天天看點

防sql注入簡單通用方法

/**
 * 處理字元轉義
 *
 * @param value
 * @return
 */
private String valueClear(String value) {
    if (value == null || "".equals(value)) {
        return value;
    }
    String result = value.toLowerCase()
            .replaceAll("(^|\\&)|(\\|)|(\\;)|(\\$)|(\\%)|(\\@)|(\\')|(\\\")|(\\>)|(\\<)|(\\))|(\\()|(\\+)|(\\,)|(\\\\)|(\\#|$)|(\\*)|(\\?)|(\\!)|(\\_)|(\\=)|(\\^)|(\\~)","")
            .replaceAll("and", "")
            .replaceAll("exec", "")
            .replaceAll("insert", "")
            .replaceAll("select", "")
            .replaceAll("delete", "")
            .replaceAll("update", "")
            .replaceAll("count", "")
            .replaceAll("chr", "")
            .replaceAll("mid", "")
            .replaceAll("master", "")
            .replaceAll("truncate", "")
            .replaceAll("char", "")
            .replaceAll("declare", "")
            .replaceAll("or", "")
            .replaceAll("mid", "")
            .replaceAll("set", "")
            .replaceAll("from", "");
    return result;
}