·í«e¦ì¸m¡G¶}µoªÌºôµ¸ >> §Þ³N±Ðµ{ >> PHP±Ðµ{ >> PHP§Þ¥© >> ¤º®e
ºë±m±ÀÂË
¤ÀÃþ³Ì·s±Ðµ{
¤ÀÃþ¼öÂI±Ðµ{
    
°ô¶ëWebº|¬}¡]¤U¡^
§@ªÌ¡G¥¼ª¾
¤é´Á¡G2004-10-09
¤H®ð¡G
§ë½Z¡Gsnow(Âà¶K)
¨Ó·½¡G¥¼ª¾
¦rÅé¡G¤j ¤¤ ¤p
¦¬ÂáG¥[¤JÂsÄý¾¹¦¬ÂÃ
¥H¤U¥¿¤å¡G
¸Ñ¨M¤èªk¡G
(1) ¬°§Aªº¼Æ¾Ú®w¤å¥ó¦WºÙ°_­Ó½ÆÂøªº«D±`³Wªº¦W¦r¡A¨Ã§â¥L©ñ¦b´X¼h¥Ø¿ý¤U¡C©Ò¿×¡u«D±`³W¡v¡A¥´­Ó¤ñ¤è¡G¤ñ¦p¦³­Ó¼Æ¾Ú®w­n«O¦sªº¬O¦³Ãö®ÑÄyªº«H®§¡A¥i¤£­n§â¥¦©R¦W¬°¡vbook.mdb¡uªº¦W¦r¡A°_­Ó©Ç©Çªº¦WºÙ¡A¤ñ¦pd34ksfslf.mdb¡A¦A§â¥L©ñ¦b¦p./kdslf/i44/studi/ ªº´X¼h¥Ø¿ý¤U¡A³o¼Ë¶Â«È­n·Q³q¹L²qªº¤è¦¡±o¨ì§AªºAccess¼Æ¾Ú®w¤å¥ó´NÃø¤W¥[Ãø¤F¡F

(2)¤£­n§â¼Æ¾Ú®w¦W¼g¦bµ{§Ç¤¤¡C¦³¨Ç¤H³ßÅw§âDSN¼g¦bµ{§Ç¤¤¡A¤ñ¦p¡G

DBPath = Server.MapPath(¡ucmddb.mdb¡v)

conn.Open ¡udriver={Microsoft Access Driver (*.mdb)};dbq=¡v & DBPath

°²¦p¸U¤@µ¹¤H®³¨ì¤F·½µ{§Ç¡A§AªºAccess¼Æ¾Ú®wªº¦W¦r´N¤@ÄýµL¾l¡C¦]¦¹«ØÄ³§A¦bODBC¸Ì³]¸m¼Æ¾Ú·½¡A¦A¦bµ{§Ç¤¤³o¼Ë¼g¡G

conn.open ¡ushujiyuan¡v

(3)¨Ï¥ÎAccess¨Ó¬°¼Æ¾Ú®w¤å¥ó½s½X¤Î¥[±K¡C­º¥ý¦b¿ï¨ú¡u¤u¨ã¡v¡÷¡u¦w¥þ¡v¡÷¡u¥[±K/¸Ñ±K¼Æ¾Ú®w¡v¡A¿ï¨ú¼Æ¾Ú®w(¦p¡Gemployer.mdb)¡AµM«á±µ½T©w¡A±µµÛ·|¥X²{¡u¼Æ¾Ú®w¥[±K«á¥t¦s¬°¡vªºµ¡¤f¡A¦s¬°¡Gemployer1.mdb¡C±µµÛ¡uemployer.mdb¡v´N·|³Q½s½X¡AµM«á¦s¬°¡Gemployer1.mdb¡C

ª`·N ¡G¥H¤Wªº°Ê§@¨Ã¤£¬O¹ï¼Æ¾Ú®w³]¸m±K½X¡A¦Ó¥u¬O¹ï¼Æ¾Ú®w¤å¥ó¥[¥H½s½X¡A¥Øªº¬O¬°¤F¨¾¤î¥L¤H¨Ï¥Î§Oªº¤u¨ã¨Ó¬d¬Ý¼Æ¾Ú®w¤å¥óªº¤º®e¡C

±µ¤U¨Ó§Ú­Ì¬°¼Æ¾Ú®w¥[±K¡A­º¥ý¥H¥´¶}¸g¹L½s½X¤Fªº¡uemployer1.mdb¡v¡A¦b¥´¶}®É¡A¿ï¾Ü¡u¿W¦û¡v¤è¦¡¡CµM«á¿ï¨ú¥\¯àªíªº¡u¤u¨ã¡v¡÷¡u¦w¥þ¡v¡÷¡u³]¸m¼Æ¾Ú®w±K½X¡v¡A±µµÛ¿é¤J±K½X§Y¥i¡C

¬°¡uemployer1.mdb¡v³]¸m±K½X¤§«á¡A±µ¤U¨Ó¦pªG¦A¨Ï¥ÎAccess¼Æ¾Ú®w¤å¥ó®É¡A«hAccess·|¥ý­n¨D¿é¤J±K½X¡AÅçÃÒ¥¿½T«á¤~¯à°÷±Ò°Ê¼Æ¾Ú®w¡C

¤£¹L­n¦bASPµ{§Ç¤¤ªºConnection¹ï¶Hªºopen¤èªk¤¤¼W¥[PWDªº°Ñ¼Æ§Y¥i¡A¨Ò¦p¡G

param=¡udriver={Microsoft Access Driver (*.mdb)};Pwd=yfdsfs¡v

param=param&¡u;dbq=¡v&server.mappath(¡uemployer1.mdb¡v)

conn.open param

³o¼Ë§Y¨Ï¥L¤H±o¨ì¤FFmployer1.mdb¤å¥ó¡A¨S¦³±K½X¥L¬OµLªk¬Ý¨ìemployer1.mdbªº¡C

5.aspµ{§Ç±K½XÅçÃÒº|¬}

º|¬}´y­z ¡G

«Ü¦hºô¯¸§â±K½X©ñ¨ì¼Æ¾Ú®w¤¤¡A¦bµn³°ÅçÃÒ¤¤¥Î¥H¤USql¡A(¥HASP¬°¨Ò)

sql=¡uselect * from user where username=¡v&username&¡uand pass=¡v& pass &¡v

¦¹®É¡A±z¥u­n®Ú¾ÚSQLºc³y¤@­Ó¯S®íªº¥Î¤á¦W©M±K½X¡A¦p¡Gben or 1=1

´N¥i¥H¶i¤J¥»¨Ó§A¨S¦³¯SÅvªº­¶­±¡C¦A¨Ó¬Ý¬Ý¤W­±¨º­Ó»y¥y§a¡G

sql=¡uselect * from user where username=¡v&username&¡uand pass=¡u& pass&¡v

or ¬O¤@­ÓÅÞ¿è¹Bºâ²Å¡A§@¥Î¬O¦b§PÂ_¨â­Ó±ø¥óªº®É­Ô¡A¥u­n¨ä¤¤¤@­Ó±ø¥ó¦¨¥ß¡A¨º»òµ¥¦¡±N·|¦¨¥ß¡C¦Ó¦b»y¨¥¤¤¡A¬O¥H1¨Ó¥Nªí¯uªº(¦¨¥ß)¡C¨º»ò¦b³o¦æ»y¥y¤¤¡A­ì»y¥yªº¡uand¡vÅçÃÒ±N¤£¦AÄ~Äò¡A¦Ó¦]¬°¡u1=1¡v©M¡uor¡v¥O»y¥yªð¦^¬°¯u­È¡C

¥t¥~§Ú­Ì¤]¥i¥Hºc³y¥H¤Uªº¥Î¤á¦W¡G

username=aa or username<>aa

pass=aa or pass<>aa

¬ÛÀ³ªº¦bÂsÄý¾¹ºÝªº¥Î¤á¦W®Ø¤º¼g¤J¡Gaa or username<>aa ¤f¥O®Ø¤º¼g¤J¡Gaa or pass<>aa¡Aª`·N³o¨â­Ó¦r²Å¦ê¨âÀY¬O¨S¦³ªº¡C³o¼Ë´N¥i¥H¦¨¥\ªºÄF¹L¨t²Î¦Ó¶i¤J¡C

«á¤@ºØ¤èªk²z½×ÁöµM¦p¦¹¡A¦ý­n¹ê½î¬O«D±`§xÃøªº¡A¤U­±¨â­Ó±ø¥ó³£¥²¶·¨ã³Æ¡C

(1)§A­º¥ý­n¯à°÷·Ç½Tªºª¾¹D¨t²Î¦bªí¤¤¬O¥Î­þ¨â­Ó¦r¬q¦sÀx¥Î¤á¦W©M¤f¥Oªº¡A¥u¦³³o¼Ë§A¤~¯à·Ç½Tªººc³y¥X³o­Ó¶i§ð©Êªº¦r²Å¦ê¡C¹ê»Ú¤W³o¬O«ÜÃø²q¤¤ªº¡C

(2)¨t²Î¹ï§A¿é¤Jªº¦r²Å¦ê¤£¶i¦æ¦³®Ä©ÊÀˬd¡C

°ÝÃD¸Ñ¨M©M«ØÄ³¡G¹ï¿é¤Jªº¤º®eÅçÃÒ©M¡u¡v¸¹ªº³B²z¡C

6.IIS4©ÎªÌIIS5¤¤¦w¸Ë¦³Index ServerªA°È·|º|¬}ASP·½µ{§Ç

°ÝÃD´y­z ¡G

¦b¹B¦æIIS4©ÎªÌIIS5ªºIndex Server¡A¿é¤J¯S®íªº¦r²Å®æ¦¡¥i¥H¬Ý¨ìASP·½µ{§Ç©ÎªÌ¨ä¥¦­¶­±ªºµ{§Ç¡C¬Æ¦Ü¥H¤Î²K¥´¤F³ÌªñÃö©ó°Ñ¬Ý·½¥N½Xªº¸É¤Bµ{§Çªº¨t²Î¡A©ÎªÌ¨S¦³.htw¤å¥óªº¨t²Î¡A¤@¼Ë¦s¦b¸Ó°ÝÃD¡CÀò±oASPµ{§Ç¡A¬Æ¦Üglobal.asp¤å¥óªº·½¥N½X¡AµLºÃ¹ï¨t²Î¬O¤@­Ó«D±`­«¤jªº¦w¥þÁô±w¡C©¹©¹³o¨Ç¥N½X¤¤¥]§t¤F¥Î¤á±K½X©MID¡A¥H¤Î¼Æ¾Ú®wªº·½¸ô®|©M¦WºÙµ¥µ¥¡C³o¹ï©ó§ðÀ»ªÌ¦¬¶°¨t²Î«H®§¡A¶i¦æ¤U¤@¨Bªº¤J«I³£¬O«D±`­«¡C

³q¹Lºc«Ø¤U­±ªº¯S®íµ{§Ç¥i¥H°Ñ¬Ý¸Óµ{§Ç·½¥N½X ¡G

http://202.116.26.38/null.htw’ÂCiWebHitsFile=/default.asp&CiRestriction=none&CiHiliteType=Full

³o¼Ë¥u¬Oªð¦^¤@¨ÇHTML®æ¦¡ªº¤å¥ó¥N½X¡A¦ý¬O·í§A²K¥[%20¨ìCiWebHitsFileªº°Ñ¼Æ«á­±¡A¦p¤U:

http://someurl/null.htw?CiWebHitsFile=/default.asp%20&CiRestriction=none&CiHiliteType=Full

³o±NÀò±o¸Óµ{§Çªº·½¥N½X¡C(ª`·N¡G/default.asp¬O¥HWebªº®Ú¶}©l­pºâ¡C¦p¬Y¯¸ÂIªºhttp://XXXXXX/welcome.asp)

¨º»ò¹ïÀ³´N¬O¡G

http://someurl/null.htw CiWebHitsFile=/XXXXXX/welcome.asp%20& CiRestriction=none&CiHiliteType=Full)

¥Ñ©óNull.htw¤å¥ó¨Ã«D¯u¥¿ªº¨t²Î¬M®g¤å¥ó¡A©Ò¥H¥u¬O¤@­ÓÀx¦s¦b¨t²Î¤º¦s¤¤ªºµêÀÀ¤å¥ó¡C­þ©È§A¤w¸g±q§Aªº¨t²Î¤¤§R°£¤F©Ò¦³ªº¯u¹êªº.htw¤å¥ó¡A¦ý¬O¥Ñ©ó¹ïNull.htw¤å¥óªº½Ð¨DÀq»{¬O¥ÑWebhits.dll¨Ó³B²z¡C©Ò¥H¡AIIS¤´µM¦¬¨ì¸Óº|¬}ªº«Â¯Ù¡C

°ÝÃD¸Ñ¨M©ÎªÌ«ØÄ³ ¡G

¦pªG¸ÓWebhits´£¨Ñªº¥\¯à¬O¨t²Î¥²¶·ªº¡A½Ð¤U¸ü¬ÛÀ³ªº¸É¤Bµ{§Ç¡C¦pªG¨S¥²­n¡A½Ð¥ÎIISªºMMCºÞ²z¤u¨ã²³æ²¾°£¡u.htw¡vªº¬M¹³¤å¥ó¡C

7.NT Index Server¦s¦bªð¦^¤W¯Å¥Ø¿ýªºº|¬}

°ÝÃD´y­z ¡G

Index Sserver2.0¬OWinNT4.0 Option Pack¤¤ªþ±aªº¤@­Ó³n¥óªº¤u¨ã¡A¨ä¤¤ªº¥\¯à¤w¸g³QWinNT/2000¤¤ªºIndexing Services©Ò¥]§t¡C·í»PIISµ²¦X¨Ï¥Î®É¡AIndex Server©MIndexing Services«K¥i¥H¦b³ÌªìªºÀô¹Ò¨ÓÂsÄýWeb Searchªºµ²ªG¡A¥¦±N¥Í¦¨¤@­ÓHTML¤å¥ó¡A¨ä¤¤¥]§t¤F¬d§ä«á©Òªð¦^­¶­±¤º®eªºÂ²µu¤Þ¥Î¡A¨Ã±N¨ä³s±µ¦Ü©Òªð¦^ªº­¶­±[§Y²Å¦X¬d¸ß¤º®eªº­¶­±]¡A¤]´N¬O¶W¯Å³s±µ¡C­n°µ¨ì³o¤@ÂI¡A¥¦«K»Ý­n¤ä«ù¥ÑWebhits.dll-ISAPIµ{§Ç³B²zªº.htw¤å¥óÃþ«¬¡C³o­ÓDll¤¹³\¦b¤@­Ó¼Òª©¤¤¨Ï¥Î¡u../¡v¥Î°µªð¦^¤W¯Å¥Ø¿ýªº¦r²Å¦ê¡C³o¼Ë¡AÁA¸ÑªA°È¾¹¤å¥óµ²ºcªº§ðÀ»ªÌ«K¥i¥H»·µ{ªº¾\Ū¸Ó¾÷¾¹¤Wªº¥ô·N¤å¥ó¤F¡C

º|¬}ªº§Q¥Î ¡G

(1)±zªº¨t²Î¤¤¦s¦b.htw¤å¥ó

Index Server´£¨Ñªº³oºØ¶W¯Å³s±µ¤¹³\Web¥Î¤áÀò±o¤@­ÓÃö©ó¥L·j´Mµ²ªGªºªð¦^­¶¡A³o­Ó­¶­±ªº¦W¦r¬O»PCiWebHits FileÅܶq¤@°_³q¹L.htw¤å¥óªº¡AWebhits.dll³o­ÓISAPIµ{§Ç±N³B²z³o­Ó½Ð¨D¡A¹ï¨ä¶i¦æ¶W¯Å³s±µ¨Ãªð¦^¸Ó­¶­±¡C¦]¦¹¥Î¤á«K¥i¥H±±¨î³q¹L.htw¤å¥óªºCiWebHitsÅܶq¡A½Ð¨D¨ì¥ô¦ó©Ò§Æ±æÀò±oªº«H®§¡C¥t¥~¦s¦bªº¤@­Ó°ÝÃD«K¬OASP©Î¨ä¥L¸}¥»¤å¥óªº·½¥N½X¤]¥i¥H§Q¥Î¸Ó¤èªk¨ÓÀò±o¡C

¤W­±§Ú­Ì»¡¹LWebhits.dll«á±µ¤W¡u../¡v«K¥i¥H³X°Ý¨ìWebµêÀÀ¥Ø¿ý¥~ªº¤å¥ó¡A¤U­±§Ú­Ì¨Ó¬Ý­Ó¨Ò¤l:

http://somerul/iissamples/issamples/oop/qfullhit.dll?CiWebHits File=/../../ winnt/system32/logfiles/w3svc1/ex000121.log&CiRestriction=none&CiHiliteType=Full

¦bÂsÄý¾¹¤¤¿é¤J¸Ó¦a§}¡A«K¥i¥HÀò±o¸ÓªA°È¾¹¤Wµ¹©w¤é´ÁªºWeb¤é»x¤å¥ó.

¦b¨t²Î±`¨£ªº.htw¼Ë¥»¤å¥ó¦³:

/iissamples/issamples/oop/qfullhit.htw

/iissamples/issamples/oop/qsumrhit.htw

/iissamples/exair/search/qfullhit.htw

/iissamples/exair/search/qsumrhit.hw

/iishelp/iis/misc/iirturnh.htw [³o­Ó¤å¥ó³q±`¨üloopback­­¨î]

(2)±zªº¨t²Î¤¤¤£¦s¦b.htw¤å¥ó

½Õ¥Î¤@­ÓWebhits.dll ISAPIµ{§Ç»Ý­n³q¹L.htw¤å¥ó¨Ó§¹¦¨¡A¦pªG±zªº¨t²Î¤¤¤£¦s¦b.htw¤å¥ó¡AÁöµM½Ð¨D¤@­Ó¤£¦s¦bªº.htw¤å¥ó±N¥¢±Ñ¡A¦ý¬O±zªº¤´µM¦s¦b¥i³Q§Q¥Îªºº|¬}¡C¨ä¤¤ªºÂ¬ªù«K¬O§Q¥ÎInetinfo.exe¨Ó½Õ¥ÎWebhits.dll¡A³o¼Ë¦P¼Ë¯à³X°Ý¨ìWebµêÀÀ¥Ø¿ý¥~ªº¤å¥ó¡C¦ý§Ú­Ì»Ý­n³q¹L»s§@¤@­Óªº¯S®íªºURL¨Ó§¹¦¨³o­Ó¤å¥ó¥²¶·¬O¤@­ÓÀRºAªº¤å¥ó¡A¦p¡u.htm¡v¡A¡u.html¡v¡A¡u.txt¡v©ÎªÌ¡u.gif¡v¡A¡u.jpg¡v¡C³o¨Ç¤å¥ó±N¥Î§@¼Òª©¨Ó³QWebhits.dll¥´¶}¡C²{¦b§Ú­Ì»Ý­nÀò±oInetinfo.exe¨Ó§Q¥ÎWebhits.dll¡A°ß¤@¥i¥H°µ¨ì³oÂIªº«K¬O½Ð¨D¤@­Ó.htw¤å¥ó:

http://url/default.htm.htw CiWebHitsFile=/../../winnt/system32/logfiles/w3svc1/ex000121.log &CiRestriction=none&CiHiliteType=Full

«Ü©úÅã¡A³o­Ó½Ð¨DªÖ©w·|¥¢±Ñ¡A¦]¬°¨t²Î¤W¤£¦s¦b³o­Ó¤å¥ó¡C¦ý½Ðª`·N¡A§Ú­Ì²{¦b¤w¸g½Õ¥Î¨ì¤FWebhits.dll¡A§Ú­Ì¥u­n¦b¤@­Ó¦s¦bªº¤å¥ó¸ê·½«á­±[¤]´N¬O¦b.htw«e­±]¥[¤W¤@¦ê¯S®íªº¼Æ¦r(%20s )¡A[´N¬O¦b¨Ò¤l¤¤¡udefault.htm¡v«á­±¥[¤W³o­Ó¥NªíªÅ®æªº¯S®í¼Æ¦r]¡A³o¼Ë§Ú­Ì«K¥i¥H´ÛÄF¹LWebªA°È¾¹±q¦Ó¹F¨ì§Ú­Ìªº¥Øªº.¥Ñ©ó¦b½w½Ä³¡¤À¤¤.htw¤å¥ó¦W¦r³¡¤À³Q§R°£±¼[¥Ñ©ó%20s³o­Ó²Å¸¹]¡A©Ò¥H¡A·í½Ð¨D¶Ç°e¨ìWebhits.dllªº®É­Ô¡A«K¥i¥H¦¨¥\ªº¥´¶}¸Ó¤å¥ó¡A¨Ãªð¦^µ¹«È¤áºÝ¡A¦Ó¥B¹Lµ{¤¤¨Ã¤£­n¨D¨t²Î¤¤¯uªº¦s¦b.htw¤å¥ó¡C

°ÝÃD¸Ñ¨M©M«ØÄ³ ¡G

·L³n¤w¸g¹ï¸Ó°ÝÃDµo©ñ¤F¸É¤B:

Index Server 2.0:

Intel: http://www.microsoft.com/downloads/release.asp ReleaseID=17727

Alpha: http://www.microsoft.com/downloads/release.asp?ReleaseID=17728

Windows 2000 Indexing Services:Intel: http://www.microsoft.com/downloads/release.asp?ReleaseID=17726

8.¶¹LÅçÃÒª½±µ¶i¤JASP­¶­±

¬ÛÃö¤å³¹¡G