- ©«¤l
- 549
- ¥DÃD
- 152
- ºëµØ
- 0
- ¿n¤À
- 691
- ÂI¦W
- 0
- §@·~¨t²Î
- WIN7
- ³nÅ骩¥»
- OFFICE 2010
- ¾\ŪÅv
- 50
- ©Ê§O
- ¨k
- µù¥U®É¶¡
- 2013-8-10
- ³Ì«áµn¿ý
- 2022-9-7
|
¦^´_ 3# joey0415
·PÁ¤j¤jªº¦^ÂÐ
¤£¹L¤p§Ì¬Ý¤£¤jÀ´....
§ä¤£¨ì·s¼W¸ê®Æ¥H¤Î³s½uªº¦a¤è
¬[³]§Ú¦³1¸Uµ§¸ê®Æn·s¼W,conn¬O³s½u«ü¥O,¨º§Ú¤U¤èªºµ{¦¡½X¸Ó¦pקï?
¥H¤Î¬Ý¨ìmsdn¤Wªº¤j¤jÌ»¡,°Ñ¼Æ¬d¸ßªk¬O¥Ø«e¤½»{¥i¥H§¹¬ü¨¾¿m SQL Injection ªº§@ªk¡C
¤£ºÞ¬O¦óºØ SQL¡A¥un§â¥N¤J¸ê®ÆȪº³¡¥÷¥Î°Ñ¼Æ¥h´À¥N´N¦æ¤F,±zªº¤è¦¡¤]¬O¥Î°Ñ¼Æ¬d¸ßªk¶Ü?
©êºp¤p§Ì¬OSQL·s¤â...
For i = 1 To 10000
strSQL = "INSERT INTO customer VALUES ('Bob'," & i & ")"
If i = 1 Then strSQL2 = strSQL Else strSQL2 = strSQL2 & ";" & strSQL
Next
conn.Execute (strSQL2) |
|