using System; using System.Collections.Generic; using System.Linq; using System.Text; namespace FangYar.Common { /// /// 简单的SQL防注入类 /// public class SqlInjection { /// /// 关键字过滤 /// /// 原始串 /// 返回True就是找到了可能sql注入的关键字 public static bool GetString(string originalString) { //参考:technet.microsoft.com/zh-cn/library/ms161953.aspx if (originalString.IndexOf(";") != -1 || originalString.IndexOf("'") != -1 || originalString.IndexOf("--") != -1 || originalString.IndexOf("/*") != -1 || originalString.IndexOf("*/") != -1 || originalString.IndexOf("xp_cmdshell") != -1) return true; else return false; } } }