T-SQL篇如何防止SQL注入的解决方法

2020-07-10 08:06:36易采站长站整理
 67:    conn.Open();
 68:    OleDbCommand cmd = conn.CreateCommand();
 69:  
 70:    cmd.CommandText = “insert into [Record] (sIP,sDate,sPath) values (‘” +
 71:        request.ServerVariables[“REMOTE_ADDR”].ToString() + “‘,'” +
 72:        DateTime.Now + “‘,'” + request.ServerVariables[“URL”].ToLower() + RelaceSingleQuotes(request.QueryString.ToString()) + “‘)”;
 73:    int code = cmd.ExecuteNonQuery();
 74:    if (code == 1)
 75:     System.Web.HttpContext.Current.Response.Write(“<br>****以上信息已记录至日志数据库****”);
 76:    else
 77:     System.Web.HttpContext.Current.Response.Write(“<br>日志数据库出错”);
 78:    conn.Close();
 79:  
 80:   }
 81:   private string RelaceSingleQuotes(string _url)
 82:   {
 83:    string URL = _url.Replace(“‘”, “单引号”);
 84:    return URL;
 85:   }
 86:   private void ShowErr()
 87:   {
 88:    //string msg = @”<font color=red>请不要尝试未授权之入侵检测!</font>” + @”<br><br>”;
 89:    //msg += @”操作IP:” + request.ServerVariables[“REMOTE_ADDR”] + @”<br>”;
 90:    //msg += @”操作时间:” + DateTime.Now + @”<br>”;
 91:    //msg += @”页面:” + request.ServerVariables[“URL”].ToLower() + request.QueryString.ToString() + @”<br>”;
 92:    //msg += @”<a href=’#’ onclick=’javascript:window.close()’>关闭</a>”;
 93:    //System.Web.HttpContext.Current.Response.Clear();
 94:    //System.Web.HttpContext.Current.Response.Write(msg);
 95:    System.Web.HttpContext.Current.Response.Write(“<script>alert(‘请不要尝试未授权之入侵检测!’);javascript:history.go(-1);</script>”);
 96:   }
 97:   ///<summary>
 98:   /// 特征字符
 99:   ///</summary>
 100:   public static string KeyWord
 101:   {
 102:    get
 103:    {
 104:     return StrKeyWord;
 105:    }
 106:   }
 107:   ///<summary>
 108:   /// 特征符号
 109:   ///</summary>
 110:   public static string RegexString
 111:   {
 112:    get
 113:    {
 114:     return StrRegex;
 115:    }
 116:   }
 117:  
 118:   ///<summary>
 119:   ///检查字符串中是否包含Sql注入关键字
 120:   /// <param name=”_key”>被检查的字符串</param>								 
			 
相关文章 大家在看