2010年3月26日 星期五
URL 排程小工具(maxGet v1.0)
2010年3月19日 星期五
[Asp].資料複制的副程式
2010年2月25日 星期四
IIS 7 允許檔案名稱有+ 號
IIS7 rejecting URLs containing + .
Here is the deal. The IIS7 request filter rejects URLs containing + characters. We do this because the + character is a dangerous choice. Some standards, e.g. the CGI standard require +'s to be converted into spaces. This can become a problem if you have code that implements name-based rules, for example urlauthorization rules that base their decisions on some part of the url.
Here is a cooked up example:
Let's suppose you have code that evaluates the following rule:
With the ambiguity of leaving +'s in place or converting +'s to spaces there is a possiblity that your rule engine allows access to a non-Admin, for example if the attacker enters http://myserver/my+vdir. The "my vdir" authorization rule won't match because your authorization code searches for the string "my+vdir" but your rule says "my vdir". Your rule won't apply and the attacker gets access.
If you absolutely want to have spaces you can simply turn off the doubleEscaping feature for your application, for your site or for the whole server. Here is an example:
%windir%\system32\inetsrv\appcmd set config "Default Web Site" -section:system.webServer/security/requestfiltering -allowDoubleEscaping:true
2010年2月24日 星期三
IIS 7掛載網芳的虛擬目錄
2010年2月11日 星期四
[SQL].列資料轉成欄資料

2010年2月10日 星期三
2010年2月5日 星期五
[Asp].IIS7 上傳檔案大小限制

附註:其實 200k 就夠用了說, 如果是分次從 user 的 client 端瀏覽器一次讀取200k 的做的話, 例如程式碼:
dim myTotalBytes
dim myReadBuffer
dim myReadLimit
myReadBuffer = 200000 '// 200KB
myTotalBytes = Request.TotalBytes
if myTotalBytes > 0 then
do
if myTotalBytes <= myReadBuffer then
'// read one time.
BinaryStream.write Request.BinaryRead(myTotalBytes)
myTotalBytes = 0
else
'// read many time.
BinaryStream.write Request.BinaryRead(myReadBuffer)
myTotalBytes = myTotalBytes - myReadBuffer
end if
if myTotalBytes < 1 then
exit do
end if
loop
end if











