📄 nosqlhack.asp
字号:
<%
Dim AV_NoSqlHack_AllStr,AV_NoSqlHack_Str,AV_NoSqlHack_ComeUrlGet,AV_NoSqlHack_ComeUrlPost,AV_NoSqlHack_Get,AV_NoSqlHack_Post,AV_NoSqlHack_i
'On Error Resume Next
AV_NoSqlHack_AllStr="'|;| and |chr(|exec |insert |select |delete from|update |mid(|master."
AV_NoSqlHack_ComeUrlGet = Request.QueryString
AV_NoSqlHack_ComeUrlPost = Request.Form
AV_NoSqlHack_Str = Split(AV_NoSqlHack_AllStr,"|")
'Post
If AV_NoSqlHack_ComeUrlPost<>"" then
For Each AV_NoSqlHack_Post In Request.Form
For AV_NoSqlHack_i = 0 To Ubound(AV_NoSqlHack_Str)
If Instr(LCase(Request.Form(AV_NoSqlHack_Post)),AV_NoSqlHack_Str(AV_NoSqlHack_i))<>0 Then
Response.End
End if
Next
Next
End if
'Get
If AV_NoSqlHack_ComeUrlGet<>"" then
For Each AV_NoSqlHack_Get In Request.QueryString
For AV_NoSqlHack_i = 0 To Ubound(AV_NoSqlHack_Str)
If Instr(LCase(Request.QueryString(AV_NoSqlHack_Get)),AV_NoSqlHack_Str(AV_NoSqlHack_i))<>0 Then
Response.End
End if
Next
Next
End if
%>
⌨️ 快捷键说明
复制代码
Ctrl + C
搜索代码
Ctrl + F
全屏模式
F11
切换主题
Ctrl + Shift + D
显示快捷键
?
增大字号
Ctrl + =
减小字号
Ctrl + -