﻿<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/"><channel><title>博客园-欢迎光临赵玉开的技术博客-最新评论</title><link>http://www.cnblogs.com/yukaizhao/CommentsRSS.aspx</link><description>天马行空 无怨无嗔</description><language>zh-cn</language><pubDate>Wed, 23 Jul 2008 09:06:06 GMT</pubDate><lastBuildDate>Wed, 23 Jul 2008 09:06:06 GMT</lastBuildDate><generator>cnblogs</generator><item><title>re: 如何定义Xsd文件</title><link>http://www.cnblogs.com/yukaizhao/archive/2008/07/25/687526.html#1267280</link><dc:creator>雨中漫步的太阳</dc:creator><author>雨中漫步的太阳</author><pubDate>Fri, 25 Jul 2008 06:54:48 GMT</pubDate><guid>http://www.cnblogs.com/yukaizhao/archive/2008/07/25/687526.html#1267280</guid><description><![CDATA[支持下 收藏了<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/yukaizhao/" target="_blank">雨中漫步的太阳</a> 2008-07-25 14:54 <a href="http://www.cnblogs.com/yukaizhao/archive/2008/07/25/687526.html#1267280#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: 如此高效通用的分页存储过程是带有sql注入漏洞的</title><link>http://www.cnblogs.com/yukaizhao/archive/2008/07/21/669617.html#1262776</link><dc:creator>玉开</dc:creator><author>玉开</author><pubDate>Mon, 21 Jul 2008 10:13:08 GMT</pubDate><guid>http://www.cnblogs.com/yukaizhao/archive/2008/07/21/669617.html#1262776</guid><description><![CDATA[@Net205 Blog<br/>这是一个思路吧，where条件通常是多变的。<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/yukaizhao/" target="_blank">玉开</a> 2008-07-21 18:13 <a href="http://www.cnblogs.com/yukaizhao/archive/2008/07/21/669617.html#1262776#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: 如此高效通用的分页存储过程是带有sql注入漏洞的</title><link>http://www.cnblogs.com/yukaizhao/archive/2008/07/18/669617.html#1260356</link><dc:creator>Net205 Blog</dc:creator><author>Net205 Blog</author><pubDate>Fri, 18 Jul 2008 09:24:27 GMT</pubDate><guid>http://www.cnblogs.com/yukaizhao/archive/2008/07/18/669617.html#1260356</guid><description><![CDATA[搜索blog找到这篇老文章，去年的，我说一下我的想法。<br/>--代码中的@strSearch假设为存储过程的参数<br/>按你的代码写的(存在SQL注入的写法)<br/>declare @strSearch varchar(100)<br/>set @strSearch = 'Jim''dog'<br/><br/>DECLARE @strSQL varchar(8000)<br/>DECLARE @strWhere varchar(1000)<br/>SET @strWhere = 'UserName LIKE ''%'+ @strSearch +'%'''<br/>set @strSQL = 'SELECT TOP 20 *  from [UserAccount]  where ' + @strWhere + ' ORDER BY ID DESC'<br/>print @strSQL<br/>exec (@strSQL)<br/><br/>解决办法：<br/>declare @strSearch varchar(100)<br/>set @strSearch = 'Jim''dog'<br/><br/>DECLARE @strSQL nvarchar(4000)<br/>DECLARE @strWhere varchar(1000)<br/>SET @strWhere = 'UserName LIKE ''%@strSearch%'''<br/>set @strSQL = 'SELECT TOP 20 *  from [UserAccount]  where ' + @strWhere + ' ORDER BY ID DESC'<br/>print @strSQL<br/>exec sp_executesql @strSQL,N'@strSearch varchar(100)',@strSearch<br/><br/>试验过<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/yukaizhao/" target="_blank">Net205 Blog</a> 2008-07-18 17:24 <a href="http://www.cnblogs.com/yukaizhao/archive/2008/07/18/669617.html#1260356#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: Js + Css的msn式的popup提示窗口的实现</title><link>http://www.cnblogs.com/yukaizhao/archive/2008/07/17/707103.html#1258871</link><dc:creator>wbb</dc:creator><author>wbb</author><pubDate>Thu, 17 Jul 2008 04:23:00 GMT</pubDate><guid>http://www.cnblogs.com/yukaizhao/archive/2008/07/17/707103.html#1258871</guid><description><![CDATA[不知道兼容不兼容firefox<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/yukaizhao/" target="_blank">wbb</a> 2008-07-17 12:23 <a href="http://www.cnblogs.com/yukaizhao/archive/2008/07/17/707103.html#1258871#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: Sql Server2005对t-sql的增强之Cross Apply</title><link>http://www.cnblogs.com/yukaizhao/archive/2008/07/17/1177554.html#1258841</link><dc:creator>andrew1234567890</dc:creator><author>andrew1234567890</author><pubDate>Thu, 17 Jul 2008 03:46:05 GMT</pubDate><guid>http://www.cnblogs.com/yukaizhao/archive/2008/07/17/1177554.html#1258841</guid><description><![CDATA[very good<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/yukaizhao/" target="_blank">andrew1234567890</a> 2008-07-17 11:46 <a href="http://www.cnblogs.com/yukaizhao/archive/2008/07/17/1177554.html#1258841#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: 必须掌握的八个【cmd 命令行】[转]</title><link>http://www.cnblogs.com/yukaizhao/archive/2008/07/16/1244403.html#1256971</link><dc:creator>火无极</dc:creator><author>火无极</author><pubDate>Wed, 16 Jul 2008 07:55:53 GMT</pubDate><guid>http://www.cnblogs.com/yukaizhao/archive/2008/07/16/1244403.html#1256971</guid><description><![CDATA[cmd命令行 好东西<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/yukaizhao/" target="_blank">火无极</a> 2008-07-16 15:55 <a href="http://www.cnblogs.com/yukaizhao/archive/2008/07/16/1244403.html#1256971#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: 必须掌握的八个【cmd 命令行】[转]</title><link>http://www.cnblogs.com/yukaizhao/archive/2008/07/16/1244403.html#1256954</link><dc:creator>thank you</dc:creator><author>thank you</author><pubDate>Wed, 16 Jul 2008 07:49:58 GMT</pubDate><guid>http://www.cnblogs.com/yukaizhao/archive/2008/07/16/1244403.html#1256954</guid><description><![CDATA[8 ge~~~~~~~~<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/yukaizhao/" target="_blank">thank you</a> 2008-07-16 15:49 <a href="http://www.cnblogs.com/yukaizhao/archive/2008/07/16/1244403.html#1256954#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: 2008,属于每一个中国人！</title><link>http://www.cnblogs.com/yukaizhao/archive/2008/07/16/1242692.html#1256595</link><dc:creator>Rick Carter</dc:creator><author>Rick Carter</author><pubDate>Wed, 16 Jul 2008 04:55:02 GMT</pubDate><guid>http://www.cnblogs.com/yukaizhao/archive/2008/07/16/1242692.html#1256595</guid><description><![CDATA[好帖，顶一个<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/yukaizhao/" target="_blank">Rick Carter</a> 2008-07-16 12:55 <a href="http://www.cnblogs.com/yukaizhao/archive/2008/07/16/1242692.html#1256595#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: 2008,属于每一个中国人！</title><link>http://www.cnblogs.com/yukaizhao/archive/2008/07/15/1242692.html#1255097</link><dc:creator>上午的绝缘杯</dc:creator><author>上午的绝缘杯</author><pubDate>Tue, 15 Jul 2008 03:13:07 GMT</pubDate><guid>http://www.cnblogs.com/yukaizhao/archive/2008/07/15/1242692.html#1255097</guid><description><![CDATA[地下室不让住人了，<br>路边摊不让摆了，<br>进京的车需要查身份证，<br>走在大街上需要暂住证，<br>汽车分单双号了，<br>地铁不让带饮料了，<br>奥运歌曲、自拍视频不让发表了，<br>网络项目也不让开了，<br>民工劝返了，<br>还有什么...<br><br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/yukaizhao/" target="_blank">上午的绝缘杯</a> 2008-07-15 11:13 <a href="http://www.cnblogs.com/yukaizhao/archive/2008/07/15/1242692.html#1255097#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: 2008,属于每一个中国人！</title><link>http://www.cnblogs.com/yukaizhao/archive/2008/07/14/1242692.html#1254372</link><dc:creator>玉开</dc:creator><author>玉开</author><pubDate>Mon, 14 Jul 2008 10:07:47 GMT</pubDate><guid>http://www.cnblogs.com/yukaizhao/archive/2008/07/14/1242692.html#1254372</guid><description><![CDATA[@thriving.country<br>大家不要写对奥运不利的句子<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/yukaizhao/" target="_blank">玉开</a> 2008-07-14 18:07 <a href="http://www.cnblogs.com/yukaizhao/archive/2008/07/14/1242692.html#1254372#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item></channel></rss>