1,
For websites with. net
Generally, a user is registered.
First, we chose to use the upload judgment vulnerability to add the image title gif89a.
2,
The second method is injection? Id = XX followed by single quotes "'"
In general, you can use nbsi and D to scan and find the bug page.
In addition, most. Net databases in China use MSSQL databases.
The injection point can also be found from login. In fact, the current success rate of this method is 75%.
3,
However, when the search type is displayed and no error message is displayed, it gets stuck here.
You can check the previous search injection article on the Internet. It's a good luck that the database is with the Web.
Write the backup log statement directly in the search. If the input box contains limited characters, you can create a post form locally.
You can also use wsockexpert to capture the search. aspx? Add injection statement after Value Analysis
It is better to get the path as long as the Web. config
The Code is as follows:
<! -- Web. config configuration file -->
<Configuration>
<System. Web>
<Customerrors mode = "on"/> 'if it is off, it will fail.
</System. Web>
</Configuration>
You only need
For example, change allyesno. aspx ~ Allyesno. aspx successfully obtains the absolute web path
4,
Good luck, found login Background:
For example: http://allyesno.cnblogs.com/admin/login.aspx
Returns to http://allyesno.cnblogs.com/admin/error.aspx if a Password error is entered
If you enter http://allyesno.cnblogs.com/admin1_5cindex.aspx, the infinitus can be verified.
5,
Background Raster Method:
'Or ''='
'Or ''='
Or
'Or' = 'or'
'Or' = 'or'