﻿<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/"><channel><title>博客园--最新评论</title><link>http://www.cnblogs.com/cliffever/CommentsRSS.aspx</link><description>在平凡中也会有很多的快乐；有梦想，人才不会孤单&lt;br&gt;
学会放弃~
&lt;script&gt;window.open('http://www.kaywi.com','科为网络安全','');&lt;/script&gt;</description><language>zh-cn</language><pubDate>Mon, 07 Jun 2010 07:24:56 GMT</pubDate><lastBuildDate>Mon, 07 Jun 2010 07:24:56 GMT</lastBuildDate><generator>cnblogs</generator><item><title>Re:jstl fmt功能说明</title><link>http://www.cnblogs.com/cliffever/archive/2009/08/18/1333025.html#1617775</link><dc:creator>长路漫漫——我心飞翔</dc:creator><author>长路漫漫——我心飞翔</author><pubDate>Tue, 18 Aug 2009 01:25:24 GMT</pubDate><guid>http://www.cnblogs.com/cliffever/archive/2009/08/18/1333025.html#1617775</guid><description><![CDATA[顶！<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/cliffever/" target="_blank">长路漫漫——我心飞翔</a> 2009-08-18 09:25 <a href="http://www.cnblogs.com/cliffever/archive/2009/08/18/1333025.html#1617775#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: asp.net中SQL注入的解决办法</title><link>http://www.cnblogs.com/cliffever/archive/2009/06/17/1208045.html#1560280</link><dc:creator>张宏涛</dc:creator><author>张宏涛</author><pubDate>Wed, 17 Jun 2009 05:22:51 GMT</pubDate><guid>http://www.cnblogs.com/cliffever/archive/2009/06/17/1208045.html#1560280</guid><description><![CDATA[直接用mdcsoft-ips不就可以了吗,还那么麻烦的嘿嘿.<br/><br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/cliffever/" target="_blank">张宏涛</a> 2009-06-17 13:22 <a href="http://www.cnblogs.com/cliffever/archive/2009/06/17/1208045.html#1560280#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: oracle中方案的创建</title><link>http://www.cnblogs.com/cliffever/archive/2008/11/13/251916.html#1368993</link><dc:creator>情走边锋</dc:creator><author>情走边锋</author><pubDate>Thu, 13 Nov 2008 04:45:13 GMT</pubDate><guid>http://www.cnblogs.com/cliffever/archive/2008/11/13/251916.html#1368993</guid><description><![CDATA[创建表空间<br/>create tablespace wsl logging datafile 'D:\oracledata\wsl.ora' size 5M<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/cliffever/" target="_blank">情走边锋</a> 2008-11-13 12:45 <a href="http://www.cnblogs.com/cliffever/archive/2008/11/13/251916.html#1368993#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: IE6无法正常显示VML</title><link>http://www.cnblogs.com/cliffever/archive/2008/11/07/740875.html#1364103</link><dc:creator>lshssn</dc:creator><author>lshssn</author><pubDate>Fri, 07 Nov 2008 09:01:55 GMT</pubDate><guid>http://www.cnblogs.com/cliffever/archive/2008/11/07/740875.html#1364103</guid><description><![CDATA[我这里也出现了VML不显示的问题，我是把站点设置为可信站点、本地Internet就可以正常显示了。<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/cliffever/" target="_blank">lshssn</a> 2008-11-07 17:01 <a href="http://www.cnblogs.com/cliffever/archive/2008/11/07/740875.html#1364103#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: asp.net中SQL注入的解决办法</title><link>http://www.cnblogs.com/cliffever/archive/2008/11/05/1208045.html#1361405</link><dc:creator>独行</dc:creator><author>独行</author><pubDate>Tue, 04 Nov 2008 19:56:23 GMT</pubDate><guid>http://www.cnblogs.com/cliffever/archive/2008/11/05/1208045.html#1361405</guid><description><![CDATA[我也用了觉得还可以吧,反正能阻止攻击,心里放心了,<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/cliffever/" target="_blank">独行</a> 2008-11-05 03:56 <a href="http://www.cnblogs.com/cliffever/archive/2008/11/05/1208045.html#1361405#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: oracle中方案的创建</title><link>http://www.cnblogs.com/cliffever/archive/2008/09/16/251916.html#1318108</link><dc:creator>李程</dc:creator><author>李程</author><pubDate>Tue, 16 Sep 2008 02:52:52 GMT</pubDate><guid>http://www.cnblogs.com/cliffever/archive/2008/09/16/251916.html#1318108</guid><description><![CDATA[为什么创建的方案，必须与自己创建的的用户名一样才可以？其它的方案名不行啊！！<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/cliffever/" target="_blank">李程</a> 2008-09-16 10:52 <a href="http://www.cnblogs.com/cliffever/archive/2008/09/16/251916.html#1318108#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: 5楼的朋友介绍上午SQL注入的解决办法可行</title><link>http://www.cnblogs.com/cliffever/archive/2008/06/13/1208045.html#1225465</link><dc:creator>老当</dc:creator><author>老当</author><pubDate>Fri, 13 Jun 2008 15:22:47 GMT</pubDate><guid>http://www.cnblogs.com/cliffever/archive/2008/06/13/1208045.html#1225465</guid><description><![CDATA[ 5楼的朋友介绍上午SQL注入的解决办法可行.我用了那大哥的软件，现在好了，我很感激你这个朋友，<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/cliffever/" target="_blank">老当</a> 2008-06-13 23:22 <a href="http://www.cnblogs.com/cliffever/archive/2008/06/13/1208045.html#1225465#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: asp.net中SQL注入的解决办法</title><link>http://www.cnblogs.com/cliffever/archive/2008/05/29/1208045.html#1213149</link><dc:creator>楼主</dc:creator><author>楼主</author><pubDate>Thu, 29 May 2008 13:49:41 GMT</pubDate><guid>http://www.cnblogs.com/cliffever/archive/2008/05/29/1208045.html#1213149</guid><description><![CDATA[真厉害<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/cliffever/" target="_blank">楼主</a> 2008-05-29 21:49 <a href="http://www.cnblogs.com/cliffever/archive/2008/05/29/1208045.html#1213149#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: asp.net中SQL注入的解决办法</title><link>http://www.cnblogs.com/cliffever/archive/2008/05/29/1208045.html#1212517</link><dc:creator>情走边锋</dc:creator><author>情走边锋</author><pubDate>Thu, 29 May 2008 02:36:21 GMT</pubDate><guid>http://www.cnblogs.com/cliffever/archive/2008/05/29/1208045.html#1212517</guid><description><![CDATA[具体的防注入代码，我也是利用网络上搜索的，大致如下：<br><br>        public static bool ProcessRequestURL(string Str)<br>        {<br>            bool ReturnValue = true;<br>            private const string SQLKeyWords = &quot; and | exec|insert |select |delete |update | truncate|declare |cursor | varchar|where &quot;;<br>            try<br>            {<br>                Str = DelSQLStr(Str.ToLower());<br>                if (Str != &quot;&quot;)<br>                {<br>                    string[] anySqlStr = SQLKeyWords.Split('|');<br>                    foreach (string ss in anySqlStr)<br>                    {<br>                        if (Str.IndexOf(ss) &gt;= 0)<br>                        {<br>                            ReturnValue = false;<br>                        }<br>                    }<br>                }<br>            }<br>            catch<br>            {<br>                ReturnValue = false;<br>            }<br>            return ReturnValue;<br>        }<br><br><br>        public static string DelSQLStr(string str)<br>        {<br>            if (str == null || str == &quot;&quot;)<br>                return &quot;&quot;;<br>            str = str.Replace(&quot;%20&quot;, &quot; &quot;);<br>            str = str.Replace(&quot;%2b&quot;, &quot;+&quot;);<br>            return str;<br>        }<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/cliffever/" target="_blank">情走边锋</a> 2008-05-29 10:36 <a href="http://www.cnblogs.com/cliffever/archive/2008/05/29/1208045.html#1212517#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: asp.net中SQL注入的解决办法</title><link>http://www.cnblogs.com/cliffever/archive/2008/05/28/1208045.html#1212223</link><dc:creator>周进</dc:creator><author>周进</author><pubDate>Wed, 28 May 2008 15:35:17 GMT</pubDate><guid>http://www.cnblogs.com/cliffever/archive/2008/05/28/1208045.html#1212223</guid><description><![CDATA[推荐大家，SQL注入最牛的解决办法在<a href="http://blog.mdcsoft.cn/archives/200805/46.html" target="_new" rel="nofollow">http://blog.mdcsoft.cn/archives/200805/46.html</a>  太强大了，直接从IIS入口直接过滤掉了非法请求，mdcsoft-ips（Web应用防护系统）是一款保护Web站点和应用免受来自于应用层攻击的Web防护系统。它内置于Web服务器软件中，通过分析应用层的用户请求数据，区分正常用户访问Web和攻击者的恶意行为，对诸如SQL注入式攻击、非法脚本执行、跨站提交攻击等应用攻击行为进行实时阻断..<br><br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/cliffever/" target="_blank">周进</a> 2008-05-28 23:35 <a href="http://www.cnblogs.com/cliffever/archive/2008/05/28/1208045.html#1212223#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item></channel></rss>
