 | | From: | 后来者 | | Subject: | 如何防止ASP通过ADSI操作或查看系统信息? | | Date: | Mon, 10 Jan 2005 16:38:05 +0800 |
|
|
 | 比如,如下代码是显示系统有哪些进程的?如何防止呢?我访问ASP的用户是iusr_机器 名!
class="table2" ID="Table4"> 8 进程 :::... | <% on error resume next set domainObject = GetObject("WinNT://.") for each obj in domainObject if lcase(mid(obj.path,4,3))="win" then Response.write("| class=""td2""> "&obj.Name&" | class=""td3""> "&obj.DisplayName &" | "&"| class=""td3""> | "&obj.path&" | ") else Response.write("| class=""td2""> "&obj.Name&" | class=""td3""> "&obj.DisplayName &" | "&"| class=""td3""> | "&obj.path& " | ") end if next %>
|
|
 | | From: | =?Utf-8?B?Y29rYWJ1Zw==?= | | Subject: | =?Utf-8?B?UkU6IOWmguS9lemYsuatokFTUOmAmui/h0FEU0nmk43kvZzmiJbmn6U=?= | | Date: | Wed, 12 Jan 2005 19:39:07 -0800 |
|
|
 | 璇曡瘯灏唀veryone瀵筗MI涓璑amespace鐨勮鍙栨潈鍙栨秷
"鍚庢潵鑰" wrote:
> 姣斿锛屽涓嬩唬鐮佹槸鏄剧ず绯荤粺鏈夊摢浜涜繘绋嬬殑锛熷浣曢槻姝㈠憿锛熸垜璁块棶ASP鐨勭敤鎴锋槸iusr_鏈哄櫒 > 鍚嶏紒 > > > > class="table2" ID="Table4"> > 8 > 杩涚▼ :::... | > <% > on error resume next > set domainObject = GetObject("WinNT://.") > for each obj in domainObject > if lcase(mid(obj.path,4,3))="win" then > Response.write("| > class=""td2""> "&obj.Name&" | > class=""td3""> "&obj.DisplayName &" | "&"| > class=""td3""> | "&obj.path&" | ") > else > Response.write("| > class=""td2""> "&obj.Name&" | > class=""td3""> "&obj.DisplayName &" | "&"| > class=""td3""> | "&obj.path& > " | ") > end if > next > %> > > > >
|
|