猜解法:此方法就是根據(jù)個(gè)人的經(jīng)驗(yàn)猜表名,一般來(lái)說(shuō),user,users,member,members,userlist,memberlist,userinfo,manager,admin,adminuser,systemuser,systemusers,sysuser,sysusers,sysaccounts,systemaccounts等。并通過(guò)語(yǔ)句進(jìn)行判斷 HTTP://xxx.xxx.xxx/abc.jsp?p=YYand (select count(*) from TestDB.dbo.表名)>0...
www.dbjr.com.cn/article/1215...htm 2025-5-29