| ºë±m±ÀÂË |
|
|
| ¤ÀÃþ³Ì·s±Ðµ{ |
|
| ¤ÀÃþ¼öÂI±Ðµ{ |
|
|
|
¸Ñ¨M¤èªk¡G
(1) ¬°§Aªº¼Æ¾Ú®w¤å¥ó¦WºÙ°_Ó½ÆÂøªº«D±`³Wªº¦W¦r¡A¨Ã§â¥L©ñ¦b´X¼h¥Ø¿ý¤U¡C©Ò¿×¡u«D±`³W¡v¡A¥´Ó¤ñ¤è¡G¤ñ¦p¦³Ó¼Æ¾Ú®wn«O¦sªº¬O¦³Ãö®ÑÄyªº«H®§¡A¥i¤£n§â¥¦©R¦W¬°¡vbook.mdb¡uªº¦W¦r¡A°_өǩǪº¦WºÙ¡A¤ñ¦pd34ksfslf.mdb¡A¦A§â¥L©ñ¦b¦p./kdslf/i44/studi/ ªº´X¼h¥Ø¿ý¤U¡A³o¼Ë¶Â«Èn·Q³q¹L²qªº¤è¦¡±o¨ì§AªºAccess¼Æ¾Ú®w¤å¥ó´NÃø¤W¥[Ãø¤F¡F
(2)¤£n§â¼Æ¾Ú®w¦W¼g¦bµ{§Ç¤¤¡C¦³¨Ç¤H³ßÅw§âDSN¼g¦bµ{§Ç¤¤¡A¤ñ¦p¡G
DBPath = Server.MapPath(¡ucmddb.mdb¡v)
conn.Open ¡udriver={Microsoft Access Driver (*.mdb)};dbq=¡v & DBPath
°²¦p¸U¤@µ¹¤H®³¨ì¤F·½µ{§Ç¡A§AªºAccess¼Æ¾Ú®wªº¦W¦r´N¤@ÄýµL¾l¡C¦]¦¹«ØÄ³§A¦bODBC¸Ì³]¸m¼Æ¾Ú·½¡A¦A¦bµ{§Ç¤¤³o¼Ë¼g¡G
conn.open ¡ushujiyuan¡v
(3)¨Ï¥ÎAccess¨Ó¬°¼Æ¾Ú®w¤å¥ó½s½X¤Î¥[±K¡Cº¥ý¦b¿ï¨ú¡u¤u¨ã¡v¡÷¡u¦w¥þ¡v¡÷¡u¥[±K/¸Ñ±K¼Æ¾Ú®w¡v¡A¿ï¨ú¼Æ¾Ú®w(¦p¡Gemployer.mdb)¡AµM«á±µ½T©w¡A±µµÛ·|¥X²{¡u¼Æ¾Ú®w¥[±K«á¥t¦s¬°¡vªºµ¡¤f¡A¦s¬°¡Gemployer1.mdb¡C±µµÛ¡uemployer.mdb¡v´N·|³Q½s½X¡AµM«á¦s¬°¡Gemployer1.mdb¡C
ª`·N ¡G¥H¤Wªº°Ê§@¨Ã¤£¬O¹ï¼Æ¾Ú®w³]¸m±K½X¡A¦Ó¥u¬O¹ï¼Æ¾Ú®w¤å¥ó¥[¥H½s½X¡A¥Øªº¬O¬°¤F¨¾¤î¥L¤H¨Ï¥Î§Oªº¤u¨ã¨Ó¬d¬Ý¼Æ¾Ú®w¤å¥óªº¤º®e¡C
±µ¤U¨Ó§Ú̬°¼Æ¾Ú®w¥[±K¡Aº¥ý¥H¥´¶}¸g¹L½s½X¤Fªº¡uemployer1.mdb¡v¡A¦b¥´¶}®É¡A¿ï¾Ü¡u¿W¦û¡v¤è¦¡¡CµM«á¿ï¨ú¥\¯àªíªº¡u¤u¨ã¡v¡÷¡u¦w¥þ¡v¡÷¡u³]¸m¼Æ¾Ú®w±K½X¡v¡A±µµÛ¿é¤J±K½X§Y¥i¡C
¬°¡uemployer1.mdb¡v³]¸m±K½X¤§«á¡A±µ¤U¨Ó¦pªG¦A¨Ï¥ÎAccess¼Æ¾Ú®w¤å¥ó®É¡A«hAccess·|¥ýn¨D¿é¤J±K½X¡AÅçÃÒ¥¿½T«á¤~¯à°÷±Ò°Ê¼Æ¾Ú®w¡C
¤£¹Ln¦bASPµ{§Ç¤¤ªºConnection¹ï¶Hªºopen¤èªk¤¤¼W¥[PWDªº°Ñ¼Æ§Y¥i¡A¨Ò¦p¡G
param=¡udriver={Microsoft Access Driver (*.mdb)};Pwd=yfdsfs¡v
param=param&¡u;dbq=¡v&server.mappath(¡uemployer1.mdb¡v)
conn.open param
³o¼Ë§Y¨Ï¥L¤H±o¨ì¤FFmployer1.mdb¤å¥ó¡A¨S¦³±K½X¥L¬OµLªk¬Ý¨ìemployer1.mdbªº¡C
5.aspµ{§Ç±K½XÅçÃÒº|¬}
º|¬}´yz ¡G
«Ü¦hºô¯¸§â±K½X©ñ¨ì¼Æ¾Ú®w¤¤¡A¦bµn³°ÅçÃÒ¤¤¥Î¥H¤USql¡A(¥HASP¬°¨Ò)
sql=¡uselect * from user where username=¡v&username&¡uand pass=¡v& pass &¡v
¦¹®É¡A±z¥un®Ú¾ÚSQLºc³y¤@Ó¯S®íªº¥Î¤á¦W©M±K½X¡A¦p¡Gben or 1=1
´N¥i¥H¶i¤J¥»¨Ó§A¨S¦³¯SÅvªº¶±¡C¦A¨Ó¬Ý¬Ý¤W±¨ºÓ»y¥y§a¡G
sql=¡uselect * from user where username=¡v&username&¡uand pass=¡u& pass&¡v
or ¬O¤@ÓÅÞ¿è¹Bºâ²Å¡A§@¥Î¬O¦b§PÂ_¨âÓ±ø¥óªº®ÉÔ¡A¥un¨ä¤¤¤@Ó±ø¥ó¦¨¥ß¡A¨º»òµ¥¦¡±N·|¦¨¥ß¡C¦Ó¦b»y¨¥¤¤¡A¬O¥H1¨Ó¥Nªí¯uªº(¦¨¥ß)¡C¨º»ò¦b³o¦æ»y¥y¤¤¡Aì»y¥yªº¡uand¡vÅçÃÒ±N¤£¦AÄ~Äò¡A¦Ó¦]¬°¡u1=1¡v©M¡uor¡v¥O»y¥yªð¦^¬°¯uÈ¡C
¥t¥~§Ṳ́]¥i¥Hºc³y¥H¤Uªº¥Î¤á¦W¡G
username=aa or username<>aa
pass=aa or pass<>aa
¬ÛÀ³ªº¦bÂsÄý¾¹ºÝªº¥Î¤á¦W®Ø¤º¼g¤J¡Gaa or username<>aa ¤f¥O®Ø¤º¼g¤J¡Gaa or pass<>aa¡Aª`·N³o¨âÓ¦r²Å¦ê¨âÀY¬O¨S¦³ªº¡C³o¼Ë´N¥i¥H¦¨¥\ªºÄF¹L¨t²Î¦Ó¶i¤J¡C
«á¤@ºØ¤èªk²z½×ÁöµM¦p¦¹¡A¦ýn¹ê½î¬O«D±`§xÃøªº¡A¤U±¨âÓ±ø¥ó³£¥²¶·¨ã³Æ¡C
(1)§Aº¥ýn¯à°÷·Ç½Tªºª¾¹D¨t²Î¦bªí¤¤¬O¥Îþ¨âÓ¦r¬q¦sÀx¥Î¤á¦W©M¤f¥Oªº¡A¥u¦³³o¼Ë§A¤~¯à·Ç½Tªººc³y¥X³oÓ¶i§ð©Êªº¦r²Å¦ê¡C¹ê»Ú¤W³o¬O«ÜÃø²q¤¤ªº¡C
(2)¨t²Î¹ï§A¿é¤Jªº¦r²Å¦ê¤£¶i¦æ¦³®Ä©ÊÀˬd¡C
°ÝÃD¸Ñ¨M©M«ØÄ³¡G¹ï¿é¤Jªº¤º®eÅçÃÒ©M¡u¡v¸¹ªº³B²z¡C
6.IIS4©ÎªÌIIS5¤¤¦w¸Ë¦³Index ServerªA°È·|º|¬}ASP·½µ{§Ç
°ÝÃD´yz ¡G
¦b¹B¦æIIS4©ÎªÌIIS5ªºIndex Server¡A¿é¤J¯S®íªº¦r²Å®æ¦¡¥i¥H¬Ý¨ìASP·½µ{§Ç©ÎªÌ¨ä¥¦¶±ªºµ{§Ç¡C¬Æ¦Ü¥H¤Î²K¥´¤F³ÌªñÃö©ó°Ñ¬Ý·½¥N½Xªº¸É¤Bµ{§Çªº¨t²Î¡A©ÎªÌ¨S¦³.htw¤å¥óªº¨t²Î¡A¤@¼Ë¦s¦b¸Ó°ÝÃD¡CÀò±oASPµ{§Ç¡A¬Æ¦Üglobal.asp¤å¥óªº·½¥N½X¡AµLºÃ¹ï¨t²Î¬O¤@Ó«D±`«¤jªº¦w¥þÁô±w¡C©¹©¹³o¨Ç¥N½X¤¤¥]§t¤F¥Î¤á±K½X©MID¡A¥H¤Î¼Æ¾Ú®wªº·½¸ô®|©M¦WºÙµ¥µ¥¡C³o¹ï©ó§ðÀ»ªÌ¦¬¶°¨t²Î«H®§¡A¶i¦æ¤U¤@¨Bªº¤J«I³£¬O«D±`«¡C
³q¹Lºc«Ø¤U±ªº¯S®íµ{§Ç¥i¥H°Ñ¬Ý¸Óµ{§Ç·½¥N½X ¡G
http://202.116.26.38/null.htw’ÂCiWebHitsFile=/default.asp&CiRestriction=none&CiHiliteType=Full
³o¼Ë¥u¬Oªð¦^¤@¨ÇHTML®æ¦¡ªº¤å¥ó¥N½X¡A¦ý¬O·í§A²K¥[%20¨ìCiWebHitsFileªº°Ñ¼Æ«á±¡A¦p¤U:
http://someurl/null.htw?CiWebHitsFile=/default.asp%20&CiRestriction=none&CiHiliteType=Full
³o±NÀò±o¸Óµ{§Çªº·½¥N½X¡C(ª`·N¡G/default.asp¬O¥HWebªº®Ú¶}©lpºâ¡C¦p¬Y¯¸ÂIªºhttp://XXXXXX/welcome.asp)
¨º»ò¹ïÀ³´N¬O¡G
http://someurl/null.htw CiWebHitsFile=/XXXXXX/welcome.asp%20& CiRestriction=none&CiHiliteType=Full)
¥Ñ©óNull.htw¤å¥ó¨Ã«D¯u¥¿ªº¨t²Î¬M®g¤å¥ó¡A©Ò¥H¥u¬O¤@ÓÀx¦s¦b¨t²Î¤º¦s¤¤ªºµêÀÀ¤å¥ó¡Cþ©È§A¤w¸g±q§Aªº¨t²Î¤¤§R°£¤F©Ò¦³ªº¯u¹êªº.htw¤å¥ó¡A¦ý¬O¥Ñ©ó¹ïNull.htw¤å¥óªº½Ð¨DÀq»{¬O¥ÑWebhits.dll¨Ó³B²z¡C©Ò¥H¡AIIS¤´µM¦¬¨ì¸Óº|¬}ªº«Â¯Ù¡C
°ÝÃD¸Ñ¨M©ÎªÌ«ØÄ³ ¡G
¦pªG¸ÓWebhits´£¨Ñªº¥\¯à¬O¨t²Î¥²¶·ªº¡A½Ð¤U¸ü¬ÛÀ³ªº¸É¤Bµ{§Ç¡C¦pªG¨S¥²n¡A½Ð¥ÎIISªºMMCºÞ²z¤u¨ã²³æ²¾°£¡u.htw¡vªº¬M¹³¤å¥ó¡C
7.NT Index Server¦s¦bªð¦^¤W¯Å¥Ø¿ýªºº|¬}
°ÝÃD´yz ¡G
Index Sserver2.0¬OWinNT4.0 Option Pack¤¤ªþ±aªº¤@Ó³n¥óªº¤u¨ã¡A¨ä¤¤ªº¥\¯à¤w¸g³QWinNT/2000¤¤ªºIndexing Services©Ò¥]§t¡C·í»PIISµ²¦X¨Ï¥Î®É¡AIndex Server©MIndexing Services«K¥i¥H¦b³ÌªìªºÀô¹Ò¨ÓÂsÄýWeb Searchªºµ²ªG¡A¥¦±N¥Í¦¨¤@ÓHTML¤å¥ó¡A¨ä¤¤¥]§t¤F¬d§ä«á©Òªð¦^¶±¤º®eªºÂ²µu¤Þ¥Î¡A¨Ã±N¨ä³s±µ¦Ü©Òªð¦^ªº¶±[§Y²Å¦X¬d¸ß¤º®eªº¶±]¡A¤]´N¬O¶W¯Å³s±µ¡Cn°µ¨ì³o¤@ÂI¡A¥¦«K»Ýn¤ä«ù¥ÑWebhits.dll-ISAPIµ{§Ç³B²zªº.htw¤å¥óÃþ«¬¡C³oÓDll¤¹³\¦b¤@Ó¼Òª©¤¤¨Ï¥Î¡u../¡v¥Î°µªð¦^¤W¯Å¥Ø¿ýªº¦r²Å¦ê¡C³o¼Ë¡AÁA¸ÑªA°È¾¹¤å¥óµ²ºcªº§ðÀ»ªÌ«K¥i¥H»·µ{ªº¾\Ū¸Ó¾÷¾¹¤Wªº¥ô·N¤å¥ó¤F¡C
º|¬}ªº§Q¥Î ¡G
(1)±zªº¨t²Î¤¤¦s¦b.htw¤å¥ó
Index Server´£¨Ñªº³oºØ¶W¯Å³s±µ¤¹³\Web¥Î¤áÀò±o¤@ÓÃö©ó¥L·j´Mµ²ªGªºªð¦^¶¡A³oÓ¶±ªº¦W¦r¬O»PCiWebHits FileÅܶq¤@°_³q¹L.htw¤å¥óªº¡AWebhits.dll³oÓISAPIµ{§Ç±N³B²z³oӽШD¡A¹ï¨ä¶i¦æ¶W¯Å³s±µ¨Ãªð¦^¸Ó¶±¡C¦]¦¹¥Î¤á«K¥i¥H±±¨î³q¹L.htw¤å¥óªºCiWebHitsÅܶq¡A½Ð¨D¨ì¥ô¦ó©Ò§Æ±æÀò±oªº«H®§¡C¥t¥~¦s¦bªº¤@Ó°ÝÃD«K¬OASP©Î¨ä¥L¸}¥»¤å¥óªº·½¥N½X¤]¥i¥H§Q¥Î¸Ó¤èªk¨ÓÀò±o¡C
¤W±§ÚÌ»¡¹LWebhits.dll«á±µ¤W¡u../¡v«K¥i¥H³X°Ý¨ìWebµêÀÀ¥Ø¿ý¥~ªº¤å¥ó¡A¤U±§Ų́ӬÝÓ¨Ò¤l:
http://somerul/iissamples/issamples/oop/qfullhit.dll?CiWebHits File=/../../ winnt/system32/logfiles/w3svc1/ex000121.log&CiRestriction=none&CiHiliteType=Full
¦bÂsÄý¾¹¤¤¿é¤J¸Ó¦a§}¡A«K¥i¥HÀò±o¸ÓªA°È¾¹¤Wµ¹©w¤é´ÁªºWeb¤é»x¤å¥ó.
¦b¨t²Î±`¨£ªº.htw¼Ë¥»¤å¥ó¦³:
/iissamples/issamples/oop/qfullhit.htw
/iissamples/issamples/oop/qsumrhit.htw
/iissamples/exair/search/qfullhit.htw
/iissamples/exair/search/qsumrhit.hw
/iishelp/iis/misc/iirturnh.htw [³oÓ¤å¥ó³q±`¨üloopback¨î]
(2)±zªº¨t²Î¤¤¤£¦s¦b.htw¤å¥ó
½Õ¥Î¤@ÓWebhits.dll ISAPIµ{§Ç»Ýn³q¹L.htw¤å¥ó¨Ó§¹¦¨¡A¦pªG±zªº¨t²Î¤¤¤£¦s¦b.htw¤å¥ó¡AÁöµM½Ð¨D¤@Ó¤£¦s¦bªº.htw¤å¥ó±N¥¢±Ñ¡A¦ý¬O±zªº¤´µM¦s¦b¥i³Q§Q¥Îªºº|¬}¡C¨ä¤¤ªºÂ¬ªù«K¬O§Q¥ÎInetinfo.exe¨Ó½Õ¥ÎWebhits.dll¡A³o¼Ë¦P¼Ë¯à³X°Ý¨ìWebµêÀÀ¥Ø¿ý¥~ªº¤å¥ó¡C¦ý§ÚÌ»Ýn³q¹L»s§@¤@Óªº¯S®íªºURL¨Ó§¹¦¨³oÓ¤å¥ó¥²¶·¬O¤@ÓÀRºAªº¤å¥ó¡A¦p¡u.htm¡v¡A¡u.html¡v¡A¡u.txt¡v©ÎªÌ¡u.gif¡v¡A¡u.jpg¡v¡C³o¨Ç¤å¥ó±N¥Î§@¼Òª©¨Ó³QWebhits.dll¥´¶}¡C²{¦b§ÚÌ»ÝnÀò±oInetinfo.exe¨Ó§Q¥ÎWebhits.dll¡A°ß¤@¥i¥H°µ¨ì³oÂIªº«K¬O½Ð¨D¤@Ó.htw¤å¥ó:
http://url/default.htm.htw CiWebHitsFile=/../../winnt/system32/logfiles/w3svc1/ex000121.log &CiRestriction=none&CiHiliteType=Full
«Ü©úÅã¡A³oӽШDªÖ©w·|¥¢±Ñ¡A¦]¬°¨t²Î¤W¤£¦s¦b³oÓ¤å¥ó¡C¦ý½Ðª`·N¡A§Ú̲{¦b¤w¸g½Õ¥Î¨ì¤FWebhits.dll¡A§ÚÌ¥un¦b¤@Ó¦s¦bªº¤å¥ó¸ê·½«á±[¤]´N¬O¦b.htw«e±]¥[¤W¤@¦ê¯S®íªº¼Æ¦r(%20s )¡A[´N¬O¦b¨Ò¤l¤¤¡udefault.htm¡v«á±¥[¤W³oÓ¥NªíªÅ®æªº¯S®í¼Æ¦r]¡A³o¼Ë§ÚÌ«K¥i¥H´ÛÄF¹LWebªA°È¾¹±q¦Ó¹F¨ì§Ú̪º¥Øªº.¥Ñ©ó¦b½w½Ä³¡¤À¤¤.htw¤å¥ó¦W¦r³¡¤À³Q§R°£±¼[¥Ñ©ó%20s³oӲŸ¹]¡A©Ò¥H¡A·í½Ð¨D¶Ç°e¨ìWebhits.dllªº®ÉÔ¡A«K¥i¥H¦¨¥\ªº¥´¶}¸Ó¤å¥ó¡A¨Ãªð¦^µ¹«È¤áºÝ¡A¦Ó¥B¹Lµ{¤¤¨Ã¤£n¨D¨t²Î¤¤¯uªº¦s¦b.htw¤å¥ó¡C
°ÝÃD¸Ñ¨M©M«ØÄ³ ¡G
·L³n¤w¸g¹ï¸Ó°ÝÃDµo©ñ¤F¸É¤B:
Index Server 2.0:
Intel: http://www.microsoft.com/downloads/release.asp ReleaseID=17727
Alpha: http://www.microsoft.com/downloads/release.asp?ReleaseID=17728
Windows 2000 Indexing Services:Intel: http://www.microsoft.com/downloads/release.asp?ReleaseID=17726
8.¶¹LÅçÃÒª½±µ¶i¤JASP¶±
|
|
|