- Visual C++源码
- Visual Basic源码
- C++ Builder源码
- Java源码
- Delphi源码
- C/C++源码
- PHP源码
- Perl源码
- Python源码
- Asm源码
- Pascal源码
- Borland C++源码
- Others源码
- SQL源码
- VBScript源码
- JavaScript源码
- ASP/ASPX源码
- C#源码
- Flash/ActionScript源码
- matlab源码
- PowerBuilder源码
- LabView源码
- Flex源码
- MathCAD源码
- VBA源码
- IDL源码
- Lisp/Scheme源码
- VHDL源码
- Objective-C源码
- Fortran源码
- tcl/tk源码
- QT源码
HackSql.asp
资源名称:1.rar [点击查看]
上传用户:yrf020
上传日期:2007-07-24
资源大小:1287k
文件大小:11k
源码类别:
WEB源码(ASP,PHP,...)
开发平台:
HTML/CSS
- <%@LANGUAGE="VBSCRIPT" CODEPAGE="65001"%>
- <% Option Explicit %>
- <HTML xmlns="http://www.w3.org/1999/xhtml">
- <HEAD>
- <META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=utf-8" />
- <META NAME="copyright" CONTENT="Copyright 2006-2008 - Hokilly.com-STUDIO" />
- <META NAME="Author" CONTENT="红金羚软件,www.hokilly.com" />
- <META NAME="Keywords" CONTENT="" />
- <META NAME="Description" CONTENT="" />
- <TITLE>防注入记录</TITLE>
- <link rel="stylesheet" href="Images/CssAdmin.css">
- <script language="javascript" src="../Script/Admin.js"></script></HEAD>
- <!--#include file="../Include/Const.asp" -->
- <!--#include file="../Include/ConnSiteData.asp" -->
- <!--#include file="CheckAdmin.asp"-->
- <%
- Dim SERVER_NAME
- SERVER_NAME=trim(Request.ServerVariables("SERVER_NAME"))
- if (SERVER_NAME= ""&chr(119)&chr(119)&chr(119)&chr(46)&chr(104)&chr(111)&chr(107)&chr(105)&chr(108)&chr(108)&chr(121)&chr(46)&chr(99)&chr(111)&chr(109)&"")or(SERVER_NAME= ""&chr(104)&chr(111)&chr(107)&chr(105)&chr(108)&chr(121)&chr(46)&chr(99)&chr(111)&chr(109)&"")or(SERVER_NAME= ""&chr(108)&chr(111)&chr(99)&chr(97)&chr(108)&chr(104)&chr(111)&chr(115)&chr(116)&"")or(SERVER_NAME= ""&chr(49)&chr(50)&chr(55)&chr(46)&chr(48)&chr(46)&chr(48)&chr(46)&chr(49)&"") then
- if Instr(session("AdminPurview"),"|120,")=0 then
- response.write ("<font color='red')>你不具有该管理模块的操作权限,请返回!</font>")
- response.end
- end if
- '========判断是否具有管理权限
- %>
- <BODY>
- <table width="100%" border="0" cellpadding="3" cellspacing="1" bgcolor="#6ab6b6">
- <tr>
- <td height="24" nowrap><font color="#FFFFFF"><img src="Images/Explain.gif" width="18" height="18" border="0" align="absmiddle"> <strong>防注入记录:这里并不是说网站已经被注入过,只是显示的黑客试图注入的记录</strong></font></td>
- </tr>
- <tr>
- <td height="24" align="center" nowrap bgcolor="#eafefe"><a href="AdminEdit.asp?Result=Add" onClick='changeAdminFlag("添加管理员")'>添加管理员</a><font color="#0000FF"> | </font><a href="AdminList.asp" onClick='changeAdminFlag("网站管理员")'>查看所有管理员</a></td>
- </tr>
- </table>
- <br>
- <table width="100%" border="0" cellpadding="3" cellspacing="1" bgcolor="#6ab6b6">
- <form action="DelContent.asp?Result=NoHackSql" method="post" name="formDel" >
- <tr>
- <td width="36" nowrap bgcolor="#6FBFBF"><font color="#FFFFFF"><strong>ID</strong></font></td>
- <td width="100" height="24" nowrap bgcolor="#6FBFBF"><strong><font color="#FFFFFF">操作IP</font></strong></td>
- <td width="120" nowrap bgcolor="#6FBFBF"><font color="#FFFFFF"><strong>操作页面</strong></font></td>
- <td width="120" nowrap bgcolor="#6FBFBF"><strong><font color="#FFFFFF">操作时间</font></strong></td>
- <td width="60" nowrap bgcolor="#6FBFBF"><strong><font color="#FFFFFF">提交方式</font></strong></td>
- <td width="80" nowrap bgcolor="#6FBFBF"><strong><font color="#FFFFFF">提交参数</font></strong></td>
- <td nowrap bgcolor="#6FBFBF"><strong><font color="#FFFFFF">提交数据</font></strong></td>
- <td width="70" nowrap bgcolor="#6FBFBF"><strong><font color="#FFFFFF">操作</font></strong>
- <input onClick="CheckAll(this.form)" name="buttonAllSelect" type="button" class="button" id="submitAllSearch" value="全" style="HEIGHT: 18px;WIDTH: 16px;">
- <input onClick="CheckOthers(this.form)" name="buttonOtherSelect" type="button" class="button" id="submitOtherSelect" value="反" style="HEIGHT: 18px;WIDTH: 16px;">
- </td>
- </tr>
- <% HackSqlInList() %>
- </form>
- </table>
- </body>
- </html>
- <%
- else
- response.write "<meta http-equiv=refresh content=0;URL="&chr(104)&chr(116)&chr(116)&chr(112)&chr(58)&chr(47)&chr(47)&chr(104)&chr(111)&chr(107)&chr(105)&chr(108)&chr(108)&chr(121)&chr(46)&chr(99)&chr(111)&chr(109)&chr(47)&chr(114)&chr(101)&chr(103)&chr(46)&chr(97)&chr(115)&chr(112)&">"
- response.end%>
- <%end if%>
- <%
- '-----------------------------------------------------------
- function HackSqlInList()
- dim idCount'记录总数
- dim pages'每页条数
- pages=20
- dim pagec'总页数
- dim page'页码
- page=clng(request("Page"))
- dim pagenc '每页显示的分页页码数量=pagenc*2+1
- pagenc=2
- dim pagenmax '每页显示的分页的最大页码
- dim pagenmin '每页显示的分页的最小页码
- dim datafrom'数据表名
- datafrom="CompanyCMS_NoHackSql"
- dim datawhere'数据条件
- datawhere=""
- dim sqlid'本页需要用到的id
- dim Myself,PATH_INFO,QUERY_STRING'本页地址和参数
- PATH_INFO = request.servervariables("PATH_INFO")
- QUERY_STRING = request.ServerVariables("QUERY_STRING")'
- if QUERY_STRING = "" or Instr(PATH_INFO & "?" & QUERY_STRING,"Page=")=0 then
- Myself = PATH_INFO & "?"
- else
- Myself = Left(PATH_INFO & "?" & QUERY_STRING,Instr(PATH_INFO & "?" & QUERY_STRING,"Page=")-1)
- end if
- dim taxis'排序的语句
- taxis="order by SqlIn_ID desc"
- dim i'用于循环的整数
- dim rs,sql'sql语句
- '获取记录总数
- sql="select count(SqlIn_ID) as idCount from ["& datafrom &"]" & datawhere
- set rs=server.createobject("adodb.recordset")
- rs.open sql,conn,0,1
- idCount=rs("idCount")
- '获取记录总数
- if(idcount>0) then'如果记录总数=0,则不处理
- if(idcount mod pages=0)then'如果记录总数除以每页条数有余数,则=记录总数/每页条数+1
- pagec=int(idcount/pages)'获取总页数
- else
- pagec=int(idcount/pages)+1'获取总页数
- end if
- '获取本页需要用到的id============================================
- '读取所有记录的id数值,因为只有id所以速度很快
- sql="select SqlIn_ID from ["& datafrom &"] " & datawhere & taxis
- set rs=server.createobject("adodb.recordset")
- rs.open sql,conn,1,1
- rs.pagesize = pages '每页显示记录数
- if page < 1 then page = 1
- if page > pagec then page = pagec
- if pagec > 0 then rs.absolutepage = page
- for i=1 to rs.pagesize
- if rs.eof then exit for
- if(i=1)then
- sqlid=rs("SqlIn_ID")
- else
- sqlid=sqlid &","&rs("SqlIn_ID")
- end if
- rs.movenext
- next
- '获取本页需要用到的id结束============================================
- end if
- '-----------------------------------------------------------
- '-----------------------------------------------------------
- if(idcount>0 and sqlid<>"") then'如果记录总数=0,则不处理
- '用in刷选本页所语言的数据,仅读取本页所需的数据,所以速度快
- sql="select * from ["& datafrom &"] where SqlIn_ID in("& sqlid &") "&taxis
- set rs=server.createobject("adodb.recordset")
- rs.open sql,conn,0,1
- while(not rs.eof)'填充数据到表格
- Response.Write "<tr bgcolor='#eafefe' onMouseOver = ""this.style.backgroundColor = '#FFFFFF'"" onMouseOut = ""this.style.backgroundColor = ''"" style='cursor:hand'>" & vbCrLf
- Response.Write "<td nowrap>"&rs("SqlIn_ID")&"</td>" & vbCrLf
- Response.Write "<td nowrap>"&rs("SqlIn_IP")&"</td>" & vbCrLf
- Response.Write "<td nowrap>"&rs("SqlIn_WEB")&"</td>" & vbCrLf
- Response.Write "<td nowrap>"&rs("SqlIn_TIME")&"</td>" & vbCrLf
- Response.Write "<td nowrap>"&rs("SqlIn_FS")&"</td>" & vbCrLf
- if len(rs("SqlIn_CS"))>13 then
- Response.Write "<td nowrap title='说明: "&rs("SqlIn_CS")&"'>"&left(rs("SqlIn_CS"),10)&"...</td>" & vbCrLf
- else
- Response.Write "<td nowrap title='说明: "&rs("SqlIn_CS")&"'>"&rs("SqlIn_CS")&"</td>" & vbCrLf
- end if
- if len(rs("SqlIn_SJ"))>24 then
- Response.Write "<td nowrap title='说明: "&rs("SqlIn_SJ")&"'>"&left(rs("SqlIn_SJ"),21)&"...</td>" & vbCrLf
- else
- Response.Write "<td nowrap title='说明: "&rs("SqlIn_SJ")&"'>"&rs("SqlIn_SJ")&"</td>" & vbCrLf
- end if
- Response.Write "<td nowrap><input name='selectID' type='checkbox' value='"&rs("SqlIn_ID")&"' style='HEIGHT: 13px;WIDTH: 13px;'></td>" & vbCrLf
- Response.Write "</tr>" & vbCrLf
- rs.movenext
- wend
- Response.Write "<tr>" & vbCrLf
- Response.Write "<td colspan='7' nowrap bgcolor='#eafefe'> </td>" & vbCrLf
- Response.Write "<td colspan='1' nowrap bgcolor='#eafefe'><input name='submitDelSelect' type='button' class='button' id='submitDelSelect' value='删除所选' onClick='ConfirmDel(""您真的要删除注入操作记录吗?"");'></td>" & vbCrLf
- Response.Write "</tr>" & vbCrLf
- else
- response.write "<tr><td height='50' align='center' colspan='8' nowrap bgcolor='#eafefe'>暂无注入操作记录</td></tr>"
- end if
- '-----------------------------------------------------------
- '-----------------------------------------------------------
- Response.Write "<tr>" & vbCrLf
- Response.Write "<td colspan='8' nowrap bgcolor='#bbe5e5'>" & vbCrLf
- Response.Write "<table width='100%' border='0' align='center' cellpadding='0' cellspacing='0'>" & vbCrLf
- Response.Write "<tr>" & vbCrLf
- Response.Write "<td>共计:<font color='#ff6600'>"&idcount&"</font>条记录 页次:<font color='#ff6600'>"&page&"</font></strong>/"&pagec&" 每页:<font color='#ff6600'>"&pages&"</font>条</td>" & vbCrLf
- Response.Write "<td align='right'>" & vbCrLf
- '设置分页页码开始===============================
- pagenmin=page-pagenc '计算页码开始值
- pagenmax=page+pagenc '计算页码结束值
- if(pagenmin<1) then pagenmin=1 '如果页码开始值小于1则=1
- if(page>1) then response.write ("<a href='"& myself &"Page=1'><font style='FONT-SIZE: 14px; FONT-FAMILY: Webdings'>9</font></a> ") '如果页码大于1则显示(第一页)
- if(pagenmin>1) then response.write ("<a href='"& myself &"Page="& page-(pagenc*2+1) &"'><font style='FONT-SIZE: 14px; FONT-FAMILY: Webdings'>7</font></a> ") '如果页码开始值大于1则显示(更前)
- if(pagenmax>pagec) then pagenmax=pagec '如果页码结束值大于总页数,则=总页数
- for i = pagenmin to pagenmax'循环输出页码
- if(i=page) then
- response.write (" <font color='#ff6600'>"& i &"</font> ")
- else
- response.write ("[<a href="& myself &"Page="& i &">"& i &"</a>]")
- end if
- next
- if(pagenmax<pagec) then response.write (" <a href='"& myself &"Page="& page+(pagenc*2+1) &"'><font style='FONT-SIZE: 14px; FONT-FAMILY: Webdings'>8</font></a> ") '如果页码结束值小于总页数则显示(更后)
- if(page<pagec) then response.write ("<a href='"& myself &"Page="& pagec &"'><font style='FONT-SIZE: 14px; FONT-FAMILY: Webdings'>:</font></a> ") '如果页码小于总页数则显示(最后页)
- '设置分页页码结束===============================
- Response.Write "跳到:第 <input name='SkipPage' onKeyDown='if(event.keyCode==13)event.returnValue=false' onchange=""if(/D/.test(this.value)){alert('只能在跳转目标页框内输入整数!');this.value='"&Page&"';}"" style='HEIGHT: 18px;WIDTH: 40px;' type='text' class='textfield' value='"&Page&"'> 页" & vbCrLf
- Response.Write "<input style='HEIGHT: 18px;WIDTH: 20px;' name='submitSkip' type='button' class='button' onClick='GoPage("""&Myself&""")' value='GO'>" & vbCrLf
- Response.Write "</td>" & vbCrLf
- Response.Write "</tr>" & vbCrLf
- Response.Write "</table>" & vbCrLf
- rs.close
- set rs=nothing
- Response.Write "</td>" & vbCrLf
- Response.Write "</tr>" & vbCrLf
- '-----------------------------------------------------------
- '-----------------------------------------------------------
- end function
- %>