<! -- # Include file = "conn. asp" -->
<%
Dim rs, strSQL, id
Set rs = server. createobject ("ADODB. recordset ")
Id = request ("id ")
StrSQL = "select * from admin where id =" & id
Rs. open strSQL, conn, 1, 3
Rs. close
%>
 
Replace admin with the table name to be forged in strSQL = "select * from admin where id =" & id ". Note that the table name must exist.
 
Then enter: http: // target IP Address/zhuru. asp? Id = 1
 
That's easy. Then, use the injection tool to scan the injection point, column directory, backup, and everything you want to do!
 
-----------------------------
Conn. asp file code:
 
<%
StrSQLServerName = "127.0.0.1" server name or address
StrSQLDBUserName = "sa" database account
StrSQLDBPassword = "123456789" Database Password
StrSQLDBName = "db_database" Database Name
Set conn = Server. CreateObject ("ADODB. Connection ")
StrCon = "Provider = SQLOLEDB.1; Persist Security Info = False; Server =" & strSQLServerName & "; User ID =" & strSQLDBUserName & "; Password =" & strSQLDBPassword &"; database = "& strSQLDBName &";"
Conn. open strCon
%>