SQL×¢Èë¼òµ¥ÔÀí·ÖÎö
	
    
    
	 SQL×¢Èë¼òµ¥·ÖÎö 
ʾÀýÓï¾ä£º 
select * from admintable where adminName like '%a%'
ÔÚ²éѯÖÐÎÒÃÇÒ»°ãÔÚaÕâ¸öµØ·½ÓɽçÃæ´«È벻ͬµÄÖµ£¬µ±ÎÒÃÇÔÚaÕâÀï´«ÈëµÄֵΪ“'”µ¥ÒýºÅʱ£¬Æ´´Õ³ÉµÄSQLÓï¾ä¾ÍÈçÏ£º
select * from admintable where adminName like '%'%'
Ö´ÐÐÕâ¾äÓï¾äÎÒÃǻᷢÏÖ³öÏÖÒÔÏÂÒì³££º
ÏûÏ¢ 105£¬¼¶±ð 15£¬×´Ì¬ 1£¬µÚ 1 ÐÐ
×Ö·û´® ' 
' ºóµÄÒýºÅ²»ÍêÕû¡£
ÏûÏ¢ 102£¬¼¶±ð 15£¬×´Ì¬ 1£¬µÚ 1 ÐÐ
' 
' ¸½½üÓÐÓï·¨´íÎó¡£
ÒòΪµ¥ÒýºÅµÄ¼ÓÈëÊÇÔ±¾ÍêÕûµÄSQLÓï¾äÆ´´Õ²»ÔÙÍêÕû£¬Òò´Ëµ¼ÖÂÒÔÉÏÒì³£¡£
¶øÒ»°ãºÚ¿ÍÔÚ¼òµ¥µÄ³¢ÊÔ×¢Èëʱ£¬ÔÚ½çÃæµÄÊäÈë´¦£¨ÈçURLµÄ²ÎÊý£¬Îı¾¿òµÄÊäÈëµÈ£©Ö±½ÓÊäÈëµ¥ÒýºÅÀ´²âÊÔÊÇ·ñ»áÒý·¢SQLÒì³££¬¸ù¾ÝÒ³ÃæµÄ´íÎó´úÂëÕ¹ÏÖÀ´ÅжÏÊÇ·ñ´æÔÚSQL×¢Èë©¶´£¬ÀýÈç»áÖ±½ÓÔÚÒ³ÃæÖгöÏÖSQLµÄÒì³£´úÂë»òÖ±½ÓÌø×ªµ½´íÎóÒ³Ãæ¡£µ±±»ÈÏΪ´æÔÚSQL×¢Èë©¶´Ê±£¬ÄÇô½«²»ÔÙÊÇÊäÈëµ¥ÒýºÅÁË£¬¶øÊÇÊäÈëÏà¹ØµÄSQLÖ´ÐÐÓï¾ä¡£
ÓÚÊǵ±ÎÒÃÇ´«È벻ͬµÄÖµÀýÈç 
  ' or 1=1 ;delete admintable where 1=1 or ''=' 
µÃµ½µÄSQLÓï¾ä¾ÍÈçÏ£º 
select * from admintable where adminName like '%' or 1=1 ;delete admintable where 1=1 or ''='%' 
¶øÕâ¾äSQLµÄÖ´ÐÐЧ¹û¾ÍÓÐÁ½¸ö£º
1¡¢select * from admintable where adminName like '%' or 1=1 ;
     --²éѯadmintable
2¡¢delete admintable where 1=1 or ''='%' 
     --½«admintableÇå¿Õ
Ò²¾ÍÊÇ˵Èç¹û°Ñdelete admintable where 1=1 Õâ¾äSQLÀ©Õ¹Ð޸ĵϰ£¬¿ÉÒÔÖ´ÐÐÔöɾ¸ÄµÈ²Ù×÷ÁË£¬ÀýÈçSQL2000ÖеÄXP_CMDShellÃüÁÄÜÖ±½ÓÖ´ÐÐCMDÃüÁį̂µÄCMDÃüÁÀ´ÊµÏÖÖ±½Ó¶Ô·þÎñÆ÷µÄ¿ØÖƵȡ£
ÖÁÓÚÈçºÎ±©Â¶³öÊý¾Ý¿âµÄ¸÷¸ö±íµÄÃû×ֵȣ¬¿ÉÒÔͨ¹ýö¾Ù²Â²âµÈ·½Ê½ÊµÏÖ£¬ÍøÂçÉÏÒѾÓÐÏà¹ØµÄSQL×¢È빤¾ß¿É¹©Ö±½ÓʹÓá£
µ±ÎÒÃǵÄÍøÕ¾´æÔÚSQL×¢Èë©¶´Ê±£¬×îºÃÐÞ¸ÄÏà¹ØµÄµ×²ã´úÂë»òÕßʹÓÃÏà¹ØµÄ¼à¿Ø¹¤¾ßÀ´ÐÞ¸´¡£Ò»¸öÍøÕ¾±»ÈëÇÖ²¢²»ÊÇºÚ¿ÍµÄ´í£¬¶øÊÇ·þÎñÆ÷¹ÜÀíÔ±ºÍÍøÕ¾¿ª·¢ÈËÔ±ÈÇϵĻö¡£
ÈçÓдíÎ󣬾´ÇëÖ¸Õý¡£
    
     
	
	
    
    
	Ïà¹ØÎĵµ£º
        
    
    ----start
    ÔÚSQLÓï¾äµÄ WHERE ×Ó¾äÖÐÓ¦¸Ã¾¡Á¿±ÜÃâÔÚ×Ö¶ÎÉÏʹÓú¯Êý£¬ÒòΪÕâÑù×ö»áʹ¸Ã×Ö¶ÎÉϵÄË÷ÒýʧЧ£¬Ó°ÏìSQLÓï¾äµÄÐÔÄÜ¡£¼´Ê¹¸Ã×Ö¶ÎÉÏûÓÐË÷Òý£¬Ò²Ó¦¸Ã±ÜÃâÔÚ×Ö¶ÎÉÏʹÓú¯Êý¡£¿¼ÂÇÏÂÃæµÄÇé¿ö£º
CREATE TABLE USER
(
NAME VARCHAR(20) NOT NULL,---ÐÕÃû
REGISTERDATE TIMESTAMP---×¢² ......
	
    
        
    
    sql ºÜ¾Ã²»Óã¬Í»È»¼äÒªÇó×ö±¨±í¡£ËùÒÔÓÖ¿ÉÒÔ²¹Ò»²¹sql֪ʶÁË¡£µ«¾³£»áÓöµ½Ò»Ð©ÈõÖÇÎÊÌâ.
дÁËÒ»Ìõsql£ºselect to_date('2009-09-24 12:20:0') Äܽ«¸Ä×Ö·û´®×ª»»ÎªÈÕÆÚ
µ«ÁíÍâÒ»Ìõsqlȴת»»²»ÁË...¸Ð¾õºÜÆæ¹Ö.ÓÚÊǺõ¡£ÔÙ×Ðϸ¿´Ò»±é ·¢ÏÖ
¸øÒ»¸öÈÕÆÚ×Ö¶ÎÉèÖñðÃûʱÉèÖóÉÁËsib.fbizDate as dateÎÒ×Ô¼º¶¼ÎÞÓïÁË¡£Ôõô»áÉè ......
	
    
        
    
    ----start
    Ç°Ã棬ÎÒÃǽéÉÜÁË ¾¡Á¿±ÜÃâÔÚSQLÓï¾äµÄWHERE×Ó¾äÖÐʹÓú¯Êý£¬ÒòΪÕâÑù×ö»áʹ¸Ã×Ö¶ÎÉϵÄË÷ÒýʧЧ£¬Ó°ÏìSQLÓï¾äµÄÐÔÄÜ¡£»ùÓÚͬÑùµÄµÀÀí£¬ÎÒÃÇÒ²Ó¦¸Ã±ÜÃâʹÓÃLIKE¡£¿¼ÂÇÏÂÃæµÄÇé¿ö£º
CREATE TABLE USER
(
NAME VARCHAR(20) NOT NULL,---ÐÕÃû
MYNUMBER VARCHAR(18)---Éí·ÝÖ¤ºÅÂë
);&nb ......
	
    
        
    
    /* 
ʹÓÃÊÂÎñÈÕÖ¾»Ö¸´Êý¾ÝµÄʵÑé
*/
--1.´´½¨²âÊÔÊý¾Ý¿â
CREATE DATABASE Db_test
ON
( NAME = Db_test_DATA,
      FILENAME = 'c:\Db_test.mdf' )
LOG ON 
( NAME = Db_test_LOG,
   FILENAME = 'c:\Db_test.ldf')
GO
--2.¹ÊÕÏ»¹ÔÄ£ÐÍÉèÖÃΪfullÄ£ÐÍ,ĬÈϵļòµ¥Ä£Ðͱ¸·Ý ......
	
    
        
    
    ÔÚExcelÖУ¬ÎÒÃÇʱ³£»áÅöµ½ÕâÑùµÄ×Ö¶Î(×î³£¼ûµÄ¾ÍÊǵ绰ºÅÂë)£¬¼´Óд¿Êý×ÖµÄ(ÈçûÓдøÇøºÅµÄµç»°ºÅÂë)£¬ÓÖÓÐÊý×ÖºÍÆäËü×Ö·û»ìºÏ (Èç“ÇøºÅ-µç
»°ºÅÂë”)µÄÊý¾Ý£¬ÔÚµ¼ÈëSQLServer¹ý³ÌÖУ¬»á·¢ÏÖҪô´¿Êý×ÖµÄÊý¾Ýµ¼¹ýÈ¥Ö®ºó±ä³ÉÁËNULL£¬ÒªÃ´¾ÍÊÇÊý×ÖºÍÆäËü×Ö·û»ìºÏµÄÊý¾Ýµ¼¹ýÈ¥Ö®ºó±ä³É
ÁËNULL¡£
  &n ......