在asp.net 的应用中,一定要判断用户在客户端的输入是否合法的,要避免各类的脚本攻击,SQL注入攻击等,在微软方面,提供了几篇好的文章来参考 How To-Protect from Injection Attacks in ASPNET How To-Use Regular Expressions to Constrain Input in ASP.NET How To-Protect from SQL Injection in ASP.NET How To-Prevent Cross-Site Scripting in ASP.NET 相关文章: