sql="select count(*) from u_user_list where user_id='"+user_id+"'and user_password='"+userpassword+"'";
rs=UserBean.executeQuery(sql);
if(rs.next())
num=rs.getInt(1);
UserBean.close();
/////////////////////防范sql注射攻击????????任//////////////////////
int pos1=user_id.indexOf("'",0);
int pos2=user_id.indexOf("'",0);
if(num>10||pos1>=0||pos2>=0)
{
%>
<script>
alert("你输入了恶意字符,存在恶意入侵嫌疑,已经记录下你的IP!");
</script>
<%
user_id="";
userpassword="";
}
/////////////////////防范sql注射攻击????????任//////////////////////