saferequest.asp

来自「设计考虑校园电子商务模式」· ASP 代码 · 共 29 行

ASP
29
字号
<%
'****************************************************
' 多多校园                      Power by ddtaobao.com
' Email:ddmaster@126.com               OICQ:136465584 
' Web: http://www.ddtaobao.com              作者:多多
' 校园、企业、医院、公司程序定做,系统开发,网站制作!
' Copyright (C) 2007 ddtaobao.com All Rights Reserved
'****************************************************
%><%
Function SafeRequest(str)
  If not isNumeric(str) then
     response.Write "<script>alert('做什么呢!');"
     response.Write "window.history.back();</script>"
     response.end()
  Else
     SafeRequest=str
  End if
End function
%>
<%
Dim StrTemp
StrTemp=request.servervariables("server_name")&request.servervariables("url")&"?"&Request.QueryString
StrTemp=LCase(StrTemp)
If Instr(StrTemp,"select%20") or Instr(StrTemp,"insert%20") or Instr(StrTemp,"delete%20from") or Instr(StrTemp,"count(") or Instr(StrTemp,"drop%20table") or Instr(StrTemp,"asc(") or Instr(StrTemp,"truncate%20") or Instr(StrTemp,"update%20") or Instr(StrTemp,"mid(") or Instr(StrTemp,"chat(") or Instr(StrTemp,"xp_cmdshell") or Instr(StrTemp,"exec%20master") or Instr(StrTemp,"net%20localgroup administrator") or Instr(StrTemp,"net%20user") or Instr(StrTemp,"%20or") or Instr(StrTemp,"%20and") or Instr(StrTemp,"""") or Instr(StrTemp,"'") or Instr(StrTemp,"“") or Instr(StrTemp,"”") or Instr(StrTemp,":") or Instr(StrTemp,": ") or Instr(StrTemp,";") or Instr(StrTemp,"; ") or Instr(StrTemp,",") or Instr(StrTemp,", ") or Instr(StrTemp,"%27") then 
   Response.Write"<script language='javascript'>alert('错误的参数传递,请不要企图破解程序! ');history.back();</script>"
   Response.end
End If
%>

⌨️ 快捷键说明

复制代码Ctrl + C
搜索代码Ctrl + F
全屏模式F11
增大字号Ctrl + =
减小字号Ctrl + -
显示快捷键?