實施修復,方法有很多在這裏介紹兩種,咱們使用第2種
方法1: Replace過濾字符
解決方法:查找login.asp下的<from找到下邊的類似
username=request.Form("name") pass=request.Form("pass") |
修改爲:
username=Replace(request.Form("name"), "’", "’’") pass=Replace(request.Form("pass"), "’", "’’") |
語法是屏蔽’和’’字符來達到效果.
方法2:在conn.asp 內加入<!--#include file="safe.asp"-->
注:(前提 登陸頁面有<!--#include file="conn.asp"-->)
把以下代碼保存爲safe.asp
qq:11422265
下面是程序代碼********************************************************
<% Dim Query_Badword,Form_Badword,i,Err_Message,Err_Web,name Err_Message = 3 Err_Web = "safe.htm" ’出錯時轉向的頁面 Query_Badword="’|and|select|update|chr|delete|%20from|;|insert|mid|master.|set|chr(37)|=" ’在這部份定義get非法參數,使用"|"號間隔 Form_Badword="’|(|)|;|=" ’在這部份定義post非法參數,使用"|"號間隔 On Error Resume Next if request.QueryString<>"" then Chk_badword=split(Query_Badword,"|") FOR EACH Query_Name IN Request.QueryString for i=0 to ubound(Chk_badword) If Instr(LCase(request.QueryString(Query_Name)),Chk_badword(i))<>0 Then Select Case Err_Message Case "1" Response.Write "<Script Language=JavaScript>alert(’傳參錯誤!參數 "&name&" 的值中包含非法字符串!\n\n請不要在參數中出現:and update delete ; insert mid master 等非法字符!’);window.close();</Script>" Case "2" Response.Write "<Script Language=JavaScript>location.href=’"&Err_Web&"’</Script>" Case "3" Response.Write "<Script Language=JavaScript>alert(’傳參錯誤!參數 "&name&"的值中包含非法字符串!\n\n請不要在參數中出現:and update delete ; insert mid master 等非法字符!’);location.href=’"&Err_Web&"’;</Script>" End Select Response.End End If NEXT NEXT End if if request.form<>"" then Chk_badword=split(Form_Badword,"|") FOR EACH name IN Request.Form for i=0 to ubound(Chk_badword) If Instr(LCase(request.form(name)),Chk_badword(i))<>0 Then Select Case Err_Message Case "1" Response.Write "<Script Language=JavaScript>alert(’出錯了!表單 "&name&" 的值中包含非法字符串!\n\n你的非法操作已記錄,請馬上停止非法行爲!’);window.close();</Script>" Case "2" Response.Write "<Script Language=JavaScript>location.href=’"&Err_Web&"’</Script>" Case "3" Response.Write "<Script Language=JavaScript>alert(’唐山味兒不濃 告訴您出錯了!參數 "&name&"的值中包含非法字符串!\n\謝謝您光臨!,請停止非法行爲!’);location.href=’"&Err_Web&"’;</Script>" End Select Response.End End If NEXT NEXT end if %> |