﻿<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/"><channel><title>博客园-Code Life-最新评论</title><link>http://www.cnblogs.com/applelure/CommentsRSS.aspx</link><description>  Joy Code...</description><language>zh-cn</language><pubDate>Thu, 15 Sep 2011 06:41:09 GMT</pubDate><lastBuildDate>Thu, 15 Sep 2011 06:41:09 GMT</lastBuildDate><generator>cnblogs</generator><item><title>Re:ASP.NET页面传值的方法</title><link>http://www.cnblogs.com/applelure/archive/2010/03/29/1182202.html#1788929</link><dc:creator>小恐龙</dc:creator><author>小恐龙</author><pubDate>Mon, 29 Mar 2010 01:55:06 GMT</pubDate><guid>http://www.cnblogs.com/applelure/archive/2010/03/29/1182202.html#1788929</guid><description><![CDATA[好！多谢！<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/applelure/" target="_blank">小恐龙</a> 2010-03-29 09:55 <a href="http://www.cnblogs.com/applelure/archive/2010/03/29/1182202.html#1788929#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>Re:PetShop 4.0架构与技术分析(1)</title><link>http://www.cnblogs.com/applelure/archive/2009/09/15/734268.html#1646889</link><dc:creator>海洋之 心</dc:creator><author>海洋之 心</author><pubDate>Tue, 15 Sep 2009 03:50:44 GMT</pubDate><guid>http://www.cnblogs.com/applelure/archive/2009/09/15/734268.html#1646889</guid><description><![CDATA[现在坐沙发，也不晚<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/applelure/" target="_blank">海洋之 心</a> 2009-09-15 11:50 <a href="http://www.cnblogs.com/applelure/archive/2009/09/15/734268.html#1646889#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>Re:写给那些ASP.NET程序员：网站中的安全问题</title><link>http://www.cnblogs.com/applelure/archive/2009/08/15/1386244.html#1615404</link><dc:creator>&amp;lt;td&amp;gt;我也想试一下，哈哈！&amp;lt;/td&amp;gt;</dc:creator><author>&amp;lt;td&amp;gt;我也想试一下，哈哈！&amp;lt;/td&amp;gt;</author><pubDate>Sat, 15 Aug 2009 03:13:11 GMT</pubDate><guid>http://www.cnblogs.com/applelure/archive/2009/08/15/1386244.html#1615404</guid><description><![CDATA[&lt;td&gt;真过瘾，哈哈！`````````````&lt;/td&gt;<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/applelure/" target="_blank">&lt;td&gt;我也想试一下，哈哈！&lt;/td&gt;</a> 2009-08-15 11:13 <a href="http://www.cnblogs.com/applelure/archive/2009/08/15/1386244.html#1615404#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: C#(局域网)获取外网IP</title><link>http://www.cnblogs.com/applelure/archive/2009/05/22/1142851.html#1535846</link><dc:creator>codelife</dc:creator><author>codelife</author><pubDate>Fri, 22 May 2009 15:23:38 GMT</pubDate><guid>http://www.cnblogs.com/applelure/archive/2009/05/22/1142851.html#1535846</guid><description><![CDATA[@子民<br/>域名系统 (Domain Name Server) <br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/applelure/" target="_blank">codelife</a> 2009-05-22 23:23 <a href="http://www.cnblogs.com/applelure/archive/2009/05/22/1142851.html#1535846#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: 写给那些ASP.NET程序员：网站中的安全问题</title><link>http://www.cnblogs.com/applelure/archive/2009/05/06/1386244.html#1520576</link><dc:creator>yay</dc:creator><author>yay</author><pubDate>Wed, 06 May 2009 02:37:33 GMT</pubDate><guid>http://www.cnblogs.com/applelure/archive/2009/05/06/1386244.html#1520576</guid><description><![CDATA[不会吧<br/>发个贴子被难为成这样<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/applelure/" target="_blank">yay</a> 2009-05-06 10:37 <a href="http://www.cnblogs.com/applelure/archive/2009/05/06/1386244.html#1520576#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: C#(局域网)获取外网IP</title><link>http://www.cnblogs.com/applelure/archive/2009/05/05/1142851.html#1519730</link><dc:creator>子民</dc:creator><author>子民</author><pubDate>Tue, 05 May 2009 05:58:44 GMT</pubDate><guid>http://www.cnblogs.com/applelure/archive/2009/05/05/1142851.html#1519730</guid><description><![CDATA[谢谢，在线等啊，急<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/applelure/" target="_blank">子民</a> 2009-05-05 13:58 <a href="http://www.cnblogs.com/applelure/archive/2009/05/05/1142851.html#1519730#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: C#(局域网)获取外网IP</title><link>http://www.cnblogs.com/applelure/archive/2009/05/05/1142851.html#1519728</link><dc:creator>子民</dc:creator><author>子民</author><pubDate>Tue, 05 May 2009 05:57:36 GMT</pubDate><guid>http://www.cnblogs.com/applelure/archive/2009/05/05/1142851.html#1519728</guid><description><![CDATA[Dns.Resolve(Dns.GetHostName()).AddressList.GetValue(0).ToString(); //内网IP<br/><br/>请问LZ：Dns是什么啊？<br/><br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/applelure/" target="_blank">子民</a> 2009-05-05 13:57 <a href="http://www.cnblogs.com/applelure/archive/2009/05/05/1142851.html#1519728#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: 写给那些ASP.NET程序员：网站中的安全问题</title><link>http://www.cnblogs.com/applelure/archive/2009/04/28/1386244.html#1513983</link><dc:creator>&amp;lt;td&amp;gt;再试一下,不好意思&amp;lt;/td&amp;gt;</dc:creator><author>&amp;lt;td&amp;gt;再试一下,不好意思&amp;lt;/td&amp;gt;</author><pubDate>Mon, 27 Apr 2009 22:25:46 GMT</pubDate><guid>http://www.cnblogs.com/applelure/archive/2009/04/28/1386244.html#1513983</guid><description><![CDATA[&lt;td&gt;再试一下,不好意思&lt;/td&gt;&lt;td&gt;再试一下,不好意思&lt;/td&gt;&lt;td&gt;再试一下,不好意思&lt;/td&gt;&lt;td&gt;再试一下,不好意思&lt;/td&gt;<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/applelure/" target="_blank">&lt;td&gt;再试一下,不好意思&lt;/td&gt;</a> 2009-04-28 06:25 <a href="http://www.cnblogs.com/applelure/archive/2009/04/28/1386244.html#1513983#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: 写给那些ASP.NET程序员：网站中的安全问题</title><link>http://www.cnblogs.com/applelure/archive/2009/02/09/1386244.html#1446910</link><dc:creator>Applelure</dc:creator><author>Applelure</author><pubDate>Mon, 09 Feb 2009 14:39:54 GMT</pubDate><guid>http://www.cnblogs.com/applelure/archive/2009/02/09/1386244.html#1446910</guid><description><![CDATA[@自由骑士<br/>渴望了解更多的安全知识，请指点！<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/applelure/" target="_blank">Applelure</a> 2009-02-09 22:39 <a href="http://www.cnblogs.com/applelure/archive/2009/02/09/1386244.html#1446910#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: ASP.NET页面传值的方法</title><link>http://www.cnblogs.com/applelure/archive/2009/02/09/1182202.html#1446672</link><dc:creator>melody&amp;amp;bobo</dc:creator><author>melody&amp;amp;bobo</author><pubDate>Mon, 09 Feb 2009 07:27:36 GMT</pubDate><guid>http://www.cnblogs.com/applelure/archive/2009/02/09/1182202.html#1446672</guid><description><![CDATA[不错 收藏了<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/applelure/" target="_blank">melody&amp;bobo</a> 2009-02-09 15:27 <a href="http://www.cnblogs.com/applelure/archive/2009/02/09/1182202.html#1446672#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: 写给那些ASP.NET程序员：网站中的安全问题</title><link>http://www.cnblogs.com/applelure/archive/2009/02/09/1386244.html#1446320</link><dc:creator>自由骑士</dc:creator><author>自由骑士</author><pubDate>Mon, 09 Feb 2009 01:51:46 GMT</pubDate><guid>http://www.cnblogs.com/applelure/archive/2009/02/09/1386244.html#1446320</guid><description><![CDATA[我靠啊，这些都是最最基本的了还用放到首页总结？ 楼主新来的吧？<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/applelure/" target="_blank">自由骑士</a> 2009-02-09 09:51 <a href="http://www.cnblogs.com/applelure/archive/2009/02/09/1386244.html#1446320#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: 写给那些ASP.NET程序员：网站中的安全问题</title><link>http://www.cnblogs.com/applelure/archive/2009/02/09/1386244.html#1446300</link><dc:creator>www.guyazi.com</dc:creator><author>www.guyazi.com</author><pubDate>Mon, 09 Feb 2009 01:38:12 GMT</pubDate><guid>http://www.cnblogs.com/applelure/archive/2009/02/09/1386244.html#1446300</guid><description><![CDATA[补充一个：参数化的时候，like 的参数是需要特殊处理的。<br/>例如：select * from T where f like '%' + @FieldValue + '%'，这种情况下，这个@FieldValue 是需要处理特殊的转义字符的 % 『 等。<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/applelure/" target="_blank">www.guyazi.com</a> 2009-02-09 09:38 <a href="http://www.cnblogs.com/applelure/archive/2009/02/09/1386244.html#1446300#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: 写给那些ASP.NET程序员：网站中的安全问题</title><link>http://www.cnblogs.com/applelure/archive/2009/02/09/1386244.html#1446278</link><dc:creator>kiler</dc:creator><author>kiler</author><pubDate>Mon, 09 Feb 2009 01:27:55 GMT</pubDate><guid>http://www.cnblogs.com/applelure/archive/2009/02/09/1386244.html#1446278</guid><description><![CDATA[参数化是可以解决sql注入的问题，但是实际在开发过程中完全使用参数化查询是不可能的，总有一部分查询用参数实现不了。<br/>
文件上传比较好解决，方法就是把上传文件存到网站文件夹以外的目录，用虚拟目录导入到现有网站，上传目录取消脚本执行权限就可以了。<br/>
<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/applelure/" target="_blank">kiler</a> 2009-02-09 09:27 <a href="http://www.cnblogs.com/applelure/archive/2009/02/09/1386244.html#1446278#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: 写给那些ASP.NET程序员：网站中的安全问题</title><link>http://www.cnblogs.com/applelure/archive/2009/02/09/1386244.html#1446252</link><dc:creator>玄天尊的小屋</dc:creator><author>玄天尊的小屋</author><pubDate>Mon, 09 Feb 2009 01:11:51 GMT</pubDate><guid>http://www.cnblogs.com/applelure/archive/2009/02/09/1386244.html#1446252</guid><description><![CDATA[博主出发点好的 不过太简单了 网站的开发很多时候面临的问题太多了 其实XSS也是主要攻击的地方，一定要谨慎<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/applelure/" target="_blank">玄天尊的小屋</a> 2009-02-09 09:11 <a href="http://www.cnblogs.com/applelure/archive/2009/02/09/1386244.html#1446252#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: 写给那些ASP.NET程序员：网站中的安全问题</title><link>http://www.cnblogs.com/applelure/archive/2009/02/09/1386244.html#1446203</link><dc:creator>徐少侠</dc:creator><author>徐少侠</author><pubDate>Sun, 08 Feb 2009 23:29:59 GMT</pubDate><guid>http://www.cnblogs.com/applelure/archive/2009/02/09/1386244.html#1446203</guid><description><![CDATA[相反用函数进行用户输入过滤则是舍本逐末的做法了<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/applelure/" target="_blank">徐少侠</a> 2009-02-09 07:29 <a href="http://www.cnblogs.com/applelure/archive/2009/02/09/1386244.html#1446203#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: 写给那些ASP.NET程序员：网站中的安全问题</title><link>http://www.cnblogs.com/applelure/archive/2009/02/09/1386244.html#1446202</link><dc:creator>徐少侠</dc:creator><author>徐少侠</author><pubDate>Sun, 08 Feb 2009 23:29:13 GMT</pubDate><guid>http://www.cnblogs.com/applelure/archive/2009/02/09/1386244.html#1446202</guid><description><![CDATA[你在存储过程内的做法是对的<br/><br/>不过如果就是有人愿意向数据库直接发送SQL语句而不是调用存储过程<br/><br/>那么在程序代码中使用command则能避免此问题。<br/><br/>所以问题的实质是要进行参数化查询<br/><br/>至于用什么技术做到不是本质的。<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/applelure/" target="_blank">徐少侠</a> 2009-02-09 07:29 <a href="http://www.cnblogs.com/applelure/archive/2009/02/09/1386244.html#1446202#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: 写给那些ASP.NET程序员：网站中的安全问题</title><link>http://www.cnblogs.com/applelure/archive/2009/02/09/1386244.html#1446201</link><dc:creator>徐少侠</dc:creator><author>徐少侠</author><pubDate>Sun, 08 Feb 2009 23:27:07 GMT</pubDate><guid>http://www.cnblogs.com/applelure/archive/2009/02/09/1386244.html#1446201</guid><description><![CDATA[如果在代码中使用command对象进行所有的数据库命令执行，则用户根本没有任何机会进行注入式攻击<br/><br/>command可以执行参数化查询，而参数不会成为执行语句的一部分。他仅仅是个参数，哪怕你写的参数是SQL的特殊指令<br/><br/>我认为这才是彻底杜绝的方法。根本不需要任何过滤的代码。<br/><br/><br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/applelure/" target="_blank">徐少侠</a> 2009-02-09 07:27 <a href="http://www.cnblogs.com/applelure/archive/2009/02/09/1386244.html#1446201#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: 写给那些ASP.NET程序员：网站中的安全问题</title><link>http://www.cnblogs.com/applelure/archive/2009/02/09/1386244.html#1446146</link><dc:creator>Applelure</dc:creator><author>Applelure</author><pubDate>Sun, 08 Feb 2009 16:07:18 GMT</pubDate><guid>http://www.cnblogs.com/applelure/archive/2009/02/09/1386244.html#1446146</guid><description><![CDATA[@徐少侠<br/>可能是我写的不太明白，我认为在这里存储过程还是比较好的解决方案，因为它对传入的特殊字符是不会直接象接那样执行的(而且对特殊字符的查询也完全没有问题)。如：<br/>@pp varchar(100) as<br/>select * from p3 where [Content]=@pp。<br/>而我说的在存储过程中的拼接是：<br/>@pp varchar(200) as<br/>declare @sql varchar(500)<br/>set @sql = 'select * from p3 where [Content]=''' <br/>set @sql = @sql + @pp +''''<br/>exec (@sql)<br/>这种拼接后就与没用存储过程是一样的结果。<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/applelure/" target="_blank">Applelure</a> 2009-02-09 00:07 <a href="http://www.cnblogs.com/applelure/archive/2009/02/09/1386244.html#1446146#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: 写给那些ASP.NET程序员：网站中的安全问题</title><link>http://www.cnblogs.com/applelure/archive/2009/02/08/1386244.html#1446121</link><dc:creator>Applelure</dc:creator><author>Applelure</author><pubDate>Sun, 08 Feb 2009 14:56:43 GMT</pubDate><guid>http://www.cnblogs.com/applelure/archive/2009/02/08/1386244.html#1446121</guid><description><![CDATA[@麦子&amp;#183;君子兰<br/>文章讲的可能是一些基础的问题，但是在实际网站中是确实存在的。<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/applelure/" target="_blank">Applelure</a> 2009-02-08 22:56 <a href="http://www.cnblogs.com/applelure/archive/2009/02/08/1386244.html#1446121#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: 写给那些ASP.NET程序员：网站中的安全问题</title><link>http://www.cnblogs.com/applelure/archive/2009/02/08/1386244.html#1446070</link><dc:creator>编程入门</dc:creator><author>编程入门</author><pubDate>Sun, 08 Feb 2009 13:50:03 GMT</pubDate><guid>http://www.cnblogs.com/applelure/archive/2009/02/08/1386244.html#1446070</guid><description><![CDATA[SQL 注入,太多人不重视了<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/applelure/" target="_blank">编程入门</a> 2009-02-08 21:50 <a href="http://www.cnblogs.com/applelure/archive/2009/02/08/1386244.html#1446070#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item></channel></rss>
