dr5648 2011-04-16 07:55
浏览 27

由于SQL注入导致进入数据库驱动的Web开发感到紧张[重复]

Possible Duplicates:
What is SQL injection?
In PHP when submitting strings to the DB should I take care of illegal characters using htmlspecialchars() or use regex?

I really need someone to clearly explain how to handle hackers and if it's really as complicated as it sounds.

  • 写回答

3条回答 默认 最新

  • duanjiati1755 2011-04-16 08:00
    关注

    The basic thing to do about sql injection is to use parameters in your queries.

    So, this is BAD, and could be used for injecting hackers's sql:

    mySqlCommand.Text = "select * from mytable where FirstName = " + tbox.Text;
    

    Do it this way:

    mySqlCommand.Parameters.Add("@FirstName", tbox.Text)
    mySqlCommand.Text = "select * from mytable where FirstName = @FirstName";
    

    Note: I used "pseudo code". I Don't know php or mysql, but the same principle should apply.

    评论

报告相同问题?

悬赏问题

  • ¥15 2020长安杯与连接网探
  • ¥15 关于#matlab#的问题:在模糊控制器中选出线路信息,在simulink中根据线路信息生成速度时间目标曲线(初速度为20m/s,15秒后减为0的速度时间图像)我想问线路信息是什么
  • ¥15 banner广告展示设置多少时间不怎么会消耗用户价值
  • ¥16 mybatis的代理对象无法通过@Autowired装填
  • ¥15 可见光定位matlab仿真
  • ¥15 arduino 四自由度机械臂
  • ¥15 wordpress 产品图片 GIF 没法显示
  • ¥15 求三国群英传pl国战时间的修改方法
  • ¥15 matlab代码代写,需写出详细代码,代价私
  • ¥15 ROS系统搭建请教(跨境电商用途)