<% '============================================================================== '软件名称:风讯网站信息管理系统 '当前版本:Foosun Content Manager System '模块功能: SQL通用防注入模块 '最新更新:2005.8.4 By lzp '============================================================================== '商业注册联系:028-85098980-601,602 技术支持:028-85098980-606、607,客户支持:608 '产品咨询QQ:159410,655071,66252421 '技术支持:所有程序使用问题,请提问到bbs.foosun.net我们将及时回答您 '程序开发:风讯开发组 & 风讯插件开发组 '论坛支持:风讯在线论坛(http://bbs.foosun.net) '官方网站:www.Foosun.net 演示站点:test.cooin.com '网站建设专区:www.cooin.com '============================================================================== '免费版本请在新闻首页保留版权信息,并做上本站LOGO友情连接 '============================================================================== Dim FS_NoSqlHack_AllStr,FS_NoSqlHack_Str,FS_NoSqlHack_ComeUrlGet,FS_NoSqlHack_ComeUrlPost,FS_NoSqlHack_Get,FS_NoSqlHack_Post,FS_NoSqlHack_i On Error Resume Next FS_NoSqlHack_AllStr="'|;| and |chr(|exec |insert |select |delete from|update |mid(|master." FS_NoSqlHack_ComeUrlGet = Request.QueryString FS_NoSqlHack_ComeUrlPost = Request.Form FS_NoSqlHack_Str = Split(FS_NoSqlHack_AllStr,"|") 'Post If FS_NoSqlHack_ComeUrlPost<>"" then For Each FS_NoSqlHack_Post In Request.Form For FS_NoSqlHack_i = 0 To Ubound(FS_NoSqlHack_Str) If Instr(LCase(Request.Form(FS_NoSqlHack_Post)),FS_NoSqlHack_Str(FS_NoSqlHack_i))<>0 Then Response.Write("Error!!") Response.End End if Next Next End if 'Get If FS_NoSqlHack_ComeUrlGet<>"" then For Each FS_NoSqlHack_Get In Request.QueryString For FS_NoSqlHack_i = 0 To Ubound(FS_NoSqlHack_Str) If Instr(LCase(Request.QueryString(FS_NoSqlHack_Get)),FS_NoSqlHack_Str(FS_NoSqlHack_i))<>0 Then Response.Write("Error!!") Response.End End if Next Next End if %> <% Private Const BITS_TO_A_BYTE = 8 Private Const BYTES_TO_A_WORD = 4 Private Const BITS_TO_A_WORD = 32 Private m_lOnBits(30) Private m_l2Power(30) Private Function LShift(lValue, iShiftBits) If iShiftBits = 0 Then LShift = lValue Exit Function ElseIf iShiftBits = 31 Then If lValue And 1 Then LShift = &H80000000 Else LShift = 0 End If Exit Function ElseIf iShiftBits < 0 Or iShiftBits > 31 Then Err.Raise 6 End If If (lValue And m_l2Power(31 - iShiftBits)) Then LShift = ((lValue And m_lOnBits(31 - (iShiftBits + 1))) * m_l2Power(iShiftBits)) Or &H80000000 Else LShift = ((lValue And m_lOnBits(31 - iShiftBits)) * m_l2Power(iShiftBits)) End If End Function Private Function RShift(lValue, iShiftBits) If iShiftBits = 0 Then RShift = lValue Exit Function ElseIf iShiftBits = 31 Then If lValue And &H80000000 Then RShift = 1 Else RShift = 0 End If Exit Function ElseIf iShiftBits < 0 Or iShiftBits > 31 Then Err.Raise 6 End If RShift = (lValue And &H7FFFFFFE) \ m_l2Power(iShiftBits) If (lValue And &H80000000) Then RShift = (RShift Or (&H40000000 \ m_l2Power(iShiftBits - 1))) End If End Function Private Function RotateLeft(lValue, iShiftBits) RotateLeft = LShift(lValue, iShiftBits) Or RShift(lValue, (32 - iShiftBits)) End Function Private Function AddUnsigned(lX, lY) Dim lX4 Dim lY4 Dim lX8 Dim lY8 Dim lResult lX8 = lX And &H80000000 lY8 = lY And &H80000000 lX4 = lX And &H40000000 lY4 = lY And &H40000000 lResult = (lX And &H3FFFFFFF) + (lY And &H3FFFFFFF) If lX4 And lY4 Then lResult = lResult Xor &H80000000 Xor lX8 Xor lY8 ElseIf lX4 Or lY4 Then If lResult And &H40000000 Then lResult = lResult Xor &HC0000000 Xor lX8 Xor lY8 Else lResult = lResult Xor &H40000000 Xor lX8 Xor lY8 End If Else lResult = lResult Xor lX8 Xor lY8 End If AddUnsigned = lResult End Function Private Function md5_F(x, y, z) md5_F = (x And y) Or ((Not x) And z) End Function Private Function md5_G(x, y, z) md5_G = (x And z) Or (y And (Not z)) End Function Private Function md5_H(x, y, z) md5_H = (x Xor y Xor z) End Function Private Function md5_I(x, y, z) md5_I = (y Xor (x Or (Not z))) End Function Private Sub md5_FF(a, b, c, d, x, s, ac) a = AddUnsigned(a, AddUnsigned(AddUnsigned(md5_F(b, c, d), x), ac)) a = RotateLeft(a, s) a = AddUnsigned(a, b) End Sub Private Sub md5_GG(a, b, c, d, x, s, ac) a = AddUnsigned(a, AddUnsigned(AddUnsigned(md5_G(b, c, d), x), ac)) a = RotateLeft(a, s) a = AddUnsigned(a, b) End Sub Private Sub md5_HH(a, b, c, d, x, s, ac) a = AddUnsigned(a, AddUnsigned(AddUnsigned(md5_H(b, c, d), x), ac)) a = RotateLeft(a, s) a = AddUnsigned(a, b) End Sub Private Sub md5_II(a, b, c, d, x, s, ac) a = AddUnsigned(a, AddUnsigned(AddUnsigned(md5_I(b, c, d), x), ac)) a = RotateLeft(a, s) a = AddUnsigned(a, b) End Sub Private Function ConvertToWordArray(sMessage) Dim lMessageLength Dim lNumberOfWords Dim lWordArray() Dim lBytePosition Dim lByteCount Dim lWordCount Const MODULUS_BITS = 512 Const CONGRUENT_BITS = 448 lMessageLength = Len(sMessage) lNumberOfWords = (((lMessageLength + ((MODULUS_BITS - CONGRUENT_BITS) \ BITS_TO_A_BYTE)) \ (MODULUS_BITS \ BITS_TO_A_BYTE)) + 1) * (MODULUS_BITS \ BITS_TO_A_WORD) ReDim lWordArray(lNumberOfWords - 1) lBytePosition = 0 lByteCount = 0 Do Until lByteCount >= lMessageLength lWordCount = lByteCount \ BYTES_TO_A_WORD lBytePosition = (lByteCount Mod BYTES_TO_A_WORD) * BITS_TO_A_BYTE lWordArray(lWordCount) = lWordArray(lWordCount) Or LShift(Asc(Mid(sMessage, lByteCount + 1, 1)), lBytePosition) lByteCount = lByteCount + 1 Loop lWordCount = lByteCount \ BYTES_TO_A_WORD lBytePosition = (lByteCount Mod BYTES_TO_A_WORD) * BITS_TO_A_BYTE lWordArray(lWordCount) = lWordArray(lWordCount) Or LShift(&H80, lBytePosition) lWordArray(lNumberOfWords - 2) = LShift(lMessageLength, 3) lWordArray(lNumberOfWords - 1) = RShift(lMessageLength, 29) ConvertToWordArray = lWordArray End Function Private Function WordToHex(lValue) Dim lByte Dim lCount For lCount = 0 To 3 lByte = RShift(lValue, lCount * BITS_TO_A_BYTE) And m_lOnBits(BITS_TO_A_BYTE - 1) WordToHex = WordToHex & Right("0" & Hex(lByte), 2) Next End Function Public Function MD5(sMessage,stype) m_lOnBits(0) = CLng(1) m_lOnBits(1) = CLng(3) m_lOnBits(2) = CLng(7) m_lOnBits(3) = CLng(15) m_lOnBits(4) = CLng(31) m_lOnBits(5) = CLng(63) m_lOnBits(6) = CLng(127) m_lOnBits(7) = CLng(255) m_lOnBits(8) = CLng(511) m_lOnBits(9) = CLng(1023) m_lOnBits(10) = CLng(2047) m_lOnBits(11) = CLng(4095) m_lOnBits(12) = CLng(8191) m_lOnBits(13) = CLng(16383) m_lOnBits(14) = CLng(32767) m_lOnBits(15) = CLng(65535) m_lOnBits(16) = CLng(131071) m_lOnBits(17) = CLng(262143) m_lOnBits(18) = CLng(524287) m_lOnBits(19) = CLng(1048575) m_lOnBits(20) = CLng(2097151) m_lOnBits(21) = CLng(4194303) m_lOnBits(22) = CLng(8388607) m_lOnBits(23) = CLng(16777215) m_lOnBits(24) = CLng(33554431) m_lOnBits(25) = CLng(67108863) m_lOnBits(26) = CLng(134217727) m_lOnBits(27) = CLng(268435455) m_lOnBits(28) = CLng(536870911) m_lOnBits(29) = CLng(1073741823) m_lOnBits(30) = CLng(2147483647) m_l2Power(0) = CLng(1) m_l2Power(1) = CLng(2) m_l2Power(2) = CLng(4) m_l2Power(3) = CLng(8) m_l2Power(4) = CLng(16) m_l2Power(5) = CLng(32) m_l2Power(6) = CLng(64) m_l2Power(7) = CLng(128) m_l2Power(8) = CLng(256) m_l2Power(9) = CLng(512) m_l2Power(10) = CLng(1024) m_l2Power(11) = CLng(2048) m_l2Power(12) = CLng(4096) m_l2Power(13) = CLng(8192) m_l2Power(14) = CLng(16384) m_l2Power(15) = CLng(32768) m_l2Power(16) = CLng(65536) m_l2Power(17) = CLng(131072) m_l2Power(18) = CLng(262144) m_l2Power(19) = CLng(524288) m_l2Power(20) = CLng(1048576) m_l2Power(21) = CLng(2097152) m_l2Power(22) = CLng(4194304) m_l2Power(23) = CLng(8388608) m_l2Power(24) = CLng(16777216) m_l2Power(25) = CLng(33554432) m_l2Power(26) = CLng(67108864) m_l2Power(27) = CLng(134217728) m_l2Power(28) = CLng(268435456) m_l2Power(29) = CLng(536870912) m_l2Power(30) = CLng(1073741824) Dim x Dim k Dim AA Dim BB Dim CC Dim DD Dim a Dim b Dim c Dim d Const S11 = 7 Const S12 = 12 Const S13 = 17 Const S14 = 22 Const S21 = 5 Const S22 = 9 Const S23 = 14 Const S24 = 20 Const S31 = 4 Const S32 = 11 Const S33 = 16 Const S34 = 23 Const S41 = 6 Const S42 = 10 Const S43 = 15 Const S44 = 21 x = ConvertToWordArray(sMessage) a = &H67452301 b = &HEFCDAB89 c = &H98BADCFE d = &H10325476 For k = 0 To UBound(x) Step 16 AA = a BB = b CC = c DD = d md5_FF a, b, c, d, x(k + 0), S11, &HD76AA478 md5_FF d, a, b, c, x(k + 1), S12, &HE8C7B756 md5_FF c, d, a, b, x(k + 2), S13, &H242070DB md5_FF b, c, d, a, x(k + 3), S14, &HC1BDCEEE md5_FF a, b, c, d, x(k + 4), S11, &HF57C0FAF md5_FF d, a, b, c, x(k + 5), S12, &H4787C62A md5_FF c, d, a, b, x(k + 6), S13, &HA8304613 md5_FF b, c, d, a, x(k + 7), S14, &HFD469501 md5_FF a, b, c, d, x(k + 8), S11, &H698098D8 md5_FF d, a, b, c, x(k + 9), S12, &H8B44F7AF md5_FF c, d, a, b, x(k + 10), S13, &HFFFF5BB1 md5_FF b, c, d, a, x(k + 11), S14, &H895CD7BE md5_FF a, b, c, d, x(k + 12), S11, &H6B901122 md5_FF d, a, b, c, x(k + 13), S12, &HFD987193 md5_FF c, d, a, b, x(k + 14), S13, &HA679438E md5_FF b, c, d, a, x(k + 15), S14, &H49B40821 md5_GG a, b, c, d, x(k + 1), S21, &HF61E2562 md5_GG d, a, b, c, x(k + 6), S22, &HC040B340 md5_GG c, d, a, b, x(k + 11), S23, &H265E5A51 md5_GG b, c, d, a, x(k + 0), S24, &HE9B6C7AA md5_GG a, b, c, d, x(k + 5), S21, &HD62F105D md5_GG d, a, b, c, x(k + 10), S22, &H2441453 md5_GG c, d, a, b, x(k + 15), S23, &HD8A1E681 md5_GG b, c, d, a, x(k + 4), S24, &HE7D3FBC8 md5_GG a, b, c, d, x(k + 9), S21, &H21E1CDE6 md5_GG d, a, b, c, x(k + 14), S22, &HC33707D6 md5_GG c, d, a, b, x(k + 3), S23, &HF4D50D87 md5_GG b, c, d, a, x(k + 8), S24, &H455A14ED md5_GG a, b, c, d, x(k + 13), S21, &HA9E3E905 md5_GG d, a, b, c, x(k + 2), S22, &HFCEFA3F8 md5_GG c, d, a, b, x(k + 7), S23, &H676F02D9 md5_GG b, c, d, a, x(k + 12), S24, &H8D2A4C8A md5_HH a, b, c, d, x(k + 5), S31, &HFFFA3942 md5_HH d, a, b, c, x(k + 8), S32, &H8771F681 md5_HH c, d, a, b, x(k + 11), S33, &H6D9D6122 md5_HH b, c, d, a, x(k + 14), S34, &HFDE5380C md5_HH a, b, c, d, x(k + 1), S31, &HA4BEEA44 md5_HH d, a, b, c, x(k + 4), S32, &H4BDECFA9 md5_HH c, d, a, b, x(k + 7), S33, &HF6BB4B60 md5_HH b, c, d, a, x(k + 10), S34, &HBEBFBC70 md5_HH a, b, c, d, x(k + 13), S31, &H289B7EC6 md5_HH d, a, b, c, x(k + 0), S32, &HEAA127FA md5_HH c, d, a, b, x(k + 3), S33, &HD4EF3085 md5_HH b, c, d, a, x(k + 6), S34, &H4881D05 md5_HH a, b, c, d, x(k + 9), S31, &HD9D4D039 md5_HH d, a, b, c, x(k + 12), S32, &HE6DB99E5 md5_HH c, d, a, b, x(k + 15), S33, &H1FA27CF8 md5_HH b, c, d, a, x(k + 2), S34, &HC4AC5665 md5_II a, b, c, d, x(k + 0), S41, &HF4292244 md5_II d, a, b, c, x(k + 7), S42, &H432AFF97 md5_II c, d, a, b, x(k + 14), S43, &HAB9423A7 md5_II b, c, d, a, x(k + 5), S44, &HFC93A039 md5_II a, b, c, d, x(k + 12), S41, &H655B59C3 md5_II d, a, b, c, x(k + 3), S42, &H8F0CCC92 md5_II c, d, a, b, x(k + 10), S43, &HFFEFF47D md5_II b, c, d, a, x(k + 1), S44, &H85845DD1 md5_II a, b, c, d, x(k + 8), S41, &H6FA87E4F md5_II d, a, b, c, x(k + 15), S42, &HFE2CE6E0 md5_II c, d, a, b, x(k + 6), S43, &HA3014314 md5_II b, c, d, a, x(k + 13), S44, &H4E0811A1 md5_II a, b, c, d, x(k + 4), S41, &HF7537E82 md5_II d, a, b, c, x(k + 11), S42, &HBD3AF235 md5_II c, d, a, b, x(k + 2), S43, &H2AD7D2BB md5_II b, c, d, a, x(k + 9), S44, &HEB86D391 a = AddUnsigned(a, AA) b = AddUnsigned(b, BB) c = AddUnsigned(c, CC) d = AddUnsigned(d, DD) Next if stype=32 then MD5 = LCase(WordToHex(a) & WordToHex(b) & WordToHex(c) & WordToHex(d)) else MD5=LCase(WordToHex(b) & WordToHex(c)) end if End Function %> <% Response.Buffer = True Dim Startime Dim SqlNowString,Dvbbs,template,MyBoardOnline Dim connbbs,Plus_Conn,Db,MyDbPath Const fversion="7.1.0 Sp1" Const EnabledSession= True Startime = Timer() '系统采用XML版本设置 '最高版本为.4.0 依次为: Const MsxmlVersion=".3.0" Const MsxmlVersion=".2.6" 最低版本Const MsxmlVersion="" Const MsxmlVersion=".3.0" '可修改设置一:========================定义数据库类别,1为SQL数据库,0为Access数据库============================= Const IsSqlDataBase1 = 1 MyDbPath = "" '================================================================================================================ If IsSqlDataBase1 = 1 Then '必修改设置二:========================SQL数据库设置============================================================= 'sql数据库连接参数:数据库名(SqlDatabaseName1)、用户密码(SqlPassword1)、用户名(SqlUsername1)、 '连接名(SqlLocalName1)(本地用local,外地用IP) Const SqlDatabaseName1 = "OperaBbs" Const SqlPassword1 = "szqj" Const SqlUsername1 = "szqj" Const SqlLocalName1="(local)" '================================================================================================================ SqlNowString = "GetDate()" Else '必修改设置三:========================Access数据库设置========================================================== '免费用户第一次使用请修改本处数据库地址并相应修改data目录中数据库名称,如:将dvbbs6.mdb修改为dvbbs6.asp Db = "data/dvbbs7.mdb" '================================================================================================================ SqlNowString = "Now()" End If Dim ConnStr If IsSqlDataBase1 = 1 Then ConnStr = "Provider = Sqloledb; User ID = " & SqlUsername1 & "; Password = " & SqlPassword1 & "; Initial Catalog = " & SqlDatabaseName1 & "; Data Source =.;" Else ConnStr = "Provider = Microsoft.Jet.OLEDB.4.0;Data Source = " & Server.MapPath(MyDbPath & db) End If On Error Resume Next Set connbbs = Server.CreateObject("ADODB.Connection") connbbs.open ConnStr If Err Then err.Clear Set connbbs = Nothing Response.Write "数据库连接出错,请检查连接字串1。"'注释,需要把这几个字翻译成英文。 Response.End End If %> <% Response.Buffer = true %> <% Const is_sqldata=1 '是否使用其他系统的数据库用户表,1为使用,0为不使用 Const is_ot_user=0 Dim connstr1,connblog,db1,dchr,delchr Dim ot_connstr,ot_conn,ot_usertable,ot_username,ot_password,ot_regurl,ot_lostpasswordurl,ot_modIfypass1,ot_modIfypass2 Dim userDB If is_sqldata=0 Then 'access数据库连接参数 '此处必须为以根目录开始 db = "/oblog31/data/oblog31.mdb" connstr = "Provider = Microsoft.Jet.OLEDB.4.0;Data Source = " & Server.MapPath(db1) dchr="#" delchr=" * " Else 'sql数据库连接参数:数据库名、用户密码、用户名、连接名(本地用local,外地用IP) Dim sql_databasename,sql_password,sql_username,sql_localname sql_localname = "(local)" sql_databasename = "OperaBlog" sql_username = "szqj" sql_password = "szqj" connstr1 = "Provider = Sqloledb; User ID = " & sql_username & "; Password = " & sql_password & "; Initial Catalog = " & sql_databasename & "; Data Source = " & sql_localname & ";" dchr="'" delchr=" " End If On Error Resume Next Set connblog = Server.CreateObject("ADODB.Connection") connblog.open connstr1 %> <% '初始化: userip = request.ServerVariables("HTTP_X_FORWARDED_FOR") If userip = "" Then userip = request.ServerVariables("REMOTE_ADDR") comeurl = Trim(request.ServerVariables("HTTP_REFERER")) autoupdate = True '更新整站首页开关 is_password_cookies = 1 '是否编码cookies,1为开启,0为关闭 is_gb2312 = 1 '系统平台,1为简体中文平台,0为其他平台 blogdir ="../blog/" f_ext="htm" cookies_name="blog" Sub SaveCookie(username, password, CookieDate, userurl) ' response.Write("156: "&cookies_name) If cookies_domain <> "" Then response.Cookies(cookies_name).domain = cookies_domain End If 'response.End() response.Cookies(cookies_name)("username") = CodeCookie(username) response.Cookies(cookies_name)("password") = CodeCookie(password) If userurl = "" Or userurl = "." Then userurl = " " response.Cookies(cookies_name)("userurl") = CodeCookie(userurl) 'response.Write("haha"&request.Cookies(cookies_name)("password")) ' response.End() Select Case CookieDate Case 0 'not save Case 1 response.Cookies(cookies_name).Expires = Date + 1 Case 2 response.Cookies(cookies_name).Expires = Date + 31 Case 3 response.Cookies(cookies_name).Expires = Date + 365 End Select 'response.Write("dsf") '' response.End() End Sub Function CodeCookie(Str) If is_password_cookies = 1 Then Dim i Dim StrRtn For i = Len(Str) To 1 Step -1 StrRtn = StrRtn & AscW(Mid(Str, i, 1)) If (i <> 1) Then StrRtn = StrRtn & "a" Next CodeCookie = StrRtn Else CodeCookie = Str End If End Function %>
神州戏曲网 广告
梨园资讯 票友天地 视听在线 演艺经纪 梨园漫话 戏曲人物 梨园超市 戏迷擂台 百家戏坛
热点
相关



节目预告  

·中央电视台戏曲频道本周三节目预
·中央电视台戏曲频道本周四节目预
·中央电视台戏曲频道本周五节目预
·中央电视台戏曲频道本周六节目预
·中央电视台戏曲频道本周日节目预
·中央电视台戏曲频道本周一节目预
·中央电视台戏曲频道本周二节目预
·中央电视台戏曲频道本周三节目预
·中央电视台戏曲频道本周四节目预
·中央电视台戏曲频道本周节五目预
·中央电视台戏曲频道本周六节目预
·中央电视台戏曲频道本周日节目预
·2007年11月25日节目预告 
·2007年11月26日节目预告 
·中央电视台戏曲频道本周一节目预
·中央电视台戏曲频道本周二节目预
·中央电视台戏曲频道本周三节目预
·中央电视台戏曲频道本周三节目预
·中央电视台戏曲频道本周三节目预
·中央电视台戏曲频道本周四节目预
·中央电视台戏曲频道本周五节目预
·中央电视台戏曲频道本周六节目预
·中央电视台戏曲频道本周日节目预
·中央电视台戏曲频道11月14日节目
·中央电视台戏曲频道11月13日节目

共7页  1 2 3 4 5 6 7

首 页梨园资讯票友天地视听在线演绎经纪梨园漫话戏曲人物梨园超市戏迷擂台百家戏谈广告服务
Copyright®2001-2006 神州戏曲网版权所有 豫ICP证:豫ICP备05009320号
E-mail:sz_audio@163.com 传真:0371-66216490 客服电话:0371-65368216
销售电话:0371-66760619 违法不良信息举报中心
神州全景客服点击这里给我发消息