asp.Net 一些常用的方法和类(12)
}
}
public bool IsReusable
{
get
{
return false;
}
}
}
防注入过滤:
using System; 
using System.Data; 
using System.Configuration; 
using System.Web; 
using System.Web.Security; 
using System.Web.UI; 
using System.Web.UI.WebControls; 
using System.Web.UI.WebControls.WebParts; 
using System.Web.UI.HtmlControls; 
using System.Data.SqlClient; 
 
/// <summary> 
/// SqlCheck 的摘要说明 
/// </summary> 
 
    public class SqlCheck 
    { 
       
        public void CheckSql() 
        { 
           
            string jk1986_sql = "exec↓select↓drop↓alter↓exists↓union↓and↓or↓xor↓order↓mid↓asc↓execute↓xp_cmdshell↓insert↓update↓delete↓join↓declare↓char↓sp_oacreate↓wscript.shell↓xp_regwrite↓'↓;↓--"; 
            string[] jk_sql = jk1986_sql.Split('↓'); 
            foreach (string jk in jk_sql) 
            { 
                // -----------------------防 Post 注入----------------------- 
                if (System.Web.HttpContext.Current.Request.Form != null) 
                { 
                    for (int k = 0; k < System.Web.HttpContext.Current.Request.Form.Count; k++) 
                    { 
	
相关新闻>>
- 发表评论
- 
				
- 最新评论 进入详细评论页>>



