• λ我爱Aspx >> Asp.Net >> 【99%的人没见过的ASP注入,等待高手解决,急。。。。。。。。。 】
  • 【99%的人没见过的ASP注入,等待高手解决,急。。。。。。。。。 】

  • :aspxer  Դ:csdn  :2007-7-6 2:38:05  ؼ:asp
  • Next

    posterrlog=replace(strTemp,"&","?")

    Call SendErrorInfo(request.servervariables("HTTP_HOST"),posterrlog)

    strTemp = LCase(strTemp)

    strTemp = URLDecode(strTemp)

    If Instr(strTemp,"declare") or Instr(strTemp,";exec") or Instr(strTemp,"iframe") or Instr(strTemp,"wscript.shell") or Instr(strTemp,"cmd.exe") or Instr(strTemp,"select") or Instr(strTemp,"insert") or Instr(strTemp,"delete") or Instr(strTemp,"count(") or Instr(strTemp,"drop") or Instr(strTemp,"update") or Instr(strTemp,"truncate") or Instr(strTemp,"asc(") or Instr(strTemp,"mid(") or Instr(strTemp,"char(") or Instr(strTemp,"xp_") or Instr(strTemp,"net%20") or Instr(strTemp,"chr") or instr(strTemp,"union") or instr(strTemp,"unicode") or Instr(strTemp,""") or Instr(strTemp,"--") or Instr(strTemp,"%") then

    response.write("<script>alert("您的操作非法!");history.go(-1)</script>")

    Ҷƪл˵?
  • һƪ新手请教简单问题
    һƪ为什么我从网上抓取的数会有总是