Sql注入校验


///


/// Sql注入校验
///

/// 字符
/// 是否成功
public static bool CheckSqlInjuect(List listWord)
{
//过滤关键字
string StrKeyWord = @"select|insert|delete|from|count\(|drop table|update|truncate|asc\(|mid\(|char\(|xp_cmdshell|exec master|netlocalgroup administrators|:|net user|""|or|and";
//过滤关键字符
string StrRegex = @"[-|;|,|/|\(|\)|\[|\]|}|{|%|\@|*|!|']";

foreach (var item in listWord)
{
if (Regex.IsMatch(item, StrKeyWord, RegexOptions.IgnoreCase) || Regex.IsMatch(item, StrRegex))
return false;
}

return true;
}

转载于:https://www.cnblogs.com/zhangzhixiong/p/11527786.html

你可能感兴趣的:(Sql注入校验)