邪恶八进制信息安全团队技术讨论组's Archiver

ring04h 2006-5-27 00:13

[转载]去除指定表中数据类型是VARCHAR,CHAR,NVARCHAR的字段值中的不可见字符

<p>信息来源: softj's Blog </p><p>--作用:去除指定表中数据类型是VARCHAR,CHAR,NVARCHAR的字段值中的不可见字符<br />--注意:此处只去掉前后的不可见字符,不包括中间的字符,而且没有区分中文<br />--有兴趣的可以自己加个判别的中文,其实也很简单的,就是限定一个字符的范围就可以了<br />--日期:2004-11-04<br />--作者:ICERIVER<br />--注意:使用前请指定对应要修改的表名,并且需要在对应数据库下执行;<br />SET NOCOUNT ON</p><p></p><p>DECLARE @TblName VARCHAR(100)<br />DECLARE @UpdateString NVARCHAR(1000)<br />DECLARE @SelectString NVARCHAR(1000)<br />DECLARE @COlName VARCHAR(100)<br />DECLARE @COUNT INT</p><p></p><p>SET @TblName = 'YOURTABLENAME'--指定想要修改的表名</p><p></p><p>--定义游标取出指定表内的数据类型是VARCHAR,char,nVARCHAR的字段名称<br />DECLARE cur_ColName CURSOR<br />FOR<br />SELECT col.name<br />FROM syscolumns AS col<br />inner join sysobjects AS obj ON col.ID = obj.ID<br />INNER join systypes AS typ ON col.xtype = typ.xtype<br />WHERE obj.xtype ='U'<br />AND obj.name = @TblName<br />AND typ.name IN ('VARCHAR','CHAR','NVARCHAR','NCHAR')<br />FOR READ ONLY<br />--打开游标<br />OPEN cur_ColName</p><p></p><p>FETCH NEXT FROM cur_ColName INTO @ColName<br />IF @@FETCH_STATUS<>0 <br />BEGIN<br />PRINT '没有对应表或字段,'<br />PRINT '请确认当前数据库内有' + @TblName + '表,'<br />PRINT '或该表内有VARCHAR、CHAR、NVARCHAR、NCHAR类型的字段!'<br />GOTO LABCLOSE<br />END<br />--循环修改<br />WHILE @@FETCH_STATUS=0<br />BEGIN <br />--拼修改字符串<br />--去掉左边的不可见字符<br />SET @SelectString = 'SELECT @COU=COUNT(*) <br /> FROM ' + @TblName +'<br /> WHERE ASCII(LEFT(' + @ColName +',1))<32<br /> AND '+ @ColName + ' IS NOT NULL'<br /><br />EXEC sp_executesql @SelectString,N'@COU INT OUTPUT',@COUNT OUTPUT</p><p></p><p>WHILE @COUNT>0 <br />BEGIN<br /> SET @UpdateString = <br /> ' UPDATE ' + @TblName +<br /> ' SET ' + @ColName + '=RIGHT(' + @ColName + ',LEN(' + @ColName + ')-1)<br /> WHERE ASCII(LEFT(' + @ColName + ',1))<32<br /> AND ' + @ColName + ' IS NOT NULL'<br /><br /> EXEC sp_executesql @UpdateString <br /> EXEC sp_executesql @SelectString,N'@COU INT OUTPUT',@COUNT OUTPUT<br />END</p><p></p><p>--去掉右边的不可见字符<br />SET @SelectString = 'SELECT @COU=COUNT(*) <br /> FROM ' + @TblName +'<br /> WHERE ASCII(RIGHT(' + @ColName +',1))<32<br /> AND '+ @ColName + ' IS NOT NULL'<br /><br />EXEC sp_executesql @SelectString,N'@COU INT OUTPUT',@COUNT OUTPUT</p><p></p><p>WHILE @COUNT>0 <br />BEGIN<br /> SET @UpdateString = <br /> ' UPDATE ' + @TblName +<br /> ' SET ' + @ColName + '=LEFT(' + @ColName + ',LEN(' + @ColName + ')-1)<br /> WHERE ASCII(RIGHT(' + @ColName + ',1))<32<br /> AND ' + @ColName + ' IS NOT NULL'<br /><br /> EXEC SP_EXECUTESQL @UpdateString <br /> EXEC sp_executesql @SelectString,N'@COU INT OUTPUT',@COUNT OUTPUT<br />END</p><p></p><p>PRINT 'column: ' + @ColName + '---ok'<br />FETCH NEXT FROM cur_ColName INTO @ColName<br />END<br />--关闭、释放游标<br />LABCLOSE: CLOSE cur_ColName<br /> DEALLOCATE cur_ColName</p>

页: [1]
© 1999-2008 EvilOctal Security Team