SQL×¢Èë½Ì³ÌÖ®ÈëÃÅÆª
Èë Êƪ
Èç¹ûÄãÒÔǰûÊÔ¹ýSQL×¢ÈëµÄ»°£¬ÄÇôµÚÒ»²½ÏȰÑIE²Ëµ¥=>¹¤¾ß=>InternetÑ¡Ïî=>¸ß¼¶=>ÏÔʾÓѺà HTTP ´íÎóÐÅÏ¢Ç°ÃæµÄ¹´È¥µô¡£·ñÔò£¬²»ÂÛ·þÎñÆ÷·µ»ØÊ²Ã´´íÎó£¬IE¶¼Ö»ÏÔʾΪHTTP 500·þÎñÆ÷´íÎ󣬲»ÄÜ»ñµÃ¸ü¶àµÄÌáʾÐÅÏ¢¡£
µÚÒ»½Ú¡¢SQL×¢ÈëÔÀí
ÒÔÏÂÎÒÃÇ´ÓÒ»¸öÍøÕ¾www.19cn.com¿ªÊ¼£¨×¢£º±¾ÎÄ·¢±íǰÒÑÕ÷µÃ¸ÃÕ¾Õ¾³¤Í¬Ò⣬´ó²¿·Ö¶¼ÊÇÕæÊµÊý¾Ý£©¡£
ÔÚÍøÕ¾Ê×Ò³ÉÏ£¬ÓÐÃûΪ“IE²»ÄÜ´ò¿ªÐ´°¿ÚµÄ¶àÖÖ½â¾ö·½·¨”µÄÁ´½Ó£¬µØÖ·Îª£ºhttp://www.19cn.com/showdetail.asp?id=49£¬ÎÒÃÇÔÚÕâ¸öµØÖ·ºóÃæ¼ÓÉϵ¥ÒýºÅ’£¬·þÎñÆ÷»á·µ»ØÏÂÃæµÄ´íÎóÌáʾ£º
Microsoft JET Database Engine ´íÎó '80040e14'
×Ö·û´®µÄÓï·¨´íÎó ÔÚ²éѯ±í´ïʽ 'ID=49'' ÖС£
/showdetail.asp£¬ÐÐ8
´ÓÕâ¸ö´íÎóÌáʾÎÒÃÇÄÜ¿´³öÏÂÃæ¼¸µã£º
1.ÍøÕ¾Ê¹ÓõÄÊÇAccessÊý¾Ý¿â£¬Í¨¹ýJETÒýÇæÁ¬½ÓÊý¾Ý¿â£¬¶ø²»ÊÇͨ¹ýODBC¡£
2.³ÌÐòûÓÐÅжϿͻ§¶ËÌá½»µÄÊý¾ÝÊÇ·ñ·ûºÏ³ÌÐòÒªÇó¡£
3.¸ÃSQLÓï¾äËù²éѯµÄ±íÖÐÓÐÒ»ÃûΪIDµÄ×ֶΡ£
´ÓÉÏÃæµÄÀý×ÓÎÒÃÇ¿ÉÒÔÖªµÀ£¬£Ó£Ñ£Ì×¢ÈëµÄÔÀí£¬¾ÍÊÇ´Ó¿Í»§¶ËÌá½»ÌØÊâµÄ´úÂ룬´Ó¶øÊÕ¼¯³ÌÐò¼°·þÎñÆ÷µÄÐÅÏ¢£¬´Ó¶ø»ñÈ¡ÄãÏëµ½µÃµ½µÄ×ÊÁÏ¡£
µÚ¶þ½Ú¡¢ÅжÏÄÜ·ñ½øÐУӣѣÌ×¢Èë
¿´ÍêµÚÒ»½Ú£¬ÓÐһЩÈË»á¾õµÃ£ºÎÒÒ²ÊǾ³£ÕâÑù²âÊÔÄÜ·ñ×¢ÈëµÄ£¬Õâ²»ÊǺܼòµ¥Âð£¿Æäʵ£¬Õâ²¢²»ÊÇ×îºÃµÄ·½·¨£¬ÎªÊ²Ã´ÄØ£¿
Ê×ÏÈ£¬²»Ò»¶¨Ã¿Ì¨·þÎñÆ÷µÄIIS¶¼·µ»Ø¾ßÌå´íÎóÌáʾ¸ø¿Í»§¶Ë£¬Èç¹û³ÌÐòÖмÓÁËcint(²ÎÊý)Ö®ÀàÓï¾äµÄ»°£¬£Ó£Ñ£Ì×¢ÈëÊDz»»á³É¹¦µÄ£¬µ«·þÎñÆ÷ͬÑù»á±¨´í£¬¾ßÌåÌáʾÐÅϢΪ´¦Àí URL ʱ·þÎñÆ÷Éϳö´í¡£ÇëºÍϵͳ¹ÜÀíÔ±ÁªÂç¡£
Æä´Î£¬²¿·Ö¶Ô£Ó£Ñ£Ì×¢ÈëÓÐÒ»µãÁ˽âµÄ³ÌÐòÔ±£¬ÈÏΪֻҪ°Ñµ¥ÒýºÅ¹ýÂ˵ô¾Í°²È«ÁË£¬ÕâÖÖÇé¿ö²»ÎªÉÙÊý£¬Èç¹ûÄãÓõ¥ÒýºÅ²âÊÔ£¬ÊDzⲻµ½×¢ÈëµãµÄ
ÄÇô£¬Ê²Ã´ÑùµÄ²âÊÔ·½·¨²ÅÊDZȽÏ×¼È·ÄØ£¿´ð°¸ÈçÏ£º
¢Ù http://www.19cn.com/showdetail.asp?id=49
¢Ú http://www.19cn.com/showdetail.asp?id=49 and 1=1
¢Û http://www.19cn.com/showdetail.asp?id=49 and 1=2
Õâ¾ÍÊǾµäµÄ1=1¡¢1=2²âÊÔ·¨ÁË£¬ÔõôÅжÏÄØ£¿¿´¿´ÉÏÃæÈý¸öÍøÖ··µ»ØµÄ½á¹û¾ÍÖªµÀÁË£º
¿ÉÒÔ×¢ÈëµÄ±íÏÖ£º
¢Ù Õý³£ÏÔʾ£¨ÕâÊDZØÈ»µÄ£¬²»È»¾ÍÊdzÌÐòÓдíÎóÁË£©
¢Ú Õý³£ÏÔʾ£¬ÄÚÈÝ»ù±¾Óë¢ÙÏàͬ
¢Û ÌáʾBOF»òEOF£¨³ÌÐòû×öÈκÎÅжÏʱ£©¡¢»òÌáʾÕÒ²»µ½¼Ç¼£¨ÅжÏÁËrs.eofʱ£©¡¢»òÏÔʾÄÚÈÝΪ¿Õ£¨³ÌÐò¼ÓÁËon error resume next£©
²»¿ÉÒÔ×¢Èë¾Í±È½ÏÈÝÒ×ÅжÏÁË£¬¢ÙͬÑùÕý³£ÏÔʾ£
Ïà¹ØÎĵµ£º
--8-1
USE Northwind
SELECT * from ::fn_dblog('', '')
GO
--8-2
USE Northwind
SELECT * from ::fn_dblog('', '') WHERE [Begin Time] >= '02/01/07'
GO
--9-1
SELECT *
from master.dbo.sysprocesses
--9-2
SELECT *
from sys.dm_exec_requests
--9-3
DECLARE @Handle varbinary(64);
SEL ......
²éѯ¼°É¾³ýÖØ¸´¼Ç¼µÄSQLÓï¾ä
1¡¢²éÕÒ±íÖжàÓàµÄÖØ¸´¼Ç¼£¬Öظ´¼Ç¼ÊǸù¾Ýµ¥¸ö×ֶΣ¨peopleId£©À´ÅжÏ
select * from people
where peopleId in (select peopleId from people group by peopleId having count(peopleId) > 1)
2¡¢É¾³ý±íÖжàÓàµÄÖØ¸´¼Ç¼£¬Öظ´¼Ç¼ÊÇ ......
µÚ1ÖÖ·½·¨£º
ÆóÒµ¹ÜÀíÆ÷
--¹ÜÀí
--ÓÒ¼üÊý¾Ý¿âά»¤¼Æ»®
--н¨Î¬»¤¼Æ»®
--<ÏÂÒ»²½>
--Ñ¡ÔñÄãÒª±¸·ÝµÄÊý¾Ý¿â
--<ÏÂÒ»²½>Ö±µ½"Ö¸¶¨Êý¾Ý¿â±¸·Ý¼Æ»®"ÕâÏî
--Ö¸¶¨´æ´¢±¸·ÝÎļþµÄλÖÃ,ÕâÀï¸ù¾ÝÐèҪѡÔñ±¸·Öµ½´Å´ø»¹ÊÇ´ÅÅÌ
--µ¥»÷µ÷¶ÈºóÃæµÄ"¸ü¸Ä"°´ ......
sql serverµÄËæ»úº¯ÊýnewID()ºÍRAND()¡¡¡¡
¡¡¡¡SELECT * from Northwind..Orders ORDER BY NEWID()
¡¡¡¡--Ëæ»úÅÅÐò
¡¡¡¡SELECT TOP 10 * from Northwind..Orders ORDER BY NEWID()
¡¡¡¡--´ÓOrders±íÖÐËæ»úÈ¡³ö10Ìõ¼Ç¼¡¡¡¡
¡¡¡¡Ê¾Àý¡¡¡¡
¡¡¡¡A.¶Ô±äÁ¿Ê¹Óà NEWID º¯Êý
¡¡¡¡ÒÔÏÂʾÀýʹÓà NEWID() ¶ÔÉùÃ÷Ϊ uniq ......
Ò»¡¢Êý¾Ý¿â´æ´¢¸ÅÊö
1¡¢Êý¾ÝÎļþÀàÐÍ
· Primary data files:ÿ¸öÊý¾Ý¿â¶¼ÓÐÒ»¸öµ¥¶ÀµÄÖ÷ÒªÊý¾ÝÎļþ£¬Ä¬ÈÏÒÔ.mdfÀ©Õ¹Ãû¡£Ö÷ÒªÊý¾ÝÎļþ²»½ö°üº¬Êý¾ÝÐÅÏ¢£¬»¹°üº¬Óë¸ÃÊý¾Ý¿â½á¹¹Ïà¹ØµÄÐÅÏ¢¡£´´½¨Êý¾Ý¿âʱ£¬Êý¾Ý¿â½á¹¹Ïà¹ØÐÅÏ¢²»½ö´æÔÚÓÚmasterÊý¾Ý¿âÖУ¬Í¬Ê ......