參數化SQL語句,防止SQL注入漏洞攻擊

來源:互聯網
上載者:User

防止SQL注入漏洞攻擊的有兩種方法:

1)第一種是所有的SQL語句都存放在預存程序中,不但可以避免SQL注入,還能提高效能,並且預存程序可以有專門的資料庫管理員(DBA)編寫和集中管理;不過這種做法有時候針對相同的幾個表有不同的查詢條件,SQl語句可能不同,這樣就會編寫大量的預存程序。於是就有了第二種查詢方法,

2)參數化查詢SQL語句


舉例如下:

//執行個體化Connection對象        SqlConnection con = new SqlConnection("資料庫連接字串");    //為添加資料庫連接字串        //執行個體化Command對象        SqlCommand cmd = new SqlCommand("SELECT * FROM UserInfo where Sex=@sex  and age=@age", con);        //SqlCommand cmd = con.CreateCommand();        //cmd.CommandText="SELECT * FROM UserInfo where Sex=@sex  and age=@age";        //第一種添加查詢參數的例子        cmd.Parameters.AddWithValue("@sex", true);        //第二種添加查詢參數的例子        SqlParameter Parameter = new SqlParameter("@age", SqlDbType.Int);        Parameter.Value = 30;        cmd.Parameters.Add(Parameter);  //添加參數        //執行個體化DataAdapter        SqlDataAdapter adapter = new SqlDataAdapter(cmd);        DataTable data = new DataTable();


聯繫我們

該頁面正文內容均來源於網絡整理,並不代表阿里雲官方的觀點,該頁面所提到的產品和服務也與阿里云無關,如果該頁面內容對您造成了困擾,歡迎寫郵件給我們,收到郵件我們將在5個工作日內處理。

如果您發現本社區中有涉嫌抄襲的內容,歡迎發送郵件至: info-contact@alibabacloud.com 進行舉報並提供相關證據,工作人員會在 5 個工作天內聯絡您,一經查實,本站將立刻刪除涉嫌侵權內容。

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.