ASP网站遭到SQL注入

[复制链接]
查看11 | 回复0 | 2008-1-1 01:58:12 | 显示全部楼层 |阅读模式
看看这段代码,我也不大懂squery=lcase(Request.ServerVariables("QUERY_STRING"))sURL=lcase(Request.ServerVariables("HTTP_HOST"))allquery=squery+sURLIf InStr(allquery,"%20")0 or InStr(allquery,"%27")0 or InStr(allquery,"'")0 or InStr(allquery,"%a1a1")0 or InStr(allquery,"%24")0 or InStr(allquery,"$")0 or InStr(allquery,"%3b")0 or InStr(allquery,";")0 or InStr(allquery,"%%")0 or InStr(allquery,"%3c")0 or InStr(allquery,"0 or InStr(allquery,">")0 or InStr(allquery,"--")0 or InStr(allquery,"sp_")0 or InStr(allquery,"xp_")0 or InStr(allquery,"exec")0 or InStr(allquery,"\")0 or InStr(allquery,"delete")0 or InStr(allquery,"dir")0 or InStr(allquery,"exe")0 or InStr(allquery,"select")0 or InStr(allquery,"Update")0 or InStr(allquery,"cmd")0 or InStr(allquery,"*")0 or InStr(allquery,"^")0 or InStr(allquery,"(")0 or InStr(allquery,")")0 or InStr(allquery,"+")0 or InStr(allquery,"copy")0 or InStr(allquery,"format")0 or not(isnumeric(Request("id"))) then Response.Redirect "/" Response.End
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

主题

0

回帖

4882万

积分

论坛元老

Rank: 8Rank: 8

积分
48824836
热门排行