using System;
using System.Collections.Generic;
using System.Linq;
using System.Text;
namespace FangYar.Common
{
///
/// 简单的SQL防注入类
///
public class SqlInjection
{
///
/// 关键字过滤
///
/// 原始串
/// 返回True就是找到了可能sql注入的关键字
public static bool GetString(string originalString)
{
//参考:technet.microsoft.com/zh-cn/library/ms161953.aspx
if (originalString.IndexOf(";") != -1 || originalString.IndexOf("'") != -1 || originalString.IndexOf("--") != -1 || originalString.IndexOf("/*") != -1 || originalString.IndexOf("*/") != -1 || originalString.IndexOf("xp_cmdshell") != -1)
return true;
else
return false;
}
}
}