SQLÈ«¾Ö±äÁ¿
SQL Server ϵͳȫ¾Ö±äÁ¿
@@CONNECTIONS
·µ»Ø×ÔÉÏ´ÎÆô¶¯ÒÔÀ´Á¬½Ó»òÊÔͼÁ¬½ÓµÄ´ÎÊý¡£
@@CURSOR_ROWS
·µ»ØÁ¬½ÓÉÏ×îºó´ò¿ªµÄÓαêÖе±Ç°´æÔڵĺϸñÐеÄÊýÁ¿(·µ»Ø±»´ò¿ªµÄÓαêÖл¹Î´±»¶ÁÈ¡µÄÓÐЧÊý¾ÝÐеÄÐÐÊý)
@@DATEFIRST
·µ»ØÿÖܵÚÒ»ÌìµÄÊý×Ö
@@ERROR
·µ»Ø×îºóÖ´ÐеÄSQL Óï¾äµÄ´íÎó´úÂë¡£
@@FETCH_STATUS
·µ»Ø±» FETCH Óï¾äÖ´ÐеÄ×îºóÓαêµÄ״̬£¬¶ø²»ÊÇÈκε±Ç°±»Á¬½Ó´ò¿ªµÄÓαêµÄ״̬¡£
@@IDENTITY
·µ»Ø×îºó²åÈëµÄ±êʶֵ
@@LANGID
·µ»Øµ±Ç°ËùʹÓÃÓïÑԵı¾µØÓïÑÔ±êʶ·û(ID)¡£
@@LANGUAGE
·µ»Øµ±Ç°Ê¹ÓõÄÓïÑÔÃû¡£
@@LOCK_TIMEOUT
·µ»Øµ±Ç°»á»°µÄµ±Ç°Ëø³¬Ê±ÉèÖ㬵¥Î»ÎªºÁÃë¡£
@@PROCID
·µ»Øµ±Ç°¹ý³ÌµÄ´æ´¢¹ý³Ì±êʶ·û (ID) ¡£
@@ROWCOUNT
·µ»ØÊÜÉÏÒ»Óï¾äÓ°ÏìµÄÐÐÊý¡£
@@SERVERNAME
·µ»ØÔËÐÐ µÄ±¾µØ·þÎñÆ÷Ãû³Æ¡£
@@SPID
·µ»Øµ±Ç°Óû§½ø³ÌµÄ·þÎñÆ÷½ø³Ì±êʶ·û (ID)¡£
@@TRANCOUNT
·µ»Øµ±Ç°Á¬½ÓµÄ»î¶¯ÊÂÎñÊý¡£
@@VERSION
·µ»Øµ±Ç°°²×°µÄÈÕÆÚ¡¢°æ±¾ºÍ´¦ÀíÆ÷ÀàÐÍ¡£
@@CPU_BUSY
·µ»Ø×ÔSQL Server ×î½üÒ»´ÎÆô¶¯ÒÔÀ´CPU µÄ¹¤×÷ʱ¼äÆ䵥λΪºÁÃë
@@DATEFIRST
·µ»ØʹÓÃSET DATEFIRST ÃüÁî¶ø±»¸³ÖµµÄDATAFIRST ²ÎÊýÖµSET DATEFIRST£¬ÃüÁîÓÃÀ´Ö¸¶¨Ã¿ÖܵĵÚÒ»ÌìÊÇÐÇÆÚ¼¸
@@DBTS
·µ»Øµ±Ç°Êý¾Ý¿âµÄʱ¼ä´ÁÖµ±ØÐë±£Ö¤Êý¾Ý¿âÖÐʱ¼ä´ÁµÄÖµÊÇΩһµÄ
@@ERROR
·µ»ØÖ´ÐÐTransact-SQL Óï¾äµÄ´íÎó´úÂë
@@FETCH_STATUS
·µ»ØÉÏÒ»´ÎFETCH Óï¾äµÄ״ֵ̬
@@IDLE
·µ»Ø×ÔSQL Server ×î½üÒ»´ÎÆô¶¯ÒÔÀ´CPU ´¦ÓÚ¿Õ±Õ״̬µÄʱ¼ä³¤¶Ìµ¥Î»ÎªºÁÃë
@@IO_BUSY
·µ»Ø×ÔSQL Server ×î½üÒ»´ÎÆô¶¯ÒÔÀ´CPU Ö´ÐÐÊäÈëÊä³ö²Ù×÷Ëù»¨·ÑµÄʱ¼äÆ䵥λΪºÁÃë
@@LANGID
·µ»Øµ±Ç°ËùʹÓõÄÓïÑÔID Öµ
@@LANGUAGE
·µ»Øµ±Ç°Ê¹ÓõÄÓïÑÔÃû³Æ
@@LOCK_TIMEOUT
·µ»Øµ±Ç°»á»°µÈ´ýËøµÄʱ¼ä³¤¶ÌÆ䵥λΪºÁÃë
@@MAX_CONNECTIONS
·µ»ØÔÊÐíÁ¬½Óµ½SQL Server µÄ×î´óÁ¬½ÓÊýÄ¿
@@MAX_PRECISION
·µ»Ødecimal ºÍnumeric Êý¾ÝÀàÐ͵ľ«È·¶È
@@NESTLEVEL
·µ»Øµ±Ç°Ö´ÐеĴ洢¹ý³ÌµÄǶÌ×¼¶Êý³õʼֵΪ0
@@OPTIONS
·µ»Øµ±Ç°SET Ñ¡ÏîµÄÐÅÏ¢
@@PACK_RECEIVED
·µ»ØSQL Server ͨ¹ýÍøÂç¶ÁÈ¡µÄÊäÈë°üµÄÊýÄ¿
@@PACK_SENT
·µ»ØSQL Server д¸øÍøÂçµÄÊä³ö°üµÄÊýÄ¿
@@PACKET_ERRORS
·µ»ØÍøÂç°üµÄ´íÎóÊýÄ¿
@@PROCID
·µ»Øµ±Ç°´æ´¢¹ý³ÌµÄID Öµ
@@REMSERVER
·µ»ØÔ¶³ÌSQL Server Êý¾Ý¿â·þÎñÆ÷µÄÃû³Æ
@@SERVICENAME
·µ»ØSQL Server ÕýÔËÐÐÓÚÄÄÖÖ·þÎñ״̬֮ÏÂÈçMSSQLSer
Ïà¹ØÎĵµ£º
1¡¢ ÓóÌÐòÖУ¬±£Ö¤ÔÚʵÏÖ¹¦ÄܵĻù´¡ÉÏ£¬¾¡Á¿¼õÉÙ¶ÔÊý¾Ý¿âµÄ·ÃÎÊ´ÎÊý£»Í¨¹ýËÑË÷²ÎÊý£¬¾¡Á¿¼õÉÙ¶Ô±íµÄ·ÃÎÊÐÐÊý,×îС»¯½á¹û¼¯£¬´Ó¶ø¼õÇáÍøÂ縺µ££»Äܹ»·Ö¿ªµÄ²Ù×÷¾¡Á¿·Ö¿ª´¦Àí£¬Ìá¸ßÿ´ÎµÄÏìÓ¦Ëٶȣ»ÔÚÊý¾Ý´°¿ÚʹÓÃSQLʱ£¬¾¡Á¿°ÑʹÓõÄË÷Òý·ÅÔÚÑ¡ÔñµÄÊ×ÁУ»Ëã·¨µÄ½á¹¹¾¡Á¿¼òµ¥£»ÔÚ²éѯʱ£¬²»Òª¹ý¶àµØʹÓà ......
Google dorks sql injection:
inurl:index.php?id=
inurl:trainers.php?id=
inurl:buy.php?category=
inurl:article.php?ID=
inurl:Play_old.php?id=
inurl:declaration_more.php?decl_id=
inurl:Pageid=
inurl:game ......
°²×°SQL Server2005 ÎÊÌâÐÅÏ¢£º
“SQL Server °²×°³ÌÐòÎÞ·¨»ñÈ¡ ASPNET ÕÊ»§µÄϵͳÕÊ»§ÐÅÏ¢”
½â¾ö°ì·¨£º
ÓÃaspnet_regiisʵÓù¤¾ßжÔغÍÖØа²×°Ò»Ï¾ͿÉÒÔÁË¡£
¾ßÌåµÄ²Ù×÷£º
1¡¢½øÈëCMD£º
C:\windows\microsoft.net\framework\v2.0.50727Îļþ¼ÐÏ£¬ÔËÐÐaspnet_regiis -uжÔØ
È»ºóÔËÐÐaspnet_regiis -i Ö ......
ÔÚ³ÌÐòÖÐÓÐЩ²éѯÓï¾äÏà¶Ô½Ï³¤£¬¿ÉÒÔ½«Óï¾äµ¥¶ÀдÔÚÒ»¸öXXX.sqlÎļþÖУ¬ÔÚ³ÌÐòÖжÁÈ¡SQLÎļþ
¾ßÌåÉæ¼°µ½
import java.io.File;
import org.apache.commons.io.FileUtils;
import java.net.URL;
URL resourceUrl = XXXX.class.getClassLoader().getResource(SQL_PATH+sqlName);//SQL_PATH¾ßÌåSQLÎļþ´æÔÚ·¾¶£¬sqlName¼ ......