asp.net最強sql防注入代碼

來源:互聯網
上載者:User


SqlConnection conn = new SqlCheck().oconn();
      // 第2種調用的方法  SqlCheck.JK1986_CheckSql();
        string osql = "select count(*) from admin";
        SqlCommand ocmd = new SqlCommand(osql, conn);

using System;
using System.Data;
using System.Configuration;
using System.Web;
using System.Web.Security;
using System.Web.UI;
using System.Web.UI.WebControls;
using System.Web.UI.WebControls.WebParts;
using System.Web.UI.HtmlControls;
using System.Data.SqlClient ;
/// <summary>
/// SqlCheck 的摘要說明
/// </summary>

// #region ,#endregion 用於VS代碼顯示的更美觀,能夠摺疊展開                     
public class SqlCheck
{
 public SqlCheck()
 {
  //
  // TODO: 在此處添加建構函式邏輯
  //  
    }

   
    public SqlConnection oconn()
    {
        SqlConnection conn = new SqlConnection();
        conn.ConnectionString = ConfigurationManager.ConnectionStrings["StudyConnectionString"].ToString();
        //第1種調用的方法   JK1986_CheckSql();
        JK1986_CheckSql();
        if ( conn.State == ConnectionState.Closed  )
        {
            conn.Open();
        }
        return conn;
    }


    public DataTable  getsource(string getds)
    {
        SqlConnection conn = oconn();
        SqlDataAdapter da = new SqlDataAdapter(getds, conn);
        DataSet ds = new DataSet();
        da.Fill(ds,"news" );
        return ds.Tables["news"];
    }
   

    public static  void JK1986_CheckSql()
    {
        string jk1986_sql = "exec↓select↓drop↓alter↓exists↓union↓and↓or↓xor↓order↓mid↓asc↓execute↓xp_cmdshell↓insert↓update↓delete↓join↓declare↓char↓sp_oacreate↓wscript.shell↓xp_regwrite↓'↓;↓--";
        string[] jk_sql = jk1986_sql.Split('↓');
        foreach (string jk in jk_sql)
        {
            // -----------------------防 Post 注入-----------------------
            if ( System.Web.HttpContext.Current.Request.Form != null)
            {
                for (int k = 0; k < System.Web.HttpContext.Current.Request.Form.Count; k++)
                {
                    string getsqlkey = System.Web.HttpContext.Current.Request.Form.Keys[k];
                    string getip;
                    if (System.Web.HttpContext.Current.Request.Form[getsqlkey].ToLower().Contains(jk) == true)
                    {
                       System.Web.HttpContext.Current.Response.Write("<script Language=JavaScript>alert('ASP.NET( C#版本 )防注入程式提示您,請勿提交非法字元!↓\n\nBlog:http://hi.baidu.com/ahhacker86 \n\nBy:

聯繫我們

該頁面正文內容均來源於網絡整理,並不代表阿里雲官方的觀點,該頁面所提到的產品和服務也與阿里云無關,如果該頁面內容對您造成了困擾,歡迎寫郵件給我們,收到郵件我們將在5個工作日內處理。

如果您發現本社區中有涉嫌抄襲的內容,歡迎發送郵件至: info-contact@alibabacloud.com 進行舉報並提供相關證據,工作人員會在 5 個工作天內聯絡您,一經查實,本站將立刻刪除涉嫌侵權內容。

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.