28,404
社区成员
发帖
与我相关
我的任务
分享<%
''--------定义部份------------------
dim Fy_Post, Fy_Get, Fy_In, Fy_Inf, Fy_Xh, Fy_db, Fy_dbstr
''自定义需要过滤的字串,用 "防" 分隔
Fy_In = "''防;防and防exec防insert防select防delete防update防count防*防%防chr防mid防master防truncate防char防declare防<防>防=防|防-防_"
Fy_Inf = split(Fy_In, "防")
if Request.form<>"" then
for each Fy_Post In Request.form
for Fy_Xh = 0 to ubound(Fy_Inf)
if instr(lcase(Request.form(Fy_Post)), Fy_Inf(Fy_Xh))<>0 then
Response.write "非法操作!本站已经给大侠您做了如下记录↓<br>"
Response.write "操作IP:"&Request.ServerVariables("REMOTE_ADDR")&"<br>"
Response.write "操作时间:"&now&"<br>"
Response.write "操作页面:"&Request.ServerVariables("URL")&"<br>"
Response.write "提交方式:POST<br>"
Response.write "提交参数:"&Fy_Post&"<br>"
Response.write "提交数据:"&Request.form(Fy_Post)
Response.end
end if
next
next
end if
if Request.QueryString<>"" then
for each Fy_Get In Request.QueryString
for Fy_Xh = 0 to ubound(Fy_Inf)
if instr(lcase(Request.QueryString(Fy_Get)), Fy_Inf(Fy_Xh))<>0 then
Response.write "非法操作!本站已经给大侠您做了如下记录↓<br>"
Response.write "操作IP:"&Request.ServerVariables("REMOTE_ADDR")&"<br>"
Response.write "操作时间:"&now&"<br>"
Response.write "操作页面:"&Request.ServerVariables("URL")&"<br>"
Response.write "提交方式:GET<br>"
Response.write "提交参数:"&Fy_Get&"<br>"
Response.write "提交数据:"&Request.QueryString(Fy_Get)
Response.end
end if
next
next
end if
%>