SQLÎÞÏÞ·Ö¼¶½á¹¹
×î½ü£¬ÒòΪÏîÄ¿µÄÔÒò£¬ÐèÒªÉè¼ÆÒ»¸öÊý¾Ý¿â£¬¸ÃÊý¾Ý¿âµÄ¹¦ÄÜÖ÷ÒªÊÇÃèÊöÎļþϵͳµÄ½á¹¹ºÍÎļþÐÅÏ¢£¬ÔÚÍøÉÏÕÒÁ˺ܶàµÄ×ÊÁÏ£¬µ«ÊÇÐí¶àÉè¼ÆÒªÃ´Õë¶Ô²éѯÁ¿±È½Ï¶àµÄÀ´×ö£¬ÒªÃ´Õë¶ÔÐ޸ġ¢²åÈëÁ¿±È½Ï¶àµÄÀ´×ö£¬¶ø¶ÔÓÚÎļþϵͳ¶øÑÔ£¬ËüµÄ²éѯ¡¢²åÈë¡¢Ð޸ͼÊÇÏ൱Ƶ·±µÄ£¬Òò´Ë£¬Êý¾Ý¿âµÄÉè¼Æ¼«ÆäÖØÒª,ÏÖ½«×Ô¼ºµÄÒ»µãÏ뷨˵˵£¬Ï£Íû´ó¼ÒÄܹ»¸øÒ»µãÒâ¼û°¡£¡£¡
Ò»¿ªÊ¼£¬ÎªÁ˾¡¿ìÀ³öÔÐÍϵͳ£¬ÎÒ²ÉÓÃÁËname£¨±¾½áµã£©£¬parent£¨¸¸½Úµã£©£¬ancestor£¨×æÏȽáµã£© À´ÃèÊöÆä½á¹¹£¬È»ºó²ÉÓõݹéË㷨ȥ¶ÔÊý¾Ý¿â½øÐвÙ×÷£¬ÕâÑù£¬¹¦ÄÜ»ù±¾¿ÉÒÔÍê³É£¬µ«ÊÇ£¬ÊµÔÚµ£ÐÄÔÚÎļþ¼ÐÉî¶È¹ý¸ßʱÊý¾Ý¿â³ÐÊܲ»ÁËÕâÑùµÄ¸ºµ££¬ÓÚÊÇ£¬ÔÚѰÕÒ½â¾ö°ì·¨¡£
µÚÒ»ÖÖ·½·¨£¬¸Ä½øSQLÓï¾äÂß¼£ºÕâÖÖ·½·¨¶ÔÓÚÏÖÓÐÊý¾Ý¿âÉè¼ÆºÍ³ÌÐòÉè¼Æ¶øÑÔ£¬Ó¦¸Ã˵ÓÅ»¯¹¤×÷Á¿ÊÇ×îСµÄ£¬µ«ÊÇ£¬±¾ÈË»¹Ã»ÓвâÊÔ¹ý²»ÖªÊÇ·ñ¿ÉÐУ¬ÏÈд³öÀ´£¬ÕûÀí˼·£º
ͨ¹ýϵͳ¹¦ÄܺÍÊý¾Ý¿â½á¹¹µÄ·ÖÎö£¬¹¦ÄܲÙ×÷ÎÞ·ÇÊǶÔÎļþ¸´ÖÆ¡¢Òƶ¯¡¢É¾³ý¡¢Ð½¨µÈ£¬¶øÕâЩ¹¦ÄܵÄÖ÷ÒªÎÊÌâÊǶÔÎļþ¼Ð½øÐÐÀàËÆ²Ù×÷ʱ£¬ÔõÑùͬʱÐÞ¸ÄÆä×ÓËï½áµãµÄÏà¹ØÐÅÏ¢£¬ÕâÒ²ÊÇÎҵݹéµÄÔÒò¡£ºó×Ðϸ¹Û²ìÊý¾Ý¿âµÄÊý¾Ý·¢ÏÖ²éѯ½áµãµÄ×ÓËï½áµãÖ»Òª¶ÔSQL½øÐиĽøËƺõ¾Í¿ÉÒÔ°ìµ½£º
$rs=mysql_query(select ancestor from info where name=$id);(²éѯҪ²Ù×÷½áµãµÄ׿ÏȽáµã)£»
$ancestor.=$rs[0]['ancestor'].":".$id;
$rs1=mysql_query(select name from info where ancestor like $ancestor%);
¶÷£¬ÕâÑùµÄ²Ù×÷ËÆºõ¿ÉÒÔÍê³É¶Ô×ÓËï½áµãµÄ»ñÈ¡£¬¶ø²»ÓñéÀú¡£¾ßÌåµÄЧ¹û£¬´ýÎÒ²âÊÔºóÔÙÌù°É¡£
µÚ¶þÖÖ·½·¨£¬ÊDZȽÏÕë¶ÔÓÚ²éѯ½Ï¶àÐ޸ĽÏÉÙµÄÊý¾Ý¿âÉè¼Æ£¬¸öÈ˾õµÃ²»Ì«ÊʺÏÏÖÓÐÕâ¸öÏîÄ¿£¬µ«ÊÇ˼·ºÍ·½·¨ÐԱȽϺã¬Ò²Ìù³öÀ´°É¡££¨×ªÔØ£©
²úÆ··ÖÀ࣬¶à¼¶µÄÊ÷×´½á¹¹µÄÂÛ̳£¬ÓʼþÁбíµÈÐí¶àµØ·½ÎÒÃǶ¼»áÓöµ½ÕâÑùµÄÎÊÌ⣺ÈçºÎ´æ´¢¶à¼¶½á¹¹µÄÊý¾Ý£¿ÔÚPHPµÄÓ¦ÓÃÖУ¬Ìṩºǫ́Êý¾Ý´æ´¢µÄͨ³£ÊǹØÏµÐÍÊý¾Ý¿â£¬ËüÄܹ»±£´æ´óÁ¿µÄÊý¾Ý£¬Ìṩ¸ßЧµÄÊý¾Ý¼ìË÷ºÍ¸üзþÎñ¡£È»¶ø¹ØÏµÐÍÊý¾ÝµÄ»ù±¾ÐÎʽÊÇ×ݺύ´íµÄ±í£¬ÊÇÒ»¸öÆ½ÃæµÄ½á¹¹£¬Èç¹ûÒª½«¶à¼¶Ê÷×´½á¹¹´æ´¢ÔÚ¹ØÏµÐÍÊý¾Ý¿âÀï¾ÍÐèÒª½øÐкÏÀíµÄ·Ò빤×÷¡£½ÓÏÂÀ´ÎһὫ×Ô¼ºµÄËù¼ûËùÎźÍһЩʵÓõľÑéºÍ´ó¼Ò̽ÌÖһϣº
²ã¼¶½á¹¹µÄÊý¾Ý±£´æÔÚÆ½ÃæµÄÊý¾Ý¿âÖлù±¾ÉÏÓÐÁ½ÖÖ³£ÓÃÉè¼Æ·½·¨£º
1¡
Ïà¹ØÎĵµ£º
--½áºÏsys.indexesºÍsys.index_columns,sys.objects,sys.columns²éѯË÷ÒýËùÊôµÄ±í»òÊÓͼµÄÐÅÏ¢
select
o.name as ±íÃû,
i.name as Ë÷ÒýÃû,
c.name as ÁÐÃû,
i.type_desc as ÀàÐÍÃèÊö,
is_primary_key as Ö÷¼üÔ¼Êø,
is_unique_constraint as Î¨Ò»Ô¼Êø,
is_disable ......
ÔÚÈëÃÅÆª£¬ÎÒÃÇѧ»áÁˣӣѣÌ×¢ÈëµÄÅжϷ½·¨£¬µ«ÕæÕýÒªÄõ½ÍøÕ¾µÄ±£ÃÜÄÚÈÝ£¬ÊÇÔ¶Ô¶²»¹»µÄ¡£½ÓÏÂÀ´£¬ÎÒÃǾͼÌÐøÑ§Ï°ÈçºÎ´ÓÊý¾Ý¿âÖлñÈ¡ÏëÒª»ñµÃµÄÄÚÈÝ£¬Ê×ÏÈ£¬ÎÒÃÇÏÈ¿´¿´£Ó£Ñ£Ì×¢ÈëµÄÒ»°ã²½Ö裺
µÚÒ»½Ú¡¢£Ó£Ñ£Ì×¢ÈëµÄÒ»°ã²½Öè
¡¡¡¡Ê×ÏÈ£¬Åжϻ·¾³£¬Ñ°ÕÒ×¢Èëµã£¬ÅжÏÊý¾Ý¿âÀàÐÍ£¬ÕâÔÚÈëÃÅÆªÒѾ½²¹ýÁË¡£
¡¡¡¡Æä´Î£¬¸ù¾Ý×¢Èë ......
Ò»£ºSQL Loader µÄÌØµã
oracle×Ô¼º´øÁ˺ܶàµÄ¹¤¾ß¿ÉÒÔÓÃÀ´½øÐÐÊý¾ÝµÄÇ¨ÒÆ¡¢±¸·ÝºÍ»Ö¸´µÈ¹¤×÷¡£µ«ÊÇÿ¸ö¹¤¾ß¶¼ÓÐ×Ô¼ºµÄÌØµã¡£
±ÈÈç˵expºÍimp¿ÉÒÔ¶ÔÊý¾Ý¿âÖеÄÊý¾Ý½øÐе¼³öºÍµ¼³öµÄ¹¤×÷£¬ÊÇÒ»ÖֺܺõÄÊý¾Ý¿â±¸·ÝºÍ»Ö¸´µÄ¹¤¾ß£¬Òò´ËÖ÷ÒªÓÃÔÚÊý¾Ý¿âµÄÈȱ¸·ÝºÍ»Ö¸´·½Ãæ¡£ÓÐ×ÅËٶȿ죬ʹÓüòµ¥£¬¿ì½ÝµÄÓŵ㣻ͬʱҲÓÐһЩȱµ ......
1¡¢¼ì²éÊÇ·ñÓзǷ¨×Ö·û
public static boolean sql_inj(String str)
{
String inj_str = "'|and|exec|insert|select|delete|update|
count|*|%|chr|mid|master|truncate|char|declare|;|or|-|+|,";
//ÕâÀïµÄ¶«Î÷»¹¿ÉÒÔ×Ô¼ºÌí¼Ó
String[] inj_stra=inj_str.split("\\|");
for ......
Ò»¡¢SQLƴд½¨Òé 1¡¢²éѯʱ²»·µ»Ø²»ÐèÒªµÄÐС¢ÁÐ ÒµÎñ´úÂëÒª¸ù¾Ýʵ¼ÊÇé¿ö¾¡Á¿¼õÉÙ¶Ô±íµÄ·ÃÎÊÐÐÊý£¬×îС»¯½á¹û¼¯£¬ÔÚ²éѯʱ£¬²»Òª¹ý¶àµØÊ¹ÓÃͨÅä·ûÈ磺select * from table1Óï¾ä£¬ÒªÓõ½¼¸ÁоÍÑ¡Ôñ¼¸ÁУ¬È磺select col1,col2 from table1;ÔÚ¿ÉÄܵÄÇé¿öϾ¡Á¿ÏÞÖÆ½á¹û¼¯ÐÐÊýÈ磺se ......