请问下这个怎么绕过登陆进行sql注入。
应该如何构造sql语句呀 ?
大神教教,感激不尽
[HTML] 纯文本查看 复制代码 <!--#include file="conn.asp"-->
<%
dim user,pass
username=request.form("username")
pass=request.form("password")
session.Timeout=60
'判断用户名和密码是否正确
set rs=server.createobject("ADODB.Recordset")
sql="select * from admin where username='"&username&"'"
rs.open sql,conn,1,3
if rs.eof then
Response.Write "<script language='javascript'>alert('\用户名输入有误!');</script>"
Response.Write "<script language='javascript'>history.go(-1);</script>"
Response.End()
else
if rs("username")=username and rs("password")=pass then
session("pass")=trim(rs("password"))
response.redirect "order.asp"
Response.End()
else
Response.Write "<script language='javascript'>alert('\密码输入有误!');</script>"
Response.Write "<script language='javascript'>history.go(-1);</script>"
Response.End()
end if
end if
%> |