'##############SQL防注入说明############################
' 随州视窗ehbsz.com SQL防注入 for GYCMS3.0
' 思客秀gyct.cn by gannyle
' 2006-6-26
'##############SQL防注入说明############################
'--------定义部份------------------
Dim Gyct_Post,Gyct_Get,Gyct_In,Gyct_Inf,Gyct_Xh,Gyct_db,Gyct_dbstr,Kill_IP,WriteSql
'自定义需要过滤的字串,用 "|" 分隔
Gyct_In = "'|;|and|(|)|exec|insert|select|delete|update|count|*|%
|chr|mid|master|truncate|char|declare"
Kill_IP=True
WriteSql=True
'----------------------------------
Gyct_Inf = split(Gyct_In,"|")
'--------POST部份------------------
If Request.Form<>"" Then
For Each Gyct_Post In Request.Form
For Gyct_Xh=0 To Ubound(Gyct_Inf)
If Instr(LCase(Request.Form(Gyct_Post)),Gyct_Inf(Gyct_Xh))<>0
Then
If WriteSql=True Then
call joekoe_cms.exec("insert into fuck
(Sqlin_IP,SqlIn_Web,SqlIn_FS,SqlIn_CS,SqlIn_SJ) values('"&Request.ServerVariables
("REMOTE_ADDR")&"','"&Request.ServerVariables("URL")
&"','POST','"&Gyct_Post&"','"&replace(Request.Form(Gyct_Post),"'","''")&"')",0)
set rs=joekoe_cms.exec(sql,1)
rs.close
Set conn = Nothing
End If
Response.Write "<Script Language=JavaScript>alert('思
客秀系统提示你,请不要给本站提交任何非法字符或参数尝试注入!');</Script>"
Response.Write "非法操作!系统做了如下记录↓<br>"
Response.Write "操作IP:"&Request.ServerVariables
("REMOTE_ADDR")&"<br>"
Response.Write "操作时间:"&Now&"<br>"
Response.Write "操作页面:"&Request.ServerVariables
("URL")&"<br>"
Response.Write "提交方式:POST<br>"
Response.Write "提交参数:"&Gyct_Post&"<br>"
Response.Write "提交数据:"&Request.Form(Gyct_Post)
Response.End
End If
Next
Next
End If
'----------------------------------
'--------GET部份-------------------
If Request.QueryString<>"" Then
For Each Gyct_Get In Request.QueryString
For Gyct_Xh=0 To Ubound(Gyct_Inf)
If Instr(LCase(Request.QueryString(Gyct_Get)),Gyct_Inf
(Gyct_Xh))<>0 Then
If WriteSql=True Then
call joekoe_cms.exec("insert into fuck
(Sqlin_IP,SqlIn_Web,SqlIn_FS,SqlIn_CS,SqlIn_SJ) values('"&Request.ServerVariables
("REMOTE_ADDR")&"','"&Request.ServerVariables("URL")
&"','GET','"&Gyct_Get&"','"&replace(Request.QueryString(Gyct_Get),"'","''")&"')",0)
set rs=joekoe_cms.exec(sql,1)
rs.close
Set conn = Nothing
End If
Response.Write "<Script Language=JavaScript>alert('思
客秀系统提示你,请不要给本站提交任何非法字符或参数尝试注入!');</Script>"
Response.Write "非法操作!系统做了如下记录↓<br>"
Response.Write "操作IP:"&Request.ServerVariables
("REMOTE_ADDR")&"<br>"
Response.Write "操作时间:"&Now&"<br>"
Response.Write "操作页面:"&Request.ServerVariables
("URL")&"<br>"
Response.Write "提交方式:GET<br>"
Response.Write "提交参数:"&Gyct_Get&"<br>"
Response.Write "提交数据:"&Request.QueryString
(Gyct_Get)
Response.End
End If
Next
Next
End If
If Kill_IP=True Then
Dim Sqlin_IP,rsKill_IP,Kill_IPsql
Kill_IPsql="select Sqlin_IP from fuck where Sqlin_IP='"&Sqlin_IP&"' and
kill_ip=true"
set rsKill_IP=joekoe_cms.exec(Kill_IPsql,1)
If Not(rsKill_IP.eof or rsKill_IP.bof) Then
Response.write "<Script Language=JavaScript>alert('随州视窗系统提示你,
你的IP已比管理员限制进入!原因可能是你尝试注入本
站!');location.href='about:blank'</script><script>window.close();</script>"
Response.End
End If
rsKill_IP.close
End If
'##############SQL防注入说明############################
' 随州视窗ehbsz.com SQL防注入 for GYCMS3.0
' 思客秀gyct.cn by gannyle
' 2006-6-26
'##############SQL防注入说明############################






正在处理数据..

