»áÔ±£º ÃÜÂ룺 ¡¡Ãâ·Ñ×¢²á | Íü¼ÇÃÜÂë | »áÔ±µÇ¼ ÍøÒ³¹¦ÄÜ£º ¼ÓÈëÊÕ²Ø ÉèΪÊ×Ò³ ÍøÕ¾ËÑË÷  
°²È«·ÀÏß > ºÚ¿Í±à³Ì
°²È«½Å±¾³ÌÐòµÄ±àд V1.0
·¢±íÈÕÆÚ£º2003-08-27 00:00:00×÷Õߣº° ³ö´¦£º  

»ù±¾Ë¼Â·£º

  ÎªÃ»Ò»¸ö¹¦ÄÜдһ¸ö¶ÀÁ¢µÄ³ÌÐò£¬³ÌÐòÒ³

  ¾¡¿ÉÄÜÉÙµÄÈÿͻ§Á˽âÄãµÄ·þÎñÆ÷¶ËÐÅÏ¢

  ²»ÒªÓÃ"¿Í»§Ó¦¸ÃÕâôд"Õâ¸ö˼·ÏëÎÊÌâ

  ¾¡¿ÉÄܶàµÄÏëµ½²»¿ÉÄÜ·¢ÉúµÄÊÂÇé

  

1.¹ØÓÚ½»»¥Ê½¶¯Ì¬ÍøÒ³¿ÉÄÜ´æÔÚµÄÎÊÌâ

1.1  formÀàÐ͵Ľ»»¥

1.1.1 ¸ÅÄî½éÉÜ

ÔÚÎÒÃǺÍä¯ÀÀÕß½øÐн»»¥Ê±£¬×î³£Óõ½µÄ¾ÍÊÇform(post/get/put·½·¨)£¬ËäÈ»·Ç³£·½±ã£¬µ«ÊǺܶàÎÊÌâÒ²ÊÇÒòËû¶øÆð¡£form±íµ¥ÖÐinput±êÖ¾

ÓÃÀ´½ÓÊÜÓû§ÊäÈëµÄÐÅÏ¢£¬ÀýÈ磺Óû§Ãû¡¢ÃÜÂë¡¢emailµÈ¡£Èç¹ûÄãûÓжÔÓû§ÊäÈë½øÐкܺõļì²éµÄ»°£¬Ò»¸ö¶ñÒâµÄÓû§»áÆÁ±ÎµôһЩ°²È«

»úÖÆ£¬Èƹý°²È«ÈÏÖ¤¡£ÀýÈ磬ÊäÈë±ê×¼µÄHTMLÓï¾ä»òÕßjavascriptÓï¾ä»á¸Ä±äÊä³ö½á¹û£¬ÔÚÊäÈë¿òÖдòÈë±ê×¼µÄHTMLÓï¾ä»áµÃµ½Ê²Ã´ÑùµÄ½á

¹ûÄØ£¿±ÈÈçÒ»¸öÁôÑÔ±¾£¬ÎÒÃÇÁôÑÔÄÚÈÝÖдòÈ룺<font size=10>ÄãºÃ£¡</font>¡¡

Èç¹ûÄãµÄ³ÌÐòÖÐûÓÐÆÁ±ÎhtmlÓï¾ä£¬ÄÇô¾Í»á¸Ä±ä"ÄãºÃ"×ÖÌåµÄ´óС¡£ÔÚÁôÑÔ±¾Öиıä×ÖÌå´óСºÍÌùͼÓÐʱ²¢²»ÊÇʲô»µÊ£¬·´¶ø¿ÉÒÔʹÁôÑÔ

±¾Éú¶¯¡£µ«ÊÇÈç¹ûÔÚÊäÈë¿òÖÐд¸ö javascript µÄËÀÑ­»·£¬±ÈÈ磺

<a herf="http://someurl" onMouseover="while(1) {window.close('/')}">µÚÒ»Íò¸ö¾ªÐĶ¯ÆÇ</a> ÄÇôÆäËû²é¿´¸ÃÁôÑԵĿÍÈËÖ»ÒªÒÆ

¶¯Êó±êµ½"µÚÒ»Íò¸ö¾ªÐĶ¯ÆÇ"£¬ÉϾͻáʹÓû§µÄä¯ÀÀÆ÷ÒòËÀÑ­»·¶øËÀµô¡£

1.1.2 ·À·¶Òªµã

(1)¶ÔÌØÊâ×Ö·û½øÐйýÂË

([\&;\`'\\\|"*?~<>^\(\)\[\]\{\}\$\n\r])/\\$1/g;)£¬Õâ¸öÊÇ×î»ù±¾µÄ£¬ÔںܶàµØ·½Ò²ÒѾ­²»Ö»Ò»´ÎÌáµ½¹ý

<script language="vbscript">

sub uBotton_onclick

if form1.uUserName.value=""then

msgbox"ÄúµÄÐÕÃû²»ÄÜΪ¿Õ£¡",0+32,"Ŷ£¡»¹²»ÐÐ"

form1.uUserName.focus

exit sub

end if

if form1.uPassword.value=""then

msgbox"ÄúµÄÃÜÂë²»ÄÜΪ¿Õ£¡",0+32,"Ŷ£¡»¹²»ÐÐ"

form1.uPassword.focus

exit sub

end if

if form1.uUserName.value=""then

msgbox"ÄúµÄÐÕÃû²»ÄÜΪ¿Õ£¡",0+32,"Ŷ£¡»¹²»ÐÐ"

form1.uUserName.focus

exit sub

end if

form1.submit

end sub

</script>

function isEmpty(objname)

{

  var str = document.inputform[objname].value

  var tmpstr = str.replace([\&;\`'\\\|"*?~<>^\(\)\[\]\{\}\$\n\r])/\\$1/g;,"")

  var tmpstr = tmpstr.replace([\&;\`'\\\|"*?~<>^\(\)\[\]\{\}\$\n\r])/\\$1/g;,"")

  return (tmpstr.length==0)

}

function check()

{

  tf=document.inputform

  errors=""

  if (isEmpty("username")) errors += "Óû§Ãû²»ÄÜΪ¿Õ¡£\n";

  if (isEmpty("password")) errors += "ÃÜÂë²»ÄÜΪ¿Õ£¡\n"

  if (errors!="")

    alert(errors);

  return (errors=="")

}  

(2) ¶ÔÊäÈëµÄ×Ö·û³¤¶È½øÐÐÏÞÖÆ

(3) ½øÐо¡¿ÉÄܶàµÄ´íÎó³öÀíºÍ´íÎóÏÝÚå

(4) ¾¡¿ÉÄܶàµÄʹÓÃÒÔÏÂÕâЩ±êÖ¾£¬¼õÉÙÓû§ÊäÈëµÄ»ú»á

 <input type="checkbox" name="checkbox" value="checkbox">

 <select name="select"> </select>

 <input type="radio" name="radiobutton" value="radiobutton">

¡¡¡¡

1.2  post/getÀàÐ͵Ľ»»¥

1.2.1 ¸ÅÄî½éÉÜ

ÕâÖÖÀàÐ͵ÄÎÊÌâÖ÷ÒªÊÇä¯ÀÀÕß¿ÉÒÔͨ¹ýä¯ÀÀÆ÷µÄµØÖ·À¸¶Ô½Å±¾Ò³Í¨¹ýÌí¼Ó²ÎÊýÀ´ºÍ·þÎñÆ÷½øÐн»»¥£¬ÕâЩ²ÎÊýÒѾ­Èƹý·ÅÔÚ¿Í»§¶ËÌá½»Ò³µÄ

ÊäÈë¼ì²éÁË£¬»¹ÓоÍÊÇ¿ÉÒÔͨ¹ýµØÖ·À¸ÊäÈë½Ï³¤µÄ²ÎÊý»ò¶ñÒâ±àÔìµÄ´úÂëÔì³É·þÎñÆ÷Òì³£ÔËËã´íÎ󣬵¼Ö·þÎñÆ÷å´»ú»ò»º³åÇøÒç³ö¡£

1.2.2 ·À·¶Òªµã

(1) ¾¡Á¿²»ÒªÈÃä¯ÀÀÕßÁ˽⵽ÄãµÄÔËËãÌá½»Ò³

(2) ²»ÔÊÐíµØÖ·À¸Ìá½»²ÎÊý

ÀýÈçASP³ÌÐòÖеÄrequest.serverVariables(QUERY_STRING)¼ì²âÊÇ·ñÓвÎÊý£¬Èç¹ûÓÐÔòʹÓÃresponse.redirect()Ç¿ÖÆ·µ»ØÖ¸¶¨Ò³£¬¿ÉÒÔ

ÊÇÊ×Ò³£¬»òÕßÄã×Ô¼º×öµÄ¾¯¸æÒ³¡£

(3) ½Å±¾Ò³¼ä´«µÝ²ÎÊý²»ÒªÔÙä¯ÀÀÆ÷À¸ÏÔʾ£¬¾¡¿ÉÄÜÉÙµÄÈÃä¯ÀÀÕßÁ˽âÄãµÄ³ÌÐò¹æÔò¡¢²ÎÊýµÈ

ÀýÈçASPÖеÄRequest.formºÍRequest.QueryStringÕâÁ½¸öÊý¾Ý¼¯ºÏ·Ö±ðʹÓõÄÊÇpostºÍget·½·¨£¬ÎÒÃǾ¡Á¿²»ÒªÊÇÓÃRequest.QueryStringÕâ

¸öÊý¾Ý¼¯ºÏ£¬¾¡¿ÉÄÜÉÙµÄÈÃä¯ÀÀÕßÓкÍÄã½»»¥µÄ»ú»á£¬

2.   °²È«ÈÏÖ¤µÄÎÊÌâ

2.1  ÐèÒª°²È«ÈÏÖ¤ÃÜÂëÈÏÖ¤µÄ¿ÉÄÜ´æÔÚµÄÎÊÌâ

2.1.1 ¸ÅÄî½éÉÜ

ÏÖÔÚÁ÷ÐеÄCGIÓ¦ÓóÌÐòÇãÏòÓÚÊÕ¼¯ÐÅÓÿ¨ÐÅÏ¢¡£Êý¾ÝÊÕ¼¯ÊÇCGI Ó¦ÓóÌÐòµÄÒ»¸ö¼òµ¥µÄÈÎÎñ£¬µ«ÊÇÃô¸ÐÐÅÏ¢µÄ

ÊÕ¼¯ÐèÒªÒ»¸ö½«ÐÅÏ¢´Óä¯ÀÀÆ÷´«Ë͸ø·þÎñÆ÷ºÍCGI³ÌÐòµÄ°²È«Í¾¾¶¡£

 

¾Ù¸öÀý×Ó£¬¼ÙÉèÎÒҪͨ¹ýInternetÀ´ÏúÊÛÊé¡£ÎÒ¿ÉÄÜÔÚä¯ÀÀÆ÷ÉϽ¨Á¢Ò»¸ö±íµ¥£¬ÔÊÐíÒª¹ºÊéµÄ¹Ë¿Íͨ¹ý±íµ¥Ìá½»ËüµÄ¸öÈËÐÅÏ¢ºÍÐÅÓÿ¨ºÅÂë

¡£Êܵ½ÕâЩÐÅÏ¢ºó£¬ÎһὫËüÃÇ´æ´¢µ½ÎҵļÆËã»ú×÷ΪÉÌÒµ¼Ç¼¡£

 

Èç¹ûÓÐÈËÇÖÈëÎÒµÄÉÌÒµ¼ÆËã»ú£¬ÄÇôËû¿ÉÄÜ»á·ÃÎÊ´æ·Å¹Ë¿ÍÐÅÏ¢ºÍÐÅÓÿ¨ºÅÂëµÄ»úÃÜÊý¾Ý¡£ÎªÁ˱ÜÃâÕâÖÖÇé¿ö£¬ÎÒ»áÉó²éÎҵļÆËã»úÅäÖð²

È«ÁË£¬²¢È·¶¨ÓÃÀ´½ÓÊÜ±íµ¥µÄCGI½Å±¾²»»á±»¶ñÒâµÄ²Ù×Ý¡£»»¾ä»°Ëµ£¬ÎÒ£¬×÷Ϊ¼ÆËã»úµÄϵͳ¹ÜÀíÔ±ºÍCGI³ÌÐòÔ±£¬Òª¾¡Á¦¿ØÖÆסµÚÒ»¸öÎÊ

Ì⣺·ÀÖ¹ÐÅÏ¢Ö±½Ó´ÓÎҵļÆËã»úÖб»ÇÔÈ¡¡£

 

È»¶ø£¬ÔõÑù·ÀÖ¹µ±ÐÅÏ¢ÓÉ¿Í»§¶Ë·¢Íù·þÎñÆ÷¹ý³ÌÖÐÓÐÈËÖÐ;ÇÔÈ¡ÄØ£¿¼ÇסÐÅÏ¢ÔõÑùÓÉWeb·þÎñÆ÷´«Ë͵½CGI³ÌÐòÁËÂð£¿ÐÅϢͨ¹ýÍøÂçÓÉä¯ÀÀ

Æ÷ÏÈ´«Ë͵½·þÎñÆ÷£¬È»ºó·þÎñÆ÷½«ÐÅÏ¢´«Ë͸øCGI³ÌÐò¡£ÕâЩÐÅÏ¢¿ÉÄÜÔÚÓÉ¿Í»§»ú´«Ë͵½·þÎñÆ÷ʱ±»ÖÐ;ÇÔÈ¡(Èçͼ2)¡£×¢Ò⣬ΪÁ˱£»¤ÐÅÏ¢

ʹÆä²»»á±»ÖÐ;ÇÔÈ¡£¬±ØÐëÔÚ¿Í»§ºÍ·þÎñÆ÷Ö®¼ä½øÐмÓÃÜ¡£µ±È»£¬Èç¹ûÄãµÄ¿Í»§»ú²»ÄÜʶ±ðµÄ»°£¬Äã²»ÄÜÖ´ÐÐÌض¨CGIµÄ¼ÓÃÜ¡£

 

ÓÉÓÚWeb´¦ÀíµÄÌص㣬ʹÓÃÄã¶ÀÓеĵ¥¶Àͨ¹ýCGI³ÌÐòʵÏֵݲȫ´¦ÀíЭÒéµÄΨһ;¾¶ÊÇ:ÔÚ±íµ¥ÐÅϢͨ¹ýä¯ÀÀÆ÷´«Ë͵½·þÎñÆ÷֮ǰ½«Æä¼ÓÃÜ

¡£ Õâ¸ö·½°¸Èç¡£

 Ö®Ç°£¬·¢Õ¹Äã×Ô¼ºµÄ°²È«´¦ÀíЭÒ鼸ºõÊDz»¿ÉÄܵġ£¸ÐлJavaÕâÑùµÄÓïÑÔ,×î½üÔÚ¿Í»§¶Ë´¦ÀíËù×÷µÄ´´Ð£¬Ê¹µÃÕâ¸ö·¢Õ¹±ä³É¿ÉÄÜ¡£ 

·½·¨ÊDzúÉúÒ»¸ö±ê×¼HTML¸ñʽÀ©Õ¹µÄJava½Ó¿Ú¡£µ±JavaµÄÌá½»°´Å¥±»Ñ¡Ôñʱ£¬Java

Applet»áÔÚÀûÓñê×¼µÄPOSTHTTPÇëÇó½«Ëü·¢Ë͵½Web·þÎñÆ÷Ç°ÏȽ«Öµ¼ÓÃÜ¡£

 Ê¹ÓÃJava×÷Ϊ¿Í»§»úÀ´·¢ËͺͽÓÊÕ¼ÓÃܵÄÊý¾Ý½«ÔÊÐíÄãʹÓÃ×Ô¼º¶¨ÖƵļÓÃÜ·½°¸£¬¶ø²»ÐèÒªÒ»¸ö°º¹óµÄÉÌÒµ·þÎñÆ÷¡£

 

 

Òò´Ë£¬ÔÚÍøÂçÉÏ°²È«±£Ãܵش«ËÍÊý¾ÝÐÅÏ¢ÐèÒªµ÷Õûä¯ÀÀÆ÷ºÍ·þÎñÆ÷Ö®¼äµÄͨÐÅ·¾¶£¬ÓÐһЩÊDz»Äܽö½ö¿¿CGI¾ÍÄܹ»¿ØÖƵġ£Ä¿Ç°ÓÐÁ½ÖÖ¼Ó

ÃÜ¿Í»§»ú/·þÎñÆ÷ÐÅÏ¢´¦ÀíµÄ½¨Ò飺SSL(Secure Sockets Layer)ºÍSHTTP(Secure HTTP),·Ö±ðÓÉNetscapeºÍEIT(Enterprise Integrations

 

Technology)ÌáÒé¡£¹ØÓÚÕâµã£¬Ä¿Ç°»¹²»Çå³þÄÄÒ»¸ö½«³ÉΪ±ê×¼£»ºÜ¶à¹«Ë¾ÔÚËûÃǵķþÎñÆ÷ÖÐÁ½ÖÖ¶¼²ÉÓÃÁË¡£Òò´Ë£¬ÖªµÀÈçºÎÔÚÕâÁ½ÕßÖбà

дCGI³ÌÐòÊǺÜÓÐÓõġ£

SSLÊÇÒ»¸öЭÒé¶ÀÁ¢µÄ¼ÓÃÜ·½°¸£¬ÔÚÍøÂçÐÅÏ¢°üµÄÓ¦ÓòãºÍ´«Êä²ãÖ®¼äÌṩÁË°²È«µÄͨµÀ(²ÎÕÕͼ5)¡£¼òµ¥ËµÀ´£¬¾ÍÊÇHTML»òCGI¾­¹ýÁËÄ»ºó

µÄ·þÎñÆ÷½øÐÐÁ˼ÓÃÜ´¦Àí£¬È»¶ø¶ÔHTMLºÍCGIµÄ×÷ÕßÀ´ËµÊÇ͸Ã÷µÄ¡£

ÒòΪ¿Í»§¶ËºÍ·þÎñÆ÷¶ËÍøÂç³ÌÐò´¦Àí¼ÓÃܹý³Ì£¬¼¸ºõÄãµÄËùÓеÄCGI½Å±¾²»ÐèÒª½øÐа²È«ÊÂÎñµÄÐÞÕý¡£ÓÐÒ»¸öÏÔÖøµÄÀýÍâ¡£Ò»¸önph(no-pars

e-header)µÄCGI³ÌÐòÈƹý·þÎñÆ÷¶øÖ±½ÓÓë¿Í»§¶Ë½øÐÐͨÐÅ¡£Òò´Ë£¬nphµÄCGI½Å±¾²»»á¾­¹ý¼ÓÃÜ´¦Àí£¬ÒòΪÐÅϢδµÃµ½¼ÓÃÜ¡£ÊÜ´ËÓ°ÏìµÄÒ»

¸öÖµµÃ×¢ÒâµÄCGIÓ¦ÓóÌÐòÊÇNetscape·þÎñÆ÷Íƶ¯µÄ¶¯Ì¬ÊµÏÖ(Netscape server-push animations)¡£

ÎÒ»³ÒÉÕâÊÇÖ÷ÒªÓ¦¸ÃÖµµÃ×¢ÒâµÄ£¬È»¶ø£¬¸ü ÓпÉÄÜÒòΪҪ°²È«µÄ´«ÊäÃô¸ÐÐÅÏ¢¶øÎþÉüÒ³ÃæÖеĶ¯»­¡£

 

SHTTP²ÉÓÃÒ»ÖÖºÍSSL²»Í¬µÄ·½·¨¡£Ëüͨ¹ýÀ©Õ¹HTTPЭÒé(Ó¦Óòã)À´ÔË×÷£¬ÓÅÓÚÒ»¸ö½ÏµÍ²ã¡£Òò´Ë£¬¾¡¹ÜSSL¿ÉÒÔÓ¦ÓÃÓÚËùÓеÄÍøÂç·þÎñ£¬

È»¶øSHTTPÊÇÒ»¸öÌض¨µÄWebЭÒé

 

ÁíÍ⣬»¹ÓÐÆäËüµÄÓŵ㡣×÷ΪHTTPµÄÀ©Õ¹¼¯£¬SHTTPÈ«¼æÈÝÓÚHTTPºÍSHTTPµÄä¯ÀÀÆ÷ºÍ·þÎñÆ÷¡£ÎªÁËʹÓÃSSL,Äã±ØÐëÓÐÒ»¸öÖ§³ÖSSLµÄä¯

ÀÀÆ÷ºÍ·þÎñÆ÷¡£ÁíÍ⣬SHTTPÊÇÒ»¸ö¸üÁé»îµÄЭÒé¡£ÀýÈ磬Õâ¸ö·þÎñÆ÷¿ÉÒÔÖ¸¶¨Ê×Ñ¡µÄ¼ÓÃÜ·½°¸¡£

 

SHTTP´¦ÀíÒÀÀµÓÚ¸½¼ÓµÄHTTPÍ·¡£Òò´Ë£¬Èç¹ûÄãÏëÈÃÄãµÄCGI³ÌÐò²ÉÓÃSHTTPµÄ¼ÓÃÜ´¦Àí£¬ÄãÐèÒª°üº¬Êʵ±µÄÍ·¡£ÀýÈ磬Ìæ»»¼òµ¥·µ»ØHTT

PÍ·¡£

 Content-type:text/html

 

µ±Ò»¸öSHTTP·þÎñÆ÷´ÓCGIÓ¦ÓóÌÐòÖÐÊÕµ½Õâ¸öÐÅÏ¢£¬Ëü»áÖªµÀÔÚ½«Æä·¢Ë͵½ä¯ÀÀÆ÷֮ǰ½«ÐÅÏ¢¼ÓÃÜ¡£Ò»¸ö·ÇSHTTPµÄä¯ÀÀÆ÷½«ºöÂÔ¸½¼ÓµÄ

Í·¡£

 

 ¹ØÓÚʹÓÃSHTTPµÄ¸ü¶àµÄÐÅÏ¢£¬Çë²ÎÕÕSHTTPµÄ˵Ã÷Êé:

http://www.commerce.net/information/standards/drafts/shttp.txt

2.1.3 ½Å±¾½âÎö

ÏÂÃæÊÇÎÒÒÔǰдµÄÒ»¶Îasp½Å±¾£¬×öÁËһЩÐ޸ģ¬°ÑËûÌù³öÀ´£¬Èôó¼Ò¿´¿´ÎÒ¼ÓÈëÁËÉèÖã¬ÄÇÀï×öµÄ²»¹»ºÃ¡£ÎÒÔÚÕâÀï¾Í²»¶à˵ÁË£¬ÓÐÐËȤ¿É

ÒÔµ½

ÎÒµÄÂÛ̳À´´ó¼ÒÌÖÂÛ¡£

<!--#include file="conn.asp"-->

<%

dim errmsg

if request.form("username")="" then

ErrMsg="Óû§Ãû²»ÄÜΪ¿Õ"

foundError=True

else

UserName=request.form("UserName")

end if

if request.form("password")="" then

  ErrMsg="ÃÜÂë²»ÄÜΪ¿Õ"

  foundError=True

else

  PassWord=request.form("PassWord")

end if

if FoundError=true then

  showAnnounce(ErrMsg)

else

  set rstmp=server.createobject("adodb.recordset")

  if Request.ServerVariables("REQUEST_METHOD") = "POST" then

    rstmp.open "Select * from User Where userName='" & UserName & "'",conn,3,3

    if rstmp.bof then

      session.contents("UserName")=UserName

      rstmp.addnew

      rstmp("username")=username

      rstmp("userpassword")=password

      rstmp("logins")=1

      rstmp("online")=1

      rstmp.update

      response.redirect("index.asp")

    elseif PassWord<>rstmp("userpassword") then

        ErrMsg="ÃÜÂë´íÀ²"

        foundError=True

        showAnnounce(ErrMsg)

      else

        session.contents("UserName")=UserName

        rstmp("logins")=rstmp("logins")+1

        rstmp("online")=1

        rstmp.update

        rstmp.close

        Set rstmp=nothing

        response.redirect("index.asp")

      end if

  else

    if session.contents("UserName")<>"" then

      rstmp.open "Select * from User Where userName='"&session.contents("UserName")&"'",conn,3,3

      rstmp("logins")=rstmp("logins")+1

      rstmp("online")=1

      rstmp.update

      rstmp.close

      Set rstmp=nothing

      conn.close

      set conn=nothing

      response.redirect("index.asp")

    end if

  end if

end if

%>

<html>

<head>

<title></title>

<link rel="stylesheet" type="text/css" href="forum.css">

</head>

<body>

<%

function showAnnounce(ErrMsg)

on error resume next

response.write "<p align=center><font color='red'><strong><Big>?¹þ¹þ</big></strong></font><BR><font

color='#0000FF'>"+ErrMsg+"</font><BR>"+chr(13)+chr(10)

%>

<tr>

<td width="100%">

<p align="center"><br>

<form action="login.asp" method="post">

ÊäÈë<INPUT name=username size=8 class='smallInput'>

<BR>¹þ¹þ<INPUT name=password size=8 class='smallInput' type=password>

</td>

</tr>

<tr>

<td width="100%">

<p align="center"><br>

<INPUT type="submit" name="B12" class='buttonface' value=¦Ì???>

<font color="#FF0000"><br> <br>

*</font>´íÁË

</td> </form>

</tr>

<%

end function

%>

###---checklogin.asp

<%

dim adname

dim passwd

adname=Request.Form("adname")

passwd=Request.Form("passwd")

if adname="" then

 response.redirect "login.asp"

end if

if passwd="" then

   response.redirect "login.asp"

end if

if adname="focus-admin" and passwd="1" then

  response.redirect "manage.asp"

 else

   response.redirect "login.asp"

end if

%>

###---checklogin.asp----end

###---manage.asp

<%

dim where

dim where1

dim refererURL

dim refererURL2

dim refererURL3

refererURL=phyURL&"login.as"

refererURL2=phyURL&"edit.asp"

refererURL3=phyURL&"manage.a"

refererURL4=phyURL&"savearti"

where=Request.ServerVariables("HTTP_REFERER")

where=left(where,(len(phyURL)+8))  

if where<>refererURL and where<> refererURL2 and where<>refererURL3 and where<>refererURL4 then

      Response.Redirect "login.asp"

  end if

  const MaxPerPage=20

  dim totalPut 

  dim CurrentPage

  dim TotalPages

  dim i,j

  if not isempty(request("page")) then

   currentPage=cint(request("page"))

  else

   currentPage=1

  end if

 

%>

###---manage.asp-----end

2.2  cookieµÄÎÊÌâ

2.2.1 ¸ÅÄî½éÉÜ

°´ÕÕNetscape¹Ù·½ÎĵµÖеĶ¨Ò壬CookieÊÇÔÚHTTPЭÒéÏ£¬·þÎñÆ÷»ò½Å±¾¿ÉÒÔά»¤¿Í»§¹¤×÷Õ¾ÉÏÐÅÏ¢µÄÒ»ÖÖ·½Ê½¡£CookieÊÇÓÉWeb·þÎñÆ÷

±£´æÔÚÓû§ä¯ÀÀÆ÷ÉϵÄС¹ãÎ÷Îļþ£¬Ëü¿ÉÒÔ°üº¬ÓйØÓû§µÄÐÅÏ¢£¨ÈçÉí·Ýʶ±ðºÅÂë¡¢ÃÜÂë¡¢Óû§ÔÚWebÕ¾µã¹ºÎïµÄ·½Ê½»òÓû§·ÃÎʸÃÕ¾µãµÄ

´ÎÊý£©¡£ÎÞÂÛºÎʱÓû§Á´½Óµ½·þÎñÆ÷£¬WebÕ¾µã¶¼¿ÉÒÔ·ÃÎÊCookieÐÅÏ¢¡£

ͨË׵ؽ²£¬ä¯ÀÀÆ÷ÓÃÒ»¸ö»ò¶à¸öÏÞ¶¨µÄÎļþÀ´Ö§³ÖCookie¡£ÕâЩÎļþÔÚʹÓÃWindows²Ù×÷ϵͳµÄ»úÆ÷ÉϽÐ×öCookieÎļþ£¬ÔÚMacintosh»úÆ÷

ÉϽÐ×ömagic Cookie

Îļþ£¬ÕâЩÎļþ±»ÍøÕ¾ÓÃÀ´ÔÚÉÏÃæ´æ´¢CookieÊý¾Ý¡£ÍøÕ¾¿ÉÒÔÔÚÕâЩCookieÎļþÖвåÈëÐÅÏ¢£¬ÕâÑù¶ÔÓÐЩÍøÂçÓû§¾ÍÓÐЩ¸±×÷Óá£ÓÐЩÓû§

ÈÏΪÕâÔì³ÉÁ˶ԸöÈËÒþ˽µÄÇÖ·¸£¬¸üÔãµÄÊÇ£¬ÓÐЩÈËÈÏΪCookieÊǶԸöÈË¿Õ¼äµÄÇÖÕ¼£¬¶øÇÒ»á¶ÔÓû§µÄ¼ÆËã»ú´øÀ´°²È«ÐÔµÄΣº¦¡£

Ä¿Ç°ÓÐЩCookieÊÇÁÙʱµÄ£¬ÁíһЩÔòÊdzÖÐøµÄ¡£ÁÙʱµÄCookieÖ»ÔÚä¯ÀÀÆ÷Éϱ£´æÒ»¶Î¹æ¶¨µÄʱ¼ä£¬Ò»µ©³¬¹ý¹æ¶¨µÄʱ¼ä¸ÃCookie¾Í»á±»ÏµÍ³

Çå³ý¡£ÀýÈçÔÚPHPÖÐCookie±»ÓÃÀ´¸ú×ÙÓû§½ø³ÌÖ±µ½Óû§À뿪ÍøÕ¾¡£³ÖÐøµÄCookieÔò±£´æÔÚÓû§µÄCookieÎļþÖУ¬ÏÂÒ»´ÎÓû§·µ»Øʱ£¬ÈÔÈ»

¿ÉÒÔ¶ÔËü½øÐе÷Óá£

ÒªÁ˽âCookie£¬±Ø²»¿ÉÉÙµØÒªÖªµÀËüµÄ¹¤×÷Ô­Àí¡£Ò»°ãÀ´Ëµ£¬Cookieͨ¹ýHTTPHeaders´Ó·þÎñÆ÷¶Ë·µ»Øµ½ä¯ÀÀÆ÷ÉÏ¡£Ê×ÏÈ£¬·þÎñÆ÷¶ËÔÚÏìÓ¦

ÖÐÀûÓÃSet-Cookie headerÀ´´´½¨Ò»¸öCookie£¬È»ºó£¬ä¯ÀÀÆ÷ÔÚËüµÄÇëÇóÖÐͨ¹ýCookie header°üº¬Õâ¸öÒѾ­´´½¨µÄCookie£¬²¢ÇÒ·´Ëü·µ»Ø

ÖÁ·þÎñÆ÷£¬´Ó¶øÍê³Éä¯ÀÀÆ÷µÄÂÛÖ¤¡£ÀýÈ磬ÎÒÃÇ´´½¨ÁËÒ»¸öÃû×ÖΪloginµÄCookieÀ´°üº¬·ÃÎÊÕßµÄÐÅÏ¢£¬´´½¨Cookieʱ£¬·þÎñÆ÷¶ËµÄHeaderÈç

ÏÂÃæËùʾ£¬ÕâÀï¼ÙÉè·ÃÎÊÕßµÄ×¢²áÃûÊÇ"Michael Jordan"£¬Í¬Ê±»¹¶ÔËù´´½¨µÄCookieµÄÊôÐÔÈçpath¡¢domain¡¢expiresµÈ½øÐÐÁËÖ¸¶¨¡£

Set-Cookie:login=Michael Jordan;path=/;domain=msn.com;

expires=Monday,01-Mar-99 00:00:01 GMT

ÉÏÃæÕâ¸öHeader»á×Ô¶¯ÔÚä¯ÀÀÆ÷¶Ë¼ÆËã»úµÄCookieÎļþÖÐÌí¼ÓÒ»Ìõ¼Ç¼¡£ä¯ÀÀÆ÷½«±äÁ¿ÃûΪ"login"µÄCookie¸³ÖµÎª"Michael Jordon"¡£×¢Òâ

£¬ÔÚʵ¼Ê´«µÝ¹ý³ÌÖÐÕâ¸öCookieµÄÖµÊǾ­¹ýÁËURLEncode·½·¨µÄURL±àÂë²Ù×÷µÄ¡£

Õâ¸öº¬ÓÐCookieÖµµÄHTTP

Header±»±£´æµ½ä¯ÀÀÆ÷µÄCookieÎļþºó£¬Header¾Í֪ͨä¯ÀÀÆ÷½«Cookieͨ¹ýÇëÇóÒÔºöÂÔ·¾¶µÄ·½Ê½·µ»Øµ½·þÎñÆ÷

£¬Íê³Éä¯ÀÀÆ÷µÄÈÏÖ¤²Ù×÷¡£

´ËÍ⣬ÎÒÃÇʹÓÃÁËCookieµÄһЩÊôÐÔÀ´ÏÞ¶¨¸ÃCookieµÄʹÓá£ÀýÈçDomainÊôÐÔÄܹ»ÔÚä¯ÀÀÆ÷¶Ë¶ÔCookie·¢ËͽøÐÐÏÞ¶¨£¬¾ßÌåµ½ÉÏÃæµÄÀý×Ó

£¬¸ÃCookieÖ»ÄÜ´«´ïÊÒµ½Ö¸¶¨µÄ·þÎñÆ÷ÉÏ£¬¶ø¾ö²»»áÅܵ½ÆäËûµÄÈçwww.hp.comµÄWebÕ¾µãÉÏÈ¥¡£ExpiresÊôÐÔÔòÖ¸¶¨Á˸ÃCookie±£´æµÄʱ

¼äÆÚÏÞ£¬ÀýÈçÉÏÃæµÄCookieÔÚä¯ÀÀÆ÷ÉÏÖ»±£´æµ½1999Äê3ÔÂ1ÈÕ1Ãë¡£µ±È»£¬Èç¹ûä¯ÀÀÆ÷ÉÏCookieÌ«¶à£¬³¬¹ýÁËϵͳËùÔÊÐíµÄ·¶Î§£¬ä¯ÀÀÆ÷½«

×Ô¶¯¶ÔËü½øÐÐɾ³ý¡£ÖÁÓÚÊôÐÔPath£¬ÓÃÀ´Ö¸¶¨Cookie½«±»·¢Ë͵½·þÎñÆ÷µÄÄÄÒ»¸öĿ¼·¾¶Ï¡£

˵Ã÷£ºä¯ÀÀÆ÷´´½¨ÁËÒ»¸öCookieºó£¬¶ÔÓÚÿһ¸öÕë¶Ô¸ÃÍøÕ¾µÄÇëÇ󣬶¼»áÔÚHeaderÖдø×ÅÕâ¸öCookie£»²»¹ý£¬¶ÔÓÚÆäËûÍøÕ¾µÄÇëÇóCookie

ÊǾø¶Ô²»»á¸ú×Å·¢Ë͵ġ£¶øÇÒä¯ÀÀÆ÷»áÕâÑùÒ»Ö±·¢ËÍ£¬Ö±µ½Cookie¹ýÆÚΪֹ¡£

2.2.2 Òªµã·½·¨

setcookie-----Ëͳö Cookie ÐÅÏ¢µ½ä¯ÀÀÆ÷¡£

Óï·¨: int setcookie(string name, string value, int expire, string path, string domain, int secure);

·µ»ØÖµ: ÕûÊý

±¾º¯Êý»á¸ú×űêʶ Header ËͳöÒ»¶ÎСÐÅÏ¢×Ö·û´®µ½ä¯ÀÀÆ÷¡£Ê¹Óñ¾º¯ÊýÒªÔÚËͳö HTML Êý¾ÝÇ°£¬Êµ¼ÊÉÏ cookie

Ò²Ëã±êʶµÄÒ»²¿·Ý¡£±¾º¯ÊýµÄ²ÎÊý³ýÁ˵ÚÒ»¸ö name Ö®Í⣬¶¼ÊÇ¿ÉÒÔÊ¡ÂԵġ£²ÎÊý name ±íʾ cookie µÄÃû³Æ£»value ±íʾÕâ¸ö cookie

µÄÖµ£¬Õâ¸ö²ÎÊýΪ¿Õ×Ö·û´®Ôò±íʾȡÏûä¯ÀÀÆ÷Öиà cookie µÄÊý¾Ý£»expire ±íʾ¸Ã cookie µÄÓÐЧʱ¼ä£»path Ϊ¸Ã cookie

µÄÏà¹Ø·¾¶£»domain ±íʾ cookie µÄÍøÕ¾£»secure ÔòÐèÔÚ https µÄ°²È«´«Êäʱ²ÅÓÐЧ¡£ÏëµÃµ½¸ü¶àµÄ cookie ÐÅÏ¢¿ÉÒÔµ½

http://www.netscape.com/newsref/std/cookie_spec.html£¬ÓÉ

cookie Ô­´´Õß Netscape ËùÌṩµÄÍêÕûÐÅÏ¢¡£

¶ÔÓÚÒ»¸öÍøÕ¾»áÔ±¶øÑÔ£¬¾­³£´æÔÚÐèÒªÒ»´Î×¢²á£¬¶à´ÎÈÏÖ¤µÄÎÊÌ⣬ÀýÈçÎÒÃǾ­³£½Ó´¥µ½µÄÂÛ̳¡¢ÉçÇøµÈ£¬Ò»°ã²ÉÓÃÊÖ¶ÎΪcookie»ò input

type=hiddenÀ´´«µÝÈÏÖ¤²ÎÊý¡£ÕâÀïÃæÓм¸µãÒþ»¼£º

  I.  

setcookieÄÚÈݱØÐëÍêÕû°üº¬ÕʺÅÃÜÂ룬»òÀàËƵÄÍêÕû°²È«ÐÅÏ¢£¬Èç¹ûֻЯ´øÕʺÅÐÅÏ¢»òÓÃijÖÖȨÏÞ±êÖ¾À´ÈÏÖ¤£¬¼«ÈÝÒ×Ôì³É·Ç·¨ÈëÇÖ¡£Àý

ÈçijվµãÖеĻáÔ±¸üÐÂÒ³ÃæÖÐЯ´øµÄÈÏÖ¤ÐÅÏ¢ÊÇÁ½¸ö£¬Óû§ÃûºÍUid(¾ùΪÃ÷ÎÄ´«ËÍ)ÒÑÖªUid¶ÔÓÚÿ¸ö»áÔ±ÊÇΨһµÄ¡£ÓÉÓÚÎÒÃÇÖ»ÐèÒªÖªµÀ

¶Ô·½µÄÕʺźÍUid¾Í¿ÉÒÔ¸ü¸Ä¶Ô·½ÐÅÏ¢£¨²»ÐèÒªÖªµÀÃÜÂ룡£©£¬Ö»Òª¹¥»÷ÕßÖªµÀUid£¨¹¥»÷Õß¿ÉÒÔͨ¹ý±©Á¦²Â²âµÄ·½·¨À´µÃµ½Uid£¬ÓÐʱºòÕ¾

µã±¾ÉíÒ²»áй¶Óû§µÄUid,ÀýÈçÔÚÂÛ̳µÈ´¦£©ÄÇô£¬¹¥»÷Õ߾ͿÉÒÔͨ¹ý±éÀú¹¥»÷Íê³É¶ÔÈÎÒâÒ»¸öÕʺŵÄÐÅÏ¢¸ü¸Ä¡£

  

  II.  

±ØÐëËùÓÐÐèҪȨÏÞ²Ù×÷µÄÒ³Ã涼±ØÐëÖ´ÐÐÈÏÖ¤ÅжϵIJÙ×÷¡£Èç¹ûÈκÎһҳûÓнøÐÐÕâÖÖÈÏÖ¤Åжϣ¬¶¼ÓпÉÄܸø¹¥»÷ÕßÒÔ¶ñÒâÈëÇֵĻú»á¡£

  

 III. 

ºÜ¶àÍøվΪÁË·½±ã£¬½«Óû§ÃûÒÔ¼°¿ÚÁîÐÅÏ¢´¢´æÔÚCookieÖУ¬ÓеÄÉõÖÁÒÔÃ÷ÎÄ·½Ê½±£´æ¿ÚÁî¡£Èç¹û¹¥»÷Õß¿ÉÒÔ·ÃÎʵ½Óû§µÄÖ÷»ú£¬¾Í¿ÉÄÜͨ

¹ý±£´æµÄCookieÎļþµÃµ½Óû§ÃûºÍ¿ÚÁî¡£

3.  ½Å±¾±£»¤µÄÎÊÌâ

3.1 ¸ÅÄî½éÉÜ

ÔÚ³ÌÐò±àдʱÓÅÐãµÄ³ÌÐòÔ±¶¼»áÖªµÀ£¬ÓÃÓÐÒâÒåµÄ±äÁ¿Ãû£¬ÎļþÃûÓÐÖúÓÚÔö¼Ó³ÌÐòµÄ¿É¶ÁÐÔ£¬¾ßÓÐÁ¼ºÃµÄ³ÌÐò·ç¸ñ¡£Õâ¸ö·Ç³£ºÃµ«Ôڽű¾Óï

ÑÔ²»Ì«Êʺϣ¬ÎªÁ˲»ÈöñÒâÓû§²Âµ½ÄãµÄ±äÁ¿»òÊý¾Ý¿âÃûµÈÐÅÏ¢£¬±ØÐë¸ÄµôÕâЩÐÅÏ¢¡£¶¯Ì¬µÄÍøÒ³ÔÚ·þÎñÆ÷¶ËÖ´Ðк󷵻ظø¿Í»§µÄÊÇÖ´Ðкó

µÄ´úÂ룬Õâ¿ÉÒÔ±£»¤·þÎñÆ÷¶ËµÄºÜ¶à²»Ïë½Ð»ò²»ÄܽÐä¯ÀÀÕßÖªµÀµÄÐÅÏ¢¡£°²È«ÊÇÏà¶ÔµÄ£¬Ã¿Ì춼ÔÚÓÐÐµİ²È«Â©¶´±»·¢ÏÖ£¬Èç¹û¶ñÒâµÄÓû§

ÔÚÄã֮ǰ֪µÀÁËÒ»¸ö¿ÉÒÔ¿´ÄãµÄ½Å±¾Ô´´úÂëµÄ©¶´»òÕâ¸ö©¶´Ò»Ê±¼äÎÞ·¨ÐÞ²¹Ôõô°ì£¿

3.2 Ö÷ÒâÒªµã

½¨ÒéÓÃһЩ±È½Ï¹ÖÒìµÄÃû×ÖÃüÃû£¬É¾µô½Å±¾ÖеÄ×¢ÊÍ¡£Èç¹û»¹ÐèÒª±£³Ö³ÌÐòµÄ¿É¶ÁÐԵĻ°£¬¿ÉÒÔ½¨Á¢Ò»¸öÓ³É䣬Äã¿ÉÒÔд¸ö¾ßÓÐÁ¼ºÃ·ç¸ñµÄ

½Å±¾³ÌÐò£¬È»ºóÔÙ×öÒ»¸ö±äÁ¿ÃûÓ³É佨Á¢Ò»¸ö¾ßÓнϰ²È«ÃüÃû·½·¨µÄ½Å±¾£¬È¥µôÕâ¸ö½Å±¾ÖеÄ×¢ÊÓºÍËùÓÐÄÜÈ¥µôµÄÐÅÏ¢£¬ÐÞ¸Äʱ×÷¸öͬ²½¾Í

¿ÉÒÔÁËÎÒÃÇ¿ÉÒÔÔÚ³ÌÐòµÄʹÓÃÇ°¶Ô³ÌÐò½øÐмÓÃÜ£¬ÒÔ±£»¤ÎÒÃÇ×Ô¼ºµÄ³ÌÐòÔÙÍòÒ»µÄÇé¿öϲ¿±»Ð¹Â©¡£

3.3 ±£»¤·½·¨

ÎÒ¿´µ½¹ýºÜ¶àµÄ¶Ô½Å±¾µÄ¼ÓÃÜ·½·¨£¬¶¼ºÜ²»´í£¬ÓеÄÊÇרÃŵļÓÃÜÈí¼þ£¬ÓеÄÊÇͨ¹ýһЩ¼¼ÇɼÓÉÏÀûÓÃÓïÑÔµÄÌØÐÔ½øÐмÓÃܵģ¬ÀýÈçËæ»úÉú

³ÉÒ»¸öÃܳף¬°ÑÃܳ׷ÅÔÚ"²»¿É¼ûµÄ"µØ·½£¬Í¨¹ýһЩËã·¨¶Ô½Å±¾½øÐмӽâÃÜ£¬¾ÍÊÇÓÉÓÚijЩϵͳ©¶´µ¼ÖÂÄãµÄ½Å±¾Ô´´úÂëй©£¬Ò²ÎÞ¼ÃÓÚÊ¡£

4 .ʵÀý˵Ã÷

ÏÂÃæÕâ¸öÀý×ÓÊÇÔÚÍøÉϾ­³£±»Ìáµ½µÄ£¬ÕâÊǸö·Ç³£¾­µäµÄÀý×Ó£¬ËùÒÔÔÚÕâÀïͨ¹ýÕâ¸öʵÀý¸æËß´ó¼Ò¿ÉÄÜ´æÔÚµÄΣÏÕ¡£

ÎÊÌâÃèÊö£º

¡¡¡¡´ó²¿·ÖÍøÕ¾°ÑÃÜÂë·Åµ½Êý¾Ý¿âÖУ¬ÔڵǽÑéÖ¤ÖÐÓÃÒÔÏÂsql,(ÒÔaspΪÀý£©

sql="select * from user where username='"&username&"'and pass='"& pass &'"

¡¡¡¡´Ëʱ£¬ÄúÖ»Òª¸ù¾Ýsql¹¹ÔìÒ»¸öÌØÊâµÄÓû§ÃûºÍÃÜÂ룬È磺ben' or '1'='1

¾Í¿ÉÒÔ½øÈë±¾À´ÄãûÓÐÌØȨµÄÒ³Ãæ¡£ÔÙÀ´¿´¿´ÉÏÃæÄǸöÓï¾ä°É£º

sql="select * from user where username='"&username&"'and pass='"& pass&'"

¡¡¡¡´Ëʱ£¬ÄúÖ»Òª¸ù¾Ýsql¹¹ÔìÒ»¸öÌØÊâµÄÓû§ÃûºÍÃÜÂ룬È磺ben' or '1'='1 ÕâÑù,³ÌÐò½«»á±ä³ÉÕâÑù: sql="select*from username where

username="&ben'or'1'=1&"and pass="&pass&" or ÊÇÒ»¸öÂß¼­ÔËËã·û,×÷ÓÃÊÇÔÚÅжÏÁ½¸öÌõ¼þµÄʱºò,Ö»ÒªÆäÖÐÒ»¸öÌõ¼þ³ÉÁ¢,ÄÇôµÈʽ

½«»á³ÉÁ¢.¶øÔÚÓïÑÔÖÐ,ÊÇÒÔ1À´´ú±íÕæµÄ(³ÉÁ¢).ÄÇôÔÚÕâÐÐÓï¾äÖÐ,Ô­Óï¾äµÄ"and"ÑéÖ¤½«²»ÔÙ¼ÌÐø,¶øÒòΪ"1=1"ºÍ"or"ÁîÓï¾ä·µ»ØΪÕæÖµ.¡£

¡¡¡¡ÁíÍâÎÒÃÇÒ²¿ÉÒÔ¹¹ÔìÒÔϵÄÓû§Ãû£º

username='aa' or username<>'aa'

pass='aa' or pass<>'aa'

¡¡¡¡ÏàÓ¦µÄÔÚä¯ÀÀÆ÷¶ËµÄÓû§Ãû¿òÄÚдÈ룺aa' or username<>'aa ¿ÚÁî¿òÄÚдÈ룺aa' or pass<>'aa,×¢ÒâÕâÁ½¸ö×Ö·û´®Á½Í·ÊÇûÓÐ'µÄ¡£Õâ

Ñù¾Í¿ÉÒԳɹ¦µÄÆ­¹ýϵͳ¶ø½øÈë¡£

¾ßÌåʵʩÊÇÕâÑùµÄ£¬Ê×ÏÈÎһᵽע²áµÄµØ·½È¥ÊÕ¼¯ÐÅÏ¢£¬Á˽⾡¿ÉÄܶàµÄÐÅÏ¢£¬ÀýÈçÄ¿±êÊý¾Ý¿âÖж¼ÓÐÓû§µÄʲôÑùµÄÐÅÏ¢£¬Ëæ±ãµÄÌîдÐÅ

ϢȻºóÌá½»£¬µ±ÄãҪע²áµÄÓû§Ãû±»×¢²áµÄÊÇÓÐϵͳ»áÌáʾÄãÒѱ»×¢²á£¬ÓеÄÍøÕ¾×öµÄ¸üºÃµÄ£¬¾ÍÊÇËûÃÇרßøÄãÉèÖõļì²âÊÇ·ñÓÐÒѾ­±»

×¢²áµÄ¹¦ÄÜ£¬Í¨¹ýÕâÑù¾Í»á·Ç³£ÈÝÒ×µÄÕÒµ½Ä¿±ê--ÄǸöÌáʾÒѱ»×¢²áµÄÓû§£¬ÈúóÄãÔÚÕâ¸ö×¢²áÒ³ÀïÌîдһЩÌØÊâµÄ×Ö·û£¬Èç'£¬/£¬,µÈ×Ö·û¿´

ϵͳÈçºÎÌáʾ£¬ÒÔÖ¤Ã÷³ÌÐòÔ±ÊÇ·ñ×¢Òâµ½ÁËÓ¦¸Ã¹ýÂË×Ö·û»ò¶®µÃÊÇ·ñÓ¦¸Ã¹ýÂËÄÇЩ×Ö·û£¬ÔÚÕâÒ³½øÐг¢ÊÔÊÇÒòΪÓеÄÍøÕ¾ÔڵǼµÄʱºòËû»á

¼Ç¼ÄãµÄipµØÖ·£¬µ±È»ÄãÒ²¿ÉÒÔÕÒÒ»¸ö±ÈÄãÖ±½ÓµÇ¼Ҫ¿ìµÄ´úÀí·þÎñÆ÷À´×öÌø°å¡£ºóÃæÄãÒª×öµÄ¾ÍÊDz쿴µÇ¼ҳµÄhtmlÔ´´úÂ룬¿´¿´ÊÇ·ñÓÐÔÚ

¿Í»§¶ËµÄ×Ö·û¹ýÂË£¬¿´¿´Õâ¸ö³ÌÐòÔ±ÊÇÓÃʲô·ç¸ñÀ´±àд³ÌÐò£¬¾¡¿ÉÄܶàµÄÁ˽â³ÌÐò±àд·ç¸ñ£¬Õâ¶ÔÄãÒÔºóµÄijЩÅжÏÓкô¦¡£Èç¹ûÓÐÔÚ¿Í

»§¶ËµÄ¹ýÂËÒ²²»Å£¬ÄãÒª¸ãÇåÊÇʲôÑùµÄ¹ýÂË£¬Äܲ»ÄܶԹ¥»÷Ôì³ÉÍþв£¬²»ÒªÒ»¿´ÓйýÂ˾ͺ¦Å£¬¿ÉÒÔ³¢ÊÔ×ÅÓñðµÄ·½·¨ÈÆ£¬¾ÍÊÇʹÓÃ×Ô¼º

¾«ÐÄ´òÔìµÄ¶ÀÁ¢½Å±¾£¬½øÐй¥»÷¡£È»ºóÄãÒª¿´¿´formµÄactionÖеÄurlÊÇ·ñ¿ÉÒÔÖ±½ÓÌá½»£¬ÔÚä¯ÀÀÆ÷µØÖ·À¸ÀïÖ±½ÓÌá½»£¬¿´¿´·µ»Øʲô£¬ÊÇ·ñ

ÓÐÀ´Â·¼ì²â¡£»¹ÓкܶàϸСµÄµØ·½£¬ÄãÒ²Ó¦¸Ã¿ÉÒÔ×¢Òâµ½£¬ÀýÈçÄÇЩµØ·½³ÌÐòÔ±µÄÕûÌåµÄ±àд·ç¸ñÊÇʲô£¬±äÁ¿Ãû¶¨ÒåµÄ·ç¸ñÊÇʲôµÈµÈ£¬

Õâ¸ö»á°ïÎÒÃÇ"²Â"µ½ºÜ¶à¶«Î÷¡£»¹ÓбðµÄÆäËûʲô£¬ÎÒÒ²¼Ç²»Ì«Çå³þÁË£¬ÁÙ³¡·¢»Ó°É¡£Í¨¹ýÕâЩÁ˽âÎÒÃÇÓÐÈçϼ¸ÖÖ¿ÉÄÜ£º

1.ÄǸö³ÌÐòÔ±·Ç³£ÉÆÁ¼ÏàÐÅÈ«ÊÀ½ç¶¼ÊǺÃÈË£¬Ê²Ã´¶¼Ã»×ö£¬¸ù±¾Ã»ÓÐÈκμì²â»úÖÆ£¬ÎÒÃÇÖ±½ÓÓÃusername='aa' or username<>'aa'£¬

pass='aa' or pass<>'aa'¾Í¿ÉÒԸ㶨£¬ÏÖÔÚÕâôÉÆÁ¼µÄÈËÉÙÀ²£¬¿ÉÊÇÄãÒªÊÇÓÐÄÍÐÄ£¬ÕÒµ½ÕâÖÖÈË»¹ÊDz»Äѵġ£

2.Õâ¸ö³ÌÐòÔ±¿ÉÄÜÌý±ðÈËÌáÆð¹ýһЩ°²È«ÎÊÌ⣬±Ï¾¹ÏÖÔÚÕâ¸öÄÇÀﶼÓÐÈË˵£¬ºÜ¶àÊéÖж¼ÓÐÌá¼°£¬µ«ÊÇ×öµÃ²»¹»ºÃ£¬ËûÖ»½øÐÐÁ˼òµ¥µÄÊäÈë¹ý

ÂË¡£¹ýÂËÓÐÁ½ÖÖ·½Ê½£¬Ò»ÖÖÊÇÔÚ¿Í»§¶ËµÄ¹ýÂË£¬Ò»ÖÖÊÇÔÚ·þÎñÆ÷¶ËµÄ¹ýÂË¡£ÏÖÔںܶàµÄ³ÌÐòÔ±¿¼Âǵ½ÔÙ·þÎñÆ÷¶Ë½øÐйýÂË¿ÉÄܸø·þÎñÆ÷Ôì³É

¸ü¶àµÄ¸ººÉ£¬»á°Ñ¼ì²â¹ý³Ì·ÅÔÚ¿Í»§¶Ë¡£Èç¹ûËûÔÚ·þÎñÆ÷¶Ëû×öÈκÎÊÂÇ飬ÄÇô»¹ÊÇ¿ÉÒÔ¶ÔÆä½øÐй¥»÷µÄ£¬ÎÒ¿ÉÒÔ½«Õâ¸öµÇ¼ҳµÄÔ´´úÂëCO

PYÏÂÀ´£¬È»ºó×Ô¼º½¨Á¢Ò»¸öÎļþ°ÑÕâЩ´úÂëPASTE½øÈ¥£¬ÔÙ¶ÔÕâ¸öÎļþ½øÐнøÒ»²½µÄÉî¼Ó¹¤£¬È¥µôÔ­À´Ò³µÄ¹ýÂË»úÖÆ£¬»òÕßÖ±½Ó½«¹¥»÷´úÂë

дµ½Õâ¸öÎļþÖÐÈ¥£¬È»ºó½«formÖеÄactionÖеĵØÖ·¸Ä³É¾ø¶ÔµØÖ·£¬Ò²¾ÍÊǽ«ÎļþÃû¸Ä³É"http://www.target.com/targer.php"ÕâÑù£¬È»ºó

¾Í¿ÉÒÔÌá½»À²¡£µ«ÊÇÈç¹û·þÎñÆ÷¶Ë¼ÓÉÏÁË"À´Â·¼ì²â"£¬Äã¾Í°×ÍæÁË¡£Èç¹ûÕâÑù»¹ÊDz»ÐУ¬ÎÒÔÙ»»Ò»ÖÖ·½·¨£¬ÔÚä¯ÀÀÆ÷µÄµØÖ·À¸ÀïÓã¿À´ÊäÈë²Î

Êý£¬¾ÍºÃÏñ"http://www.targer.com/targer.php?username='aa' or username<>'aa'&pass='aa' or pass<>'aa'

"È»ºóÇûسµ°É£¬ÆäʵӦ¸ÃÏȳ¢ÊÔÕâÖÖ·½·¨ÒòΪÕâÓ÷½·¨¸ü¼òµ¥£¬·À»¤ÆðÀ´Ò²ºÜ¼òµ¥£¬ÕâÖÖÌá½»·½Ê½²»ÊÇpost ¶øÊÇget

£¬Ö»Òª·þÎñÆ÷¶Ë³ÌÐò¼ì²âÄãµÄÌá½»·½·¨£¬¾Í¿ÉÒÔkillµôÕâ¸öÒõı¡£Èç¹ûµ¥´¿µÄÖ»¼ì²âÁË"À´Â·"£¬»¹ÊDz»Ì«°²È«µÄ£¬¿ÉÒÔÏÈÕýÈ·µÄÌá½»Ò»´Î£¬ÔÚ

Ìá½»¹ý³ÌÖÐÂíÉÏÍ£Ö¹£¬¾ÍÊDZ£´æÕâ¸ö»·¾³£¬È»ºóÔÙ¹¹ÔìÇëÇó.ÎÒ×ö¹ý¼¸´ÎÊÔÑéµÃµ½µÄ½á¹û¶¼²»Ì«Ò»Ñù£¬Ó¦¸ÃÊǺÍÖÕÖ¹µÄʱ»úÓйأ¬»¶Ó­´ó¼ÒÀ´

½»Á÷£©¡£

3.Ò»¸öºÜ³öÉ«µÄ³ÌÐòÔ±£¬°²È«Òâʶ·Ç³£¸ß£¬ËûÔÚ·þÎñÆ÷¶Ë×öÁËÈçϼì²â£º¼ì²âÌá½»µÄ·½·¨£»¼ì²âÌá½»µÄ"À´Â·"£»¼ì²âÌá½»ÄÚÈݵij¤¶È£»È«Ãæ¼ì

²âÌá½»ÄÚÈÝ£¬ÕâÑùÎÒÃǾͺÜÄÑͨ¹ýÉÏÃæµÄ·½·¨¶ÔÆä½øÐй¥»÷£¬Äǵ½±£ÃܵÄ×ÊÁϾÍÒѾ­²»Ì«¿ÉÄÜÁË£¨Èç¹û¸÷λ»¹ÓÐʲôºÃµÄ°ì·¨£¬ÇëÒ»¶¨À´ÐÅ

¸æËßСµÜ£¬Ð¡µÜÔÚÕâÀïÏÈлÁË£©¡£µ«ÊÇÎÒ»¹Ïë˵µÄÊǹ¥»÷²¢²»´ú±íÊÇ·ÇÒªÈëÇÖ½øÈ¥£¬Äõ½Ä³Ð©¶«Î÷²Å½ÐÈëÇÖ£¬¶ÔÄãµÄ»úÆ÷½øÐÐÆÆ»µÒ²½ÐÈëÇÖ

°¡£¬ÀýÈçÌύһЩ´íÎóµÄÇëÇ󣬽ű¾½âÊͳÌÐò¾Í»á·Ç³£¹æ¾ØµÄ¸øÄã·µ»Ø´íÎóÐÅÏ¢£¬×îdzÏԵĺó¹û¾ÍÊDZ©Â¶ÎïÀí·¾­£¬ÓеÄʱºòһЩÌØÊâµÄÇë

Çó»áʹweb·þÎñå´µô£¬ÕâЩ¸öÎÒÈÏΪ¾ø¶ÔÊÇÊôÓÚ¹¥»÷£¬¾ø¶ÔÊÇΣº¦£¬Ò²ÐíÄãÈÏΪ±©Â¶ÎïÀí·¾¶Ã»ÓÐʲô£¬ÊÇÔÚµ¥¶À¿´À´Ã»ÓÐʲô£¬µ«ÒªÊÇÔÚÒ»

¸öÓмƻ®µÄ¹¥»÷ÀÕâ¸ö¾Í»á·¢»ÓºÜ¶à×÷Óã¬ÄÇʱÄã¿ÉÄÜ»¹»áĪÃûΪʲôËûÃÇÕÒµ½ÁËÎÒµÄÎļþÄØ¡£Ò²ÐíÓÐÈËÈÏΪÕâ¸öÊǽű¾½âÊͳÌÐòµÄbug£¬

Ò²ÐíÓеÄÊÇ£¬µ«ÊÇ·µ»Ø´íÎóÐÅÏ¢¾ø¶Ô²»Êǽű¾½âÊͳÌÐòµÄ´íÎó£¬Õâ¸öÊÇÿ¸ö½âÊͳÌÐò¶¼Òª×öµ½µÄ£¬ÔÚÎÒ¿´À´Õâ¸öÓ¦¸ÃÊÇ»¹ÊdzÌÐòÔ±µÄÎÊÌ⣬

³ÌÐòԱûÓÐ×öºÃ¶Ô´íÎóµÄ´¦Àí¡£Ã¿Ò»±¾½ÌÄãÈçºÎ±àд³ÌÐòµÄÊé¼®Àï»ù±¾¶¼»áÓдíÎó´¦ÀíÖ®ÀàµÄÕ½ڣ¬²¢ÇÒÿÖÖÓïÑÔ»ù±¾¶¼ÓдíÎó´¦Àíº¯ÊýºÍ

·½·¨£¬Ö»²»¹ýÄãûÓÐÏëµ½°ÕÁË¡£ÖÁÓÚ¾¿¾¹ÒªÔõô´¦ÀíÄǾÍÒª¿´Äã¶Ôcgi³ÌÐò°²È«µÄÊìϤ³Ì¶ÈÁË£¬ÄǾÍÒª¿´Äã¶ÔÕâÖֽű¾ÓïÑÔµÄÌØÐÔÊìϤ¶àÉÙÁË

£¬Ëµµ½µ×¾ÍÊǾ­Ñ飬ΨһµÄ°ì·¨¾ÍÊǶ࿴¶àд¶àÏë¶à½»Á÷¡£

4.·Ç³£ÓÅÐãµÄ³ÌÐòÔ±£¬ÒÔÉÏÄÇЩ×öµÄ¶¼·Ç³£ºÃ£¨Ò²Ðí¾ÍÊÇÄã°¡£¬±Ï¾¹²»ÄÑÂ¼ÓÉϺÜÉٵĴúÂë¾Í¿ÉÒÔÁË£©£¬Ôõô°ì£¿£¿Ôõô°ì£¿£¡Ôõô°ì£¡£¡

ÔÚÒ»ÅÔ͵͵µÄÅå·þ°É£¡¹þ¹þ¡£

5. ÆäËü×¢ÒâÊÂÏ˼·ºÍ·½·¨

Ö¸µ¼Ë¼Ï룺

I.Ñϸñ¿ØÖƳÌÐòÓëÓû§½»»¥µÄ;¾¶

II.Ñϸñ¿ØÖƳÌÐòÓëÓû§½»»¥µÄÄÚÈÝ

III.¾¡¿ÉÄܺõı£»¤ÎÒÃÇ¿ØÖÆ

»ù±¾Ë¼Â·£º

I.Ϊûһ¸ö¹¦ÄÜдһ¸ö¶ÀÁ¢µÄ³ÌÐò£¬³ÌÐòÒ³

II.¾¡¿ÉÄÜÉÙµÄÈÿͻ§Á˽âÄãµÄ·þÎñÆ÷¶ËÐÅÏ¢

III.²»ÒªÓÃ"¿Í»§Ó¦¸ÃÕâôд"Õâ¸ö˼·ÏëÎÊÌâ

IV.¾¡¿ÉÄܶàµÄÏëµ½²»¿ÉÄÜ·¢ÉúµÄÊÂÇé

»ù±¾·½·¨£º

¾¡¿ÉÄܶàµÄ¿ØÖƽ»»¥£º

I.¼ì²âÌá½»µÄ·½·¨£¬¾ÍÊÇ¿ØÖÆËûµÄpost»¹ÊÇget£»

II.¼ì²âÌá½»µÄ"À´Â·"£¬¾ÍÊǼì²âÒ»¸ö»·¾³±äÁ¿HTTP_REFERER£»

III.¼ì²âÌá½»ÄÚÈݵij¤¶È£»

IVÈ«Ãæ¼ì²âÌá½»ÄÚÈÝ£»

»ý¼«-Ïû¼«·À»¤£º

I.¾¡¿ÉÄܶàµÄ´íÎó´¦Àí£¬ÀýÈçµ±¼ì²âµ½Á˲»ÕýÈ·µÄÊäÈëʱ£¬Ó¦¸ÃÔõô×ö£¬ÊÇÇ¿ÖÆ·µ»Ø£¬»¹ÊÇ·¢³ö¾¯¸æ£»

II.³ä·Ö·¢»ÓÈÕÖ¾¹¦Óã¬ÀýÈçÔÚÄã¼ì²âµ½Á˲»ÕýÈ·µÄÌύʱ£¬¾Í¼Ç¼Ï¿ͻ§¶ËµÄÐÅÏ¢£¬ÀýÈçIP£¬ÏµÍ³ÅäÖã¬ÇëÇóµÈµÈ£¬±Ï¾¹ÏÖÔÚÊǼ¼Êõ·ÉÔ¾µÄʱ

´ú£¬²»Äܱ£Ö¤¿ÉÒÔÏ뵽ÿһÖÖ¿ÉÄÜ£¬ÕâÒ²ÊÇÎÒÔÚÕâƪÎÄÕÂÀï²»Ö¹Ò»´ÎÌáµ½"¾¡¿ÉÄÜ"Õâ¸ö´ÊµÄÔ­Òò¡£³ä·ÖµÄÈÕÖ¾¼Ç¼²»È«ÊÇΪÁËץסÈëÇÖÕߣ¨Èç

¹ûÈëÇÖÕßʹÓÃÁËÌø°å£¬¼Ç¼ÁËIPÒ²ÊÇûÓÐÓõģ©£¬¸üÖØÒªµÄÊÇΪÁËÄÜ·¢ÏÖÎÊÌâµÄËùÔÚ£¬ÕÒµ½ÎÊÌ⣬¸ÄÕýÎÊÌ⣬ÍöÑò²¹ÀΣ¬Õâ¸ö²ÅÊÇ×îÖØÒªµÄ¡£

III.³ä·Ö·¢»ÓÄãµÄÏëÏóÁ¦£¬ÓÃÒ»ÖÖÈëÇÖÕßµÄ˼Ï뿼ÂÇÎÊÌ⣬ÓÃÒ»ÖÖÁíÀàµÄ˼Ï뿼ÂÇÎÊÌ⣬¾¡¿ÉÄÜÏëµ½²»¿ÉÄÜ·¢ÉúµÄÊ£¬°ÑÎÊÌâ¶óɱÔÚÃÈÑ¿Àï¡£

ÎÒÃÇxundi¸ç˵µÄºÃ£ºÕÆÎÕ·½·¨£¡£¡£¡ÏÖÔڽű¾ÓïÑÔ²ã³ö²»Çasp£¬perl£¬php£¬jspµÈµÈ£¬»ù±¾²»¿ÉÄܾ«Í¨Ã¿Ò»ÖÖ£¬£¨Ò²ÐíÄãÀ÷º¦£¬¶¼Äܾ«Í¨

£¬ÎұȽϴô£¬»áÒ»¸ö¾Í²»´íÀ²£©£¬µ«ÊÇÒªÊÇÕÆÎÕÁË·½·¨¾Í²»Í¬ÁË°¡£¬¸÷λÍøÂçµÄ¾«Ó¢¾ÙÒ»·´Èý´¥ÀàÅÔͨ£¬¿Ï¶¨ÊÇÓÅÐãµÄ²»µÃÁË¡£ÎÒд½Å±¾Ò»

¹²Ò²Ã»¶àÉÙÌ죬дÕâ¸ö¶«Î÷ÎÒÖªµÀ¿Ï¶¨ÊÇ°àÃÅŪ¸«ÁË£¬´íÎóÖ®´¦»¹Çë¸÷λ´óϺ±§×ÅÍì¾ÈºÍ°ïÖúµÄ¾«Éñ£¬¸æ֪СµÜ£¨·½Ê½¡¢·½·¨¡¢Ì¬¶È²»ÏÞ£©

£¬Ð¡µÜÎÒÔÚÕâÀïÏÈлÁË¡£Ð´Õâ¸ö¶«Î÷£¬ÎÒÖ»ÊÇÏë˵˵СµÜµÄһЩСµÄÐĵã¬Óë´ó¼Ò¹²Ã㣬ÎÒÏë¸æËß´ó¼ÒµÄ¾ÍÊÇ"Áì»á¾«Éñ"£¬ºÙºÙ£¬"Áì»á¾«Éñ"

¡£´ó¼ÒÒªÊÇÓÐʲôºÃµÄ·½·¨£¬Ï£Íû²»Òª±£Áô£¬³ä·Ö·¢»ÓÍøÂçµÄ×ÔÓù²Ïí£¬ÄóöÀ´£¬´ó¼Ò½»Á÷½»Á÷£¬²»Ê¤¸Ð¼¤¡£ÕâÀïÓкܶà¸ÅÄîµÄ¶«Î÷ÊÇÎÒ³­

Ï®À´µÄ£¬ÕâÖÖ¶«Î÷СµÜ²»¸Ò×Ô¼ºÐ´£¨ºÙºÙ£¬Êµ¼Ê»¹Óв»ÉÙÀÁµÄ³É·Ö£¬¹þ¹þ£©£¬Ï£Íû´ó¼Ò²»Òª¼û¹Ö¡£

¡¾·µ»Ø¶¥²¿¡¿ ¡¾´òÓ¡±¾Ò³¡¿ ¡¾¹Ø±Õ´°¿Ú¡¿

¹ØÓÚÎÒÃÇ / ¸øÎÒÁôÑÔ / °æȨ¾Ù±¨ / Òâ¼û½¨Òé / ÍøÕ¾±à³ÌQQȺ   
Copyright ©2003- 2024 Lihuasoft.net webmaster(at)lihuasoft.net ¼ÓÔØʱ¼ä 0.00416