ÊÇ×îСµÄ£¬µ«ÊÇ£¬±¾ÈË»¹Ã»ÓвâÊÔ¹ý²»ÖªÊÇ·ñ¿ÉÐУ¬ÏÈд³öÀ´£¬ÕûÀí˼·£º
ͨ¹ýϵͳ¹¦ÄܺÍÊý¾Ý¿â½á¹¹µÄ·ÖÎö£¬¹¦ÄܲÙ×÷ÎÞ·ÇÊǶÔÎļþ¸´ÖÆ¡¢Òƶ¯¡¢É¾³ý¡¢Ð½¨µÈ£¬¶øÕâЩ¹¦ÄܵÄÖ÷ÒªÎÊÌâÊǶÔÎļþ¼Ð½øÐÐÀàËÆ²Ù×÷ʱ£¬ÔõÑùͬʱÐÞ¸ÄÆä×ÓËï½áµãµÄÏà¹ØÐÅÏ¢£¬ÕâÒ²ÊÇÎҵݹéµÄÔÒò¡£ºó×Ðϸ¹Û²ìÊý¾Ý¿âµÄÊý¾Ý·¢ÏÖ²éѯ½áµãµÄ×ÓËï½áµãÖ»Òª¶ÔSQL½øÐиĽøËƺõ¾Í¿ÉÒÔ°ìµ½£º
$rs=mysql_query(select ancestor from info where name=$id);(²éѯҪ²Ù×÷½áµãµÄ׿ÏȽáµã)£»
$ancestor.=$rs[0]['ancestor'].":".$id;
$rs1=mysql_query(select name from info where ancestor like $ancestor%);
¶÷£¬ÕâÑùµÄ²Ù×÷ËÆºõ¿ÉÒÔÍê³É¶Ô×ÓËï½áµãµÄ»ñÈ¡£¬¶ø²»ÓñéÀú¡£¾ßÌåµÄЧ¹û£¬´ýÎÒ²âÊÔºóÔÙÌù°É¡£
µÚ¶þÖÖ·½·¨£¬ÊDZȽÏÕë¶ÔÓÚ²éѯ½Ï¶àÐ޸ĽÏÉÙµÄÊý¾Ý¿âÉè¼Æ£¬¸öÈ˾õµÃ²»Ì«ÊʺÏÏÖÓÐÕâ¸öÏîÄ¿£¬µ«ÊÇ˼·ºÍ·½·¨ÐԱȽϺã¬Ò²Ìù³öÀ´°É¡££¨×ªÔØ£©
²úÆ··ÖÀ࣬¶à¼¶µÄÊ÷×´½á¹¹µÄÂÛ̳£¬ÓʼþÁбíµÈÐí¶àµØ·½ÎÒÃǶ¼»áÓöµ½ÕâÑùµÄÎÊÌ⣺ÈçºÎ´æ´¢¶à¼¶½á¹¹µÄÊý¾Ý£¿ÔÚPHPµÄÓ¦ÓÃÖУ¬Ìṩºǫ́Êý¾Ý´æ´¢µÄͨ³£ÊǹØÏµÐÍÊý¾Ý¿â£¬ËüÄܹ»±£´æ´óÁ¿µÄÊý¾Ý£¬Ìṩ¸ßЧµÄÊý¾Ý¼ìË÷ºÍ¸üзþÎñ¡£È»¶ø¹ØÏµÐÍÊý¾ÝµÄ»ù±¾ÐÎʽÊÇ×ݺύ´íµÄ±í£¬ÊÇÒ»¸öÆ½ÃæµÄ½á¹¹£¬Èç¹ûÒª½«¶à¼¶Ê÷×´½á¹¹´æ´¢ÔÚ¹ØÏµÐÍÊý¾Ý¿âÀï¾ÍÐèÒª½øÐкÏÀíµÄ·Ò빤×÷¡£½ÓÏÂÀ´ÎһὫ×Ô¼ºµÄËù¼ûËùÎźÍһЩʵÓõľÑéºÍ´ó¼Ò̽ÌÖһϣº
²ã¼¶½á¹¹µÄÊý¾Ý±£´æÔÚÆ½ÃæµÄÊý¾Ý¿âÖлù±¾ÉÏÓÐÁ½ÖÖ³£ÓÃÉè¼Æ·½·¨£º
1¡
Ïà¹ØÎĵµ£º
Èë Êƪ
Èç¹ûÄãÒÔǰûÊÔ¹ýSQL×¢ÈëµÄ»°£¬ÄÇôµÚÒ»²½ÏȰÑIE²Ëµ¥=>¹¤¾ß=>InternetÑ¡Ïî=>¸ß¼¶=>ÏÔʾÓѺà HTTP ´íÎóÐÅÏ¢Ç°ÃæµÄ¹´È¥µô¡£·ñÔò£¬²»ÂÛ·þÎñÆ÷·µ»ØÊ²Ã´´íÎó£¬IE¶¼Ö»ÏÔʾΪHTTP 500·þÎñÆ÷´íÎ󣬲»ÄÜ»ñµÃ¸ü¶àµÄÌáʾÐÅÏ¢¡£
µÚÒ»½Ú¡¢SQL×¢ÈëÔÀí
ÒÔÏÂÎÒÃÇ´ÓÒ»¸öÍøÕ¾www.19cn.com¿ªÊ¼£¨×¢£º±¾ÎÄ·¢±íǰÒÑÕ÷µ ......
1.Stop ËùÓзþÎñ
2.Óà Windows Install Clean Up ¹¤¾ßÐ¶ÔØSQL 2005×é¼þ
3.ÓÃSrvInstw.exeɾ³ýËùÓÐSQL·þÎñ
4.Çå³ý×¢²á±í
a. ½«HKEY_CURRENT_USER---Software----MicrosoftϵÄMicrosoft SQL ServerÎļþ¼ÐÈ«²¿É¾³ý
b. ½«HKEY_LOCAL_mACHINE---SOFTWARE---MicrosoftÏ ......
Æô¶¯SQL Server (SQLEXPRESS)·þÎñʱÌáʾ´íÎó£¬Ê¼þ²é¿´Æ÷ÏÔʾÒÔÏÂÐÅÏ¢£¨ID 9003£©£º
´«µÝ¸øÊý¾Ý¿â 'master' ÖеÄÈÕ־ɨÃè²Ù×÷µÄÈÕ־ɨÃèºÅ (276:232:1) ÎÞЧ¡£´Ë´íÎó¿ÉÄÜָʾÊý¾ÝË𻵣¬»òÕßÈÕÖ¾Îļþ(.ldf)ÓëÊý¾ÝÎļþ(.mdf)²»Æ¥Åä¡£Èç¹û´Ë´íÎóÊÇÔÚ¸´ÖÆÆÚ¼ä³öÏֵģ¬ÇëÖØÐ´´½¨·¢²¼¡£·ñÔò£¬Èç¹û¸ÃÎÊÌâµ¼ÖÂÆô¶¯ÆÚ¼ä³ö´í£¬Çë´Ó± ......
1¡¢¼ì²éÊÇ·ñÓзǷ¨×Ö·û
public static boolean sql_inj(String str)
{
String inj_str = "'|and|exec|insert|select|delete|update|
count|*|%|chr|mid|master|truncate|char|declare|;|or|-|+|,";
//ÕâÀïµÄ¶«Î÷»¹¿ÉÒÔ×Ô¼ºÌí¼Ó
String[] inj_stra=inj_str.split("\\|");
for ......
[code]declare @startdt datetime
declare @enddt datetime
select @startdt='2009-12-03',@enddt='2009-12-05'
select * from tb
where ¿ªÊ¼ÈÕÆÚ between @startdt and @enddt
or ½áÊøÈÕÆÚ between @startdt and @enddt
or @startdt between ¿ªÊ¼ÈÕÆÚ and ½áÊøÈÕÆÚ
or @enddt between ¿ªÊ¼ÈÕÆÚ and ......