锘?!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<%
'Dim yisenceinje_Post,yisenceinje_Get,yisenceinje_In,yisenceinje_Inf,yisenceinje_Xh,yisenceinje_db,yisenceinje_dbstr
'您可以在yisenceinje_In中新增要过滤的参数,用#号隔开
yisenceinje_In = "'#;#and#exec#insert#select#delete#update#count#chr#mid#master#truncate#char#declare"
yisenceinje_Inf = split(yisenceinje_In,"#")
'判断post参数
If Request.Form<>"" Then StopInjection(Request.Form)
'判断get参数
If Request.QueryString<>"" Then StopInjection(Request.QueryString)
'判断cookies参数
If Request.Cookies<>"" Then StopInjection(Request.Cookies)
Function StopInjection(values)
For Each yisenceinje_Get In values
For yisenceinje_Xh=0 To Ubound(yisenceinje_Inf)
If Instr(LCase(values(yisenceinje_Get)),yisenceinje_Inf(yisenceinje_Xh))<>0 Then
Response.Write ""
Response.Write "非法操作!系统已经给你做了如下记录: "
Response.Write "操作IP:"&Request.ServerVariables("REMOTE_ADDR")&" "
Response.Write "操作时间:"&Now&" "
Response.Write "操作页面:"&Request.ServerVariables("URL")&" "
Response.Write "提交数据:"&values(yisenceinje_Get)
Response.End
End If
Next
Next
End Function
%>