%
On Error Resume Next
connstr="driver={SQL Server};server=(local);database=wawa8;uid=wawa8;pwd=rewrr;"
set conn=server.createobject("ADODB.CONNECTION")
conn.open connstr
%>
<%
Function Filter_SQL(strData)
strFilter="',;,/,--,@,_,exec,declare,create,(,),=,>,<,'"
blnFlag=Flase
Dim arrayFilter
arrayFilter=Split(strFilter,",")
For i=0 To UBound(arrayFilter)
If Instr(lcase(strData),arrayFilter(i))>0 Then
blnFlag=True
Exit For
End If
Next
If blnFlag Then
response.write ""
Else
Filter_SQL=strData
End If
End Function
%>