Ò׽ؽØͼÈí¼þ¡¢µ¥Îļþ¡¢Ãâ°²×°¡¢´¿ÂÌÉ«¡¢½ö160KB

SQL×¢Èë¼òµ¥Ô­Àí·ÖÎö

 SQL×¢Èë¼òµ¥·ÖÎö
ʾÀýÓï¾ä£º
select * from admintable where adminName like '%a%'
ÔÚ²éѯÖÐÎÒÃÇÒ»°ãÔÚaÕâ¸öµØ·½ÓɽçÃæ´«È벻ͬµÄÖµ£¬µ±ÎÒÃÇÔÚaÕâÀï´«ÈëµÄֵΪ“'”µ¥ÒýºÅʱ£¬Æ´´Õ³ÉµÄSQLÓï¾ä¾ÍÈçÏ£º
select * from admintable where adminName like '%'%'
Ö´ÐÐÕâ¾äÓï¾äÎÒÃǻᷢÏÖ³öÏÖÒÔÏÂÒì³££º
ÏûÏ¢ 105£¬¼¶±ð 15£¬×´Ì¬ 1£¬µÚ 1 ÐÐ
×Ö·û´® '
' ºóµÄÒýºÅ²»ÍêÕû¡£
ÏûÏ¢ 102£¬¼¶±ð 15£¬×´Ì¬ 1£¬µÚ 1 ÐÐ
'
' ¸½½üÓÐÓï·¨´íÎó¡£
ÒòΪµ¥ÒýºÅµÄ¼ÓÈëÊÇÔ­±¾ÍêÕûµÄSQLÓï¾äÆ´´Õ²»ÔÙÍêÕû£¬Òò´Ëµ¼ÖÂÒÔÉÏÒì³£¡£
¶øÒ»°ãºÚ¿ÍÔÚ¼òµ¥µÄ³¢ÊÔ×¢Èëʱ£¬ÔÚ½çÃæµÄÊäÈë´¦£¨ÈçURLµÄ²ÎÊý£¬Îı¾¿òµÄÊäÈëµÈ£©Ö±½ÓÊäÈëµ¥ÒýºÅÀ´²âÊÔÊÇ·ñ»áÒý·¢SQLÒì³££¬¸ù¾ÝÒ³ÃæµÄ´íÎó´úÂëÕ¹ÏÖÀ´ÅжÏÊÇ·ñ´æÔÚSQL×¢È멶´£¬ÀýÈç»áÖ±½ÓÔÚÒ³ÃæÖгöÏÖSQLµÄÒì³£´úÂë»òÖ±½ÓÌøתµ½´íÎóÒ³Ãæ¡£µ±±»ÈÏΪ´æÔÚSQL×¢È멶´Ê±£¬ÄÇô½«²»ÔÙÊÇÊäÈëµ¥ÒýºÅÁË£¬¶øÊÇÊäÈëÏà¹ØµÄSQLÖ´ÐÐÓï¾ä¡£
ÓÚÊǵ±ÎÒÃÇ´«È벻ͬµÄÖµÀýÈç
  ' or 1=1 ;delete admintable where 1=1 or ''=' 
µÃµ½µÄSQLÓï¾ä¾ÍÈçÏ£º
select * from admintable where adminName like '%' or 1=1 ;delete admintable where 1=1 or ''='%'
¶øÕâ¾äSQLµÄÖ´ÐÐЧ¹û¾ÍÓÐÁ½¸ö£º
1¡¢select * from admintable where adminName like '%' or 1=1 ;
     --²éѯadmintable
2¡¢delete admintable where 1=1 or ''='%'
     --½«admintableÇå¿Õ
Ò²¾ÍÊÇ˵Èç¹û°Ñdelete admintable where 1=1 Õâ¾äSQLÀ©Õ¹Ð޸ĵĻ°£¬¿ÉÒÔÖ´ÐÐÔöɾ¸ÄµÈ²Ù×÷ÁË£¬ÀýÈçSQL2000ÖеÄXP_CMDShellÃüÁÄÜÖ±½ÓÖ´ÐÐCMDÃüÁį̂µÄCMDÃüÁÀ´ÊµÏÖÖ±½Ó¶Ô·þÎñÆ÷µÄ¿ØÖƵȡ£
ÖÁÓÚÈçºÎ±©Â¶³öÊý¾Ý¿âµÄ¸÷¸ö±íµÄÃû×ֵȣ¬¿ÉÒÔͨ¹ýö¾Ù²Â²âµÈ·½Ê½ÊµÏÖ£¬ÍøÂçÉÏÒѾ­ÓÐÏà¹ØµÄSQL×¢È빤¾ß¿É¹©Ö±½ÓʹÓá£
µ±ÎÒÃǵÄÍøÕ¾´æÔÚSQL×¢È멶´Ê±£¬×îºÃÐÞ¸ÄÏà¹ØµÄµ×²ã´úÂë»òÕßʹÓÃÏà¹ØµÄ¼à¿Ø¹¤¾ßÀ´ÐÞ¸´¡£Ò»¸öÍøÕ¾±»ÈëÇÖ²¢²»ÊÇºÚ¿ÍµÄ´í£¬¶øÊÇ·þÎñÆ÷¹ÜÀíÔ±ºÍÍøÕ¾¿ª·¢ÈËÔ±ÈÇϵĻö¡£
ÈçÓдíÎ󣬾´ÇëÖ¸Õý¡£


Ïà¹ØÎĵµ£º

SQLÓÅ»¯½éÉÜÒ»

Ò»¡¢Ñ¡Ôñ×îÓÐЧÂʵıíÃû˳Ðò(Ö»ÔÚ»ùÓÚ¹æÔòµÄÓÅ»¯Æ÷ÖÐÓÐЧ)
 
ORACLEµÄ½âÎöÆ÷°´ÕÕ´ÓÓÒµ½×óµÄ˳Ðò´¦Àífrom×Ó¾äÖеıíÃû,Òò´Ëfrom×Ó¾äÖÐдÔÚ×îºóµÄ±í(»ù´¡±í driving table)½«±»×îÏÈ´¦Àí. ÔÚfrom×Ó¾äÖаüº¬¶à¸ö±íµÄÇé¿öÏÂ,Äã±ØÐëÑ¡Ôñ¼Ç¼ÌõÊý×îÉٵıí×÷Ϊ»ù´¡±í.µ±ORACLE´¦Àí¶à¸ö±íʱ, »áÔËÓÃÅÅÐò¼°ºÏ²¢µÄ·½Ê½Á¬½ÓËüÃÇ ......

£¨×îгɹ¦£©Ãâ°²×°OracleÔËÐÐpl/sql developer

1.µ½http://www.oracle.com/technology/global/cn/software/tech/oci/instantclient/htdocs/winsoft.htmlÏÂÔØ
11.1.0.7.0 °æµÄ¼´Ê±¿Í»§¶Ë³ÌÐò°ü — Basic£¨²»ÊÇBasic Lite£©
2.½«ÏÂÔص½µÄÎļþ½âѹ£¬½âѹºóÎÒ½«Ä¿Â¼instantclient_11_1ÀïµÄÈ«²¿Îļþ¿½±´µ½ÁËÒ»¸öеÄĿ¼£ºE:\programs\OracleClient¡£ÄãÒ²¿ÉÒÔ²»¿½±´£¬Ö ......

sql server ÖÐÁÙʱ±íÓë±í±äÁ¿µÄÇø±ð

 
ÎÒÃÇÔÚÊý¾Ý¿âÖÐʹÓñíµÄʱºò,¾­³£»áÓöµ½Á½ÖÖʹÓñíµÄ·½·¨,·Ö±ð¾ÍÊÇʹÓÃÁÙʱ±í¼°±í±äÁ¿¡£ÔÚʵ¼ÊʹÓõÄʱºò£¬ÎÒÃÇÈçºÎÁé»îµÄÔÚ´æ´¢¹ý³ÌÖÐÔËÓÃËüÃÇ£¬ËäÈ»ËüÃÇʵÏֵŦÄÜ»ù±¾ÉÏÊÇÒ»ÑùµÄ£¬¿ÉÈçºÎÔÚÒ»¸ö´æ´¢¹ý³ÌÖÐÓÐʱºòȥʹÓÃÁÙʱ±í¶ø²»Ê¹Óñí±äÁ¿£¬ÓÐʱºòȥʹÓñí±äÁ¿¶ø²»Ê¹ÓÃÁÙʱ±íÄØ?
¡¡¡¡ÁÙʱ±í
¡¡¡¡ÁÙʱ±íÓëÓÀ¾Ã± ......

ÈçºÎÓÃSQLÓï¾äÔÚÁ½¸öÊý¾Ý¿â¼ä¸´ÖÆ´æ´¢¹ý³Ì

 --1.ÔÚÄ¿±ê·þÎñÆ÷ÉϽ¨Á¢Èç϶ÔÏó(±»Í¬²½µÄ·þÎñÆ÷)  
   
  if   exists   (select   *   from   dbo.sysobjects   where   id   =   object_id(N'[sys_syscomments_bak]')   and   OBJECTPROPERTY(id,   N'IsUserTable')   ......

SQL Server Êý¾Ý¿âµ¼Èëµ¼³ö²¿·Ö

1.ÔÚ²éѯ·ÖÎöÆ÷ϲéѯExcelÎĵµ
Select * from
OpenDataSource('Microsoft.Jet.OLEDB.4.0','Data Source = "c:\²âÊÔ.xls";User ID = Admin;Password=;Extended properties=Excel8.0)....Sheet1$
2.´ÓÊý¾Ý¿âÖе¼³öÊý¾Ý²¢´æµ½ÎļþÖÐ
EXEC master..xp_cmdshell 'bcp CAS2004..HGZ_LIAOJIAN out c:\temp1.xls -c -q -S"."- ......
© 2009 ej38.com All Rights Reserved. ¹ØÓÚE½¡ÍøÁªÏµÎÒÃÇ | Õ¾µãµØͼ | ¸ÓICP±¸09004571ºÅ