access|asp+| Security | data | Database 1. Filter all client submissions, including? Id=n class, and the operating database in the submitted HTML code, such as Select, and ASP file operation syntax, you can escape the submitted word, and then deposit the database
2. Authorize access to the Access database pages, such as using only SELECT statements for display data pages, and filtering what other update,asp files are classified as permission Access database pages and restricted access pages.
3. Modify the number of libraries according to the connection file name conn.asp to similar 123ljuvo345l3kj34534v.asp files
4. Modify database name similar to q397d0394pjsdlkfgjwetoiu.asp file
5. Add a connection password to the Access database (although it can be cracked, deal with rookie, and prevent uploaded files from unrestricted connection to the database)
6. Encode and encrypt the database with Access software
7. Encrypt the user's password with MD5 encryption algorithm, and the field of a kind of password hint problem
8. Restrict search engine to related pages
9. Prevent the database from downloading tools, such as adding <%response.end%> in the database to prevent the output to the client statement
10 do a good job of ASP upload file Template security management, to prevent uploading ASP Trojan
11. Deny client access to data inventory connection files, only the server ASP file access
12. Limit the number of IP Access databases for the same client
13. If it is necessary to encrypt the contents of the database, return to the client to decrypt, even if the database is downloaded, it is not easy to get the original encrypted content
14. Restrictions on the header content of the connection service, such as only allow IE, Firefox browsing access
15. Prevent through the file view way, get the database information, the client can enter the password, to the password and the content, uses certain algorithm to save the database, the output, lets the client enter the password, decrypts the content
16. Change the table name and field name to Aslkejrwoieru,werkuwoeiruwe similar characters
17. Prevent the addition of <% code blocks in the database%> let the renamed to. asp data execution, can escape the <% characters to be stored in the database, in each table, enter <%RESPONSE.REDIRCT ("http://www.qqmo.com")% ><%set sdflkjsd=welrkjwel<><><%> code and so on to make the ASP perform the wrong content
18. The best condition to use ODBC to connect the database, plus the connection password