zoukankan      html  css  js  c++  java
  • .net 通用防注入代码 天高地厚

    using System;

    namespace web.comm
    {
        
    /// <summary>
        
    /// ProcessRequest 的摘要说明。
        
    /// </summary>

        public class ProcessRequest
        
    {
            
    public ProcessRequest()
            
    {
                
    //
                
    // TODO: 在此处添加构造函数逻辑
                
    //
            }


            
    #region SQL注入式攻击代码分析
            
    /// <summary>
            
    /// 处理用户提交的请求
            
    /// </summary>

            public static void StartProcessRequest()
            
    {
                
    //            System.Web.HttpContext.Current.Response.Write("<script>alert('dddd');</script>");
                try
                
    {
                    
    string getkeys = "";
                    
    //string sqlErrorPage = System.Configuration.ConfigurationSettings.AppSettings["CustomErrorPage"].ToString();
                    if (System.Web.HttpContext.Current.Request.QueryString != null)
                    
    {
        
                        
    for(int i=0;i<System.Web.HttpContext.Current.Request.QueryString.Count;i++)
                        
    {
                            getkeys 
    = System.Web.HttpContext.Current.Request.QueryString.Keys[i];
                            
    if (!ProcessSqlStr(System.Web.HttpContext.Current.Request.QueryString[getkeys],0))
                            
    {
                                
    //System.Web.HttpContext.Current.Response.Redirect (sqlErrorPage+"?errmsg=sqlserver&sqlprocess=true");
                                System.Web.HttpContext.Current.Response.Write("<script>alert('请勿非法提交!');history.back();</script>");
                                System.Web.HttpContext.Current.Response.End();
                            }

                        }

                    }

                    
    if (System.Web.HttpContext.Current.Request.Form != null)
                    
    {
                        
    for(int i=0;i<System.Web.HttpContext.Current.Request.Form.Count;i++)
                        
    {
                            getkeys 
    = System.Web.HttpContext.Current.Request.Form.Keys[i];
                            
    if (!ProcessSqlStr(System.Web.HttpContext.Current.Request.Form[getkeys],1))
                            
    {
                                
    //System.Web.HttpContext.Current.Response.Redirect (sqlErrorPage+"?errmsg=sqlserver&sqlprocess=true");
                                System.Web.HttpContext.Current.Response.Write("<script>alert('请勿非法提交!');history.back();</script>");
                                System.Web.HttpContext.Current.Response.End();
                            }

                        }

                    }

                }

                
    catch
                
    {
                    
    // 错误处理: 处理用户提交信息!
                }

            }

            
    /// <summary>
            
    /// 分析用户请求是否正常
            
    /// </summary>
            
    /// <param name="Str">传入用户提交数据</param>
            
    /// <returns>返回是否含有SQL注入式攻击代码</returns>

            private static bool ProcessSqlStr(string Str,int type)
            
    {
                
    string SqlStr;

                
    if(type == 1)
                    SqlStr 
    = "exec |insert |select |delete |update |count |chr |mid |master |truncate |char |declare ";
                
    else
                    SqlStr 
    = "'|and|exec|insert|select|delete|update|count|*|chr|mid|master|truncate|char|declare";

                
    bool ReturnValue = true;
                
    try
                
    {
                    
    if (Str != "")
                    
    {
                        
    string[] anySqlStr = SqlStr.Split('|');
                        
    foreach (string ss in anySqlStr)
                        
    {
                            
    if (Str.IndexOf(ss)>=0)
                            
    {
                                ReturnValue 
    = false;
                            }

                        }

                    }

                }

                
    catch
                
    {
                    ReturnValue 
    = false;
                }

                
    return ReturnValue;
            }

            
    #endregion



        }

    }

     

    不登高山,怎知天高;不临深溪,焉知地厚!站在坚实的土地上,做着生命中最真实的事情;像一棵挺拔的大树,认可自己的命运并敢于迎接属于这一方天空的风风雨雨。

  • 相关阅读:
    Jenkins
    python爬虫
    git分布式版本控制
    CKA考试认证总结
    gitlab-ci 工具链
    gitlab-ci 模板库实践
    gitlab-cicd
    gitlab配置文件gitlab.rb详解
    局部变量表中的slot简述
    JVM系统线程类型
  • 原文地址:https://www.cnblogs.com/net2012/p/2823004.html
Copyright © 2011-2022 走看看