һЩ»ù±¾µÄSQLÃüÁî
--ÏÔʾ°æ±¾ºÅ£¬µ±Ç°ÈÕÆÚ
SELECT VERSION(),CURRENT_DATE(),NOW();
--Ãâ·ÑµÄ¼ÆËãÆ÷
SELECT (20+5)*4 AS RESULT,SIN(PI()/3);
--´´½¨Êý¾Ý¿â
CREATE DATABASE databasename;
--ɾ³ýÊý¾Ý¿â
DROP DATABASE databasename;
--ÏÔʾµ±Ç°´æÔÚµÄÊý¾Ý¿â
SHOW DATABASES;
--Ñ¡ÔñÊý¾Ý¿â
USE databasename;
--ÏÔʾµ±Ç°Ñ¡ÔñµÄÊý¾Ý¿â
SELECT DATABASE(), USER();
--ÏÔʾµ±Ç°Êý¾Ý¿âÖеıí
SHOW TABLES;
--²åÈë±í
CREATE TABLE tablename
(
id varchar(32) not null primary key,
name varchar(20) not null,
password varchar(20) not null
);
--²åÈëÊý¾Ý
INSERT INTO tablename VALUES ('CZX','Christen','litejava');
--µ¼Èë½Å±¾
SOURCE filepath; -- eg SOURCE C:/blog.sql
--ɾ³ý±í
DROP TABLE tablename;
--ɾ³ý±íÖеÄÈ«²¿Êý¾Ý
DELETE from tablename;
--¸üÐÂÊý¾Ý
UPDATE tablename SET password='123456';
--ÏÔʾ±íµÄÄÚÈÝ
SELECT * from tablename;
--ÃèÊö±íµÄ½á¹¹
DESCRIBE tablename;
--´ÓÎı¾Öе¼ÈëÊý¾Ý
LOAD DATA LOCAL INFILE 'file path' INTO TABLE tablename;
--Ñ¡ÔñÌØÊâÐÐ
SELECT * from tablename WHERE id = 'czx';
SELECT name,password from tablename WHERE id = 'czx' AND name = 'Christen'
SELECT * from tablename WHERE name IS NULL;
--È¥³ýÖØ¸´ÐÐ
SELECT DISTINCT name from tablename;
--Ä£ºý²éѯ
SELECT * from tablename WHERE name LIKE '%³Â×ÔÐÂ%';
--¼ÆÊý
SELECT COUNT(*) from tablename;
#°´Ìõ¼þ¹ýÂË
SELECT * from T_Employee WHERE FSalary>4000 AND FSalary<8000
SELECT * from T_Employee WHERE FSalary BETWEEN 4000 AND 8000
#ÅÅÐòascÉýÐò,desc½µÐò
#select * from info order by wage desc
#select * from info order by name asc
#Ä£ºý²éѯ
#SELECT address from info where t_name like '%c%'
#²åÈëÒ»ÁÐ
#alter table info add t_phone varchar(24) null
#ÇóºÍsum,max,min,avg
#select sum(c_2) from tablename
ÏÔʾÊý¾Ý¿â»ò±í:
show databases;
use database_name;
show tables;
¸ü¸Ä±íÃû:
&
Ïà¹ØÎĵµ£º
×î½ü·¢ÏÖÎÒÃǹ«Ë¾µÄASP.NETµÄ´úÂëÓÐÆ´½ÓSQLÓï¾äµÄϰ¹ß£¡ÕâÊǷdz£Î£Ïյġ£ÒÔÏÂÎÒ¾ÙÀý˵Ã÷Ò»ÏÂ
Àý×Ó1£º
statement := "SELECT * from users WHERE name = '" + userName + "'; "
½«Óû§Ãû±äÁ¿(¼´username)ÉèÖÃΪ£º
a' or 't'='t£¬´ËʱÔʼÓï¾ä·¢ÉúÁ˱仯£º
SELECT * from users WHERE name = 'a' OR 't'='t';
Èç¹ûÕâ ......
Google dorks sql injection:
inurl:index.php?id=
inurl:trainers.php?id=
inurl:buy.php?category=
inurl:article.php?ID=
inurl:Play_old.php?id=
inurl:declaration_more.php?decl_id=
inurl:Pageid=
inurl:game ......
MySQL:
SELECT column from table
ORDER BY RAND()
LIMIT 1
PostgreSQL:
SELECT column from table
ORDER BY RANDOM()
LIMIT 1
Microsoft SQL Server:
SELECT TOP 1 column from table
ORDER BY NEWID()
IBM DB2
SELECT column, RAND() as IDX
from table
ORDER BY IDX FETCH FIRST 1 ROWS ONLY
Thanks Ti ......
Ó¦Ò»¸öÅóÓѵÄÒªÇó£¬ÌùÉÏÊղصÄSQL³£Ó÷ÖÒ³µÄ°ì·¨¡«¡«
±íÖÐÖ÷¼ü±ØÐëΪ±êʶÁУ¬[ID] int IDENTITY (1,1)
1.·ÖÒ³·½°¸Ò»£º(ÀûÓÃNot InºÍSELECT TOP·ÖÒ³)
Óï¾äÐÎʽ£º
SELECT TOP Ò³¼Ç¼ÊýÁ¿ *
from ±íÃû
WHERE (ID NOT IN
(SELECT TOP (ÿҳÐÐÊý*(Ò³Êý-1)) ID
from ± ......
·¢±íϱ¾È˽øÐЩ¶´ÍÚ¾òµÄÊׯªÔ´´ÎÄÕ£º
¶ÔDiscuz nT3.0½øÐÐÁË·ÖÎö£¬·¢ÏÖspacemanage.aspxÒ³Ãæ´æÔÚÒ»¸ö×¢Èë©¶´£¬
¸ÃÒ³ÃæÎ»Öãºdnt3_src\dnt3\Discuz.Web\space\Admin
´úÂëÈçÏ£º
public void BindData()
{
DataGrid1.AllowCustomPaging = true;
string username = Usernam ......