⭐ 欢迎来到虫虫下载站! | 📦 资源下载 📁 资源专辑 ℹ️ 关于我们
⭐ 虫虫下载站

📄 conn.asp

📁 留言 留言本采用asp+access数据结构
💻 ASP
字号:
<%'    ==================================================
'//             粑粑工作室留言本
'//     程序版本:    粑粑工作室留言本 v2.1 
'//     技术支持:    www.gongliyi.cn
'//     程序演示:    www.gongliyi.cn/book2
'//     作    者:    龚礼仪(粑粑)
'//     文件信息:    conn.asp(数据库连接文件)
'//     最后修改:    2008.11.23   
'//     升级修改:    2008.12.12  
'    ==================================================
%>
<%

'--------定义部份------------------
Dim XH_Post,XH_Get,XH_In,XH_Inf,XH_Xh,XH_db,XH_dbstr
'自定义需要过滤的字串,用 "|" 分隔
XH_In = "'|;|and|exec|insert|select|delete%20from|update|count|*|%|chr|mid|master|truncate|char|declare|drop%20table|from|net%20user|xp_cmdshell|/add|net%20localgroup%20administrators|Asc|char"
'----------------------------------
%>

<%
XH_Inf = split(XH_In,"|")
'--------POST部份------------------
If Request.Form<>"" Then
For Each XH_Post In Request.Form

For XH_Xh=0 To Ubound(XH_Inf)
If Instr(LCase(Request.Form(XH_Post)),XH_Inf(XH_Xh))<>0 Then
Response.Write "<Script Language=JavaScript>alert('提交内容非法!有事加我QQ:253436577');</Script>"
Response.Write "非法操作!系统做了如下记录↓<br>"
Response.Write "操作Ip:"&Request.ServerVariables("REMOTE_ADDR")&"<br>"
Response.Write "操作时间:"&Now&"<br>"
Response.Write "操作页面:"&Request.ServerVariables("URL")&"<br>"
Response.Write "提交方式:post<br>"
Response.Write "提交参数:"&XH_Post&"<br>"
Response.Write "提交数据:"&Request.Form(XH_Post)
Response.Write "<Script Language=JavaScript>alert('提交内容非法!有事加我QQ:253436577');window.close();</Script>"
Response.End
End If
Next

Next
End If
'----------------------------------

'--------GET部份-------------------
If Request.QueryString<>"" Then
For Each XH_Get In Request.QueryString

For XH_Xh=0 To Ubound(XH_Inf)
If Instr(LCase(Request.QueryString(XH_Get)),XH_Inf(XH_Xh))<>0 Then
Response.Write "<Script Language=JavaScript>alert('提交内容非法!有事加我QQ:253436577');</Script>"
Response.Write "非法操作!系统做了如下记录↓<br>"
Response.Write "操作Ip:"&Request.ServerVariables("REMOTE_ADDR")&"<br>"
Response.Write "操作时间:"&Now&"<br>"
Response.Write "操作页面:"&Request.ServerVariables("URL")&"<br>"
Response.Write "提交方式:GET<br>"
Response.Write "提交参数:"&XH_Get&"<br>"
Response.Write "提交数据:"&Request.QueryString(XH_Get)
Response.Write "<Script Language=JavaScript>alert('提交内容非法!有事加我QQ:253436577');window.close();</Script>"
Response.End
End If
Next
Next
End If
'----------------------------------
%>

<%
dim conn,mydb,db,rs
On error resume next
db=dbstr&"data/#baba@%&%yaoyao520.asp"
AccessPath=dbstr&"data" 
Set Conn = Server.CreateObject("ADODB.Connection")
mydb="Provider=Microsoft.Jet.OLEDB.4.0;Data Source=" & Server.MapPath(""&db&"")
Conn.Open Mydb
%>

⌨️ 快捷键说明

复制代码 Ctrl + C
搜索代码 Ctrl + F
全屏模式 F11
切换主题 Ctrl + Shift + D
显示快捷键 ?
增大字号 Ctrl + =
减小字号 Ctrl + -