The ultimate security Dafa 18 Asp+access Database

Source: Internet
Author: User
Tags md5 encryption modify table name access database
access|asp+| Security | data | Database 1. Filter all client submissions, including? Id=n class, and the operating database in the submitted HTML code, such as Select, and ASP file operation syntax, you can escape the submitted word, and then deposit the database

2. Authorize access to the Access database pages, such as using only SELECT statements for display data pages, and filtering what other update,asp files are classified as permission Access database pages and restricted access pages.

3. Modify the number of libraries according to the connection file name conn.asp to similar 123ljuvo345l3kj34534v.asp files

4. Modify database name similar to q397d0394pjsdlkfgjwetoiu.asp file

5. Add a connection password to the Access database (although it can be cracked, deal with rookie, and prevent uploaded files from unrestricted connection to the database)

6. Encode and encrypt the database with Access software

7. Encrypt the user's password with MD5 encryption algorithm, and the field of a kind of password hint problem

8. Restrict search engine to related pages

9. Prevent the database from downloading tools, such as adding <%response.end%> in the database to prevent the output to the client statement

10 do a good job of ASP upload file Template security management, to prevent uploading ASP Trojan

11. Deny client access to data inventory connection files, only the server ASP file access

12. Limit the number of IP Access databases for the same client

13. If it is necessary to encrypt the contents of the database, return to the client to decrypt, even if the database is downloaded, it is not easy to get the original encrypted content

14. Restrictions on the header content of the connection service, such as only allow IE, Firefox browsing access

15. Prevent through the file view way, get the database information, the client can enter the password, to the password and the content, uses certain algorithm to save the database, the output, lets the client enter the password, decrypts the content

16. Change the table name and field name to Aslkejrwoieru,werkuwoeiruwe similar characters

17. Prevent the addition of <% code blocks in the database%> let the renamed to. asp data execution, can escape the <% characters to be stored in the database, in each table, enter &LT;%RESPONSE.REDIRCT ("http://www.qqmo.com")% ><%set sdflkjsd=welrkjwel<><><%> code and so on to make the ASP perform the wrong content

18. The best condition to use ODBC to connect the database, plus the connection password



Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.