Java中Mysql防止注入攻击

String sql = "select * from users u where u.id = ? and u.password = ?";

preparedstatement ps = connection.preparestatement(sql);
ps.setint(1,id);
ps.setstring(2,pwd);
resultset rs = ps.executequery();
 
正则表达式过滤:
 
同时过滤它们的十六进制:





posted @ 2014-03-05 15:04  有根竹子  阅读(765)  评论(0编辑  收藏  举报