SQL injection attacks use designed vulnerabilities to run SQL commands on the target server and perform other attacks, the failure to verify the data entered by the user during dynamic generation of SQL commands is the main cause of the successful SQL injection attacks. For example:
If your query statement is select * from admin where username = '"& user &"' and password = '"& pwd &"'"
Then, if my user name is: 1 'or '1' = '1
Then, your query statement will become:
Select * from admin where username = '1 or '1' = '1' and password = '"& pwd &"'"
In this way, your query statements are passed and you can access your management interface.
Therefore, you need to check user input for defense purposes. Special characters, such as single quotes, double quotation marks, semicolons, commas, colons, and connection numbers, are converted or filtered.
Special characters and strings to be filtered include:
Net user
Xp_mongoshell
/Add
Exec master. dbo. xp_mongoshell
Net localgroup administrators
Select
Count
Asc
Char
Mid
'
:
"
Insert
Delete from
Drop table
Update
Truncate
From
%
Below are two types of code I have written to prevent injection attacks for your reference!
Code for preventing SQL injection attacks in js version ~ :
[Code start]
<Script language = "javascript">
<! --
Var url = location. search;
Var re =/^? (. *) (Select % 20 | insert % 20 | delete % 20 from % 20 | count (| drop % 20 table
| Update % 20 truncate % 20 | asc (| mid (| char (| xp_mongoshell | exec % 20 master
| Net % 20 localgroup % 20administrators | "|: | net % 20user | '| % 20or % 20) (. *) $/gi;
Var e = re. test (url );
If (e ){
Alert ("the address contains invalid characters ~ ");
Location. href = "error. asp ";
}
// -->
<Script>
[Code end]
Code for asp to prevent SQL injection attacks ~ :
[Code start]
<%
On Error Resume Next
Dim strTemp
If LCase (Request. ServerVariables ("HTTPS") = "off" Then