过滤非法字符

using System;
using System.ComponentModel;
using System.Collections;
using System.Diagnostics;
using System.Data;
using System.Data.SqlClient;
using System.Configuration;

namespace Components.GlobalFun
{
    public class badword
    {

        static public bool checkBadword(SqlParameter[] prams)
        {
            if (prams == null)
            {
                return true;
            }
            string strWord = "";
            for (int i = 0; i < prams.Length; i++)
            {
                object result = prams[i].Value;

                if (result == null)
                {
                    break;
                }
                if (prams[i].ToString() == "@sqlTmp")
                {
                    return true;
                }
                strWord = result.ToString();
                if (strWord.Contains("select") || strWord.Contains("update") || strWord.Contains("insert") || strWord.Contains("delete") || strWord.Contains("declare") || strWord.Contains("exec") || strWord.Contains("set"))
               {
                   return false;
               }
            }
            return true;
        }
        static public bool checkBadword(string strWord)
        {

            if (strWord.Contains("@") || strWord.Contains("=") || strWord.Contains("'") || strWord.Contains("select") || strWord.Contains("update") || strWord.Contains("insert") || strWord.Contains("delete") || strWord.Contains("declare") || strWord.Contains("exec") || strWord.Contains("set"))
            {
                return false;
            }
           
            return true;
        }
        static public string ChangeStr(string oldstr)
        {
            if (oldstr != null)
            {
                string NewStr = oldstr.Replace('/'', '‘');
                NewStr = NewStr.Replace(';', ';');
                return NewStr;
            }
            else
            {
                return null;
            }
        }
        static public string RequestChstr(string request_str)
        {
            bool IsValue = true;
            string strSQLin = "'|and|--|exec|insert|select|delete|update|count|*|%|chr|mid|master|truncate|char|declare|;|&|%20|==|>|<";
            string[] strSQLinGroup = strSQLin.Split(new char[] { '|' }, 23);//23个关键字,有待补充
            for (int i = 0; i < strSQLinGroup.Length; i++)
            {
                if (request_str.ToLower().IndexOf(strSQLinGroup[i]) != -1)
                {
                    IsValue = false;
                    break;
                }
            }
            if (IsValue)
            {
                return request_str;
            }
            return "";
        }
    }


}

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值