注入SQL
<%Dim StrServer,StrUid,StrSaPwd,StrDbName
StrServer="192.168.1.2" '数据库服务器名
StrUid="sa" '您的登录帐号
StrSaPwd="8866333" '您的登录密码
StrDbName="dzjt" '您的数据库名称
Dim Conn '数据库连接
Dim StrDSN '数据库连接字符串
Dim Rs '命令字符串
StrDSN="driver={SQL server};server="&StrServer&";uid="&StrUid&";pwd="&StrSaPwd&";database="&StrDbName
'建立和数据库master的连接
set Conn = Server.CreateObject("ADODB.Connection")
set Rs=Server.CreateObject("ADODB.RecordSet")
Conn.Open StrDSN
%>
+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
<!--#include file="adoconn.asp"-->
<!--#include file="md5.asp"-->
<%
username=request.Form("username")
password=request.Form("password")
crypt_password=md5(password)
SQL="Select Max(F_ID) From T_usercore"
set rs1=conn.Execute(SQL)
tmp=rs1(0)
sql="select * from T_usercore where F_username='"&username&"'"
rs.open sql,conn,1,1
If Not rs.eof Then
response.write "no"
response.end
End If
rs.close
sql="insert into T_usercore(F_id,F_username,F_type,F_Seconds,F_active,F_stoptime,F_password,F_Coints) values('" & (tmp+1) & "','"&username&"',0,720000,1,'"&Now()&"','"&crypt_password&"',0)"
rs.open sql,conn,1,3
response.write "yes"
%>
+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
<!--#include file="adoconn.asp"-->
<%
username=Replace(request.querystring("username"),"'","")
sql="select * from T_usercore where F_username='"&username&"'"
rs.open sql,conn,1,1
if rs.eof then
response.write "no"
else
response.write "yes"
end if
rs.close
%>
+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
哪位高手看下这个怎么注入