ASP.net中防止sql注入攻击

    void Application_BeginRequest(object sender,EventArgs e)
    {
        StartRequest();
    }

    private bool ProcessSqlStr(string Str)
    {
        bool ReturnValue = true;
        if (Str != null)
        {
            try
            {
                if(Str.Trim()!= "")
                {
                    string SqlStr = "exec|insert|select|delete|master|update|truncate|declare|cmd|or|char|and|join|'|--";
                    string[] anySqlStr = SqlStr.Split('|');
                    foreach (string ss in anySqlStr)
                    {
                        if (!Str.ToLower().Contains("updatepanel"))
                        {
                            if (Str.ToLower().IndexOf(ss) >= 0)
                            {
                                ReturnValue = false;
                                break;
                            }
                        }
                    }
                }
            }
            catch
            {
                ReturnValue = false;
            }
        }
        return ReturnValue;
    }
   
    private void StartRequest()
    {
        try
        {
            string getkeys = "";
            string sqlErrorPage = "Error.aspx";
            if (System.Web.HttpContext.Current.Request.QueryString!= null)
            {
                for (int i = 0; i < System.Web.HttpContext.Current.Request.QueryString.Count; i++)
                {
                    getkeys = System.Web.HttpContext.Current.Request.QueryString.Keys[i];
                    if (getkeys == "_VIEWSTATE") continue;
                    if (!ProcessSqlStr(System.Web.HttpContext.Current.Request.QueryString[getkeys].ToString()))
                    {
                        System.Web.HttpContext.Current.Response.Redirect(sqlErrorPage);
                        System.Web.HttpContext.Current.Response.End();
                    }
                }
            }
            if (System.Web.HttpContext.Current.Request.Form != null)
            {
                for (int k = 0; k < System.Web.HttpContext.Current.Request.Form.Count; k++)
                {
                    getkeys = System.Web.HttpContext.Current.Request.Form[2].ToString();
                    if (getkeys == "_VIEWSTATE") continue;
                    if (!ProcessSqlStr(System.Web.HttpContext.Current.Request.Form[getkeys].ToString()))
                    {
                        System.Web.HttpContext.Current.Response.Redirect(sqlErrorPage);
                        System.Web.HttpContext.Current.Response.End();
                    }
                }
            }
        }
        catch
        {
            
        }
    }

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值