注入式攻击??
我现在的这段代码代码存在 了 会被 SQL 注入式攻击的问题··有人能帮我改下吗·· 使他不回被 攻击了
sqlcon = new SqlConnection(strCon);
sqlcon.Open();
string sqlstr = "SELECT * FROM [Future].[dbo].[Users] where [username]='" + Txtuser.Value + "'and [password]='" + Txtpass.Value + "'";
sqlstr.Replace("'", "''");
SqlDataAdapter MyAdapter = new SqlDataAdapter(sqlstr, sqlcon);
DataSet ds = new DataSet();
MyAdapter.Fill(ds);
sqlcon.Close();
if (ds.Tables[0].Rows.Count == 1)
{
Response.Redirect("datum.aspx");
}
else{
Response.Write("<script>alert('错误的用户名和密码')</script>");
}