»ù±¾Ë¼Â·£º Ϊûһ¸ö¹¦ÄÜдһ¸ö¶ÀÁ¢µÄ³ÌÐò£¬³ÌÐòÒ³ ¾¡¿ÉÄÜÉÙµÄÈÿͻ§Á˽âÄãµÄ·þÎñÆ÷¶ËÐÅÏ¢ ²»ÒªÓÃ"¿Í»§Ó¦¸ÃÕâôд"Õâ¸ö˼·ÏëÎÊÌâ ¾¡¿ÉÄܶàµÄÏëµ½²»¿ÉÄÜ·¢ÉúµÄÊÂÇé 1.¹ØÓÚ½»»¥Ê½¶¯Ì¬ÍøÒ³¿ÉÄÜ´æÔÚµÄÎÊÌâ 1.1 formÀàÐ͵Ľ»»¥ 1.1.1 ¸ÅÄî½éÉÜ ÔÚÎÒÃǺÍä¯ÀÀÕß½øÐн»»¥Ê±£¬×î³£Óõ½µÄ¾ÍÊÇform(post/get/put·½·¨)£¬ËäÈ»·Ç³£·½±ã£¬µ«ÊǺܶàÎÊÌâÒ²ÊÇÒòËû¶øÆð¡£form±íµ¥ÖÐinput±êÖ¾ ÓÃÀ´½ÓÊÜÓû§ÊäÈëµÄÐÅÏ¢£¬ÀýÈ磺Óû§Ãû¡¢ÃÜÂë¡¢emailµÈ¡£Èç¹ûÄãûÓжÔÓû§ÊäÈë½øÐкܺõļì²éµÄ»°£¬Ò»¸ö¶ñÒâµÄÓû§»áÆÁ±ÎµôһЩ°²È« »úÖÆ£¬Èƹý°²È«ÈÏÖ¤¡£ÀýÈ磬ÊäÈë±ê×¼µÄHTMLÓï¾ä»òÕßjavascriptÓï¾ä»á¸Ä±äÊä³ö½á¹û£¬ÔÚÊäÈë¿òÖдòÈë±ê×¼µÄHTMLÓï¾ä»áµÃµ½Ê²Ã´ÑùµÄ½á ¹ûÄØ£¿±ÈÈçÒ»¸öÁôÑÔ±¾£¬ÎÒÃÇÁôÑÔÄÚÈÝÖдòÈ룺<font size=10>ÄãºÃ£¡</font>¡¡ Èç¹ûÄãµÄ³ÌÐòÖÐûÓÐÆÁ±ÎhtmlÓï¾ä£¬ÄÇô¾Í»á¸Ä±ä"ÄãºÃ"×ÖÌåµÄ´óС¡£ÔÚÁôÑÔ±¾Öиıä×ÖÌå´óСºÍÌùͼÓÐʱ²¢²»ÊÇʲô»µÊ£¬·´¶ø¿ÉÒÔʹÁôÑÔ ±¾Éú¶¯¡£µ«ÊÇÈç¹ûÔÚÊäÈë¿òÖÐд¸ö javascript µÄËÀÑ»·£¬±ÈÈ磺 <a herf="http://someurl" onMouseover="while(1) {window.close('/')}">µÚÒ»Íò¸ö¾ªÐĶ¯ÆÇ</a> ÄÇôÆäËû²é¿´¸ÃÁôÑԵĿÍÈËÖ»ÒªÒÆ ¶¯Êó±êµ½"µÚÒ»Íò¸ö¾ªÐĶ¯ÆÇ"£¬ÉϾͻáʹÓû§µÄä¯ÀÀÆ÷ÒòËÀÑ»·¶øËÀµô¡£ 1.1.2 ·À·¶Òªµã (1)¶ÔÌØÊâ×Ö·û½øÐйýÂË ([\&;\`'\\\|"*?~<>^\(\)\[\]\{\}\$\n\r])/\\$1/g;)£¬Õâ¸öÊÇ×î»ù±¾µÄ£¬ÔںܶàµØ·½Ò²ÒѾ²»Ö»Ò»´ÎÌáµ½¹ý <script language="vbscript"> sub uBotton_onclick if form1.uUserName.value=""then msgbox"ÄúµÄÐÕÃû²»ÄÜΪ¿Õ£¡",0+32,"Ŷ£¡»¹²»ÐÐ" form1.uUserName.focus exit sub end if if form1.uPassword.value=""then msgbox"ÄúµÄÃÜÂë²»ÄÜΪ¿Õ£¡",0+32,"Ŷ£¡»¹²»ÐÐ" form1.uPassword.focus exit sub end if if form1.uUserName.value=""then msgbox"ÄúµÄÐÕÃû²»ÄÜΪ¿Õ£¡",0+32,"Ŷ£¡»¹²»ÐÐ" form1.uUserName.focus exit sub end if form1.submit end sub </script> function isEmpty(objname) { var str = document.inputform[objname].value var tmpstr = str.replace([\&;\`'\\\|"*?~<>^\(\)\[\]\{\}\$\n\r])/\\$1/g;,"") var tmpstr = tmpstr.replace([\&;\`'\\\|"*?~<>^\(\)\[\]\{\}\$\n\r])/\\$1/g;,"") return (tmpstr.length==0) } function check() { tf=document.inputform errors="" if (isEmpty("username")) errors += "Óû§Ãû²»ÄÜΪ¿Õ¡£\n"; if (isEmpty("password")) errors += "ÃÜÂë²»ÄÜΪ¿Õ£¡\n" if (errors!="") alert(errors); return (errors=="") } (2) ¶ÔÊäÈëµÄ×Ö·û³¤¶È½øÐÐÏÞÖÆ (3) ½øÐо¡¿ÉÄܶàµÄ´íÎó³öÀíºÍ´íÎóÏÝÚå (4) ¾¡¿ÉÄܶàµÄʹÓÃÒÔÏÂÕâЩ±êÖ¾£¬¼õÉÙÓû§ÊäÈëµÄ»ú»á <input type="checkbox" name="checkbox" value="checkbox"> <select name="select"> </select> <input type="radio" name="radiobutton" value="radiobutton"> ¡¡¡¡ 1.2 post/getÀàÐ͵Ľ»»¥ 1.2.1 ¸ÅÄî½éÉÜ ÕâÖÖÀàÐ͵ÄÎÊÌâÖ÷ÒªÊÇä¯ÀÀÕß¿ÉÒÔͨ¹ýä¯ÀÀÆ÷µÄµØÖ·À¸¶Ô½Å±¾Ò³Í¨¹ýÌí¼Ó²ÎÊýÀ´ºÍ·þÎñÆ÷½øÐн»»¥£¬ÕâЩ²ÎÊýÒѾÈƹý·ÅÔÚ¿Í»§¶ËÌá½»Ò³µÄ ÊäÈë¼ì²éÁË£¬»¹ÓоÍÊÇ¿ÉÒÔͨ¹ýµØÖ·À¸ÊäÈë½Ï³¤µÄ²ÎÊý»ò¶ñÒâ±àÔìµÄ´úÂëÔì³É·þÎñÆ÷Òì³£ÔËËã´íÎ󣬵¼Ö·þÎñÆ÷å´»ú»ò»º³åÇøÒç³ö¡£ 1.2.2 ·À·¶Òªµã (1) ¾¡Á¿²»ÒªÈÃä¯ÀÀÕßÁ˽⵽ÄãµÄÔËËãÌá½»Ò³ (2) ²»ÔÊÐíµØÖ·À¸Ìá½»²ÎÊý ÀýÈçASP³ÌÐòÖеÄrequest.serverVariables(QUERY_STRING)¼ì²âÊÇ·ñÓвÎÊý£¬Èç¹ûÓÐÔòʹÓÃresponse.redirect()Ç¿ÖÆ·µ»ØÖ¸¶¨Ò³£¬¿ÉÒÔ ÊÇÊ×Ò³£¬»òÕßÄã×Ô¼º×öµÄ¾¯¸æÒ³¡£ (3) ½Å±¾Ò³¼ä´«µÝ²ÎÊý²»ÒªÔÙä¯ÀÀÆ÷À¸ÏÔʾ£¬¾¡¿ÉÄÜÉÙµÄÈÃä¯ÀÀÕßÁ˽âÄãµÄ³ÌÐò¹æÔò¡¢²ÎÊýµÈ ÀýÈçASPÖеÄRequest.formºÍRequest.QueryStringÕâÁ½¸öÊý¾Ý¼¯ºÏ·Ö±ðʹÓõÄÊÇpostºÍget·½·¨£¬ÎÒÃǾ¡Á¿²»ÒªÊÇÓÃRequest.QueryStringÕâ ¸öÊý¾Ý¼¯ºÏ£¬¾¡¿ÉÄÜÉÙµÄÈÃä¯ÀÀÕßÓкÍÄã½»»¥µÄ»ú»á£¬ 2. °²È«ÈÏÖ¤µÄÎÊÌâ 2.1 ÐèÒª°²È«ÈÏÖ¤ÃÜÂëÈÏÖ¤µÄ¿ÉÄÜ´æÔÚµÄÎÊÌâ 2.1.1 ¸ÅÄî½éÉÜ ÏÖÔÚÁ÷ÐеÄCGIÓ¦ÓóÌÐòÇãÏòÓÚÊÕ¼¯ÐÅÓÿ¨ÐÅÏ¢¡£Êý¾ÝÊÕ¼¯ÊÇCGI Ó¦ÓóÌÐòµÄÒ»¸ö¼òµ¥µÄÈÎÎñ£¬µ«ÊÇÃô¸ÐÐÅÏ¢µÄ ÊÕ¼¯ÐèÒªÒ»¸ö½«ÐÅÏ¢´Óä¯ÀÀÆ÷´«Ë͸ø·þÎñÆ÷ºÍCGI³ÌÐòµÄ°²È«Í¾¾¶¡£ ¾Ù¸öÀý×Ó£¬¼ÙÉèÎÒҪͨ¹ýInternetÀ´ÏúÊÛÊé¡£ÎÒ¿ÉÄÜÔÚä¯ÀÀÆ÷ÉϽ¨Á¢Ò»¸ö±íµ¥£¬ÔÊÐíÒª¹ºÊéµÄ¹Ë¿Íͨ¹ý±íµ¥Ìá½»ËüµÄ¸öÈËÐÅÏ¢ºÍÐÅÓÿ¨ºÅÂë ¡£Êܵ½ÕâЩÐÅÏ¢ºó£¬ÎһὫËüÃÇ´æ´¢µ½ÎҵļÆËã»ú×÷ΪÉÌÒµ¼Ç¼¡£ Èç¹ûÓÐÈËÇÖÈëÎÒµÄÉÌÒµ¼ÆËã»ú£¬ÄÇôËû¿ÉÄÜ»á·ÃÎÊ´æ·Å¹Ë¿ÍÐÅÏ¢ºÍÐÅÓÿ¨ºÅÂëµÄ»úÃÜÊý¾Ý¡£ÎªÁ˱ÜÃâÕâÖÖÇé¿ö£¬ÎÒ»áÉó²éÎҵļÆËã»úÅäÖð² È«ÁË£¬²¢È·¶¨ÓÃÀ´½ÓÊÜ±íµ¥µÄCGI½Å±¾²»»á±»¶ñÒâµÄ²Ù×Ý¡£»»¾ä»°Ëµ£¬ÎÒ£¬×÷Ϊ¼ÆËã»úµÄϵͳ¹ÜÀíÔ±ºÍCGI³ÌÐòÔ±£¬Òª¾¡Á¦¿ØÖÆסµÚÒ»¸öÎÊ Ì⣺·ÀÖ¹ÐÅÏ¢Ö±½Ó´ÓÎҵļÆËã»úÖб»ÇÔÈ¡¡£ È»¶ø£¬ÔõÑù·ÀÖ¹µ±ÐÅÏ¢ÓÉ¿Í»§¶Ë·¢Íù·þÎñÆ÷¹ý³ÌÖÐÓÐÈËÖÐ;ÇÔÈ¡ÄØ£¿¼ÇסÐÅÏ¢ÔõÑùÓÉWeb·þÎñÆ÷´«Ë͵½CGI³ÌÐòÁËÂð£¿ÐÅϢͨ¹ýÍøÂçÓÉä¯ÀÀ Æ÷ÏÈ´«Ë͵½·þÎñÆ÷£¬È»ºó·þÎñÆ÷½«ÐÅÏ¢´«Ë͸øCGI³ÌÐò¡£ÕâЩÐÅÏ¢¿ÉÄÜÔÚÓÉ¿Í»§»ú´«Ë͵½·þÎñÆ÷ʱ±»ÖÐ;ÇÔÈ¡(Èçͼ2)¡£×¢Ò⣬ΪÁ˱£»¤ÐÅÏ¢ ʹÆä²»»á±»ÖÐ;ÇÔÈ¡£¬±ØÐëÔÚ¿Í»§ºÍ·þÎñÆ÷Ö®¼ä½øÐмÓÃÜ¡£µ±È»£¬Èç¹ûÄãµÄ¿Í»§»ú²»ÄÜʶ±ðµÄ»°£¬Äã²»ÄÜÖ´ÐÐÌض¨CGIµÄ¼ÓÃÜ¡£ ÓÉÓÚWeb´¦ÀíµÄÌص㣬ʹÓÃÄã¶ÀÓеĵ¥¶Àͨ¹ýCGI³ÌÐòʵÏֵݲȫ´¦ÀíÐÒéµÄΨһ;¾¶ÊÇ:ÔÚ±íµ¥ÐÅϢͨ¹ýä¯ÀÀÆ÷´«Ë͵½·þÎñÆ÷֮ǰ½«Æä¼ÓÃÜ ¡£ Õâ¸ö·½°¸Èç¡£ ֮ǰ£¬·¢Õ¹Äã×Ô¼ºµÄ°²È«´¦ÀíÐÒ鼸ºõÊDz»¿ÉÄܵġ£¸ÐлJavaÕâÑùµÄÓïÑÔ,×î½üÔÚ¿Í»§¶Ë´¦ÀíËù×÷µÄ´´Ð£¬Ê¹µÃÕâ¸ö·¢Õ¹±ä³É¿ÉÄÜ¡£ ·½·¨ÊDzúÉúÒ»¸ö±ê×¼HTML¸ñʽÀ©Õ¹µÄJava½Ó¿Ú¡£µ±JavaµÄÌá½»°´Å¥±»Ñ¡Ôñʱ£¬Java Applet»áÔÚÀûÓñê×¼µÄPOSTHTTPÇëÇó½«Ëü·¢Ë͵½Web·þÎñÆ÷Ç°ÏȽ«Öµ¼ÓÃÜ¡£ ʹÓÃJava×÷Ϊ¿Í»§»úÀ´·¢ËͺͽÓÊÕ¼ÓÃܵÄÊý¾Ý½«ÔÊÐíÄãʹÓÃ×Ô¼º¶¨ÖƵļÓÃÜ·½°¸£¬¶ø²»ÐèÒªÒ»¸ö°º¹óµÄÉÌÒµ·þÎñÆ÷¡£ Òò´Ë£¬ÔÚÍøÂçÉÏ°²È«±£Ãܵش«ËÍÊý¾ÝÐÅÏ¢ÐèÒªµ÷Õûä¯ÀÀÆ÷ºÍ·þÎñÆ÷Ö®¼äµÄͨÐÅ·¾¶£¬ÓÐһЩÊDz»Äܽö½ö¿¿CGI¾ÍÄܹ»¿ØÖƵġ£Ä¿Ç°ÓÐÁ½ÖÖ¼Ó ÃÜ¿Í»§»ú/·þÎñÆ÷ÐÅÏ¢´¦ÀíµÄ½¨Ò飺SSL(Secure Sockets Layer)ºÍSHTTP(Secure HTTP),·Ö±ðÓÉNetscapeºÍEIT(Enterprise Integrations Technology)ÌáÒé¡£¹ØÓÚÕâµã£¬Ä¿Ç°»¹²»Çå³þÄÄÒ»¸ö½«³ÉΪ±ê×¼£»ºÜ¶à¹«Ë¾ÔÚËûÃǵķþÎñÆ÷ÖÐÁ½ÖÖ¶¼²ÉÓÃÁË¡£Òò´Ë£¬ÖªµÀÈçºÎÔÚÕâÁ½ÕßÖбà дCGI³ÌÐòÊǺÜÓÐÓõġ£ SSLÊÇÒ»¸öÐÒé¶ÀÁ¢µÄ¼ÓÃÜ·½°¸£¬ÔÚÍøÂçÐÅÏ¢°üµÄÓ¦ÓòãºÍ´«Êä²ãÖ®¼äÌṩÁË°²È«µÄͨµÀ(²ÎÕÕͼ5)¡£¼òµ¥ËµÀ´£¬¾ÍÊÇHTML»òCGI¾¹ýÁËÄ»ºó µÄ·þÎñÆ÷½øÐÐÁ˼ÓÃÜ´¦Àí£¬È»¶ø¶ÔHTMLºÍCGIµÄ×÷ÕßÀ´ËµÊÇ͸Ã÷µÄ¡£ ÒòΪ¿Í»§¶ËºÍ·þÎñÆ÷¶ËÍøÂç³ÌÐò´¦Àí¼ÓÃܹý³Ì£¬¼¸ºõÄãµÄËùÓеÄCGI½Å±¾²»ÐèÒª½øÐа²È«ÊÂÎñµÄÐÞÕý¡£ÓÐÒ»¸öÏÔÖøµÄÀýÍâ¡£Ò»¸önph(no-pars e-header)µÄCGI³ÌÐòÈƹý·þÎñÆ÷¶øÖ±½ÓÓë¿Í»§¶Ë½øÐÐͨÐÅ¡£Òò´Ë£¬nphµÄCGI½Å±¾²»»á¾¹ý¼ÓÃÜ´¦Àí£¬ÒòΪÐÅϢδµÃµ½¼ÓÃÜ¡£ÊÜ´ËÓ°ÏìµÄÒ» ¸öÖµµÃ×¢ÒâµÄCGIÓ¦ÓóÌÐòÊÇNetscape·þÎñÆ÷Íƶ¯µÄ¶¯Ì¬ÊµÏÖ(Netscape server-push animations)¡£ ÎÒ»³ÒÉÕâÊÇÖ÷ÒªÓ¦¸ÃÖµµÃ×¢ÒâµÄ£¬È»¶ø£¬¸ü ÓпÉÄÜÒòΪҪ°²È«µÄ´«ÊäÃô¸ÐÐÅÏ¢¶øÎþÉüÒ³ÃæÖеĶ¯»¡£ SHTTP²ÉÓÃÒ»ÖÖºÍSSL²»Í¬µÄ·½·¨¡£Ëüͨ¹ýÀ©Õ¹HTTPÐÒé(Ó¦Óòã)À´ÔË×÷£¬ÓÅÓÚÒ»¸ö½ÏµÍ²ã¡£Òò´Ë£¬¾¡¹ÜSSL¿ÉÒÔÓ¦ÓÃÓÚËùÓеÄÍøÂç·þÎñ£¬ È»¶øSHTTPÊÇÒ»¸öÌض¨µÄWebÐÒé ÁíÍ⣬»¹ÓÐÆäËüµÄÓŵ㡣×÷ΪHTTPµÄÀ©Õ¹¼¯£¬SHTTPÈ«¼æÈÝÓÚHTTPºÍSHTTPµÄä¯ÀÀÆ÷ºÍ·þÎñÆ÷¡£ÎªÁËʹÓÃSSL,Äã±ØÐëÓÐÒ»¸öÖ§³ÖSSLµÄä¯ ÀÀÆ÷ºÍ·þÎñÆ÷¡£ÁíÍ⣬SHTTPÊÇÒ»¸ö¸üÁé»îµÄÐÒé¡£ÀýÈ磬Õâ¸ö·þÎñÆ÷¿ÉÒÔÖ¸¶¨Ê×Ñ¡µÄ¼ÓÃÜ·½°¸¡£ SHTTP´¦ÀíÒÀÀµÓÚ¸½¼ÓµÄHTTPÍ·¡£Òò´Ë£¬Èç¹ûÄãÏëÈÃÄãµÄCGI³ÌÐò²ÉÓÃSHTTPµÄ¼ÓÃÜ´¦Àí£¬ÄãÐèÒª°üº¬Êʵ±µÄÍ·¡£ÀýÈ磬Ìæ»»¼òµ¥·µ»ØHTT PÍ·¡£ Content-type:text/html µ±Ò»¸öSHTTP·þÎñÆ÷´ÓCGIÓ¦ÓóÌÐòÖÐÊÕµ½Õâ¸öÐÅÏ¢£¬Ëü»áÖªµÀÔÚ½«Æä·¢Ë͵½ä¯ÀÀÆ÷֮ǰ½«ÐÅÏ¢¼ÓÃÜ¡£Ò»¸ö·ÇSHTTPµÄä¯ÀÀÆ÷½«ºöÂÔ¸½¼ÓµÄ Í·¡£ ¹ØÓÚʹÓÃSHTTPµÄ¸ü¶àµÄÐÅÏ¢£¬Çë²ÎÕÕSHTTPµÄ˵Ã÷Êé: http://www.commerce.net/information/standards/drafts/shttp.txt 2.1.3 ½Å±¾½âÎö ÏÂÃæÊÇÎÒÒÔǰдµÄÒ»¶Îasp½Å±¾£¬×öÁËһЩÐ޸ģ¬°ÑËûÌù³öÀ´£¬Èôó¼Ò¿´¿´ÎÒ¼ÓÈëÁËÉèÖã¬ÄÇÀï×öµÄ²»¹»ºÃ¡£ÎÒÔÚÕâÀï¾Í²»¶à˵ÁË£¬ÓÐÐËȤ¿É ÒÔµ½ ÎÒµÄÂÛ̳À´´ó¼ÒÌÖÂÛ¡£ <!--#include file="conn.asp"--> <% dim errmsg if request.form("username")="" then ErrMsg="Óû§Ãû²»ÄÜΪ¿Õ" foundError=True else UserName=request.form("UserName") end if if request.form("password")="" then ErrMsg="ÃÜÂë²»ÄÜΪ¿Õ" foundError=True else PassWord=request.form("PassWord") end if if FoundError=true then showAnnounce(ErrMsg) else set rstmp=server.createobject("adodb.recordset") if Request.ServerVariables("REQUEST_METHOD") = "POST" then rstmp.open "Select * from User Where userName='" & UserName & "'",conn,3,3 if rstmp.bof then session.contents("UserName")=UserName rstmp.addnew rstmp("username")=username rstmp("userpassword")=password rstmp("logins")=1 rstmp("online")=1 rstmp.update response.redirect("index.asp") elseif PassWord<>rstmp("userpassword") then ErrMsg="ÃÜÂë´íÀ²" foundError=True showAnnounce(ErrMsg) else session.contents("UserName")=UserName rstmp("logins")=rstmp("logins")+1 rstmp("online")=1 rstmp.update rstmp.close Set rstmp=nothing response.redirect("index.asp") end if else if session.contents("UserName")<>"" then rstmp.open "Select * from User Where userName='"&session.contents("UserName")&"'",conn,3,3 rstmp("logins")=rstmp("logins")+1 rstmp("online")=1 rstmp.update rstmp.close Set rstmp=nothing conn.close set conn=nothing response.redirect("index.asp") end if end if end if %> <html> <head> <title></title> <link rel="stylesheet" type="text/css" href="forum.css"> </head> <body> <% function showAnnounce(ErrMsg) on error resume next response.write "<p align=center><font color='red'><strong><Big>?¹þ¹þ</big></strong></font><BR><font color='#0000FF'>"+ErrMsg+"</font><BR>"+chr(13)+chr(10) %> <tr> <td width="100%"> <p align="center"><br> <form action="login.asp" method="post"> ÊäÈë<INPUT name=username size=8 class='smallInput'> <BR>¹þ¹þ<INPUT name=password size=8 class='smallInput' type=password> </td> </tr> <tr> <td width="100%"> <p align="center"><br> <INPUT type="submit" name="B12" class='buttonface' value=¦Ì???> <font color="#FF0000"><br> <br> *</font>´íÁË </td> </form> </tr> <% end function %> ###---checklogin.asp <% dim adname dim passwd adname=Request.Form("adname") passwd=Request.Form("passwd") if adname="" then response.redirect "login.asp" end if if passwd="" then response.redirect "login.asp" end if if adname="focus-admin" and passwd="1" then response.redirect "manage.asp" else response.redirect "login.asp" end if %> ###---checklogin.asp----end ###---manage.asp <% dim where dim where1 dim refererURL dim refererURL2 dim refererURL3 refererURL=phyURL&"login.as" refererURL2=phyURL&"edit.asp" refererURL3=phyURL&"manage.a" refererURL4=phyURL&"savearti" where=Request.ServerVariables("HTTP_REFERER") where=left(where,(len(phyURL)+8)) if where<>refererURL and where<> refererURL2 and where<>refererURL3 and where<>refererURL4 then Response.Redirect "login.asp" end if const MaxPerPage=20 dim totalPut dim CurrentPage dim TotalPages dim i,j if not isempty(request("page")) then currentPage=cint(request("page")) else currentPage=1 end if %> ###---manage.asp-----end 2.2 cookieµÄÎÊÌâ 2.2.1 ¸ÅÄî½éÉÜ °´ÕÕNetscape¹Ù·½ÎĵµÖеĶ¨Ò壬CookieÊÇÔÚHTTPÐÒéÏ£¬·þÎñÆ÷»ò½Å±¾¿ÉÒÔά»¤¿Í»§¹¤×÷Õ¾ÉÏÐÅÏ¢µÄÒ»ÖÖ·½Ê½¡£CookieÊÇÓÉWeb·þÎñÆ÷ ±£´æÔÚÓû§ä¯ÀÀÆ÷ÉϵÄС¹ãÎ÷Îļþ£¬Ëü¿ÉÒÔ°üº¬ÓйØÓû§µÄÐÅÏ¢£¨ÈçÉí·Ýʶ±ðºÅÂë¡¢ÃÜÂë¡¢Óû§ÔÚWebÕ¾µã¹ºÎïµÄ·½Ê½»òÓû§·ÃÎʸÃÕ¾µãµÄ ´ÎÊý£©¡£ÎÞÂÛºÎʱÓû§Á´½Óµ½·þÎñÆ÷£¬WebÕ¾µã¶¼¿ÉÒÔ·ÃÎÊCookieÐÅÏ¢¡£ ͨË׵ؽ²£¬ä¯ÀÀÆ÷ÓÃÒ»¸ö»ò¶à¸öÏÞ¶¨µÄÎļþÀ´Ö§³ÖCookie¡£ÕâЩÎļþÔÚʹÓÃWindows²Ù×÷ϵͳµÄ»úÆ÷ÉϽÐ×öCookieÎļþ£¬ÔÚMacintosh»úÆ÷ ÉϽÐ×ömagic Cookie Îļþ£¬ÕâЩÎļþ±»ÍøÕ¾ÓÃÀ´ÔÚÉÏÃæ´æ´¢CookieÊý¾Ý¡£ÍøÕ¾¿ÉÒÔÔÚÕâЩCookieÎļþÖвåÈëÐÅÏ¢£¬ÕâÑù¶ÔÓÐЩÍøÂçÓû§¾ÍÓÐЩ¸±×÷Óá£ÓÐЩÓû§ ÈÏΪÕâÔì³ÉÁ˶ԸöÈËÒþ˽µÄÇÖ·¸£¬¸üÔãµÄÊÇ£¬ÓÐЩÈËÈÏΪCookieÊǶԸöÈË¿Õ¼äµÄÇÖÕ¼£¬¶øÇÒ»á¶ÔÓû§µÄ¼ÆËã»ú´øÀ´°²È«ÐÔµÄΣº¦¡£ Ä¿Ç°ÓÐЩCookieÊÇÁÙʱµÄ£¬ÁíһЩÔòÊdzÖÐøµÄ¡£ÁÙʱµÄCookieÖ»ÔÚä¯ÀÀÆ÷Éϱ£´æÒ»¶Î¹æ¶¨µÄʱ¼ä£¬Ò»µ©³¬¹ý¹æ¶¨µÄʱ¼ä¸ÃCookie¾Í»á±»ÏµÍ³ Çå³ý¡£ÀýÈçÔÚPHPÖÐCookie±»ÓÃÀ´¸ú×ÙÓû§½ø³ÌÖ±µ½Óû§À뿪ÍøÕ¾¡£³ÖÐøµÄCookieÔò±£´æÔÚÓû§µÄCookieÎļþÖУ¬ÏÂÒ»´ÎÓû§·µ»Øʱ£¬ÈÔÈ» ¿ÉÒÔ¶ÔËü½øÐе÷ÓᣠҪÁ˽âCookie£¬±Ø²»¿ÉÉÙµØÒªÖªµÀËüµÄ¹¤×÷ÔÀí¡£Ò»°ãÀ´Ëµ£¬Cookieͨ¹ýHTTPHeaders´Ó·þÎñÆ÷¶Ë·µ»Øµ½ä¯ÀÀÆ÷ÉÏ¡£Ê×ÏÈ£¬·þÎñÆ÷¶ËÔÚÏìÓ¦ ÖÐÀûÓÃSet-Cookie headerÀ´´´½¨Ò»¸öCookie£¬È»ºó£¬ä¯ÀÀÆ÷ÔÚËüµÄÇëÇóÖÐͨ¹ýCookie header°üº¬Õâ¸öÒѾ´´½¨µÄCookie£¬²¢ÇÒ·´Ëü·µ»Ø ÖÁ·þÎñÆ÷£¬´Ó¶øÍê³Éä¯ÀÀÆ÷µÄÂÛÖ¤¡£ÀýÈ磬ÎÒÃÇ´´½¨ÁËÒ»¸öÃû×ÖΪloginµÄCookieÀ´°üº¬·ÃÎÊÕßµÄÐÅÏ¢£¬´´½¨Cookieʱ£¬·þÎñÆ÷¶ËµÄHeaderÈç ÏÂÃæËùʾ£¬ÕâÀï¼ÙÉè·ÃÎÊÕßµÄ×¢²áÃûÊÇ"Michael Jordan"£¬Í¬Ê±»¹¶ÔËù´´½¨µÄCookieµÄÊôÐÔÈçpath¡¢domain¡¢expiresµÈ½øÐÐÁËÖ¸¶¨¡£ Set-Cookie:login=Michael Jordan;path=/;domain=msn.com; expires=Monday,01-Mar-99 00:00:01 GMT ÉÏÃæÕâ¸öHeader»á×Ô¶¯ÔÚä¯ÀÀÆ÷¶Ë¼ÆËã»úµÄCookieÎļþÖÐÌí¼ÓÒ»Ìõ¼Ç¼¡£ä¯ÀÀÆ÷½«±äÁ¿ÃûΪ"login"µÄCookie¸³ÖµÎª"Michael Jordon"¡£×¢Òâ £¬ÔÚʵ¼Ê´«µÝ¹ý³ÌÖÐÕâ¸öCookieµÄÖµÊǾ¹ýÁËURLEncode·½·¨µÄURL±àÂë²Ù×÷µÄ¡£ Õâ¸öº¬ÓÐCookieÖµµÄHTTP Header±»±£´æµ½ä¯ÀÀÆ÷µÄCookieÎļþºó£¬Header¾Í֪ͨä¯ÀÀÆ÷½«Cookieͨ¹ýÇëÇóÒÔºöÂÔ·¾¶µÄ·½Ê½·µ»Øµ½·þÎñÆ÷ £¬Íê³Éä¯ÀÀÆ÷µÄÈÏÖ¤²Ù×÷¡£ ´ËÍ⣬ÎÒÃÇʹÓÃÁËCookieµÄһЩÊôÐÔÀ´ÏÞ¶¨¸ÃCookieµÄʹÓá£ÀýÈçDomainÊôÐÔÄܹ»ÔÚä¯ÀÀÆ÷¶Ë¶ÔCookie·¢ËͽøÐÐÏÞ¶¨£¬¾ßÌåµ½ÉÏÃæµÄÀý×Ó £¬¸ÃCookieÖ»ÄÜ´«´ïÊÒµ½Ö¸¶¨µÄ·þÎñÆ÷ÉÏ£¬¶ø¾ö²»»áÅܵ½ÆäËûµÄÈçwww.hp.comµÄWebÕ¾µãÉÏÈ¥¡£ExpiresÊôÐÔÔòÖ¸¶¨Á˸ÃCookie±£´æµÄʱ ¼äÆÚÏÞ£¬ÀýÈçÉÏÃæµÄCookieÔÚä¯ÀÀÆ÷ÉÏÖ»±£´æµ½1999Äê3ÔÂ1ÈÕ1Ãë¡£µ±È»£¬Èç¹ûä¯ÀÀÆ÷ÉÏCookieÌ«¶à£¬³¬¹ýÁËϵͳËùÔÊÐíµÄ·¶Î§£¬ä¯ÀÀÆ÷½« ×Ô¶¯¶ÔËü½øÐÐɾ³ý¡£ÖÁÓÚÊôÐÔPath£¬ÓÃÀ´Ö¸¶¨Cookie½«±»·¢Ë͵½·þÎñÆ÷µÄÄÄÒ»¸öĿ¼·¾¶Ï¡£ ˵Ã÷£ºä¯ÀÀÆ÷´´½¨ÁËÒ»¸öCookieºó£¬¶ÔÓÚÿһ¸öÕë¶Ô¸ÃÍøÕ¾µÄÇëÇ󣬶¼»áÔÚHeaderÖдø×ÅÕâ¸öCookie£»²»¹ý£¬¶ÔÓÚÆäËûÍøÕ¾µÄÇëÇóCookie ÊǾø¶Ô²»»á¸ú×Å·¢Ë͵ġ£¶øÇÒä¯ÀÀÆ÷»áÕâÑùÒ»Ö±·¢ËÍ£¬Ö±µ½Cookie¹ýÆÚΪֹ¡£ 2.2.2 Òªµã·½·¨ setcookie-----Ëͳö Cookie ÐÅÏ¢µ½ä¯ÀÀÆ÷¡£ Óï·¨: int setcookie(string name, string value, int expire, string path, string domain, int secure); ·µ»ØÖµ: ÕûÊý ±¾º¯Êý»á¸ú×űêʶ Header ËͳöÒ»¶ÎСÐÅÏ¢×Ö·û´®µ½ä¯ÀÀÆ÷¡£Ê¹Óñ¾º¯ÊýÒªÔÚËͳö HTML Êý¾ÝÇ°£¬Êµ¼ÊÉÏ cookie Ò²Ëã±êʶµÄÒ»²¿·Ý¡£±¾º¯ÊýµÄ²ÎÊý³ýÁ˵ÚÒ»¸ö name Ö®Í⣬¶¼ÊÇ¿ÉÒÔÊ¡ÂԵġ£²ÎÊý name ±íʾ cookie µÄÃû³Æ£»value ±íʾÕâ¸ö cookie µÄÖµ£¬Õâ¸ö²ÎÊýΪ¿Õ×Ö·û´®Ôò±íʾȡÏûä¯ÀÀÆ÷Öиà cookie µÄÊý¾Ý£»expire ±íʾ¸Ã cookie µÄÓÐЧʱ¼ä£»path Ϊ¸Ã cookie µÄÏà¹Ø·¾¶£»domain ±íʾ cookie µÄÍøÕ¾£»secure ÔòÐèÔÚ https µÄ°²È«´«Êäʱ²ÅÓÐЧ¡£ÏëµÃµ½¸ü¶àµÄ cookie ÐÅÏ¢¿ÉÒÔµ½ http://www.netscape.com/newsref/std/cookie_spec.html£¬ÓÉ cookie Ô´´Õß Netscape ËùÌṩµÄÍêÕûÐÅÏ¢¡£ ¶ÔÓÚÒ»¸öÍøÕ¾»áÔ±¶øÑÔ£¬¾³£´æÔÚÐèÒªÒ»´Î×¢²á£¬¶à´ÎÈÏÖ¤µÄÎÊÌ⣬ÀýÈçÎÒÃǾ³£½Ó´¥µ½µÄÂÛ̳¡¢ÉçÇøµÈ£¬Ò»°ã²ÉÓÃÊÖ¶ÎΪcookie»ò input type=hiddenÀ´´«µÝÈÏÖ¤²ÎÊý¡£ÕâÀïÃæÓм¸µãÒþ»¼£º I. setcookieÄÚÈݱØÐëÍêÕû°üº¬ÕʺÅÃÜÂ룬»òÀàËƵÄÍêÕû°²È«ÐÅÏ¢£¬Èç¹ûֻЯ´øÕʺÅÐÅÏ¢»òÓÃijÖÖȨÏÞ±êÖ¾À´ÈÏÖ¤£¬¼«ÈÝÒ×Ôì³É·Ç·¨ÈëÇÖ¡£Àý ÈçijվµãÖеĻáÔ±¸üÐÂÒ³ÃæÖÐЯ´øµÄÈÏÖ¤ÐÅÏ¢ÊÇÁ½¸ö£¬Óû§ÃûºÍUid(¾ùΪÃ÷ÎÄ´«ËÍ)ÒÑÖªUid¶ÔÓÚÿ¸ö»áÔ±ÊÇΨһµÄ¡£ÓÉÓÚÎÒÃÇÖ»ÐèÒªÖªµÀ ¶Ô·½µÄÕʺźÍUid¾Í¿ÉÒÔ¸ü¸Ä¶Ô·½ÐÅÏ¢£¨²»ÐèÒªÖªµÀÃÜÂ룡£©£¬Ö»Òª¹¥»÷ÕßÖªµÀUid£¨¹¥»÷Õß¿ÉÒÔͨ¹ý±©Á¦²Â²âµÄ·½·¨À´µÃµ½Uid£¬ÓÐʱºòÕ¾ µã±¾ÉíÒ²»áй¶Óû§µÄUid,ÀýÈçÔÚÂÛ̳µÈ´¦£©ÄÇô£¬¹¥»÷Õ߾ͿÉÒÔͨ¹ý±éÀú¹¥»÷Íê³É¶ÔÈÎÒâÒ»¸öÕʺŵÄÐÅÏ¢¸ü¸Ä¡£ II. ±ØÐëËùÓÐÐèҪȨÏÞ²Ù×÷µÄÒ³Ã涼±ØÐëÖ´ÐÐÈÏÖ¤ÅжϵIJÙ×÷¡£Èç¹ûÈκÎһҳûÓнøÐÐÕâÖÖÈÏÖ¤Åжϣ¬¶¼ÓпÉÄܸø¹¥»÷ÕßÒÔ¶ñÒâÈëÇֵĻú»á¡£ III. ºÜ¶àÍøվΪÁË·½±ã£¬½«Óû§ÃûÒÔ¼°¿ÚÁîÐÅÏ¢´¢´æÔÚCookieÖУ¬ÓеÄÉõÖÁÒÔÃ÷ÎÄ·½Ê½±£´æ¿ÚÁî¡£Èç¹û¹¥»÷Õß¿ÉÒÔ·ÃÎʵ½Óû§µÄÖ÷»ú£¬¾Í¿ÉÄÜͨ ¹ý±£´æµÄCookieÎļþµÃµ½Óû§ÃûºÍ¿ÚÁî¡£ 3. ½Å±¾±£»¤µÄÎÊÌâ 3.1 ¸ÅÄî½éÉÜ ÔÚ³ÌÐò±àдʱÓÅÐãµÄ³ÌÐòÔ±¶¼»áÖªµÀ£¬ÓÃÓÐÒâÒåµÄ±äÁ¿Ãû£¬ÎļþÃûÓÐÖúÓÚÔö¼Ó³ÌÐòµÄ¿É¶ÁÐÔ£¬¾ßÓÐÁ¼ºÃµÄ³ÌÐò·ç¸ñ¡£Õâ¸ö·Ç³£ºÃµ«Ôڽű¾Óï ÑÔ²»Ì«Êʺϣ¬ÎªÁ˲»ÈöñÒâÓû§²Âµ½ÄãµÄ±äÁ¿»òÊý¾Ý¿âÃûµÈÐÅÏ¢£¬±ØÐë¸ÄµôÕâЩÐÅÏ¢¡£¶¯Ì¬µÄÍøÒ³ÔÚ·þÎñÆ÷¶ËÖ´Ðк󷵻ظø¿Í»§µÄÊÇÖ´Ðкó µÄ´úÂ룬Õâ¿ÉÒÔ±£»¤·þÎñÆ÷¶ËµÄºÜ¶à²»Ïë½Ð»ò²»ÄܽÐä¯ÀÀÕßÖªµÀµÄÐÅÏ¢¡£°²È«ÊÇÏà¶ÔµÄ£¬Ã¿Ì춼ÔÚÓÐÐµİ²È«Â©¶´±»·¢ÏÖ£¬Èç¹û¶ñÒâµÄÓû§ ÔÚÄã֮ǰ֪µÀÁËÒ»¸ö¿ÉÒÔ¿´ÄãµÄ½Å±¾Ô´´úÂëµÄ©¶´»òÕâ¸ö©¶´Ò»Ê±¼äÎÞ·¨ÐÞ²¹Ôõô°ì£¿ 3.2 Ö÷ÒâÒªµã ½¨ÒéÓÃһЩ±È½Ï¹ÖÒìµÄÃû×ÖÃüÃû£¬É¾µô½Å±¾ÖеÄ×¢ÊÍ¡£Èç¹û»¹ÐèÒª±£³Ö³ÌÐòµÄ¿É¶ÁÐԵĻ°£¬¿ÉÒÔ½¨Á¢Ò»¸öÓ³É䣬Äã¿ÉÒÔд¸ö¾ßÓÐÁ¼ºÃ·ç¸ñµÄ ½Å±¾³ÌÐò£¬È»ºóÔÙ×öÒ»¸ö±äÁ¿ÃûÓ³É佨Á¢Ò»¸ö¾ßÓнϰ²È«ÃüÃû·½·¨µÄ½Å±¾£¬È¥µôÕâ¸ö½Å±¾ÖеÄ×¢ÊÓºÍËùÓÐÄÜÈ¥µôµÄÐÅÏ¢£¬ÐÞ¸Äʱ×÷¸öͬ²½¾Í ¿ÉÒÔÁËÎÒÃÇ¿ÉÒÔÔÚ³ÌÐòµÄʹÓÃÇ°¶Ô³ÌÐò½øÐмÓÃÜ£¬ÒÔ±£»¤ÎÒÃÇ×Ô¼ºµÄ³ÌÐòÔÙÍòÒ»µÄÇé¿öϲ¿±»Ð¹Â©¡£ 3.3 ±£»¤·½·¨ ÎÒ¿´µ½¹ýºÜ¶àµÄ¶Ô½Å±¾µÄ¼ÓÃÜ·½·¨£¬¶¼ºÜ²»´í£¬ÓеÄÊÇרÃŵļÓÃÜÈí¼þ£¬ÓеÄÊÇͨ¹ýһЩ¼¼ÇɼÓÉÏÀûÓÃÓïÑÔµÄÌØÐÔ½øÐмÓÃܵģ¬ÀýÈçËæ»úÉú ³ÉÒ»¸öÃܳף¬°ÑÃܳ׷ÅÔÚ"²»¿É¼ûµÄ"µØ·½£¬Í¨¹ýһЩËã·¨¶Ô½Å±¾½øÐмӽâÃÜ£¬¾ÍÊÇÓÉÓÚijЩϵͳ©¶´µ¼ÖÂÄãµÄ½Å±¾Ô´´úÂëй©£¬Ò²ÎÞ¼ÃÓÚÊ¡£ 4 .ʵÀý˵Ã÷ ÏÂÃæÕâ¸öÀý×ÓÊÇÔÚÍøÉϾ³£±»Ìáµ½µÄ£¬ÕâÊǸö·Ç³£¾µäµÄÀý×Ó£¬ËùÒÔÔÚÕâÀïͨ¹ýÕâ¸öʵÀý¸æËß´ó¼Ò¿ÉÄÜ´æÔÚµÄΣÏÕ¡£ ÎÊÌâÃèÊö£º ¡¡¡¡´ó²¿·ÖÍøÕ¾°ÑÃÜÂë·Åµ½Êý¾Ý¿âÖУ¬ÔڵǽÑéÖ¤ÖÐÓÃÒÔÏÂsql,(ÒÔaspΪÀý£© sql="select * from user where username='"&username&"'and pass='"& pass &'" ¡¡¡¡´Ëʱ£¬ÄúÖ»Òª¸ù¾Ýsql¹¹ÔìÒ»¸öÌØÊâµÄÓû§ÃûºÍÃÜÂ룬È磺ben' or '1'='1 ¾Í¿ÉÒÔ½øÈë±¾À´ÄãûÓÐÌØȨµÄÒ³Ãæ¡£ÔÙÀ´¿´¿´ÉÏÃæÄǸöÓï¾ä°É£º sql="select * from user where username='"&username&"'and pass='"& pass&'" ¡¡¡¡´Ëʱ£¬ÄúÖ»Òª¸ù¾Ýsql¹¹ÔìÒ»¸öÌØÊâµÄÓû§ÃûºÍÃÜÂ룬È磺ben' or '1'='1 ÕâÑù,³ÌÐò½«»á±ä³ÉÕâÑù: sql="select*from username where username="&ben'or'1'=1&"and pass="&pass&" or ÊÇÒ»¸öÂß¼ÔËËã·û,×÷ÓÃÊÇÔÚÅжÏÁ½¸öÌõ¼þµÄʱºò,Ö»ÒªÆäÖÐÒ»¸öÌõ¼þ³ÉÁ¢,ÄÇôµÈʽ ½«»á³ÉÁ¢.¶øÔÚÓïÑÔÖÐ,ÊÇÒÔ1À´´ú±íÕæµÄ(³ÉÁ¢).ÄÇôÔÚÕâÐÐÓï¾äÖÐ,ÔÓï¾äµÄ"and"ÑéÖ¤½«²»ÔÙ¼ÌÐø,¶øÒòΪ"1=1"ºÍ"or"ÁîÓï¾ä·µ»ØΪÕæÖµ.¡£ ¡¡¡¡ÁíÍâÎÒÃÇÒ²¿ÉÒÔ¹¹ÔìÒÔϵÄÓû§Ãû£º username='aa' or username<>'aa' pass='aa' or pass<>'aa' ¡¡¡¡ÏàÓ¦µÄÔÚä¯ÀÀÆ÷¶ËµÄÓû§Ãû¿òÄÚдÈ룺aa' or username<>'aa ¿ÚÁî¿òÄÚдÈ룺aa' or pass<>'aa,×¢ÒâÕâÁ½¸ö×Ö·û´®Á½Í·ÊÇûÓÐ'µÄ¡£Õâ Ñù¾Í¿ÉÒԳɹ¦µÄƹýϵͳ¶ø½øÈë¡£ ¾ßÌåʵʩÊÇÕâÑùµÄ£¬Ê×ÏÈÎһᵽע²áµÄµØ·½È¥ÊÕ¼¯ÐÅÏ¢£¬Á˽⾡¿ÉÄܶàµÄÐÅÏ¢£¬ÀýÈçÄ¿±êÊý¾Ý¿âÖж¼ÓÐÓû§µÄʲôÑùµÄÐÅÏ¢£¬Ëæ±ãµÄÌîдЊϢȻºóÌá½»£¬µ±ÄãҪע²áµÄÓû§Ãû±»×¢²áµÄÊÇÓÐϵͳ»áÌáʾÄãÒѱ»×¢²á£¬ÓеÄÍøÕ¾×öµÄ¸üºÃµÄ£¬¾ÍÊÇËûÃÇרßøÄãÉèÖõļì²âÊÇ·ñÓÐÒѾ±» ×¢²áµÄ¹¦ÄÜ£¬Í¨¹ýÕâÑù¾Í»á·Ç³£ÈÝÒ×µÄÕÒµ½Ä¿±ê--ÄǸöÌáʾÒѱ»×¢²áµÄÓû§£¬ÈúóÄãÔÚÕâ¸ö×¢²áÒ³ÀïÌîдһЩÌØÊâµÄ×Ö·û£¬Èç'£¬/£¬,µÈ×Ö·û¿´ ϵͳÈçºÎÌáʾ£¬ÒÔÖ¤Ã÷³ÌÐòÔ±ÊÇ·ñ×¢Òâµ½ÁËÓ¦¸Ã¹ýÂË×Ö·û»ò¶®µÃÊÇ·ñÓ¦¸Ã¹ýÂËÄÇЩ×Ö·û£¬ÔÚÕâÒ³½øÐг¢ÊÔÊÇÒòΪÓеÄÍøÕ¾ÔڵǼµÄʱºòËû»á ¼Ç¼ÄãµÄipµØÖ·£¬µ±È»ÄãÒ²¿ÉÒÔÕÒÒ»¸ö±ÈÄãÖ±½ÓµÇ¼Ҫ¿ìµÄ´úÀí·þÎñÆ÷À´×öÌø°å¡£ºóÃæÄãÒª×öµÄ¾ÍÊDz쿴µÇ¼ҳµÄhtmlÔ´´úÂ룬¿´¿´ÊÇ·ñÓÐÔÚ ¿Í»§¶ËµÄ×Ö·û¹ýÂË£¬¿´¿´Õâ¸ö³ÌÐòÔ±ÊÇÓÃʲô·ç¸ñÀ´±àд³ÌÐò£¬¾¡¿ÉÄܶàµÄÁ˽â³ÌÐò±àд·ç¸ñ£¬Õâ¶ÔÄãÒÔºóµÄijЩÅжÏÓкô¦¡£Èç¹ûÓÐÔÚ¿Í »§¶ËµÄ¹ýÂËÒ²²»Å£¬ÄãÒª¸ãÇåÊÇʲôÑùµÄ¹ýÂË£¬Äܲ»ÄܶԹ¥»÷Ôì³ÉÍþв£¬²»ÒªÒ»¿´ÓйýÂ˾ͺ¦Å£¬¿ÉÒÔ³¢ÊÔ×ÅÓñðµÄ·½·¨ÈÆ£¬¾ÍÊÇʹÓÃ×Ô¼º ¾«ÐÄ´òÔìµÄ¶ÀÁ¢½Å±¾£¬½øÐй¥»÷¡£È»ºóÄãÒª¿´¿´formµÄactionÖеÄurlÊÇ·ñ¿ÉÒÔÖ±½ÓÌá½»£¬ÔÚä¯ÀÀÆ÷µØÖ·À¸ÀïÖ±½ÓÌá½»£¬¿´¿´·µ»Øʲô£¬ÊÇ·ñ ÓÐÀ´Â·¼ì²â¡£»¹ÓкܶàϸСµÄµØ·½£¬ÄãÒ²Ó¦¸Ã¿ÉÒÔ×¢Òâµ½£¬ÀýÈçÄÇЩµØ·½³ÌÐòÔ±µÄÕûÌåµÄ±àд·ç¸ñÊÇʲô£¬±äÁ¿Ãû¶¨ÒåµÄ·ç¸ñÊÇʲôµÈµÈ£¬ Õâ¸ö»á°ïÎÒÃÇ"²Â"µ½ºÜ¶à¶«Î÷¡£»¹ÓбðµÄÆäËûʲô£¬ÎÒÒ²¼Ç²»Ì«Çå³þÁË£¬ÁÙ³¡·¢»Ó°É¡£Í¨¹ýÕâЩÁ˽âÎÒÃÇÓÐÈçϼ¸ÖÖ¿ÉÄÜ£º 1.ÄǸö³ÌÐòÔ±·Ç³£ÉÆÁ¼ÏàÐÅÈ«ÊÀ½ç¶¼ÊǺÃÈË£¬Ê²Ã´¶¼Ã»×ö£¬¸ù±¾Ã»ÓÐÈκμì²â»úÖÆ£¬ÎÒÃÇÖ±½ÓÓÃusername='aa' or username<>'aa'£¬ pass='aa' or pass<>'aa'¾Í¿ÉÒԸ㶨£¬ÏÖÔÚÕâôÉÆÁ¼µÄÈËÉÙÀ²£¬¿ÉÊÇÄãÒªÊÇÓÐÄÍÐÄ£¬ÕÒµ½ÕâÖÖÈË»¹ÊDz»Äѵġ£ 2.Õâ¸ö³ÌÐòÔ±¿ÉÄÜÌý±ðÈËÌáÆð¹ýһЩ°²È«ÎÊÌ⣬±Ï¾¹ÏÖÔÚÕâ¸öÄÇÀﶼÓÐÈË˵£¬ºÜ¶àÊéÖж¼ÓÐÌá¼°£¬µ«ÊÇ×öµÃ²»¹»ºÃ£¬ËûÖ»½øÐÐÁ˼òµ¥µÄÊäÈë¹ý ÂË¡£¹ýÂËÓÐÁ½ÖÖ·½Ê½£¬Ò»ÖÖÊÇÔÚ¿Í»§¶ËµÄ¹ýÂË£¬Ò»ÖÖÊÇÔÚ·þÎñÆ÷¶ËµÄ¹ýÂË¡£ÏÖÔںܶàµÄ³ÌÐòÔ±¿¼Âǵ½ÔÙ·þÎñÆ÷¶Ë½øÐйýÂË¿ÉÄܸø·þÎñÆ÷Ôì³É ¸ü¶àµÄ¸ººÉ£¬»á°Ñ¼ì²â¹ý³Ì·ÅÔÚ¿Í»§¶Ë¡£Èç¹ûËûÔÚ·þÎñÆ÷¶Ëû×öÈκÎÊÂÇ飬ÄÇô»¹ÊÇ¿ÉÒÔ¶ÔÆä½øÐй¥»÷µÄ£¬ÎÒ¿ÉÒÔ½«Õâ¸öµÇ¼ҳµÄÔ´´úÂëCO PYÏÂÀ´£¬È»ºó×Ô¼º½¨Á¢Ò»¸öÎļþ°ÑÕâЩ´úÂëPASTE½øÈ¥£¬ÔÙ¶ÔÕâ¸öÎļþ½øÐнøÒ»²½µÄÉî¼Ó¹¤£¬È¥µôÔÀ´Ò³µÄ¹ýÂË»úÖÆ£¬»òÕßÖ±½Ó½«¹¥»÷´úÂë дµ½Õâ¸öÎļþÖÐÈ¥£¬È»ºó½«formÖеÄactionÖеĵØÖ·¸Ä³É¾ø¶ÔµØÖ·£¬Ò²¾ÍÊǽ«ÎļþÃû¸Ä³É"http://www.target.com/targer.php"ÕâÑù£¬È»ºó ¾Í¿ÉÒÔÌá½»À²¡£µ«ÊÇÈç¹û·þÎñÆ÷¶Ë¼ÓÉÏÁË"À´Â·¼ì²â"£¬Äã¾Í°×ÍæÁË¡£Èç¹ûÕâÑù»¹ÊDz»ÐУ¬ÎÒÔÙ»»Ò»ÖÖ·½·¨£¬ÔÚä¯ÀÀÆ÷µÄµØÖ·À¸ÀïÓã¿À´ÊäÈë²Î Êý£¬¾ÍºÃÏñ"http://www.targer.com/targer.php?username='aa' or username<>'aa'&pass='aa' or pass<>'aa' "È»ºóÇûسµ°É£¬ÆäʵӦ¸ÃÏȳ¢ÊÔÕâÖÖ·½·¨ÒòΪÕâÓ÷½·¨¸ü¼òµ¥£¬·À»¤ÆðÀ´Ò²ºÜ¼òµ¥£¬ÕâÖÖÌá½»·½Ê½²»ÊÇpost ¶øÊÇget £¬Ö»Òª·þÎñÆ÷¶Ë³ÌÐò¼ì²âÄãµÄÌá½»·½·¨£¬¾Í¿ÉÒÔkillµôÕâ¸öÒõı¡£Èç¹ûµ¥´¿µÄÖ»¼ì²âÁË"À´Â·"£¬»¹ÊDz»Ì«°²È«µÄ£¬¿ÉÒÔÏÈÕýÈ·µÄÌá½»Ò»´Î£¬ÔÚ Ìá½»¹ý³ÌÖÐÂíÉÏÍ£Ö¹£¬¾ÍÊDZ£´æÕâ¸ö»·¾³£¬È»ºóÔÙ¹¹ÔìÇëÇó.ÎÒ×ö¹ý¼¸´ÎÊÔÑéµÃµ½µÄ½á¹û¶¼²»Ì«Ò»Ñù£¬Ó¦¸ÃÊǺÍÖÕÖ¹µÄʱ»úÓйأ¬»¶Ó´ó¼ÒÀ´ ½»Á÷£©¡£ 3.Ò»¸öºÜ³öÉ«µÄ³ÌÐòÔ±£¬°²È«Òâʶ·Ç³£¸ß£¬ËûÔÚ·þÎñÆ÷¶Ë×öÁËÈçϼì²â£º¼ì²âÌá½»µÄ·½·¨£»¼ì²âÌá½»µÄ"À´Â·"£»¼ì²âÌá½»ÄÚÈݵij¤¶È£»È«Ãæ¼ì ²âÌá½»ÄÚÈÝ£¬ÕâÑùÎÒÃǾͺÜÄÑͨ¹ýÉÏÃæµÄ·½·¨¶ÔÆä½øÐй¥»÷£¬Äǵ½±£ÃܵÄ×ÊÁϾÍÒѾ²»Ì«¿ÉÄÜÁË£¨Èç¹û¸÷λ»¹ÓÐʲôºÃµÄ°ì·¨£¬ÇëÒ»¶¨À´ÐÅ ¸æËßСµÜ£¬Ð¡µÜÔÚÕâÀïÏÈлÁË£©¡£µ«ÊÇÎÒ»¹Ïë˵µÄÊǹ¥»÷²¢²»´ú±íÊÇ·ÇÒªÈëÇÖ½øÈ¥£¬Äõ½Ä³Ð©¶«Î÷²Å½ÐÈëÇÖ£¬¶ÔÄãµÄ»úÆ÷½øÐÐÆÆ»µÒ²½ÐÈëÇÖ °¡£¬ÀýÈçÌύһЩ´íÎóµÄÇëÇ󣬽ű¾½âÊͳÌÐò¾Í»á·Ç³£¹æ¾ØµÄ¸øÄã·µ»Ø´íÎóÐÅÏ¢£¬×îdzÏԵĺó¹û¾ÍÊDZ©Â¶ÎïÀí·¾£¬ÓеÄʱºòһЩÌØÊâµÄÇë Çó»áʹweb·þÎñå´µô£¬ÕâЩ¸öÎÒÈÏΪ¾ø¶ÔÊÇÊôÓÚ¹¥»÷£¬¾ø¶ÔÊÇΣº¦£¬Ò²ÐíÄãÈÏΪ±©Â¶ÎïÀí·¾¶Ã»ÓÐʲô£¬ÊÇÔÚµ¥¶À¿´À´Ã»ÓÐʲô£¬µ«ÒªÊÇÔÚÒ» ¸öÓмƻ®µÄ¹¥»÷ÀÕâ¸ö¾Í»á·¢»ÓºÜ¶à×÷Óã¬ÄÇʱÄã¿ÉÄÜ»¹»áĪÃûΪʲôËûÃÇÕÒµ½ÁËÎÒµÄÎļþÄØ¡£Ò²ÐíÓÐÈËÈÏΪÕâ¸öÊǽű¾½âÊͳÌÐòµÄbug£¬ Ò²ÐíÓеÄÊÇ£¬µ«ÊÇ·µ»Ø´íÎóÐÅÏ¢¾ø¶Ô²»Êǽű¾½âÊͳÌÐòµÄ´íÎó£¬Õâ¸öÊÇÿ¸ö½âÊͳÌÐò¶¼Òª×öµ½µÄ£¬ÔÚÎÒ¿´À´Õâ¸öÓ¦¸ÃÊÇ»¹ÊdzÌÐòÔ±µÄÎÊÌ⣬ ³ÌÐòԱûÓÐ×öºÃ¶Ô´íÎóµÄ´¦Àí¡£Ã¿Ò»±¾½ÌÄãÈçºÎ±àд³ÌÐòµÄÊé¼®Àï»ù±¾¶¼»áÓдíÎó´¦ÀíÖ®ÀàµÄÕ½ڣ¬²¢ÇÒÿÖÖÓïÑÔ»ù±¾¶¼ÓдíÎó´¦Àíº¯ÊýºÍ ·½·¨£¬Ö»²»¹ýÄãûÓÐÏëµ½°ÕÁË¡£ÖÁÓÚ¾¿¾¹ÒªÔõô´¦ÀíÄǾÍÒª¿´Äã¶Ôcgi³ÌÐò°²È«µÄÊìϤ³Ì¶ÈÁË£¬ÄǾÍÒª¿´Äã¶ÔÕâÖֽű¾ÓïÑÔµÄÌØÐÔÊìϤ¶àÉÙÁË £¬Ëµµ½µ×¾ÍÊǾÑ飬ΨһµÄ°ì·¨¾ÍÊǶ࿴¶àд¶àÏë¶à½»Á÷¡£ 4.·Ç³£ÓÅÐãµÄ³ÌÐòÔ±£¬ÒÔÉÏÄÇЩ×öµÄ¶¼·Ç³£ºÃ£¨Ò²Ðí¾ÍÊÇÄã°¡£¬±Ï¾¹²»ÄÑÂ¼ÓÉϺÜÉٵĴúÂë¾Í¿ÉÒÔÁË£©£¬Ôõô°ì£¿£¿Ôõô°ì£¿£¡Ôõô°ì£¡£¡ ÔÚÒ»ÅÔ͵͵µÄÅå·þ°É£¡¹þ¹þ¡£ 5. ÆäËü×¢ÒâÊÂÏ˼·ºÍ·½·¨ Ö¸µ¼Ë¼Ï룺 I.Ñϸñ¿ØÖƳÌÐòÓëÓû§½»»¥µÄ;¾¶ II.Ñϸñ¿ØÖƳÌÐòÓëÓû§½»»¥µÄÄÚÈÝ III.¾¡¿ÉÄܺõı£»¤ÎÒÃÇ¿ØÖÆ »ù±¾Ë¼Â·£º I.Ϊûһ¸ö¹¦ÄÜдһ¸ö¶ÀÁ¢µÄ³ÌÐò£¬³ÌÐòÒ³ II.¾¡¿ÉÄÜÉÙµÄÈÿͻ§Á˽âÄãµÄ·þÎñÆ÷¶ËÐÅÏ¢ III.²»ÒªÓÃ"¿Í»§Ó¦¸ÃÕâôд"Õâ¸ö˼·ÏëÎÊÌâ IV.¾¡¿ÉÄܶàµÄÏëµ½²»¿ÉÄÜ·¢ÉúµÄÊÂÇé »ù±¾·½·¨£º ¾¡¿ÉÄܶàµÄ¿ØÖƽ»»¥£º I.¼ì²âÌá½»µÄ·½·¨£¬¾ÍÊÇ¿ØÖÆËûµÄpost»¹ÊÇget£» II.¼ì²âÌá½»µÄ"À´Â·"£¬¾ÍÊǼì²âÒ»¸ö»·¾³±äÁ¿HTTP_REFERER£» III.¼ì²âÌá½»ÄÚÈݵij¤¶È£» IVÈ«Ãæ¼ì²âÌá½»ÄÚÈÝ£» »ý¼«-Ïû¼«·À»¤£º I.¾¡¿ÉÄܶàµÄ´íÎó´¦Àí£¬ÀýÈçµ±¼ì²âµ½Á˲»ÕýÈ·µÄÊäÈëʱ£¬Ó¦¸ÃÔõô×ö£¬ÊÇÇ¿ÖÆ·µ»Ø£¬»¹ÊÇ·¢³ö¾¯¸æ£» II.³ä·Ö·¢»ÓÈÕÖ¾¹¦Óã¬ÀýÈçÔÚÄã¼ì²âµ½Á˲»ÕýÈ·µÄÌύʱ£¬¾Í¼Ç¼Ï¿ͻ§¶ËµÄÐÅÏ¢£¬ÀýÈçIP£¬ÏµÍ³ÅäÖã¬ÇëÇóµÈµÈ£¬±Ï¾¹ÏÖÔÚÊǼ¼Êõ·ÉÔ¾µÄʱ ´ú£¬²»Äܱ£Ö¤¿ÉÒÔÏ뵽ÿһÖÖ¿ÉÄÜ£¬ÕâÒ²ÊÇÎÒÔÚÕâƪÎÄÕÂÀï²»Ö¹Ò»´ÎÌáµ½"¾¡¿ÉÄÜ"Õâ¸ö´ÊµÄÔÒò¡£³ä·ÖµÄÈÕÖ¾¼Ç¼²»È«ÊÇΪÁËץסÈëÇÖÕߣ¨Èç ¹ûÈëÇÖÕßʹÓÃÁËÌø°å£¬¼Ç¼ÁËIPÒ²ÊÇûÓÐÓõģ©£¬¸üÖØÒªµÄÊÇΪÁËÄÜ·¢ÏÖÎÊÌâµÄËùÔÚ£¬ÕÒµ½ÎÊÌ⣬¸ÄÕýÎÊÌ⣬ÍöÑò²¹ÀΣ¬Õâ¸ö²ÅÊÇ×îÖØÒªµÄ¡£ III.³ä·Ö·¢»ÓÄãµÄÏëÏóÁ¦£¬ÓÃÒ»ÖÖÈëÇÖÕßµÄ˼Ï뿼ÂÇÎÊÌ⣬ÓÃÒ»ÖÖÁíÀàµÄ˼Ï뿼ÂÇÎÊÌ⣬¾¡¿ÉÄÜÏëµ½²»¿ÉÄÜ·¢ÉúµÄÊ£¬°ÑÎÊÌâ¶óɱÔÚÃÈÑ¿Àï¡£ ÎÒÃÇxundi¸ç˵µÄºÃ£ºÕÆÎÕ·½·¨£¡£¡£¡ÏÖÔڽű¾ÓïÑÔ²ã³ö²»Çasp£¬perl£¬php£¬jspµÈµÈ£¬»ù±¾²»¿ÉÄܾ«Í¨Ã¿Ò»ÖÖ£¬£¨Ò²ÐíÄãÀ÷º¦£¬¶¼Äܾ«Í¨ £¬ÎұȽϴô£¬»áÒ»¸ö¾Í²»´íÀ²£©£¬µ«ÊÇÒªÊÇÕÆÎÕÁË·½·¨¾Í²»Í¬ÁË°¡£¬¸÷λÍøÂçµÄ¾«Ó¢¾ÙÒ»·´Èý´¥ÀàÅÔͨ£¬¿Ï¶¨ÊÇÓÅÐãµÄ²»µÃÁË¡£ÎÒд½Å±¾Ò» ¹²Ò²Ã»¶àÉÙÌ죬дÕâ¸ö¶«Î÷ÎÒÖªµÀ¿Ï¶¨ÊÇ°àÃÅŪ¸«ÁË£¬´íÎóÖ®´¦»¹Çë¸÷λ´óϺ±§×ÅÍì¾ÈºÍ°ïÖúµÄ¾«Éñ£¬¸æ֪СµÜ£¨·½Ê½¡¢·½·¨¡¢Ì¬¶È²»ÏÞ£© £¬Ð¡µÜÎÒÔÚÕâÀïÏÈлÁË¡£Ð´Õâ¸ö¶«Î÷£¬ÎÒÖ»ÊÇÏë˵˵СµÜµÄһЩСµÄÐĵã¬Óë´ó¼Ò¹²Ã㣬ÎÒÏë¸æËß´ó¼ÒµÄ¾ÍÊÇ"Áì»á¾«Éñ"£¬ºÙºÙ£¬"Áì»á¾«Éñ" ¡£´ó¼ÒÒªÊÇÓÐʲôºÃµÄ·½·¨£¬Ï£Íû²»Òª±£Áô£¬³ä·Ö·¢»ÓÍøÂçµÄ×ÔÓù²Ïí£¬ÄóöÀ´£¬´ó¼Ò½»Á÷½»Á÷£¬²»Ê¤¸Ð¼¤¡£ÕâÀïÓкܶà¸ÅÄîµÄ¶«Î÷ÊÇÎÒ³ Ï®À´µÄ£¬ÕâÖÖ¶«Î÷СµÜ²»¸Ò×Ô¼ºÐ´£¨ºÙºÙ£¬Êµ¼Ê»¹Óв»ÉÙÀÁµÄ³É·Ö£¬¹þ¹þ£©£¬Ï£Íû´ó¼Ò²»Òª¼û¹Ö¡£ |