zoukankan      html  css  js  c++  java
  • .net 防止sql注入

     public class SqlCheck  
    {  
        public SqlCheck()  
        {  
            //  
            // TODO: 在此处添加构造函数逻辑  
            //     
        }  
     
          
        public SqlConnection oconn()  
        {  
            SqlConnection conn = new SqlConnection();  
            conn.ConnectionString = ConfigurationManager.ConnectionStrings["StudyConnectionString"].ToString();  
            //第1种调用的方法   JK1986_CheckSql();  
            JK1986_CheckSql();  
            if ( conn.State == ConnectionState.Closed  )   
            {  
                conn.Open();  
            }  
            return conn;  
        }  
     
     
        public DataTable  getsource(string getds)   
        {  
            SqlConnection conn = oconn();  
            SqlDataAdapter da = new SqlDataAdapter(getds, conn);  
            DataSet ds = new DataSet();  
            da.Fill(ds,"news" );  
            return ds.Tables["news"];  
        }  
          
     
        public static  void JK1986_CheckSql()  
        {  
            string jk1986_sql = "exec↓select↓drop↓alter↓exists↓union↓and↓or↓xor↓order↓mid↓asc↓execute↓xp_cmdshell↓insert↓update↓delete↓join↓declare↓char↓sp_oacreate↓wscript.shell↓xp_regwrite↓'↓;↓--";  
            string[] jk_sql = jk1986_sql.Split('↓');  
            foreach (string jk in jk_sql)  
            {  
                // -----------------------防 Post 注入-----------------------  
                if ( System.Web.HttpContext.Current.Request.Form != null)  
                {  
                    for (int k = 0; k < System.Web.HttpContext.Current.Request.Form.Count; k++)  
                    {  
                        string getsqlkey = System.Web.HttpContext.Current.Request.Form.Keys[k];  
                        string getip;  
                        if (System.Web.HttpContext.Current.Request.Form[getsqlkey].ToLower().Contains(jk) == true)  
                        {  
                           System.Web.HttpContext.Current.Response.Write("<script Language=JavaScript>alert('ASP.NET( C#版本 )防注入程序提示您,请勿提交非法字符!↓\\n\\nBlog:http://hi.baidu.com/ahhacker86
    \\n\\nBy:aa && JK1986');</" + "script>");  
                           System.Web.HttpContext.Current.Response.Write("非法操作!系统做了如下记录 ↓" + "<br>");  
                           if (System.Web.HttpContext.Current.Request.ServerVariables["HTTP_X_FORWARDED_FOR"] != null)  
                            {  
                                getip = System.Web.HttpContext.Current.Request.ServerVariables["HTTP_X_FORWARDED_FOR"];  
                            }  
                            else 
                            {  
                                getip = System.Web.HttpContext.Current.Request.ServerVariables["REMOTE_ADDR"];  
                            }  
                            System.Web.HttpContext.Current.Response.Write("操 作 I  P :" + getip + "<br>");  
                            System.Web.HttpContext.Current.Response.Write("操 作 时 间:" + DateTime.Now.ToString() + "<br>");  
                            System.Web.HttpContext.Current.Response.Write("操 作 页 面:" + System.Web.HttpContext.Current.Request.ServerVariables["URL"] + "<br>");  
                            System.Web.HttpContext.Current.Response.Write("提 交 方 式:P O S T " + "<br>");  
                            System.Web.HttpContext.Current.Response.Write("提 交 参 数:" + jk + "<br>");  
                            System.Web.HttpContext.Current.Response.Write("提 交 数 据:" + System.Web.HttpContext.Current.Request.Form[getsqlkey].ToLower() + "<br>");  
                            System.Web.HttpContext.Current.Response.End();  
                        }  
                    }  
                }  
                // -----------------------防 GET 注入-----------------------  
                if (System.Web.HttpContext.Current.Request.QueryString != null)  
                {  
                    for (int k = 0; k < System.Web.HttpContext.Current.Request.QueryString.Count; k++)  
                    {  
                        string getsqlkey = System.Web.HttpContext.Current.Request.QueryString.Keys[k];  
                        string getip;  
                        if (System.Web.HttpContext.Current.Request.QueryString[getsqlkey].ToLower().Contains(jk) == true)  
                        {  
                            System.Web.HttpContext.Current.Response.Write("<script Language=JavaScript>alert('ASP.NET( C#版本 )防注入程序提示您,请勿提交非法字符!↓\\n\\nBlog:http://hi.baidu.com/ahhacker86
    \\n\\nBy:aa && JK1986');</" + "script>");  
                            System.Web.HttpContext.Current.Response.Write("非法操作!系统做了如下记录 ↓" + "<br>");  
                            if (System.Web.HttpContext.Current.Request.ServerVariables["HTTP_X_FORWARDED_FOR"] != null)  
                            {  
                                getip = System.Web.HttpContext.Current.Request.ServerVariables["HTTP_X_FORWARDED_FOR"];  
                            }  
                            else 
                            {  
                                getip = System.Web.HttpContext.Current.Request.ServerVariables["REMOTE_ADDR"];  
                            }  
                            System.Web.HttpContext.Current.Response.Write("操 作 I  P :" + getip + "<br>");  
                            System.Web.HttpContext.Current.Response.Write("操 作 时 间:" + DateTime.Now.ToString() + "<br>");  
                            System.Web.HttpContext.Current.Response.Write("操 作 页 面:" + System.Web.HttpContext.Current.Request.ServerVariables["URL"] + "<br>");  
                            System.Web.HttpContext.Current.Response.Write("提 交 方 式:G E T " + "<br>");  
                            System.Web.HttpContext.Current.Response.Write("提 交 参 数:" + jk + "<br>");  
                            System.Web.HttpContext.Current.Response.Write("提 交 数 据:" + System.Web.HttpContext.Current.Request.QueryString[getsqlkey].ToLower() + "<br>");  
                            System.Web.HttpContext.Current.Response.End();  
                        }  
                    }  
                }  
     
                // -----------------------防 Cookies 注入-----------------------  
                if (System.Web.HttpContext.Current.Request.Cookies != null)  
                {  
                    for (int k = 0; k < System.Web.HttpContext.Current.Request.Cookies.Count; k++)  
                    {  
                        string getsqlkey = System.Web.HttpContext.Current.Request.Cookies.Keys[k];  
                        string getip;  
                        if (System.Web.HttpContext.Current.Request.Cookies[getsqlkey].Value.ToLower().Contains(jk) == true)  
                        {  
                            System.Web.HttpContext.Current.Response.Write("<script Language=JavaScript>alert('ASP.NET( C#版本 )防注入程序提示您,请勿提交非法字符!↓\\n\\nBlog:http://hi.baidu.com/ahhacker86
    \\n\\nBy:aa && JK1986');</" + "script>");  
                            System.Web.HttpContext.Current.Response.Write("非法操作!系统做了如下记录 ↓" + "<br>");  
                            if (System.Web.HttpContext.Current.Request.ServerVariables["HTTP_X_FORWARDED_FOR"] != null)  
                            {  
                                getip = System.Web.HttpContext.Current.Request.ServerVariables["HTTP_X_FORWARDED_FOR"];  
                            }  
                            else 
                            {  
                                getip = System.Web.HttpContext.Current.Request.ServerVariables["REMOTE_ADDR"];  
                            }  
                            System.Web.HttpContext.Current.Response.Write("操 作 I  P :" + getip + "<br>");  
                            System.Web.HttpContext.Current.Response.Write("操 作 时 间:" + DateTime.Now.ToString() + "<br>");  
                            System.Web.HttpContext.Current.Response.Write("操 作 页 面:" + System.Web.HttpContext.Current.Request.ServerVariables["URL"] + "<br>");  
                            System.Web.HttpContext.Current.Response.Write("提 交 方 式: Cookies " + "<br>");  
                            System.Web.HttpContext.Current.Response.Write("提 交 参 数:" + jk + "<br>");  
                            System.Web.HttpContext.Current.Response.Write("提 交 数 据:" + System.Web.HttpContext.Current.Request.Cookies[getsqlkey].Value.ToLower() + "<br>");  
                            System.Web.HttpContext.Current.Response.End();  
                        }  
                    }  
                }  
     
            }  
        }       
          
    }

     

     

    来源于:www.hackbadboy.com B.B.S.T 信息安全团队 BadBoy网络安全小组

  • 相关阅读:
    创建逻辑卷LVM以及swap分区
    Linux下命令别名配置
    vim多行注释与删除
    Linux下parted分区超过2TB硬盘-分区格式化
    scp命令限速远程拷贝
    tar命令加密压缩/解密解压
    centos下dnsmasq安装与配置
    Mac OS: xcrun: error: invalid active developer path, missing xcrun
    C/C++编译器GCC:GNU Compiler Collection
    es分页查询限制的问题
  • 原文地址:https://www.cnblogs.com/secbook/p/2654922.html
Copyright © 2011-2022 走看看