
//
//
//
//
//
//
//
//
//
//
软件Tags:
效果图:以下代码复制后存成a.bat文件后放到要分析的日志(.log后缀)目录下,双击,等,黑窗结束后查看结果,以后不用再为了分析庞大的日志文件头疼了,简单的一条命令而已,更多功能可以无限扩展哟。。 复制代码
代码如下:::日志提取特征加强版::md Analyfindstr /c:"and" *.log >> Analy/and.txtfindstr /c:"or" *.log >> Analy/or.txtfindstr /c:"select" *.log >> Analy/select.txtfindstr /c:"exec" *.log >> Analy/exec.txtfindstr /c:"0x" *.log >> Analy/0x.txtfindstr /c:"md5" *.log >> Analy/md5.txtfindstr /c:"schema" *.log >> Analy/schema.txtfindstr /c:"eval" *.log >> Analy/eval.txtfindstr /c:"cmd" *.log >> Analy/cmd.txtfindstr /c:"char" *.log >> Analy/char.txtfindstr /c:"alter" *.log >> Analy/alter.txtfindstr /c:"begin" *.log >> Analy/begin.txtfindstr /c:"cast" *.log >> Analy/cast.txtfindstr /c:"chr" *.log >> Analy/chr.txtfindstr /c:"convert" *.log >> Analy/convert.txtfindstr /c:"count" *.log >> Analy/count.txtfindstr /c:"CONCAT" *.log >> Analy/CONCAT.txtfindstr /c:"create" *.log >> Analy/create.txtfindstr /c:"cursor" *.log >> Analy/cursor.txtfindstr /c:"declare" *.log >> Analy/declare.txtfindstr /c:"delete" *.log >> Analy/delete.txtfindstr /c:"dir" *.log >> Analy/dir.txtfindstr /c:"drop" *.log >> Analy/drop.txtfindstr /c:"end" *.log >> Analy/end.txtfindstr /c:"fetch" *.log >> Analy/fetch.txtfindstr /c:"format" *.log >> Analy/format.txtfindstr /c:"insert" *.log >> Analy/insert.txtfindstr /c:"limit" *.log >> Analy/limit.txtfindstr /c:"kill" *.log >> Analy/kill.txtfindstr /c:"master" *.log >> Analy/master.txtfindstr /c:"mid" *.log >> Analy/mid.txtfindstr /c:"open" *.log >> Analy/open.txtfindstr /c:"password" *.log >> Analy/password.txtfindstr /c:"request" *.log >> Analy/request.txtfindstr /c:"script" *.log >> Analy/script.txtfindstr /c:"shell" *.log >> Analy/shell.txtfindstr /c:"sp_" *.log >> Analy/sp_.txtfindstr /c:"where" *.log >> Analy/where.txtfindstr /c:"xp_" *.log >> Analy/xp_.txtfindstr /c:"sys" *.log >> Analy/sys.txtfindstr /c:"table" *.log >> Analy/table.txtfindstr /c:"truncate" *.log >> Analy/truncate.txtfindstr /c:"update" *.log >> Analy/update.txtfindstr /c:"union" *.log >> Analy/union.txt</p><p>::提取日志二次筛选::cd Analyfindstr /c:"200 0 0" *.txt >> 200.logfindstr /c:"POST" 200.log >> 200POST.txtfindstr /c:"php" 200.log >> php.txtfindstr /c:"asa" 200.log >> asa.txtfindstr /c:"asp" 200.log >> asp.txtfindstr /c:"aspx" 200.log >> aspx.txtfindstr /c:"cer" 200.log >> cer.txt警告:运行BAT源码是一种危险的动作,如果你不熟悉,请不要尝试!
